Virus

Bonjour,

Hier je suis allé sur le site de Leclerc et j'ai l'impression que j'ai attrapé un virus. Avast me disait que j'ai attrapé un virus j'ai voulu le supprimer mais impossible... Je l'ai redemarrer et mon fond d'écran est devenu vert avec un message d'avertissement. Puis une notification dans la barre d'outils s'est affiché avec le message "Click here to protect to computer from spyware" et un long message en Anglais. Depuis j'ai desinstallé Avast (en mode sans échec) pour installer Avira Antivir qui ne veut pas s'installer.

Merci d'avance, cordialement
T!T!

27 réponses

Résumé de la discussion

Une suspicion d’infection est évoquée après une visite sur le site Leclerc, avec un fond d’écran vert, des avertissements et une notification en anglais prétendant protéger l’ordinateur contre les spyware. Les échanges indiquent qu’ Avast détecte le virus mais que la suppression échoue et que le redémarrage affiche des messages d’alerte en anglais; l’installation d’Avira Antivir échoue en mode normal. D’autres réponses évoquent des fichiers système manquants et des outils de désinfection, suggérant une infection plus avancée et la nécessité d’une prise en charge par le propriétaire de l’ordinateur. Au moins, le fil montre l’usage de ComboFix et Malwarebytes pour des analyses critiques, et qu’aucune solution définitive n’est confirmée à ce stade, laissant planer une éventuelle réinfection.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut titi40240

    C'est sur que cela n'étais pas fini, le PC étais encore infecté et des fichiers systèmes manquant :
    c:\windows\System32\drivers\beep.sys ... manque !!
    c:\windows\System32\wscntfy.exe ... manque !!
    c:\windows\System32\regsvc.dll ... manque !!


    Sinon demande au propriétaire du PC de venir s'inscrire pour poursuivre la désinfection

    @++ :)
    1
    1. Contributeur sécurité
      Salut titi40240

      Oui je serai là pour la suite

      @++ :)
      1
      1. *Télécharger Malwarebytes' Anti-Malware (MBAM) sur le Bureau.

        https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

        *Double-cliquer sur le fichier téléchargé pour lancer le processus d'installation.

        *Dans l'onglet Mise à jour, cliquer sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepter.

        *Une fois la mise à jour terminée, se rendre dans l'onglet Recherche.

        *Sélectionner Exécuter un Examen Complet.

        *Cliquer sur Rechercher. L'analyse dure généralement entre 30 minutes et 2 heures.

        *A la fin de l'analyse, un message s'affiche :

        "L'examen s'est terminé normalement. Cliquez sur "Afficher les résultats" pour afficher tous les objets trouvés"

        *Cliquer sur OK pour poursuivre. Si MBAM n'a rien trouvé, il le dira aussi.

        *Fermer les navigateurs (Internet Explorer, Mozilla Firefox, etc.).

        Si des Malwares ont été détectés, cliquer sur Afficher les résultats.
        Sélectionner tout (ou laisser coché) et cliquer sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
        MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copier-coller le rapport entier sur le forum Virus/Sécurité.

        - Utilisation d'un logiciel de diagnostic

        *Télécharger ZHPDiag (de Nicolas Coolman)

        https://www.zebulon.fr/telechargements/securite/systeme/zhpdiag.html

        *Se laisser guider lors de l'installation, le programme se lancera automatiquement à la fin.

        *Cliquer sur l'icône représentant une loupe (« Lancer le diagnostic »)

        *Enregistrer le rapport sur le Bureau à l'aide de l'icône représentant une disquette

        *Héberger le rapport ZHPDiag.txt sur un site tel que cijoint.fr, puis copier/coller le lien fourni sur le forum Virus/Sécurité de CCM.

        ESET NOD32 Antivirus/Malwarebytes' Anti-Malware 1.46(PRO)/Advanced SystemCare PRO/
        Google Chrome(AdBlock, WOT)/Ccleaner/Update Checker/O&ODefrag
        0
        1. J'ai pas fini je suis encore au scan MalwarBytes
          0
          1. Voici le rapport de MalwarBytes :
            Je ferai le reste demain la je ne peux pas.

            Malwarebytes' Anti-Malware 1.46
            www.malwarebytes.org

            Version de la base de données: 4078

            Windows 5.1.2600 Service Pack 2 (Safe Mode)
            Internet Explorer 7.0.5730.13

            08/05/2010 19:32:49
            mbam-log-2010-05-08 (19-32-49).txt

            Type d'examen: Examen complet (C:\|D:\|)
            Elément(s) analysé(s): 167216
            Temps écoulé: 22 minute(s), 51 seconde(s)

            Processus mémoire infecté(s): 1
            Module(s) mémoire infecté(s): 1
            Clé(s) du Registre infectée(s): 9
            Valeur(s) du Registre infectée(s): 6
            Elément(s) de données du Registre infecté(s): 18
            Dossier(s) infecté(s): 1
            Fichier(s) infecté(s): 22

            Processus mémoire infecté(s):
            C:\WINDOWS\system32\smss32.exe (Trojan.FakeAlert) -> Unloaded process successfully.

            Module(s) mémoire infecté(s):
            C:\WINDOWS\system32\helpers32.dll (Trojan.Agent) -> Delete on reboot.

            Clé(s) du Registre infectée(s):
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\TypeLib\{18af7201-4f14-4bcf-93fe-45617cf259ff} (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\Interface\{df76e9b7-35ec-46fc-af56-5b79ded9d64f} (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_CLASSES_ROOT\CLSID\{c10dc1f4-ccdf-4224-a24d-b23afc3573c8} (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c10dc1f4-ccdf-4224-a24d-b23afc3573c8} (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c10dc1f4-ccdf-4224-a24d-b23afc3573c8} (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\SE2010 (Rogue.Securityessentials2010) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo (Rogue.Eorezo) -> Quarantined and deleted successfully.

            Valeur(s) du Registre infectée(s):
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\spidermessenger (Spyware.AgenceExclusive) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\security essentials 2010 (Rogue.SecurityEssentials) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\eorezo (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\softwarehelper (Rogue.Eorezo) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smss32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smss32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

            Elément(s) de données du Registre infecté(s):
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: c:\windows\system32\winlogon32.exe -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.FakeAlert) -> Data: system32\winlogon32.exe -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\get-key-se10.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-security-essentials.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\buy-security-essentials.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\is-software-download.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-soft-package.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\download-software-package.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\get-key-se10.com\http (Hijack.TrustedZone) -> Bad: (2) Good: (4) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\winlogon32.exe) Good: (userinit.exe) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\ActiveDesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\activedesktop\NoChangingWallpaper (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSetActiveDesktop (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

            Dossier(s) infecté(s):
            C:\Program Files\Securityessentials2010 (Rogue.SecurityEssentials2010) -> Delete on reboot.

            Fichier(s) infecté(s):
            C:\WINDOWS\system32\helpers32.dll (Trojan.Agent) -> Delete on reboot.
            C:\Program Files\SpiderMessenger\SpiderMessenger.exe (Spyware.AgenceExclusive) -> Quarantined and deleted successfully.
            C:\Program Files\Securityessentials2010\SE2010.exe (Rogue.SecurityEssentials) -> Delete on reboot.
            C:\Program Files\EoRezo\eorezo.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
            C:\Documents and Settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
            C:\Documents and Settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdate.exe (Rogue.Eorezo) -> Quarantined and deleted successfully.
            C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\PHD09ORK\exe[1].exe (Adware.BHO) -> Quarantined and deleted successfully.
            C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\3CGBWIWL\gibsvc[1].exe (Adware.Gibmedia) -> Quarantined and deleted successfully.
            C:\Program Files\EoRezo\EoRezoBHO.dll (Rogue.Eorezo) -> Quarantined and deleted successfully.
            C:\System Volume Information\_restore{73F74EBC-C794-4174-8D7F-7202B69DC0E4}\RP1200\A0025593.dll (Trojan.Agent) -> Quarantined and deleted successfully.
            C:\System Volume Information\_restore{73F74EBC-C794-4174-8D7F-7202B69DC0E4}\RP1200\A0026455.exe (Rogue.SecurityEssentials) -> Quarantined and deleted successfully.
            C:\System Volume Information\_restore{73F74EBC-C794-4174-8D7F-7202B69DC0E4}\RP1211\A0034309.exe (Rootkit.Dropper) -> Quarantined and deleted successfully.
            C:\System Volume Information\_restore{73F74EBC-C794-4174-8D7F-7202B69DC0E4}\RP1211\A0034699.exe (Adware.BHO) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\61.exe (Adware.BHO) -> Quarantined and deleted successfully.
            D:\drivers\Malwarebytes_Anti-Malware_v1.36_(Multilingual)_by_knowl3dg3[1]\Malwarebytes Anti-Malware v1.36 (Multilingual) by knowl3dg3\keygen\haha.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\warnings.html (Malware.Trace) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Quick Launch\Security essentials 2010.lnk (Rogue.SecurityEssentials2010) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\config\systemprofile\Menu Démarrer\Security essentials 2010.lnk (Rogue.SecurityEssentials2010) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\smss32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
            C:\WINDOWS\system32\Winlogon32.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
            C:\Documents and Settings\Administrateur\Application Data\avdrn.dat (Malware.Trace) -> Quarantined and deleted successfully.
            C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage\wwwzuc32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
            0
            1. Tu as bien Supprimée la Sélection et redémarré ton pc ?

              N'oublie pas ZHPDiag
              ESET NOD32 Antivirus/Malwarebytes' Anti-Malware 1.46(PRO)/Advanced SystemCare PRO/
              Google Chrome(AdBlock, WOT)/Ccleaner/Update Checker/O&ODefrag
              0
              1. Bonjour,
                Désolé du retard. Oui j'ai supprimé la selection et redemarré le pc, voici le rapport(le lien) : http://www.cijoint.fr/cjlink.php?file=cj201005/cijavwx9Np.txt
                0
                1. Pouvez vous me répondre s'il vous plaît.

                  Merci
                  0
                  1. Contributeur sécurité
                    Salut titi40240

                    Télécharge combofix.exe (de sUBs) sur le bureau :

                    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                    http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

                    Important Désactive ton Antivirus, antispyware et Pare feu avant le scan avec Combofix :
                    https://forum.pcastuces.com/default.asp
                    https://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/

                    ==> Sauvegarde ton travail et ferme toutes les fenêtres actives, il peut y avoir un redémarrage du PC. Ne lance aucun programme tant que Combofix n'est pas fini. <==

                    Double clique sur combofix.exe, clique sur OUI et valide par Entrée

                    Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                    Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure

                    @++ :)
                    0
                    1. Bonjour dédétraqué et merci de ton aide, voilà le rapport combofix :

                      ComboFix 10-05-08.03 - Administrateur 09/05/2010 16:05:47.1.1 - x86 NETWORK
                      Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.511.356 [GMT 2:00]
                      Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
                      .

                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      c:\documents and settings\Administrateur\Application Data\Icones\icones_pa.ico
                      c:\windows\system32\17422.exe
                      c:\windows\system32\fjhdyfhsn.bat
                      c:\windows\system32\msconfig.exe

                      .
                      ((((((((((((((((((((((((((((( Fichiers créés du 2010-04-09 au 2010-05-09 ))))))))))))))))))))))))))))))))))))
                      .

                      2010-05-09 13:10 . 2010-05-09 13:11 -------- d-----w- c:\program files\ZHPDiag
                      2010-05-08 16:57 . 2010-05-08 16:57 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
                      2010-05-08 16:57 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                      2010-05-08 16:57 . 2010-05-08 16:57 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                      2010-05-08 16:57 . 2010-05-08 16:57 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                      2010-05-08 16:57 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
                      2010-05-08 16:27 . 2010-05-08 16:27 -------- d-----w- c:\windows\LastGood
                      2010-05-08 12:46 . 2009-06-29 08:33 2452872 ------w- c:\windows\system32\dllcache\ieapfltr.dat
                      2010-05-07 13:15 . 2010-05-07 13:15 74752 ------w- c:\windows\system32\eecb.sys
                      2010-05-06 23:45 . 2010-05-06 23:45 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.182\itstv.exe
                      2010-05-05 00:07 . 2010-05-05 00:07 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.180\itstv.exe
                      2010-05-04 01:01 . 2010-05-04 01:01 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.179\itstv.exe
                      2010-05-03 05:01 . 2010-05-03 05:01 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.178\itstv.exe
                      2010-05-01 22:48 . 2010-05-01 22:48 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.177\itstv.exe
                      2010-04-30 22:48 . 2010-04-30 22:48 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.176\itstv.exe
                      2010-04-30 02:48 . 2010-04-30 02:48 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.175\itstv.exe
                      2010-04-29 00:48 . 2010-04-29 00:48 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.174\itstv.exe
                      2010-04-28 00:47 . 2010-04-28 00:47 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.173\itstv.exe
                      2010-04-27 00:47 . 2010-04-27 00:47 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.172\itstv.exe
                      2010-04-26 00:47 . 2010-04-26 00:47 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.171\itstv.exe
                      2010-04-24 22:46 . 2010-04-24 22:46 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.170\itstv.exe
                      2010-04-23 22:00 . 2010-04-23 22:00 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.169\itstv.exe
                      2010-04-23 12:00 . 2010-04-23 12:00 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.168\itstv.exe
                      2010-04-22 16:08 . 2010-04-22 16:08 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.167\itstv.exe
                      2010-04-20 10:26 . 2001-08-23 15:47 99840 ----a-w- c:\windows\system32\srusd.dll
                      2010-04-20 10:26 . 2001-08-23 15:20 6912 ----a-w- c:\windows\system32\drivers\serscan.sys
                      2010-04-20 10:26 . 2001-08-23 15:47 72192 ----a-w- c:\windows\system32\fnfilter.dll
                      2010-04-20 10:24 . 2010-04-20 10:24 -------- d-----w- c:\documents and settings\Administrateur\Application Data\EPSON
                      2010-04-20 02:23 . 2010-04-20 02:23 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.165\itstv.exe
                      2010-04-19 16:48 . 2010-04-19 16:48 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.164\itstv.exe
                      2010-04-17 02:54 . 2010-04-17 02:54 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.162\itstv.exe
                      2010-04-16 02:53 . 2010-04-16 02:53 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.161\itstv.exe
                      2010-04-15 02:58 . 2010-04-15 02:58 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.160\itstv.exe
                      2010-04-14 10:09 . 2010-04-14 10:09 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.159\itstv.exe
                      2010-04-12 23:36 . 2010-04-12 23:36 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.158\itstv.exe
                      2010-04-12 15:36 . 2010-04-12 15:36 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.157\itstv.exe
                      2010-04-11 03:34 . 2010-04-11 03:34 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.156\itstv.exe
                      2010-04-10 07:33 . 2010-04-10 07:33 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.155\itstv.exe

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2010-05-09 14:08 . 2009-12-05 17:19 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Icones
                      2010-05-08 16:35 . 2007-12-18 02:04 83700 ----a-w- c:\windows\system32\perfc00C.dat
                      2010-05-08 16:35 . 2007-12-18 02:04 509008 ----a-w- c:\windows\system32\perfh00C.dat
                      2010-05-07 14:28 . 2010-05-07 14:28 16 ----a-w- c:\windows\system32\config\systemprofile\Application Data\qvjsge.dat
                      2010-05-07 13:13 . 2010-05-07 13:13 16 ----a-w- c:\documents and settings\Administrateur\Application Data\qvjsge.dat
                      2010-04-15 04:58 . 2010-02-23 21:32 -------- d-----w- c:\program files\EoRezo
                      2010-04-09 10:22 . 2010-04-09 10:22 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.154\itstv.exe
                      2010-04-08 03:46 . 2010-04-08 03:46 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.153\itstv.exe
                      2010-04-07 13:45 . 2010-04-07 13:45 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.152\itstv.exe
                      2010-04-05 22:30 . 2010-04-05 22:30 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.151\itstv.exe
                      2010-04-04 22:29 . 2010-04-04 22:29 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.150\itstv.exe
                      2010-04-04 00:29 . 2010-04-04 00:29 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.149\itstv.exe
                      2010-04-03 08:30 . 2010-04-03 08:30 -------- d-----w- c:\program files\SpiderMessenger
                      2010-04-03 00:28 . 2010-04-03 00:28 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.148\itstv.exe
                      2010-04-02 01:05 . 2010-04-02 01:05 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.147\itstv.exe
                      2010-04-01 05:05 . 2010-04-01 05:05 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.146\itstv.exe
                      2010-03-30 22:02 . 2010-03-30 22:02 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.145\itstv.exe
                      2010-03-30 00:07 . 2010-03-30 00:07 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.144\itstv.exe
                      2010-03-29 05:28 . 2010-03-29 05:28 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.143\itstv.exe
                      2010-03-28 01:42 . 2010-03-28 01:42 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.142\itstv.exe
                      2010-03-26 08:50 . 2010-02-24 10:31 670 ----a-w- c:\documents and settings\Administrateur\Application Data\wklnhst.dat
                      2010-03-26 06:34 . 2010-03-26 06:34 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.140\itstv.exe
                      2010-03-25 11:15 . 2010-03-25 11:15 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.139\itstv.exe
                      2010-03-23 15:24 . 2010-03-23 15:24 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.137\itstv.exe
                      2010-03-22 08:45 . 2010-03-22 08:45 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.136\itstv.exe
                      2010-03-20 10:32 . 2010-03-20 10:32 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.134\itstv.exe
                      2010-03-19 00:24 . 2010-03-19 00:24 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.133\itstv.exe
                      2010-03-18 19:42 . 2010-03-18 19:42 10 ----a-w- c:\windows\popcinfo.dat
                      2010-03-18 19:42 . 2009-11-13 13:25 -------- d-----w- c:\program files\Zuma Deluxe
                      2010-03-18 10:15 . 2010-03-18 10:15 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.132\itstv.exe
                      2010-03-17 00:21 . 2010-03-17 00:21 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.131\itstv.exe
                      2010-03-15 23:30 . 2010-03-15 23:30 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.130\itstv.exe
                      2010-03-15 10:10 . 2010-03-15 10:10 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.129\itstv.exe
                      2010-02-27 15:20 . 2009-11-13 12:20 324704 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                      2010-02-27 01:41 . 2010-02-27 01:41 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.116\itstv.exe
                      2010-02-25 23:41 . 2010-02-25 23:41 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.115\itstv.exe
                      2010-02-24 23:30 . 2010-02-24 23:30 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.114\itstv.exe
                      2010-02-24 08:16 . 2009-11-13 13:46 181632 ------w- c:\windows\system32\MpSigStub.exe
                      2010-02-23 23:35 . 2010-02-23 23:35 20480 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\Software\itsTV\3.0.1.113\itstv.exe
                      2010-02-23 21:43 . 2010-02-23 21:33 149787648 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\install.exe
                      2010-02-23 21:32 . 2010-02-23 21:32 698903 ----a-w- c:\documents and settings\Administrateur\Application Data\eoRezo\SoftwareUpdate\unins000.exe
                      2010-02-23 20:41 . 2009-11-13 12:50 1 ----a-w- c:\documents and settings\Administrateur\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
                      .

                      ------- Sigcheck -------

                      [-] 2008-04-14 . F2317622D29F9FF0F88AEECD5F60F0DD . 1037824 . . [6.00.2900.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\explorer.exe
                      [-] 2007-12-18 . ADDC47DFD517F2143D71E9310E414B50 . 1789952 . . [6.00.2900.3156] . . c:\windows\explorer.exe

                      [-] 2008-04-14 . 02DA31AB433A6C1110A736C85701DECA . 13824 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\wscntfy.exe

                      [-] 2008-04-14 . E17C85D5B5CF477638433B851A98499E . 1571840 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\sfcfiles.dll
                      [-] 2007-12-18 . A3D1AC12DEF2E1B391E57C4A63C46F56 . 1548288 . . [5.1.2600.2180] . . c:\windows\system32\sfcfiles.dll

                      [-] 2008-04-14 . 59DC5BB82E4C8E0B3EADCFDBC44BA6E4 . 15360 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\ctfmon.exe
                      [-] 2007-12-18 . 43836CFFABAC8D6779E8EE55E308DF2C . 25088 . . [5.1.2600.2180] . . c:\windows\system32\ctfmon.exe

                      [-] 2008-04-14 . E598D81197E2E0EC42A0C55772BB00E8 . 59904 . . [5.1.2600.5512] . . c:\windows\SoftwareDistribution\Download\327771f7f3830b5acec68906a2aac4ab\regsvc.dll

                      [-] 2007-12-18 02:04 . C51B4A5C05A5475708E3C81C7765B71D . 27136 . . [11.0.5721.5145] . . c:\windows\system32\mspmsnsv.dll

                      c:\windows\System32\drivers\beep.sys ... manque !!
                      c:\windows\System32\wscntfy.exe ... manque !!
                      c:\windows\System32\regsvc.dll ... manque !!
                      .
                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                      REGEDIT4

                      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ADE49752-DBBC-43A3-9498-379A82F574BF}]
                      2010-03-09 09:10 188088 ----a-w- c:\program files\SpiderMessenger\SpiderMessenger.BHO.dll

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
                      "msnmsgr"="c:\progra~1\WI1F86~1\MESSEN~1\msnmsgr.exe" [2009-07-26 3883856]
                      "ccleaner"="c:\program files\CCleaner\CCleaner.exe" [2010-01-26 1724728]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-10-25 8466432]
                      "nwiz"="nwiz.exe" [2007-10-25 1626112]
                      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-10-25 81920]
                      "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2007-01-10 1235456]
                      "UberIcon"="c:\program files\UberIcon\UberIcon Manager.exe" [2006-07-17 122880]
                      "VisualTaskTips"="c:\windows\System32\VisualTaskTips.exe" [2007-12-18 36864]
                      "Vistadrv"="c:\windows\system32\Vistadrive\vsdrv.exe" [2006-07-30 121089]
                      "Styler"="c:\program files\styler\Styler.exe" [2006-05-03 307200]
                      "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
                      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-11-13 149280]
                      "NeroFilterCheck"="c:\program files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
                      "Server Application"="c:\windows\system32\ServoApp.exe" [2008-05-16 417792]
                      "GDI Manager"="c:\program files\MFP Server\App\Common\MFPAgent.exe" [2008-05-16 741376]
                      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
                      "Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
                      "Microsoft Works Update Detection"="c:\program files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2003-06-10 50688]
                      "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-04-29 1090952]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                      "WIAWizardMenu"="c:\windows\system32\sti_ci.dll" [2007-12-18 678912]

                      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                      "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]

                      c:\documents and settings\Administrateur\Menu D'marrer\Programmes\D'marrage\
                      OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-4-16 384000]

                      c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
                      Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]

                      [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
                      "NoSMHelp"= 1 (0x1)

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
                      @="Service"

                      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                      "AntiVirusOverride"=dword:00000001
                      "FirewallOverride"=dword:00000001

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                      "%windir%\\system32\\sessmgr.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                      "14135:UDP"= 14135:UDP:Server Application
                      "14135:TCP"= 14135:TCP:Server Application
                      "13621:UDP"= 13621:UDP:MFP Setup Wizard
                      "13878:UDP"= 13878:UDP:MFP Manager
                      "13364:UDP"= 13364:UDP:MFP Server Manager
                      "69:UDP"= 69:UDP:MFP Server Manager TFTP

                      R0 Si3124;Si3124;c:\windows\system32\drivers\si3124.sys [18/12/2007 04:04 76208]
                      R0 Si3531;Si3531;c:\windows\system32\drivers\Si3531.sys [18/12/2007 04:04 210224]
                      R1 eecb;eecb;c:\windows\system32\eecb.sys [07/05/2010 15:15 74752]
                      R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 20:19 13592]
                      R3 WUSBVBus;MFP Server Detector;c:\windows\system32\drivers\mfpvbus.sys [01/12/2009 11:36 10240]
                      S2 ALIWEHCD;MFP Server Enhanced Controller;c:\windows\system32\drivers\mfpec.sys [01/12/2009 11:36 34944]

                      --- Autres Services/Pilotes en mémoire ---

                      *Deregistered* - Secdrv
                      .
                      Contenu du dossier 'Tâches planifiées'

                      2010-05-09 c:\windows\Tasks\MP Scheduled Scan.job
                      - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
                      .
                      .
                      ------- Examen supplémentaire -------
                      .
                      uStart Page = hxxp://y.lo.st
                      uDefault_Search_URL = hxxp://www.google.fr/keyword/%s
                      mStart Page = hxxp://www.duxot.com/
                      uSearchURL,(Default) = hxxp://www.google.fr/keyword/%s
                      .
                      - - - - ORPHELINS SUPPRIMES - - - -

                      Toolbar-SaveLinksOrder - (no file)
                      Toolbar-Locked - (no file)
                      Toolbar-ITBarLayout - (no file)
                      Toolbar-ITBarLayout - (no file)
                      Toolbar-ITBar7Layout - (no file)
                      Toolbar-ITBar7Position - (no file)
                      HKLM-Run-CmPCIaudio - CMICNFG3.cpl

                      **************************************************************************

                      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2010-05-09 16:09
                      Windows 5.1.2600 Service Pack 2 NTFS

                      Recherche de processus cachés ...

                      Recherche d'éléments en démarrage automatique cachés ...

                      Recherche de fichiers cachés ...

                      Scan terminé avec succès
                      Fichiers cachés: 0

                      **************************************************************************
                      .
                      --------------------- DLLs chargées dans les processus actifs ---------------------

                      - - - - - - - > 'winlogon.exe'(808)
                      c:\windows\system32\SETUPAPI.dll
                      c:\windows\system32\sfc_os.dll
                      c:\windows\system32\cscui.dll

                      - - - - - - - > 'lsass.exe'(960)
                      c:\windows\system32\SETUPAPI.dll
                      .
                      Heure de fin: 2010-05-09 16:12:07
                      ComboFix-quarantined-files.txt 2010-05-09 14:11

                      Avant-CF: 10 094 903 296 octets libres
                      Après-CF: 10 106 728 448 octets libres

                      WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
                      [boot loader]
                      timeout=2
                      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                      [operating systems]
                      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect

                      - - End Of File - - 7FE5CE5335C15979EF87B80048DD2901
                      0
                      1. Contributeur sécurité
                        Salut titi40240

                        Bon pas jolie tout ça, fichier système probablement patché (modifié) et fichier système manquant.

                        Ton Windows est-il légal?
                        As-tu un CD de Windows XP?

                        Télécharge Gmer et enregistre-le sur ton bureau.
                        http://www2.gmer.net/download.php

                        - Déconnecte toi d'internet si possible et ferme tous les programmes, puis lance l'outil.
                        - Clique sur le bouton "Scan" sur la droite.

                        - Lorsque le scan est terminé, clic sur "Copy".
                        - Ouvre le bloc-note et clic sur le Menu Edition / Coller
                        - Le rapport doit alors apparaître.

                        - Enregistre le fichier sur ton bureau et copie/colle le contenu ici.

                        @++ :)
                        0
                        1. En fait ce n'est pas mon ordinateur et oui son Windows Xp est un téléchargé. Je vais faire ce que tu me dis.
                          0
                          1. Voilà le rapport :

                            GMER 1.0.15.15281 - http://www.gmer.net
                            Autostart scan 2010-05-09 17:08:59
                            Windows 5.1.2600 Service Pack 2

                            HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

                            HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,

                            HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
                            dimsntfy@DLLName = %SystemRoot%\System32\dimsntfy.dll /*file not found*/
                            WgaLogon@DLLName = WgaLogon.dll

                            HKLM\SYSTEM\CurrentControlSet\Services\ >>>
                            Fax@ = %systemroot%\system32\fxssvc.exe
                            ImapiService@ = %systemroot%\system32\imapi.exe /*file not found*/
                            JavaQuickStarterService@ = "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
                            WinDefend@ = "C:\Program Files\Windows Defender\MsMpEng.exe"

                            HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
                            @NvCplDaemonRUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup = RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                            @nwiznwiz.exe /install = nwiz.exe /install
                            @NvMediaCenterRUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit = RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                            @SidebarC:\Program Files\Windows Sidebar\sidebar.exe /autoRun /*file not found*/ = C:\Program Files\Windows Sidebar\sidebar.exe /autoRun /*file not found*/
                            @UberIcon"C:\Program Files\UberIcon\UberIcon Manager.exe" = "C:\Program Files\UberIcon\UberIcon Manager.exe"
                            @VisualTaskTipsC:\Windows\System32\VisualTaskTips.exe = C:\Windows\System32\VisualTaskTips.exe
                            @VistadrvC:\WINDOWS\system32\Vistadrive\vsdrv.exe = C:\WINDOWS\system32\Vistadrive\vsdrv.exe
                            @StylerC:\Program Files\styler\Styler.exe = C:\Program Files\styler\Styler.exe
                            @Windows Defender"C:\Program Files\Windows Defender\MSASCui.exe" -hide = "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                            @SunJavaUpdateSched"C:\Program Files\Java\jre6\bin\jusched.exe" = "C:\Program Files\Java\jre6\bin\jusched.exe"
                            @NeroFilterCheckC:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe = C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                            @Server ApplicationC:\WINDOWS\system32\ServoApp.exe = C:\WINDOWS\system32\ServoApp.exe
                            @GDI Manager"C:\Program Files\MFP Server\App\Common\MFPAgent.exe" = "C:\Program Files\MFP Server\App\Common\MFPAgent.exe"
                            @Adobe Reader Speed Launcher"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                            @Adobe ARM"C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" = "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
                            @Microsoft Works Update DetectionC:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe = C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
                            RunOnce@WIAWizardMenu = RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu

                            HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
                            @IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 = "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                            @msnmsgr"C:\PROGRA~1\WI1F86~1\MESSEN~1\msnmsgr.exe" /background = "C:\PROGRA~1\WI1F86~1\MESSEN~1\msnmsgr.exe" /background
                            @ccleaner"C:\Program Files\CCleaner\CCleaner.exe" /AUTO = "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                            @ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe

                            HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad@WPDShServiceObj = C:\WINDOWS\system32\wpdshserviceobj.dll

                            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks >>>
                            @{091EB208-39DD-417D-A5DD-7E2C2D8FB9CB}C:\PROGRA~1\WIFD1F~1\MpShHook.dll = C:\PROGRA~1\WIFD1F~1\MpShHook.dll
                            @{AEB6717E-7E19-11d0-97EE-00C04FD91972}(null) =

                            HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
                            @{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Extension Affichage Panorama du Panneau de configuration*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
                            @{A70C977A-BF00-412C-90B7-034C51DA2439} /*NvCpl DesktopContext Class*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
                            @{FFB699E0-306A-11d3-8BD1-00104B6F7516} /*Play on my TV helper*/C:\WINDOWS\system32\nvcpl.dll = C:\WINDOWS\system32\nvcpl.dll
                            @{1CDB2949-8F65-4355-8456-263E7C208A5D} /*Desktop Explorer*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
                            @{1E9B04FB-F9E5-4718-997B-B8DA88302A47} /*Desktop Explorer Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
                            @{1E9B04FB-F9E5-4718-997B-B8DA88302A48} /*nView Desktop Context Menu*/C:\WINDOWS\system32\nvshell.dll = C:\WINDOWS\system32\nvshell.dll
                            @{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
                            @{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
                            @{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Page de propriétés des versions précédentes*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
                            @{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versions précédentes*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
                            @{87D62D94-71B3-4b9a-9489-5FE6850DC73E} /*Avi Properties Handler*/(null) =
                            @{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
                            @{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
                            @{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
                            @{08AB18D7-ACFB-4B59-93BA-81BBEE32D401} /*Xentient.Thumbs*/C:\Windows\System32\thumbs.dll = C:\Windows\System32\thumbs.dll
                            @{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Program Files\WinRAR\rarext.dll = C:\Program Files\WinRAR\rarext.dll
                            @{B327765E-D724-4347-8B16-78AE18552FC3} /*NeroDigitalIconHandler*/C:\Program Files\Fichiers communs\Nero\Lib\NeroDigitalExt.dll = C:\Program Files\Fichiers communs\Nero\Lib\NeroDigitalExt.dll
                            @{7F1CF152-04F8-453A-B34C-E609530A9DC8} /*NeroDigitalPropSheetHandler*/C:\Program Files\Fichiers communs\Nero\Lib\NeroDigitalExt.dll = C:\Program Files\Fichiers communs\Nero\Lib\NeroDigitalExt.dll
                            @{0563DB41-F538-4B37-A92D-4659049B7766} /*WLMD Message Handler*/C:\Program Files\Windows Live\Mail\mailcomm.dll = C:\Program Files\Windows Live\Mail\mailcomm.dll
                            @{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
                            @{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
                            @{45670FA8-ED97-4F44-BC93-305082590BFB} /*Microsoft.XPS.Shell.Metadata.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
                            @{44121072-A222-48f2-A58A-6D9AD51EBBE9} /*Microsoft.XPS.Shell.Thumbnail.1*/%SystemRoot%\System32\XPSSHHDR.DLL = %SystemRoot%\System32\XPSSHHDR.DLL
                            @{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} /*OpenOffice.org Column Handler*/"C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll"
                            @{087B3AE3-E237-4467-B8DB-5A38AB959AC9} /*OpenOffice.org Infotip Handler*/"C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll"
                            @{63542C48-9552-494A-84F7-73AA6A7C99C1} /*OpenOffice.org Property Sheet Handler*/"C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll"
                            @{3B092F0C-7696-40E3-A80F-68D74DA84210} /*OpenOffice.org Thumbnail Viewer*/"C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll" = "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll"
                            @{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Dossiers Web*/C:\PROGRA~1\FICHIE~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = C:\PROGRA~1\FICHIE~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
                            @{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\Office10\msohev.dll = C:\Program Files\Microsoft Office\Office10\msohev.dll

                            HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
                            EPPShellEx@{509FE1AF-ADD5-49EC-BC55-7CF81FD16E78} = C:\Program Files\EPSON\Creativity Suite\Easy Photo Print\EPPShell.dll
                            WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

                            HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

                            HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
                            MBAMShlExt@{57CE581A-0CB6-4266-9CA0-19364C90A0B3} = C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
                            WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll

                            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
                            @{18DF081C-E8AD-4283-A596-FA578C2EBDC3}C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll = C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                            @{9030D464-4C02-4ABF-8ECC-5164760863C6}C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll = C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            @{ADE49752-DBBC-43A3-9498-379A82F574BF}C:\Program Files\SpiderMessenger\SpiderMessenger.BHO.dll = C:\Program Files\SpiderMessenger\SpiderMessenger.BHO.dll
                            @{DBC80044-A445-435b-BC74-9C25C1C588A9}C:\Program Files\Java\jre6\bin\jp2ssv.dll = C:\Program Files\Java\jre6\bin\jp2ssv.dll
                            @{E7E6F031-17CE-4C07-BC86-EABFE594F69C}C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll = C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                            @{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll = C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll

                            HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\system32\bubbles.scr

                            HKLM\Software\Microsoft\Internet Explorer\Main >>>
                            @Default_Page_URLhttps://www.msn.com/fr-fr/?ocid=iehp = https://www.msn.com/fr-fr/?ocid=iehp
                            @Start Pagehttp://www.duxot.com/ = http://www.duxot.com/
                            @Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

                            HKCU\Software\Microsoft\Internet Explorer\Main >>>
                            @Start Pagehttp://y.lo.st = http://y.lo.st
                            @Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm

                            HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
                            cdo@CLSID = C:\Program Files\Fichiers communs\Microsoft Shared\Web Folders\PKMCDO.DLL
                            dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
                            its@CLSID = C:\WINDOWS\system32\itss.dll
                            livecall@CLSID = C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                            mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
                            ms-its@CLSID = C:\WINDOWS\system32\itss.dll
                            ms-itss@CLSID = C:\Program Files\Fichiers communs\Microsoft Shared\Information Retrieval\msitss.dll
                            msnim@CLSID = C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
                            tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
                            wia@CLSID = C:\WINDOWS\system32\wiascr.dll

                            HKLM\Software\Classes\PROTOCOLS\Handler\wlmailhtml@CLSID = C:\Program Files\Windows Live\Mail\mailcomm.dll

                            C:\Documents and Settings\Administrateur\Menu Démarrer\Programmes\Démarrage = OpenOffice.org 3.1.lnk

                            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage = Microsoft Office.lnk

                            ---- EOF - GMER 1.0.15 ----
                            0
                            1. Répondez-moi s'il vous plaît.
                              0
                              1. S'il vous plaît répondez-moi !
                                0
                                1. Contributeur sécurité
                                  bonjour, soit patient c'est le week end et il fait beau dédétraqué que je salut en passant est surement partie prendre l'aire , il va revenir !!

                                  sinon la tu dis que ta version de windows n'est pas une version légal dans ce cas ne soit pas surpris d'avoir des problème , perso j'estime que quand on est assé grand pour jouer avec des choses comme celle-ci on devrait savoir se sortir de la merd.. tout seul , la solution tu formates et tu réinstalles ton windows piraté !!! lol !!
                                  0
                              2. Contributeur sécurité
                                Salut titi40240

                                C'est pas le bon rapport, tu as bien télécharger la version que je t'ai donner?

                                @++ :)

                                P.S. - Merci de resté patient et de ne plus remonter le poste
                                0
                                • 1
                                • 2