Détection d'un virus - Page 2

Résolu
  1. Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Version de la base de données: 4447

    Windows 6.0.6002 Service Pack 2
    Internet Explorer 8.0.6001.18943

    2010-08-18 20:06:17
    mbam-log-2010-08-18 (20-06-17).txt

    Type d'examen: Examen rapide
    Elément(s) analysé(s): 145623
    Temps écoulé: 5 minute(s), 46 seconde(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
    1. DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)

      Télécharge List_Kill'em et enregistre le sur ton bureau

      http://sd-1.archive-host.com/...

      double clique ( clic droit "executer en tant qu'administrateur" pour Vista/7 ) sur le raccourci sur ton bureau pour lancer l'installation

      une fois terminée , clic sur "terminer" et le programme se lancera seul

      choisis choisis l'option Search

      un icone blanc et noir va s'afficher sur le bureau , il te servira à rappeler le programme si besoin.

      laisse travailler l'outil

      à l'apparition de la fenetre blanche , c'est un peu long , c'est normal , le programme n'est pas bloqué.

      un rapport du nom de catchme apparait sur ton bureau , ignore-le,ne le poste pas , , il s'auto supprimera a la fin du scan

      Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"
      0
      1. ¤¤¤¤¤¤¤¤¤¤ List'em by g3n-h@ckm@n 2.0.0.4 ¤¤¤¤¤¤¤¤¤¤

        User : Franky (Administrateurs)
        Update on 23/05/2010 by g3n-h@ckm@n ::::: 15.00
        Start at: 06:43:42 | 2010-08-19

        Intel(R) Pentium(R) Dual CPU E2180 @ 2.00GHz
        Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-bit) # Service Pack 2
        Internet Explorer 8.0.6001.18943
        Windows Firewall Status : Disabled
        AV : avast! antivirus 4.8.1356 [VPS 091010-0] 4.8.1356 [ Enabled | Updated ]

        C:\ -> Disque fixe local | 97,66 Go (57,85 Go free) | NTFS
        D:\ -> Disque fixe local | 51,39 Go (37,74 Go free) | NTFS
        E:\ -> Disque CD-ROM | 4,05 Go (0 Mo free) [MyDisc] | CDFS

        Boot: Normal
        ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
        C:\Program Files\CDBurnerXP\NMSAccessU.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
        C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
        C:\Program Files\Common Files\Java\Java Update\jusched.exe
        C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Free Download Manager\fdm.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Windows\system32\rundll32.exe
        C:\Windows\system32\FirewallControlPanel.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\List_Kill'em\List_Kill'em.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\cmd.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Program Files\List_Kill'em\pv.exe

        ======================
        Keys "Run"
        ======================

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        Sidebar REG_SZ C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        Free Download Manager REG_SZ C:\Program Files\Free Download Manager\fdm.exe -autorun
        MsnMsgr REG_SZ "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        Windows Defender REG_EXPAND_SZ %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        avast! REG_SZ C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        RtHDVCpl REG_SZ C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s
        IgfxTray REG_SZ C:\Windows\system32\igfxtray.exe
        HotKeysCmds REG_SZ C:\Windows\system32\hkcmd.exe
        Persistence REG_SZ C:\Windows\system32\igfxpers.exe
        SunJavaUpdateSched REG_SZ "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
        ArcSoft Connection Service REG_SZ C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
        Adobe Reader Speed Launcher REG_SZ "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        Adobe ARM REG_SZ "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
        QuickTime Task REG_SZ "C:\Program Files\QuickTime\QTTask.exe" -atboottime

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
        Malwarebytes' Anti-Malware REG_SZ C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent

        =====================
        Other Keys
        =====================

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
        ConsentPromptBehaviorAdmin REG_DWORD 2 (0x2)
        ConsentPromptBehaviorUser REG_DWORD 1 (0x1)
        EnableInstallerDetection REG_DWORD 1 (0x1)
        EnableLUA REG_DWORD 1 (0x1)
        EnableSecureUIAPaths REG_DWORD 1 (0x1)
        EnableVirtualization REG_DWORD 1 (0x1)
        PromptOnSecureDesktop REG_DWORD 1 (0x1)
        ValidateAdminCodeSignatures REG_DWORD 0 (0x0)
        dontdisplaylastusername REG_DWORD 0 (0x0)
        scforceoption REG_DWORD 0 (0x0)
        shutdownwithoutlogon REG_DWORD 1 (0x1)
        undockwithoutlogon REG_DWORD 1 (0x1)
        FilterAdministratorToken REG_DWORD 0 (0x0)
        LegalNoticeText REG_SZ
        LegalNoticeCaption REG_SZ
        EnableUIADesktopToggle REG_DWORD 0 (0x0)

        ===============

        [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]

        ===============

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
        BindDirectlyToPropertySetStorage REG_DWORD 0 (0x0)

        ===============

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
        AppInit_DLLS REG_SZ

        ===============

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
        ReportBootOk REG_SZ 1
        Shell REG_SZ explorer.exe
        Userinit REG_SZ C:\Windows\system32\userinit.exe,
        VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
        AutoRestartShell REG_DWORD 1 (0x1)
        PowerdownAfterShutdown REG_SZ 0
        ShutdownWithoutLogon REG_SZ 0
        cachedlogonscount REG_SZ 10
        forceunlocklogon REG_DWORD 0 (0x0)
        passwordexpirywarning REG_DWORD 14 (0xe)
        Background REG_SZ 0 0 0
        DebugServerCommand REG_SZ no
        WinStationsDisabled REG_SZ 0
        DisableCAD REG_DWORD 1 (0x1)
        scremoveoption REG_SZ 0
        ShutdownFlags REG_DWORD 39 (0x27)
        AutoAdminLogon REG_SZ 0
        allocatecdroms REG_SZ 0
        DefaultUserName REG_SZ franky
        LegalNoticeText REG_SZ
        LegalNoticeCaption REG_SZ

        ===============

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\igfxcui]

        ===============

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]

        ===============

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
        C:\Program Files\Orbitdownloader\orbitdm.exe REG_SZ C:\Program Files\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit
        C:\Program Files\Orbitdownloader\orbitnet.exe REG_SZ C:\Program Files\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit

        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

        ===============
        ActivX controls
        ===============

        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{166B1BCA-3F9C-11CF-8075-444553540000}]
        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
        [HKEY_LOCAL_MACHINE\software\microsoft\code store database\distribution units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}]
        0
        1. ===============
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{26923b43-4d38-484f-9b9e-de460746276c}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{2C7339CF-2B09-4501-B3F3-F3508C9228ED}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3af36230-a269-11d1-b5bf-0000f8051515}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{3C3901C5-3455-3E0A-A214-0B093A5070A6}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA840-CC51-11CF-AAFA-00AA00B6015C}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA848-CC51-11CF-AAFA-00AA00B6015C}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{44BBA855-CC51-11CF-AAFA-00AA00B6015F}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{45ea75a0-a269-11d1-b5bf-0000f8051515}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{4f645220-306d-11d2-995d-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{5fd399c0-a70a-11d1-9948-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{630b1da0-b465-11d1-9948-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6fab99d0-bab8-11d1-994a-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{72E7D204-8696-A6C4-3A14-DB4CB97F7A0A}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7790769C-0471-11d2-AF11-00C04FA35D02}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7C028AF8-F614-47B3-82DA-BA94E41B1089}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4340}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89820200-ECBD-11cf-8B85-00AA005B4383}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{89B4C1CD-B018-4511-B0A1-5476DBF70820}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{9381D8F2-0288-11D0-9501-00AA00B911A5}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C6BAF60B-6E91-453F-BFF9-D3789CFEFCDD}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{C9E9A340-D1F1-11D0-821E-444553540600}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{CDD7975E-60F8-41d5-8149-19E51D6F71D0}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{D27CDB6E-AE6D-11CF-96B8-444553540000}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{de5aed00-a4bf-11d1-9948-00c04f98bbc9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{E92B03AB-B707-11d2-9CBD-0000F87A369E}]

          ==============
          BHO :
          ======

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{4f3ed5cd-0726-42a9-87f5-d13f3d2976ac}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]

          ===
          DNS
          ===

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{0769241C-5845-4C26-BA99-262F6BEA3D2B}: DhcpNameServer=205.151.67.2 205.151.67.6
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{0769241C-5845-4C26-BA99-262F6BEA3D2B}: DhcpNameServer=205.151.67.2 205.151.67.6
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{0769241C-5845-4C26-BA99-262F6BEA3D2B}: DhcpNameServer=205.151.67.2 205.151.67.6
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=205.151.67.2 205.151.67.6
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=205.151.67.2 205.151.67.6
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=205.151.67.2 205.151.67.6

          ================
          Internet Explorer :
          ================

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          Start Page REG_SZ https://www.msn.com/fr-fr
          Local Page REG_SZ C:\Windows\System32\blank.htm
          Default_Search_URL REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
          Default_Page_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          Start Page REG_SZ https://www.msn.com/fr-fr
          Local Page REG_SZ C:\Windows\system32\blank.htm

          ========
          Services
          ========

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services]

          Ndisuio : 0x3 ( OK = 3 )
          EapHost : 0x3 ( OK = 2 )
          Wlansvc : 0x2 ( OK = 2 )
          SharedAccess : 0x3 ( OK = 2 )
          windefend : 0x2 ( OK = 2 )
          wuauserv : 0x2 ( OK = 2 )
          wscsvc : 0x2 ( OK = 2 )
          0
          1. ========
            Safemode
            ========

            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot : OK !!
            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal : OK !!
            HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network : OK !!

            =========
            Atapi.sys
            =========

            C:\Windows\System32\drivers\atapi.sys :
            MD5 :: [1f05b78ab91c9075565a9d8a4b880bc4]
            SHA256 :: [737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd]

            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_7de13c21\atapi.sys :
            MD5 :: [b35cfcef838382ab6490b321c87edf17]
            SHA256 :: [a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0]

            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_b12d8e84\atapi.sys :
            MD5 :: [1f05b78ab91c9075565a9d8a4b880bc4]
            SHA256 :: [737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd]

            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys :
            MD5 :: [4f4fcb8b6ea06784fb6d475b7ec7300f]
            SHA256 :: [6202d85c9a75e3f01f5f94f069c4cd8a2b9295a182301eae5940ec3bc2c1d896]

            C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys :
            MD5 :: [2d9c903dc76a66813d350a562de40ed9]
            SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16632_none_db337a442479c42c\atapi.sys :
            MD5 :: [b35cfcef838382ab6490b321c87edf17]
            SHA256 :: [a13985b87b5918d123072c7128e12dc28b0fcfd68383afa6e1da72a25bd781e0]

            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20757_none_dbac78a93da31a8b\atapi.sys :
            MD5 :: [e03e8c99d15d0381e02743c36afc7c6f]
            SHA256 :: [8217348674fc4d0c6d567ffc95b14dfd507f47c5a4728c2ba93d72c412e8527b]

            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys :
            MD5 :: [2d9c903dc76a66813d350a562de40ed9]
            SHA256 :: [82609f01a08c6842e4c17c077bb641c1429c0e6657964b7f2d114035e1bdcbf3]

            C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_df23a1261eab99e8\atapi.sys :
            MD5 :: [1f05b78ab91c9075565a9d8a4b880bc4]
            SHA256 :: [737be9f9376dab0ccdfed93ea6d67f0c432367ea63cd772a453485be769af3bd]

            Référence :
            ==========

            Win 2000_SP2 : ff953a8f08ca3f822127654375786bbe
            Win 2000_SP4 : 8c718aa8c77041b3285d55a0ce980867
            Win XP_32b : a64013e98426e1877cb653685c5c0009
            Win XP_SP2_32b : CDFE4411A69C224BD1D11B2DA92DAC51
            Win XP_SP3_32b : 9F3A2F5AA6875C72BF062C712CFA2674
            Vista_32b : e03e8c99d15d0381e02743c36afc7c6f
            Vista_SP1_32b : 2d9c903dc76a66813d350a562de40ed9
            Vista_SP2_32b : 1F05B78AB91C9075565A9D8A4B880BC4
            Vista_SP2_64b : 1898FAE8E07D97F2F6C2D5326C633FAC
            Windows 7_32b : 80C40F7FDFC376E4C5FEEC28B41C119E
            Windows 7_64b : 02062C0B390B7729EDC9E69C680A6F3C
            Windows 7_32b_Ultimate : 338c86357871c167a96ab976519bf59e

            =======
            Drive :
            =======

            D'fragmenteur de disque Windows
            Copyright (c) 2006 Microsoft Corp.

            Rapport d'analyse pour le volume C:

            Taille du volume = 97.66 Go
            Espace libre = 57.87 Go
            tendue d'espace libre la plus grande = 13.46 Go
            Pourcentage de fragmentation des fichiers = 1 %

            Remarqueÿ: sur les volumes NTFS, les fragments de fichiers de plus de 64ÿMo ne sont pas inclus dans les statistiques de fragmentation.

            Il n'est pas n'cessaire de d'fragmenter ce volume.

            ¤¤¤¤¤¤¤¤¤¤ Files/folders :

            Present !! : C:\ProgramData\xml91D3.tmp
            Present !! : C:\ProgramData\xml952E.tmp
            Present !! : C:\ProgramData\xml9667.tmp
            Present !! : C:\ProgramData\xml987B.tmp
            Present !! : C:\ProgramData\Application Data\.zreglib
            Present !! : C:\ProgramData\xml91D3.tmp
            Present !! : C:\ProgramData\xml952E.tmp
            Present !! : C:\ProgramData\xml9667.tmp
            Present !! : C:\ProgramData\xml987B.tmp
            Present !! : C:\ProgramData\xml91D3.tmp
            Present !! : C:\ProgramData\xml952E.tmp
            Present !! : C:\ProgramData\xml9667.tmp
            Present !! : C:\ProgramData\xml987B.tmp
            Present !! : C:\ProgramData\xml91D3.tmp
            Present !! : C:\ProgramData\xml952E.tmp
            Present !! : C:\ProgramData\xml9667.tmp
            Present !! : C:\ProgramData\xml987B.tmp
            Present !! : C:\ProgramData\xml91D3.tmp
            Present !! : C:\ProgramData\xml952E.tmp
            Present !! : C:\ProgramData\xml9667.tmp
            Present !! : C:\ProgramData\xml987B.tmp
            Present !! : C:\ProgramData\.zreglib
            Present !! : C:\Windows\System32\x64
            Present !! : C:\Users\Franky\AppData\Local\d3d8caps.dat
            Present !! : C:\Users\Franky\AppData\Local\d3d9caps.dat
            Present !! : C:\Users\Franky\AppData\Local\GDIPFONTCACHEV1.DAT
            Present !! : C:\Users\Franky\Application Data\Skinux

            ¤¤¤¤¤¤¤¤¤¤ Keys :

            Present !! : "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}"
            Present !! : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
            Present !! : HKLM\Software\Classes\CLSID\{9AFB8248-617F-460D-9366-D71CDEDA3179}

            ============

            catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2010-08-19 06:55:59
            Windows 6.0.6002 Service Pack 2 FAT NTAPI

            scanning hidden processes ...

            [0] 0x0000F3E9

            scanning hidden services ...

            scanning hidden autostart entries ...

            scanning hidden files ...

            scan completed successfully
            hidden processes: 1
            hidden services: 0
            hidden files: 0

            Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

            device: opened successfully
            user: MBR read successfully
            called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll intelide.sys PCIIDEX.SYS atapi.sys
            kernel: MBR read successfully
            user & kernel MBR OK

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
            cval REG_DWORD 1 (0x1)

            ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

            End of scan : 6:56:00,38
            0
            1. Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
              mais cette fois-ci :

              choisis l'option clean
              ton PC va redemarrer,

              laisse travailler l'outil.

              en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

              colle le contenu dans ta reponse
              0
              1. ¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.0.0.4 ¤¤¤¤¤¤¤¤¤¤

                User : Franky (Administrateurs)
                Update on 23/05/2010 by g3n-h@ckm@n ::::: 15.00
                Start at: 16:23:57 | 2010-08-19

                Intel(R) Pentium(R) Dual CPU E2180 @ 2.00GHz
                Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-bit) # Service Pack 2
                Internet Explorer 8.0.6001.18943
                Windows Firewall Status : Disabled
                AV : avast! antivirus 4.8.1356 [VPS 091010-0] 4.8.1356 [ Enabled | Updated ]

                C:\ -> Disque fixe local | 97,66 Go (57,96 Go free) | NTFS
                D:\ -> Disque fixe local | 51,39 Go (37,74 Go free) | NTFS
                E:\ -> Disque CD-ROM | 4,05 Go (0 Mo free) [MyDisc] | CDFS

                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes running

                C:\Windows\System32\smss.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\wininit.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\services.exe
                C:\Windows\system32\lsass.exe
                C:\Windows\system32\lsm.exe
                C:\Windows\system32\winlogon.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\SLsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\System32\spoolsv.exe
                C:\Windows\system32\taskeng.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\Explorer.EXE
                C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                C:\Program Files\CDBurnerXP\NMSAccessU.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\SearchIndexer.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\Windows\system32\runonce.exe
                C:\Windows\system32\cmd.exe
                C:\Windows\system32\conime.exe
                C:\Windows\system32\wbem\wmiprvse.exe
                C:\Program Files\List_Kill'em\ERUNT.EXE
                C:\Program Files\List_Kill'em\pv.exe

                ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                Quarantined & Deleted !! : C:\ProgramData\xml91D3.tmp
                Quarantined & Deleted !! : C:\ProgramData\xml952E.tmp
                Quarantined & Deleted !! : C:\ProgramData\xml9667.tmp
                Quarantined & Deleted !! : C:\ProgramData\xml987B.tmp
                Quarantined & Deleted !! : C:\ProgramData\Application Data\.zreglib

                Quarantined & Deleted !! : C:\Windows\System32\x64
                Quarantined & Deleted !! : C:\Users\Franky\AppData\Local\d3d8caps.dat
                Quarantined & Deleted !! : C:\Users\Franky\AppData\Local\d3d9caps.dat
                Quarantined & Deleted !! : C:\Users\Franky\AppData\Local\GDIPFONTCACHEV1.DAT
                Quarantined & Deleted !! : C:\Users\Franky\Application Data\Skinux
                Deleted !! : C:\$Recycle.bin\S-1-5-21-2356678355-4250095907-2822896115-1001\$I0YG1KY.lnk
                Deleted !! : C:\$Recycle.bin\S-1-5-21-2356678355-4250095907-2822896115-1001\$I7FKU5E.lnk
                Deleted !! : C:\$Recycle.bin\S-1-5-21-2356678355-4250095907-2822896115-1001\$INUYLFZ.lnk
                Deleted !! : C:\$Recycle.bin\S-1-5-21-2356678355-4250095907-2822896115-1001\$R0YG1KY.lnk
                Deleted !! : C:\$Recycle.bin\S-1-5-21-2356678355-4250095907-2822896115-1001\$R7FKU5E.lnk
                Deleted !! : C:\$Recycle.bin\S-1-5-21-2356678355-4250095907-2822896115-1001\$RNUYLFZ.lnk

                =======
                Hosts :
                =======

                127.0.0.1 localhost

                ========
                Registry
                ========

                Deleted : "HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}"
                Deleted : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
                =================
                Internet Explorer
                =================

                [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                Start Page REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                Default_Search_URL REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                Default_Page_URL REG_SZ https://www.msn.com/fr-fr/?ocid=iehp
                Search Page REG_SZ https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                Start Page REG_SZ https://www.google.com/?gws_rd=ssl
                Local Page REG_SZ C:\WINDOWS\system32\blank.htm
                Search Page REG_SZ http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                ===============
                Security Center
                ===============

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                cval REG_DWORD 1 (0x1)
                FirstRunDisabled REG_DWORD 1 (0x1)
                AntiVirusDisableNotify REG_DWORD 0 (0x0)
                FirewallDisableNotify REG_DWORD 0 (0x0)
                UpdatesDisableNotify REG_DWORD 0 (0x0)
                AntiVirusOverride REG_DWORD 1 (0x1)
                FirewallOverride REG_DWORD 1 (0x1)

                ========
                Services
                =========

                Ndisuio : Start = 3
                EapHost : Start = 2
                Wlansvc : Start = 2
                SharedAccess : Start = 2
                windefend : Start = 2
                wuauserv : Start = 2
                wscsvc : Start = 2

                ============
                Disk Cleaned
                anti-ver blaster : OK
                Prefetch cleaned
                ================

                Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                device: opened successfully
                user: MBR read successfully
                called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll intelide.sys PCIIDEX.SYS atapi.sys
                kernel: MBR read successfully
                user & kernel MBR OK

                ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤( EOF )¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                0
                1. il semble aller bien
                  maintenant que je n'ai plus de ccleaner et de spybot ... existe t-il d'autre logiciel pour faire le travail ou je répète ses étapes une fois de temps en temps?
                  0
                  1. "j'ai ccleaner et spybot and destroy et un ad-adware mais c tout je connais pas d'autres facon de vérifier l'ordi"

                    Quand tu as dis cela, je me suis trompé ds ma réponse !!!

                    Ccleaner est à garder...Ce sont les 2 autres qui sont à virer...

                    Utilises Malwarebytes régulièrement en le mettant à jour à chaque utilisation.

                    Pour desinstaller les outils utilisés

                    Télécharge OTCleanIt sur ton Bureau: http://www.geekstogo.com/forum/files/file/403-otc-oldtimers-clean-it/

                    Lance OTCleanIt avec un double-clic (sous Vista, lance-le en cliquant droit sur OTCleanIt.exe et en sélectionnant "exécuter en tant qu'administrateur")

                    Appuie sur le bouton "CleanUp!"

                    A la question "begin cleanup process?", réponds "YES"

                    A la fin de l'opération, si OTCleanIt demande de redémarrer ("Do you want to reboot now?"), ferme ce que tu es en train de faire (internet, documents divers...) et clique sur "YES":

                    Au redémarrage, OTCleanIt aura supprimé les outils de désinfection, et se sera même autodétruit!

                    puis

                    ---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
                    https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

                    * Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
                    * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
                    * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse(Sauvegarde la base de registre).
                    * Décoche la case plus vieux que 24 h

                    TRES IMPORTANT:

                    ---> Il est nécessaire de désactiver,redémarrer puis réactiver la restauration système pour la purger :
                    XP:
                    http://service1.symantec.com/support/inter/tsgeninfointl.Nsf/fr_docid/20020830101856924
                    VISTA:
                    https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista

                    ---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
                    https://www.vulgarisation-informatique.com/creer-point-restauration.php

                    ---> Changes le statut de ce topic :
                    et mets le en "résolu"
                    https://www.commentcamarche.net/infos/25917-forum-ccm-mode-d-emploi-marquer-mon-sujet-comme-resolu/

                    a+
                    0
                    1. merci grandement pour ton aide !!!

                      enfin un ordi propre :-)
                      0
                      Précédent
                      • 1
                      • 2