Aide pour enlever Bamital-AE ?

Résolu
Bonjour,

mon ordi est infecté par Bamital-AE. J'ai fait tourner AVAST qui m'indique que les 2 fichiers windows explorer.exe et winlogon.exe sont infectés et impossible à réparer (fichiers en lecture seule mais si je suis en mode admin).
Et impossible de remettre la main sur le CD windows.

Un scan complet avec Malrewabyte ne détecte aucune infection.

A lire les différents post, j'ai l'impression que la manip pour se débarasser de ce virus est assez complexe et à chaque fois différente.

Merci d'avance pour votre aide.

22 réponses

  1. Bonjour

    On va faire une analyse de ton systéme.

    * Télécharge ftp://zebulon.fr/ZHPDiag.exe ZHPDiag ( de Nicolas coolman ).
    ou
    http://www.premiumorange.com/zeb-help-process/zhpdiag.html (En bas de page).

    ***********************
    /!\Utilisateurs de Vista et Windows 7 : Clique droit sur le logo de ZHPDiag.exe, " exécuter en tant qu'Administrateur /!\
    * Laisse toi guider lors de l'installation
    * Il se lancera automatiquement à la fin de l'installation
    * Clique sur l'icône représentant une loupe (« Lancer le diagnostic »)
    * Enregistre le rapport sur ton Bureau à l'aide de l'icône représentant une disquette
    * Héberge le rapport ZHPDiag.txt sur le site cijoint.fr ou toofiles puis copie/colle le lien fournit dans ta prochaine réponse sur le forum
    0
    1. Voici le rapport de zhpdiag :

      http://www.cijoint.fr/cjlink.php?file=cj201011/cijNRcy21u.txt

      Merci pour ton analyse.
      0
      1. /!\ A l'attention de ceux qui passent sur ce sujet /!\
        Le logiciel qui suit n'est pas à utiliser à la légère et peut faire des dégâts s'il est mal utilisé ! Ne le faites que si un helpeur du forum qui connait bien cet outil vous l'a recommandé.

        /!\ Désactive tous tes logiciels de protection (Antivirus, Antispywares) /!\

        * Télécharge combofix(de sUBs) sur ton Bureau.
        * Double-clique sur ComboFix.exe afin de le lancer.
        * Il va te demander d'installer la console de récupération : accepte. (important en cas de problème)
        /!\ Ne touche ni à la souris, ni au clavier durant le scan /!\
        * Lorsque la recherche sera terminée, un rapport apparaîtra.
        * Héberge le rapport C:\Combofix.txt sur le site cijoint.fr, puis copie/colle le lien fournit dans ta prochaine réponse sur le forum
        #Si combofix ne veut pas se lancer renommes le en ccm.exe et éxécutes le en mode sans échec .
        Tutoriel officiel de Combofix : http://www.bleepingcomputer.com/combofix/fr/comment-utiliser¬-combofix
        0
        1. Combix a tourné et, j'ai l'impression, fait un peu le ménage...

          Voici le rapport :
          http://www.cijoint.fr/cjlink.php?file=cj201011/cijkGEJZUI.txt

          Merci
          0
          1. Pour le bon fonctionnement de ton ordi un seul antivirus est necessaire .
            2 antivirus sur un pc et tu as obligatoirement un conflit qui généreras un ralentissement du systéme et une mauvaise marche du programme.

            comme tu la écrit combo a fais du ménage.On va s'assurer pour les deux fichiers restaure.

            * rends toi sur ce site : https://www.virustotal.com/gui/
            ==>Analyse ce fichier:
            ------------------------------------------------------------------------------------------
            c:\windows\system32\winlogon.exe
            et
            c:\windows\explorer.exe


            ------------------------------------------------------------------------------------------
            * Cliquez sur Parcourir... :
            * Sélectionnez le fichier que vous voulez analyser et cliquez sur Ouvrir :
            * Cliquez ensuite sur Envoyez le fichier : s'il a déjà été analysé, demande une nouvelle analyse.
            * Fais un copier/coller du rapport sur le forum.
            0
            1. Le fichier explorer.exe est clean.

              Le fichier winlogon a un pb :
              nProtect 2010-11-01.01 2010.11.01 Trojan-Downloader/W32.Small.512000.B

              Je dois m'absenter qq heures, je lirai ta réponse en revenant.

              Merci pour ton aide
              0
              1. j'ai besoin du rapport virus total au complet.
                0
            2. Voici le rapport pour le fichier winlogon.exe

              Antivirus Version Last Update Result
              AhnLab-V3 2010.11.01.01 2010.11.01 -
              AntiVir 7.10.13.76 2010.11.01 -
              Antiy-AVL 2.0.3.7 2010.11.01 -
              Authentium 5.2.0.5 2010.11.01 -
              Avast 4.8.1351.0 2010.11.01 -
              Avast5 5.0.594.0 2010.11.01 -
              AVG 9.0.0.851 2010.11.01 -
              BitDefender 7.2 2010.11.01 -
              CAT-QuickHeal 11.00 2010.10.26 -
              ClamAV 0.96.2.0-git 2010.11.01 -
              Comodo 6580 2010.11.01 -
              DrWeb 5.0.2.03300 2010.11.01 -
              Emsisoft 5.0.0.50 2010.11.01 -
              eSafe 7.0.17.0 2010.11.01 -
              eTrust-Vet 36.1.7947 2010.11.01 -
              F-Prot 4.6.2.117 2010.11.01 -
              F-Secure 9.0.16160.0 2010.11.01 -
              Fortinet 4.2.249.0 2010.11.01 -
              GData 21 2010.11.01 -
              Ikarus T3.1.1.90.0 2010.11.01 -
              Jiangmin 13.0.900 2010.11.01 -
              K7AntiVirus 9.67.2882 2010.11.01 -
              Kaspersky 7.0.0.125 2010.11.01 -
              McAfee 5.400.0.1158 2010.11.01 -
              McAfee-GW-Edition 2010.1C 2010.11.01 -
              Microsoft 1.6301 2010.11.01 -
              NOD32 5582 2010.11.01 -
              Norman 6.06.10 2010.11.01 -
              nProtect 2010-11-01.01 2010.11.01 Trojan-Downloader/W32.Small.512000.B
              Panda 10.0.2.7 2010.11.01 -
              PCTools 7.0.3.5 2010.11.01 -
              Prevx 3.0 2010.11.01 -
              Rising 22.71.06.04 2010.11.01 -
              Sophos 4.59.0 2010.11.01 -
              Sunbelt 7186 2010.11.01 -
              SUPERAntiSpyware 4.40.0.1006 2010.11.01 -
              Symantec 20101.2.0.161 2010.11.01 -
              TheHacker 6.7.0.1.074 2010.11.01 -
              TrendMicro 9.120.0.1004 2010.11.01 -
              TrendMicro-HouseCall 9.120.0.1004 2010.11.01 -
              VBA32 3.12.14.1 2010.11.01 -
              ViRobot 2010.10.4.4074 2010.11.01 -
              VirusBuster 12.70.15.0 2010.11.01 -
              Additional informationShow all
              MD5 : dd73d6b9f6b4cb630cf35b438b540174
              SHA1 : 2904328b7e27f004042d4f83440c50659d64018b
              SHA256: ecef5a07dbc72e99adcb82af4dab143f5a2bad3812ccbfa87ea5e82e29e133fa
              ssdeep: 6144:SNZlxEdL5RvGlcHF37newMLao6nMnKHOD13XRnCfOVSePfLtisgZYlg:tdz+lcDKao6nSK
              HsRqOMgxZgp
              File size : 512000 bytes
              First seen: 2009-02-13 09:43:40
              Last seen : 2010-11-01 18:00:04
              TrID:
              Win64 Executable Generic (80.9%)
              Win32 Executable Generic (8.0%)
              Win32 Dynamic Link Library (generic) (7.1%)
              Generic Win/DOS Executable (1.8%)
              DOS Executable Generic (1.8%)
              sigcheck:
              publisher....: Microsoft Corporation
              copyright....: (c) Microsoft Corporation. Tous droits r_serv_s.
              product......: Syst_me d_exploitation Microsoft_ Windows_
              description..: Application d_ouverture de session Windows NT
              original name: WINLOGON.EXE
              internal name: winlogon
              file version.: 5.1.2600.5512 (xpsp.080413-2113)
              comments.....: n/a
              signers......: -
              signing date.: -
              verified.....: Unsigned
              PEInfo: PE structure information

              [[ basic data ]]
              entrypointaddress: 0x3E5E1
              timedatestamp....: 0x48027549 (Sun Apr 13 21:04:09 2008)
              machinetype......: 0x14c (I386)

              [[ 3 section(s) ]]
              name, viradd, virsiz, rawdsiz, ntropy, md5
              .text, 0x1000, 0x70991, 0x70A00, 6.82, 82b1e7e83279c56e34dc6c6e8c33f81d
              .data, 0x72000, 0x4E70, 0x2000, 6.28, 44bd27282514b5e3a27b570106930d8d
              .rsrc, 0x77000, 0xA18C, 0xA200, 3.69, 2de1a63c2a7883cf163c3699bb614883

              [[ 20 import(s) ]]
              ADVAPI32.dll: ConvertStringSecurityDescriptorToSecurityDescriptorA, A_SHAInit, A_SHAUpdate, A_SHAFinal, LsaStorePrivateData, LsaRetrievePrivateData, LsaNtStatusToWinError, CryptGetUserKey, CryptGetKeyParam, CryptEncrypt, CryptSetProvParam, CryptSignHashW, CryptDeriveKey, CryptGetProvParam, RegOpenCurrentUser, RegDeleteKeyW, AddAccessAllowedAceEx, RegSetKeySecurity, I_ScSendTSMessage, MD5Init, MD5Update, MD5Final, SetFileSecurityA, AllocateLocallyUniqueId, LsaOpenPolicy, LsaQueryInformationPolicy, LsaFreeMemory, LsaClose, RegNotifyChangeKeyValue, QueryServiceConfigW, SetKernelObjectSecurity, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegEnumKeyExW, GetCurrentHwProfileW, RegCloseKey, RegQueryValueExW, RegOpenKeyW, FreeSid, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AddAccessAllowedAce, InitializeAcl, GetLengthSid, AllocateAndInitializeSid, RegOpenKeyExW, CreateProcessAsUserW, DuplicateTokenEx, CloseServiceHandle, ControlService, StartServiceW, QueryServiceStatus, OpenServiceW, OpenSCManagerW, EqualSid, GetTokenInformation, RegSetValueExW, RegCreateKeyExW, CryptGenRandom, CryptDestroyHash, CryptVerifySignatureW, CryptSetHashParam, CryptGetHashParam, CryptHashData, CryptCreateHash, CryptDecrypt, ReportEventW, RegisterEventSourceW, CryptImportKey, CryptAcquireContextW, CryptReleaseContext, CryptDestroyKey, RegEnumValueW, RegQueryInfoKeyW, RegDeleteValueW, CredFree, CredDeleteW, CredEnumerateW, CopySid, GetSidLengthRequired, GetSidSubAuthority, GetSidSubAuthorityCount, GetUserNameW, OpenThreadToken, EnumServicesStatusW, ImpersonateLoggedOnUser, RegQueryValueExA, CheckTokenMembership, DeregisterEventSource, LsaGetUserName, RevertToSelf, LookupAccountSidW, IsValidSid, SetTokenInformation, LogonUserW, LookupAccountNameW, OpenProcessToken, SynchronizeWindows31FilesAndWindowsNTRegistry, QueryWindows31FilesMigration, AdjustTokenPrivileges, RegQueryInfoKeyA
              AUTHZ.dll: AuthzInitializeResourceManager, AuthzAccessCheck, AuthziFreeAuditEventType, AuthziInitializeAuditEvent, AuthziInitializeAuditParams, AuthziInitializeAuditEventType, AuthziLogAuditEvent, AuthzFreeAuditEvent, AuthzFreeResourceManager, AuthzFreeHandle
              CRYPT32.dll: CryptImportPublicKeyInfo, CryptVerifyMessageSignature, CertCreateCertificateContext, CertSetCertificateContextProperty, CertVerifyCertificateChainPolicy, CryptSignMessage, CertCloseStore, CertComparePublicKeyInfo, CryptExportPublicKeyInfo, CertFindExtension, CryptDecryptMessage, CertGetCertificateContextProperty, CertAddCertificateContextToStore, CertOpenStore, CertVerifySubjectCertificateContext, CertGetIssuerCertificateFromStore, CertDuplicateCertificateContext, CertFreeCertificateContext, CertEnumCertificatesInStore, CryptImportPublicKeyInfoEx
              GDI32.dll: RemoveFontResourceW, AddFontResourceW
              KERNEL32.dll: WTSGetActiveConsoleSessionId, GetTimeFormatW, GetUserDefaultLCID, FileTimeToSystemTime, FileTimeToLocalFileTime, GetProcAddress, LoadLibraryW, GetModuleHandleW, SystemTimeToFileTime, GetSystemTime, SetLastError, TerminateProcess, GetCurrentProcess, CreateTimerQueueTimer, CreateThread, lstrcpynW, GetShortPathNameW, GetProfileStringW, FreeLibrary, ReleaseSemaphore, CreateSemaphoreW, GetSystemInfo, GetComputerNameW, GetEnvironmentVariableW, WaitForSingleObjectEx, LoadResource, FindResourceW, SetThreadExecutionState, DeleteTimerQueueTimer, ResetEvent, GetSystemDirectoryW, TransactNamedPipe, SetNamedPipeHandleState, GetTickCount, CreateFileW, GlobalGetAtomNameW, VirtualLock, VirtualQuery, GetDriveTypeW, Beep, ExpandEnvironmentStringsW, OpenMutexW, QueueUserWorkItem, LeaveCriticalSection, EnterCriticalSection, DisconnectNamedPipe, SearchPathW, lstrcatW, LocalReAlloc, TerminateThread, ResumeThread, GetDiskFreeSpaceExW, GlobalMemoryStatusEx, DeleteFileW, WriteProfileStringW, ReadFile, FindVolumeClose, FindNextVolumeW, FindFirstVolumeW, FormatMessageW, SetPriorityClass, MoveFileExW, WaitForMultipleObjectsEx, GetExitCodeProcess, SleepEx, InterlockedExchange, FindClose, FindFirstFileW, GetWindowsDirectoryW, SetTimerQueueTimer, GetComputerNameA, GetVersionExW, VerSetConditionMask, WriteFile, WaitNamedPipeW, WaitForMultipleObjects, ConnectNamedPipe, GetVersionExA, DuplicateHandle, OpenProcess, GetOverlappedResult, lstrcmpW, SetEnvironmentVariableW, UnregisterWait, CreateNamedPipeW, CreateRemoteThread, CreateActCtxW, GetModuleFileNameW, ExitProcess, LoadLibraryExW, SetErrorMode, SetUnhandledExceptionFilter, GetPrivateProfileStringW, LocalSize, VirtualAlloc, VirtualQueryEx, DebugBreak, CreateFileA, InitializeCriticalSection, ProcessIdToSessionId, SetInformationJobObject, AssignProcessToJobObject, TerminateJobObject, PostQueuedCompletionStatus, PulseEvent, GetQueuedCompletionStatus, CreateIoCompletionPort, CreateJobObjectW, ActivateActCtx, DeactivateActCtx, InterlockedCompareExchange, LoadLibraryA, QueryPerformanceCounter, GetSystemTimeAsFileTime, UnhandledExceptionFilter, GetModuleHandleA, GetStartupInfoA, GetCurrentProcessId, SetThreadPriority, GetCurrentThreadId, lstrcmpiW, GetProfileIntW, LoadLibraryExA, lstrcpyW, lstrlenW, Sleep, LocalAlloc, CreateEventW, GetExitCodeThread, SetThreadAffinityMask, GetProcessAffinityMask, CreateWaitableTimerW, CreateMutexW, OpenEventW, RegisterWaitForSingleObject, WaitForSingleObject, CreateProcessW, SetWaitableTimer, ReleaseMutex, SetEvent, UnregisterWaitEx, CloseHandle, lstrlenA, lstrcpyA, MultiByteToWideChar, GetACP, WideCharToMultiByte, HeapAlloc, GetProcessHeap, HeapFree, lstrcpynA, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, lstrcmpiA, GetFileSize, SetFilePointer, GlobalAlloc, GlobalFree, GetLastError, LocalFree, lstrcatA, lstrcmpA, GetLogicalDriveStringsA, GetDriveTypeA, GetVolumeInformationW, GlobalMemoryStatus, CreateMutexA, FindResourceExW, LockResource, SizeofResource, VerifyVersionInfoW, GetSystemDirectoryA, GetCurrentThread, DelayLoadFailureHook, BaseInitAppcompatCacheSupport, OpenProfileUserMapping, CloseProfileUserMapping, BaseCleanupAppcompatCacheSupport, InitializeCriticalSectionAndSpinCount, VirtualProtect, CreateEventA, TlsSetValue, TlsGetValue, DeleteCriticalSection, TlsAlloc, VirtualFree, TlsFree
              msvcrt.dll: wcslen, _vsnwprintf, wcsncpy, wcsstr, atoi, wcstok, memmove, wcschr, swprintf, swscanf, _local_unwind2, _wcslwr, wcscmp, _snwprintf, malloc, _c_exit, _exit, _XcptFilter, _cexit, exit, _acmdln, __getmainargs, _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, __3@YAXPAX@Z, __2@YAPAXI@Z, __CxxFrameHandler, _itow, _snprintf, _wtol, _strnicmp, sscanf, wcstombs, sprintf, strchr, strncmp, atof, _ftol, isspace, wcscpy, _controlfp, wcsncmp, _wcsupr, ceil, wcscat, _except_handler3, free, _wcsicmp
              NDdeApi.dll: -, -, -, -
              ntdll.dll: RtlSubAuthoritySid, RtlAllocateHeap, NtPowerInformation, NtSetSystemPowerState, NtRaiseHardError, RtlDeleteCriticalSection, NtOpenSymbolicLinkObject, NtReplyPort, NtCompleteConnectPort, NtReplyWaitReceivePort, NtAcceptConnectPort, NtCreatePort, RtlConvertSidToUnicodeString, RtlFreeUnicodeString, NtLockProductActivationKeys, RtlTimeToTimeFields, NtUnmapViewOfSection, NtMapViewOfSection, NtOpenSection, NtQuerySymbolicLinkObject, NtQueryVolumeInformationFile, NtSetSecurityObject, RtlAdjustPrivilege, NtOpenFile, NtFsControlFile, RtlAllocateAndInitializeSid, RtlDestroyEnvironment, RtlFreeHeap, NtQueryInformationToken, NtShutdownSystem, RtlEnterCriticalSection, RtlLeaveCriticalSection, RtlInitializeCriticalSection, RtlCreateEnvironment, RtlQueryEnvironmentVariable_U, RtlSetEnvironmentVariable, RtlInitUnicodeString, NtOpenKey, NtQueryValueKey, RtlInitializeSid, RtlLengthRequiredSid, NtAllocateLocallyUniqueId, RtlGetDaclSecurityDescriptor, RtlCopySid, RtlLengthSid, NtSetInformationThread, NtDuplicateToken, NtDuplicateObject, RtlEqualSid, RtlSetDaclSecurityDescriptor, RtlCreateSecurityDescriptor, NtClose, RtlOpenCurrentUser, RtlAddAce, RtlCreateAcl, RtlNtStatusToDosError, NtSetInformationProcess, NtQuerySystemInformation, NtCreateEvent, NtCreatePagingFile, RtlDosPathNameToNtPathName_U, RtlRegisterWait, NtSetValueKey, NtCreateKey, RtlTimeToSecondsSince1980, NtQuerySystemTime, NtPrivilegeObjectAuditAlarm, NtPrivilegeCheck, NtOpenThreadToken, NtOpenProcessToken, RtlInitString, RtlUnhandledExceptionFilter, NtQueryInformationProcess, DbgBreakPoint, RtlCheckProcessParameters, RtlSetThreadIsCritical, RtlSetProcessIsCritical, RtlGetNtProductType, NtInitiatePowerAction, DbgPrint, NtFilterToken, NtQueryInformationJobObject, NtOpenEvent, RtlGetAce, RtlQueryInformationAcl, NtQuerySecurityObject, RtlCompareUnicodeString, NtOpenDirectoryObject
              PROFMAP.dll: InitializeProfileMappingApi, RemapAndMoveUserW
              PSAPI.DLL: EnumProcesses, EnumProcessModules, GetModuleBaseNameW
              REGAPI.dll: RegDefaultUserConfigQueryW, RegUserConfigQuery
              RPCRT4.dll: RpcServerRegisterIfEx, RpcServerUseProtseqEpW, RpcImpersonateClient, I_RpcMapWin32Status, RpcServerRegisterIf, RpcGetAuthorizationContextForClient, RpcFreeAuthorizationContext, RpcServerListen, RpcRevertToSelf, NdrServerCall2, UuidCreate
              Secur32.dll: LsaCallAuthenticationPackage, GetUserNameExW, LsaLookupAuthenticationPackage, LsaRegisterLogonProcess
              SETUPAPI.dll: SetupDiDestroyDeviceInfoList, SetupDiEnumDeviceInfo, SetupDiGetClassDevsW, SetupDiGetDeviceRegistryPropertyW
              USER32.dll: SetFocus, EnumWindows, CreateWindowStationW, RegisterLogonProcess, RecordShutdownReason, LoadLocalFonts, UnhookWindowsHook, SetWindowsHookW, GetWindowTextW, CallNextHookEx, DialogBoxParamW, GetWindowPlacement, GetSystemMenu, DeleteMenu, SetWindowPlacement, SetUserObjectInformationW, GetAsyncKeyState, PostThreadMessageW, SetUserObjectSecurity, CreateDesktopW, GetMessageTime, SetTimer, SetLogonNotifyWindow, UnlockWindowStation, ReplyMessage, UnregisterHotKey, RegisterHotKey, OpenInputDesktop, GetUserObjectInformationW, CloseDesktop, RegisterDeviceNotificationW, SetThreadDesktop, CreateWindowExW, GetMessageW, TranslateMessage, RegisterWindowMessageW, RegisterClassW, SetCursor, FindWindowW, MessageBoxW, SendNotifyMessageW, PostQuitMessage, MsgWaitForMultipleObjects, GetWindowRect, GetSystemMetrics, PeekMessageW, DispatchMessageW, KillTimer, SetProcessWindowStation, UpdateWindow, ShowWindow, SetWindowPos, PostMessageW, ExitWindowsEx, EnumDisplayMonitors, SystemParametersInfoW, GetDlgItem, SendMessageW, CreateDialogParamW, DestroyWindow, GetWindowLongW, GetDlgItemTextW, EndDialog, SetWindowLongW, LoadStringW, SetWindowTextW, SetDlgItemTextW, wsprintfW, wsprintfA, LockWindowStation, MBToWCSEx, SetWindowStationUser, UpdatePerUserSystemParameters, DialogBoxIndirectParamW, wvsprintfW, SetLastErrorEx, LoadCursorW, CheckDlgButton, IsDlgButtonChecked, DefWindowProcW, CloseWindowStation, LoadImageW, GetParent, GetKeyState, GetDesktopWindow, SetForegroundWindow, SwitchDesktop, OpenDesktopW
              USERENV.dll: -, WaitForUserPolicyForegroundProcessing, GetAllUsersProfileDirectoryW, -, -, -, WaitForMachinePolicyForegroundProcessing, -, -, -, UnloadUserProfile, LoadUserProfileW, -, RegisterGPNotification, CreateEnvironmentBlock, DestroyEnvironmentBlock, UnregisterGPNotification, GetUserProfileDirectoryW
              VERSION.dll: GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
              WINSTA.dll: WinStationRequestSessionsList, WinStationQueryLogonCredentialsW, WinStationIsHelpAssistantSession, WinStationAutoReconnect, _WinStationWaitForConnect, _WinStationNotifyLogoff, WinStationDisconnect, _WinStationCallback, WinStationNameFromLogonIdW, _WinStationFUSCanRemoteUserDisconnect, WinStationEnumerate_IndexedW, WinStationGetMachinePolicy, WinStationQueryInformationW, WinStationFreeMemory, WinStationReset, _WinStationNotifyDisconnectPipe, WinStationConnectW, WinStationSetInformationW, WinStationShutdownSystem, WinStationCheckLoopBack, _WinStationNotifyLogon
              WINTRUST.dll: CryptCATAdminEnumCatalogFromHash, CryptCATCatalogInfoFromContext, CryptCATAdminCalcHashFromFileHandle, CryptCATAdminAcquireContext, CryptCATAdminReleaseCatalogContext, WTHelperProvDataFromStateData, WinVerifyTrust, WTHelperGetProvSignerFromChain, CryptCATAdminReleaseContext
              WS2_32.dll: -, -, getaddrinfo
              ExifTool:
              file metadata
              CharacterSet: Unicode
              CodeSize: 461312
              CompanyName: Microsoft Corporation
              EntryPoint: 0x3e5e1
              FileDescription: Application d'ouverture de session Windows NT
              FileFlagsMask: 0x003f
              FileOS: Windows NT 32-bit
              FileSize: 500 kB
              FileSubtype: 0
              FileType: Win32 EXE
              FileVersion: 5.1.2600.5512 (xpsp.080413-2113)
              FileVersionNumber: 5.1.2600.5512
              ImageVersion: 21315.20512
              InitializedDataSize: 49664
              InternalName: winlogon
              LanguageCode: French
              LegalCopyright: Microsoft Corporation. Tous droits r serv s.
              LinkerVersion: 7.1
              MIMEType: application/octet-stream
              MachineType: Intel 386 or later, and compatibles
              OSVersion: 5.1
              ObjectFileType: Executable application
              OriginalFilename: WINLOGON.EXE
              PEType: PE32
              ProductName: Syst me d'exploitation Microsoft Windows
              ProductVersion: 5.1.2600.5512
              ProductVersionNumber: 5.1.2600.5512
              Subsystem: Windows GUI
              SubsystemVersion: 4.0
              TimeStamp: 2008:04:13 23:04:09+02:00
              UninitializedDataSize: 0
              Warning: Possibly corrupt Version resource
              0
              1. J'ajoute le rapport de virus total pour le fichier explorer.exe, il y a un warning signalé à la fin.

                MD5 : f2317622d29f9ff0f88aeecd5f60f0dd
                SHA1 : d54b0b83de6ee5922dd90db1446872bf32062b25
                SHA256: 1ab74a4ae472156a5d2c6714e2e1a60e3b32ceb4996f923887a12b6a27315d13
                ssdeep: 12288:6HmcoCUyZtwAvAs4wTCyrPT7lvGVa/oXqoJpaz/g/J/v1S:4mfty/wAvN7lrPlvGEoXJa
                z/g/J/t
                File size : 1037824 bytes
                First seen: 2009-02-18 14:14:13
                Last seen : 2010-11-01 18:07:59
                TrID:
                Win32 Executable Generic (42.3%)
                Win32 Dynamic Link Library (generic) (37.6%)
                Generic Win/DOS Executable (9.9%)
                DOS Executable Generic (9.9%)
                Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%)
                sigcheck:
                publisher....: Microsoft Corporation
                copyright....: (c) Microsoft Corporation. Tous droits r_serv_s.
                product......: Syst_me d_exploitation Microsoft_ Windows_
                description..: Explorateur Windows
                original name: EXPLORER.EXE
                internal name: explorer
                file version.: 6.00.2900.5512 (xpsp.080413-2105)
                comments.....: n/a
                signers......: -
                signing date.: -
                verified.....: Unsigned
                PEInfo: PE structure information

                [[ basic data ]]
                entrypointaddress: 0x1A55F
                timedatestamp....: 0x48025C30 (Sun Apr 13 19:17:04 2008)
                machinetype......: 0x14c (I386)

                [[ 4 section(s) ]]
                name, viradd, virsiz, rawdsiz, ntropy, md5
                .text, 0x1000, 0x44C09, 0x44E00, 6.38, 013207a9f70ec52b78392db51f333ff0
                .data, 0x46000, 0x1DB4, 0x1800, 1.30, 983f35021232560eaaa99fcbc1b7d359
                .rsrc, 0x48000, 0xB3280, 0xB3400, 6.63, e73694f42fb4ef5e9b8ea017fcf60103
                .reloc, 0xFC000, 0x374C, 0x3800, 6.78, ec335057489badbf6d8142b57175fd91

                [[ 13 import(s) ]]
                ADVAPI32.dll: RegSetValueW, RegEnumKeyExW, GetUserNameW, RegNotifyChangeKeyValue, RegEnumValueW, RegQueryValueExA, RegOpenKeyExA, RegEnumKeyW, RegCloseKey, RegCreateKeyW, RegQueryInfoKeyW, RegOpenKeyExW, RegQueryValueExW, RegCreateKeyExW, RegSetValueExW, RegDeleteValueW, RegQueryValueW
                BROWSEUI.dll: -, -, -, -
                GDI32.dll: GetStockObject, CreatePatternBrush, OffsetViewportOrgEx, GetLayout, CombineRgn, CreateDIBSection, GetTextExtentPoint32W, StretchBlt, CreateRectRgnIndirect, CreateRectRgn, GetClipRgn, IntersectClipRect, GetViewportOrgEx, SetViewportOrgEx, SelectClipRgn, PatBlt, GetBkColor, CreateCompatibleDC, CreateCompatibleBitmap, OffsetWindowOrgEx, DeleteDC, SetBkColor, BitBlt, ExtTextOutW, GetTextExtentPointW, GetClipBox, GetObjectW, SetTextColor, SetBkMode, CreateFontIndirectW, DeleteObject, GetTextMetricsW, SelectObject, GetDeviceCaps, TranslateCharsetInfo, SetStretchBltMode
                KERNEL32.dll: GetSystemDirectoryW, CreateThread, CreateJobObjectW, ExitProcess, SetProcessShutdownParameters, ReleaseMutex, CreateMutexW, SetPriorityClass, GetCurrentProcess, GetStartupInfoW, GetCommandLineW, SetErrorMode, LeaveCriticalSection, EnterCriticalSection, ResetEvent, LoadLibraryExA, CompareFileTime, GetSystemTimeAsFileTime, SetThreadPriority, GetCurrentThreadId, GetThreadPriority, GetCurrentThread, GetUserDefaultLangID, Sleep, GetBinaryTypeW, GetModuleHandleExW, SystemTimeToFileTime, GetLocalTime, GetCurrentProcessId, GetEnvironmentVariableW, UnregisterWait, GlobalGetAtomNameW, GetFileAttributesW, MoveFileW, lstrcmpW, LoadLibraryExW, FindClose, FindNextFileW, FindFirstFileW, lstrcmpiA, SetEvent, AssignProcessToJobObject, GetDateFormatW, GetTimeFormatW, FlushInstructionCache, lstrcpynW, GetSystemWindowsDirectoryW, SetLastError, GetProcessHeap, HeapFree, HeapReAlloc, HeapSize, HeapAlloc, GetUserDefaultLCID, ReadProcessMemory, OpenProcess, InterlockedCompareExchange, LoadLibraryA, QueryPerformanceCounter, UnhandledExceptionFilter, SetUnhandledExceptionFilter, VirtualFree, VirtualAlloc, ResumeThread, TerminateProcess, TerminateThread, GetSystemDefaultLCID, GetLocaleInfoW, CreateEventW, GetLastError, OpenEventW, DelayLoadFailureHook, WaitForSingleObject, GetTickCount, ExpandEnvironmentStringsW, GetModuleFileNameW, GetPrivateProfileStringW, lstrcmpiW, CreateProcessW, FreeLibrary, GetWindowsDirectoryW, LocalAlloc, CreateFileW, DeviceIoControl, LocalFree, GetQueuedCompletionStatus, CreateIoCompletionPort, SetInformationJobObject, CloseHandle, LoadLibraryW, GetModuleHandleW, ActivateActCtx, DeactivateActCtx, GetFileAttributesExW, GetProcAddress, DeleteCriticalSection, CreateEventA, HeapDestroy, InitializeCriticalSection, MulDiv, InitializeCriticalSectionAndSpinCount, lstrlenW, InterlockedDecrement, InterlockedIncrement, GlobalAlloc, InterlockedExchange, GetModuleHandleA, GetVersionExA, GlobalFree, GetProcessTimes, lstrcpyW, GetLongPathNameW, RegisterWaitForSingleObject
                msvcrt.dll: _itow, free, memmove, realloc, _except_handler3, malloc, _ftol, _vsnwprintf
                ntdll.dll: RtlNtStatusToDosError, NtQueryInformationProcess
                ole32.dll: CoFreeUnusedLibraries, RegisterDragDrop, CreateBindCtx, RevokeDragDrop, CoInitializeEx, CoUninitialize, OleInitialize, CoRevokeClassObject, CoRegisterClassObject, CoMarshalInterThreadInterfaceInStream, CoCreateInstance, OleUninitialize, DoDragDrop
                OLEAUT32.dll: -, -
                SHDOCVW.dll: -, -, -
                SHELL32.dll: -, -, SHGetFolderPathW, -, -, -, -, -, ExtractIconExW, -, -, -, -, -, -, -, -, -, -, -, -, -, -, SHGetSpecialFolderLocation, ShellExecuteExW, -, -, -, SHGetSpecialFolderPathW, -, -, -, SHBindToParent, -, -, -, SHParseDisplayName, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, SHChangeNotify, SHGetDesktopFolder, SHAddToRecentDocs, -, -, -, DuplicateIcon, -, -, -, -, -, -, -, -, SHUpdateRecycleBinIcon, SHGetFolderLocation, SHGetPathFromIDListA, -, -, -, -, -, -, -, SHGetPathFromIDListW, -, -, -
                SHLWAPI.dll: StrCpyNW, -, -, -, -, StrRetToBufW, StrRetToStrW, -, -, -, -, SHQueryValueExW, PathIsNetworkPathW, -, AssocCreate, -, -, -, -, -, StrCatW, StrCpyW, -, -, -, -, -, -, SHGetValueW, -, StrCmpNIW, PathRemoveBlanksW, PathRemoveArgsW, PathFindFileNameW, StrStrIW, PathGetArgsW, -, StrToIntW, SHRegGetBoolUSValueW, SHRegWriteUSValueW, SHRegCloseUSKey, SHRegCreateUSKeyW, SHRegGetUSValueW, SHSetValueW, -, PathAppendW, PathUnquoteSpacesW, -, -, PathQuoteSpacesW, -, SHSetThreadRef, SHCreateThreadRef, -, -, -, PathCombineW, -, -, -, SHStrDupW, PathIsPrefixW, PathParseIconLocationW, AssocQueryKeyW, -, AssocQueryStringW, StrCmpW, -, -, -, -, -, -, -, -, SHRegQueryUSValueW, SHRegOpenUSKeyW, SHRegSetUSValueW, PathIsDirectoryW, PathFileExistsW, PathGetDriveNumberW, -, StrChrW, PathFindExtensionW, -, -, PathRemoveFileSpecW, PathStripToRootW, -, -, -, SHOpenRegStream2W, -, -, -, StrDupW, SHDeleteValueW, StrCatBuffW, SHDeleteKeyW, StrCmpIW, -, -, wnsprintfW, -, -, StrCmpNW, -, -
                USER32.dll: TileWindows, GetDoubleClickTime, GetSystemMetrics, GetSysColorBrush, AllowSetForegroundWindow, LoadMenuW, GetSubMenu, RemoveMenu, SetParent, GetMessagePos, CheckDlgButton, EnableWindow, GetDlgItemInt, SetDlgItemInt, CopyIcon, AdjustWindowRectEx, DrawFocusRect, DrawEdge, ExitWindowsEx, WindowFromPoint, SetRect, AppendMenuW, LoadAcceleratorsW, LoadBitmapW, SendNotifyMessageW, SetWindowPlacement, CheckMenuItem, EndDialog, SendDlgItemMessageW, MessageBeep, GetActiveWindow, PostQuitMessage, MoveWindow, GetDlgItem, RemovePropW, GetClassNameW, GetDCEx, SetCursorPos, ChildWindowFromPoint, ChangeDisplaySettingsW, RegisterHotKey, UnregisterHotKey, SetCursor, SendMessageTimeoutW, GetWindowPlacement, LoadImageW, SetWindowRgn, IntersectRect, OffsetRect, EnumDisplayMonitors, RedrawWindow, SubtractRect, TranslateAcceleratorW, WaitMessage, InflateRect, CallWindowProcW, GetDlgCtrlID, SetCapture, LockSetForegroundWindow, SystemParametersInfoW, FindWindowW, CreatePopupMenu, GetMenuDefaultItem, DestroyMenu, GetShellWindow, EnumChildWindows, GetWindowLongW, SendMessageW, RegisterWindowMessageW, GetKeyState, CopyRect, MonitorFromRect, MonitorFromPoint, RegisterClassW, SetPropW, GetWindowLongA, SetWindowLongW, FillRect, GetCursorPos, MessageBoxW, LoadStringW, ReleaseDC, GetDC, EnumDisplaySettingsExW, EnumDisplayDevicesW, PostMessageW, DispatchMessageW, TranslateMessage, GetMessageW, PeekMessageW, PtInRect, BeginPaint, EndPaint, SetWindowTextW, GetAsyncKeyState, InvalidateRect, GetWindow, ShowWindowAsync, TrackPopupMenuEx, UpdateWindow, DestroyIcon, IsRectEmpty, SetActiveWindow, GetSysColor, DrawTextW, IsHungAppWindow, SetTimer, GetMenuItemID, TrackPopupMenu, EndTask, SendMessageCallbackW, GetClassLongW, LoadIconW, OpenInputDesktop, CloseDesktop, SetScrollPos, ShowWindow, BringWindowToTop, GetDesktopWindow, CascadeWindows, CharUpperBuffW, SwitchToThisWindow, InternalGetWindowText, GetScrollInfo, GetMenuItemCount, CreateWindowExW, DialogBoxParamW, MsgWaitForMultipleObjects, CharNextA, RegisterClipboardFormatW, EndDeferWindowPos, DeferWindowPos, BeginDeferWindowPos, PrintWindow, SetClassLongW, GetPropW, GetNextDlgGroupItem, GetNextDlgTabItem, ChildWindowFromPointEx, IsChild, NotifyWinEvent, TrackMouseEvent, GetCapture, GetAncestor, CharUpperW, SetWindowLongA, DrawCaption, ModifyMenuW, InsertMenuW, IsWindowEnabled, GetMenuState, LoadCursorW, GetParent, IsDlgButtonChecked, DestroyWindow, EnumWindows, IsWindowVisible, GetClientRect, UnionRect, EqualRect, GetWindowThreadProcessId, GetForegroundWindow, KillTimer, GetClassInfoExW, DefWindowProcW, RegisterClassExW, GetIconInfo, SetScrollInfo, GetLastActivePopup, SetForegroundWindow, IsWindow, GetSystemMenu, IsIconic, IsZoomed, EnableMenuItem, SetMenuDefaultItem, MonitorFromWindow, GetMonitorInfoW, GetWindowInfo, GetFocus, SetFocus, MapWindowPoints, ScreenToClient, ClientToScreen, GetWindowRect, SetWindowPos, DeleteMenu, GetMenuItemInfoW, SetMenuItemInfoW, CharNextW
                UxTheme.dll: GetThemeBackgroundContentRect, GetThemeBool, GetThemePartSize, DrawThemeParentBackground, OpenThemeData, DrawThemeBackground, GetThemeTextExtent, DrawThemeText, CloseThemeData, SetWindowTheme, GetThemeBackgroundRegion, -, GetThemeMargins, GetThemeColor, GetThemeFont, GetThemeRect, IsAppThemed
                ExifTool:
                file metadata
                CharacterSet: Unicode
                CodeSize: 282112
                CompanyName: Microsoft Corporation
                EntryPoint: 0x1a55f
                FileDescription: Explorateur Windows
                FileFlagsMask: 0x003f
                FileOS: Windows NT 32-bit
                FileSize: 1014 kB
                FileSubtype: 0
                FileType: Win32 EXE
                FileVersion: 6.00.2900.5512 (xpsp.080413-2105)
                FileVersionNumber: 6.0.2900.5512
                ImageVersion: 5.1
                InitializedDataSize: 754688
                InternalName: explorer
                LanguageCode: French
                LegalCopyright: Microsoft Corporation. Tous droits r serv s.
                LinkerVersion: 7.1
                MIMEType: application/octet-stream
                MachineType: Intel 386 or later, and compatibles
                OSVersion: 5.1
                ObjectFileType: Executable application
                OriginalFilename: EXPLORER.EXE
                PEType: PE32
                ProductName: Syst me d'exploitation Microsoft Windows
                ProductVersion: 6.00.2900.5512
                ProductVersionNumber: 6.0.2900.5512
                Subsystem: Windows GUI
                SubsystemVersion: 4.1
                TimeStamp: 2008:04:13 21:17:04+02:00
                UninitializedDataSize: 0
                Warning: Possibly corrupt Version resource
                0
                1. Post un nouveau rapport zhpdiag.
                  Héberge le rapport ZHPDiag.txt sur le site cijoint.fr ou toofiles puis copie/colle le lien fournit dans ta prochaine réponse sur le forum
                  0
                  1. Voici le nouveau rapport ZHPDiag :

                    http://www.cijoint.fr/cjlink.php?file=cj201011/cijk97DEd0.txt

                    J'ai l'impression que c'est nettement mieux. J'attends ta confirmation mais d'ores et déjà, merci bcp.
                    0
                    1. A faire dans l'ordre.

                      1/ Copie/colle les lignes suivantes et place les dans ZHPFix :
                      2/Lance ZHPFix (soit via le raccourci sur ton Bureau, soit via ZHPDiag)
                      3/Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)

                      ----------------------------------------------------------
                      [HKCU\Software\3]
                      O69 - SBI: SearchScopes [HKCU] {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} - (Ask Search) - http://websearch.ask.com
                      O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} [DefaultScope] - (Google) - http://findgala.com
                      [HKLM\Software\BrowserChoice]
                      O69 - SBI: SearchScopes [HKCU] {afdbddaa-5d3f-42ee-b79c-185a7020515b} - (Radio Bar 2 Customized Web Search) - http://search.conduit.com
                      R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} Clé orpheline
                      [HKCU\Software\Conduit]
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:25380
                      R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} Clé orpheline
                      O4 - HKCU\..\Run: [avgsys] regedit \s C:\Documents and Settings\All Users\Application Data\2f4e48\555645.reg (.not file.)
                      O4 - HKUS\S-1-5-21-3978596816-1502510054-2796973502-1006\..\Run: [avgsys] regedit \s C:\Documents and Settings\All Users\Application Data\2f4e48\555645.reg (.not file.)
                      [HKCU\Software\Conduit]
                      O69 - SBI: SearchScopes [HKCU] {afdbddaa-5d3f-42ee-b79c-185a7020515b} - (Radio Bar 2 Customized Web Search) - http://search.conduit.com
                      OPT: O4 - HKLM\..\Run: [Tvs] . (.TOSHIBA Corporation - TOSHIBA Virtual Sound Taskbar Module.) -- C:\Program Files\Toshiba\Tvs\TvsTray.exe
                      OPT:O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\qttask.exe
                      OPT:O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
                      OPT:O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                      OPT:O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe


                      ----------------------------------------------------------
                      * Clique sur"ok" (Tu dois avoir seulement les lignes copiées sur le forum)
                      * Clique sur « Tous », puis sur « Nettoyer »
                      * Copie/colle la totalité du rapport dans ta prochaine réponse

                      ====================================================
                      Télécharge Ad-Remover sur ton bureau:

                      http://www.teamxscript.org/adremoverTelechargement.html

                      /!\ Ferme toutes tes applications ouvertes. /!\

                      * Désactive la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner la procédure de recherche et de nettoyage de l'outil.

                      Double clique sur le fichier que tu viens de télécharger, à l'écran qui apparait, clique sur
                      "Nettoyer".
                      Laisse travailler l'outil.
                      Poste le rapport qui s'affiche à l'écran quand l'analyse est terminée.
                      Si le rapport n'apparait pas il se trouve à cet emplacement :C:\Ad-Report-CLEAN[1].txt
                      0
                      1. Ci-dessous le rapport de ZHPFix. J'enchaine avec les actions suivantes (ad remover...)

                        Rapport de ZHPFix 1.12.3213 par Nicolas Coolman, Update du 27/10/2010
                        Fichier d'export Registre : C:\ZHPExportRegistry-01-11-2010-21-47-35.txt
                        Run by user at 01/11/2010 21:47:35
                        Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
                        Contact : nicolascoolman@yahoo.fr

                        ========== Clé(s) du Registre ==========
                        HKCU\Software\3 => Clé supprimée avec succès
                        O69 - SBI: SearchScopes [HKCU] {6A1806CD-94D4-4689-BA73-E35EA1EA9990} [DefaultScope] - (Google) - http://findgala.com => Clé absente
                        HKLM\Software\BrowserChoice => Clé supprimée avec succès
                        HKCU\Software\Conduit => Clé supprimée avec succès

                        ========== Valeur(s) du Registre ==========
                        R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} Clé orpheline => Valeur supprimée avec succès
                        O4 - HKCU\..\Run: [avgsys] regedit \s C:\Documents and Settings\All Users\Application Data\2f4e48\555645.reg (.not file.) => Valeur supprimée avec succès
                        O4 - HKUS\S-1-5-21-3978596816-1502510054-2796973502-1006\..\Run: [avgsys] regedit \s C:\Documents and Settings\All Users\Application Data\2f4e48\555645.reg (.not file.) => Valeur absente
                        O4 - HKLM\..\Run: [Tvs] . (.TOSHIBA Corporation - TOSHIBA Virtual Sound Taskbar Module.) -- C:\Program Files\Toshiba\Tvs\TvsTray.exe => Valeur supprimée avec succès
                        O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\qttask.exe => Valeur supprimée avec succès
                        O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe => Valeur supprimée avec succès
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe => Valeur supprimée avec succès
                        O4 - HKCU\..\Run: [swg] . (.Google Inc. - GoogleToolbarNotifier.) -- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe => Valeur supprimée avec succès

                        ========== Elément(s) de donnée du Registre ==========
                        O69 - SBI: SearchScopes [HKCU] {171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E} - (Ask Search) - http://www.search.ask.com/?o=10148&l=dis => Donnée remplacée avec succès
                        O69 - SBI: SearchScopes [HKCU] {afdbddaa-5d3f-42ee-b79c-185a7020515b} - (Radio Bar 2 Customized Web Search) - http://search.conduit.com => Donnée remplacée avec succès
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:25380 => Donnée supprimée avec succès

                        ========== Fichier(s) ==========
                        c:\documents and settings\all users\application data\2f4e48\555645.reg () => Fichier absent

                        ========== Récapitulatif ==========
                        4 : Clé(s) du Registre
                        8 : Valeur(s) du Registre
                        3 : Elément(s) de donnée du Registre
                        1 : Fichier(s)

                        End of the scan
                        0
                        1. Et voici le rapport de Ad R :
                          ======= RAPPORT D'AD-REMOVER 2.0.0.2,B | UNIQUEMENT XP/VISTA/7 =======

                          Mis à jour par TeamXscript le 25/10/10 à 11:40
                          Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
                          Site web: http://www.teamxscript.org

                          C:\Program Files\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 21:51:11 le 01/11/2010, Mode normal

                          Microsoft Windows XP Édition familiale Service Pack 3 (X86)
                          user@PASCAL ( )

                          ============== ACTION(S) ==============

                          Dossier supprimé: C:\Documents and Settings\Elsa\Application Data\OfferBox

                          (!) -- Fichiers temporaires supprimés.

                          Clé supprimée: HKLM\Software\Classes\CLSID\{47C6C527-6204-4F91-849D-66E234DEE015}
                          Clé supprimée: HKLM\Software\Classes\CLSID\{9461b922-3c5a-11d2-bf8b-00c04fb93661}
                          Clé supprimée: HKLM\Software\Classes\CLSID\{B791A095-A4AC-4312-8894-5B7E8FF5B3CD}
                          Clé supprimée: HKLM\Software\Classes\TypeLib\{ECA4E801-17AE-4863-9F5C-AF4047AABEE0}
                          Clé supprimée: HKLM\Software\Classes\Toolbar.CT2405727
                          Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\Barre d'outils Crawler
                          Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\WebMediaPlayer
                          Clé supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\OfferBox
                          Clé supprimée: HKCU\Software\Microsoft\SystemCertificates\TrustedPublisher\Certificates\7EE743314C844C7F445B8B1D7617612DF1FDD50F

                          Valeur supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo jimddp
                          Valeur supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo hpfanicgkffmccehnpkikogcffaepkfp
                          Valeur supprimée: HKCU\Software\Microsoft\Windows\CurrentVersion\WinTrust\Trust Providers\Software Publishing\Trust Database\0|goicfboogidikkejccmclpieicihhlpo dgnckdmmolaijpbbakmplfhlfpdhglgc
                          Valeur supprimée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{4B3803EA-5230-4DC3-A7FC-33638F3D3542}

                          ============== SCAN ADDITIONNEL ==============

                          ** Internet Explorer Version [8.0.6001.18702] **

                          [HKCU\Software\Microsoft\Internet Explorer\Main]
                          AutoHide: yes
                          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                          Do404Search: 0x01000000
                          Enable Browser Extensions: yes
                          Local Page: C:\WINDOWS\system32\blank.htm
                          Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                          Show_ToolBar: yes
                          Start Page: hxxp://fr.msn.com/
                          Use Custom Search URL: 1
                          Use Search Asst: no

                          [HKLM\Software\Microsoft\Internet Explorer\Main]
                          Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                          Delete_Temp_Files_On_Exit: yes
                          Local Page: C:\WINDOWS\system32\blank.htm
                          Search bar: hxxp://search.msn.com/spbasic.htm
                          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                          Start Page: hxxp://fr.msn.com/

                          [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
                          Tabs: res://ieframe.dll/tabswelcome.htm
                          Blank: res://mshtml.dll/blank.htm

                          ========================================

                          C:\Program Files\Ad-Remover\Quarantine: 1 Fichier(s)
                          C:\Program Files\Ad-Remover\Backup: 13 Fichier(s)

                          C:\Ad-Report-CLEAN[1].txt - 01/11/2010 (558 Octet(s))

                          Fin à: 21:52:21, 01/11/2010

                          ============== E.O.F ==============
                          0
                          1. Attention le scan peu durer entre 2 et 3 heures.

                            Télécharger Eset Nod32 :
                            http://download.eset.com/special/eos/esetsmartinstaller_fra.exe
                            * Lancer le fichier
                            * Accepter les conditions
                            * Autoriser le programme à accéder à Internet
                            * Cliquer sur paramètre avancées pour ouvrir le menu et sélectionner les options (par défaut le scanner analyse votre ordinateur entièrement)
                            * Téléchargement des signatures

                            Il est recommander de désactiver votre antivirus afin de ne pas ralentir le scan et d'afficher des message d'alerte !

                            * Le scan débute dés la fin du téléchargement
                            * Générer le rapport
                            * Cliquer sur liste des menaces détectées puis sur exporter dans un fichier texte...

                            Vous pouvez l'enregistrer sur le bureau en lui donnant un nom. Poster le rapport sur le forum.

                            Pour vous aider voici un tuto rédigé par dorgane :
                            https://www.commentcamarche.net/faq/29643-scanner-en-ligne-avec-eset-nod32
                            0
                        2. Ayant fermé l'appli un peu rapidement à la fin du scan, je ne sais pas si le rapport a été généré.
                          J'ai trouvé le fichier txt ci-dessous, qui correspond au diagnostic affiché à la fin du scan (10 fichiers infectés et nettoyés).

                          SETSmartInstaller@High as downloader log:
                          all ok
                          # version=7
                          # OnlineScannerApp.exe=1.0.0.1
                          # OnlineScanner.ocx=1.0.0.6211
                          # api_version=3.0.2
                          # EOSSerial=30b3b24001a3af45a5fe9d328bd6f33b
                          # end=finished
                          # remove_checked=true
                          # archives_checked=false
                          # unwanted_checked=true
                          # unsafe_checked=true
                          # antistealth_checked=true
                          # utc_time=2010-11-01 11:02:51
                          # local_time=2010-11-02 12:02:51 (+0100, Paris, Madrid)
                          # country="France"
                          # lang=1036
                          # osver=5.1.2600 NT Service Pack 3
                          # compatibility_mode=512 16777215 100 0 0 0 0 0
                          # compatibility_mode=768 16777215 100 0 291352 291352 0 0
                          # compatibility_mode=1280 16777195 100 0 73659086 73659086 0 0
                          # compatibility_mode=6143 16777215 0 0 0 0 0 0
                          # compatibility_mode=8192 67108863 100 0 3934 3934 0 0
                          # scanned=127632
                          # found=10
                          # cleaned=10
                          # scan_time=4123
                          C:\Documents and Settings\user\Application Data\Sun\Java\Deployment\cache\6.0\30\6ae3af5e-208bb67c Java/TrojanDownloader.OpenStream.NAC cheval de troie (nettoyé par suppression - mis en quarantaine) 00000000000000000000000000000000 C
                          C:\Documents and Settings\user\Bureau\sauvegarde 427515\Documents and Settings\Zaza\Local Settings\Temporary Internet Files\Content.IE5\RK68MKNP\index[1].htm HTML/ScrInject.B.Gen virus (supprimé - mis en quarantaine) 00000000000000000000000000000000 C
                          C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\2f4e48\32.mof.vir Win32/RogueAV.A cheval de troie (nettoyé par suppression - mis en quarantaine) 00000000000000000000000000000000 C
                          C:\Qoobox\Quarantine\C\WINDOWS\explorer.exe.vir Win32/Bamital.EL cheval de troie (supprimé - mis en quarantaine) 00000000000000000000000000000000 C
                          C:\Qoobox\Quarantine\C\WINDOWS\system32\winlogon.exe.vir Win32/Bamital.EL cheval de troie (supprimé - mis en quarantaine) 00000000000000000000000000000000 C
                          C:\System Volume Information\_restore{E92664F3-D946-4EF2-B89C-ACACA4457F7A}\RP29\A0009109.exe Win32/Bamital.EL cheval de troie (supprimé - mis en quarantaine) 00000000000000000000000000000000 C
                          C:\System Volume Information\_restore{E92664F3-D946-4EF2-B89C-ACACA4457F7A}\RP29\A0009111.exe Win32/Bamital.EL cheval de troie (supprimé - mis en quarantaine) 00000000000000000000000000000000 C
                          C:\System Volume Information\_restore{E92664F3-D946-4EF2-B89C-ACACA4457F7A}\RP29\A0009112.mof Win32/RogueAV.A cheval de troie (nettoyé par suppression - mis en quarantaine) 00000000000000000000000000000000 C
                          C:\System Volume Information\_restore{E92664F3-D946-4EF2-B89C-ACACA4457F7A}\RP7\A0001428.reg REG/Startup.C cheval de troie (nettoyé par suppression - mis en quarantaine) 00000000000000000000000000000000 C
                          C:\WINDOWS\system32\sarp32.dll une variante de Win32/BHO.NVR cheval de troie (nettoyé par suppression - mis en quarantaine) 00000000000000000000000000000000 C
                          0
                          1. Pour vérifier et finaliser postes un nouveau rapport zhpdiag.
                            Héberge le rapport ZHPDiag.txt sur le site cijoint.fr ou toofiles puis copie/colle le lien fournit dans ta prochaine réponse sur le forum

                            je regarderais ton rapport certainement en soirée.
                            0
                            1. Bonjour,
                              voici le rapport ZHPDiag :
                              http://www.cijoint.fr/cjlink.php?file=cj201011/cij6RIHIV2.txt

                              J'attends ton retour, mais depuis ton intervention, mon pc fonctionne vraiment bien (plus aucune pertubation et plus rapide).

                              Merci
                              0
                              1. Bonjour

                                Une infection est toujours presente.On va devoir le faire a la mano.

                                Clic sur Windows + R.Une fenetre va apparaitre.Inscrit regedit et ok
                                ensuite suit cette arborescence

                                HKEY_CURRENT_USER==>SOFTWARE==>Microsoft==>InternetExplorer==>SearchScopes
                                Clic droit sur 6A1806CD-94D4-4689-BA73-E35EA1EA9990 et supprimer.

                                Si cela ne veut pas fonctionner fais le en mode sans échec.

                                Tiens moi au courant....
                                0
                                1. Bonjour,
                                  je viens de supprimer la clé en question.

                                  Dois je refaire un scan ?
                                  0
                                  1. Oui refait un scan zhpdiag
                                    0
                                    1. Voici le lien vers le résultat du scan :
                                      http://www.cijoint.fr/cjlink.php?file=cj201011/cijLws51vA.txt

                                      Merci pour tes vérifications
                                      0
                                      • 1
                                      • 2