Win32 Malware gen

Résolu
Bonjour,

Je suis sous XP et depuis quelques temps j'ai souvent des fenêtres qui s'ouvrent quand je suis sur internet... je les ferme tout de suite en général mais ça m'est aussi arrivé d'être redirigée sur gomeo par exemple.

J'ai Avast et il me détecte souvent le virus Win32 Malware gen... j'ai beau le supprimer il revient toujours.

Je fais des analyses avec Malwarebytes et j'ai déjà supprimé des choses, j'ai eu droit à Adware.Adrotator, Trojan.BHO tout à l'heure.

J'en ai marre je n'arrive pas à réellement me débarrasser de tout ça j'aurai besoin que quelqu'un m'aide parce que moi et l'informatique... c'est pas trop ça lol.

Je vous remercie d'avance pour vos réponses.

48 réponses

Résumé de la discussion

Le sujet porte sur une machine sous Windows XP confrontée à des fenêtres publicitaires, des redirections et la détection répétée de Win32 Malware gen par Avast. Les solutions évoquées incluent l'analyse avec Malwarebytes qui pointe Adware.Adrotator et Trojan.BHO, et l'exigence de partager le dernier rapport Malwarebytes pour confirmer le problème observé. Des pistes complémentaires évoquent le démarrage en mode sans échec avec prise en charge réseau, puis l'analyse avec les outils concernés et des vérifications des rapports pour étudier les infections et leur persistance. Par ailleurs, certains échanges mentionnent des liens vers des fichiers de rapport et des outils tiers pour compléter l'investigation, tout en soulignant la nécessité d'éviter des actions risquées non vérifiées.

Bobot (l’IA à votre service)
  1. bonjour sauvegarde ton travail puis :


    /!\ ATTENTION SUIVRE A LA LETTRE CES INDICATIONS/!\

    __________________________________________________________
    >Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
    >>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
    =====================================================


    ▶ Surtout , pense à l'enregistrement à renommer Combofix en "ton prenom.exe" avant qu'il soit enregistré sur ton disque dur

    Telecharge ici : Combofix

    Avant d'utiliser ComboFix :

    Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection. Utilise Defogger pour les désactiver temporairement :

    ▶ Télécharge Defogger (de jpshortstuff) sur ton Bureau

    ▶ Lance le

    Une fenêtre apparait : clique sur "Disable"

    ▶ Fais redémarrer l'ordinateur si l'outil te le demande

    Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"

    _________________________________________________________
    >> referme les fenêtres de tous les programmes en cours.
    >> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
    >>la protection en temps réel de ton Antivirus et de tes Antispywares,
    >>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur combofix renommé

    ▶ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

    ▶ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    ▶▶ Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

    0
    1. Comment je fais pour renommer Combofix ?
      0
      1. clic droit sur le lien de telechargement , enregistrer la cible sous.....un autre nom sur le bureau
        0
        1. D'ac merci, je fais ça et je poste le rapport...
          0
          1. Signaler gen-hackman

            sans doute mais cela fait des années que je pratique ceci et mon pc tourne a merveille jamais de problème. voila pourquoi je lui est proposé ces logiciels
            0
            1. ????
              0
            2. et ben fais toi infecter par les même virus que le posteur, et après on verra sites logiciels sont si efficaces que ça.

              pourquoi tu dis "signaler" ?

              regarde un peu le profil de gen-hackman, ce n'est pas un bras-cassé qui essaye de donner des conseil au hasard. C'est un professionnel.
              0
          2. ComboFix 10-11-17.03 - sha'a 18/11/2010 14:36:10.1.2 - x86
            Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.2047.1599 [GMT 1:00]
            Lancé depuis: c:\documents and settings\sha'a\Bureau\charlene.exe
            AV: avast! antivirus 4.8.1368 [VPS 101118-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

            AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
            .

            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
            .

            c:\windows\system32\cellset.dll

            .
            \\.\PhysicalDrive0 - Bootkit TDL4 was found and disinfected
            .
            ((((((((((((((((((((((((((((( Fichiers créés du 2010-10-18 au 2010-11-18 ))))))))))))))))))))))))))))))))))))
            .

            2010-11-16 19:23 . 2010-11-16 19:23 -------- d-----r- c:\documents and settings\NetworkService\Favoris
            2010-11-14 17:21 . 2010-11-14 17:21 -------- d-----w- c:\program files\Fichiers communs\SWF Studio
            2010-11-14 08:42 . 2010-11-14 08:42 -------- d-----w- c:\documents and settings\sha'a\Application Data\Creative
            2010-11-13 08:59 . 2010-11-13 08:59 -------- d-----r- c:\documents and settings\LocalService\Favoris
            2010-11-11 21:12 . 2010-11-11 22:45 -------- d-----w- c:\documents and settings\sha'a\Application Data\PhotoFiltre
            2010-11-11 21:12 . 2010-11-11 21:12 -------- d-----w- c:\program files\PhotoFiltre
            2010-11-11 18:03 . 2010-11-11 18:34 -------- d-----w- c:\program files\JDownloader
            2010-11-06 12:50 . 2008-04-14 02:33 221184 ----a-w- c:\windows\system32\wmpns.dll
            2010-11-05 20:42 . 1998-11-13 12:16 308224 ----a-w- c:\windows\IsUn040c.exe
            2010-11-05 20:41 . 2005-03-14 17:00 24576 ------w- c:\windows\system32\CTWEBFUN.DLL
            2010-11-05 20:41 . 2005-03-30 17:06 36864 ----a-r- c:\windows\system32\CtCamMgr.dll
            2010-11-05 20:40 . 2010-11-05 20:43 -------- d-----w- c:\program files\Creative
            2010-11-05 20:34 . 2010-11-05 20:34 -------- d-----w- c:\documents and settings\sha'a\Application Data\ArcSoft
            2010-11-05 20:34 . 2010-11-05 20:34 -------- d-----w- c:\documents and settings\All Users\Application Data\element5
            2010-11-05 20:34 . 2010-11-05 20:34 -------- d-----w- c:\program files\Fichiers communs\element5 Shared
            2010-11-05 20:19 . 2003-09-19 16:45 21248 ----a-w- c:\windows\system32\drivers\pfc.sys
            2010-11-05 20:18 . 1995-07-31 12:44 212480 ----a-w- c:\windows\PCDLIB32.DLL
            2010-11-05 20:00 . 2010-11-05 20:00 -------- d-----w- c:\program files\Fichiers communs\HP
            2010-11-05 20:00 . 2010-11-05 20:00 -------- d-----w- c:\program files\Fichiers communs\Hewlett-Packard
            2010-11-05 20:00 . 2009-04-20 11:23 315904 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpfpp70w.dll
            2010-11-05 20:00 . 2009-04-20 11:23 123904 ----a-w- c:\windows\system32\hpf3l70w.dll
            2010-11-05 19:59 . 2010-11-05 20:00 -------- d-----w- c:\program files\HP
            2010-11-05 19:59 . 2008-04-13 19:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
            2010-11-05 19:59 . 2008-04-13 19:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
            2010-11-05 19:58 . 2008-10-29 00:27 21568 ----a-w- c:\windows\system32\drivers\HPZius12.sys
            2010-11-05 19:58 . 2008-10-29 00:27 49920 ----a-w- c:\windows\system32\drivers\HPZid412.sys
            2010-11-05 19:58 . 2008-10-29 00:27 16496 ----a-w- c:\windows\system32\drivers\HPZipr12.sys
            2010-11-05 19:58 . 2009-04-16 11:53 452408 ----a-w- c:\windows\system32\hpzids01.dll
            2010-11-05 19:58 . 2009-02-11 11:03 966656 ----a-w- c:\windows\system32\hpost_p02e.dll
            2010-11-05 19:58 . 2009-02-11 11:03 712704 ----a-w- c:\windows\system32\hposwia_p02e.dll
            2010-11-05 19:58 . 2009-02-11 11:03 315392 ----a-w- c:\windows\system32\hposc_p02a.dll
            2010-11-05 19:58 . 2008-10-29 00:27 372736 ----a-w- c:\windows\system32\hppldcoi.dll
            2010-11-04 20:32 . 2010-11-04 20:32 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
            2010-11-04 20:31 . 2010-11-04 20:31 240592 ----a-w- c:\windows\system32\nvdrsdb0.bin
            2010-11-04 20:31 . 2010-11-04 20:31 1 ----a-w- c:\windows\system32\nvdrssel.bin
            2010-11-04 20:31 . 2010-11-04 20:31 240592 ----a-w- c:\windows\system32\nvdrsdb1.bin
            2010-11-04 20:31 . 2010-10-16 18:55 888424 ----a-w- c:\windows\system32\nvdispco32.dll
            2010-11-04 20:31 . 2010-10-16 18:55 813672 ----a-w- c:\windows\system32\nvgenco32.dll
            2010-11-04 20:31 . 2010-10-16 18:55 61440 ----a-w- c:\windows\system32\OpenCL.dll
            2010-11-04 20:31 . 2010-10-16 18:55 2932840 ----a-w- c:\windows\system32\nvcuvid.dll
            2010-11-04 20:31 . 2010-10-16 18:55 2666600 ----a-w- c:\windows\system32\nvcuvenc.dll
            2010-11-04 20:31 . 2010-10-16 18:55 2293194 ----a-w- c:\windows\system32\nvdata.bin
            2010-11-04 20:31 . 2010-10-16 18:55 13012992 ----a-w- c:\windows\system32\nvcompiler.dll
            2010-11-04 20:30 . 2010-11-04 20:32 -------- d-----w- c:\program files\NVIDIA Corporation
            2010-11-04 20:30 . 2010-11-04 20:30 -------- d-----w- C:\NVIDIA
            2010-11-04 20:25 . 2010-11-04 20:25 -------- d-----w- c:\program files\Fichiers communs\Java
            2010-11-04 20:25 . 2010-11-04 20:25 73728 ----a-w- c:\windows\system32\javacpl.cpl
            2010-11-04 20:25 . 2010-11-04 20:25 472808 ----a-w- c:\windows\system32\deployJava1.dll
            2010-11-04 17:54 . 2010-11-15 20:42 -------- d-----w- c:\program files\trend micro
            2010-11-04 17:54 . 2010-11-04 17:55 -------- d-----w- C:\rsit
            2010-11-03 19:00 . 2010-11-03 19:00 -------- d-----w- c:\program files\ma-config.com
            2010-11-03 19:00 . 2010-11-03 19:00 -------- d-----w- c:\documents and settings\All Users\Application Data\ma-config.com
            2010-11-03 18:18 . 2010-11-03 18:18 -------- d-----w- c:\documents and settings\sha'a\Application Data\Samsung
            2010-11-03 18:17 . 2010-11-03 18:17 -------- d-----w- c:\program files\DIFX
            2010-11-03 18:17 . 2008-02-22 14:33 14976 ----a-w- c:\windows\system32\drivers\sscdmdfl.sys
            2010-11-03 18:17 . 2008-02-22 14:33 12160 ----a-w- c:\windows\system32\drivers\sscdwhnt.sys
            2010-11-03 18:17 . 2008-02-22 14:33 12160 ----a-w- c:\windows\system32\drivers\sscdwh.sys
            2010-11-03 18:17 . 2008-02-22 14:33 114304 ----a-w- c:\windows\system32\drivers\sscdmdm.sys
            2010-11-03 18:17 . 2008-02-22 14:33 87936 ----a-w- c:\windows\system32\drivers\sscdbus.sys
            2010-11-03 18:17 . 2008-02-22 14:33 12160 ----a-w- c:\windows\system32\drivers\sscdcmnt.sys
            2010-11-03 18:17 . 2008-02-22 14:33 12160 ----a-w- c:\windows\system32\drivers\sscdcm.sys
            2010-11-03 18:16 . 2010-11-03 18:17 -------- d-----w- c:\windows\system32\Samsung_USB_Drivers
            2010-11-03 18:16 . 2006-07-24 15:05 5632 ----a-w- c:\windows\system32\drivers\StarOpen.sys
            2010-11-03 18:16 . 2010-11-03 18:16 -------- d-----w- c:\program files\Samsung
            2010-11-03 13:32 . 2010-11-03 16:28 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
            2010-11-02 18:11 . 2010-11-02 18:11 -------- d-----w- c:\documents and settings\All Users\Application Data\TerraTec
            2010-11-02 18:11 . 2010-11-02 18:11 -------- d-----w- c:\program files\TerraTec
            2010-11-02 18:01 . 2008-04-13 19:46 17024 -c--a-w- c:\windows\system32\dllcache\ccdecode.sys
            2010-11-02 17:00 . 2010-11-07 20:12 -------- d-----w- c:\documents and settings\sha'a\Local Settings\Application Data\Adobe
            2010-11-02 16:53 . 2010-03-29 20:30 65536 ----a-w- c:\windows\system32\MFC71DEU.DLL
            2010-11-02 16:53 . 2010-03-29 20:30 61440 ----a-w- c:\windows\system32\MFC71ITA.DLL
            2010-11-02 16:53 . 2010-03-29 20:30 61440 ----a-w- c:\windows\system32\MFC71FRA.DLL
            2010-11-02 16:53 . 2010-03-29 20:30 61440 ----a-w- c:\windows\system32\MFC71ESP.DLL
            2010-11-02 16:53 . 2010-03-29 20:30 57344 ----a-w- c:\windows\system32\MFC71ENU.DLL
            2010-11-02 16:53 . 2010-03-29 20:30 49152 ----a-w- c:\windows\system32\MFC71KOR.DLL
            2010-11-02 16:53 . 2010-03-29 20:30 49152 ----a-w- c:\windows\system32\MFC71JPN.DLL
            2010-11-02 16:53 . 2010-03-29 20:30 45056 ----a-w- c:\windows\system32\MFC71CHT.DLL
            2010-11-02 16:53 . 2010-03-29 20:30 40960 ----a-w- c:\windows\system32\MFC71CHS.DLL
            2010-11-02 16:53 . 2010-03-29 20:30 1712128 ----a-w- c:\windows\system32\gdiplus.dll
            2010-11-02 16:53 . 2010-03-29 20:30 1047552 ----a-w- c:\windows\system32\MFC71u.dll
            2010-11-02 16:52 . 2010-11-02 19:10 -------- d-----w- c:\program files\Fichiers communs\TerraTec
            2010-11-02 16:52 . 2008-10-31 11:49 456096 ----a-r- c:\windows\system32\drivers\dvb7700all.sys
            2010-11-02 16:50 . 2010-11-02 17:58 -------- d-----w- c:\documents and settings\sha'a\Application Data\TerraTec
            2010-11-02 13:17 . 2010-11-02 13:17 -------- d-----w- c:\documents and settings\sha'a\Application Data\vlc
            2010-11-02 12:45 . 2010-11-02 12:45 -------- d-----w- c:\documents and settings\sha'a\Application Data\Malwarebytes
            2010-11-02 12:45 . 2010-04-29 14:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
            2010-11-02 12:45 . 2010-11-02 12:45 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
            2010-11-02 12:45 . 2010-11-02 12:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
            2010-11-02 12:45 . 2010-04-29 14:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
            2010-11-01 20:06 . 2010-11-01 20:06 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
            2010-11-01 19:53 . 2010-11-01 19:53 -------- d-----w- c:\windows\Sun
            2010-11-01 17:14 . 2010-11-02 17:53 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
            2010-11-01 17:14 . 2010-11-01 17:14 -------- d-----w- C:\ProgramData
            2010-11-01 16:50 . 2010-11-01 16:50 -------- d-----w- c:\program files\Microsoft WSE
            2010-11-01 16:48 . 2006-09-28 15:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll
            2010-11-01 16:48 . 2010-11-01 16:48 -------- d-----w- c:\windows\Logs
            2010-11-01 16:43 . 2010-11-01 18:50 -------- d-----w- c:\program files\Electronic Arts
            2010-11-01 16:21 . 2010-11-01 16:22 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
            2010-11-01 16:15 . 2010-11-01 16:22 691696 ----a-w- c:\windows\system32\drivers\sptd.sys
            2010-11-01 14:20 . 2010-11-01 14:20 -------- d-----w- c:\program files\Java
            2010-10-31 20:20 . 2010-10-31 20:20 -------- d-----w- c:\documents and settings\sha'a\Local Settings\Application Data\Identities
            2010-10-31 14:08 . 2009-11-24 23:50 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
            2010-10-31 14:08 . 2009-11-24 23:50 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
            2010-10-31 14:01 . 2009-11-24 23:48 23120 ----a-w- c:\windows\system32\drivers\aswRdr.sys
            2010-10-31 14:01 . 2009-11-24 23:49 48560 ----a-w- c:\windows\system32\drivers\aswTdi.sys
            2010-10-31 14:01 . 2009-11-24 23:47 27408 ----a-w- c:\windows\system32\drivers\aavmker4.sys
            2010-10-31 14:01 . 2009-11-24 23:51 93424 ----a-w- c:\windows\system32\drivers\aswmon.sys
            2010-10-31 14:01 . 2009-11-24 23:50 94160 ----a-w- c:\windows\system32\drivers\aswmon2.sys
            2010-10-31 14:01 . 2009-11-24 23:54 1280480 ----a-w- c:\windows\system32\aswBoot.exe
            2010-10-31 14:01 . 2009-11-24 23:47 97480 ----a-w- c:\windows\system32\AVASTSS.scr
            2010-10-31 14:01 . 2004-01-09 09:13 380928 ----a-w- c:\windows\system32\actskin4.ocx
            2010-10-30 20:33 . 2010-10-30 20:33 -------- d-----w- c:\documents and settings\sha'a\Local Settings\Application Data\Mozilla
            2010-10-30 20:05 . 2010-10-30 20:05 -------- d-sh--w- c:\documents and settings\sha'a\PrivacIE
            2010-10-30 20:03 . 2010-10-30 20:03 -------- d-sh--w- c:\documents and settings\sha'a\IETldCache
            2010-10-30 20:01 . 2010-08-26 11:08 13312 -c----w- c:\windows\system32\dllcache\iecompat.dll
            2010-10-30 20:01 . 2010-09-10 05:50 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
            2010-10-30 20:01 . 2010-09-10 05:50 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
            2010-10-30 20:01 . 2010-09-10 05:50 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
            2010-10-30 20:01 . 2010-09-10 05:50 1986560 -c----w- c:\windows\system32\dllcache\iertutil.dll
            2010-10-30 20:01 . 2010-09-10 05:50 247808 -c----w- c:\windows\system32\dllcache\ieproxy.dll
            2010-10-30 20:01 . 2010-09-10 05:50 11080192 -c----w- c:\windows\system32\dllcache\ieframe.dll
            2010-10-30 20:01 . 2010-09-10 05:50 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
            2010-10-30 20:00 . 2010-10-30 20:00 -------- dc-h--w- c:\windows\ie8
            2010-10-30 16:50 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
            2010-10-30 16:50 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2010-10-16 18:55 . 2008-10-07 05:33 9623680 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
            2010-10-16 18:55 . 2008-10-07 05:33 6359552 ----a-w- c:\windows\system32\nv4_disp.dll
            2010-10-16 18:55 . 2008-10-07 05:33 4882432 ----a-w- c:\windows\system32\nvcuda.dll
            2010-10-16 18:55 . 2008-10-07 05:33 1462272 ----a-w- c:\windows\system32\nvapi.dll
            2010-10-16 18:55 . 2008-10-07 05:33 14532608 ----a-w- c:\windows\system32\nvoglnt.dll
            2010-10-16 11:04 . 2010-10-16 11:04 81920 ----a-w- c:\windows\system32\nvwddi.dll
            2010-10-16 11:04 . 2010-10-16 11:04 277608 ----a-w- c:\windows\system32\nvmccs.dll
            2010-10-16 11:04 . 2010-10-16 11:04 13851752 ----a-w- c:\windows\system32\nvcpl.dll
            2010-10-16 11:04 . 2010-10-16 11:04 110696 ----a-w- c:\windows\system32\nvmctray.dll
            2010-10-16 11:04 . 2010-10-16 11:04 156776 ----a-w- c:\windows\system32\nvsvc32.exe
            2010-10-16 11:04 . 2010-10-16 11:04 145000 ----a-w- c:\windows\system32\nvcolor.exe
            2010-09-18 10:23 . 2004-08-05 12:00 974848 ----a-w- c:\windows\system32\mfc42u.dll
            2010-09-18 06:53 . 2004-08-05 12:00 974848 ----a-w- c:\windows\system32\mfc42.dll
            2010-09-18 06:53 . 2004-08-05 12:00 954368 ----a-w- c:\windows\system32\mfc40.dll
            2010-09-18 06:53 . 2004-08-05 12:00 953856 ----a-w- c:\windows\system32\mfc40u.dll
            2010-09-10 05:50 . 2004-08-05 12:00 916480 ----a-w- c:\windows\system32\wininet.dll
            2010-09-10 05:50 . 2004-08-05 12:00 43520 ------w- c:\windows\system32\licmgr10.dll
            2010-09-10 05:50 . 2004-08-05 12:00 1469440 ------w- c:\windows\system32\inetcpl.cpl
            2010-09-01 11:51 . 2004-08-05 12:00 285824 ----a-w- c:\windows\system32\atmfd.dll
            2010-09-01 07:55 . 2004-08-05 12:00 1852928 ----a-w- c:\windows\system32\win32k.sys
            2010-08-27 08:02 . 2004-08-05 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
            2010-08-27 05:58 . 2004-08-05 12:00 99840 ----a-w- c:\windows\system32\srvsvc.dll
            2010-08-27 01:43 . 2008-05-05 05:25 5632 ----a-w- c:\windows\system32\xpsp4res.dll
            2010-08-26 13:39 . 2004-08-05 12:00 357248 ----a-w- c:\windows\system32\drivers\srv.sys
            2010-08-23 16:12 . 2004-08-05 12:00 617472 ----a-w- c:\windows\system32\comctl32.dll
            .

            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4

            [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0F6E720A-1A6B-40E1-A294-1D4D19F156C8}]
            2009-10-15 08:53 165184 ----a-w- c:\program files\SFR\Kit\SFRNavErrorHelper.dll

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2008-04-10 29757440]
            "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
            "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
            "SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
            "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2010-10-16 110696]
            "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2010-10-16 13851752]
            "nwiz"="c:\program files\NVIDIA Corporation\nView\nwiz.exe" [2010-08-25 1753192]
            "PD0630 STISvc"="P0630Pin.dll" [2005-06-05 36864]

            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Remote Control Editor]
            2010-06-09 10:47 1689088 ----a-w- c:\program files\Fichiers communs\TerraTec\Remote\TTTvRc.exe

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
            "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
            "c:\\Program Files\\TerraTec\\TerraTec Home Cinema\\CinergyDvr.exe"=
            "c:\\Program Files\\TerraTec\\TerraTec Home Cinema\\VersionCheck\\VersionCheck.exe"=
            "c:\\Program Files\\TerraTec\\TerraTec Home Cinema\\tvtvSetup\\tvtv_Wizard.exe"=
            "c:\\Program Files\\TerraTec\\TerraTec Home Cinema\\InstTool.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfcCopy.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=

            R0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [01/11/2010 17:15 691696]
            R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [31/10/2010 15:08 114768]
            R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [31/10/2010 15:08 20560]
            R3 P0630VID;Creative WebCam Live!;c:\windows\system32\drivers\P0630Vid.sys [05/11/2010 21:43 91841]
            R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [30/10/2010 15:05 222976]
            S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [12/09/2010 15:30 251248]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
            HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
            .
            .
            ------- Examen supplémentaire -------
            .
            FF - ProfilePath - c:\documents and settings\sha'a\Application Data\Mozilla\Firefox\Profiles\5s0throo.default\
            FF - prefs.js: browser.search.selectedEngine - Google
            FF - prefs.js: browser.startup.homepage - hxxp://google.fr/
            FF - prefs.js: keyword.URL - hxxp://redirecterror.sfr.fr/?q=
            FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
            FF - plugin: c:\program files\ma-config.com\nphardwaredetection.dll

            ---- PARAMETRES FIREFOX ----
            FF - user.js: keyword.URL - hxxp://redirecterror.sfr.fr/?q=
            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
            c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
            c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
            .
            - - - - ORPHELINS SUPPRIMES - - - -

            HKCU-Run-EA Core - c:\program files\Electronic Arts\EADM\Core.exe
            HKLM-Run-gchk - c:\windows\$NtUninstallMTF197$\upg.exe

            **************************************************************************

            catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2010-11-18 14:39
            Windows 5.1.2600 Service Pack 3 NTFS

            Recherche de processus cachés ...

            Recherche d'éléments en démarrage automatique cachés ...

            HKLM\Software\Microsoft\Windows\CurrentVersion\Run
            HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

            Recherche de fichiers cachés ...

            Scan terminé avec succès
            Fichiers cachés: 0

            **************************************************************************
            .
            Heure de fin: 2010-11-18 14:40:11
            ComboFix-quarantined-files.txt 2010-11-18 13:40

            Avant-CF: 22 530 768 896 octets libres
            Après-CF: 22 565 588 992 octets libres

            - - End Of File - - C3A2871085F93F18FF5FD0C66B0E5E0A
            0
            1. Télécharge ici :OTL

              enregistre le sur ton Bureau.

              si tu as XP => double clique
              si tu as Vista ou windows 7 => clic droit "executer en tant que...."


              sur OTL.exe pour le lancer.

              ▶ Coche les 2 cases Lop et Purity

              ▶ Coche la case devant tous les utilisateurs

              ▶ règle age du fichier sur "60 jours"

              ▶ dans la moitié gauche , mets tout sur "tous"

              ne modifie pas ceci :

              "fichiers créés" et "fichiers Modifiés"


              ▶Clic sur Analyse.

              A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

              Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

              ▶▶▶ NE LE POSTE PAS SUR LE FORUM

              Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

              ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

              ▶ Clique sur Ouvrir.

              ▶ Clique sur "Cliquez ici pour déposer le fichier".

              juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

              http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

              ▶ Copie ce lien dans ta réponse.

              ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
              0
              1. Voila les deux liens...

                http://www.cijoint.fr/cjlink.php?file=cj201011/cijnyZhTyj.txt

                http://www.cijoint.fr/cjlink.php?file=cj201011/cijOxRjLD3.txt
                0
                1. Je dois y aller je reviendrai ce soir, merci déjà pour ton aide.
                  0
                  1. hello

                    si tu as XP => double clique
                    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                    sur OTL.exe pour le lancer.

                    ▶Copie la liste qui se trouve en gras ci-dessous,

                    ▶ colle-la dans la zone sous "Personnalisation" :


                    :processes
                    explorer.exe
                    iexplore.exe
                    firefox.exe
                    msnmsgr.exe
                    Teatimer.exe

                    :OTL
                    FF - prefs.js..browser.search.defaultenginename: "Web Search..."
                    O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

                    :Reg
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                    "Adobe Reader Speed Launcher"=-
                    "nwiz"=-

                    :Files
                    C:\WINDOWS\System32\dllcache\mstsc.exe
                    C:\WINDOWS\System32\Uninstall.ico

                    :commands
                    [emptytemp]
                    [start explorer]
                    [reboot]


                    ▶ Clique sur "Correction" pour lancer la suppression.

                    ▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.
                    0
                    1. Salut,
                      Voila le rapport :


                      All processes killed
                      ========== PROCESSES ==========
                      No active process named explorer.exe was found!
                      No active process named iexplore.exe was found!
                      No active process named firefox.exe was found!
                      No active process named msnmsgr.exe was found!
                      No active process named Teatimer.exe was found!
                      ========== OTL ==========
                      Prefs.js: "Web Search..." removed from browser.search.defaultenginename
                      Registry key HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Internet Explorer\Restrictions\ deleted successfully.
                      ========== REGISTRY ==========
                      Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
                      Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\nwiz deleted successfully.
                      ========== FILES ==========
                      C:\WINDOWS\System32\dllcache\mstsc.exe moved successfully.
                      C:\WINDOWS\System32\Uninstall.ico moved successfully.
                      ========== COMMANDS ==========

                      [EMPTYTEMP]

                      User: All Users

                      User: Default User
                      ->Temp folder emptied: 0 bytes
                      ->Temporary Internet Files folder emptied: 67 bytes

                      User: LocalService
                      ->Temp folder emptied: 65748 bytes
                      ->Temporary Internet Files folder emptied: 33170 bytes
                      ->Java cache emptied: 0 bytes
                      ->Flash cache emptied: 1527 bytes

                      User: NetworkService
                      ->Temp folder emptied: 0 bytes
                      ->Temporary Internet Files folder emptied: 33170 bytes
                      ->Java cache emptied: 14 bytes
                      ->Flash cache emptied: 1732 bytes

                      User: sha'a
                      ->Temp folder emptied: 21607 bytes
                      ->Temporary Internet Files folder emptied: 33170 bytes
                      ->Java cache emptied: 0 bytes
                      ->FireFox cache emptied: 48599823 bytes
                      ->Flash cache emptied: 1506 bytes

                      %systemdrive% .tmp files removed: 0 bytes
                      %systemroot% .tmp files removed: 2134506 bytes
                      %systemroot%\System32 .tmp files removed: 3072 bytes
                      %systemroot%\System32\dllcache .tmp files removed: 0 bytes
                      %systemroot%\System32\drivers .tmp files removed: 0 bytes
                      Windows Temp folder emptied: 32768 bytes
                      %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
                      %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
                      RecycleBin emptied: 0 bytes

                      Total Files Cleaned = 49,00 mb

                      OTL by OldTimer - Version 3.2.17.3 log created on 11192010_123418

                      Files\Folders moved on Reboot...
                      File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                      File\Folder C:\WINDOWS\temp\JET5544.tmp not found!
                      File\Folder C:\WINDOWS\temp\JET5582.tmp not found!
                      File move failed. C:\WINDOWS\temp\Perflib_Perfdata_590.dat scheduled to be moved on reboot.

                      Registry entries deleted on Reboot...
                      0
                      1. DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!! (car l'outil est detecté a tort comme infection contenant un module qui sert à arrêter des processus , et un autre servant à prendre des droits dans le registre pour effectuer des suppressions)

                        ▶ Télécharge ici :List_Kill'em

                        et enregistre le sur ton bureau

                        si tu as XP => double clique
                        si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                        sur le raccourci sur ton bureau pour lancer l'installation

                        Laisse coché :

                        ♦ Executer List_Kill'em

                        une fois terminée , clic sur "terminer" et le programme se lancera seul

                        Il commencera par telecharger et installer ses mises à jour , puis te donnera son menu

                        choisis l'option Search

                        ▶ laisse travailler l'outil

                        il se peut qu'une boite de dialogue s'ouvre , dans ce cas clique sur "ok" ou "Agree"

                        à l'apparition de la fenetre blanche , c'est un peu long , c'est normal ,c'est une recherche supplementaire de fichiers cachés , le programme n'est pas bloqué.

                        ▶ Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                        ▶▶▶ NE LE POSTE PAS SUR LE FORUM

                        Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                        ▶ Clique sur Parcourir et cherche le fichier C:\List'em.txt

                        ▶ Clique sur Ouvrir.

                        ▶ Clique sur "Cliquez ici pour déposer le fichier".

                        Un lien de cette forme :

                        http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt

                        est ajouté dans la page.

                        ▶ Copie ce lien dans ta réponse.

                        ▶ Fais de même avec more.txt qui se trouve sur ton bureau
                        0
                        1. http://www.cijoint.fr/cjlink.php?file=cj201011/cijws4o4cg.txt

                          http://www.cijoint.fr/cjlink.php?file=cj201011/cijjJRO49i.txt

                          Voila... et merci pour ton aide
                          0
                          1. si tu as XP => double clique
                            si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                            ▶ Relance List_Kill'em,avec le raccourci sur ton bureau.

                            mais cette fois-ci :

                            ▶ choisis l'Option Clean

                            ▶▶▶ Ne clique qu'une seule fois sur le bouton !!

                            laisse travailler l'outil.

                            en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                            ▶ colle le contenu dans ta reponse
                            0
                            1. ¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.2.0 ¤¤¤¤¤¤¤¤¤¤

                              User : sha'a (Administrateurs)
                              Update on 18/11/2010 by g3n-h@ckm@n ::::: 11.00
                              Start at: 13:22:37 | 19/11/2010

                              Processeur Intel Pentium III Xeon
                              Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                              Internet Explorer 8.0.6001.18702
                              Windows Firewall Status : Disabled
                              AV : avast! antivirus 4.8.1368 [VPS 101119-0] 4.8.1368 [ (!) Disabled | Updated ]

                              A:\ -> Lecteur de disquettes 3 ½ pouces
                              C:\ -> Disque fixe local | 30,07 Go (20,65 Go free) | NTFS
                              D:\ -> Disque fixe local | 118,97 Go (40,21 Go free) [D] | NTFS
                              E:\ -> Disque CD-ROM
                              F:\ -> Disque amovible
                              G:\ -> Disque amovible
                              H:\ -> Disque amovible
                              I:\ -> Disque amovible

                              ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                              ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

                              127.0.0.1 localhost

                              ¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤

                              ¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                              Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                              Local Page = C:\WINDOWS\system32\blank.htm
                              Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                              Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                              Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                              Start Page = https://www.google.com/?gws_rd=ssl
                              Local Page = C:\WINDOWS\system32\blank.htm
                              Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                              ¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                              FirstRunDisabled = 1 (0x1)
                              AntiVirusDisableNotify = 0 (0x0)
                              FirewallDisableNotify = 0 (0x0)
                              UpdatesDisableNotify = 0 (0x0)
                              AntiVirusOverride = 0 (0x0)
                              FirewallOverride = 0 (0x0)

                              ¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤

                              Ndisuio : Start = 3
                              EapHost : Start = 2
                              Ip6Fw : Start = 2
                              SharedAccess : Start = 2
                              wuauserv : Start = 2
                              wscsvc : Start = 2

                              ¤¤¤¤¤¤¤¤¤¤ Winlogon

                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
                              Shell = explorer.exe
                              Userinit = C:\WINDOWS\System32\userinit.exe,

                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                              Disk Cleaned
                              anti-ver blaster : OK
                              Prefetch cleaned
                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                              FEATURE_BROWSER_EMULATION | svchost :
                              ====================================

                              Deleted : HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION : svchost.exe

                              Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
                              Windows 5.1.2600 Disk: SAMSUNG_HD161HJ rev.JF100-19 -> Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-6

                              device: opened successfully
                              user: MBR read successfully

                              Disk trace:
                              called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys spsm.sys >>UNKNOWN [0x89E04938]<<
                              spsm.sys
                              1 ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Harddisk0\DR0[0x89DAAAB8]
                              3 CLASSPNP[0xB80E8FD7] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\00000064[0x89E213B0]
                              5 ACPI[0xB7E73620] -> ntkrnlpa!IofCallDriver[0x804EF1A6] -> \Device\Ide\IdeDeviceP2T0L0-6[0x89E216A8]
                              kernel: MBR read successfully
                              user & kernel MBR OK
                              copy of MBR has been found in sector 9 !

                              End of Scan : 13:23:07,00

                              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                              0
                              1. si tu as XP => double clique
                                si tu as Vista ou windows 7 => clic droit "executer en tant que...."


                                ▶ Relance List&Kill'em,avec le raccourci sur ton bureau.

                                mais cette fois-ci :

                                ▶ choisis l'option Script

                                une fenêtre noire va s'ouvrir brievement , et List_Kill'em va se fermer

                                observe ton bureau une icône "Script" s'est rajouté sur ton bureau

                                ▶ crée un nouveau document texte sur ton bureau et copie/colle ce en gras si dessous :


                                FILE:C:\WINDOWS\Temp\JET49E9.tmp
                                REM:"HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{0E5CBF21-D15F-11D0-8301-00AA005B4383}"
                                REM:"HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDrives"
                                REM:"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDrives"


                                ▶ enregistre le document texte avec l'onglet fichier (enregistrer) de ce dernier , puis ferme-le

                                ▶ effectue un glisser/deposer de ce fichier sur l'icone "Script"

                                laisse travailler l'outil

                                poste le resultat

                                ▶ Ferme List_Kill'em

                                Note : le rapport est sur ton bureau : Script_(4 chiffres).txt
                                0
                                1. ¤¤¤¤¤¤¤¤¤¤ Script of List_Kill'em by gen-hackman ¤¤¤¤¤¤¤¤¤¤

                                  User : sha'a (Administrateurs)
                                  Update on 18/11/2010 by g3n-h@ckm@n ::::: 11.00
                                  Start at: 13:41:47 | 19/11/2010

                                  Processeur Intel Pentium III Xeon
                                  Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                                  Internet Explorer 8.0.6001.18702
                                  Windows Firewall Status : Disabled
                                  AV : avast! antivirus 4.8.1368 [VPS 101119-0] 4.8.1368 [ (!) Disabled | Updated ]

                                  A:\ -> Lecteur de disquettes 3 ½ pouces
                                  C:\ -> Disque fixe local | 30,07 Go (20,59 Go free) | NTFS
                                  D:\ -> Disque fixe local | 118,97 Go (40,21 Go free) [D] | NTFS
                                  E:\ -> Disque CD-ROM
                                  F:\ -> Disque amovible
                                  G:\ -> Disque amovible
                                  H:\ -> Disque amovible
                                  I:\ -> Disque amovible

                                  Switch : "C:\Documents and Settings\sha'a\Bureau\Nouveau Document texte.txt"

                                  ¤¤¤¤¤¤¤¤¤¤ Processes

                                  ¤¤¤¤¤¤¤¤¤¤ Added Keys

                                  ¤¤¤¤¤¤¤¤¤¤ Removed Keys

                                  Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser" /v "{0E5CBF21-D15F-11D0-8301-00AA005B4383}
                                  Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDrives
                                  Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer" /v "NoDrives"

                                  ¤¤¤¤¤¤¤¤¤¤ File|Folder deleted

                                  ¤¤¤¤¤¤¤¤¤¤ Drivers deleted

                                  ¤¤¤¤¤¤¤¤¤¤ Object Restored

                                  ¤¤¤¤¤¤¤¤¤¤ Folder List

                                  ¤¤¤¤¤¤¤¤¤¤ Read File

                                  ¤¤¤¤¤¤¤¤¤¤ Sign control

                                  ¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤
                                  0
                                  1. refais un scan avast et poste le rapport stp
                                    0
                                    1. En général je fais les scan avec Malwarebytes, je le fais quand même qu'avec Avast ?
                                      0
                                      • 1
                                      • 2
                                      • 3