Virus Cycbot.b

asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention   -  
asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention   -
Bonjour,

Windows Defender a détecté Cycbot.b et il n'arrive pas à le supprimer, Avira n'arrive pas à le détecter tout. Est-il possible de m'aider à le supprimer.

Merci !

60 réponses

  • 1
  • 2
  • 3
Résumé de la discussion

Problème central: Windows Defender détecte Cycbot.b et ne peut pas le supprimer; Avira ne le détecte pas non plus, ce qui complique le nettoyage et nécessite des outils dédiés.
Plusieurs solutions proposées ciblent le nettoyage grâce à des outils spécialisés comme ComboFix et des analyses via VirusTotal, avec instructions spécifiques et précautions pour désactiver temporairement la protection en place.
En cas d’infection, des éléments pratiques incluent l’analyse de fichiers sur VirusTotal, l’exécution d’outils tels qu’OTL et ComboFix, et la vérification du Master Boot Record pour repérer les composants persistants.
Le dernier volet évoque l’obtention de rapports détaillés après redémarrage, utiles pour confirmer la suppression, vérifier l’absence de rémanence et localiser d’éventuels restes à traiter par la suite.

Généré automatiquement par IA
sur la base des meilleures réponses
  1. gen-hackman
     
    salut :

    lance ceci et poste rapport.txt qui apparaitra sur ton bureau en fin de scan

    http://dl.dropbox.com/u/21363431/Pre_Scan.exe
    0
  2. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
     
    Salut,

    j'ai lancé ton programme et là d'un coup j'ai eu un écran bleu indiquant que si je vois cet écran pour la première fois c'est que mon ordi a été attaqué de façon grave et puis mon ordi a fait un son bizarre et a redemarré. Sincérement, j'ai peur de relancer le programme est-ce que je dois le relancer tout de même ?
    0
  3. gen-hackman
     
    c'est à cause de l infection....elle le bloque...


    /!\ ATTENTION SUIVRE A LA LETTRE CES INDICATIONS/!\

    __________________________________________________________
    >Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.<
    >>>>>>>Ne pas utiliser en dehors de ce cas de figure : dangereux!<<<<<<<<
    =====================================================


    ▶ Surtout , pense à l'enregistrement à renommer Combofix en "ton prenom.exe" avant qu'il soit enregistré sur ton disque dur

    Telecharge ici : Combofix

    Avant d'utiliser ComboFix :

    Si tu utilises AVG, IL FAUT IMPERATIVEMENT LE DESINSTALLER avant d'utiliser Combofix car il peut causer des dégâts en interaction avec l'outil pouvant mener à la réinstallation totale du système.
    La simple désactivation du résident n'est pas suffisante.
    Télécharge le désinstalleur d'AVG sur ce lien : https://www.avg.com/fr-fr/avg-remover
    Choisis la version adéquate (32 ou 64 bits)/!\

    Les logiciels d'émulation de CD comme Daemon Tools peuvent gêner les outils de désinfection. Utilise Defogger pour les désactiver temporairement :

    ▶ Télécharge Defogger (de jpshortstuff) sur ton Bureau

    ▶ Lance le

    Une fenêtre apparait : clique sur "Disable"

    ▶ Fais redémarrer l'ordinateur si l'outil te le demande

    Note : Quand nous aurons terminé la désinfection, tu pourras réactiver ces logiciels en relançant Defogger et en cliquant sur "Re-enable"

    _________________________________________________________
    >> referme les fenêtres de tous les programmes en cours.
    >> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix,
    >>la protection en temps réel de ton Antivirus et de tes Antispywares,
    >>qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    °°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°°


    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur combofix renommé

    ¤¤¤¤¤¤¤¤¤¤ LAISSE-LE INSTALLER LA CONSOLE DE RECUPERATION S'IL TE LE DEMANDE ¤¤¤¤¤¤¤¤¤¤

    ▶ !!!!!NE TOUCHE A RIEN PENDANT LE TRAVAIL DE COMBOFIX (SOURIS/CLAVIER.....)!!!!!

    ▶ n'oublie pas de reactiver la garde de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    ▶▶ Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

    0
  4. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
     
    je n'ai pas pu lancer Defogger une fenêtre me dit que Defogger.exe n'est pas une application Win32 valide. Dois-je me passer de cet outil et désinstaller Daemon Tools puis lancer combofix ?
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
     
    voilà j'ai désinstallé Daemon Tools et lancer Combofix voici le rapport :

    ComboFix 11-03-27.02 - Asma 2011-03-28 11:40:00.1.2 - x64
    Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6002.2.1252.2.1036.18.3998.1981 [GMT -4:00]
    Lancé depuis: c:\users\Asma\Desktop\asmuss.exe
    AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
    SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\users\Asma\AppData\Roaming\dwm.exe
    c:\users\Asma\AppData\Roaming\Microsoft\conhost.exe
    c:\users\Asma\g2mdlhlpx.exe
    c:\windows\system32\AutoRun.inf
    c:\windows\SysWow64\Ijl11.dll
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-02-28 au 2011-03-28 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-03-28 15:54 . 2011-03-28 15:54 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-03-28 14:47 . 2011-03-28 14:47 -------- d-----w- C:\Temp
    2011-03-25 11:11 . 2011-03-15 05:17 8424784 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DB266E10-6CDD-4BBD-A965-F8D53A9A2DCB}\mpengine.dll
    2011-03-25 09:58 . 2011-03-27 10:04 174344 ----a-w- c:\temp\KK.exe
    2011-03-23 11:24 . 2011-02-22 13:53 1149440 ----a-w- c:\windows\system32\FntCache.dll
    2011-03-23 11:24 . 2011-02-22 14:47 479744 ----a-w- c:\windows\system32\XpsGdiConverter.dll
    2011-03-23 11:24 . 2011-02-22 14:13 288768 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
    2011-03-23 11:24 . 2011-02-22 13:53 1555968 ----a-w- c:\windows\system32\DWrite.dll
    2011-03-23 11:24 . 2011-02-22 13:33 1068544 ----a-w- c:\windows\SysWow64\DWrite.dll
    2011-03-21 22:56 . 2011-03-21 22:56 -------- d-----w- c:\users\Asma\AppData\Roaming\Downloaded Installations
    2011-03-20 02:31 . 2011-03-20 22:52 -------- d-----w- C:\WinSetupFromUSB
    2011-03-20 01:08 . 2011-03-20 22:51 -------- d-----w- C:\pebuilder3110a
    2011-03-19 21:12 . 2011-03-19 21:12 -------- d-----w- c:\users\Asma\AppData\Local\eMule
    2011-03-17 16:05 . 2011-03-20 00:41 -------- d-----w- c:\program files (x86)\Citrix
    2011-03-17 16:04 . 2011-03-17 16:04 -------- d-----w- c:\users\Asma\AppData\Local\Apps
    2011-03-17 16:04 . 2011-03-17 16:16 -------- d-----w- c:\users\Asma\AppData\Local\Deployment
    2011-03-10 01:15 . 2011-03-10 01:15 -------- d-----w- c:\program files (x86)\Common Files\Skype
    2011-03-09 19:04 . 2010-12-17 17:34 2425344 ----a-w- c:\windows\system32\mstscax.dll
    2011-03-09 19:04 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\SysWow64\mstscax.dll
    2011-03-09 19:04 . 2010-12-17 15:41 731136 ----a-w- c:\windows\system32\mstsc.exe
    2011-03-09 19:04 . 2010-12-17 13:54 677888 ----a-w- c:\windows\SysWow64\mstsc.exe
    2011-03-09 19:04 . 2010-12-29 19:01 416768 ----a-w- c:\windows\system32\sbe.dll
    2011-03-09 19:04 . 2010-12-29 19:01 559616 ----a-w- c:\windows\system32\EncDec.dll
    2011-03-09 19:04 . 2010-12-29 18:59 226816 ----a-w- c:\windows\system32\mpg2splt.ax
    2011-03-09 19:04 . 2010-12-29 18:28 322560 ----a-w- c:\windows\SysWow64\sbe.dll
    2011-03-09 19:04 . 2010-12-29 18:28 153088 ----a-w- c:\windows\SysWow64\sbeio.dll
    2011-03-09 19:04 . 2010-12-29 18:28 429056 ----a-w- c:\windows\SysWow64\EncDec.dll
    2011-03-09 19:04 . 2010-12-29 18:26 177664 ----a-w- c:\windows\SysWow64\mpg2splt.ax
    2011-03-09 19:04 . 2010-12-29 19:01 210944 ----a-w- c:\windows\system32\sbeio.dll
    2011-03-08 02:02 . 2011-03-08 02:24 -------- d-----w- C:\TYPSoft FTP Server
    2011-03-08 00:02 . 2011-03-08 00:03 -------- d-----w- c:\program files (x86)\FileZilla FTP Client
    2011-03-07 23:47 . 2011-03-07 23:47 -------- d-----w- c:\program files (x86)\Common Files\Java
    2011-03-07 22:26 . 2011-03-08 02:30 -------- d-----w- c:\users\Asma\AppData\Roaming\FileZilla
    2011-03-07 22:02 . 2011-03-08 00:08 -------- d-----w- c:\program files (x86)\FileZilla Server
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-03-12 14:20 . 2010-06-24 15:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2011-02-03 02:40 . 2010-05-01 23:13 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
    2011-02-02 22:11 . 2009-10-13 11:07 270720 ------w- c:\windows\system32\MpSigStub.exe
    2011-01-20 16:46 . 2011-02-10 02:08 900480 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
    2011-01-20 16:17 . 2011-02-10 02:08 366592 ----a-w- c:\windows\system32\winspool.drv
    2011-01-20 16:17 . 2011-02-10 02:08 625152 ----a-w- c:\windows\system32\dxgi.dll
    2011-01-20 16:16 . 2011-02-10 02:08 287232 ----a-w- c:\windows\system32\d3d10core.dll
    2011-01-20 16:16 . 2011-02-10 02:08 327680 ----a-w- c:\windows\system32\d3d10_1core.dll
    2011-01-20 16:16 . 2011-02-10 02:08 196096 ----a-w- c:\windows\system32\d3d10_1.dll
    2011-01-20 16:16 . 2011-02-10 02:08 1268224 ----a-w- c:\windows\system32\d3d10.dll
    2011-01-20 16:16 . 2011-02-10 02:08 748544 ----a-w- c:\windows\system32\stobject.dll
    2011-01-20 16:16 . 2011-02-10 02:08 47104 ----a-w- c:\windows\system32\cdd.dll
    2011-01-20 16:16 . 2011-02-10 02:08 3548672 ----a-w- c:\windows\system32\mf.dll
    2011-01-20 16:16 . 2011-02-10 02:08 35840 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
    2011-01-20 16:14 . 2011-02-10 02:08 278528 ----a-w- c:\windows\system32\mfplat.dll
    2011-01-20 16:14 . 2011-02-10 02:08 195072 ----a-w- c:\windows\system32\mfps.dll
    2011-01-20 16:08 . 2011-02-10 02:08 478720 ----a-w- c:\windows\SysWow64\dxgi.dll
    2011-01-20 16:08 . 2011-02-10 02:08 219648 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
    2011-01-20 16:08 . 2011-02-10 02:08 160768 ----a-w- c:\windows\SysWow64\d3d10_1.dll
    2011-01-20 16:08 . 2011-02-10 02:08 1029120 ----a-w- c:\windows\SysWow64\d3d10.dll
    2011-01-20 16:08 . 2011-02-10 02:08 189952 ----a-w- c:\windows\SysWow64\d3d10core.dll
    2011-01-20 16:07 . 2011-02-10 02:08 258048 ----a-w- c:\windows\SysWow64\winspool.drv
    2011-01-20 16:07 . 2011-02-10 02:08 586240 ----a-w- c:\windows\SysWow64\stobject.dll
    2011-01-20 16:06 . 2011-02-10 02:08 2873344 ----a-w- c:\windows\SysWow64\mf.dll
    2011-01-20 16:04 . 2011-02-10 02:08 209920 ----a-w- c:\windows\SysWow64\mfplat.dll
    2011-01-20 16:04 . 2011-02-10 02:08 98816 ----a-w- c:\windows\SysWow64\mfps.dll
    2011-01-20 15:01 . 2011-02-10 02:08 3068416 ----a-w- c:\windows\system32\xpsservices.dll
    2011-01-20 15:01 . 2011-02-10 02:08 1653760 ----a-w- c:\windows\system32\XpsPrint.dll
    2011-01-20 14:59 . 2011-02-10 02:08 1032192 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
    2011-01-20 14:58 . 2011-02-10 02:08 1461760 ----a-w- c:\windows\system32\OpcServices.dll
    2011-01-20 14:57 . 2011-02-10 02:08 231936 ----a-w- c:\windows\system32\XpsRasterService.dll
    2011-01-20 14:42 . 2011-02-10 02:08 1257984 ----a-w- c:\windows\system32\MFH264Dec.dll
    2011-01-20 14:41 . 2011-02-10 02:08 428544 ----a-w- c:\windows\system32\MFHEAACdec.dll
    2011-01-20 14:40 . 2011-02-10 02:08 345088 ----a-w- c:\windows\system32\mfreadwrite.dll
    2011-01-20 14:40 . 2011-02-10 02:08 34304 ----a-w- c:\windows\system32\mfpmp.exe
    2011-01-20 14:40 . 2011-02-10 02:08 377344 ----a-w- c:\windows\system32\mfmp4src.dll
    2011-01-20 14:37 . 2011-02-10 02:08 2002944 ----a-w- c:\windows\system32\d3d10warp.dll
    2011-01-20 14:35 . 2011-02-10 02:08 566272 ----a-w- c:\windows\system32\d3d10level9.dll
    2011-01-20 14:28 . 2011-02-10 02:08 1554432 ----a-w- c:\windows\SysWow64\xpsservices.dll
    2011-01-20 14:27 . 2011-02-10 02:08 876032 ----a-w- c:\windows\SysWow64\XpsPrint.dll
    2011-01-20 14:25 . 2011-02-10 02:08 847360 ----a-w- c:\windows\SysWow64\OpcServices.dll
    2011-01-20 14:24 . 2011-02-10 02:08 135680 ----a-w- c:\windows\SysWow64\XpsRasterService.dll
    2011-01-20 14:15 . 2011-02-10 02:08 979456 ----a-w- c:\windows\SysWow64\MFH264Dec.dll
    2011-01-20 14:14 . 2011-02-10 02:08 357376 ----a-w- c:\windows\SysWow64\MFHEAACdec.dll
    2011-01-20 14:14 . 2011-02-10 02:08 302592 ----a-w- c:\windows\SysWow64\mfmp4src.dll
    2011-01-20 14:14 . 2011-02-10 02:08 261632 ----a-w- c:\windows\SysWow64\mfreadwrite.dll
    2011-01-20 14:12 . 2011-02-10 02:08 1172480 ----a-w- c:\windows\SysWow64\d3d10warp.dll
    2011-01-20 14:11 . 2011-02-10 02:08 486400 ----a-w- c:\windows\SysWow64\d3d10level9.dll
    2011-01-20 14:06 . 2011-02-10 02:08 834048 ----a-w- c:\windows\system32\d2d1.dll
    2011-01-20 13:47 . 2011-02-10 02:08 683008 ----a-w- c:\windows\SysWow64\d2d1.dll
    2011-01-08 09:03 . 2011-02-10 02:07 48128 ----a-w- c:\windows\system32\atmlib.dll
    2011-01-08 08:47 . 2011-02-10 02:07 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
    2011-01-08 06:45 . 2011-02-10 02:07 367104 ----a-w- c:\windows\system32\atmfd.dll
    2011-01-08 06:28 . 2011-02-10 02:07 292352 ----a-w- c:\windows\SysWow64\atmfd.dll
    2011-01-03 21:21 . 2011-01-03 21:21 62701672 ----a-w- c:\users\Asma\AVSVideoConverter.exe
    2010-12-31 14:16 . 2011-02-10 02:08 2757632 ----a-w- c:\windows\system32\win32k.sys
    2010-12-28 16:08 . 2011-01-12 06:25 466944 ----a-w- c:\windows\system32\odbc32.dll
    .
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-14 39408]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
    "HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-08-26 1644088]
    "ooVoo.exe"="c:\program files (x86)\ooVoo\oovoo.exe" [2011-01-25 22504120]
    "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-01-26 15026056]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "DVDAgent"="c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-09-26 1148200]
    "TSMAgent"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-09-26 1152296]
    "CLMLServer for HP TouchSmart"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-09-26 189736]
    "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
    "QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-02 202032]
    "UpdatePDIRShortCut"="c:\program files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
    "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
    "TVAgent"="c:\program files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-04-23 206120]
    "HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
    "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-18 421888]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-04-28 142120]
    "WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744]
    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    "FileZilla Server Interface"="c:\program files (x86)\FileZilla Server\FileZilla Server Interface.exe" [2010-10-17 1259008]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
    Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-1-17 1207312]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    R2 Application Policy Service;Application Policy Service;c:\windows\SysWOW64\config\systemprofile\AppData\Local\Application Policy Service\svchost.exe [2011-03-27 449894]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Service Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
    R3 NETw3v64;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw3v64.sys [x]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
    R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
    R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk60x64.sys [x]
    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
    S2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2008-09-26 27632]
    S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\AESTSr64.exe [x]
    S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 27648]
    S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
    S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
    S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files (x86)\SMINST\BLService.exe [2008-10-06 365952]
    S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [x]
    S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2009-04-23 296320]
    S2 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2009-04-23 116104]
    S3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
    S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x]
    S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]
    .
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    Akamai REG_MULTI_SZ Akamai
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2008-06-09 17:14 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-02 00:07]
    .
    2011-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-02 00:07]
    .
    2011-03-07 c:\windows\Tasks\HPCeeScheduleForAsma.job
    - c:\program files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe [2008-11-04 19:34]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender"="%ProgramFiles%\Windows Defender\MSASCui.exe -hide" [X]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1533736]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
    "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-07-22 450048]
    "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 161304]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "LoadAppInit_DLLs"=0x0
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.ca/
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyServer = http=127.0.0.1:53293
    uInternet Settings,ProxyOverride = *.local;<local>
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
    FF - ProfilePath - c:\users\Asma\AppData\Roaming\Mozilla\Firefox\Profiles\r25ex48o.default\
    FF - prefs.js: browser.startup.homepage - hxxp://fr.msn.com/
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 53293
    FF - prefs.js: network.proxy.type - 1
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
    FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\users\Asma\AppData\Roaming\Move Networks
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
    .
    - - - - ORPHELINS SUPPRIMES - - - -
    .
    Wow6432Node-HKCU-Run-conhost - c:\users\Asma\AppData\Roaming\Microsoft\conhost.exe
    Wow6432Node-HKLM-Run-conhost - c:\users\Asma\AppData\Roaming\Microsoft\conhost.exe
    WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    HKLM-Run-SmartMenu - %ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
    .
    .
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySQL]
    "ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
    "ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_USERS\S-1-5-21-1502214498-3565008414-2400695767-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.Email.1"
    .
    [HKEY_USERS\S-1-5-21-1502214498-3565008414-2400695767-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.VCard.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
    @="Shockwave Flash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
    @Denied: (A 2) (Everyone)
    @=""
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
    @="FlashBroker"
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    Heure de fin: 2011-03-28 12:16:26
    ComboFix-quarantined-files.txt 2011-03-28 16:16
    .
    Avant-CF: 38 148 198 400 octets libres
    Après-CF: 40 470 061 056 octets libres
    .
    - - End Of File - - 4E43E88A5051BA47ED5D2551C89D4CA2
    0
  7. gen-hackman
     

    __________________________________________________
    =>/!\Le script qui suit a été écrit spécialement cet ordinateur/!\ <=
    =>il est fort déconseillé de le transposer sur un autre ordinateur !<=
    ----------------------------------------------------------------------------


    Toujours avec toutes les protections désactivées, fais ceci :

    ▶ Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
    ▶ Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

    ----------------------------------------------------------
    KillAll::

    File::
    c:\temp\KK.exe

    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "HP Software Update"=-
    "QuickTime Task"=-
    "iTunesHelper"=-
    "Adobe Reader Speed Launcher"=-
    "SunJavaUpdateSched"=-

    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:53293
    uInternet Settings,ProxyOverride = *.local;<local>

    Firefox::
    FF - prefs.js: network.proxy.http_port - 53293
    FF - prefs.js: network.proxy.type - 1

    RegLock::
    [HKEY_USERS\S-1-5-21-1502214498-3565008414-2400695767-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
    [HKEY_USERS\S-1-5-21-1502214498-3565008414-2400695767-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] => Macromedia Shockwave Flash
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] => Macromedia Shockwave Flash
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] => Macromedia Shockwave Flash
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

    MBR::

    ------------------------------------------------------------------

    ▶ Enregistre ce fichier sur ton Bureau (et pas ailleurs !) sous le nom CFScript.txt
    ▶ Quitte le Bloc Notes

    ▶ Fais un glisser/déposer de ce fichier CFScript sur le fichier combofix

    ▶ Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
    ▶ Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
    ▶ Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt

    0
  8. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
     
    j'ai fait comme tu mas dit mais mon ordi s'est mis en veille avec un arrêt du disque dur (ça fait 1h45 que j'ai lancé combofix) lorsque j'ai appuyé sur une touche, l'écran bleu était encore là mais comme si aucun programme n'était en cours d'exécution est-ce que je relance combofix sachant que le fichier CScript.txt
    a disparu de mon bureau. Est-ce que j'aurai dû laisser mon ordi en veille dans ce cas bien que il semblait au repos et qu'aucun programme ne semblait être exécuté

    Merci
    0
  9. gen-hackman
     
    refais un CFScript avec juste ca dedans :

    SkipFix::
    0
  10. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
     
    ComboFix 11-03-27.02 - Asma 2011-03-28 16:46:43.2.2 - x64
    Microsoft® Windows Vista(TM) Édition Familiale Premium 6.0.6002.2.1252.2.1036.18.3998.2134 [GMT -4:00]
    Lancé depuis: c:\users\Asma\Desktop\asmuss.exe
    Commutateurs utilisés :: c:\users\Asma\Desktop\CFScript.txt
    AV: AntiVir Desktop *Disabled/Updated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
    SP: AntiVir Desktop *Disabled/Updated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    - Mode FONCTIONNALITES REDUITES -
    .
    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2011-02-28 au 2011-03-28 ))))))))))))))))))))))))))))))))))))
    .
    .
    2011-03-28 20:48 . 2011-03-28 20:48 -------- d-----w- c:\users\Default\AppData\Local\temp
    2011-03-28 15:35 . 2011-03-28 16:16 -------- d-----w- C:\asmuss
    2011-03-28 14:47 . 2011-03-28 14:47 -------- d-----w- C:\Temp
    2011-03-25 11:11 . 2011-03-15 05:17 8424784 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{DB266E10-6CDD-4BBD-A965-F8D53A9A2DCB}\mpengine.dll
    2011-03-25 09:58 . 2011-03-27 10:04 174344 ----a-w- c:\temp\KK.exe
    2011-03-23 11:24 . 2011-02-22 13:53 1149440 ----a-w- c:\windows\system32\FntCache.dll
    2011-03-23 11:24 . 2011-02-22 14:47 479744 ----a-w- c:\windows\system32\XpsGdiConverter.dll
    2011-03-23 11:24 . 2011-02-22 14:13 288768 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll
    2011-03-23 11:24 . 2011-02-22 13:53 1555968 ----a-w- c:\windows\system32\DWrite.dll
    2011-03-23 11:24 . 2011-02-22 13:33 1068544 ----a-w- c:\windows\SysWow64\DWrite.dll
    2011-03-21 22:56 . 2011-03-21 22:56 -------- d-----w- c:\users\Asma\AppData\Roaming\Downloaded Installations
    2011-03-20 02:31 . 2011-03-20 22:52 -------- d-----w- C:\WinSetupFromUSB
    2011-03-20 01:08 . 2011-03-20 22:51 -------- d-----w- C:\pebuilder3110a
    2011-03-19 21:12 . 2011-03-19 21:12 -------- d-----w- c:\users\Asma\AppData\Local\eMule
    2011-03-17 16:05 . 2011-03-20 00:41 -------- d-----w- c:\program files (x86)\Citrix
    2011-03-17 16:04 . 2011-03-17 16:04 -------- d-----w- c:\users\Asma\AppData\Local\Apps
    2011-03-17 16:04 . 2011-03-17 16:16 -------- d-----w- c:\users\Asma\AppData\Local\Deployment
    2011-03-10 01:15 . 2011-03-10 01:15 -------- d-----w- c:\program files (x86)\Common Files\Skype
    2011-03-09 19:04 . 2010-12-17 17:34 2425344 ----a-w- c:\windows\system32\mstscax.dll
    2011-03-09 19:04 . 2010-12-17 15:45 2067968 ----a-w- c:\windows\SysWow64\mstscax.dll
    2011-03-09 19:04 . 2010-12-17 15:41 731136 ----a-w- c:\windows\system32\mstsc.exe
    2011-03-09 19:04 . 2010-12-17 13:54 677888 ----a-w- c:\windows\SysWow64\mstsc.exe
    2011-03-09 19:04 . 2010-12-29 19:01 416768 ----a-w- c:\windows\system32\sbe.dll
    2011-03-09 19:04 . 2010-12-29 19:01 559616 ----a-w- c:\windows\system32\EncDec.dll
    2011-03-09 19:04 . 2010-12-29 18:59 226816 ----a-w- c:\windows\system32\mpg2splt.ax
    2011-03-09 19:04 . 2010-12-29 18:28 322560 ----a-w- c:\windows\SysWow64\sbe.dll
    2011-03-09 19:04 . 2010-12-29 18:28 153088 ----a-w- c:\windows\SysWow64\sbeio.dll
    2011-03-09 19:04 . 2010-12-29 18:28 429056 ----a-w- c:\windows\SysWow64\EncDec.dll
    2011-03-09 19:04 . 2010-12-29 18:26 177664 ----a-w- c:\windows\SysWow64\mpg2splt.ax
    2011-03-09 19:04 . 2010-12-29 19:01 210944 ----a-w- c:\windows\system32\sbeio.dll
    2011-03-08 02:02 . 2011-03-08 02:24 -------- d-----w- C:\TYPSoft FTP Server
    2011-03-08 00:02 . 2011-03-08 00:03 -------- d-----w- c:\program files (x86)\FileZilla FTP Client
    2011-03-07 23:47 . 2011-03-07 23:47 -------- d-----w- c:\program files (x86)\Common Files\Java
    2011-03-07 22:26 . 2011-03-08 02:30 -------- d-----w- c:\users\Asma\AppData\Roaming\FileZilla
    2011-03-07 22:02 . 2011-03-08 00:08 -------- d-----w- c:\program files (x86)\FileZilla Server
    .
    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2011-03-12 14:20 . 2010-06-24 15:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    2011-02-03 02:40 . 2010-05-01 23:13 472808 ----a-w- c:\windows\SysWow64\deployJava1.dll
    2011-02-02 22:11 . 2009-10-13 11:07 270720 ------w- c:\windows\system32\MpSigStub.exe
    2011-01-20 16:46 . 2011-02-10 02:08 900480 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
    2011-01-20 16:17 . 2011-02-10 02:08 366592 ----a-w- c:\windows\system32\winspool.drv
    2011-01-20 16:17 . 2011-02-10 02:08 625152 ----a-w- c:\windows\system32\dxgi.dll
    2011-01-20 16:16 . 2011-02-10 02:08 287232 ----a-w- c:\windows\system32\d3d10core.dll
    2011-01-20 16:16 . 2011-02-10 02:08 327680 ----a-w- c:\windows\system32\d3d10_1core.dll
    2011-01-20 16:16 . 2011-02-10 02:08 196096 ----a-w- c:\windows\system32\d3d10_1.dll
    2011-01-20 16:16 . 2011-02-10 02:08 1268224 ----a-w- c:\windows\system32\d3d10.dll
    2011-01-20 16:16 . 2011-02-10 02:08 748544 ----a-w- c:\windows\system32\stobject.dll
    2011-01-20 16:16 . 2011-02-10 02:08 47104 ----a-w- c:\windows\system32\cdd.dll
    2011-01-20 16:16 . 2011-02-10 02:08 3548672 ----a-w- c:\windows\system32\mf.dll
    2011-01-20 16:16 . 2011-02-10 02:08 35840 ----a-w- c:\windows\system32\printfilterpipelineprxy.dll
    2011-01-20 16:14 . 2011-02-10 02:08 278528 ----a-w- c:\windows\system32\mfplat.dll
    2011-01-20 16:14 . 2011-02-10 02:08 195072 ----a-w- c:\windows\system32\mfps.dll
    2011-01-20 16:08 . 2011-02-10 02:08 478720 ----a-w- c:\windows\SysWow64\dxgi.dll
    2011-01-20 16:08 . 2011-02-10 02:08 219648 ----a-w- c:\windows\SysWow64\d3d10_1core.dll
    2011-01-20 16:08 . 2011-02-10 02:08 160768 ----a-w- c:\windows\SysWow64\d3d10_1.dll
    2011-01-20 16:08 . 2011-02-10 02:08 1029120 ----a-w- c:\windows\SysWow64\d3d10.dll
    2011-01-20 16:08 . 2011-02-10 02:08 189952 ----a-w- c:\windows\SysWow64\d3d10core.dll
    2011-01-20 16:07 . 2011-02-10 02:08 258048 ----a-w- c:\windows\SysWow64\winspool.drv
    2011-01-20 16:07 . 2011-02-10 02:08 586240 ----a-w- c:\windows\SysWow64\stobject.dll
    2011-01-20 16:06 . 2011-02-10 02:08 2873344 ----a-w- c:\windows\SysWow64\mf.dll
    2011-01-20 16:04 . 2011-02-10 02:08 209920 ----a-w- c:\windows\SysWow64\mfplat.dll
    2011-01-20 16:04 . 2011-02-10 02:08 98816 ----a-w- c:\windows\SysWow64\mfps.dll
    2011-01-20 15:01 . 2011-02-10 02:08 3068416 ----a-w- c:\windows\system32\xpsservices.dll
    2011-01-20 15:01 . 2011-02-10 02:08 1653760 ----a-w- c:\windows\system32\XpsPrint.dll
    2011-01-20 14:59 . 2011-02-10 02:08 1032192 ----a-w- c:\windows\system32\printfilterpipelinesvc.exe
    2011-01-20 14:58 . 2011-02-10 02:08 1461760 ----a-w- c:\windows\system32\OpcServices.dll
    2011-01-20 14:57 . 2011-02-10 02:08 231936 ----a-w- c:\windows\system32\XpsRasterService.dll
    2011-01-20 14:42 . 2011-02-10 02:08 1257984 ----a-w- c:\windows\system32\MFH264Dec.dll
    2011-01-20 14:41 . 2011-02-10 02:08 428544 ----a-w- c:\windows\system32\MFHEAACdec.dll
    2011-01-20 14:40 . 2011-02-10 02:08 345088 ----a-w- c:\windows\system32\mfreadwrite.dll
    2011-01-20 14:40 . 2011-02-10 02:08 34304 ----a-w- c:\windows\system32\mfpmp.exe
    2011-01-20 14:40 . 2011-02-10 02:08 377344 ----a-w- c:\windows\system32\mfmp4src.dll
    2011-01-20 14:37 . 2011-02-10 02:08 2002944 ----a-w- c:\windows\system32\d3d10warp.dll
    2011-01-20 14:35 . 2011-02-10 02:08 566272 ----a-w- c:\windows\system32\d3d10level9.dll
    2011-01-20 14:28 . 2011-02-10 02:08 1554432 ----a-w- c:\windows\SysWow64\xpsservices.dll
    2011-01-20 14:27 . 2011-02-10 02:08 876032 ----a-w- c:\windows\SysWow64\XpsPrint.dll
    2011-01-20 14:25 . 2011-02-10 02:08 847360 ----a-w- c:\windows\SysWow64\OpcServices.dll
    2011-01-20 14:24 . 2011-02-10 02:08 135680 ----a-w- c:\windows\SysWow64\XpsRasterService.dll
    2011-01-20 14:15 . 2011-02-10 02:08 979456 ----a-w- c:\windows\SysWow64\MFH264Dec.dll
    2011-01-20 14:14 . 2011-02-10 02:08 357376 ----a-w- c:\windows\SysWow64\MFHEAACdec.dll
    2011-01-20 14:14 . 2011-02-10 02:08 302592 ----a-w- c:\windows\SysWow64\mfmp4src.dll
    2011-01-20 14:14 . 2011-02-10 02:08 261632 ----a-w- c:\windows\SysWow64\mfreadwrite.dll
    2011-01-20 14:12 . 2011-02-10 02:08 1172480 ----a-w- c:\windows\SysWow64\d3d10warp.dll
    2011-01-20 14:11 . 2011-02-10 02:08 486400 ----a-w- c:\windows\SysWow64\d3d10level9.dll
    2011-01-20 14:06 . 2011-02-10 02:08 834048 ----a-w- c:\windows\system32\d2d1.dll
    2011-01-20 13:47 . 2011-02-10 02:08 683008 ----a-w- c:\windows\SysWow64\d2d1.dll
    2011-01-08 09:03 . 2011-02-10 02:07 48128 ----a-w- c:\windows\system32\atmlib.dll
    2011-01-08 08:47 . 2011-02-10 02:07 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
    2011-01-08 06:45 . 2011-02-10 02:07 367104 ----a-w- c:\windows\system32\atmfd.dll
    2011-01-08 06:28 . 2011-02-10 02:07 292352 ----a-w- c:\windows\SysWow64\atmfd.dll
    2011-01-03 21:21 . 2011-01-03 21:21 62701672 ----a-w- c:\users\Asma\AVSVideoConverter.exe
    2010-12-31 14:16 . 2011-02-10 02:08 2757632 ----a-w- c:\windows\system32\win32k.sys
    .
    .
    ((((((((((((((((((((((((((((( SnapShot@2011-03-28_15.55.47 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-01-21 02:23 . 2011-03-28 11:21 75068 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-01-21 02:23 . 2011-03-28 20:15 75068 c:\windows\system32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2009-08-12 20:45 . 2011-03-28 20:15 18308 c:\windows\system32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1502214498-3565008414-2400695767-1000_UserData.bin
    + 2009-08-12 21:35 . 2011-03-28 16:22 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-08-12 21:35 . 2011-03-28 14:48 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2009-08-12 21:35 . 2011-03-28 16:22 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-08-12 21:35 . 2011-03-28 11:25 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2009-08-12 21:35 . 2011-03-28 11:25 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-08-12 21:35 . 2011-03-28 16:22 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-11-26 16:32 . 2011-03-28 20:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-11-26 16:32 . 2011-03-28 14:48 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2009-11-26 16:32 . 2011-03-28 14:48 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2009-11-26 16:32 . 2011-03-28 20:13 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2011-03-28 20:13 . 2011-03-28 20:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    - 2011-03-28 11:18 . 2011-03-28 14:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2011-03-28 20:13 . 2011-03-28 20:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2011-03-28 11:18 . 2011-03-28 14:48 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    + 2009-08-14 03:04 . 2011-03-28 20:11 969038 c:\windows\system32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
    + 2006-11-02 15:45 . 2011-03-28 20:15 155468 c:\windows\system32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2009-08-12 22:45 . 2011-03-28 16:22 245760 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    - 2009-08-12 22:45 . 2011-03-28 02:21 245760 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
    + 2010-11-11 03:45 . 2011-03-28 20:12 471080 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    - 2010-11-11 03:45 . 2011-03-28 03:06 471080 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
    - 2009-08-12 21:58 . 2011-03-28 03:06 4453232 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
    + 2009-08-12 21:58 . 2011-03-28 20:12 4453232 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
    .
    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-08-14 39408]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 138240]
    "HPADVISOR"="c:\program files (x86)\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2009-08-26 1644088]
    "ooVoo.exe"="c:\program files (x86)\ooVoo\oovoo.exe" [2011-01-25 22504120]
    "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2011-01-26 15026056]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "DVDAgent"="c:\program files (x86)\Hewlett-Packard\Media\DVD\DVDAgent.exe" [2008-09-26 1148200]
    "TSMAgent"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe" [2008-09-26 1152296]
    "CLMLServer for HP TouchSmart"="c:\program files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe" [2008-09-26 189736]
    "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
    "QlbCtrl.exe"="c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2008-08-02 202032]
    "UpdatePDIRShortCut"="c:\program files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" [2008-06-14 210216]
    "HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2007-03-12 49152]
    "TVAgent"="c:\program files (x86)\Hewlett-Packard\Media\TV\TVAgent.exe" [2009-04-23 206120]
    "HP Health Check Scheduler"="c:\program files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-10-09 75008]
    "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-03-18 421888]
    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2010-04-28 142120]
    "WirelessAssistant"="c:\program files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2009-07-23 498744]
    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
    "ArcSoft Connection Service"="c:\program files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2010-10-29 249064]
    "FileZilla Server Interface"="c:\program files (x86)\FileZilla Server\FileZilla Server Interface.exe" [2010-10-17 1259008]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files (x86)\Hp\Digital Imaging\bin\hpqtra08.exe [2007-3-11 210520]
    Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2010-1-17 1207312]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"
    .
    R2 Application Policy Service;Application Policy Service;c:\windows\SysWOW64\config\systemprofile\AppData\Local\Application Policy Service\svchost.exe [2011-03-27 449894]
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
    R2 gupdate;Service Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-02 135664]
    R3 NETw3v64;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\NETw3v64.sys [x]
    R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
    R3 WPFFontCache_v0400;Cache de police de Windows Presentation Foundation 4.0.0.0;c:\windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 1020768]
    R3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk60x64.sys [x]
    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
    S2 {55662437-DA8C-40c0-AADA-2C816A897A49};{55662437-DA8C-40c0-AADA-2C816A897A49};c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl [2008-09-26 27632]
    S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt64.inf_58be29c0\AESTSr64.exe [x]
    S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2008-01-21 27648]
    S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [2009-05-13 108289]
    S2 hpsrv;HP Service;c:\windows\system32\Hpservice.exe [x]
    S2 Recovery Service for Windows;Recovery Service for Windows;c:\program files (x86)\SMINST\BLService.exe [2008-10-06 365952]
    S2 SSPORT;SSPORT;c:\windows\system32\Drivers\SSPORT.sys [x]
    S2 TVCapSvc;TV Background Capture Service (TVBCS);c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVCapSvc.exe [2009-04-23 296320]
    S2 TVSched;TV Task Scheduler (TVTS);c:\program files (x86)\Hewlett-Packard\Media\TV\Kernel\TV\TVSched.exe [2009-04-23 116104]
    S3 Com4QLBEx;Com4QLBEx;c:\program files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840]
    S3 enecir;ENE CIR Receiver;c:\windows\system32\DRIVERS\enecir.sys [x]
    S3 IntcHdmiAddService;Intel(R) High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys [x]
    .
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    Akamai REG_MULTI_SZ Akamai
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    2008-06-09 17:14 451872 ----a-w- c:\program files (x86)\Common Files\LightScribe\LSRunOnce.exe
    .
    Contenu du dossier 'Tâches planifiées'
    .
    2011-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-02 00:07]
    .
    2011-03-28 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-02-02 00:07]
    .
    2011-03-07 c:\windows\Tasks\HPCeeScheduleForAsma.job
    - c:\program files (x86)\hewlett-packard\sdp\ceement\HPCEE.exe [2008-11-04 19:34]
    .
    .
    --------- x86-64 -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-06-20 1533736]
    "SmartMenu"="%ProgramFiles%\Hewlett-Packard\HP MediaSmart\SmartMenu.exe" [BU]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2009-06-17 130576]
    "SysTrayApp"="c:\program files\IDT\WDM\sttray64.exe" [2009-07-22 450048]
    "AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-08-26 161304]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256]
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.ca/
    uLocal Page = c:\windows\system32\blank.htm
    mLocal Page = c:\windows\SysWOW64\blank.htm
    uInternet Settings,ProxyServer = http=127.0.0.1:53293
    uInternet Settings,ProxyOverride = *.local;<local>
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
    FF - ProfilePath - c:\users\Asma\AppData\Roaming\Mozilla\Firefox\Profiles\r25ex48o.default\
    FF - prefs.js: browser.startup.homepage - hxxp://fr.msn.com/
    FF - prefs.js: network.proxy.http - 127.0.0.1
    FF - prefs.js: network.proxy.http_port - 53293
    FF - prefs.js: network.proxy.type - 1
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files (x86)\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
    FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
    FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
    FF - Ext: WOT: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} - %profile%\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
    FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
    FF - Ext: Move Media Player: moveplayer@movenetworks.com - c:\users\Asma\AppData\Roaming\Move Networks
    FF - user.js: yahoo.ytff.general.dontshowhpoffer - true
    .
    - - - - ORPHELINS SUPPRIMES - - - -
    .
    WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    .
    .
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\MySQL]
    "ImagePath"="\"c:\program files\MySQL\MySQL Server 5.1\bin\mysqld\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.1\my.ini\" MySQL"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\{55662437-DA8C-40c0-AADA-2C816A897A49}]
    "ImagePath"="\??\c:\program files (x86)\Hewlett-Packard\Media\DVD\000.fcl"
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
    .
    [HKEY_USERS\S-1-5-21-1502214498-3565008414-2400695767-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.Email.1"
    .
    [HKEY_USERS\S-1-5-21-1502214498-3565008414-2400695767-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.VCard.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.10"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
    @="Shockwave Flash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
    @Denied: (A 2) (Everyone)
    @=""
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
    @="FlashBroker"
    .
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
    "SymbolicLinkValue"=hex(6):5c,00,52,00,45,00,47,00,49,00,53,00,54,00,52,00,59,
    00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,4f,00,46,00,\
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    Heure de fin: 2011-03-28 16:52:28
    ComboFix-quarantined-files.txt 2011-03-28 20:52
    ComboFix2.txt 2011-03-28 16:16
    .
    Avant-CF: 41 242 615 808 octets libres
    Après-CF: 41 207 361 536 octets libres
    .
    - - End Of File - - ED30FFDF149BD13D74736A66C6C8B533
    0
  11. gen-hackman
     
    retente un cfscript normal avec tout le texte plus haut et cette fois-ci desactive windows defender aussi avant
    0
  12. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
     
    je t'écris d'un autre ordi... je ne pense que ce script marche car mon ordi s'est mis en veille et le disque dur s'est arrêté maintenant
    0
    1. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
       
      j'ai d'ailleurs mis fin au programme qui ne s'exécute pas
      0
  13. gen-hackman
     
    immédiatement apres le glisser/deposer ?
    0
  14. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
     
    non pas immédiatement mais lorsqu'il arrive à l'étape d'analyse des fichiers infectés qui peut prendre pas moins de 10 min ou le double du temps lorsqu'il y a beacoup de fichiers infectés
    0
    1. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
       
      arrivé à cette phase il n y a pas le déroulement des différentes étapes et il bloque càd rien ne se passe jusqu,à ce que l'ordi se met en veille et il y a arrêt du disque dur
      0
  15. gen-hackman
     
    ok reessaie mais avec ceci à la place

    KillAll::

    File::
    c:\temp\KK.exe

    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "HP Software Update"=-
    "QuickTime Task"=-
    "iTunesHelper"=-
    "Adobe Reader Speed Launcher"=-
    "SunJavaUpdateSched"=-

    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:53293
    uInternet Settings,ProxyOverride = *.local;<local>

    Firefox::
    FF - prefs.js: network.proxy.http_port - 53293
    FF - prefs.js: network.proxy.type - 1

    RegLock::
    [HKEY_USERS\S-1-5-21-1502214498-3565008414-2400695767-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
    [HKEY_USERS\S-1-5-21-1502214498-3565008414-2400695767-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] => Macromedia Shockwave Flash
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] => Macromedia Shockwave Flash
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{D27CDB6B-AE6D-11CF-96B8-444553540000}\1.0]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}]
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\TypeLib\{FAB3E735-69C7-453B-A446-B6823C6DF1C9}\1.0]
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\Classes]
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]

    MBR::
    0
  16. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
     
    ca ne marche toujours pas, même en mettant à jour combofix
    0
  17. gen-hackman
     
    ouais j'avais edité pour virer ca mais apparement c'est pas passé

    => Macromedia Shockwave Flash
    0
  18. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
     
    y a t-il pas un autre moyen que combofix ?
    0
  19. gen-hackman
     
    pour debloquer des cles bloqués de registre bloquées j'en connais pas non
    0
  20. asmuss3 Messages postés 34 Date d'inscription   Statut Membre Dernière intervention  
     
    cela veut dire que le virus est encore là et que cela peut affecter sérieusement mon ordi
    0
  21. gen-hackman
     
    bon on va essayer de contourner le probleme :

    Télécharge ici :OTL

    enregistre le sur ton Bureau.

    si tu as XP => double clique
    si tu as Vista ou windows 7 => clic droit "executer en tant que...."


    sur OTL.exe pour le lancer.

    ▶ Coche les 2 cases Lop et Purity

    ▶ Coche la case devant tous les utilisateurs

    ▶ règle age du fichier sur "60 jours"

    ▶ dans les 6 onglets de la moitié gauche , mets tout sur "tous"

    ne modifie pas ceci :

    "fichiers créés" et "fichiers Modifiés"


    ▶Clic sur Analyse.

    A la fin du scan, le Bloc-Notes va s'ouvrir avec le rapport (OTL.txt).

    Ce fichier est sur ton Bureau (en général C:\Documents and settings\le_nom_de_ta_session\OTL.txt)

    ▶▶▶ NE LE POSTE PAS SUR LE FORUM (il est trop long)

    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

    ▶ Clique sur Parcourir et cherche le fichier ci-dessus.

    ▶ Clique sur Ouvrir.

    ▶ Clique sur "Cliquez ici pour déposer le fichier".

    juste au niveau du bouton , en fin de chargement du fichier , Un lien de cette forme apparaitra :

    http://www.cijoint.fr/cjlink.php?file=cjge368/cijSKAP5fU.txt

    ▶ Copie ce lien dans ta réponse.

    ▶▶ Tu feras la meme chose avec le "Extra.txt" qui logiquement sera aussi sur ton bureau.
    0
  • 1
  • 2
  • 3