[virus] impossible a supprimer

Résolu
bonjour,

apres avoir telechargé un programme permettant de regarder des chaines sportives sur l ordinateur, celui ci a commencé a avoir des problemes avec apparition de fenetre plublicitaires sans que je navigues sur internet...apres avoir essayé tout un panel d anti virus ou anti spyware comme spyboot, adaware, ccleaner, avg, ainsi que mon anti virus norton, les problemes ont changé... des fenetres pub ont disparu mais ont été remplacée par d autres (asiatique), ma page d acceuil IE est inchangable,elle affiche page blanche avec dans ma barre d outil des points d interrogation...

de plus, tout ces antivus telechargés ont ralentit mon ordinateur, et j ai depuis des bruits (comme si j essayer de cliquer sur un objet que windows ne peut pas ouvrir...) toutes les 30 secondes, sans que je navigue sur internet...

je remerci d avance le courageux qui voudra bien se pencher sur mon cas, en esperant qu il puisse m apporter une solution...

merci

ps: j ai actuellement windows XP SP2, antivirus norton (je sais, c est pas le mieux...)
Configuration: Windows XP
Firefox 1.5.0.9

41 réponses

Résumé de la discussion

Un ordinateur sous Windows XP SP2 est affecté par une infection après le téléchargement d’un programme, avec des fenêtres publicitaires qui s’ouvrent sans navigation, une page d’accueil IE bloquée et des ralentissements répétés. Plusieurs réponses recommandent d’exécuter HijackThis puis de supprimer des entrées et fichiers suspects, de nettoyer le système avec CCleaner, et d’effectuer des scans antivirus en ligne et des analyses avec SpywareBlaster ou AVG anti-spyware. D’autres préconisent d’installer un pare‑feu tiers (Kerio), de désactiver le pare‑feu Windows et de créer un point de restauration « propre », puis de mettre à jour Windows et le navigateur pour éviter de nouvelles infections.

Bobot (l’IA à votre service)
  1. Salut

    fait ceci :

    Télécharge HijackThis :
    ---> http://www.infos-du-net.com/telecharger/HijackThis,0301-454.html
    Installe le dans son propre dossier :
    - clic droit sur le bureau, tu choisis "nouveau dossier" puis installe-le à l'intérieur.
    Double-clic sur HijackThis.
    Clic sur "do a system scan and save logfile"
    Puis copie et colle le rapport ici

    ET

    - Ouvre HijackThis

    Clic sur "open the misc tools section"
    Clic sur "open uninstall manager"
    Clic sur "Save list" dans la fenêtre qui va s'ouvrir enregistre le fichier à un endroit ou tu le retrouvera facilement.
    1. merci,

      voici le rapport:

      Logfile of HijackThis v1.99.1
      Scan saved at 02:22:32, on 22/02/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Windows Defender\MsMpEng.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Acer\eManager\anbmServ.exe
      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      C:\WINDOWS\system32\CTsvcCDA.EXE
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
      C:\WINDOWS\system32\ffudf.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\system32\keyhook.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Arcade\PCMService.exe
      C:\Program Files\Launch Manager\QtZgAcer.EXE
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Acer\Empowering Technology\eRecovery\Monitor.exe
      C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
      C:\WINDOWS\SYSTEM32\SWEEPER.EXE
      C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
      C:\WINDOWS\system32\sistray.exe
      C:\Program Files\Nikon\NkView6\NkvMon.exe
      F:\eMule\emule.exe
      C:\WINDOWS\system32\svchost.exe
      F:\BitComet\BitComet.exe
      C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
      C:\WINDOWS\system32\mssys32.exe
      C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Windows Media Player\wmplayer.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\bayle\Bureau\Hijackthis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao123.union123.com/index.htm
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao123.union123.com/index.htm
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.0\NppBho.dll
      O2 - BHO: (no name) - {4b16577c-a8e2-4c7f-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32\4c7fcfsb.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: ʵÓÃËÑË÷ - {6CFD436C-7AAD-4e50-992F-C0C87A94CAD2} - (no file)
      O2 - BHO: (no name) - {A4B313AC-16DC-52D1-A4D7-1D4F7B1A9C4E} - C:\WINDOWS\system32\mshtmll.dll
      O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: 7c97 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\496cntos.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
      O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
      O3 - Toolbar: 7c97 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\496cntos.dll
      O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [System] C:\Program Files\Fichiers communs\System\Updaterun.exe
      O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [srodzxdjht] c:\windows\system32\srodzxdjht.exe srodzxdjht
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
      O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
      O4 - HKLM\..\Run: [sdafdsafds] C:\WINDOWS\temp\162.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
      O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
      O4 - HKLM\..\Run: [LaunchApp] Alaunch
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [Internet Sweeper] C:\WINDOWS\SYSTEM32\SWEEPER.EXE /Q
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [mssys32] C:\WINDOWS\system32\mssys32.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [mshtmll] regsvr32 /s C:\WINDOWS\system32\mshtmll.dll
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
      O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
      O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
      O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptimg.dll
      O23 - Service: 988FC5FC - Unknown owner - C:\WINDOWS\system32\988FC5FC.EXE (file missing)
      O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
      O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe

      BON COURAGE !!
      ET MERCI ENCORE
    2. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 09:57:53, on 22/12/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
      C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
      C:\Program Files\AntivirusFirewall\Anti-Virus\FSGK32.EXE
      C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
      C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
      C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
      C:\Program Files\AntivirusFirewall\Anti-Virus\fssm32.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\AntivirusFirewall\Common\FSMB32.EXE
      C:\Program Files\AntivirusFirewall\Common\FCH32.EXE
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\AntivirusFirewall\Common\FAMEH32.EXE
      C:\Program Files\AntivirusFirewall\Anti-Virus\fsqh.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\Program Files\AntivirusFirewall\Anti-Virus\fsrw.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\AntivirusFirewall\Anti-Virus\fsav32.exe
      C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\WINDOWS\system32\carpserv.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
      C:\Program Files\CyberLink\PowerCinema\PCMService.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\PROGRA~1\ANTIVI~1\ANTI-S~1\fsaw.exe
      C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\AntivirusFirewall\FSGUI\fsguidll.exe
      C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Logitech\QuickCam\Quickcam.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Fichiers communs\Teleca Shared\CapabilityManager.exe
      C:\WINDOWS\system32\mwsrvacc.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
      C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
      C:\Program Files\AntivirusFirewall\FSGUI\fsavgui.exe
      C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
      C:\PROGRA~1\Wanadoo\WOOBRO~1\DownloadManager.exe
      C:\DOCUME~1\SÉBAST~1\MESDOC~1\SEBAST~1\hijackthis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://eo.st#
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.olidata.com/
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.ea.com/games/the-sims
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O4 - HKLM\..\Run: [CARPService] carpserv.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
      O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
      O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
      O4 - HKLM\..\Run: [MSys32] "C:\Program Files\Sectors of Death\Web\morfitwebentrance.exe"
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\AntivirusFirewall\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\AntivirusFirewall\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\AntivirusFirewall\FSGUI\FSSW.EXE" /reboot
      O4 - HKLM\..\Run: [News Service] "C:\Program Files\AntivirusFirewall\FSGUI\ispnews.exe"
      O4 - HKLM\..\Run: [DriveCleaner 2006 Free] "C:\Program Files\DriveCleaner 2006 Free\UDC2006.exe" /min
      O4 - HKLM\..\Run: [udc6cw] "C:\Program Files\DriveCleaner 2006 Free\udc6cw.exe" -c
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [afwdgjirq] c:\windows\system32\afwdgjirq.exe afwdgjirq
      O4 - HKLM\..\Run: [LcpaLite] "C:\Program Files\LCPA Lite\Lcpa Lite.exe"
      O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
      O4 - HKLM\..\Run: [uifybksd] c:\windows\system32\uifybksd.exe uifybksd
      O4 - HKLM\..\Run: [I downloaded pirated Software from P2P ] C:\WINDOWS\system32\Age of Empires 3 The Warchiefs.exe
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\mwsrvacc.exe /run
      O4 - HKCU\..\Run: [WeatherWatcher] C:\Program Files\Weather Watcher\ww.exe
      O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
      O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
      O4 - HKCU\..\Run: [rs32net] C:\WINDOWS\System32\rs32net.exe
      O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\AntivirusFirewall\backweb\6588780\Program\fspex.exe
      O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\AntivirusFirewall\Anti-Spyware\blockpopups.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
      O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\AntivirusFirewall\Anti-Spyware\ieshield.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O14 - IERESET.INF: START_PAGE_URL=https://www.olidata.com/
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {5F4D3335-3194-4167-85AE-E7325F2695EF} - http://es6-scripts.dlv4.com/binaries/egaccess4/egaccess4_1068_em_XP.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O20 - AppInit_DLLs: zsrypo.dll
      O21 - SSODL: featherweed - {ab340860-fd81-4a65-b345-82eb77a66b5e} - C:\WINDOWS\system32\jbtazy.dll (file missing)
      O22 - SharedTaskScheduler: featherweed - {ab340860-fd81-4a65-b345-82eb77a66b5e} - C:\WINDOWS\system32\jbtazy.dll (file missing)
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\ANTIVI~1\backweb\6588780\Program\SERVIC~1.EXE
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Anti-Virus\fsgk32st.exe
      O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\AntivirusFirewall\backweb\6588780\program\fsbwsys.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\AntivirusFirewall\Common\FSMA32.EXE
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
  2. Fait ceci dans l'ordre :

    ¤ Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked"

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao123.union123.com/index.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao123.union123.com/index.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    O2 - BHO: (no name) - {4b16577c-a8e2-4c7f-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32\4c7fcfsb.dll
    O2 - BHO: ʵÓÃËÑË÷ - {6CFD436C-7AAD-4e50-992F-C0C87A94CAD2} - (no file)
    O2 - BHO: (no name) - {A4B313AC-16DC-52D1-A4D7-1D4F7B1A9C4E} - C:\WINDOWS\system32\mshtmll.dll
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: 7c97 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\496cntos.dll
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [System] C:\Program Files\Fichiers communs\System\Updaterun.exe
    O4 - HKLM\..\Run: [srodzxdjht] c:\windows\system32\srodzxdjht.exe srodzxdjht
    O4 - HKLM\..\Run: [sdafdsafds] C:\WINDOWS\temp\162.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [mssys32] C:\WINDOWS\system32\mssys32.exe
    O4 - HKCU\..\Run: [mshtmll] regsvr32 /s C:\WINDOWS\system32\mshtmll.dll
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptimg.dll
    O23 - Service: 988FC5FC - Unknown owner - C:\WINDOWS\system32\988FC5FC.EXE (file missing)

    ¤ Clic sur démarrer, rechercher, cherche et supprime ces fichiers :

    - 4c7fcfsb.dll
    - mshtmll.dll
    - 496cntos.dll
    - Updaterun.exe
    - mssys32.exe
    - mshtmll.dll

    **Si un fichier/dossier persiste lors de la suppression fait ceci:
    - Redémarre ton PC. Dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaître choisis "mode sans echec" attends un peu..
    Puis va supprimer les fichiers/dossiers, vide ta corbeille et redémarre ton PC normalement.

    ¤ Fait ce nettoyage: à faire réguliérement

    ¤ Télécharge et installe CCleaner (n'installe pas la barre d'outil Yahoo)
    ---> http://www.infos-du-net.com/telecharger/CCleaner,0301-1039.html

    - Dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, clic sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
    Les sauvegardes que tu aura faites, tu pourra les supprimer si ton ordinateur n'a plus de problémes.

    - Relance Ccleaner, vas dans l'onglet "nettoyeur" présent sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"

    Si tu as besoin d'aide avec Ccleaner, regarde ce tutoriel :
    https://kerio.probb.fr/t242-tuto-ccleaner-v-2

    ¤ Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2 (en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
    Une fois qu'il a terminé colle le rapport ici stp

    https://www.bitdefender.com/toolbox/

    ¤ Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2 (en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
    Une fois qu'il a terminé colle le rapport ici stp

    https://www.bitdefender.com/toolbox/

    A plus tard ;-)
    1. re bonjour,

      j ai effectué toutes les opérations présédentes, à noter que je n ai pas trouver le fichier 496cntos.dll.
      J ai effectué un scan bitdefender, voici le rapport:

      Scanned File

      Status

      C:\WINDOWS\system32\t21.exe=>(NSIS o)=>lzma_nsis0004

      Infected with: Trojan.Adload.H

      C:\WINDOWS\system32\t21.exe=>(NSIS o)=>lzma_nsis0004

      Disinfection failed

      C:\WINDOWS\system32\t21.exe=>(NSIS o)=>lzma_nsis0004

      Deleted

      C:\WINDOWS\system32\t21.exe=>(NSIS o)

      Update failed

      C:\WINDOWS\system32\1010s.exe=>(NSIS o)=>lzma_solid_nsis0001

      Infected with: Trojan.Downloader.Small.R

      C:\WINDOWS\system32\1010s.exe=>(NSIS o)=>lzma_solid_nsis0001

      Disinfection failed

      C:\WINDOWS\system32\1010s.exe=>(NSIS o)=>lzma_solid_nsis0001

      Deleted

      C:\WINDOWS\system32\1010s.exe=>(NSIS o)

      Update failed

      C:\WINDOWS\system32\bind_50099.exe~

      Infected with: Trojan.Downloader.Small.R

      C:\WINDOWS\system32\bind_50099.exe~

      Disinfection failed

      C:\WINDOWS\system32\bind_50099.exe~

      Deleted

      C:\WINDOWS\system32\cryptimg.dll

      Infected with: Trojan.Downloader.Agent.AYG

      C:\WINDOWS\system32\cryptimg.dll

      Disinfection failed

      C:\WINDOWS\system32\cryptimg.dll

      Deleted

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)=>lzma_solid_nsis0001

      Infected with: Trojan.Downloader.Agent.AZI

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)=>lzma_solid_nsis0001

      Disinfection failed

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)=>lzma_solid_nsis0001

      Deleted

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)

      Update failed

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)=>lzma_solid_nsis0003

      Infected with: Trojan.Downloader.Small.DK

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)=>lzma_solid_nsis0003

      Disinfection failed

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)=>lzma_solid_nsis0003

      Deleted

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)

      Update failed

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)=>lzma_solid_nsis0004

      Infected with: Trojan.Downloader.Harnig.XB

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)=>lzma_solid_nsis0004

      Disinfection failed

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)=>lzma_solid_nsis0004

      Deleted

      C:\WINDOWS\system32\tubar1250.exe=>(NSIS o)

      Update failed

      C:\WINDOWS\system32\UniBar.exe

      Infected with: Trojan.Nimosw.A

      C:\WINDOWS\system32\UniBar.exe

      Disinfection failed

      C:\WINDOWS\system32\UniBar.exe

      Deleted

      C:\WINDOWS\system32\cacheur.exe

      Infected with: Trojan.Agent.AJW

      C:\WINDOWS\system32\cacheur.exe

      Disinfection failed

      C:\WINDOWS\system32\cacheur.exe

      Deleted

      C:\WINDOWS\bar.exe=>(NSIS o)=>bzip2_solid_nsis0003

      Detected with: Adware.Baidubar.J

      C:\WINDOWS\bar.exe=>(NSIS o)=>bzip2_solid_nsis0003

      Disinfection failed

      C:\WINDOWS\bar.exe=>(NSIS o)=>bzip2_solid_nsis0003

      Deleted

      C:\WINDOWS\bar.exe=>(NSIS o)

      Update failed

      C:\WINDOWS\rising819.exe

      Infected with: Generic.PWStealer.AAD65AC9

      C:\WINDOWS\rising819.exe

      Disinfection failed

      C:\WINDOWS\rising819.exe

      Deleted

      C:\WINDOWS\rising415.exe

      Infected with: Generic.PWStealer.AAD65AC9

      C:\WINDOWS\rising415.exe

      Disinfection failed

      C:\WINDOWS\rising415.exe

      Deleted

      C:\WINDOWS\rising101.exe

      Infected with: Generic.PWStealer.AAD65AC9

      C:\WINDOWS\rising101.exe

      Disinfection failed

      C:\WINDOWS\rising101.exe

      Deleted

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP1\A0000011.exe

      Infected with: Trojan.Nimosw.A

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP1\A0000011.exe

      Disinfection failed

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP1\A0000011.exe

      Deleted

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000335.EXE

      Infected with: Trojan.Agent.AJW

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000335.EXE

      Disinfection failed

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000335.EXE

      Deleted

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000340.exe

      Infected with: Trojan.Nimosw.A

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000340.exe

      Disinfection failed

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000340.exe

      Deleted

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000414.exe

      Infected with: Trojan.Nimosw.A

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000414.exe

      Disinfection failed

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000414.exe

      Deleted

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000415.exe

      Infected with: Trojan.Agent.AJW

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000415.exe

      Disinfection failed

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000415.exe

      Deleted

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000416.exe

      Infected with: Generic.PWStealer.AAD65AC9

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000416.exe

      Disinfection failed

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000416.exe

      Deleted

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000417.exe

      Infected with: Generic.PWStealer.AAD65AC9

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000417.exe

      Disinfection failed

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000417.exe

      Deleted

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000418.exe

      Infected with: Generic.PWStealer.AAD65AC9

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000418.exe

      Disinfection failed

      C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000418.exe

      Deleted

      voila tout, j espere que ca vous aideras...
      encore merci
      1. Ok, merci.

        ¤ Tu dis avoir AVG peux-tu le mettre à jour et faire un scan complet de ton PC et coller le rapport ici stp.

        ¤ Fait ces deux choses :

        A² squared : gratuit en français (fait un scan rusé et colle le rapport ici stp)
        ----> http://www.infos-du-net.com/telecharger/a-squared,0301-1233.html

        Si tu as besoin d'aide avec A-squared regarde ce tutoriel :
        --> https://kerio.probb.fr/t223-tuto-pour-a-squared-free

        Télécharge Spywareblaster
        ----> spyware blaster

        Puis exécute le logiciel pour lui appliquer les protections.
        Si tu as besoin d'aide, regarde ce tutoriel pour Spywareblaster
        https://kerio.probb.fr/t241-tuto-spywareblaster

        ¤ Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2(en haut) va se mettre à clignoter, clique dessus et choisit "accepter l'active X" pour faire fonctionner le scan anti-virus.
        Une fois qu'il a terminé colle le rapport ici stp

        ---> https://www.kaspersky.fr/downloads

        - Kaspersky Online Scanner
        - Accept

        T'es pas mal infecté, on va finir par y voir le bout ;-)
        1. alors, voila le rapport kaspersky, suivi du rapport a2:

          KASPERSKY

          Statistiques de l'analyse
          Total d'objets analysés 39416
          Nombre de virus trouvés 9
          Nombre d'objets infectés 38 / 0
          Nombre d'objets suspects 2
          Durée de l'analyse 01:00:24

          Nom de l'objet infecté Nom du virus Dernière action
          C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\SYSTEM L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\SOFTWARE L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\DEFAULT L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
          C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
          C:\WINDOWS\system32\drivers\sptddrv1.sys L'objet est verrouillé ignoré
          C:\WINDOWS\system32\drivers\sptd.sys L'objet est verrouillé ignoré
          C:\WINDOWS\system32\drivers\gzqkx.sys L'objet est verrouillé ignoré
          C:\WINDOWS\system32\drivers\ffpbek.sys Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
          C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
          C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
          C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
          C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
          C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
          C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
          C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
          C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
          C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
          C:\WINDOWS\system32\mctet.d11 Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\WINDOWS\system32\B3A2BF22.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\WINDOWS\system32\dczet.dll Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\WINDOWS\system32\tubar1250.exe/stream/data0001 Infecté : Trojan-Downloader.Win32.Agent.bdr ignoré
          C:\WINDOWS\system32\tubar1250.exe/stream/data0003 Infecté : Trojan-Downloader.Win32.Small.dnb ignoré
          C:\WINDOWS\system32\tubar1250.exe/stream/data0004 Infecté : Trojan-Downloader.Win32.Small.edb ignoré
          C:\WINDOWS\system32\tubar1250.exe/stream Infecté : Trojan-Downloader.Win32.Small.edb ignoré
          C:\WINDOWS\system32\tubar1250.exe NSIS: infecté - 4 ignoré
          C:\WINDOWS\system32\cievz.dll L'objet est verrouillé ignoré
          C:\WINDOWS\system32\mctet.dll Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\WINDOWS\system32\umtcap.dll Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\WINDOWS\system32\cacheur.exe Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\WINDOWS\system32\jsefusf.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\WINDOWS\system32\dufs2.exe L'objet est verrouillé ignoré
          C:\WINDOWS\system32\dufs1.exe L'objet est verrouillé ignoré
          C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
          C:\WINDOWS\Temp\SYSTEM.dat Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
          C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
          C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
          C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
          C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
          C:\WINDOWS\f2.exe Infecté : Trojan-Downloader.Win32.Agent.bbb ignoré
          C:\Documents and Settings\All Users\Application Data\Microsoft\Windows Defender\Support\MPLog-02152007-210325.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2007-02-22_Log.ALUSchedulerSvc.LiveUpdate L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\Shared\QBackup\index.qbs L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\E03081D5.TMP L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\F7AA1DEE.TMP L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log L'objet est verrouillé ignoré
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip/Updaterun.exe Suspect : Password-protected-EXE ignoré
          C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\SmitfraudC2.zip ZIP: suspect - 1 ignoré
          C:\Documents and Settings\All Users\Modèles\temp.exe Infecté : Trojan-Downloader.Win32.QQHelper.uu ignoré
          C:\Documents and Settings\NetworkService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
          C:\Documents and Settings\NetworkService\Cookies\index.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
          C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
          C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
          C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
          C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\NTUSER.DAT L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\ntuser.dat.LOG L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Temp\~DFC7BC.tmp L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Temp\~DF13E8.tmp L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Temp\~DFB56C.tmp L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Temp\~DF2DA3.tmp L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Historique\History.IE5\MSHist012007022220070223\index.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Temporary Internet Files\Content.IE5\FPQRS2CV\ad_1161[1].exe L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Temporary Internet Files\Content.IE5\FPQRS2CV\ww.kuaiso[1].htm L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{E365B40D-D2C8-46EA-AEE0-100FCF4F6BBF} L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\dbeam L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\dbeao L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\dbdam L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\dbdao L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\dbu2d.ht1 L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\dbc2e.ht1 L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\dbvmh.ht1 L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\dbvm.cf1 L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\dbm L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\fiih.ht1 L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\fii.cf1 L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\rpmh.ht1 L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\rpm.cf1 L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\hpt2i.ht1 L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Local Settings\Application Data\Google\Google Desktop Search\hp L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Cookies\index.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\index2.dat L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\contactgroup256.dbb L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\profile256.dbb L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\chat512.dbb L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\call256.dbb L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\callmember256.dbb L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\chatmsg256.dbb L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\chatmsg512.dbb L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\user16384.dbb L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\user1024.dbb L'objet est verrouillé ignoré
          C:\Documents and Settings\bayle\Application Data\Skype\valb03\user256.dbb L'objet est verrouillé ignoré
          C:\Program Files\Fichiers communs\Symantec Shared\NFWEVT.LOG L'objet est verrouillé ignoré
          C:\Program Files\Fichiers communs\Symantec Shared\SNDSYS.log L'objet est verrouillé ignoré
          C:\Program Files\Fichiers communs\Symantec Shared\SNDFW.log L'objet est verrouillé ignoré
          C:\Program Files\Fichiers communs\Symantec Shared\SNDCON.log L'objet est verrouillé ignoré
          C:\Program Files\Fichiers communs\Symantec Shared\SNDALRT.log L'objet est verrouillé ignoré
          C:\Program Files\Fichiers communs\Symantec Shared\SNDIDS.log L'objet est verrouillé ignoré
          C:\Program Files\Fichiers communs\Symantec Shared\SNDDBG.log L'objet est verrouillé ignoré
          C:\Program Files\Fichiers communs\Symantec Shared\EENGINE\EPERSIST.DAT L'objet est verrouillé ignoré
          C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log L'objet est verrouillé ignoré
          C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log L'objet est verrouillé ignoré
          C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log L'objet est verrouillé ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP1\A0000010.dll Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP1\A0000023.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP1\A0000029.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP2\A0000142.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP2\A0000149.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP2\A0000176.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP2\A0000190.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP2\A0000199.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP2\A0000229.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP2\A0000239.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000332.sys Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000333.DLL Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000334.DLL Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000365.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000381.exe Infecté : Trojan-Downloader.Win32.Agent.bdn ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000389.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000431.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000447.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000454.SYS Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000455.DLL Infecté : Trojan-Downloader.Win32.Agent.bcc ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\change.log L'objet est verrouillé ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000512.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000524.exe Infecté : Backdoor.Win32.Agent.ahj ignoré
          Analyse terminée.

          ET VOICI LE RAPPORT A2:

          Version - a-squared Free 2.1

          Réglages Scan:

          Objets: Mémoire, Traces, Cookies, C:\WINDOWS\, C:\Program Files
          Scan archives: Marche
          Heuristiques: Marche
          Scan ADS: Marche

          Début du scan: 22/02/2007 20:40:15

          C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt:10 Détecter: Trace.TrackingCookie
          C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt:11 Détecter: Trace.TrackingCookie
          C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt:12 Détecter: Trace.TrackingCookie
          C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt:27 Détecter: Trace.TrackingCookie
          C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt:28 Détecter: Trace.TrackingCookie
          C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt:29 Détecter: Trace.TrackingCookie

          Scanné

          Fichiers: 15423
          Traces: 84342
          Cookies: 35
          Processus: 47

          Trouver

          Fichiers: 0
          Traces: 0
          Cookies: 6
          Processus: 0
          Clés de Registre: 0

          Fin du Scan: 22/02/2007 20:52:23
          Temps du Scan: 00:12:08

          j ai effacé avg car je l avais juste telechargé pr essayer d enlever les virus mais ca a echoué et du coup je l ai effacé car mon ordinateur peinait un peu avec tout les programmes d antivirus...a l origine, il fonctionne avec norton, mais je comprend pas pourquoi kaspersky detecte tant de virus et pas l analyse norton...

          si jamais besoins en est, je peux retelecharger avg...

          merci
          1. Ok, merci.
            Kaspersky a detecté des virus tout simplement parce que les anti-virus n'ont pas la même base virale (pour la détection des virus).

            C'est pas très propre, donc :

            ¤ Clic sur démarrer, poste de travail, C:, Windows, system 32 cherche et supprime ces processus :

            - mctet.d11
            - B3A2BF22.exe
            - dczet.dll Infecté
            - tubar1250.exe/
            - cievz.dll
            - mctet.dll
            - umtcap.dll
            - cacheur.exe
            - jsefusf.exe
            - dufs2.exe
            - dufs1.exe

            ¤ Clic sur démarrer, poste de travail, C:, Windows et supprime ces processus :

            - f2.exe
            - bar.exe

            **Si un fichier/dossier persiste lors de la suppression fait ceci:
            - Redémarre ton PC. Dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaître choisis "mode sans echec" attends un peu..
            Puis va supprimer les fichiers/dossiers, vide ta corbeille et redémarre ton PC normalement.

            ¤ Redémarre le PC en mode sans échec : tu tapotes sur la touche F8 de ton clavier (ou F5 ) dès le démarrage et tu choisis le mode sans échec)

            Puis fait un nettoyage complet avec CCleaner (à bien faire en mode sans echec pour virer les infections qui traine où elles ne devraient pas)

            Remet un rapport hijackthis dès que c'est fait stp
            1. voici le rapport hijcakthis :

              Logfile of HijackThis v1.99.1
              Scan saved at 00:56:51, on 23/02/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Windows Defender\MsMpEng.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\RUNDLL32.EXE
              C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Acer\eManager\anbmServ.exe
              C:\WINDOWS\system32\B3A2BF22.exe
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              C:\WINDOWS\system32\CTsvcCDA.EXE
              C:\WINDOWS\system32\rundll32.exe
              C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\WINDOWS\system32\keyhook.exe
              C:\Program Files\Arcade\PCMService.exe
              C:\Program Files\Launch Manager\QtZgAcer.EXE
              C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              C:\Acer\Empowering Technology\eRecovery\Monitor.exe
              C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
              C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\SYSTEM32\SWEEPER.EXE
              C:\Program Files\Skype\Phone\Skype.exe
              C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
              C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
              C:\WINDOWS\system32\sistray.exe
              C:\Program Files\Nikon\NkView6\NkvMon.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Documents and Settings\bayle\Bureau\Hijackthis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao123.union123.com/index.htm
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao123.union123.com/index.htm
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\PROGRA~1\ËÑË÷À¸\tbhelper.dll
              O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.0\NppBho.dll
              O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: (no name) - {b6eb141f-48ab-4a8a-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32\4a8acfsb.dll
              O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O2 - BHO: 49df - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\4142ntos.dll
              O2 - BHO: TBSB03263 - {EEC7E620-B32A-4E3B-B200-291660803474} - C:\PROGRA~1\ËÑË÷À¸\eqiso.dll
              O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
              O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
              O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
              O3 - Toolbar: 49df - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\4142ntos.dll
              O3 - Toolbar: ??? - {33E640D8-EB95-4B22-B475-1852B7D35993} - C:\Program Files\ËÑË÷À¸\eqiso.dll
              O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
              O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
              O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
              O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
              O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
              O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
              O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
              O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
              O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
              O4 - HKLM\..\Run: [LaunchApp] Alaunch
              O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
              O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
              O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
              O4 - HKLM\..\Run: [Internet Sweeper] C:\WINDOWS\SYSTEM32\SWEEPER.EXE /Q
              O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
              O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
              O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
              O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
              O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra button: ²Æ¸»Í¨ - {C1F0024B-8278-4999-B7E6-2718426D9FE6} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
              O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
              O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
              O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptimg.dll
              O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
              O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
              O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
              O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
              O23 - Service: jsefusf - Unknown owner - C:\WINDOWS\system32\jsefusf.exe (file missing)
              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
              O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
              O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe

              Par contr eje n ai pas reussi a effacer le fichier - cievz.dll meme en mode sans echec, un fenetre me disant que le fichier est actuellement utilisé et qu il faut que je ferme le programme qui l utilise, mais lequel?

              MERCI
              1. Salut

                ¤ Clic sur "démarrer", "exécuter", tape: services.msc
                Cherche dans la liste les lignes ci-dessous, tu fais un clic droit dessus choisis "propriétés" et régle les sur "désactivé"

                - InstallDriver Table Manager
                - jsefusf

                ¤ Télécharge et installe AVG anti-spyware :
                Tu fais un scan complet de ton système, dès qu'il a fini.
                Si il te trouve des espions, supprime les. Enregistre le rapport et colle le ici stp

                AVG anti-spyware : reste gratuit après la période d'essai en français
                ---->http://www.infos-du-net.com/telecharger/Anti-Spyware-AVG,0301-7063.html

                Si tu as besoin d'aide avec Ewido(devenu AVG-antispyware) regarde ce tutoriel:
                --> http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

                ¤ Télécharge lopxp :
                http://perso.numericable.fr/~altshift/Info/Fichiers/lopxpMH2.zip

                dézippe-le sur ton bureau puis double-clic sur le fichier "lopxpMH.bat"
                quand il a terminé, un rapport s'ouvre : fait un copier-coller du rapport puis mets le ici
                1. voici le rapport avg:

                  AVG Anti-Spyware - Rapport d'analyse
                  ---------------------------------------------------------

                  + Créé à: 22:50:46 23/02/2007

                  + Résultat de l'analyse:

                  C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000626.dll -> Adware.Agent : Aucune action entreprise.
                  C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000627.dll -> Adware.Agent : Aucune action entreprise.
                  C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000628.dll -> Adware.Agent : Aucune action entreprise.
                  C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000629.dll -> Adware.Agent : Aucune action entreprise.
                  C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000630.sys -> Adware.Agent : Aucune action entreprise.
                  C:\Documents and Settings\bayle\Local Settings\Temp\AIS_1161_0.EXE -> Adware.Boran : Aucune action entreprise.
                  HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6A512BF7-EC78-4e8d-9841-6C02E8FA9838} -> Adware.Generic : Aucune action entreprise.
                  C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000625.sys -> Adware.Hooya : Aucune action entreprise.
                  C:\Program Files\ËÑË÷À¸\tbhelper.dll -> Adware.Softomate : Aucune action entreprise.
                  C:\WINDOWS\system32\B3A2BF22.exe -> Backdoor.Agent.ahj : Aucune action entreprise.
                  C:\WINDOWS\system32\__delete_on_reboot__B_3_A_2_B_F_2_2_._e_x_e_ -> Backdoor.Agent.ahj : Aucune action entreprise.
                  [2012] C:\WINDOWS\system32\B3A2BF22.exe -> Backdoor.Agent.ahj : Aucune action entreprise.
                  C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000621.exe -> Downloader.Agent.bcc : Aucune action entreprise.
                  C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000622.sys -> Downloader.Agent.bcc : Aucune action entreprise.
                  C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000623.DLL -> Downloader.Agent.bcc : Aucune action entreprise.
                  C:\WINDOWS\system32\__delete_on_reboot__m_c_t_e_t_._d_l_l_ -> Downloader.Agent.bcc : Aucune action entreprise.
                  C:\System Volume Information\_restore{3FFD409C-A779-4E68-83FD-8EA2CEAF0EFF}\RP3\A0000624.exe -> Downloader.QQHelper.uu : Aucune action entreprise.
                  :mozilla.11:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Casalemedia : Aucune action entreprise.
                  :mozilla.12:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Casalemedia : Aucune action entreprise.
                  :mozilla.13:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Casalemedia : Aucune action entreprise.
                  :mozilla.14:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Casalemedia : Aucune action entreprise.
                  :mozilla.15:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Casalemedia : Aucune action entreprise.
                  :mozilla.16:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Casalemedia : Aucune action entreprise.
                  :mozilla.58:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                  :mozilla.59:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                  :mozilla.60:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                  :mozilla.61:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                  :mozilla.62:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                  :mozilla.63:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                  :mozilla.23:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
                  :mozilla.24:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
                  :mozilla.25:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
                  :mozilla.26:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.

                  Fin du rapport

                  je n arrive pas a installer lopxp, il est ecris quand je le lance que le fichier est introuvable, et que le systeme n a pas la clé, et erreur car trop de parametre en ligne...

                  quand je relance une analyse avg, j ai tjs des virus qui revienne avec les meme nom, pourtant je les ai effacé juste avant de rallumer mon ordinateur, soit ils ne se supprime pas en fait, ou alors il repenetre mon ordinateur des l allumge...je sais pas
                  1. Salut

                    fait ceci puis refait un scan vaec AVG stp

                    Alors ceci : C:\System Volume Information\_restore
                    Indique que ta restauration du système etait infecté ou est infecté, pour être sûr, nous allons créer un point propre.

                    Clic sur "demarrer", cliques droit sur "poste de travail", "propriétés", onglet "restauration du système"

                    ¤ coches la case "desactiver la restauration du systéme sur tous les lecteurs", puis clic ur "appliquer"
                    ¤ décoches la case et clic sur "appliquer" puis "ok".

                    Maintenant, que l'ont à effacés les point infectés, nous allons créer un point propre :

                    Clic sur "demarrer", "tous les programmes", "accessoires", "outils système", "restauration du système", choisis "créer un point de restauration" nommes le " ccm" par exemple, clic sur "créer" puis "ok".
                    Voilà, maintenant le point de restauration est créer
                    Si un jour tu le décides, tu pourra revenir en arrière à la date que tu as créér ce point de restauration.
                    En exécutant la restauration du système tu pourra remettre ton ordinateur à la date ou l'on à créer ce point de restauration mais tu perdra les modifications que tu aura faites entre deux.
                    1. voici le rapport avg apres modif, y a l air d avoir moins de trucs...

                      ---------------------------------------------------------
                      AVG Anti-Spyware - Rapport d'analyse
                      ---------------------------------------------------------

                      + Créé à: 01:08:51 24/02/2007

                      + Résultat de l'analyse:

                      C:\Documents and Settings\bayle\Local Settings\Temp\AIS_1161_0.EXE -> Adware.Boran : Aucune action entreprise.
                      HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{6A512BF7-EC78-4e8d-9841-6C02E8FA9838} -> Adware.Generic : Aucune action entreprise.
                      C:\Program Files\ËÑË÷À¸\tbhelper.dll -> Adware.Softomate : Aucune action entreprise.
                      C:\WINDOWS\system32\B3A2BF22.exe -> Backdoor.Agent.ahj : Aucune action entreprise.
                      [228] C:\WINDOWS\system32\B3A2BF22.exe -> Backdoor.Agent.ahj : Aucune action entreprise.
                      :mozilla.16:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Casalemedia : Aucune action entreprise.
                      :mozilla.45:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                      :mozilla.46:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                      :mozilla.47:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                      :mozilla.48:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                      :mozilla.49:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                      :mozilla.50:C:\Documents and Settings\bayle\Application Data\Mozilla\Firefox\Profiles\g0504vtx.default\cookies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.

                      Fin du rapport

                      suite?
                      merci
                      1. Recommence le scan avec AVG et supprime bien tout car la Aucune action entreprise

                        Puis remet un rapport hijackthis ;-)
                        1. j ai enregistré ce rapport juste avant de supprimer toutes les infections relevées, apres il ne reste rien...je n arrivais pas a effacer avant d enregistrer le rapport car il faur redemarrer l ordinateur apres avoir supprimer les infections pr que ce soit efficace...je ferai prochainement une analyse hijackthis...
                          1. voici le rapport hijackthis :

                            Logfile of HijackThis v1.99.1
                            Scan saved at 16:01:34, on 24/02/2007
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Windows Defender\MsMpEng.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Acer\eManager\anbmServ.exe
                            C:\WINDOWS\system32\B3A2BF22.exe
                            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                            C:\WINDOWS\system32\CTsvcCDA.EXE
                            C:\WINDOWS\system32\rundll32.exe
                            C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
                            C:\WINDOWS\system32\ffudf.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\WINDOWS\SOUNDMAN.EXE
                            C:\WINDOWS\system32\keyhook.exe
                            C:\Program Files\Arcade\PCMService.exe
                            C:\Program Files\Launch Manager\QtZgAcer.EXE
                            C:\WINDOWS\System32\svchost.exe
                            C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                            C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                            C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                            C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
                            C:\WINDOWS\SYSTEM32\SWEEPER.EXE
                            C:\Program Files\Skype\Phone\Skype.exe
                            C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
                            C:\WINDOWS\system32\sistray.exe
                            C:\Program Files\Nikon\NkView6\NkvMon.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\Documents and Settings\bayle\Bureau\Hijackthis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao123.union123.com/index.htm
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao123.union123.com/index.htm
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\PROGRA~1\ËÑË÷À¸\tbhelper.dll
                            O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.0\NppBho.dll
                            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O2 - BHO: (no name) - {5b04469f-0b09-4f4e-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32\4f4ecfsb.dll (file missing)
                            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O2 - BHO: b9f5 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\4153ntos.dll (file missing)
                            O2 - BHO: TBSB03263 - {EEC7E620-B32A-4E3B-B200-291660803474} - C:\PROGRA~1\ËÑË÷À¸\eqiso.dll
                            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                            O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
                            O3 - Toolbar: b9f5 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\4153ntos.dll (file missing)
                            O3 - Toolbar: ??? - {33E640D8-EB95-4B22-B475-1852B7D35993} - C:\Program Files\ËÑË÷À¸\eqiso.dll
                            O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                            O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                            O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
                            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                            O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
                            O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                            O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                            O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
                            O4 - HKLM\..\Run: [LaunchApp] Alaunch
                            O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                            O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                            O4 - HKLM\..\Run: [Internet Sweeper] C:\WINDOWS\SYSTEM32\SWEEPER.EXE /Q
                            O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                            O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
                            O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                            O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
                            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                            O9 - Extra button: ²Æ¸»Í¨ - {C1F0024B-8278-4999-B7E6-2718426D9FE6} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
                            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
                            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                            O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                            O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                            O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptimg.dll
                            O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
                            O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                            O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                            O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                            O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
                            O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
                            O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
                            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                            O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                            O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe

                            esque je dois cliquer sur scan apres ou pas?
                            1. ¤ Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked"

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao123.union123.com/index.htm
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hao123.union123.com/index.htm < sauf si tu connais, ça semble Asiatique j'arrive pas a y accèder.
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R3 - URLSearchHook: ToolbarURLSearchHook Class - {CA3EB689-8F09-4026-AA10-B9534C691CE0} - C:\PROGRA~1\ËÑË÷À¸\tbhelper.dll
                              O2 - BHO: (no name) - {5b04469f-0b09-4f4e-8b0d-4e03f37a8dbf} - C:\WINDOWS\system32\4f4ecfsb.dll (file missing)
                              O2 - BHO: b9f5 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\4153ntos.dll (file missing)
                              O2 - BHO: TBSB03263 - {EEC7E620-B32A-4E3B-B200-291660803474} - C:\PROGRA~1\ËÑË÷À¸\eqiso.dll
                              O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                              O3 - Toolbar: b9f5 - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - C:\WINDOWS\system32\4153ntos.dll (file missing)
                              O3 - Toolbar: ??? - {33E640D8-EB95-4B22-B475-1852B7D35993} - C:\Program Files\ËÑË÷À¸\eqiso.dll

                              ¤ Clic sur poste de travail, C:, program files et supprime un dossier :

                              - ËÑË÷À¸ < quelque chose de bizarre il se peut que le nom différe.

                              ¤ Télécharge OTMoveIt sur ton bureau
                              http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                              Double-clic sur OTMoveIt.exe.
                              Copie et colle les lignes ci-dessous dans OTMoveIt dans la fenêtre de gauche.

                              C:\WINDOWS\system32\cryptimg.dll
                              C:\WINDOWS\system32\drivers\voodoo.sys

                              Clic sur Moveit! (en rouge)
                              Les lignes passeront dans la fenêtre de droite copie et colle le résultat ici.
                              Si un fichier/dossier ne peut-être supprimé, un message te demandera si tu veux redémarrer ton PC clic sur "YES"

                              Puis remet un rapport hijackthis stp

                              ¤ Télécharge Gmer
                              http://www2.gmer.net/gmer.zip

                              Ferme internet et tous les programmes
                              Dézippe le fichier et double-clic sur gmer.exe

                              Sur la droite laisse juste coché "files" et "services" puis clic sur "scan "
                              Lorsque le scan est terminé clic sur "copy"

                              Ouvre le bloc-note et clic sur le édition puis coller, le rapport va apparaître.
                              Copie et colle le contenu ici stp
                              1. voici le resultat OTMoveIt:

                                DllUnregisterServer procedure not found in C:\WINDOWS\system32\cryptimg.dll
                                C:\WINDOWS\system32\cryptimg.dll NOT unregistered.
                                C:\WINDOWS\system32\cryptimg.dll moved successfully.
                                File/Folder C:\WINDOWS\system32\drivers\voodoo.sys not found.

                                Created on 02/24/2007 19:30:37

                                rapport hijacthis:

                                Logfile of HijackThis v1.99.1
                                Scan saved at 19:32:19, on 24/02/2007
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Windows Defender\MsMpEng.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Acer\eManager\anbmServ.exe
                                C:\WINDOWS\system32\B3A2BF22.exe
                                C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                C:\WINDOWS\system32\CTsvcCDA.EXE
                                C:\WINDOWS\system32\rundll32.exe
                                C:\WINDOWS\SYSTEM32\RUNDLLFROMWIN2000.EXE
                                C:\WINDOWS\system32\ffudf.exe
                                C:\Program Files\Windows Defender\MSASCui.exe
                                C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                C:\WINDOWS\SOUNDMAN.EXE
                                C:\WINDOWS\system32\keyhook.exe
                                C:\Program Files\Arcade\PCMService.exe
                                C:\Program Files\Launch Manager\QtZgAcer.EXE
                                C:\WINDOWS\System32\svchost.exe
                                C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                                C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
                                C:\WINDOWS\SYSTEM32\SWEEPER.EXE
                                C:\Program Files\Skype\Phone\Skype.exe
                                C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
                                C:\WINDOWS\system32\sistray.exe
                                C:\Program Files\Nikon\NkView6\NkvMon.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Documents and Settings\bayle\Bureau\OTMoveIt.exe
                                C:\Documents and Settings\bayle\Bureau\Hijackthis\HijackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.0\NppBho.dll
                                O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
                                O3 - Toolbar: (no name) - {DFCB34B6-902D-426E-AE2B-1B294AE19F4F} - (no file)
                                O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
                                O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
                                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                                O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
                                O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                                O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                                O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Arcade\PCMService.exe"
                                O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
                                O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                                O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
                                O4 - HKLM\..\Run: [LaunchApp] Alaunch
                                O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                                O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                                O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                                O4 - HKLM\..\Run: [Internet Sweeper] C:\WINDOWS\SYSTEM32\SWEEPER.EXE /Q
                                O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                                O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
                                O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe
                                O4 - Global Startup: NkvMon.exe.lnk = C:\Program Files\Nikon\NkView6\NkvMon.exe
                                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                O9 - Extra button: ²Æ¸»Í¨ - {C1F0024B-8278-4999-B7E6-2718426D9FE6} - C:\WINDOWS\system32\shdocvw.dll (HKCU)
                                O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
                                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                                O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                                O20 - Winlogon Notify: cryptimg - C:\WINDOWS\SYSTEM32\cryptimg.dll
                                O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
                                O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                                O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                                O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
                                O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
                                O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
                                O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
                                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                                O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\AppCore\AppSvc32.exe

                                concernant le fichier ËÑË÷À ds progrmamme files, je l ai deja effacer avant mais j ai l impression qu il revient tjs des que je rallume l ordinateur...je viens a nouveau de l effacer, on verra...les programmes asiatiques dont tu parles sont ceux qui m ouvre des fenetre IE avec des ? dans la barre d outils google, et parfois des annonces asiatque...dernierement c est une page yahoo asiatique qui s est ouverte...

                                je poursuit les manipulations avec Gmer...a+ tard et tjs merci
                                1. comment je vais pour trouver le bloc note?
                                  L analyse dit qu elle n a rien trouvé (aucune modification systeme...)
                                  1. Pour le bloc-note :
                                    Clic démarrer, tous les programmes, accessoires, bloc-notes.

                                    Coche toutes les cases puis refait un scan avec Gmer et envoi le rapport stp.

                                    Télécharge Rustbfix (par ejvindh)
                                    http://www.uploads.ejvindh.net/rustbfix.exe
                                    Sauvegarde-le sur ton Bureau.

                                    Double clique rustbfix.exe afin de lancer l'outil.
                                    Si une infection Rustock.b est détectée, une invite t'indiquera qu'il est nécessaire de redémarrer le PC. Ce redémarrage pourrait être plus long que d'habitude, et il est possible que deux redémarrages soient requis.
                                    CCopie-colle le contenu C:\Rustbfix\pelog.txt
                                    1. voici le rapport le rapport Gmer:

                                      GMER 1.0.12.12027 - http://www.gmer.net
                                      Rootkit scan 2007-02-24 21:46:06
                                      Windows 5.1.2600 Service Pack 2

                                      ---- System - GMER 1.0.12 ----

                                      SSDT 855F5AE8 ZwAlertResumeThread
                                      SSDT 855F45C8 ZwAlertThread
                                      SSDT 85646E68 ZwAllocateVirtualMemory
                                      SSDT 854F9CE0 ZwConnectPort
                                      SSDT \??\C:\WINDOWS\system32\Drivers\SYMEVENT.SYS ZwCreateKey
                                      SSDT 85575108 ZwCreateMutant
                                      SSDT 854FC098 ZwCreateThread
                                      SSDT \??\C:\WINDOWS\system32\drivers\hidproc.sys ZwDeleteKey
                                      SSDT \??\C:\WINDOWS\system32\drivers\hidproc.sys ZwDeleteValueKey
                                      SSDT sptd.sys ZwEnumerateKey
                                      SSDT sptd.sys ZwEnumerateValueKey
                                      SSDT 855208A8 ZwFreeVirtualMemory
                                      SSDT 854924B0 ZwImpersonateAnonymousToken
                                      SSDT 854971E0 ZwImpersonateThread
                                      SSDT fowf_n.sys ZwLoadDriver
                                      SSDT 854EEA30 ZwMapViewOfSection
                                      SSDT 854BC6C8 ZwOpenEvent
                                      SSDT sptd.sys ZwOpenKey
                                      SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess
                                      SSDT 85511050 ZwOpenProcessToken
                                      SSDT 85503938 ZwOpenThreadToken
                                      SSDT sptd.sys ZwQueryKey
                                      SSDT sptd.sys ZwQueryValueKey
                                      SSDT 85601580 ZwResumeThread
                                      SSDT 85742D28 ZwSetContextThread
                                      SSDT 85504168 ZwSetInformationProcess
                                      SSDT 854FDDC0 ZwSetInformationThread
                                      SSDT \??\C:\WINDOWS\system32\drivers\hidproc.sys ZwSetValueKey
                                      SSDT 8551E1F0 ZwSuspendProcess
                                      SSDT 85605A18 ZwSuspendThread
                                      SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess
                                      SSDT 85621498 ZwTerminateThread
                                      SSDT 85504808 ZwUnmapViewOfSection
                                      SSDT 8555BEE8 ZwWriteVirtualMemory

                                      ---- Kernel code sections - GMER 1.0.12 ----

                                      .text fowf_n.sys F7860300 61 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
                                      .text fowf_n.sys F786033E 9 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
                                      .text fowf_n.sys F7860348 10 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
                                      .text fowf_n.sys F7860353 41 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
                                      .text fowf_n.sys F786037D 50 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ]
                                      .text ...
                                      .text USBPORT.SYS!DllUnload F6B4962C 5 Bytes JMP 852251B8

                                      ---- Devices - GMER 1.0.12 ----

                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CREATE [F78618C0] fowf_n.sys
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLOSE 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_READ 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_WRITE 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_INFORMATION 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_INFORMATION [F7861C60] fowf_n.sys
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_EA 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_EA 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FLUSH_BUFFERS 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_QUERY_VOLUME_INFORMATION 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SET_VOLUME_INFORMATION 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DIRECTORY_CONTROL 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_FILE_SYSTEM_CONTROL 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_DEVICE_CONTROL 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_SHUTDOWN 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_LOCK_CONTROL 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_CLEANUP 8576C1D8
                                      Device \FileSystem\Fastfat \FatCdrom IRP_MJ_PNP 8576C1D8
                                      Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CREATE 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_CLOSE 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_DEVICE_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_POWER 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_SYSTEM_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-0 IRP_MJ_PNP 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_CREATE 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_CLOSE 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_DEVICE_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_POWER 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_SYSTEM_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBPDO-1 IRP_MJ_PNP 852241D8
                                      Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_CREATE 8520D1D8
                                      Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_CLOSE 8520D1D8
                                      Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_DEVICE_CONTROL 8520D1D8
                                      Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8520D1D8
                                      Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_POWER 8520D1D8
                                      Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_SYSTEM_CONTROL 8520D1D8
                                      Device \Driver\usbehci \Device\USBPDO-2 IRP_MJ_PNP 8520D1D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CREATE 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_READ 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_WRITE 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_FLUSH_BUFFERS 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_DEVICE_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_INTERNAL_DEVICE_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SHUTDOWN 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_CLEANUP 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_POWER 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_SYSTEM_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume1 IRP_MJ_PNP 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CREATE 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_READ 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_WRITE 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_FLUSH_BUFFERS 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_DEVICE_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_INTERNAL_DEVICE_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SHUTDOWN 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_CLEANUP 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_POWER 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_SYSTEM_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume2 IRP_MJ_PNP 857D51D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CREATE 852441D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_CLOSE 852441D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_READ 852441D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_WRITE 852441D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_FLUSH_BUFFERS 852441D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_DEVICE_CONTROL 852441D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_INTERNAL_DEVICE_CONTROL 852441D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SHUTDOWN 852441D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_POWER 852441D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_SYSTEM_CONTROL 852441D8
                                      Device \Driver\Cdrom \Device\CdRom0 IRP_MJ_PNP 852441D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CREATE 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_READ 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_WRITE 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_FLUSH_BUFFERS 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_DEVICE_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_INTERNAL_DEVICE_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SHUTDOWN 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_CLEANUP 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_POWER 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_SYSTEM_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume3 IRP_MJ_PNP 857D51D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CREATE 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_CLOSE 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_DEVICE_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_INTERNAL_DEVICE_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_POWER 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_SYSTEM_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-3 IRP_MJ_PNP 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CREATE 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_CLOSE 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_DEVICE_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_INTERNAL_DEVICE_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_POWER 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_SYSTEM_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort0 IRP_MJ_PNP 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CREATE 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_CLOSE 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_DEVICE_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_INTERNAL_DEVICE_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_POWER 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_SYSTEM_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdePort1 IRP_MJ_PNP 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CREATE 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_CLOSE 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_DEVICE_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_INTERNAL_DEVICE_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_POWER 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_SYSTEM_CONTROL 8576D1D8
                                      Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-e IRP_MJ_PNP 8576D1D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CREATE 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_READ 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_WRITE 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_FLUSH_BUFFERS 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_DEVICE_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_INTERNAL_DEVICE_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SHUTDOWN 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_CLEANUP 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_POWER 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_SYSTEM_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\HarddiskVolume4 IRP_MJ_PNP 857D51D8
                                      Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CREATE 8541C990
                                      Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLOSE 8541C990
                                      Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_DEVICE_CONTROL 8541C990
                                      Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_INTERNAL_DEVICE_CONTROL 8541C990
                                      Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_CLEANUP 8541C990
                                      Device \Driver\NetBT \Device\NetBt_Wins_Export IRP_MJ_PNP 8541C990
                                      Device \Driver\USBSTOR \Device\00000084 IRP_MJ_CREATE 85491890
                                      Device \Driver\USBSTOR \Device\00000084 IRP_MJ_CLOSE 85491890
                                      Device \Driver\USBSTOR \Device\00000084 IRP_MJ_READ 85491890
                                      Device \Driver\USBSTOR \Device\00000084 IRP_MJ_WRITE 85491890
                                      Device \Driver\USBSTOR \Device\00000084 IRP_MJ_DEVICE_CONTROL 85491890
                                      Device \Driver\USBSTOR \Device\00000084 IRP_MJ_INTERNAL_DEVICE_CONTROL 85491890
                                      Device \Driver\USBSTOR \Device\00000084 IRP_MJ_POWER 85491890
                                      Device \Driver\USBSTOR \Device\00000084 IRP_MJ_SYSTEM_CONTROL 85491890
                                      Device \Driver\USBSTOR \Device\00000084 IRP_MJ_PNP 85491890
                                      Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CREATE 8541C990
                                      Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLOSE 8541C990
                                      Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_DEVICE_CONTROL 8541C990
                                      Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_INTERNAL_DEVICE_CONTROL 8541C990
                                      Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_CLEANUP 8541C990
                                      Device \Driver\NetBT \Device\NetbiosSmb IRP_MJ_PNP 8541C990
                                      Device \Driver\USBSTOR \Device\00000085 IRP_MJ_CREATE 85491890
                                      Device \Driver\USBSTOR \Device\00000085 IRP_MJ_CLOSE 85491890
                                      Device \Driver\USBSTOR \Device\00000085 IRP_MJ_READ 85491890
                                      Device \Driver\USBSTOR \Device\00000085 IRP_MJ_WRITE 85491890
                                      Device \Driver\USBSTOR \Device\00000085 IRP_MJ_DEVICE_CONTROL 85491890
                                      Device \Driver\USBSTOR \Device\00000085 IRP_MJ_INTERNAL_DEVICE_CONTROL 85491890
                                      Device \Driver\USBSTOR \Device\00000085 IRP_MJ_POWER 85491890
                                      Device \Driver\USBSTOR \Device\00000085 IRP_MJ_SYSTEM_CONTROL 85491890
                                      Device \Driver\USBSTOR \Device\00000085 IRP_MJ_PNP 85491890
                                      Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_CREATE 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_CLOSE 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_DEVICE_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_INTERNAL_DEVICE_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_POWER 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_SYSTEM_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-0 IRP_MJ_PNP 852241D8
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{335F1D9F-7235-49C9-AAD7-E99CDD604F53} IRP_MJ_CREATE 8541C990
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{335F1D9F-7235-49C9-AAD7-E99CDD604F53} IRP_MJ_CLOSE 8541C990
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{335F1D9F-7235-49C9-AAD7-E99CDD604F53} IRP_MJ_DEVICE_CONTROL 8541C990
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{335F1D9F-7235-49C9-AAD7-E99CDD604F53} IRP_MJ_INTERNAL_DEVICE_CONTROL 8541C990
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{335F1D9F-7235-49C9-AAD7-E99CDD604F53} IRP_MJ_CLEANUP 8541C990
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{335F1D9F-7235-49C9-AAD7-E99CDD604F53} IRP_MJ_PNP 8541C990
                                      Device \Driver\usbohci \Device\USBFDO-1 IRP_MJ_CREATE 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-1 IRP_MJ_CLOSE 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-1 IRP_MJ_DEVICE_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-1 IRP_MJ_INTERNAL_DEVICE_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-1 IRP_MJ_POWER 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-1 IRP_MJ_SYSTEM_CONTROL 852241D8
                                      Device \Driver\usbohci \Device\USBFDO-1 IRP_MJ_PNP 852241D8
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_NAMED_PIPE 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLOSE 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_READ 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_WRITE 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_INFORMATION 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_INFORMATION 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_EA 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_EA 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FLUSH_BUFFERS 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_VOLUME_INFORMATION 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_VOLUME_INFORMATION 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DIRECTORY_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_FILE_SYSTEM_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_INTERNAL_DEVICE_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SHUTDOWN 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_LOCK_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CLEANUP 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_CREATE_MAILSLOT 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_SECURITY 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_SECURITY 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_POWER 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SYSTEM_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_DEVICE_CHANGE 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_QUERY_QUOTA 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_SET_QUOTA 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver IRP_MJ_PNP 854C1660
                                      Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_CREATE 8520D1D8
                                      Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_CLOSE 8520D1D8
                                      Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_DEVICE_CONTROL 8520D1D8
                                      Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_INTERNAL_DEVICE_CONTROL 8520D1D8
                                      Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_POWER 8520D1D8
                                      Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_SYSTEM_CONTROL 8520D1D8
                                      Device \Driver\usbehci \Device\USBFDO-2 IRP_MJ_PNP 8520D1D8
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_NAMED_PIPE 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLOSE 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_READ 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_WRITE 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_INFORMATION 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_INFORMATION 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_EA 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_EA 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FLUSH_BUFFERS 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_VOLUME_INFORMATION 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_VOLUME_INFORMATION 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DIRECTORY_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_FILE_SYSTEM_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_INTERNAL_DEVICE_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SHUTDOWN 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_LOCK_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CLEANUP 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_CREATE_MAILSLOT 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_SECURITY 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_SECURITY 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_POWER 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SYSTEM_CONTROL 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_DEVICE_CHANGE 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_QUERY_QUOTA 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_SET_QUOTA 854C1660
                                      Device \FileSystem\MRxSmb \Device\LanmanRedirector IRP_MJ_PNP 854C1660
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CREATE 857D51D8
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_READ 857D51D8
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_WRITE 857D51D8
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_FLUSH_BUFFERS 857D51D8
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_DEVICE_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_INTERNAL_DEVICE_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SHUTDOWN 857D51D8
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_CLEANUP 857D51D8
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_POWER 857D51D8
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_SYSTEM_CONTROL 857D51D8
                                      Device \Driver\Ftdisk \Device\FtControl IRP_MJ_PNP 857D51D8
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{4A4E9951-4753-43D3-9C2F-870569D6A285} IRP_MJ_CREATE 8541C990
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{4A4E9951-4753-43D3-9C2F-870569D6A285} IRP_MJ_CLOSE 8541C990
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{4A4E9951-4753-43D3-9C2F-870569D6A285} IRP_MJ_DEVICE_CONTROL 8541C990
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{4A4E9951-4753-43D3-9C2F-870569D6A285} IRP_MJ_INTERNAL_DEVICE_CONTROL 8541C990
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{4A4E9951-4753-43D3-9C2F-870569D6A285} IRP_MJ_CLEANUP 8541C990
                                      Device \Driver\NetBT \Device\NetBT_Tcpip_{4A4E9951-4753-43D3-9C2F-870569D6A285} IRP_MJ_PNP 8541C990
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_CREATE [F78618C0] fowf_n.sys
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_CLOSE 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_READ 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_WRITE 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION [F7861C60] fowf_n.sys
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_SET_EA 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP 8576C1D8
                                      Device \FileSystem\Fastfat \Fat IRP_MJ_PNP 8576C1D8
                                      Device \FileSystem\FltMgr \FileSystem\Filters\FltMgr IRP_MJ_SET_INFORMATION [F158069E] hidproc.sys
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_CREATE 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLOSE 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_READ 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_INFORMATION 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_SET_INFORMATION 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_QUERY_VOLUME_INFORMATION 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_DIRECTORY_CONTROL 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_FILE_SYSTEM_CONTROL 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_DEVICE_CONTROL 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_SHUTDOWN 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_LOCK_CONTROL 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_CLEANUP 85166720
                                      Device \FileSystem\Cdfs \Cdfs IRP_MJ_PNP 85166720

                                      ---- Threads - GMER 1.0.12 ----

                                      Thread 4:156 857E1450

                                      ---- EOF - GMER 1.0.12 ----
                                      • 1
                                      • 2
                                      • 3