Problème virusgarde.com

Résolu
Bonjour à tous,

Depuis quelques jours, j'ai un message du genre "votre ordi est infecté, cliquez ici pour le désinfecter", qui envoie vers la page "http://virusgarde.com".

J'ai fait tourner bitdefender & avg spyware, qui me répèrent un souci, mais n'arrivent pas à l'éradiquer, même en mode sans échec...

Pouvez-vous m'apporter votre aide ?

D'avance merci à vous.

A bientôt

Antonio

Ci-joint, le rapport hijackthis :

Logfile of HijackThis v1.99.1
Scan saved at 08:58:46, on 03/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\SNDVOL32.EXE
D:\Utilitaires\Desinfectant\hijackthis_199\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {BB190C66-082F-446C-911A-CB01DDEB759A} - C:\WINDOWS\system32\dfrgre.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/71365/kavwebscan_unicode.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Configuration: Windows XP
Internet Explorer 6.0

32 réponses

Résumé de la discussion

Le fil aborde une infection informatique où un message avertit que l’ordinateur est infecté et redirige vers virusgarde.com, avec des symptômes persistants malgré Avast et AVG en mode normal. Plusieurs réponses proposent des outils de diagnostic et de nettoyage dédiés, notamment DiagHelp de Malekal et SREng, avec instructions précises pour extraire les résultats et éviter l’exécution accidentelle. D’autres interventions suggèrent ensuite l’emploi de ComboFix et la collecte de rapports HijackThis pour partager des éléments de registre et de modules malveillants, afin de guider une désinfection coordonnée et documentée. En parallèle, le fil montre une diversité de logs et de composants installés, rappelant l’importance de ne pas exécuter des fichiers suspects et de redémarrer selon les consignes des outils.

Bobot (l’IA à votre service)
  1. Salut,
    Deja, je ne suit pas un pro de hijackthis, mais internet n'est pas en lui meme capable de te detecter une infection.
    1. Contributeur sécurité
      Salut,

      1/ * Ouvrir l'explorateur windows (Démarrer>programmes>Accessoires>Explorateur windows ou Démarrer>programmes>Explorateur windows).
      * Cliquer sur outils>options des dossiers>affichage.
      * Sélectionner :
      o afficher les fichiers et dossiers cachés,
      o décocher "masquer les extensions des fichiers dont le type est connu",
      o décocher masquer les fichiers protégés du système d'exploitation (recommandé)".

      * "appliquer" et "ok"

      2/ * Peux-tu tester ceci : C:\WINDOWS\system32\dfrgre.dll
      * Clique sur ce lien : http://www.virustotal.com/en/indexf.html
      * Clique sur parcourir et indique le chemin du fichier que j’ai désigné.
      * Clique sur send. Au bout de quelques minutes, un rapport est généré. Poste-le dans ta prochaine réponse.

      Edite ce rapport.

      FillPCA
      1. Bonjour, et merci pour votre aide.

        C'est en effet ce fichier qu'AVG n'arrivait pas à nettoyer, même en mode sans échec.

        Voilà le rapport :

        Antivirus Version Dernière mise à jour Résultat
        AhnLab-V3 2007.12.1.0 2007.12.03 -
        AntiVir 7.6.0.34 2007.12.03 -
        Authentium 4.93.8 2007.12.02 -
        Avast 4.7.1074.0 2007.12.02 -
        AVG 7.5.0.503 2007.12.02 -
        BitDefender 7.2 2007.12.03 -
        CAT-QuickHeal 9.00 2007.12.01 -
        ClamAV 0.91.2 2007.12.03 -
        DrWeb 4.44.0.09170 2007.12.03 -
        eSafe 7.0.15.0 2007.11.29 -
        eTrust-Vet 31.3.5340 2007.11.30 -
        Ewido 4.0 2007.12.02 -
        FileAdvisor 1 2007.12.03 -
        Fortinet 3.14.0.0 2007.12.03 -
        F-Prot 4.4.2.54 2007.12.02 -
        F-Secure 6.70.13030.0 2007.12.03 Trojan.Win32.BHO.abo
        Ikarus T3.1.1.12 2007.12.03 Trojan-PWS.Win32.Lmir
        Kaspersky 7.0.0.125 2007.12.03 Trojan.Win32.BHO.abo
        McAfee 5175 2007.11.30 -
        Microsoft 1.3007 2007.12.03 -
        NOD32v2 2697 2007.12.02 -
        Norman 5.80.02 2007.11.30 -
        Panda 9.0.0.4 2007.12.02 Suspicious file
        Prevx1 V2 2007.12.03 -
        Rising 20.21.01.00 2007.12.03 -
        Sophos 4.23.0 2007.12.03 -
        Sunbelt 2.2.907.0 2007.12.01 -
        Symantec 10 2007.12.03 -
        TheHacker 6.2.9.147 2007.12.01 -
        VBA32 3.12.2.5 2007.12.02 -
        VirusBuster 4.3.26:9 2007.12.02 -
        Webwasher-Gateway 6.6.2 2007.12.03 -

        Information additionnelle
        File size: 93184 bytes
        MD5: d5830514bdb623c0ac5266d45c24a1dc
        SHA1: 87ae79dad397223692fdf1bd41b7d2dae8a77fbb
        PEiD: -
        packers: UPX
        packers: UPX
        packers: PE_Patch.UPX, UPX
        1. Contributeur sécurité
          Re,

          1/ * Télécharge OTMoveIt (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
          * Double-clique sur OTMoveIt.exe pour lancer le programme,
          * Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste List Of Files/Folders to be moved" :

          C:\WINDOWS\system32\dfrgre.dll

          * Clique sur MoveIt! pour lancer la suppression,
          * Le résultat appraraîtra dans le cadre Results.
          * Clique sur Exit pour fermer le programme.
          * Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
          * Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.

          2/ Ouvre Hijackthis>"Do a scan only" et coche cette ligne :
          O2 - BHO: (no name) - {BB190C66-082F-446C-911A-CB01DDEB759A} - C:\WINDOWS\system32\dfrgre.dll

          Clique sur fix/réparer.

          3/ Edite le rapport OTMoveIt et un nouveau rapport Hijackthis.

          FillPCA
          1. Re ;o)

            J'ai fait tout ça. Otmoveit m'a demandé de rebooter, je l'ai fait. Le rapport hijackthis montrait que le fichier dfrgre.dll était toujours là. J'ai fait "fix checked" après l'avoir sélectionné, et il est toujours là...

            Voilà les rapports... :

            ========================
            OTMOVEIT
            ========================

            C:\WINDOWS\system32\dfrgre.dll unregistered successfully.
            File move failed. C:\WINDOWS\system32\dfrgre.dll scheduled to be moved on reboot.

            Created on 12/03/2007 09:31:27

            ========================
            HIJACKTHIS
            ========================

            Logfile of HijackThis v1.99.1
            Scan saved at 10:07:59, on 03/12/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
            C:\WINDOWS\system32\taskmgr.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Mozilla Thunderbird\thunderbird.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\system32\NOTEPAD.EXE
            D:\Utilitaires\Desinfectant\hijackthis_199\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {BB190C66-082F-446C-911A-CB01DDEB759A} - C:\WINDOWS\system32\dfrgre.dll
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/71365/kavwebscan_unicode.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
            O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
            O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
            O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            1. Contributeur sécurité
              Re,

              Je ne suis pas surpris...

              * Télécharge KillAFile (par Marckie) sur ton Bureau : http://users.telenet.be/marcvn/tools/KillAFile.exe
              * Double clique sur KillAFile.exe afin de le lancer. Une fenêtre DOS au fond rouge apparaîtra.
              * Tape le chiffre 2 puis valide avec la touche Entrée pour choisir "Replace a file by a dummy on reboot".
              * Tu verras maintenant une nouvelle invite : "Insert full path and filename to delete. and then press enter:"
              * Tu dois taper ceci, au complet et très exactement :

              C:\WINDOWS\system32\dfrgre.dll

              * Appuie sur la touche Entrée.
              * À l'invite qui suit, appuie sur n'importe quelle touche pour valider (Entrée par exemple).
              * Ton PC va maintenant redémarrer.
              * Edite le rapport généré par killafile. Il se trouve aussi ici : C:\kaflog.txt

              FillPCA
              1. C'est fait.

                Voilà le rapport :

                KILLAFILE - logfile

                Running from: "C:\Documents and Settings\Tonio\Bureau"

                Replace on reboot: C:\WINDOWS\system32\dfrgre.dll

                --- Rebooting the computer ---
                1. Contributeur sécurité
                  Re,

                  OK. Peux-tu éditer un rapport Hijackthis ?

                  FillPCA
                  1. oui, pardon, je l'avais fait en plus, mais je l'ai pas mis... ;o)

                    Logfile of HijackThis v1.99.1
                    Scan saved at 10:30:14, on 03/12/2007
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                    C:\WINDOWS\system32\taskmgr.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                    C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\Program Files\Mozilla Thunderbird\thunderbird.exe
                    C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
                    C:\Program Files\Internet Explorer\iexplore.exe
                    D:\Utilitaires\Desinfectant\hijackthis_199\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {BB190C66-082F-446C-911A-CB01DDEB759A} - C:\WINDOWS\system32\dfrgre.dll
                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                    O4 - HKLM\..\Run: [KillAFile] C:\Documents and Settings\Tonio\Bureau\KillAFile.exe /rd
                    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                    O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/71365/kavwebscan_unicode.cab
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                    O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                    O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
                    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                    1. Contributeur sécurité
                      Re,

                      1/ Ouvre Hijackthis>"Do a scan only" et coche ceci :
                      O2 - BHO: (no name) - {BB190C66-082F-446C-911A-CB01DDEB759A} - C:\WINDOWS\system32\dfrgre.dl
                      O4 - HKLM\..\Run: [KillAFile] C:\Documents and Settings\Tonio\Bureau\KillAFile.exe /rd


                      Clique sur fix/réparer.

                      2/ * Double-clique sur OTMoveIt.exe pour lancer le programme,
                      * Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste List Of Files/Folders to be moved" :

                      C:\WINDOWS\system32\dfrgre.dll

                      * Clique sur MoveIt! pour lancer la suppression,
                      * Le résultat appraraîtra dans le cadre Results.
                      * Clique sur Exit pour fermer le programme.
                      * Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
                      * Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.

                      3/ Edite le rapport OTMoveIt et un nouveau rapport Hijackthis.

                      FillPCA
                      1. Re,

                        Voilà les rapports. Ca a l'air costaud, le fichier est toujours présent...

                        ==============
                        OTMOVEIT
                        ==============

                        C:\WINDOWS\system32\dfrgre.dll unregistered successfully.
                        File move failed. C:\WINDOWS\system32\dfrgre.dll scheduled to be moved on reboot.

                        Created on 12/03/2007 10:44:54

                        ==============
                        HIJACKTHIS
                        ==============
                        Logfile of HijackThis v1.99.1
                        Scan saved at 10:53:46, on 03/12/2007
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                        C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\taskmgr.exe
                        C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\WINDOWS\system32\wuauclt.exe
                        C:\Program Files\Mozilla Thunderbird\thunderbird.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\WINDOWS\system32\NOTEPAD.EXE
                        D:\Utilitaires\Desinfectant\hijackthis_199\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {BB190C66-082F-446C-911A-CB01DDEB759A} - C:\WINDOWS\system32\dfrgre.dll
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/71365/kavwebscan_unicode.cab
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                        O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
                        O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                        O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                        1. Contributeur sécurité
                          Re,

                          On rencontre actuellement pas mal d'infections de cette famille et qui peuvent être très résistance, mais on l'aura. Ca prendra simplement un peu plus de temps.

                          * Télécharge delfkill32 (de Marckie) sur le bureau : http://users.telenet.be/marcvn/tools/win32delfkil.exe
                          * Double clique sur win32delfkil.exe et accepte les instructions. Ne t'inquiète pas si les icones disparaissent.
                          Si le PC ne redémarre pas tout seul, fais-le.
                          Poste le contenu du bloc-note qui s'ouvre.

                          Edite aussi un rapport Hijackthis.

                          FillPCA
                          1. Re,

                            hé bien, merci infiniment pour le temps passé à m'aider à résoure ce problème !

                            Voici les rapports :

                            ===================
                            DELFKILL
                            ===================
                            WIN32DELFKIL LOGFILE - by Marckie

                            version 3.131
                            03/12/2007 11:04:35,25
                            running from: "C:\Documents and Settings\Tonio\Bureau"

                            --- File(s) found in Windows directory ---

                            --- File(s) found in system32 folder ---

                            --- Services ---

                            --- Export SharedTaskScheduler key ---
                            REGEDIT4

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                            "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
                            "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

                            --- Notify key ---

                            --- rebooting the computer ---

                            --- File(s) found in Windows directory ---

                            --- File(s) found in system32 folder ---

                            --- Services ---

                            --- Export SharedTaskSchedulerkey ---
                            REGEDIT4

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                            "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
                            "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

                            --- Notify key ---

                            Finished!

                            ===================
                            HIJACKTHIS
                            ===================

                            Logfile of HijackThis v1.99.1
                            Scan saved at 11:12:58, on 03/12/2007
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                            C:\WINDOWS\system32\taskmgr.exe
                            C:\WINDOWS\system32\wuauclt.exe
                            C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
                            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            C:\Program Files\Mozilla Thunderbird\thunderbird.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            D:\Utilitaires\Desinfectant\hijackthis_199\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: (no name) - {BB190C66-082F-446C-911A-CB01DDEB759A} - C:\WINDOWS\system32\dfrgre.dll
                            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                            O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                            O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/71365/kavwebscan_unicode.cab
                            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                            O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                            O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
                            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                            O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                            1. Contributeur sécurité
                              Bon, on fait autrement.

                              * Télécharge combofix.exe (par sUBs) sur ton Bureau : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                              * Double clique combofix.exe et suis les invites.
                              * Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                              Edite aussi un rapport Hijackthis.

                              FillPCA
                              1. Contributeur sécurité
                                Re,

                                Je dois m'absenter. Je reprends en fin d'après-midi.

                                FillPCA
                                1. OK, merci d'avoir prévenu de votre absence.

                                  J'ai été un peu long : la 1ère fois, mon portable a planté (écran bleu, vidage mémoire physique etc, etc...). J'ai tout de même relancé Combofix après ça, et ça a fonctionné sans souci.

                                  A tout-à-l'heure, et merci encore du temps que vous m'accordez, et de votre patience ;o)

                                  Antonio

                                  Voilà les 2 rapports :

                                  ===================
                                  COMBOFIX
                                  ===================
                                  ComboFix 07-12-02.6 - Tonio 2007-12-03 11:34:09.2 - NTFSx86
                                  Running from: C:\Documents and Settings\Tonio\Bureau\ComboFix.exe
                                  .

                                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                  .

                                  C:\WINDOWS\opera6.ini
                                  C:\WINDOWS\system32\taskmgr.com

                                  .
                                  ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

                                  .
                                  -------\npf

                                  ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-03 to 2007-12-03 ))))))))))))))))))))))))))))))))))))
                                  .

                                  2007-12-03 11:04 . 2007-12-03 11:04 <REP> d-------- C:\_backupD
                                  2007-12-03 11:04 . 2007-12-03 11:04 280,286 --a------ C:\win32delfkil.exe
                                  2007-12-03 10:15 . 2007-12-03 11:04 <REP> d-------- C:\WINDOWS\system32\regdacl
                                  2007-12-03 10:15 . 2007-12-03 11:04 90,112 --a------ C:\WINDOWS\system32\regdacl.exe
                                  2007-12-03 10:15 . 2007-12-03 11:04 53,248 --a------ C:\WINDOWS\system32\process.exe
                                  2007-12-03 10:15 . 2007-12-03 11:04 16,384 --a------ C:\WINDOWS\system32\restart.exe
                                  2007-12-03 10:15 . 2007-12-03 11:04 4,096 --a------ C:\WINDOWS\system32\reboot.exe
                                  2007-11-29 15:17 . 19,200 C:\WINDOWS\system32\drivers\gzrmxkhe.dat
                                  2007-11-29 15:15 . 2001-10-03 00:20 111,104 --a------ C:\WINDOWS\system32\dfrgre.2
                                  2007-11-29 15:15 . 2001-10-03 00:20 93,184 --a------ C:\WINDOWS\system32\dfrgre.dll
                                  2007-11-29 15:15 . 2001-10-03 00:20 83,456 --a------ C:\WINDOWS\system32\dfrgre.1
                                  2007-11-23 12:43 . 2007-11-24 09:46 <REP> d-------- C:\Program Files\Spyware Terminator
                                  2007-11-22 23:50 . 2005-02-11 22:46 371,712 -ra------ C:\WINDOWS\system32\drivers\BCMWL5.SYS
                                  2007-11-22 15:01 . 2007-11-30 16:54 1,404 --a------ C:\WINDOWS\system32\tmp.reg
                                  2007-11-22 14:59 . 2007-11-22 15:00 <REP> d-------- C:\Program Files\RogueRemover FREE
                                  2007-11-22 11:42 . 2007-11-22 11:55 <REP> d-------- C:\Program Files\Navilog1
                                  2007-11-17 12:05 . 2007-11-17 12:05 754 --a------ C:\WINDOWS\WORDPAD.INI

                                  .
                                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                  .
                                  2007-12-03 10:29 --------- d-----w C:\Program Files\Mozilla Thunderbird
                                  2007-11-29 14:55 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                                  2007-10-28 21:29 --------- d-----w C:\Program Files\CDex_150
                                  2007-10-28 21:20 --------- d-----w C:\Documents and Settings\Tonio\Application Data\Ahead
                                  2007-10-18 07:50 --------- d-----w C:\Program Files\Java
                                  .

                                  ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                  .
                                  .
                                  REGEDIT4
                                  *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BB190C66-082F-446C-911A-CB01DDEB759A}]
                                  2001-10-03 00:20 93184 --a------ C:\WINDOWS\system32\dfrgre.dll

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 11:06]
                                  "Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2005-11-14 23:51]

                                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15:09]

                                  R0 fcsrelmg;fcsrelmg;C:\WINDOWS\system32\drivers\gzrmxkhe.dat
                                  R3 fbxusb;FreeBox USB Network Adapter;C:\WINDOWS\system32\DRIVERS\fbxusb.sys
                                  S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187B.sys

                                  .
                                  **************************************************************************

                                  catchme 0.3.1318 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                  Rootkit scan 2007-12-03 11:41:30
                                  Windows 5.1.2600 Service Pack 2 NTFS

                                  scanning hidden processes ...

                                  scanning hidden autostart entries ...

                                  scanning hidden files ...

                                  scan completed successfully
                                  hidden files: 0

                                  **************************************************************************
                                  .
                                  Completion time: 2007-12-03 11:44:22 - machine was rebooted
                                  .
                                  --- E O F ---

                                  ===================
                                  HIJACKTHIS
                                  ===================
                                  Logfile of HijackThis v1.99.1
                                  Scan saved at 11:49:39, on 03/12/2007
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
                                  C:\Program Files\Mozilla Thunderbird\thunderbird.exe
                                  C:\WINDOWS\system32\taskmgr.exe
                                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                  D:\Utilitaires\Desinfectant\hijackthis_199\HijackThis.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: (no name) - {BB190C66-082F-446C-911A-CB01DDEB759A} - C:\WINDOWS\system32\dfrgre.dll
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                  O4 - Global Startup: Wireless Configuration Utility HW.14.lnk = C:\Program Files\TRENDnet\TEW-424UB\WlanCU.exe
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/71365/kavwebscan_unicode.cab
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                  O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                                  O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
                                  O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                  O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                                  1. Contributeur sécurité
                                    Re,

                                    Ouvre un nouveau fichier du Bloc-notes , puis "Copie/Colle" tout le contenu de la boîte Code ci-bas dans le fichier (incluant l'URL):

                                    Sauvegarde ce fichier sous le nom de CFScript.txt sur ton Bureau.

                                    http://www.commentcamarche.net/forum/affich-4210247-probleme-virusgarde-com#0

                                    Registry::
                                    [-HKEY_LOCAL_MACHINE \SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BB190C66-082F-446C-911A-CB01DDEB759A}]

                                    Collect::
                                    C:\WINDOWS\system32\dfrgre.dll


                                    Déplace CFScript.txt sur ComboFix.exe
                                    ComboFix sera lancé.

                                    De plus, ComboFix créera ces fichiers sur ton Bureau :

                                    * Un fichier zippé nommé Submit [Date Time].zip
                                    * Un second fichier nommé - CF-Submit.htm

                                    ComboFix peut exiger un redémarrage pour compléter son travail. Accepte.

                                    Lorsque l'outil aura terminé, un rapport ComboFix.log apparaîtra à l'écran.

                                    Une nouvelle fenêtre avec invite "Submit Files for further analysis" s'ouvrira. Clique "OK"

                                    Ton navigateur se lancera automatiquement avec le fichier CF-Submit.htm et une fenêtre s'ouvrira :

                                    * Clique sur le bouton "Browse"("Parcourir") et navigue vers le fichier
                                    Submit [Date Time].zip qui est sur ton Bureau.
                                    * Clique sur le fichier afin de le sélectionner.
                                    * Soumets le fichier en cliquant "OK"

                                    Lorsque cette opération sera complétée, tu peux supprimer ces deux fichiers qui se trouvent sur ton Bureau.

                                    Prière de poster les deux rapports suivants dans ta prochaine réponse :

                                    - Combofix.txt
                                    - Un nouveau rapport HijackThis

                                    FillPCA
                                    1. bonjour je suis attentivement le topic car moi aussi depuis quelque jours j'ai le meme problème et kaspersky s'enerve toute les 30 secondes sans pouvoir rien faire ... je suis pas très calé en informatique donc je pige pas ce qu'est "Hijack" et tout le reste mais je vais chercher^^
                                      J'espere que vous trouverez la solution

                                      Merci
                                      1. Contributeur sécurité
                                        Salut,

                                        Il faudrait que tu ouvres ton propre sujet. Tu auras plus de chance d'obtenir une réponse et cela évitera une confusion entre les deux sujets, car chaque cas est spécifique : une même infection peut revêtir des formes variables.

                                        FillPCA
                                        1. bah pour l'instant j'ai repris tout ce qui a été fais depuis le début du topic et c'est similaire en tout pointje vais continuer a voir
                                          • 1
                                          • 2