Win32.Agent.ctz

Résolu
Bonjour,
Cela fait quand meme pas mal de temps que mon ordinateur é infecter de virus que j'arive a supprimer mais il revienne de nouveau aprés mon redemarage. Aprés tous ce temps a chercher une reponse a mon probleme je m'en remet à vous!

Mon anti virus (avast) a détecté Trojan.Win32.BHO.zn, Trojan.Win32.BHO.alf, Adware.Win32.SuperJuan.bb, ainsi que plein d'autres dans pas mal de mes fichier

En regardant les solution péché sur internet j'ai instalé 2a-squared Free qui pendant son scan à trouver pas mal de chose mais a fait s'affolé mon anti virus Avast. Ad-Aware SE Personal, Avast et 2a-squared Free on trouvé pas mal de chose mais a mon grand regret au demarage suivant mon anti virus a redecouvert les mm virus. A L'AIDE !!!!
En vous remerciant et en attente de votre reponce, je vous colle un rapport HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:00:15, on 26/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\bymmhocr.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\a-squared Free\a2free.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sapo.pt/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar6.dll
O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [74a2ef0b] rundll32.exe "C:\WINDOWS\system32\mwtftbeu.dll",b
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: (no name) - {49783ED4-258D-4f9f-BE11-137C18D3E543} - (no file)
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\HP_Propriétaire\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {A4069847-C342-48E2-9257-01A24E5C78EA} (F-Secure Online Scanner 3.2) - https://www.f-secure.com/en/home/support
O18 - Protocol: hola - {626601A0-4BAE-11D1-A7E1-00A0246C1E64} - (no file)
O18 - Protocol: holb - {626601A1-4BAE-11D1-A7E1-00A0246C1E64} - (no file)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: DomainService - - C:\WINDOWS\system32\bymmhocr.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

--
End of file - 7533 bytes
Configuration: Windows XP
Internet Explorer 7.0

49 réponses

Résumé de la discussion

Infections persistantes sur une machine Windows XP, avec des virus et malwares qui réapparaissent après le redémarrage, Avast détectant Trojan.Win32.BHO.zn, Trojan.Win32.BHO.alf et Adware.Win32.SuperJuan.bb, et un rapport HijackThis détaillant de nombreuses entrées potentiellement malveillantes. Plusieurs outils tels qu'Avast, Ad-Aware SE Personal, 2a-squared Free et HijackThis signalent des composants malveillants et des entrées de démarrage problématiques, ce qui confirme l'étendue du problème. Des mesures recommandées incluent démarrer en mode sans échec, désactiver les objets non autorisés et nettoyer les entrées BHO via HijackThis, puis vérifier les services et les programmes qui se lancent au démarrage. En dernier lieu, l'analyse doit s'étendre aux extensions de navigateur et barres d'outils actives, afin d'identifier les composants résiduels et prévenir les redémarrages répétés.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonsoir,

    Télécharge navilog1 (Merci il.mafioso!)

    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    * Ensuite double clique sur navilog1.exe pour lancer l'installation.

    * Une fois l'installation terminée, le fix s'exécutera automatiquement.

    * (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    * Laisse-toi guider. Au menu principal, choisis 1 et valides.

    /*\ Ne fais pas le choix 2,3 ou 4 sans notre avis/accord /*\

    * Patiente jusqu'au message : *** Analyse terminée le ..... ***

    * Appuie sur une touche comme demandé, le Bloc-notes va s'ouvrir.

    * Copie-colle l'intégralité du rapport dans ta prochaine réponse. Referme le Bloc-notes.

    * Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    0
    1. Bonsoir Philae, je vous remercie pour votre reponce aussi rapide. J'ai lancer une analyse navilog1 une foi celle ci terminer je vous enverez l'intégralité du rapport.
      0
      1. voci le rapport Navilog1:

        Search Navipromo version 3.3.8 commencé le 26/12/2007 à 18:17:44,59

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!
        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

        Outil exécuté depuis C:\Program Files\navilog1
        Mise à jour le 11.12.2007 à 18h00 par IL-MAFIOSO

        Microsoft Windows XP [version 5.1.2600]
        Internet Explorer : 7.0.5730.11
        Système de fichiers : NTFS

        Executé en mode normal

        *** Recherche Programmes installés ***

        *** Recherche dossiers dans C:\WINDOWS ***

        *** Recherche dossiers dans C:\Program Files ***

        *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

        *** Recherche dossiers dans "C:\Documents and Settings\HP_Propriétaire\application data" ***

        *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
        pour + d'infos : http://www.gmer.net

        Aucun Fichier trouvé

        *** Recherche avec GenericNaviSearch ***
        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
        !!! A vérifier impérativement avant toute suppression manuelle !!!

        * Recherche dans C:\WINDOWS\system32 *

        * Recherche dans "C:\Documents and Settings\HP_Propriétaire\local settings\application data" *

        *** Recherche fichiers ***

        C:\WINDOWS\pack.epk trouvé !
        C:\WINDOWS\tmlpcert2007 trouvé !

        *** Recherche clés spécifiques dans le Registre ***

        HKEY_CURRENT_USER\Software\Lanconfig trouvé !

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche nouveaux fichiers Instant Access :

        2)Recherche Heuristique :

        * Dans C:\WINDOWS\system32 :

        cvxnqxh.dat trouvé !
        cvxnqxh_nav.dat trouvé !

        * Dans "C:\Documents and Settings\HP_Propriétaire\local settings\application data" :

        3)Recherche Certificats :

        Certificat Egroup trouvé !

        4)Recherche fichiers connus :

        C:\WINDOWS\system32\nqtwa.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
        C:\WINDOWS\system32\nqtwa.bak1 trouvé ! infection Vundo possible non traitée par cet outil !
        C:\WINDOWS\system32\nqtwa.bak2 trouvé ! infection Vundo possible non traitée par cet outil !

        *** Analyse terminée le 26/12/2007 à 18:42:46,85 ***
        0
        1. Contributeur sécurité
          re ok, plusieurs infections donc

          on continue

          * Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.

          * Au menu principal, choisis 2 et valide.

          * Le fix va t'informer qu'il va alors redémarrer ton PC

          * Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts

          * Appuie sur une touche comme demandé. (si ton Pc ne redémarre pas automatiquement, fais le toi même)

          * Au redémarrage de ton PC, choisis ta session habituelle.

          * Patiente jusqu'au message : *** Nettoyage Termine le ..... ***

          * Le Bloc-notes va s'ouvrir.

          * Sauvegarde le rapport de manière à le retrouver.

          * Referme le Bloc-Notes. Ton bureau va réapparaître.

          * Note : Si ton bureau ne réapparaît pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.

          * Rends-toi à l'onglet "Processus", clique en haut à gauche sur > Fichiers et choisis > Exécuter

          * Tape explorer et valide. Celà te fera apparaître ton Bureau.

          * Tu posteras le rapport de Navilog1

          ensuite

          * Télécharge VundoFix.exe (par Atribune) sur ton Bureau

          http://www.atribune.org/ccount/click.php?id=4

          * Double-clique VundoFix.exe afin de le lancer

          * Clique sur le bouton Scan for Vundo

          * Lorsque le scan est complété, clique sur le bouton Remove Vundo

          * Une invite te demandera si tu veux supprimer les fichiers, clique YES

          * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers

          * Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK

          * Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse

          Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".

          ainsi qu'un nouveau rapport hijackthis

          je serais là après diner

          0
          1. Re, voci le rapport de Navilog1 dans mon prochain message j'y mettrai le rapport Vundo.

            Clean Navipromo version 3.3.8 commencé le 26/12/2007 à 19:11:53,13

            Outil exécuté depuis C:\Program Files\navilog1
            Mise à jour le 11.12.2007 à 18h00 par IL-MAFIOSO

            Microsoft Windows XP [version 5.1.2600]
            Internet Explorer : 7.0.5730.11
            Système de fichiers : NTFS

            Mode suppression automatique

            *** fsbl1.txt non trouvé ***
            (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

            *** Suppression avec sauvegardes résultats GenericNaviSearch ***

            * Suppression dans C:\WINDOWS\System32 *

            * Suppression dans "C:\Documents and Settings\HP_Propriétaire\local settings\application data" *

            *** Suppression dossiers dans C:\WINDOWS ***

            *** Suppression dossiers dans C:\Program Files ***

            *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

            *** Suppression dossiers dans "C:\Documents and Settings\HP_Propriétaire\application data" ***

            *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

            *** Suppression fichiers ***

            C:\WINDOWS\pack.epk supprimé !
            C:\WINDOWS\tmlpcert2007 supprimé !

            *** Suppression fichiers temporaires ***

            Nettoyage contenu C:\WINDOWS\Temp effectué !
            Nettoyage contenu C:\Documents and Settings\HP_Propri‚taire\local settings\Temp effectué !

            *** Traitement Recherche complémentaire ***
            (Recherche fichiers spécifiques)

            1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

            2)Recherche, création sauvegardes et suppression Heuristique :

            * Dans C:\WINDOWS\system32 *

            cvxnqxh.dat trouvé !
            Copie cvxnqxh.dat réalisée avec succès !
            cvxnqxh.dat supprimé !

            cvxnqxh_nav.dat trouvé !
            Copie cvxnqxh_nav.dat réalisée avec succès !
            cvxnqxh_nav.dat supprimé !

            cvxnqxh_navps.dat trouvé !
            Copie cvxnqxh_navps.dat réalisée avec succès !
            cvxnqxh_navps.dat supprimé !

            * Dans "C:\Documents and Settings\HP_Propriétaire\local settings\application data" *

            *** Sauvegarde du Registre vers dossier Backupnavi ***

            sauvegarde du Registre réalisée avec succès !

            *** Nettoyage Registre ***

            Nettoyage Registre Ok

            *** Certificats ***

            Certificat Egroup supprimé !

            *** Nettoyage terminé le 26/12/2007 à 19:16:37,64 ***
            0
            1. Contributeur sécurité
              tu reposteras un nouveau rapport hijackthis stp

              je verrais après dîner
              0
              1. voici le rapport vundo, mais apres plusieur annalyse il en reste toujours un qui perciste:

                VundoFix V6.7.7

                Checking Java version...

                Java version is 1.4.2.3
                Old versions of java are exploitable and should be removed.

                Scan started at 19:28:51 26/12/2007

                Listing files found while scanning....

                C:\WINDOWS\system32\amnryyyn.dll
                C:\WINDOWS\system32\avilnjbe.exe
                C:\WINDOWS\system32\awtqn.dll
                C:\WINDOWS\system32\ayccwpsd.dll
                C:\WINDOWS\system32\bgyjyvpf.dll
                C:\WINDOWS\system32\bkufwonb.ini
                C:\WINDOWS\system32\blrpxmsc.dll
                C:\WINDOWS\system32\bnowfukb.dll
                C:\WINDOWS\system32\boruhfoa.dll
                C:\WINDOWS\system32\bymmhocr.exe
                C:\WINDOWS\system32\cjtvejcp.dll
                C:\WINDOWS\system32\dcjpfsfr.dll
                C:\WINDOWS\system32\depkygkp.dll
                C:\WINDOWS\system32\dspwccya.ini
                C:\WINDOWS\system32\faspwsca.dll
                C:\WINDOWS\system32\fypqwqvb.dll
                C:\WINDOWS\system32\hbpjimte.dll
                C:\WINDOWS\system32\ijbepcrj.dll
                C:\WINDOWS\system32\itycfkgb.dll
                C:\WINDOWS\system32\jnhroibn.dll
                C:\WINDOWS\system32\kncynakv.dll
                C:\WINDOWS\system32\ldxpwpdw.dll
                C:\WINDOWS\system32\mwtftbeu.dll
                C:\WINDOWS\system32\nolbypfn.dll
                C:\WINDOWS\system32\nqtwa.bak1
                C:\WINDOWS\system32\nqtwa.bak2
                C:\windows\system32\nqtwa.ini
                C:\windows\system32\nqtwa.ini2
                C:\windows\system32\nqtwa.tmp
                C:\WINDOWS\system32\obkqwcqx.dll
                C:\WINDOWS\system32\ovkhyynv.dll
                C:\WINDOWS\system32\pildbbok.dll
                C:\WINDOWS\system32\pkvymyxv.dll
                C:\WINDOWS\system32\qiothgum.dll
                C:\WINDOWS\system32\qonsvblb.dll
                C:\WINDOWS\system32\quwiuust.dll
                C:\WINDOWS\system32\qvmraoqf.dll
                C:\WINDOWS\system32\rsllqsah.dll
                C:\WINDOWS\system32\rvbivofd.dll
                C:\WINDOWS\system32\smulwiyg.dll
                C:\WINDOWS\system32\tapbmryx.dll
                C:\WINDOWS\system32\tritwsvd.dll
                C:\WINDOWS\system32\ugcjmpum.dll
                C:\WINDOWS\system32\uktynypc.dll
                C:\WINDOWS\system32\umkodabd.dll
                C:\WINDOWS\system32\uyskoeqy.dll
                C:\WINDOWS\system32\xfwijgqf.dll
                C:\WINDOWS\system32\ydgyleey.dll
                C:\WINDOWS\system32\yfjfgqib.dll

                Beginning removal...

                Attempting to delete C:\WINDOWS\system32\amnryyyn.dll
                C:\WINDOWS\system32\amnryyyn.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\avilnjbe.exe
                C:\WINDOWS\system32\avilnjbe.exe Has been deleted!

                Attempting to delete C:\WINDOWS\system32\awtqn.dll
                C:\WINDOWS\system32\awtqn.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\ayccwpsd.dll
                C:\WINDOWS\system32\ayccwpsd.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\bgyjyvpf.dll
                C:\WINDOWS\system32\bgyjyvpf.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\bkufwonb.ini
                C:\WINDOWS\system32\bkufwonb.ini Has been deleted!

                Attempting to delete C:\WINDOWS\system32\blrpxmsc.dll
                C:\WINDOWS\system32\blrpxmsc.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\bnowfukb.dll
                C:\WINDOWS\system32\bnowfukb.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\boruhfoa.dll
                C:\WINDOWS\system32\boruhfoa.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\bymmhocr.exe
                C:\WINDOWS\system32\bymmhocr.exe Could not be deleted.

                Attempting to delete C:\WINDOWS\system32\cjtvejcp.dll
                C:\WINDOWS\system32\cjtvejcp.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\dcjpfsfr.dll
                C:\WINDOWS\system32\dcjpfsfr.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\depkygkp.dll
                C:\WINDOWS\system32\depkygkp.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\dspwccya.ini
                C:\WINDOWS\system32\dspwccya.ini Has been deleted!

                Attempting to delete C:\WINDOWS\system32\faspwsca.dll
                C:\WINDOWS\system32\faspwsca.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\fypqwqvb.dll
                C:\WINDOWS\system32\fypqwqvb.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\hbpjimte.dll
                C:\WINDOWS\system32\hbpjimte.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\ijbepcrj.dll
                C:\WINDOWS\system32\ijbepcrj.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\itycfkgb.dll
                C:\WINDOWS\system32\itycfkgb.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\jnhroibn.dll
                C:\WINDOWS\system32\jnhroibn.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\kncynakv.dll
                C:\WINDOWS\system32\kncynakv.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\ldxpwpdw.dll
                C:\WINDOWS\system32\ldxpwpdw.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\mwtftbeu.dll
                C:\WINDOWS\system32\mwtftbeu.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\nolbypfn.dll
                C:\WINDOWS\system32\nolbypfn.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\nqtwa.bak1
                C:\WINDOWS\system32\nqtwa.bak1 Has been deleted!

                Attempting to delete C:\WINDOWS\system32\nqtwa.bak2
                C:\WINDOWS\system32\nqtwa.bak2 Has been deleted!

                Attempting to delete C:\windows\system32\nqtwa.ini
                C:\windows\system32\nqtwa.ini Has been deleted!

                Attempting to delete C:\windows\system32\nqtwa.ini2
                C:\windows\system32\nqtwa.ini2 Has been deleted!

                Attempting to delete C:\windows\system32\nqtwa.tmp
                C:\windows\system32\nqtwa.tmp Has been deleted!

                Attempting to delete C:\WINDOWS\system32\obkqwcqx.dll
                C:\WINDOWS\system32\obkqwcqx.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\ovkhyynv.dll
                C:\WINDOWS\system32\ovkhyynv.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\pildbbok.dll
                C:\WINDOWS\system32\pildbbok.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\pkvymyxv.dll
                C:\WINDOWS\system32\pkvymyxv.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\qiothgum.dll
                C:\WINDOWS\system32\qiothgum.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\qonsvblb.dll
                C:\WINDOWS\system32\qonsvblb.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\quwiuust.dll
                C:\WINDOWS\system32\quwiuust.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\qvmraoqf.dll
                C:\WINDOWS\system32\qvmraoqf.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\rsllqsah.dll
                C:\WINDOWS\system32\rsllqsah.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\rvbivofd.dll
                C:\WINDOWS\system32\rvbivofd.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\smulwiyg.dll
                C:\WINDOWS\system32\smulwiyg.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\tapbmryx.dll
                C:\WINDOWS\system32\tapbmryx.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\tritwsvd.dll
                C:\WINDOWS\system32\tritwsvd.dll Could not be deleted.

                Attempting to delete C:\WINDOWS\system32\ugcjmpum.dll
                C:\WINDOWS\system32\ugcjmpum.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\uktynypc.dll
                C:\WINDOWS\system32\uktynypc.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\umkodabd.dll
                C:\WINDOWS\system32\umkodabd.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\uyskoeqy.dll
                C:\WINDOWS\system32\uyskoeqy.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\xfwijgqf.dll
                C:\WINDOWS\system32\xfwijgqf.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\ydgyleey.dll
                C:\WINDOWS\system32\ydgyleey.dll Has been deleted!

                Attempting to delete C:\WINDOWS\system32\yfjfgqib.dll
                C:\WINDOWS\system32\yfjfgqib.dll Has been deleted!

                Performing Repairs to the registry.
                Done!

                VundoFix V6.7.7

                Checking Java version...

                Java version is 1.4.2.3
                Old versions of java are exploitable and should be removed.

                Scan started at 19:59:20 26/12/2007

                Listing files found while scanning....

                C:\WINDOWS\system32\bymmhocr.exe
                C:\WINDOWS\system32\dvswtirt.ini
                C:\WINDOWS\system32\tritwsvd.dll

                Beginning removal...

                Attempting to delete C:\WINDOWS\system32\bymmhocr.exe
                C:\WINDOWS\system32\bymmhocr.exe Could not be deleted.

                Attempting to delete C:\WINDOWS\system32\dvswtirt.ini
                C:\WINDOWS\system32\dvswtirt.ini Has been deleted!

                Attempting to delete C:\WINDOWS\system32\tritwsvd.dll
                C:\WINDOWS\system32\tritwsvd.dll Has been deleted!

                Performing Repairs to the registry.
                Done!

                Beginning removal...

                Attempting to delete C:\WINDOWS\system32\bymmhocr.exe
                C:\WINDOWS\system32\bymmhocr.exe Could not be deleted.

                Performing Repairs to the registry.
                Done!
                0
                1. voici le rapport HijackThis:

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 20:42:52, on 26/12/2007
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\a-squared Free\a2service.exe
                  C:\WINDOWS\system32\bymmhocr.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\WINDOWS\system32\svchost.exe
                  c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\windows\system\hpsysdrv.exe
                  C:\WINDOWS\system32\hphmon06.exe
                  C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\WINDOWS\system32\RUNDLL32.EXE
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sapo.pt/
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O2 - BHO: (no name) - {0158351F-EAE2-40A9-8043-C519F6DD893B} - (no file)
                  O2 - BHO: (no name) - {036e2109-f9be-488a-8c52-3194e09f4d48} - (no file)
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {0E6584FC-5675-45BE-9447-231E21B8F054} - (no file)
                  O2 - BHO: (no name) - {0F8B3A97-6CCA-47E9-A0EC-ED47B7AAB253} - (no file)
                  O2 - BHO: (no name) - {108AD16E-81C8-447B-85EA-B3496706477E} - (no file)
                  O2 - BHO: (no name) - {18880181-ed36-4adc-96f6-3a0f55bca445} - (no file)
                  O2 - BHO: (no name) - {1B3F756C-418D-410B-852C-F82F79B37166} - (no file)
                  O2 - BHO: (no name) - {23153EBC-39A7-4A0B-89BD-86BA900A229A} - (no file)
                  O2 - BHO: (no name) - {3B375025-0C4A-4D2B-8C83-26D5A18144A4} - (no file)
                  O2 - BHO: (no name) - {458D217F-16CD-4335-A01E-A31481A26CDE} - (no file)
                  O2 - BHO: (no name) - {4753DF9C-210D-45CC-B2C8-B5A5E0023C1D} - C:\WINDOWS\system32\awtqn.dll (file missing)
                  O2 - BHO: (no name) - {4C161245-22BC-4732-8B1C-263346F439F7} - (no file)
                  O2 - BHO: (no name) - {4d0d6e37-4184-404e-ac14-9796ccfce243} - (no file)
                  O2 - BHO: (no name) - {55028745-FDF4-461E-AA31-4C3642E6D17E} - (no file)
                  O2 - BHO: (no name) - {579a91bf-ece2-4b85-8146-d61b59dd0a3d} - (no file)
                  O2 - BHO: (no name) - {62A343BD-143D-45FF-B2E2-057CAF814CEA} - (no file)
                  O2 - BHO: (no name) - {66AACC8E-3933-4219-BF8A-87E8BC62DA08} - (no file)
                  O2 - BHO: (no name) - {6746F1E3-DFE2-4009-A2A0-289693ABABB8} - (no file)
                  O2 - BHO: (no name) - {6B987E65-1671-40FB-BF2A-2DE821B9BD62} - (no file)
                  O2 - BHO: (no name) - {6F8A4B70-86F4-4719-962D-7D5B19912B68} - (no file)
                  O2 - BHO: (no name) - {764D8C35-A69A-4074-9A08-116B74520806} - (no file)
                  O2 - BHO: (no name) - {7C7557BA-217F-4D28-BE4C-E0135E56E9AA} - (no file)
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: {ce9f6183-ac9f-446b-0a54-69082954f088} - {880f4592-8096-45a0-b644-f9ca3816f9ec} - C:\WINDOWS\system32\qvmraoqf.dll (file missing)
                  O2 - BHO: (no name) - {8e694f47-366a-427b-a1d0-9c96acab4664} - (no file)
                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: (no name) - {92CF17B8-97BA-45F0-87A5-659E90496CB5} - (no file)
                  O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                  O2 - BHO: (no name) - {9728B320-FD65-4375-B687-EC6449A64C62} - (no file)
                  O2 - BHO: (no name) - {980E5A99-D684-4346-9024-5B4DAEE7DC94} - (no file)
                  O2 - BHO: (no name) - {A0F85361-45A8-4B58-8CDA-C782AFA01D63} - (no file)
                  O2 - BHO: (no name) - {a42fa66d-7152-4f43-b238-a15a0b5040a7} - (no file)
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar6.dll
                  O2 - BHO: (no name) - {abce94ad-7f9b-4f1b-baa9-6d3d9d638f35} - (no file)
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                  O2 - BHO: (no name) - {AFA85A03-3A73-45EA-AC62-BC8330D82000} - (no file)
                  O2 - BHO: (no name) - {B55DB1B3-D239-46B0-A828-D1F6A9CC36B4} - (no file)
                  O2 - BHO: (no name) - {B723A736-024E-404C-9732-1ED8E83D6AF3} - (no file)
                  O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                  O2 - BHO: (no name) - {D2EFD432-CAE6-40D0-AB12-B03802710C2F} - (no file)
                  O2 - BHO: (no name) - {DA244D3D-2AA3-4E92-A7E1-BE7465DD065C} - (no file)
                  O2 - BHO: (no name) - {DADC99AE-3619-43BA-9A89-C8E2AB04300F} - (no file)
                  O2 - BHO: (no name) - {DEF14CF2-7F2E-4A3A-8A3C-34A3633E2DC7} - (no file)
                  O2 - BHO: (no name) - {e716cbf5-6958-447f-a8a0-76cb02ced9e5} - (no file)
                  O2 - BHO: (no name) - {E73DF09D-E7A5-44A0-A411-BF0D91BE9C72} - (no file)
                  O2 - BHO: (no name) - {ED34EF0C-1F27-4150-8BFF-056227FC8F73} - (no file)
                  O2 - BHO: (no name) - {EFB6EF28-20D6-4E02-B52D-767D3412734A} - (no file)
                  O2 - BHO: (no name) - {F7ADCC66-9534-4ECC-9801-B6CDCAFE1E17} - (no file)
                  O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
                  O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                  O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar6.dll
                  O3 - Toolbar: (no name) - {11A69AE4-FBED-4832-A2BF-45AF82825583} - (no file)
                  O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                  O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                  O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                  O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                  O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                  O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [74a2ef0b] rundll32.exe "C:\WINDOWS\system32\tritwsvd.dll",b
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                  O9 - Extra button: (no name) - {49783ED4-258D-4f9f-BE11-137C18D3E543} - (no file)
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                  O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\HP_Propriétaire\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                  O16 - DPF: {A4069847-C342-48E2-9257-01A24E5C78EA} (F-Secure Online Scanner 3.2) - https://www.f-secure.com/en/home/support
                  O18 - Protocol: hola - {626601A0-4BAE-11D1-A7E1-00A0246C1E64} - (no file)
                  O18 - Protocol: holb - {626601A1-4BAE-11D1-A7E1-00A0246C1E64} - (no file)
                  O20 - Winlogon Notify: urqrqno - C:\WINDOWS\
                  O20 - Winlogon Notify: xxyvuro - C:\WINDOWS\
                  O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: DomainService - - C:\WINDOWS\system32\bymmhocr.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                  0
                  1. Contributeur sécurité
                    me revoilà

                    du joli monde tout ça....

                    on continue, ce n'est pas terminé

                    * Télécharge combofix.exe (par sUBs) sur ton Bureau
                    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                    IMPORTANT

                    *désactive ton antivirus, antispyware, et spybot (résident) durant l'utilisation de ComboFix . Merci. Tu réactives ensuite
                    puis

                    * Double clique combofix.exe.

                    * Tape sur la touche Y (Yes) pour démarrer le scan.

                    * Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse

                    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                    et reposte un nouveau rapport hijackthis stp

                    0
                    1. voci le rapport de l'analyse de ComboFix:

                      ComboFix 07-12-21.4 - HP_Propriétaire 2007-12-26 21:35:25.1 - NTFSx86
                      Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.554 [GMT 1:00]
                      Running from: C:\Documents and Settings\HP_Propriétaire\Bureau\ComboFix.exe
                      .

                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      C:\Documents and Settings\All Users\Menu Démarrer\Live Safety Center.lnk
                      C:\Documents and Settings\All Users\Menu Démarrer\Online Security Guide.lnk
                      C:\Documents and Settings\HP_Propriétaire\Favoris\Online Security Guide.lnk
                      C:\Program Files\Temporary
                      C:\Program Files\WinAble
                      C:\svchost.exe
                      C:\Temp\1cb
                      C:\Temp\1cb\syscheck.log
                      C:\WINDOWS\cookies.ini
                      C:\WINDOWS\Fonts\a.zip
                      C:\WINDOWS\system32\b3
                      C:\WINDOWS\system32\bymmhocr.exe
                      C:\WINDOWS\system32\e1
                      C:\WINDOWS\system32\eeqkcgif.ini
                      C:\WINDOWS\system32\eqfythhi.dll
                      C:\WINDOWS\system32\figckqee.dll
                      C:\WINDOWS\system32\ihhtyfqe.ini
                      C:\WINDOWS\system32\myrqvwwu.ini
                      C:\WINDOWS\system32\pac.txt
                      C:\WINDOWS\system32\u4
                      C:\WINDOWS\system32\uwwvqrym.dll
                      C:\x.dat
                      C:\z.dat
                      D:\Autorun.inf
                      K:\Autorun.inf
                      C:\WINDOWS\Fonts\'

                      .
                      ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

                      .
                      -------\LEGACY_DOMAINSERVICE
                      -------\DomainService

                      ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-26 to 2007-12-26 ))))))))))))))))))))))))))))))))))))
                      .

                      2007-12-26 19:28 . 2007-12-26 20:32 <REP> d-------- C:\VundoFix Backups
                      2007-12-26 18:13 . 2007-12-26 19:16 <REP> d-------- C:\Program Files\Navilog1
                      2007-12-26 17:01 . 2007-12-26 19:17 474 ---hs---- C:\WINDOWS\system32\uebtftwm.ini
                      2007-12-26 13:19 . 2007-12-26 16:17 <REP> d-------- C:\Program Files\a-squared Free
                      2007-12-26 13:17 . 2007-12-26 16:59 354 ---hs---- C:\WINDOWS\system32\fcjlowku.ini
                      2007-12-26 13:13 . 2007-12-26 13:13 294 ---hs---- C:\WINDOWS\system32\yqeoksyu.ini
                      2007-12-26 12:00 . 2007-12-26 12:00 714 ---hs---- C:\WINDOWS\system32\dbadokmu.ini
                      2007-12-26 11:53 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
                      2007-12-26 11:53 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
                      2007-12-26 11:53 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
                      2007-12-26 11:53 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
                      2007-12-26 11:53 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
                      2007-12-26 11:53 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
                      2007-12-26 11:52 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
                      2007-12-26 11:51 . 2007-12-26 11:58 654 ---hs---- C:\WINDOWS\system32\fyxdnpwv.ini
                      2007-12-26 11:38 . 2007-12-26 11:45 534 ---hs---- C:\WINDOWS\system32\fkmyeglj.ini
                      2007-12-26 02:12 . 2007-12-26 11:33 414 ---hs---- C:\WINDOWS\system32\fhbifkap.ini
                      2007-12-24 15:07 . 2007-12-24 15:07 <REP> d-------- C:\Program Files\Dusco
                      2007-12-24 15:07 . 2007-12-24 15:07 294 ---hs---- C:\WINDOWS\system32\ksajugbd.ini
                      2007-12-24 11:45 . 2007-12-24 11:46 414 ---hs---- C:\WINDOWS\system32\miirscde.ini
                      2007-12-23 22:13 . 2007-12-24 11:40 354 ---hs---- C:\WINDOWS\system32\afovjtnq.ini
                      2007-12-23 21:34 . 2007-12-23 22:09 406 ---hs---- C:\WINDOWS\system32\hfdtkfws.ini
                      2007-12-23 20:40 . 2007-12-23 20:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
                      2007-12-23 19:08 . 2007-12-23 19:08 <REP> d-------- C:\Program Files\Eidos
                      2007-12-23 17:28 . 2007-12-23 17:28 <REP> d-------- C:\Program Files\Ubi Soft
                      2007-12-23 17:28 . 2002-09-29 01:09 69,632 -ra------ C:\WINDOWS\system32\xmltok.dll
                      2007-12-23 17:28 . 2002-09-29 01:09 36,864 -ra------ C:\WINDOWS\system32\xmlparse.dll
                      2007-12-23 17:28 . 2002-09-29 01:09 35,840 -ra------ C:\WINDOWS\system32\comdlg32.oca
                      2007-12-23 17:28 . 2002-12-23 17:54 26,096 -ra------ C:\WINDOWS\system32\xmlinst.exe
                      2007-12-23 17:28 . 2002-09-29 01:09 24,576 -ra------ C:\WINDOWS\system32\msxml3a.dll
                      2007-12-23 17:00 . 2007-12-23 17:48 <REP> d-------- C:\Program Files\ubi.com
                      2007-12-23 17:00 . 2007-12-23 19:07 <REP> d-------- C:\Program Files\Red Storm Entertainment
                      2007-12-23 13:43 . 2007-12-23 21:31 406 ---hs---- C:\WINDOWS\system32\fqgjiwfx.ini
                      2007-12-22 18:51 . 2007-12-22 19:02 354 ---hs---- C:\WINDOWS\system32\xyrmbpat.ini
                      2007-12-22 18:42 . 2007-12-22 18:51 354 ---hs---- C:\WINDOWS\system32\acswpsaf.ini
                      2007-12-19 16:48 . 2007-12-19 16:48 54,156 --ah----- C:\WINDOWS\QTFont.qfn
                      2007-12-19 16:48 . 2007-12-19 16:48 1,409 --a------ C:\WINDOWS\QTFont.for
                      2007-12-10 18:57 . 2006-10-04 15:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
                      2007-12-10 18:57 . 2006-10-04 15:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
                      2007-12-10 18:57 . 2006-10-04 15:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb
                      2007-12-10 18:55 . 2007-12-10 18:56 <REP> d-------- C:\Program Files\Windows Media Connect 2
                      2007-12-10 18:51 . 2007-12-10 18:53 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
                      2007-12-08 15:31 . 2007-12-09 15:40 <REP> d-------- C:\Program Files\IMVU
                      2007-12-07 18:52 . 2007-12-20 18:08 774 ---hs---- C:\WINDOWS\system32\qfqiisnp.ini
                      2007-12-05 19:25 . 2007-12-05 19:25 414 ---hs---- C:\WINDOWS\system32\bdhaaaij.ini
                      2007-12-05 18:00 . 2007-12-05 18:00 294 ---hs---- C:\WINDOWS\system32\ewbgckqx.ini
                      2007-12-04 19:17 . 2007-12-05 19:20 354 ---hs---- C:\WINDOWS\system32\nlbbhhfl.ini
                      2007-11-27 19:42 . 2007-11-27 19:42 <REP> d-------- C:\fsaua.data

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2007-12-26 15:47 --------- d-----w C:\Program Files\eMule
                      2007-12-26 01:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
                      2007-12-23 20:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
                      2007-11-26 11:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                      2007-11-25 19:28 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
                      2007-11-25 12:38 120 ----a-w C:\n.bat
                      2007-11-24 22:20 36,864 ----a-w C:\Documents and Settings\SANDRA\services.exe
                      2007-11-20 19:23 --------- d-----w C:\Program Files\RogueRemover FREE
                      2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
                      2007-11-07 10:01 --------- d-----w C:\Program Files\Trend Micro
                      2007-11-04 21:21 --------- d-----w C:\Program Files\Custom-Strike
                      2007-10-10 09:13 737,280 ----a-w C:\WINDOWS\iun6002.exe
                      2007-05-04 16:10 80,232 ----a-w C:\Documents and Settings\SANDRA\Application Data\GDIPFONTCACHEV1.DAT
                      2006-05-31 17:29 19,968 ----a-w C:\Program Files\msn blok.doc
                      2006-03-31 11:40 484,560 ----a-w C:\Program Files\DXSETUP.exe
                      2006-03-31 11:40 2,248,912 ----a-w C:\Program Files\dsetup32.dll
                      2006-03-31 11:39 74,448 ----a-w C:\Program Files\DSETUP.dll
                      2006-01-04 18:29 1,884,336 ----a-w C:\Program Files\ptvector.exe
                      2006-01-04 11:27 1,210,249 ----a-w C:\Program Files\recolored_recolored_0.6.0_beta_francais_18429.exe
                      2005-12-19 14:17 35,246,592 ----a-w C:\Program Files\directx_9c_oct05sdk_redist.exe
                      2004-07-30 12:16 2,805 ----a-w C:\Program Files\history.txt
                      2004-07-29 18:03 173,056 ----a-w C:\Program Files\chaoscope.EN
                      2004-07-29 17:57 1,377,280 ----a-w C:\Program Files\chaoscope.exe
                      2004-04-08 01:43 592,896 ----a-w C:\Program Files\converter.exe
                      2007-06-24 13:16 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007062420070625\index.dat
                      .

                      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      REGEDIT4
                      *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4753DF9C-210D-45CC-B2C8-B5A5E0023C1D}]
                      C:\WINDOWS\system32\awtqn.dll

                      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{880f4592-8096-45a0-b644-f9ca3816f9ec}]
                      C:\WINDOWS\system32\qvmraoqf.dll

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 23:15]
                      "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:09]
                      "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04]
                      "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 22:55]
                      "HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 18:43]
                      "ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 13:03]
                      "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 20:43]
                      "SiSPower"="Rundll32.exe" [2004-08-19 15:10 C:\WINDOWS\system32\rundll32.exe]
                      "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 21:54]
                      "SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2005-01-01 10:09]
                      "UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
                      "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-04-23 19:34]
                      "NvCplDaemon"="RUNDLL32.exe" [2004-08-19 15:10 C:\WINDOWS\system32\rundll32.exe]
                      "nwiz"="nwiz.exe" [2006-10-22 11:22 C:\WINDOWS\system32\nwiz.exe]
                      "NvMediaCenter"="RUNDLL32.exe" [2004-08-19 15:10 C:\WINDOWS\system32\rundll32.exe]
                      "ppmate"="C:\Program Files\PPMate\PPMate\ppmate.exe" [2006-11-23 02:45]
                      "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-24 02:24]
                      "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00]
                      "74a2ef0b"="C:\WINDOWS\system32\tritwsvd.dll" []

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqrqno]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyvuro]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
                      path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
                      backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
                      path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
                      backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
                      path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
                      backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^TribalWeb.lnk]
                      path=C:\Documents and Settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\TribalWeb.lnk
                      backup=C:\WINDOWS\pss\TribalWeb.lnkStartup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
                      AGRSMMSG.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
                      ALCXMNTR.EXE

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
                      C:\Program Files\BearShare\BearShare.exe /pause

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bibshim]
                      C:\DOCUME~1\HP_PRO~1\APPLIC~1\README~1\boobwait.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
                      C:\Program Files\BitTorrent\bittorrent.exe --force_start_minimized

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
                      C:\Program Files\DAEMON Tools\daemon.exe -lang 1033

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
                      C:\Program Files\D-Tools\daemon.exe -lang 1033

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Host Process]
                      C:\WINDOWS\Fonts\svchost.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06]
                      2004-06-07 18:53 49152 --a------ c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
                      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe -start

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
                      2004-06-08 20:31 286720 --a------ C:\Program Files\iTunes\iTunesHelper.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
                      2003-02-11 12:02 61440 --a------ C:\HP\KBD\KBD.EXE

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
                      C:\Program Files\MessengerPlus! 3\MsgPlus.exe /WinStart

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
                      C:\Program Files\Messenger\msmsgs.exe /background

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
                      C:\Program Files\MSN Messenger\msnmsgr.exe /background

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
                      2001-07-09 11:50 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                      C:\Program Files\QuickTime\qttask.exe -atboottime

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shareaza]
                      C:\Program Files\Shareaza\Shareaza.exe -tray

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
                      C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySpotter]
                      C:\Program Files\SpySpotter3\SpySpotter.exe -startup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySpotter System Defender]
                      C:\Program Files\SpySpotter3\Defender.exe -startup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
                      C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /startintray

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
                      C:\steam\Steam.exe -silent

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe -osboot

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
                      C:\Program Files\TomTom HOME\TomTomHOME.exe -s

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Trans Safe Bags Team]
                      C:\Documents and Settings\All Users\Application Data\Blah gram trans safe\Acid real.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
                      2003-11-19 12:03 45056 --------- C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
                      C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
                      VTTimer.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
                      2007-05-14 23:22 35328 --a------ C:\Program Files\Winamp\winampa.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                      "SPBBCSvc"=2 (0x2)
                      "SAVScan"=3 (0x3)

                      R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 22:41]
                      R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 22:41]
                      R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
                      R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2004-04-14 10:08]
                      R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2004-04-14 10:08]
                      S3 lredbooo;lredbooo;C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\lredbooo.sys []
                      S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
                      S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2004-04-14 10:08]
                      S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2004-04-14 10:08]

                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
                      \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94cd7612-645e-11dc-aa07-0011d873ea37}]
                      \Shell\AutoRun\command - K:\InstallTomTomHOME.exe

                      .
                      Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
                      "2007-12-26 20:00:00 C:\WINDOWS\Tasks\AD0D03E1918AB325.job"
                      - c:\docume~1\hp_pro~1\applic~1\readme~1\CAST OWNS ISO.exe
                      "2007-12-21 19:25:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                      - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                      "2007-12-24 14:12:26 C:\WINDOWS\Tasks\SesamTVMC.job"
                      .
                      **************************************************************************

                      catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2007-12-26 21:49:18
                      Windows 5.1.2600 Service Pack 2 NTFS

                      scanning hidden processes ...

                      scanning hidden autostart entries ...

                      scanning hidden files ...

                      scan completed successfully
                      hidden files: 0

                      **************************************************************************
                      .
                      Completion time: 2007-12-26 21:51:15 - machine was rebooted [HP_Propri‚taire]
                      .
                      2007-12-13 01:12:37 --- E O F ---
                      0
                      1. voila un nouveau rapport HijackThis:

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 21:56:14, on 26/12/2007
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\a-squared Free\a2service.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\WINDOWS\system32\svchost.exe
                        c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\windows\system\hpsysdrv.exe
                        C:\WINDOWS\system32\hphmon06.exe
                        C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                        C:\WINDOWS\system32\RUNDLL32.EXE
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\MSN Messenger\msnmsgr.exe
                        C:\WINDOWS\system32\wscntfy.exe
                        c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymSCUI.exe
                        C:\Program Files\Internet Explorer\IEXPLORE.EXE
                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sapo.pt/
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {4753DF9C-210D-45CC-B2C8-B5A5E0023C1D} - C:\WINDOWS\system32\awtqn.dll (file missing)
                        O2 - BHO: {ce9f6183-ac9f-446b-0a54-69082954f088} - {880f4592-8096-45a0-b644-f9ca3816f9ec} - C:\WINDOWS\system32\qvmraoqf.dll (file missing)
                        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar6.dll
                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                        O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                        O3 - Toolbar: Vue HP - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
                        O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
                        O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar6.dll
                        O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                        O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
                        O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                        O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                        O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
                        O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
                        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [ppmate] C:\Program Files\PPMate\PPMate\ppmate.exe -autoplay
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [74a2ef0b] rundll32.exe "C:\WINDOWS\system32\tritwsvd.dll",b
                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - Startup: IMVU.lnk = C:\Program Files\IMVU\IMVUClient.exe
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                        O9 - Extra button: (no name) - {49783ED4-258D-4f9f-BE11-137C18D3E543} - (no file)
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                        O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
                        O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\HP_Propriétaire\Menu Démarrer\Programmes\IMVU\Run IMVU.lnk
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                        O16 - DPF: {A4069847-C342-48E2-9257-01A24E5C78EA} (F-Secure Online Scanner 3.2) - https://www.f-secure.com/en/home/support
                        O18 - Protocol: hola - {626601A0-4BAE-11D1-A7E1-00A0246C1E64} - (no file)
                        O18 - Protocol: holb - {626601A1-4BAE-11D1-A7E1-00A0246C1E64} - (no file)
                        O20 - Winlogon Notify: urqrqno - C:\WINDOWS\
                        O20 - Winlogon Notify: xxyvuro - C:\WINDOWS\
                        O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                        O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
                        0
                        1. Contributeur sécurité
                          ok merci

                          je suis en train de te préparer la suite à donner.
                          réponse dans un petit moment
                          0
                          1. c'est moi qui te remerci pour ton aide. je suis en attente de ta reponce.
                            0
                            1. Contributeur sécurité
                              merci,
                              IMPORTANT

                              * télécharge ERUNT pour sauvegarder ta base de registre avant de continuer les manips stp.

                              https://www.zebulon.fr/telechargements/utilitaires/systeme-utilitaires/erunt.html
                              tuto
                              http://pageperso.aol.fr/loraline60/tuto_erunt.htm

                              ensuite tu feras les manips dans l'ordre indiquée stp.

                              puis

                              Sélectionne le texte suivant :
                              File::
                              C:\WINDOWS\system32\uebtftwm.ini 
                              C:\WINDOWS\system32\fcjlowku.ini 
                              C:\WINDOWS\system32\yqeoksyu.ini 
                              C:\WINDOWS\system32\dbadokmu.ini 
                              C:\WINDOWS\system32\fyxdnpwv.ini 
                              C:\WINDOWS\system32\fkmyeglj.ini 
                              C:\WINDOWS\system32\fhbifkap.ini 
                              C:\WINDOWS\system32\ksajugbd.ini 
                              C:\WINDOWS\system32\miirscde.ini 
                              C:\WINDOWS\system32\afovjtnq.ini 
                              C:\WINDOWS\system32\hfdtkfws.ini 
                              C:\WINDOWS\system32\fqgjiwfx.ini 
                              C:\WINDOWS\system32\xyrmbpat.ini 
                              C:\WINDOWS\system32\acswpsaf.ini 
                              C:\WINDOWS\system32\qfqiisnp.ini 
                              C:\WINDOWS\system32\bdhaaaij.ini 
                              C:\WINDOWS\system32\ewbgckqx.ini 
                              C:\WINDOWS\system32\nlbbhhfl.ini 
                              
                              Registry::
                              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1636FDA8-5F11-418D-AB43-22D93B418309}]
                              
                              [-HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4753DF9C-210D-45CC-B2C8-B5A5E0023C1D}]
                              
                              [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqrqno]
                              
                              [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyvuro] 
                              
                              [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Trans Safe Bags Team]


                              # Copie le texte sélectionné (CTRL+C).
                              # Ouvre le bloc-note (programme>Accessoire>bloc-note).
                              # Colle le texte copié dans ce bloc-note (CTRL+V).
                              # Sauvegarde ce fichier sous le nom de CFScript.txt
                              # Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe

                              * Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
                              * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
                              Ne touche à rien tant que le scan n'est pas terminé.
                              * Une fois le scan achevé, un rapport va s'afficher: Poste son contenu.
                              * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                              puis

                              * lance hijackthis "do a system scan only" puis coche ces lignes :

                              O2 - BHO: (no name) - {4753DF9C-210D-45CC-B2C8-B5A5E0023C1D} - C:\WINDOWS\system32\awtqn.dll (file missing)
                              O2 - BHO: {ce9f6183-ac9f-446b-0a54-69082954f088} - {880f4592-8096-45a0-b644-f9ca3816f9ec} - C:\WINDOWS\system32\qvmraoqf.dll (file missing)
                              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                              O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [74a2ef0b] rundll32.exe "C:\WINDOWS\system32\tritwsvd.dll",b
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
                              O9 - Extra button: (no name) - {49783ED4-258D-4f9f-BE11-137C18D3E543} - (no file)
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                              O18 - Protocol: hola - {626601A0-4BAE-11D1-A7E1-00A0246C1E64} - (no file)
                              O18 - Protocol: holb - {626601A1-4BAE-11D1-A7E1-00A0246C1E64} - (no file)
                              O20 - Winlogon Notify: urqrqno - C:\WINDOWS\
                              O20 - Winlogon Notify: xxyvuro - C:\WINDOWS\

                              * toutes applications fermées et HORS CONNEXION, clique sur FIX CHECKED

                              puis

                              Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.
                              http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                              double-clique sur OTMoveIt.exe pour le lancer.
                              copie la liste qui se trouve en citation ci-dessous,
                              et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                              C:\WINDOWS\Fonts\svchost.exe


                              clique sur MoveIt! pour lancer la suppression.
                              le résultat apparaitra dans le cadre Results.
                              clique sur Exit pour fermer.
                              poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                              il te sera peut-être demander de redémarrer le pc pour achever la suppression.
                              si c'est le cas accepte par Yes.

                              puis

                              relance combo et poste le rapport

                              ainsi qu'un nouveau rapport hijackthis

                              et tu feras ceci

                              Télécharge System Repair Engineer - SREng (par Smallfrogs) de ce lien:
                              http://www.kztechs.com/eng/download.html

                              Extrais tout son contenu sur ton Bureau
                              (clic droit sur le fichier .zip >> "Extraire tout...")
                              Du dossier sreng2 qui se trouve maintenant sur ton Bureau, double-clique sur SREngPS.exe afin de lancer l'outil
                              Clique sur Smart Scan
                              Ensuite, clique sur le bouton [Scan]. L'analyse durera quelques instants.

                              Lorsque complété, clique sur le bouton [Save Reports]
                              Sauvegarde le rapport sur ton Bureau
                              Copie/colle le contenu du fichier SREnglLOG.log dans ta prochaine réponse, s'il te plaît.

                              0
                              1. Salut
                                si tu as le temps peux tu m'expliquer la suppression de :
                                O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe

                                Merci
                                A+
                                0
                              2. Contributeur sécurité
                                @cgui33ce n'est pas une suppression vraiment, mais une suppression du démarrage. C'est inutile au démarrage
                                maintenant si tu veux conserver, conserve
                                0
                              3. @philae83Merki Philae
                                0
                            2. ja n'arrive pas a trouver le pack de langue français ( erunt-loc_fr.zip)
                              0
                              1. voici le rapport Combofix:

                                ComboFix 07-12-21.4 - HP_Propriétaire 2007-12-26 22:47:03.2 - NTFSx86
                                Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.575 [GMT 1:00]
                                Running from: C:\Documents and Settings\HP_Propriétaire\Bureau\ComboFix.exe
                                Command switches used :: C:\Documents and Settings\HP_Propriétaire\Bureau\CFScript.txt
                                * Created a new restore point

                                FILE
                                C:\WINDOWS\system32\acswpsaf.ini
                                C:\WINDOWS\system32\afovjtnq.ini
                                C:\WINDOWS\system32\bdhaaaij.ini
                                C:\WINDOWS\system32\dbadokmu.ini
                                C:\WINDOWS\system32\ewbgckqx.ini
                                C:\WINDOWS\system32\fcjlowku.ini
                                C:\WINDOWS\system32\fhbifkap.ini
                                C:\WINDOWS\system32\fkmyeglj.ini
                                C:\WINDOWS\system32\fqgjiwfx.ini
                                C:\WINDOWS\system32\fyxdnpwv.ini
                                C:\WINDOWS\system32\hfdtkfws.ini
                                C:\WINDOWS\system32\ksajugbd.ini
                                C:\WINDOWS\system32\miirscde.ini
                                C:\WINDOWS\system32\nlbbhhfl.ini
                                C:\WINDOWS\system32\qfqiisnp.ini
                                C:\WINDOWS\system32\uebtftwm.ini
                                C:\WINDOWS\system32\xyrmbpat.ini
                                C:\WINDOWS\system32\yqeoksyu.ini
                                .

                                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                .

                                C:\WINDOWS\system32\acswpsaf.ini
                                C:\WINDOWS\system32\afovjtnq.ini
                                C:\WINDOWS\system32\bdhaaaij.ini
                                C:\WINDOWS\system32\dbadokmu.ini
                                C:\WINDOWS\system32\ewbgckqx.ini
                                C:\WINDOWS\system32\fcjlowku.ini
                                C:\WINDOWS\system32\fhbifkap.ini
                                C:\WINDOWS\system32\fkmyeglj.ini
                                C:\WINDOWS\system32\fqgjiwfx.ini
                                C:\WINDOWS\system32\fyxdnpwv.ini
                                C:\WINDOWS\system32\hfdtkfws.ini
                                C:\WINDOWS\system32\ksajugbd.ini
                                C:\WINDOWS\system32\miirscde.ini
                                C:\WINDOWS\system32\nlbbhhfl.ini
                                C:\WINDOWS\system32\qfqiisnp.ini
                                C:\WINDOWS\system32\uebtftwm.ini
                                C:\WINDOWS\system32\xyrmbpat.ini
                                C:\WINDOWS\system32\yqeoksyu.ini

                                .
                                ((((((((((((((((((((((((((((( Fichiers créés 2007-11-26 to 2007-12-26 ))))))))))))))))))))))))))))))))))))
                                .

                                2007-12-26 19:28 . 2007-12-26 20:32 <REP> d-------- C:\VundoFix Backups
                                2007-12-26 18:13 . 2007-12-26 19:16 <REP> d-------- C:\Program Files\Navilog1
                                2007-12-26 13:19 . 2007-12-26 16:17 <REP> d-------- C:\Program Files\a-squared Free
                                2007-12-26 11:53 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
                                2007-12-26 11:53 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
                                2007-12-26 11:53 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
                                2007-12-26 11:53 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
                                2007-12-26 11:53 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
                                2007-12-26 11:53 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
                                2007-12-26 11:52 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
                                2007-12-24 15:07 . 2007-12-24 15:07 <REP> d-------- C:\Program Files\Dusco
                                2007-12-23 20:40 . 2007-12-23 20:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Trymedia
                                2007-12-23 19:08 . 2007-12-23 19:08 <REP> d-------- C:\Program Files\Eidos
                                2007-12-23 17:28 . 2007-12-23 17:28 <REP> d-------- C:\Program Files\Ubi Soft
                                2007-12-23 17:28 . 2002-09-29 01:09 69,632 -ra------ C:\WINDOWS\system32\xmltok.dll
                                2007-12-23 17:28 . 2002-09-29 01:09 36,864 -ra------ C:\WINDOWS\system32\xmlparse.dll
                                2007-12-23 17:28 . 2002-09-29 01:09 35,840 -ra------ C:\WINDOWS\system32\comdlg32.oca
                                2007-12-23 17:28 . 2002-12-23 17:54 26,096 -ra------ C:\WINDOWS\system32\xmlinst.exe
                                2007-12-23 17:28 . 2002-09-29 01:09 24,576 -ra------ C:\WINDOWS\system32\msxml3a.dll
                                2007-12-23 17:00 . 2007-12-23 17:48 <REP> d-------- C:\Program Files\ubi.com
                                2007-12-23 17:00 . 2007-12-23 19:07 <REP> d-------- C:\Program Files\Red Storm Entertainment
                                2007-12-19 16:48 . 2007-12-19 16:48 54,156 --ah----- C:\WINDOWS\QTFont.qfn
                                2007-12-19 16:48 . 2007-12-19 16:48 1,409 --a------ C:\WINDOWS\QTFont.for
                                2007-12-10 18:57 . 2006-10-04 15:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
                                2007-12-10 18:57 . 2006-10-04 15:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
                                2007-12-10 18:57 . 2006-10-04 15:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb
                                2007-12-10 18:55 . 2007-12-10 18:56 <REP> d-------- C:\Program Files\Windows Media Connect 2
                                2007-12-10 18:51 . 2007-12-10 18:53 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
                                2007-12-08 15:31 . 2007-12-09 15:40 <REP> d-------- C:\Program Files\IMVU
                                2007-12-08 15:31 . 2007-12-26 21:49 <REP> d-------- C:\Documents and Settings\HP_Propriétaire\Application Data\IMVU
                                2007-11-27 19:42 . 2007-11-27 19:42 <REP> d-------- C:\fsaua.data

                                .
                                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2007-12-26 15:47 --------- d-----w C:\Program Files\eMule
                                2007-12-26 01:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
                                2007-12-23 20:23 --------- d--h--w C:\Program Files\InstallShield Installation Information
                                2007-12-23 18:42 98,304 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
                                2007-12-01 20:48 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\Skype
                                2007-11-27 19:28 --------- d-----w C:\Documents and Settings\HP_Propriétaire\Application Data\SopCast
                                2007-11-26 11:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                                2007-11-25 19:28 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
                                2007-11-25 19:17 36,864 ----a-w C:\Documents and Settings\HP_Propriétaire\services.exe
                                2007-11-25 19:17 36,864 ----a-w C:\Documents and Settings\HP_Propriétaire\services.exe
                                2007-11-25 12:38 120 ----a-w C:\n.bat
                                2007-11-25 12:38 0 ----a-w C:\Documents and Settings\HP_Propriétaire\x.dat
                                2007-11-25 12:38 0 ----a-w C:\Documents and Settings\HP_Propriétaire\x.dat
                                2007-11-25 12:37 531 ----a-w C:\Documents and Settings\HP_Propriétaire\z.dat
                                2007-11-25 12:37 531 ----a-w C:\Documents and Settings\HP_Propriétaire\z.dat
                                2007-11-24 22:20 36,864 ----a-w C:\Documents and Settings\SANDRA\services.exe
                                2007-11-20 19:23 --------- d-----w C:\Program Files\RogueRemover FREE
                                2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
                                2007-11-07 12:45 4,586 ----a-w C:\WINDOWS\system32\tmp.reg
                                2007-11-07 10:01 --------- d-----w C:\Program Files\Trend Micro
                                2007-11-05 14:18 147,456 ----a-w C:\WINDOWS\system32\vbzip10.dll
                                2007-11-04 21:21 --------- d-----w C:\Program Files\Custom-Strike
                                2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
                                2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
                                2007-10-10 09:13 737,280 ----a-w C:\WINDOWS\iun6002.exe
                                2007-10-03 22:36 25,600 ----a-w C:\WINDOWS\system32\WS2Fix.exe
                                2007-09-08 11:18 81,008 ----a-w C:\Documents and Settings\HP_Propriétaire\Application Data\GDIPFONTCACHEV1.DAT
                                2007-05-04 16:10 80,232 ----a-w C:\Documents and Settings\SANDRA\Application Data\GDIPFONTCACHEV1.DAT
                                2006-05-31 17:29 19,968 ----a-w C:\Program Files\msn blok.doc
                                2006-03-31 11:40 484,560 ----a-w C:\Program Files\DXSETUP.exe
                                2006-03-31 11:40 2,248,912 ----a-w C:\Program Files\dsetup32.dll
                                2006-03-31 11:39 74,448 ----a-w C:\Program Files\DSETUP.dll
                                2006-01-04 18:29 1,884,336 ----a-w C:\Program Files\ptvector.exe
                                2006-01-04 11:27 1,210,249 ----a-w C:\Program Files\recolored_recolored_0.6.0_beta_francais_18429.exe
                                2005-12-19 14:17 35,246,592 ----a-w C:\Program Files\directx_9c_oct05sdk_redist.exe
                                2005-12-11 15:36 13,306 ----a-w C:\Documents and Settings\HP_Propriétaire\Application Data\wklnhst.dat
                                2004-07-30 12:16 2,805 ----a-w C:\Program Files\history.txt
                                2004-07-29 18:03 173,056 ----a-w C:\Program Files\chaoscope.EN
                                2004-07-29 17:57 1,377,280 ----a-w C:\Program Files\chaoscope.exe
                                2004-04-08 01:43 592,896 ----a-w C:\Program Files\converter.exe
                                2007-06-24 13:16 32,768 --sha-w C:\WINDOWS\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012007062420070625\index.dat
                                .

                                ((((((((((((((((((((((((((((( snapshot@2007-12-26_21.50.45.64 )))))))))))))))))))))))))))))))))))))))))
                                .
                                + 2005-10-20 11:02:28 163,328 ----a-w C:\WINDOWS\erdnt\26-12-2007\ERDNT.EXE
                                + 2007-12-26 21:39:25 23,785,472 ----a-w C:\WINDOWS\erdnt\26-12-2007\Users\[u]0[/u]0000001\NTUSER.DAT
                                + 2007-12-26 21:39:25 28,672 ----a-w C:\WINDOWS\erdnt\26-12-2007\Users\[u]0[/u]0000002\UsrClass.dat
                                .
                                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                REGEDIT4
                                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                                [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4753DF9C-210D-45CC-B2C8-B5A5E0023C1D}]
                                C:\WINDOWS\system32\awtqn.dll

                                [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{880f4592-8096-45a0-b644-f9ca3816f9ec}]
                                C:\WINDOWS\system32\qvmraoqf.dll

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-23 23:15]
                                "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15:09]
                                "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 11:55]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 16:04]
                                "IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2004-08-20 22:55]
                                "HPHmon06"="C:\WINDOWS\system32\hphmon06.exe" [2004-06-07 18:43]
                                "ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-06-16 13:03]
                                "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2004-04-14 20:43]
                                "SiSPower"="Rundll32.exe" [2004-08-19 15:10 C:\WINDOWS\system32\rundll32.exe]
                                "LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 21:54]
                                "SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2005-01-01 10:09]
                                "UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" []
                                "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-04-23 19:34]
                                "NvCplDaemon"="RUNDLL32.exe" [2004-08-19 15:10 C:\WINDOWS\system32\rundll32.exe]
                                "nwiz"="nwiz.exe" [2006-10-22 11:22 C:\WINDOWS\system32\nwiz.exe]
                                "NvMediaCenter"="RUNDLL32.exe" [2004-08-19 15:10 C:\WINDOWS\system32\rundll32.exe]
                                "ppmate"="C:\Program Files\PPMate\PPMate\ppmate.exe" [2006-11-23 02:45]
                                "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-24 02:24]
                                "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00]
                                "74a2ef0b"="C:\WINDOWS\system32\tritwsvd.dll" []

                                C:\Documents and Settings\HP_Propri‚taire\Menu D‚marrer\Programmes\D‚marrage\
                                ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [2005-10-20 12:04:08]
                                IMVU.lnk - C:\Program Files\IMVU\IMVUClient.exe [2007-12-20 03:00:16]

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Digital Imaging Monitor.lnk]
                                path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Digital Imaging Monitor.lnk
                                backup=C:\WINDOWS\pss\HP Digital Imaging Monitor.lnkCommon Startup

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
                                path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
                                backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
                                path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
                                backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^HP_Propriétaire^Menu Démarrer^Programmes^Démarrage^TribalWeb.lnk]
                                path=C:\Documents and Settings\HP_Propriétaire\Menu Démarrer\Programmes\Démarrage\TribalWeb.lnk
                                backup=C:\WINDOWS\pss\TribalWeb.lnkStartup

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
                                AGRSMMSG.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
                                ALCXMNTR.EXE

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BearShare]
                                C:\Program Files\BearShare\BearShare.exe /pause

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Bibshim]
                                C:\DOCUME~1\HP_PRO~1\APPLIC~1\README~1\boobwait.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
                                C:\Program Files\BitTorrent\bittorrent.exe --force_start_minimized

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
                                C:\Program Files\DAEMON Tools\daemon.exe -lang 1033

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools-1033]
                                C:\Program Files\D-Tools\daemon.exe -lang 1033

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Host Process]
                                C:\WINDOWS\Fonts\svchost.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPHUPD06]
                                2004-06-07 18:53 49152 --a------ c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
                                C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe -start

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
                                2004-06-08 20:31 286720 --a------ C:\Program Files\iTunes\iTunesHelper.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
                                2003-02-11 12:02 61440 --a------ C:\HP\KBD\KBD.EXE

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MessengerPlus3]
                                C:\Program Files\MessengerPlus! 3\MsgPlus.exe /WinStart

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
                                C:\Program Files\Messenger\msmsgs.exe /background

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
                                C:\Program Files\MSN Messenger\msnmsgr.exe /background

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]
                                2001-07-09 11:50 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
                                C:\Program Files\QuickTime\qttask.exe -atboottime

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shareaza]
                                C:\Program Files\Shareaza\Shareaza.exe -tray

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
                                C:\Program Files\Skype\Phone\Skype.exe /nosplash /minimized

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySpotter]
                                C:\Program Files\SpySpotter3\SpySpotter.exe -startup

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySpotter System Defender]
                                C:\Program Files\SpySpotter3\Defender.exe -startup

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpySweeper]
                                C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /startintray

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
                                C:\steam\Steam.exe -silent

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
                                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe -osboot

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe]
                                C:\Program Files\TomTom HOME\TomTomHOME.exe -s

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ulead AutoDetector]
                                2003-11-19 12:03 45056 --------- C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
                                C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
                                VTTimer.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
                                2007-05-14 23:22 35328 --a------ C:\Program Files\Winamp\winampa.exe

                                [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                                "SPBBCSvc"=2 (0x2)
                                "SAVScan"=3 (0x3)

                                R0 d346bus;d346bus;C:\WINDOWS\system32\DRIVERS\d346bus.sys [2004-03-12 22:41]
                                R0 d346prt;d346prt;C:\WINDOWS\system32\Drivers\d346prt.sys [2004-03-12 22:41]
                                R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
                                R3 WmBEnum;Logitech Virtual Bus Enumerator Driver;C:\WINDOWS\system32\drivers\WmBEnum.sys [2004-04-14 10:08]
                                R3 WmXlCore;Logitech WingMan Translation Layer Driver;C:\WINDOWS\system32\drivers\WmXlCore.sys [2004-04-14 10:08]
                                S3 lredbooo;lredbooo;C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\lredbooo.sys []
                                S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
                                S3 WmFilter;Logitech WingMan HID Filter Driver;C:\WINDOWS\system32\drivers\WmFilter.sys [2004-04-14 10:08]
                                S3 WmVirHid;Logitech Virtual Hid Device Driver;C:\WINDOWS\system32\drivers\WmVirHid.sys [2004-04-14 10:08]

                                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
                                \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

                                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{94cd7612-645e-11dc-aa07-0011d873ea37}]
                                \Shell\AutoRun\command - K:\InstallTomTomHOME.exe

                                .
                                Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                                "2007-12-26 21:00:00 C:\WINDOWS\Tasks\AD0D03E1918AB325.job"
                                - c:\docume~1\hp_pro~1\applic~1\readme~1\CAST OWNS ISO.exe
                                "2007-12-21 19:25:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                                - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                                "2007-12-24 14:12:26 C:\WINDOWS\Tasks\SesamTVMC.job"
                                .
                                **************************************************************************

                                catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2007-12-26 22:52:00
                                Windows 5.1.2600 Service Pack 2 NTFS

                                scanning hidden processes ...

                                scanning hidden autostart entries ...

                                scanning hidden files ...

                                **************************************************************************
                                .
                                Completion time: 2007-12-26 22:53:24
                                C:\ComboFix2.txt ... 2007-12-26 21:51
                                .
                                2007-12-13 01:12:37 --- E O F ---
                                0
                                1. Contributeur sécurité
                                  n'oublie pas SRENG et un nouveau rapport hijackthis stp

                                  0
                                  1. lorsque je click sur movelt il y a un message d'erreur qui s'affiche:
                                    Cannot create file C:\_OTMoveIt\MovedFiles\12262007_231520.log.
                                    0
                                    1. Contributeur sécurité
                                      et sais tu quelle action il a faite ?

                                      n'oublie pas SRENG et un nouveau rapport hijackthis stp
                                      0
                                      • 1
                                      • 2
                                      • 3