Micro infecté - Page 2

  1. ça yest, je crois que c'est fait mais le lien est à gauche et la case n'est pas cochéé (Désactiver la restauration de Système)
    1. ok c'est bon ! sinon quand tu fait le glisser deposer du script dans combofix , a t il demarer tout seul ?car celas ne semble pas avoir fonctionner
      1. Ouvre le Bloc-Notes puis colle le texte copié.
        (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
        Sauvegarde ce fichier sous le nom de CFScript.txt.

        Copie le texte en gras : ci-dessous :

        Registry::
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqp]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnk]
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqpo]
        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{07AA283A-43D7-4CBE-A064-32A21112D94D}]
        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5639B06-57B2-40E6-940C-5DADCD2D7E8C}]

        File::
        C:\WINDOWS\system32\ljjhf.dll
        C:\Documents and Settings\All Users\Application Data\Nettordinateur
        C:\Documents and Settings\christiane\Application Data\Nettordinateur
        C:\Program Files\LibreSystem
        C:\WINDOWS\system32\acdgh.bak1
        C:\WINDOWS\system32\adcfe.bak1
        C:\WINDOWS\system32\adcfe.bak2
        C:\WINDOWS\system32\cddgh.bak1
        C:\WINDOWS\system32\egfhk.bak1
        C:\WINDOWS\system32\egfhk.bak2
        C:\WINDOWS\system32\ehhjl.bak1
        C:\WINDOWS\system32\gijjl.bak1
        C:\WINDOWS\system32\jihhk.bak1
        C:\WINDOWS\system32\jihhk.bak2
        C:\WINDOWS\system32\jmppo.bak1
        C:\WINDOWS\system32\kknnn.bak1
        C:\WINDOWS\system32\knqru.bak1
        C:\WINDOWS\system32\lmllm.bak1
        C:\WINDOWS\system32\mmnpo.bak1
        C:\WINDOWS\system32\onoqr.bak1
        C:\WINDOWS\system32\onoqr.bak2
        C:\WINDOWS\system32\opqru.bak1
        C:\WINDOWS\system32\oqppo.bak1
        C:\WINDOWS\system32\oqppo.bak2
        C:\WINDOWS\system32\pqtss.bak1
        C:\WINDOWS\system32\pqtss.bak2
        C:\WINDOWS\system32\rqpoq.bak1
        C:\WINDOWS\system32\ruvut.bak1
        C:\WINDOWS\system32\tssru.bak1

        Folder::
        C:\Program Files\Fichiers communs\TrojansFiltre\stmon.exe"
        C:\Program Files\Fichiers communs\Nettordinateur\mc.exe"
        C:\Program Files\Fichiers communs\DefenseNetSurfage

        Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

        http://serveur1.archive-host.com/membres/up/1366464061/CFScript.gif

        Cela va relancer Combofix,

        Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

        Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

        Ne touche à rien tant que le scan n'est pas terminé.

        Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

        S'il n'y a pas de rédémarrage, poste quand même les rapports.
        1. ComboFix 08-01-20.1 - christiane 2008-01-22 9:33:10.3 - NTFSx86
          Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.696 [GMT 1:00]
          Running from: C:\Documents and Settings\christiane\Bureau\ComboFix.exe

          [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
          .

          ((((((((((((((((((((((((((((( Fichiers créés 2007-12-22 to 2008-01-22 ))))))))))))))))))))))))))))))))))))
          .

          2008-01-21 14:34 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
          2008-01-21 11:10 . 2008-01-21 13:44 <REP> d-------- C:\VundoFix Backups
          2008-01-21 09:53 . 2008-01-21 09:53 <REP> d-------- C:\Program Files\Trend Micro
          2008-01-13 17:36 . 2008-01-13 17:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
          2008-01-09 18:45 . 2008-01-09 18:45 118 --a------ C:\WINDOWS\system32\MRT.INI
          2008-01-09 18:42 . 2008-01-09 18:42 1,355 --a------ C:\WINDOWS\imsins.BAK
          2008-01-01 15:40 . 2008-01-01 15:40 268 --ah----- C:\sqmdata01.sqm
          2008-01-01 15:40 . 2008-01-01 15:40 244 --ah----- C:\sqmnoopt01.sqm
          2007-12-29 15:39 . 2008-01-13 17:32 <REP> d-------- C:\Program Files\MalwareAlarm
          2007-12-29 15:39 . 2007-12-29 15:39 1,271,822 --a------ C:\Install

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-01-22 07:56 --------- d-----w C:\Program Files\adslTV
          2008-01-21 09:18 --------- d-----w C:\Program Files\Yahoo!
          2008-01-21 09:15 --------- d-----w C:\Program Files\LibreSystem
          2008-01-15 15:39 --------- d-----w C:\Program Files\Fichiers communs\Nettordinateur
          2008-01-13 16:38 --------- d-----w C:\Program Files\Fichiers communs\TrojansFiltre
          2007-12-27 14:43 --------- d-----w C:\Documents and Settings\christiane\Application Data\Creative
          2007-12-16 13:16 --------- d-----w C:\Program Files\TrojansFiltre
          2007-12-06 17:57 --------- d-----w C:\Documents and Settings\christiane\Application Data\Nettordinateur
          2007-12-06 17:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nettordinateur
          2007-12-05 19:40 --------- d-----w C:\Program Files\Fichiers communs\DefenseNetSurfage
          2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
          2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
          2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
          2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
          2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
          2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
          2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
          2007-11-28 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\muvee Technologies
          2007-11-28 15:55 --------- d-----w C:\Documents and Settings\christiane\Application Data\muvee Technologies
          2007-11-20 14:36 118,784 ----a-w C:\WINDOWS\system32\MaDRM.dll
          2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
          2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
          2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
          2007-09-22 13:44 6,440 --sh--w C:\WINDOWS\system32\acdgh.bak1
          2007-09-19 12:08 6,480 --sh--w C:\WINDOWS\system32\adcfe.bak1
          2007-10-06 18:41 14,324 --sh--w C:\WINDOWS\system32\adcfe.bak2
          2007-09-19 16:22 6,480 --sh--w C:\WINDOWS\system32\cddgh.bak1
          2007-09-09 11:20 6,440 --sh--w C:\WINDOWS\system32\egfhk.bak1
          2007-09-12 12:21 6,642 --sh--w C:\WINDOWS\system32\egfhk.bak2
          2007-09-15 11:15 6,440 --sh--w C:\WINDOWS\system32\ehhjl.bak1
          2007-09-16 17:31 6,480 --sh--w C:\WINDOWS\system32\gijjl.bak1
          2007-09-13 12:27 6,440 --sh--w C:\WINDOWS\system32\jihhk.bak1
          2007-09-15 16:23 6,665 --sh--w C:\WINDOWS\system32\jihhk.bak2
          2007-09-17 11:37 6,440 --sh--w C:\WINDOWS\system32\jmppo.bak1
          2007-09-20 15:32 6,440 --sh--w C:\WINDOWS\system32\kknnn.bak1
          2007-09-24 11:11 6,480 --sh--w C:\WINDOWS\system32\knqru.bak1
          2007-09-23 17:38 6,480 --sh--w C:\WINDOWS\system32\lmllm.bak1
          2007-09-10 12:23 6,440 --sh--w C:\WINDOWS\system32\mmnpo.bak1
          2007-09-26 17:03 6,440 --sh--w C:\WINDOWS\system32\onoqr.bak1
          2007-10-01 16:38 23,969 --sh--w C:\WINDOWS\system32\onoqr.bak2
          2007-10-01 13:19 6,480 --sh--w C:\WINDOWS\system32\opqru.bak1
          2007-09-23 12:57 6,440 --sh--w C:\WINDOWS\system32\oqppo.bak1
          2007-10-03 13:56 10,828 --sh--w C:\WINDOWS\system32\oqppo.bak2
          2007-09-18 16:36 6,480 --sh--w C:\WINDOWS\system32\pqtss.bak1
          2007-09-25 09:03 6,514 --sh--w C:\WINDOWS\system32\pqtss.bak2
          2007-09-20 11:06 6,440 --sh--w C:\WINDOWS\system32\rqpoq.bak1
          2007-09-25 08:29 6,440 --sh--w C:\WINDOWS\system32\ruvut.bak1
          2007-09-21 14:55 6,440 --sh--w C:\WINDOWS\system32\tssru.bak1
          .

          ((((((((((((((((((((((((((((( snapshot@2008-01-21_14.53.19.47 )))))))))))))))))))))))))))))))))))))))))
          .
          + 2008-01-22 07:55:58 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_598.dat
          .
          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          REGEDIT4
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{07AA283A-43D7-4CBE-A064-32A21112D94D}]

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5639B06-57B2-40E6-940C-5DADCD2D7E8C}]
          C:\WINDOWS\system32\ljjhf.dll

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
          "Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe" [2005-10-27 11:00 299008]
          "IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-03-01 17:01 208946]
          "NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 19:14 1867776]
          "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-17 12:32 68856]
          "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]
          "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
          "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 17:28 49152]
          "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 14:18 241664]
          "DXDllRegExe"="dxdllreg.exe" []
          "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
          "SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 07:23 132624]
          "Salestart(1)"="C:\Program Files\Fichiers communs\TrojansFiltre\stmon.exe" [ ]
          "Salestart(2)"="C:\Program Files\Fichiers communs\Nettordinateur\mc.exe" [ ]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]
          "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]

          [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
          "{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 15:51 192512]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqp]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnk]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqpo]

          S3 OLITEC(OLITEC);Stick USB 802.11g OLITEC Driver(OLITEC);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-09-29 11:00]
          S3 V0260VID;Live! Cam Vista IM;C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-04-01 16:16]
          S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;C:\WINDOWS\system32\ZDBRGSYS.SYS []

          .
          **************************************************************************

          catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-01-22 09:35:32
          Windows 5.1.2600 Service Pack 2 NTFS

          scanning hidden processes ...

          scanning hidden autostart entries ...

          scanning hidden files ...

          scan completed successfully
          hidden files: 0

          **************************************************************************
          .
          Completion time: 2008-01-22 9:37:09
          ComboFix-quarantined-files.txt 2008-01-22 08:36:42
          ComboFix2.txt 2008-01-21 13:55:07
          .
          2008-01-09 17:45:02 --- E O F ---

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 14:23:22, on 22/01/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16574)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\wscntfy.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\HP\HP Software Update\HPWuSchd.exe
          C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
          C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Creative\Shared Files\CamTray.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Picasa2\PicasaMediaDetector.exe
          C:\PROGRA~1\INCRED~1\bin\IMApp.exe
          C:\Program Files\adslTV\adsltv.exe
          C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O2 - BHO: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
          O2 - BHO: (no name) - {C5639B06-57B2-40E6-940C-5DADCD2D7E8C} - C:\WINDOWS\system32\ljjhf.dll (file missing)
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
          O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
          O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
          O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
          O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Fichiers communs\TrojansFiltre\stmon.exe" dm=http://trojansfiltre.com; ad=http://trojansfiltre.com
          O4 - HKLM\..\Run: [Salestart(2)] "C:\Program Files\Fichiers communs\Nettordinateur\mc.exe" dm=http://nettordinateur.com ad=http://nettordinateur.com sd=http://paylogs.nettordinateur.com
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
          O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
          O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
          O4 - Startup: adsl TV.LNK = C:\Program Files\adslTV\adsltv.exe
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
          O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
          O20 - Winlogon Notify: sstqp - C:\WINDOWS\
          O20 - Winlogon Notify: urqnk - C:\WINDOWS\
          O20 - Winlogon Notify: urqpo - C:\WINDOWS\
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
          1. bon on vas faire autrement !

            télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
            double-clique sur OTMoveIt.exe pour le lancer.
            copie la liste qui se trouve en citation ci-dessous,
            et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

            Citation :

            C:\WINDOWS\system32\ljjhf.dll
            C:\Program Files\LibreSystem
            C:\WINDOWS\system32\acdgh.bak1
            C:\WINDOWS\system32\adcfe.bak1
            C:\WINDOWS\system32\adcfe.bak2
            C:\WINDOWS\system32\cddgh.bak1
            C:\WINDOWS\system32\egfhk.bak1
            C:\WINDOWS\system32\egfhk.bak2
            C:\WINDOWS\system32\ehhjl.bak1
            C:\WINDOWS\system32\gijjl.bak1
            C:\WINDOWS\system32\jihhk.bak1
            C:\WINDOWS\system32\jihhk.bak2
            C:\WINDOWS\system32\jmppo.bak1
            C:\WINDOWS\system32\kknnn.bak1
            C:\WINDOWS\system32\knqru.bak1
            C:\WINDOWS\system32\lmllm.bak1
            C:\WINDOWS\system32\mmnpo.bak1
            C:\WINDOWS\system32\onoqr.bak1
            C:\WINDOWS\system32\onoqr.bak2
            C:\WINDOWS\system32\opqru.bak1
            C:\WINDOWS\system32\oqppo.bak1
            C:\WINDOWS\system32\oqppo.bak2
            C:\WINDOWS\system32\pqtss.bak1
            C:\WINDOWS\system32\pqtss.bak2
            C:\WINDOWS\system32\rqpoq.bak1
            C:\WINDOWS\system32\ruvut.bak1
            C:\WINDOWS\system32\tssru.bak1



            clique sur MoveIt! pour lancer la suppression.
            le résultat apparaitra dans le cadre "Results".
            clique sur Exit pour fermer.
            poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
            copie et colle le rapport ici
            il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

            poste moi aussi un nouvel hijackthis stp
            1. les voici:

              File/Folder C:\WINDOWS\system32\ljjhf.dll not found.
              C:\Program Files\LibreSystem moved successfully.
              C:\WINDOWS\system32\acdgh.bak1 moved successfully.
              C:\WINDOWS\system32\adcfe.bak1 moved successfully.
              C:\WINDOWS\system32\adcfe.bak2 moved successfully.
              C:\WINDOWS\system32\cddgh.bak1 moved successfully.
              C:\WINDOWS\system32\egfhk.bak1 moved successfully.
              C:\WINDOWS\system32\egfhk.bak2 moved successfully.
              C:\WINDOWS\system32\ehhjl.bak1 moved successfully.
              C:\WINDOWS\system32\gijjl.bak1 moved successfully.
              C:\WINDOWS\system32\jihhk.bak1 moved successfully.
              C:\WINDOWS\system32\jihhk.bak2 moved successfully.
              C:\WINDOWS\system32\jmppo.bak1 moved successfully.
              C:\WINDOWS\system32\kknnn.bak1 moved successfully.
              C:\WINDOWS\system32\knqru.bak1 moved successfully.
              C:\WINDOWS\system32\lmllm.bak1 moved successfully.
              C:\WINDOWS\system32\mmnpo.bak1 moved successfully.
              C:\WINDOWS\system32\onoqr.bak1 moved successfully.
              C:\WINDOWS\system32\onoqr.bak2 moved successfully.
              C:\WINDOWS\system32\opqru.bak1 moved successfully.
              C:\WINDOWS\system32\oqppo.bak1 moved successfully.
              C:\WINDOWS\system32\oqppo.bak2 moved successfully.
              C:\WINDOWS\system32\pqtss.bak1 moved successfully.
              C:\WINDOWS\system32\pqtss.bak2 moved successfully.
              C:\WINDOWS\system32\rqpoq.bak1 moved successfully.
              C:\WINDOWS\system32\ruvut.bak1 moved successfully.
              C:\WINDOWS\system32\tssru.bak1 moved successfully.

              Created on 01/22/2008 14:54:21

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 14:56:34, on 22/01/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16574)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\HP\HP Software Update\HPWuSchd.exe
              C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
              C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
              C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Creative\Shared Files\CamTray.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Picasa2\PicasaMediaDetector.exe
              C:\PROGRA~1\INCRED~1\bin\IMApp.exe
              C:\Program Files\adslTV\adsltv.exe
              C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
              C:\WINDOWS\explorer.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O2 - BHO: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
              O2 - BHO: (no name) - {C5639B06-57B2-40E6-940C-5DADCD2D7E8C} - C:\WINDOWS\system32\ljjhf.dll (file missing)
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
              O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
              O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
              O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Fichiers communs\TrojansFiltre\stmon.exe" dm=http://trojansfiltre.com; ad=http://trojansfiltre.com
              O4 - HKLM\..\Run: [Salestart(2)] "C:\Program Files\Fichiers communs\Nettordinateur\mc.exe" dm=http://nettordinateur.com ad=http://nettordinateur.com sd=http://paylogs.nettordinateur.com
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
              O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
              O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
              O4 - Startup: adsl TV.LNK = C:\Program Files\adslTV\adsltv.exe
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
              O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
              O20 - Winlogon Notify: sstqp - C:\WINDOWS\
              O20 - Winlogon Notify: urqnk - C:\WINDOWS\
              O20 - Winlogon Notify: urqpo - C:\WINDOWS\
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
              1. créer un fichier reg

                Fix.reg

                Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(X)) :

                XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
                REGEDIT4

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqp]
                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnk]
                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqpo]
                [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{07AA283A-43D7-4CBE-A064-32A21112D94D}]
                [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5639B06-57B2-40E6-940C-5DADCD2D7E8C}]

                XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
                note : regedit 4 est sur la premiere ligne et il y a une ligne blanche a la fin
                Puis click sur "fichier"/"enregistrer sous" :
                dans : sur le bureau
                Nom du fichier : fix.reg
                Type de fichier : "tous les fichiers"
                clique sur "enregistrer"

                ca doit ressembler a ca une fois enrregistré :

                http://img520.imageshack.us/img520/4251/screenshot005ps2.png

                quitte internet et double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
                Si c'est bien le cas, clique sur "oui"
                1. bonsoir, j'ai tout fait mais message d'erreur "Impossible d'importer: C:/Documents and seting/christiane/Bureau/Fix.reg: erreur d'accès au registre"
                  1. bonjour, voici le log:

                    ComboFix 08-01-20.1 - christiane 2008-01-24 8:13:11.5 - NTFSx86
                    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.695 [GMT 1:00]
                    Running from: C:\Documents and Settings\christiane\Bureau\ComboFix.exe

                    [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
                    .

                    ((((((((((((((((((((((((((((( Fichiers créés 2007-12-24 to 2008-01-24 ))))))))))))))))))))))))))))))))))))
                    .

                    2008-01-21 14:34 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
                    2008-01-21 11:10 . 2008-01-21 13:44 <REP> d-------- C:\VundoFix Backups
                    2008-01-21 09:53 . 2008-01-21 09:53 <REP> d-------- C:\Program Files\Trend Micro
                    2008-01-13 17:36 . 2008-01-13 17:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                    2008-01-09 18:45 . 2008-01-09 18:45 118 --a------ C:\WINDOWS\system32\MRT.INI
                    2008-01-09 18:42 . 2008-01-09 18:42 1,355 --a------ C:\WINDOWS\imsins.BAK
                    2008-01-01 15:40 . 2008-01-01 15:40 268 --ah----- C:\sqmdata01.sqm
                    2008-01-01 15:40 . 2008-01-01 15:40 244 --ah----- C:\sqmnoopt01.sqm
                    2007-12-29 15:39 . 2008-01-13 17:32 <REP> d-------- C:\Program Files\MalwareAlarm
                    2007-12-29 15:39 . 2007-12-29 15:39 1,271,822 --a------ C:\Install

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2008-01-24 07:10 --------- d-----w C:\Program Files\adslTV
                    2008-01-21 09:18 --------- d-----w C:\Program Files\Yahoo!
                    2008-01-15 15:39 --------- d-----w C:\Program Files\Fichiers communs\Nettordinateur
                    2008-01-13 16:38 --------- d-----w C:\Program Files\Fichiers communs\TrojansFiltre
                    2007-12-27 14:43 --------- d-----w C:\Documents and Settings\christiane\Application Data\Creative
                    2007-12-16 13:16 --------- d-----w C:\Program Files\TrojansFiltre
                    2007-12-06 17:57 --------- d-----w C:\Documents and Settings\christiane\Application Data\Nettordinateur
                    2007-12-06 17:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nettordinateur
                    2007-12-05 19:40 --------- d-----w C:\Program Files\Fichiers communs\DefenseNetSurfage
                    2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
                    2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
                    2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
                    2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
                    2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
                    2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
                    2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
                    2007-11-28 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\muvee Technologies
                    2007-11-28 15:55 --------- d-----w C:\Documents and Settings\christiane\Application Data\muvee Technologies
                    2007-11-20 14:36 118,784 ----a-w C:\WINDOWS\system32\MaDRM.dll
                    2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
                    2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
                    2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
                    .

                    ((((((((((((((((((((((((((((( snapshot@2008-01-21_14.53.19.47 )))))))))))))))))))))))))))))))))))))))))
                    .
                    + 2008-01-24 07:10:11 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_598.dat
                    .
                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    REGEDIT4
                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{07AA283A-43D7-4CBE-A064-32A21112D94D}]

                    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5639B06-57B2-40E6-940C-5DADCD2D7E8C}]
                    C:\WINDOWS\system32\ljjhf.dll

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
                    "Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe" [2005-10-27 11:00 299008]
                    "IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-03-01 17:01 208946]
                    "NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 19:14 1867776]
                    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-17 12:32 68856]
                    "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]
                    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
                    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 17:28 49152]
                    "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 14:18 241664]
                    "DXDllRegExe"="dxdllreg.exe" []
                    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
                    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
                    "SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 07:23 132624]
                    "Salestart(1)"="C:\Program Files\Fichiers communs\TrojansFiltre\stmon.exe" [ ]
                    "Salestart(2)"="C:\Program Files\Fichiers communs\Nettordinateur\mc.exe" [ ]

                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]
                    "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]

                    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
                    "{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 15:51 192512]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqp]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnk]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqpo]

                    S3 OLITEC(OLITEC);Stick USB 802.11g OLITEC Driver(OLITEC);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-09-29 11:00]
                    S3 V0260VID;Live! Cam Vista IM;C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-04-01 16:16]
                    S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;C:\WINDOWS\system32\ZDBRGSYS.SYS []

                    .
                    **************************************************************************

                    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2008-01-24 08:15:30
                    Windows 5.1.2600 Service Pack 2 NTFS

                    scanning hidden processes ...

                    scanning hidden autostart entries ...

                    scanning hidden files ...

                    scan completed successfully
                    hidden files: 0

                    **************************************************************************
                    .
                    Completion time: 2008-01-24 8:17:06
                    ComboFix-quarantined-files.txt 2008-01-24 07:16:39
                    ComboFix2.txt 2008-01-22 13:14:16
                    ComboFix3.txt 2008-01-22 08:37:10
                    ComboFix4.txt 2008-01-21 13:55:07
                    .
                    2008-01-09 17:45:02 --- E O F ---
                    1. bonjour , je travail sur ton rapport en attendant , je t'invite a desinstaler ceci : Nettordinateur
                      1. Merci mais je n'ai pas trouvé NETTordinateur ni dans "suppression de programmes" ni dans "démarrer", "programme"
                        1. re ok ! il faut recommencer cette manip ca n'as pas marche a cause d'un oublie de ma part ! (merci g!rly )

                          Ouvre le Bloc-Notes puis colle le texte copié.
                          (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
                          Sauvegarde ce fichier sous le nom de CFScript.txt.

                          Copie le texte en gras : ci-dessous :

                          registre::
                          [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqp]
                          [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnk]
                          [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqpo]
                          [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{07AA283A-43D7-4CBE-A064-32A21112D94D}]
                          [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5639B06-57B2-40E6-940C-5DADCD2D7E8C}]
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "Salestart(1)"=-
                          "Salestart(2)"=-

                          files::
                          C:\Install

                          folder::
                          C:\Program Files\MalwareAlarm
                          C:\Program Files\Fichiers communs\Nettordinateur
                          C:\Program Files\Fichiers communs\TrojansFiltre
                          C:\VundoFix Backups


                          Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

                          http://serveur1.archive-host.com/membres/up/1366464061/CFScript.gif

                          Cela va relancer Combofix,

                          Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                          Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                          Ne touche à rien tant que le scan n'est pas terminé.

                          Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

                          S'il n'y a pas de rédémarrage, poste quand même les rapports.
                          1. merci de votre réponse, j'ai du m'absenter mais cela semble pas marcher. Voici les rapports;

                            ComboFix 08-01-20.1 - christiane 2008-01-27 11:54:00.6 - NTFSx86
                            Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.695 [GMT 1:00]
                            Running from: C:\Documents and Settings\christiane\Bureau\ComboFix.exe

                            [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
                            .

                            ((((((((((((((((((((((((((((( Fichiers créés 2007-12-27 to 2008-01-27 ))))))))))))))))))))))))))))))))))))
                            .

                            2008-01-21 14:34 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
                            2008-01-21 11:10 . 2008-01-21 13:44 <REP> d-------- C:\VundoFix Backups
                            2008-01-21 09:53 . 2008-01-21 09:53 <REP> d-------- C:\Program Files\Trend Micro
                            2008-01-13 17:36 . 2008-01-13 17:38 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                            2008-01-09 18:45 . 2008-01-09 18:45 118 --a------ C:\WINDOWS\system32\MRT.INI
                            2008-01-09 18:42 . 2008-01-09 18:42 1,355 --a------ C:\WINDOWS\imsins.BAK
                            2008-01-01 15:40 . 2008-01-01 15:40 268 --ah----- C:\sqmdata01.sqm
                            2008-01-01 15:40 . 2008-01-01 15:40 244 --ah----- C:\sqmnoopt01.sqm
                            2007-12-29 15:39 . 2008-01-13 17:32 <REP> d-------- C:\Program Files\MalwareAlarm
                            2007-12-29 15:39 . 2007-12-29 15:39 1,271,822 --a------ C:\Install

                            .
                            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            2008-01-27 10:48 --------- d-----w C:\Program Files\adslTV
                            2008-01-21 09:18 --------- d-----w C:\Program Files\Yahoo!
                            2008-01-15 15:39 --------- d-----w C:\Program Files\Fichiers communs\Nettordinateur
                            2008-01-13 16:38 --------- d-----w C:\Program Files\Fichiers communs\TrojansFiltre
                            2007-12-27 14:43 --------- d-----w C:\Documents and Settings\christiane\Application Data\Creative
                            2007-12-16 13:16 --------- d-----w C:\Program Files\TrojansFiltre
                            2007-12-06 17:57 --------- d-----w C:\Documents and Settings\christiane\Application Data\Nettordinateur
                            2007-12-06 17:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nettordinateur
                            2007-12-05 19:40 --------- d-----w C:\Program Files\Fichiers communs\DefenseNetSurfage
                            2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
                            2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
                            2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
                            2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
                            2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
                            2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
                            2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
                            2007-11-28 16:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\muvee Technologies
                            2007-11-28 15:55 --------- d-----w C:\Documents and Settings\christiane\Application Data\muvee Technologies
                            2007-11-20 14:36 118,784 ----a-w C:\WINDOWS\system32\MaDRM.dll
                            2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
                            2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
                            .

                            ((((((((((((((((((((((((((((( snapshot@2008-01-21_14.53.19.47 )))))))))))))))))))))))))))))))))))))))))
                            .
                            + 2008-01-27 10:47:48 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5a0.dat
                            .
                            ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            .
                            REGEDIT4
                            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                            [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{07AA283A-43D7-4CBE-A064-32A21112D94D}]

                            [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5639B06-57B2-40E6-940C-5DADCD2D7E8C}]
                            C:\WINDOWS\system32\ljjhf.dll

                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
                            "Creative WebCam Tray"="C:\Program Files\Creative\Shared Files\CamTray.exe" [2005-10-27 11:00 299008]
                            "IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-03-01 17:01 208946]
                            "NBJ"="C:\Program Files\Ahead\Nero BackItUp\NBJ.exe" [2004-07-26 19:14 1867776]
                            "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-17 12:32 68856]
                            "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]
                            "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2007-08-31 16:46 1460560]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
                            "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd.exe" [2003-08-04 17:28 49152]
                            "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 14:18 241664]
                            "DXDllRegExe"="dxdllreg.exe" []
                            "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
                            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 03:00 132496]
                            "SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 07:23 132624]
                            "Salestart(1)"="C:\Program Files\Fichiers communs\TrojansFiltre\stmon.exe" [ ]
                            "Salestart(2)"="C:\Program Files\Fichiers communs\Nettordinateur\mc.exe" [ ]

                            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                            "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]
                            "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2007-09-28 02:17 443968]

                            [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
                            "{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 15:51 192512]

                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstqp]

                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqnk]

                            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\urqpo]

                            S3 OLITEC(OLITEC);Stick USB 802.11g OLITEC Driver(OLITEC);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-09-29 11:00]
                            S3 V0260VID;Live! Cam Vista IM;C:\WINDOWS\system32\DRIVERS\V0260Vid.sys [2006-04-01 16:16]
                            S3 ZDBRGSYS;ZDBRGSYS NDIS Protocol Driver;C:\WINDOWS\system32\ZDBRGSYS.SYS []

                            .
                            **************************************************************************

                            catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2008-01-27 11:56:19
                            Windows 5.1.2600 Service Pack 2 NTFS

                            scanning hidden processes ...

                            scanning hidden autostart entries ...

                            scanning hidden files ...

                            scan completed successfully
                            hidden files: 0

                            **************************************************************************
                            .
                            Completion time: 2008-01-27 11:57:56
                            ComboFix-quarantined-files.txt 2008-01-27 10:57:29
                            ComboFix2.txt 2008-01-24 07:17:07
                            ComboFix3.txt 2008-01-22 13:14:16
                            ComboFix4.txt 2008-01-22 08:37:10
                            ComboFix5.txt 2008-01-21 13:55:07
                            .
                            2008-01-09 17:45:02 --- E O F ---

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 12:08:19, on 27/01/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            C:\WINDOWS\system32\wscntfy.exe
                            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            C:\Program Files\HP\HP Software Update\HPWuSchd.exe
                            C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                            C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                            C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Creative\Shared Files\CamTray.exe
                            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            C:\Program Files\Picasa2\PicasaMediaDetector.exe
                            C:\Program Files\adslTV\adsltv.exe
                            C:\PROGRA~1\INCRED~1\bin\IMApp.exe
                            C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                            C:\WINDOWS\explorer.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = https://support.microsoft.com/en-US/topic/internet-explorer-downloads-d49e1f0d-571c-9a7b-d97e-be248806ca70
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                            O2 - BHO: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
                            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                            O2 - BHO: (no name) - {C5639B06-57B2-40E6-940C-5DADCD2D7E8C} - C:\WINDOWS\system32\ljjhf.dll (file missing)
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                            O3 - Toolbar: (no name) - {07AA283A-43D7-4CBE-A064-32A21112D94D} - (no file)
                            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
                            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                            O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
                            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                            O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
                            O4 - HKLM\..\Run: [Salestart(1)] "C:\Program Files\Fichiers communs\TrojansFiltre\stmon.exe" dm=http://trojansfiltre.com; ad=http://trojansfiltre.com
                            O4 - HKLM\..\Run: [Salestart(2)] "C:\Program Files\Fichiers communs\Nettordinateur\mc.exe" dm=http://nettordinateur.com ad=http://nettordinateur.com sd=http://paylogs.nettordinateur.com
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [Creative WebCam Tray] "C:\Program Files\Creative\Shared Files\CamTray.exe"
                            O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
                            O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
                            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                            O4 - Startup: adsl TV.LNK = C:\Program Files\adslTV\adsltv.exe
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.fr/SnapfishActivia.cab
                            O16 - DPF: {DEB21AD3-FDA4-42F6-B57D-EE696A675EE8} (IPSUploader Control) - http://as.photoprintit.de/ips-opdata/layout/default01/activex/IPSUploader.cab
                            O20 - Winlogon Notify: sstqp - C:\WINDOWS\
                            O20 - Winlogon Notify: urqnk - C:\WINDOWS\
                            O20 - Winlogon Notify: urqpo - C:\WINDOWS\
                            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                            O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
                            Précédent
                            • 1
                            • 2