Aidez moi win32:tratBHO impossible a effacer

Résolu
Bonjour,
J'ai attrapper win32:trat BHO et je n'arrive pas a le degager aide serai bien venu merci d'avance

log hjt

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:09:54, on 06/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [UberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"
O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
O4 - Startup: RocketDock.lnk.disabled
O4 - Startup: UberIcon.lnk.disabled
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 3685 bytes
Configuration: Windows XP
Firefox 2.0.0.11

23 réponses

  1. Contributeur
    oui c´est embetant...

    on va faire comme ca :

    * Télécharge OTMoveIt2 (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

    n´y touche pas pour le moment

    redemarre en mode sans echec : en mode sans echec tu n´auras plus acces a internet alors copie les instructions si dessous dans un fichier texte par exemple ou imprime les avant de commencer

    Comment redémarrer en mode sans echec?

    Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
    Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
    capture d´ecran : http://www.coupdepoucepc.com/images_cdppc4/fichespratiques/windowsxp/modese/modese2.jpg
    Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
    Ps : si F8 ne marche pas utilise la touche F5.

    une fois en mode sans echec :

    Fix.reg

    Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(x)) :

    XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
    REGEDIT4

    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvv]

    XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
    Note : regedit4 doit etre sur la premiere ligne dans le bloc note et il y a une ligne blanche a la fin
    Puis click sur "fichier"/"enregistrer sous" :
    dans : sur le bureau
    Nom du fichier : fix.reg
    Type de fichier : "tous les fichiers"
    clique sur "enregistrer"

    ca doit ressembler a ca une fois enrregistré :

    http://img520.imageshack.us/img520/4251/screenshot005ps2.png

    quitte internet et double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
    Si c'est bien le cas, clique sur "oui"

    puis

    * Double-clique sur OTMoveIt.exe pour lancer le programme,
    * Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste Custom List of Files/Folders to Move" :

    C:\WINDOWS\mrofinu2000351.exe
    C:\WINDOWS\system32\DRIVERS\nvsmu.sys
    C:\WINDOWS\system32\spoolsvv.exe

    * Clique sur MoveIt! pour lancer la suppression,
    * Le résultat appraraîtra dans le cadre Results.
    * Clique sur Exit pour fermer le programme.
    * Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
    * Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.

    redemarre en mode normal et post le resulat de ot Move it

    et le resulatat de ce scan :

    Télécharge ComboScan sur ton Bureau en bas de cette pae en clickant sur download file

    -> http://www.geekstogo.com/forum/files/

    Ferme toutes les applications en cours : antivirus, pare-feu, etc ..
    Double-clic sur comboscan.exe, dans la fenêtre qui s'affiche, clic sur OK.
    Soit patient...
    Le rapport Comboscan.txt s'affichera, copie et colle le contenu de ce fichier ici.

    Le rapport peut-être long et en deux morceaux vérifie qu'il soit en entier.

    ps ; si tu ne comprends pas quelque chose demande moi avant de commencer

    @+
    1
    1. Contributeur
      salut,

      fais ceci :

      Télécharge combofix.exe (par sUBs) sur ton Bureau.

      -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

      -> Double clique combofix.exe.
      -> Tape sur la touche 1 (Yes) pour démarrer le scan.
      -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

      NOTE : Le rapport se trouve également ici : C:\Combofix.txt

      et

      repost un nouveau hjack this dans ta reponse

      @+
      0
      1. 1er rapport de combo fix

        ComboFix 08-02.05.3 - nadgy 2008-02-06 18:04:31.1 - NTFSx86
        Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.644 [GMT 1:00]
        Endroit: C:\Documents and Settings\nadgy\Bureau\ComboFix.exe
        * Création d'un nouveau point de restauration

        [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
        .

        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
        .

        C:\WINDOWS\system32\config\47116946.Evt
        C:\WINDOWS\system32\ssqpp.dll
        C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
        C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
        C:\install.exe
        C:\Windows.exe
        C:\WINDOWS\mrofinu2000351.exe
        C:\WINDOWS\system32\config\47116946.Evt
        C:\WINDOWS\system32\gebbyxv.dll
        C:\WINDOWS\system32\mcrh.tmp
        C:\WINDOWS\system32\ppqss.ini
        C:\WINDOWS\system32\ppqss.ini2
        C:\WINDOWS\system32\ssqpp.dll
        D:\Autorun.inf

        ----- BITS: Possible sites infect‚s -----

        hxxp://www.download.windowsupdate.com
        .
        ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

        .
        -------\LEGACY_ASC3550P
        -------\asc3550p

        ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-01-06 to 2008-02-06 ))))))))))))))))))))))))))))))))))))
        .

        2008-02-06 15:39 . 2008-02-06 15:39 <REP> d-------- C:\Program Files\Trend Micro
        2008-02-06 14:57 . 2008-02-06 14:57 <REP> d-------- C:\Program Files\Panda Security
        2008-02-05 11:58 . 2008-02-05 11:49 691,545 --a------ C:\WINDOWS\unins000.exe
        2008-02-05 11:58 . 2008-02-05 11:58 3,447 --a------ C:\WINDOWS\unins000.dat
        2008-02-04 15:24 . 2008-02-04 15:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
        2008-02-04 15:22 . 2008-02-04 15:22 <REP> d-------- C:\Program Files\Sony
        2008-02-04 15:22 . 2008-02-04 15:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sony
        2008-02-04 15:20 . 2008-02-04 15:20 <REP> d-------- C:\Program Files\MSBuild
        2008-02-04 15:17 . 2008-02-04 15:17 <REP> d-------- C:\WINDOWS\system32\XPSViewer
        2008-02-04 15:16 . 2008-02-04 15:16 <REP> d-------- C:\Program Files\Reference Assemblies
        2008-02-04 15:16 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
        2008-02-04 15:12 . 2008-02-04 15:12 <REP> d-------- C:\Program Files\Sony Setup
        2008-02-04 15:12 . 2008-02-04 15:12 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Sony Setup
        2008-02-03 00:55 . 2008-02-04 15:22 <REP> d-------- C:\Program Files\VSTplugins
        2008-02-03 00:55 . 2008-02-03 00:55 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Publish Providers
        2008-02-03 00:54 . 2008-02-04 15:24 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Sony
        2008-02-02 20:16 . 2008-02-02 20:16 <REP> dr-h----- C:\Documents and Settings\nadgy\Application Data\SecuROM
        2008-02-02 20:16 . 2008-02-02 20:16 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
        2008-02-02 20:06 . 2008-02-02 20:06 36,864 --a------ C:\WINDOWS\mrofinu2000351.exe.tmp
        2008-02-02 01:17 . 2008-02-02 01:17 <REP> d-------- C:\Program Files\SystemRequirementsLab
        2008-02-02 01:17 . 2008-02-02 01:17 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\SystemRequirementsLab
        2008-02-02 01:14 . 2008-02-06 18:07 51,048 --a------ C:\WINDOWS\system32\nvapps.xml
        2008-02-02 01:14 . 2006-08-18 09:00 17,056 --a------ C:\WINDOWS\system32\nvdisp.nvu
        2008-02-02 01:11 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
        2008-02-02 01:10 . 2008-02-02 01:10 <REP> d-------- C:\NVIDIA
        2008-01-27 18:50 . 2008-02-06 15:58 <REP> d-------- C:\VundoFix Backups
        2008-01-26 17:36 . 2008-01-26 17:36 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\dvdcss
        2008-01-26 14:00 . 2008-02-02 23:02 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
        2008-01-26 13:52 . 2008-01-26 14:12 <REP> d-------- C:\Program Files\VirtualDJ
        2008-01-26 13:42 . 2008-01-26 13:45 <REP> d-------- C:\Program Files\Windows Live
        2008-01-25 15:28 . 2008-01-25 15:29 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\MMTVConfig
        2008-01-25 15:27 . 2008-01-25 15:27 <REP> d-------- C:\Program Files\MMTVConfig
        2008-01-24 21:48 . 2008-01-25 12:38 <REP> d-------- C:\Program Files\MeuhMeuhTV
        2008-01-24 20:53 . 2008-01-24 20:53 <REP> d-------- C:\Program Files\DivX
        2008-01-23 10:52 . 2008-01-23 10:52 <REP> d-------- C:\Program Files\DIFX
        2008-01-23 10:50 . 2007-01-12 14:57 110,592 --a------ C:\WINDOWS\system32\SynTPCo4.dll
        2008-01-23 10:46 . 2008-01-23 10:46 <REP> d-------- C:\Program Files\Broadcom
        2008-01-23 10:38 . 2008-01-23 10:38 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\InstallShield
        2008-01-21 14:17 . 2008-01-21 14:17 58 --a------ C:\WINDOWS\yesmessenger.ini
        2008-01-19 23:54 . 2008-01-19 23:54 583 --a------ C:\WINDOWS\eReg.dat
        2008-01-16 19:58 . 2008-01-16 19:58 <REP> d-------- C:\Program Files\Flagship Studios
        2008-01-16 19:58 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
        2008-01-16 19:58 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
        2008-01-16 19:58 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
        2008-01-16 15:40 . 2008-01-16 15:40 528 -r-hs---- C:\WINDOWS\egirllic151
        2008-01-16 15:38 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
        2008-01-16 15:38 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
        2008-01-15 12:20 . 2008-02-06 14:21 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\OpenOffice.org2
        2008-01-15 10:59 . 2008-01-15 10:59 <REP> d-------- C:\Program Files\OpenOffice.org 2.3
        2008-01-15 10:58 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
        2008-01-12 17:56 . 2008-01-12 17:55 57,856 --a------ C:\WINDOWS\taskmon.exe
        2008-01-12 12:00 . 2008-01-12 12:00 <REP> d-------- C:\myinst
        2008-01-12 11:59 . 2008-01-12 11:59 720,896 --a------ C:\WINDOWS\iun6002.exe
        2008-01-12 09:59 . 2008-01-12 09:59 368,640 --a------ C:\WINDOWS\system32\ReWire.dll
        2008-01-12 09:59 . 2008-01-12 09:59 233,472 --a------ C:\WINDOWS\system32\REX Shared Library.dll
        2008-01-12 09:56 . 2008-01-12 10:27 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Propellerhead Software
        2008-01-12 09:56 . 2008-01-12 09:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Propellerhead Software
        2008-01-12 09:55 . 2008-01-12 09:55 <REP> d-------- C:\Program Files\Propellerhead
        2008-01-11 23:41 . 2008-01-11 23:41 <REP> d-------- C:\WINDOWS\Downloaded Installations
        2008-01-11 12:40 . 2008-01-11 12:40 <REP> d-------- C:\Program Files\KONAMI
        2008-01-09 22:38 . 2008-02-02 22:23 <REP> d-------- C:\Program Files\eMule
        2008-01-09 21:54 . 2008-01-09 21:54 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\HP
        2008-01-09 12:14 . 2006-10-04 15:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
        2008-01-09 12:14 . 2006-10-04 15:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
        2008-01-09 12:14 . 2006-10-04 15:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
        2008-01-09 12:13 . 2008-02-06 16:05 <REP> d-------- C:\WINDOWS\system32\LogFiles
        2008-01-09 12:13 . 2008-01-09 12:13 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
        2008-01-09 11:06 . 2008-01-30 16:42 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\AdobeUM
        2008-01-09 11:00 . 2008-01-09 11:00 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Steinberg
        2008-01-09 10:45 . 2005-05-09 20:08 33,792 --a------ C:\WINDOWS\system32\drivers\cledx.sys
        2008-01-09 10:38 . 2008-01-09 10:38 <REP> d-------- C:\Program Files\Steinberg
        2008-01-09 10:35 . 2003-07-31 20:28 147,425 --a------ C:\WINDOWS\system32\SYNSOACC-Aide.chm
        2008-01-09 10:35 . 2003-05-26 15:29 120,468 --a------ C:\WINDOWS\system32\SYNSOACC-Hilfe.chm
        2008-01-09 10:35 . 2003-05-26 15:29 114,279 --a------ C:\WINDOWS\system32\SYNSOACC-Help.chm
        2008-01-09 10:33 . 2008-01-09 10:43 <REP> d-------- C:\Program Files\Syncrosoft
        2008-01-09 10:33 . 2005-10-17 09:35 704,512 --a------ C:\WINDOWS\system32\SYNSOACC.dll
        2008-01-09 10:33 . 2004-05-10 15:58 147,456 --a------ C:\WINDOWS\system32\SynsoLChk.dll
        2008-01-09 10:33 . 2002-11-25 08:36 45,056 --a------ C:\WINDOWS\system32\Synsopos.exe
        2008-01-09 10:33 . 2002-11-25 05:46 16,896 --a------ C:\WINDOWS\system32\drivers\SynasUSB.sys
        2008-01-09 10:27 . 2008-01-09 10:27 <REP> d-------- C:\Program Files\Alcohol Soft
        2008-01-08 18:30 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
        2008-01-08 18:30 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\dllcache\mouhid.sys
        2008-01-08 17:03 . 2008-01-08 17:03 <REP> d-------- C:\Program Files\Codemasters
        2008-01-07 18:47 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\drivers\MPE.sys
        2008-01-07 18:47 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\dllcache\mpe.sys
        2008-01-07 18:46 . 2008-01-07 18:46 <REP> d-------- C:\Program Files\MSXML 4.0
        2008-01-07 18:46 . 2007-06-14 14:41 466,048 --a------ C:\WINDOWS\system32\drivers\Ltn_stk7070P.sys
        2008-01-07 18:46 . 2004-08-04 00:55 18,432 --a------ C:\WINDOWS\system32\dllcache\bdaplgin.ax
        2008-01-07 18:46 . 2004-08-04 00:55 18,432 --a------ C:\WINDOWS\system32\BdaPlgIn.ax
        2008-01-07 18:46 . 2007-02-02 18:30 13,696 --a------ C:\WINDOWS\system32\drivers\PctvVirtualNdis.sys
        2008-01-07 18:46 . 2007-06-13 19:30 13,440 --a------ C:\WINDOWS\system32\drivers\Ltn_stkrc.sys
        2008-01-07 18:46 . 2004-08-03 23:10 11,776 --a------ C:\WINDOWS\system32\drivers\BdaSup.sys
        2008-01-07 18:46 . 2004-08-03 23:10 11,776 --a------ C:\WINDOWS\system32\dllcache\bdasup.sys
        2008-01-07 18:45 . 2006-12-01 23:54 626,688 --------- C:\WINDOWS\system32\msvcr80.dll
        2008-01-07 18:45 . 2006-12-01 23:54 548,864 --------- C:\WINDOWS\system32\msvcp80.dll
        2008-01-07 18:45 . 2004-07-23 09:00 446,464 --------- C:\WINDOWS\system32\HHActiveX.dll
        2008-01-07 18:42 . 2008-01-24 20:51 <REP> d-------- C:\Program Files\Pinnacle
        2008-01-07 18:40 . 2008-01-24 20:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
        2008-01-07 17:28 . 2008-01-07 17:28 <REP> d-------- C:\Program Files\Hercules
        2008-01-07 17:28 . 2004-04-26 09:49 381,056 --------- C:\WINDOWS\system32\drivers\MPUSens.sys

        .
        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-01-23 09:46 822,272 ----a-w C:\WINDOWS\system32\drivers\BCMWL5.SYS
        2008-01-19 22:54 11,376 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
        2008-01-19 22:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
        2008-01-15 13:27 --------- d-----w C:\Program Files\Fichiers communs\LightScribe
        2008-01-15 09:58 --------- d-----w C:\Program Files\Java
        2008-01-09 11:14 --------- d-----w C:\Program Files\Windows Media Connect 2
        2008-01-07 11:08 --------- d-----w C:\Program Files\Hewlett-Packard
        2008-01-06 18:51 --------- d-----w C:\Program Files\Windows Plus
        2008-01-06 18:50 --------- d-----w C:\Program Files\Synaptics
        2008-01-06 18:49 --------- d-----w C:\Program Files\NetWaiting
        2008-01-06 18:49 --------- d-----w C:\Program Files\microsoft frontpage
        2008-01-06 18:48 --------- d-----w C:\Program Files\HP
        2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
        2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
        2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\Java
        2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\Adobe
        2008-01-06 18:47 --------- d-----w C:\Program Files\CONEXANT
        2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
        2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBSI
        2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
        2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
        2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
        2008-01-06 10:30 --------- d-----w C:\Program Files\Symantec
        2008-01-06 10:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
        2008-01-06 10:22 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
        2008-01-06 10:10 1,658 --sha-r C:\WINDOWS\system32\drivers\103C_HP_NTBK_HP PAVILION DV6000 (RP980EA#ABF)_YN_0Pavi_QCNF6472Z0M_E432250052_46_I30B8_SQuanta_V65.29_BF.3B_T071002_WXP2_L40C_M1023_J80_7AMD_8Turion 64 Technology MK-36_92.01_#060920_N14E44311_(RP980EA#ABF)_XMOBILE.MRK
        2008-01-06 10:05 --------- d-----w C:\Program Files\HPQ
        .

        ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        REGEDIT4
        *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "UberIcon"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe" [2006-05-21 08:43 180224]
        "RocketDock"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-18 23:05 630784]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 14:36 827392]
        "RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 09:23 1187840]
        "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
        "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-18 09:00 7585792]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
        "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
        "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide de HP Photosmart Premier.lnk.disabled]
        path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide de HP Photosmart Premier.lnk.disabled
        backup=C:\WINDOWS\pss\Démarrage rapide de HP Photosmart Premier.lnk.disabledCommon Startup

        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Gamesurround Muse Pocket.lnk.disabled]
        path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Gamesurround Muse Pocket.lnk.disabled
        backup=C:\WINDOWS\pss\Gamesurround Muse Pocket.lnk.disabledCommon Startup

        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Pavilion Webcam Tray Icon.lnk]
        path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Pavilion Webcam Tray Icon.lnk
        backup=C:\WINDOWS\pss\HP Pavilion Webcam Tray Icon.lnkCommon Startup

        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
        path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
        backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^LoopBe1 Monitor.lnk]
        path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\LoopBe1 Monitor.lnk
        backup=C:\WINDOWS\pss\LoopBe1 Monitor.lnkCommon Startup

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
        --a------ 2007-07-02 11:29 220544 C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
        --a------ 2006-03-25 05:00 15360 C:\WINDOWS\system32\ctfmon.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
        --a------ 2005-08-05 20:34 64512 C:\WINDOWS\ehome\ehtray.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
        --a------ 2006-06-02 01:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
        --a------ 2005-02-16 22:11 49152 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
        --a------ 2006-05-03 21:58 458752 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
        C:\WINDOWS\system32\dumprep 0 -k

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
        --a------ 2004-08-04 08:07 1667584 C:\Program Files\Messenger\msmsgs.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
        --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\MsnMsgr.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
        --a------ 2006-08-18 09:00 7585792 C:\WINDOWS\system32\NvCpl.dll

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
        --a------ 2006-08-18 09:00 86016 C:\WINDOWS\system32\NvMcTray.dll

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
        --a------ 2006-08-18 09:00 1617920 C:\WINDOWS\system32\nwiz.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
        C:\WINDOWS\system32\PSDrvCheck.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCRemote]
        C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCS]
        C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
        --a------ 2006-06-19 10:33 163840 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
        C:\WINDOWS\mrofinu2000351.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvv]
        C:\WINDOWS\system32\spoolsvv.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
        -rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
        --a------ 2005-11-10 20:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
        --------- 2006-11-03 09:59 204288 C:\Program Files\Windows Media Player\WMPNSCFG.exe

        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
        "LightScribeService"=2 (0x2)
        "IDriverT"=3 (0x3)
        "Nero BackItUp Scheduler 3"=2 (0x2)
        "McrdSvc"=2 (0x2)
        "hpqwmiex"=2 (0x2)
        "WMPNetworkSvc"=2 (0x2)

        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
        "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
        "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
        "PMCLoader"=C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks
        "PMCRemote"=C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
        "AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount

        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
        "Cpqset"=C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
        "NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        "nwiz"=nwiz.exe /installquiet /nodetect
        "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
        "NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
        "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
        "H2O"=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
        "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe"
        "Pinnacle WebUpdater"="C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles

        R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
        R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 00:49]
        R3 PctvVirtualNdis;Pinnacle Virtual Miniport;C:\WINDOWS\system32\DRIVERS\PctvVirtualNdis.sys [2007-02-02 18:30]
        R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
        S3 Ltn_stk7070P;PCTV based TV tuner device;C:\WINDOWS\system32\DRIVERS\Ltn_stk7070P.sys [2007-06-14 14:41]
        S3 Ltn_stkrc;PCTV Infrared Receiver;C:\WINDOWS\system32\DRIVERS\Ltn_stkrc.sys [2007-06-13 19:30]
        S3 MPUSens;MPUSens;C:\WINDOWS\system32\drivers\MPUSens.sys [2004-04-26 09:49]
        S3 USB28xxBGA;PCTV 100e/150e Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2005-11-22 19:04]
        S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2005-11-22 19:04]

        .
        Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
        "2008-02-02 19:27:06 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
        - C:\Program Files\TuneUp Utilities 2008\OneClick.exe
        .
        **************************************************************************

        catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-02-06 18:08:01
        Windows 5.1.2600 Service Pack 2 NTFS

        Balayage processus cach‚s ...

        Balayage cach‚ autostart entries ...

        Balayage des fichiers cach‚s ...

        Scan termin‚ avec succŠs
        Les fichiers cach‚s: 0

        **************************************************************************
        .
        --------------------- DLLs a charg‚ sous des processus courants ---------------------

        PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
        -> C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
        -> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
        .
        ------------------------ Other Running Processes ------------------------
        .
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        .
        **************************************************************************
        .
        Temps d'accomplissement: 2008-02-06 18:09:19 - machine was rebooted
        ComboFix-quarantined-files.txt 2008-02-06 17:09:09
        .
        2008-01-10 09:59:12 --- E O F ---

        et voici le log hjt

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:12:00, on 06/02/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe
        C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\notepad.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKCU\..\Run: [UberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"
        O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
        O4 - Startup: RocketDock.lnk.disabled
        O4 - Startup: UberIcon.lnk.disabled
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
        O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        0
        1. Contributeur
          re,

          Copie le texte ci-dessous :

          File::
          C:\WINDOWS\mrofinu2000351.exe
          C:\WINDOWS\system32\DRIVERS\nvsmu.sys
          C:\WINDOWS\system32\spoolsvv.exe

          Folder::
          C:\Program Files\Symantec
          C:\Documents and Settings\All Users\Application Data\Symantec

          Registry::
          [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
          [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvv]

          Driver::
          nvsmu

          Ouvre le Bloc-Notes puis colle le texte copié.
          (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
          Sauvegarde ce fichier sous le nom de CFScript.txt.

          Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

          http://serveur1.archive-host.com/membres/up/1366464061/CFScript.gif

          Cela va relancer Combofix,

          Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

          Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

          Ne touche à rien tant que le scan n'est pas terminé.

          Après redémarrage, poste le contenu du rapport Combofix.txt2

          puis :

          Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
          http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
          Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
          • Redémarre ton ordinateur
          • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
          • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
          • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
          • Choisis ton compte.
          Déroule la liste des instructions ci-dessous :
          • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
          • Appuie sur Y pour commencer le processus de nettoyage.
          • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
          • Appuie sur une touche pour redémarrer le PC.
          • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
          • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
          • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
          • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
          • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

          donc post les deux rapport stp

          ps : j´ai vu que tu as pas mal de logiciels de music, tu donnes dans quel style?

          @+
          0
          1. voici le rapport combofix

            ComboFix 08-02.05.3 - nadgy 2008-02-07 11:15:59.2 - NTFSx86
            Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.612 [GMT 1:00]
            Endroit: C:\Documents and Settings\nadgy\Bureau\ComboFix.exe
            Command switches used :: C:\Documents and Settings\nadgy\Mes documents\CFScript.txt
            * Création d'un nouveau point de restauration

            [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

            FILE
            File::C:\WINDOWS\mrofinu2000351.exeC:\WINDOWS\system32\DRIVERS\nvsmu.sysC:\WINDOWS\system32\spoolsvv.exe Folder::C:\Program Files\SymantecC:\Documents and Settings\All Users\Application Data\Symantec Registry::[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1][-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvv] Driver::nvsmu
            .

            ((((((((((((((((((((((((((((( Fichiers créés 2008-01-07 to 2008-02-07 ))))))))))))))))))))))))))))))))))))
            .

            2008-02-07 11:15 . 2008-02-07 11:17 53,248 --a------ C:\WINDOWS\PSEXESVC.EXE
            2008-02-06 15:39 . 2008-02-06 15:39 <REP> d-------- C:\Program Files\Trend Micro
            2008-02-06 14:57 . 2008-02-06 14:57 <REP> d-------- C:\Program Files\Panda Security
            2008-02-05 11:58 . 2008-02-05 11:49 691,545 --a------ C:\WINDOWS\unins000.exe
            2008-02-05 11:58 . 2008-02-05 11:58 3,447 --a------ C:\WINDOWS\unins000.dat
            2008-02-04 15:24 . 2008-02-04 15:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
            2008-02-04 15:22 . 2008-02-04 15:22 <REP> d-------- C:\Program Files\Sony
            2008-02-04 15:22 . 2008-02-04 15:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sony
            2008-02-04 15:20 . 2008-02-04 15:20 <REP> d-------- C:\Program Files\MSBuild
            2008-02-04 15:17 . 2008-02-04 15:17 <REP> d-------- C:\WINDOWS\system32\XPSViewer
            2008-02-04 15:16 . 2008-02-04 15:16 <REP> d-------- C:\Program Files\Reference Assemblies
            2008-02-04 15:16 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
            2008-02-04 15:12 . 2008-02-04 15:12 <REP> d-------- C:\Program Files\Sony Setup
            2008-02-04 15:12 . 2008-02-04 15:12 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Sony Setup
            2008-02-03 00:55 . 2008-02-04 15:22 <REP> d-------- C:\Program Files\VSTplugins
            2008-02-03 00:55 . 2008-02-03 00:55 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Publish Providers
            2008-02-03 00:54 . 2008-02-04 15:24 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Sony
            2008-02-02 20:16 . 2008-02-02 20:16 <REP> dr-h----- C:\Documents and Settings\nadgy\Application Data\SecuROM
            2008-02-02 20:16 . 2008-02-02 20:16 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
            2008-02-02 20:06 . 2008-02-02 20:06 36,864 --a------ C:\WINDOWS\mrofinu2000351.exe.tmp
            2008-02-02 01:17 . 2008-02-02 01:17 <REP> d-------- C:\Program Files\SystemRequirementsLab
            2008-02-02 01:17 . 2008-02-02 01:17 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\SystemRequirementsLab
            2008-02-02 01:14 . 2008-02-06 22:49 51,048 --a------ C:\WINDOWS\system32\nvapps.xml
            2008-02-02 01:14 . 2006-08-18 09:00 17,056 --a------ C:\WINDOWS\system32\nvdisp.nvu
            2008-02-02 01:11 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
            2008-02-02 01:10 . 2008-02-02 01:10 <REP> d-------- C:\NVIDIA
            2008-01-27 18:50 . 2008-02-06 15:58 <REP> d-------- C:\VundoFix Backups
            2008-01-26 17:36 . 2008-01-26 17:36 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\dvdcss
            2008-01-26 14:00 . 2008-02-02 23:02 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
            2008-01-26 13:52 . 2008-01-26 14:12 <REP> d-------- C:\Program Files\VirtualDJ
            2008-01-26 13:42 . 2008-01-26 13:45 <REP> d-------- C:\Program Files\Windows Live
            2008-01-25 15:28 . 2008-01-25 15:29 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\MMTVConfig
            2008-01-25 15:27 . 2008-01-25 15:27 <REP> d-------- C:\Program Files\MMTVConfig
            2008-01-24 21:48 . 2008-01-25 12:38 <REP> d-------- C:\Program Files\MeuhMeuhTV
            2008-01-24 20:53 . 2008-01-24 20:53 <REP> d-------- C:\Program Files\DivX
            2008-01-23 10:52 . 2008-01-23 10:52 <REP> d-------- C:\Program Files\DIFX
            2008-01-23 10:50 . 2007-01-12 14:57 110,592 --a------ C:\WINDOWS\system32\SynTPCo4.dll
            2008-01-23 10:46 . 2008-01-23 10:46 <REP> d-------- C:\Program Files\Broadcom
            2008-01-23 10:38 . 2008-01-23 10:38 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\InstallShield
            2008-01-21 14:17 . 2008-01-21 14:17 58 --a------ C:\WINDOWS\yesmessenger.ini
            2008-01-19 23:54 . 2008-01-19 23:54 583 --a------ C:\WINDOWS\eReg.dat
            2008-01-16 19:58 . 2008-01-16 19:58 <REP> d-------- C:\Program Files\Flagship Studios
            2008-01-16 19:58 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
            2008-01-16 19:58 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
            2008-01-16 19:58 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
            2008-01-16 15:40 . 2008-01-16 15:40 528 -r-hs---- C:\WINDOWS\egirllic151
            2008-01-16 15:38 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
            2008-01-16 15:38 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
            2008-01-15 12:20 . 2008-02-06 14:21 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\OpenOffice.org2
            2008-01-15 10:59 . 2008-01-15 10:59 <REP> d-------- C:\Program Files\OpenOffice.org 2.3
            2008-01-15 10:58 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
            2008-01-12 17:56 . 2008-01-12 17:55 57,856 --a------ C:\WINDOWS\taskmon.exe
            2008-01-12 12:00 . 2008-01-12 12:00 <REP> d-------- C:\myinst
            2008-01-12 11:59 . 2008-01-12 11:59 720,896 --a------ C:\WINDOWS\iun6002.exe
            2008-01-12 09:59 . 2008-01-12 09:59 368,640 --a------ C:\WINDOWS\system32\ReWire.dll
            2008-01-12 09:59 . 2008-01-12 09:59 233,472 --a------ C:\WINDOWS\system32\REX Shared Library.dll
            2008-01-12 09:56 . 2008-01-12 10:27 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Propellerhead Software
            2008-01-12 09:56 . 2008-01-12 09:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Propellerhead Software
            2008-01-12 09:55 . 2008-01-12 09:55 <REP> d-------- C:\Program Files\Propellerhead
            2008-01-11 23:41 . 2008-01-11 23:41 <REP> d-------- C:\WINDOWS\Downloaded Installations
            2008-01-11 12:40 . 2008-01-11 12:40 <REP> d-------- C:\Program Files\KONAMI
            2008-01-09 22:38 . 2008-02-02 22:23 <REP> d-------- C:\Program Files\eMule
            2008-01-09 21:54 . 2008-01-09 21:54 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\HP
            2008-01-09 12:14 . 2006-10-04 15:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
            2008-01-09 12:14 . 2006-10-04 15:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
            2008-01-09 12:14 . 2006-10-04 15:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
            2008-01-09 12:13 . 2008-02-06 16:05 <REP> d-------- C:\WINDOWS\system32\LogFiles
            2008-01-09 12:13 . 2008-01-09 12:13 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
            2008-01-09 11:06 . 2008-01-30 16:42 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\AdobeUM
            2008-01-09 11:00 . 2008-01-09 11:00 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Steinberg
            2008-01-09 10:45 . 2005-05-09 20:08 33,792 --a------ C:\WINDOWS\system32\drivers\cledx.sys
            2008-01-09 10:38 . 2008-01-09 10:38 <REP> d-------- C:\Program Files\Steinberg
            2008-01-09 10:35 . 2003-07-31 20:28 147,425 --a------ C:\WINDOWS\system32\SYNSOACC-Aide.chm
            2008-01-09 10:35 . 2003-05-26 15:29 120,468 --a------ C:\WINDOWS\system32\SYNSOACC-Hilfe.chm
            2008-01-09 10:35 . 2003-05-26 15:29 114,279 --a------ C:\WINDOWS\system32\SYNSOACC-Help.chm
            2008-01-09 10:33 . 2008-01-09 10:43 <REP> d-------- C:\Program Files\Syncrosoft
            2008-01-09 10:33 . 2005-10-17 09:35 704,512 --a------ C:\WINDOWS\system32\SYNSOACC.dll
            2008-01-09 10:33 . 2004-05-10 15:58 147,456 --a------ C:\WINDOWS\system32\SynsoLChk.dll
            2008-01-09 10:33 . 2002-11-25 08:36 45,056 --a------ C:\WINDOWS\system32\Synsopos.exe
            2008-01-09 10:33 . 2002-11-25 05:46 16,896 --a------ C:\WINDOWS\system32\drivers\SynasUSB.sys
            2008-01-09 10:27 . 2008-01-09 10:27 <REP> d-------- C:\Program Files\Alcohol Soft
            2008-01-08 18:30 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
            2008-01-08 18:30 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\dllcache\mouhid.sys
            2008-01-08 17:03 . 2008-01-08 17:03 <REP> d-------- C:\Program Files\Codemasters
            2008-01-07 18:47 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\drivers\MPE.sys
            2008-01-07 18:47 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\dllcache\mpe.sys
            2008-01-07 18:46 . 2008-01-07 18:46 <REP> d-------- C:\Program Files\MSXML 4.0
            2008-01-07 18:46 . 2007-06-14 14:41 466,048 --a------ C:\WINDOWS\system32\drivers\Ltn_stk7070P.sys
            2008-01-07 18:46 . 2004-08-04 00:55 18,432 --a------ C:\WINDOWS\system32\dllcache\bdaplgin.ax
            2008-01-07 18:46 . 2004-08-04 00:55 18,432 --a------ C:\WINDOWS\system32\BdaPlgIn.ax
            2008-01-07 18:46 . 2007-02-02 18:30 13,696 --a------ C:\WINDOWS\system32\drivers\PctvVirtualNdis.sys
            2008-01-07 18:46 . 2007-06-13 19:30 13,440 --a------ C:\WINDOWS\system32\drivers\Ltn_stkrc.sys
            2008-01-07 18:46 . 2004-08-03 23:10 11,776 --a------ C:\WINDOWS\system32\drivers\BdaSup.sys
            2008-01-07 18:46 . 2004-08-03 23:10 11,776 --a------ C:\WINDOWS\system32\dllcache\bdasup.sys
            2008-01-07 18:45 . 2006-12-01 23:54 626,688 --------- C:\WINDOWS\system32\msvcr80.dll
            2008-01-07 18:45 . 2006-12-01 23:54 548,864 --------- C:\WINDOWS\system32\msvcp80.dll
            2008-01-07 18:45 . 2004-07-23 09:00 446,464 --------- C:\WINDOWS\system32\HHActiveX.dll
            2008-01-07 18:42 . 2008-01-24 20:51 <REP> d-------- C:\Program Files\Pinnacle
            2008-01-07 18:40 . 2008-01-24 20:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
            2008-01-07 17:28 . 2008-01-07 17:28 <REP> d-------- C:\Program Files\Hercules

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2008-02-05 11:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
            2008-02-05 11:06 --------- d-----w C:\Program Files\Spybot - Search & Destroy
            2008-01-23 09:46 822,272 ----a-w C:\WINDOWS\system32\drivers\BCMWL5.SYS
            2008-01-19 22:54 11,376 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
            2008-01-19 22:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
            2008-01-15 13:27 --------- d-----w C:\Program Files\Fichiers communs\LightScribe
            2008-01-15 09:58 --------- d-----w C:\Program Files\Java
            2008-01-09 11:14 --------- d-----w C:\Program Files\Windows Media Connect 2
            2008-01-07 11:29 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
            2008-01-07 11:08 --------- d-----w C:\Program Files\Hewlett-Packard
            2008-01-07 10:49 --------- d-----w C:\Program Files\Wanadoo
            2008-01-06 18:51 --------- d-----w C:\Program Files\Windows Plus
            2008-01-06 18:50 --------- d-----w C:\Program Files\Synaptics
            2008-01-06 18:49 --------- d-----w C:\Program Files\NetWaiting
            2008-01-06 18:49 --------- d-----w C:\Program Files\microsoft frontpage
            2008-01-06 18:48 --------- d-----w C:\Program Files\HP
            2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
            2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
            2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\Java
            2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\Adobe
            2008-01-06 18:47 --------- d-----w C:\Program Files\CONEXANT
            2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
            2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBSI
            2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
            2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
            2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
            2008-01-06 12:10 --------- d-----w C:\Documents and Settings\nadgy\Application Data\Talkback
            2008-01-06 10:30 --------- d-----w C:\Program Files\Symantec
            2008-01-06 10:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
            2008-01-06 10:27 --------- d-----w C:\Program Files\Alwil Software
            2008-01-06 10:22 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
            2008-01-06 10:10 1,658 --sha-r C:\WINDOWS\system32\drivers\103C_HP_NTBK_HP PAVILION DV6000 (RP980EA#ABF)_YN_0Pavi_QCNF6472Z0M_E432250052_46_I30B8_SQuanta_V65.29_BF.3B_T071002_WXP2_L40C_M1023_J80_7AMD_8Turion 64 Technology MK-36_92.01_#060920_N14E44311_(RP980EA#ABF)_XMOBILE.MRK
            2008-01-06 10:05 --------- d-----w C:\Program Files\HPQ
            2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
            2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
            2007-11-14 07:28 450,560 ------w C:\WINDOWS\system32\dllcache\jscript.dll
            2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
            2007-11-07 09:28 728,576 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
            .

            ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            REGEDIT4
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "UberIcon"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe" [2006-05-21 08:43 180224]
            "RocketDock"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-18 23:05 630784]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 14:36 827392]
            "RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 09:23 1187840]
            "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
            "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-18 09:00 7585792]

            C:\Documents and Settings\nadgy\Menu D‚marrer\Programmes\D‚marrage\
            RocketDock.lnk.disabled [2008-01-07 12:29:08 842]
            UberIcon.lnk.disabled [2008-01-07 12:29:11 862]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
            "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
            "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide de HP Photosmart Premier.lnk.disabled]
            path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide de HP Photosmart Premier.lnk.disabled
            backup=C:\WINDOWS\pss\Démarrage rapide de HP Photosmart Premier.lnk.disabledCommon Startup

            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Gamesurround Muse Pocket.lnk.disabled]
            path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Gamesurround Muse Pocket.lnk.disabled
            backup=C:\WINDOWS\pss\Gamesurround Muse Pocket.lnk.disabledCommon Startup

            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Pavilion Webcam Tray Icon.lnk]
            path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Pavilion Webcam Tray Icon.lnk
            backup=C:\WINDOWS\pss\HP Pavilion Webcam Tray Icon.lnkCommon Startup

            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
            path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
            backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

            [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^LoopBe1 Monitor.lnk]
            path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\LoopBe1 Monitor.lnk
            backup=C:\WINDOWS\pss\LoopBe1 Monitor.lnkCommon Startup

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
            --a------ 2007-07-02 11:29 220544 C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
            --a------ 2006-03-25 05:00 15360 C:\WINDOWS\system32\ctfmon.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
            --a------ 2005-08-05 20:34 64512 C:\WINDOWS\ehome\ehtray.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
            --a------ 2006-06-02 01:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
            --a------ 2005-02-16 22:11 49152 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
            --a------ 2006-05-03 21:58 458752 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
            C:\WINDOWS\system32\dumprep 0 -k

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
            --a------ 2004-08-04 08:07 1667584 C:\Program Files\Messenger\msmsgs.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
            --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\MsnMsgr.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
            --a------ 2006-08-18 09:00 7585792 C:\WINDOWS\system32\NvCpl.dll

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
            --a------ 2006-08-18 09:00 86016 C:\WINDOWS\system32\NvMcTray.dll

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
            --a------ 2006-08-18 09:00 1617920 C:\WINDOWS\system32\nwiz.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
            C:\WINDOWS\system32\PSDrvCheck.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCRemote]
            C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCS]
            C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
            --a------ 2006-06-19 10:33 163840 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
            C:\WINDOWS\mrofinu2000351.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvv]
            C:\WINDOWS\system32\spoolsvv.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
            -rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
            --a------ 2005-11-10 20:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
            --------- 2006-11-03 09:59 204288 C:\Program Files\Windows Media Player\WMPNSCFG.exe

            [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
            "LightScribeService"=2 (0x2)
            "IDriverT"=3 (0x3)
            "Nero BackItUp Scheduler 3"=2 (0x2)
            "McrdSvc"=2 (0x2)
            "hpqwmiex"=2 (0x2)
            "WMPNetworkSvc"=2 (0x2)

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
            "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
            "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
            "PMCLoader"=C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks
            "PMCRemote"=C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
            "AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
            "Cpqset"=C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
            "NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            "nwiz"=nwiz.exe /installquiet /nodetect
            "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
            "NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
            "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
            "H2O"=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
            "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe"
            "Pinnacle WebUpdater"="C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles

            R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
            R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-06 00:49]
            R3 PctvVirtualNdis;Pinnacle Virtual Miniport;C:\WINDOWS\system32\DRIVERS\PctvVirtualNdis.sys [2007-02-02 18:30]
            R3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
            S3 Ltn_stk7070P;PCTV based TV tuner device;C:\WINDOWS\system32\DRIVERS\Ltn_stk7070P.sys [2007-06-14 14:41]
            S3 Ltn_stkrc;PCTV Infrared Receiver;C:\WINDOWS\system32\DRIVERS\Ltn_stkrc.sys [2007-06-13 19:30]
            S3 MPUSens;MPUSens;C:\WINDOWS\system32\drivers\MPUSens.sys [2004-04-26 09:49]
            S3 USB28xxBGA;PCTV 100e/150e Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2005-11-22 19:04]
            S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2005-11-22 19:04]

            .
            Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
            "2008-02-02 19:27:06 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
            - C:\Program Files\TuneUp Utilities 2008\OneClick.exe
            .
            **************************************************************************

            catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2008-02-07 11:17:49
            Windows 5.1.2600 Service Pack 2 NTFS

            Balayage processus cachés ...

            Balayage caché autostart entries ...

            Balayage des fichiers cachés ...

            Scan terminé avec succès
            Les fichiers cachés: 0

            **************************************************************************
            .
            --------------------- DLLs a chargé sous des processus courants ---------------------

            PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2180]
            -> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
            -> C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon.dll
            .
            Temps d'accomplissement: 2008-02-07 11:18:18
            ComboFix-quarantined-files.txt 2008-02-07 10:18:09
            ComboFix2.txt 2008-02-06 17:09:20
            .
            2008-01-10 09:59:12 --- E O F ---

            voici le raport sdfix

            SDFix: Version 1.137

            Run by Administrateur on 07/02/2008 at 11:27

            Microsoft Windows XP [version 5.1.2600]

            Running From: C:\SDFix

            Safe Mode:
            Checking Services:

            Restoring Windows Registry Values
            Restoring Windows Default Hosts File

            Rebooting...

            Normal Mode:
            Checking Files:

            Trojan Files Found:

            C:\WINDOWS\mrofinu2000351.exe.tmp - Deleted
            C:\WINDOWS\taskmon.exe - Deleted

            Removing Temp Files...

            ADS Check:

            Final Check:

            catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2008-02-07 11:30:46
            Windows 5.1.2600 Service Pack 2 NTFS

            scanning hidden processes ...

            scanning hidden services & system hive ...

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
            "s1"=dword:2df9c43f
            "s2"=dword:110480d0
            "h0"=dword:00000001

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
            "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
            "h0"=dword:00000000
            "ujdew"=hex:f5,2b,2c,63,d4,ca,e9,17,68,4a,28,23,23,7c,3d,9b,60,02,d8,a9,8f,..
            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
            "p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
            "h0"=dword:00000000
            "ujdew"=hex:f5,2b,2c,63,d4,ca,e9,17,68,4a,28,23,23,7c,3d,9b,60,02,d8,a9,8f,..

            scanning hidden registry entries ...

            scanning hidden files ...

            scan completed successfully
            hidden processes: 0
            hidden services: 0
            hidden files: 10

            Remaining Services:
            ------------------

            Authorized Application Key Export:

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

            Remaining Files:
            ---------------

            File Backups: - C:\SDFix\backups\backups.zip

            Files with Hidden Attributes:

            Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
            Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
            Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
            Wed 9 Jan 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

            Finished!

            en fait je debute dasn le sound design je fai pas vraiment de musique a proprement parler en fait pour tout dire pour l'instant j'essai juste de maitriser un pu plus tous ces prog

            re ps: est ce que tu pourrais m'expliquer les manip que je viens de faire et qu'est ce qui c passer je suis assez curieux de savoir comment ca marche c trojan a la con et comment on a fait pour le virer
            0
            1. Contributeur
              salut nadgy,

              c´est cool ca que tu t´interresse au sound disign, je fais moi meme de la musique sur pc, j´utilise acid pro6 de sony, je vais bientot me prendre reason comme toi ;-)

              pour l´infection tu n´as malheureusement pas bien effectué la derniere manip

              je t´avais demandé de copier le script post 3 pour l´inserer dans combofix, tu l´as fais mais pas comme il aurait falue ;-(

              il va faloir recommencer.

              en faite tu copie la sitation :

              File::
              C:\WINDOWS\mrofinu2000351.exe
              C:\WINDOWS\system32\DRIVERS\nvsmu.sys
              C:\WINDOWS\system32\spoolsvv.exe

              Folder::
              C:\Program Files\Symantec
              C:\Documents and Settings\All Users\Application Data\Symantec

              Registry::
              [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
              [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvv]

              Driver::
              nvsmu

              exactement comme elle est ici. dans le bloc note elle doit etre sous la meme forme, ce qui c´est passé quand tu l´as copié, tu as mis tout a la suite, il faut que le lignes soient les unes en dessous des autres, exactement comme ci dessus

              en faite la on retire les entrées nefastes du registre et on supprime les fichiers infectés.

              refais le

              Copie le texte ci-dessous :

              File::
              C:\WINDOWS\mrofinu2000351.exe
              C:\WINDOWS\system32\DRIVERS\nvsmu.sys
              C:\WINDOWS\system32\spoolsvv.exe

              Folder::
              C:\Program Files\Symantec
              C:\Documents and Settings\All Users\Application Data\Symantec

              Registry::
              [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\runner1]
              [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spoolsvv]

              Driver::
              nvsmu

              Ouvre le Bloc-Notes puis colle le texte copié.
              (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
              Sauvegarde ce fichier sous le nom de CFScript.txt.

              Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

              http://serveur1.archive-host.com/membres/up/1366464061/CFScript.gif

              Cela va relancer Combofix,

              Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

              Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

              Ne touche à rien tant que le scan n'est pas terminé.

              Après redémarrage, poste le contenu du rapport Combofix.txt3

              @+
              0
              1. alors j'ai reassayer mais ca marche pas combofix se lance tjrs de la meme maniere je comprends pas pourquoi.
                je continue a faire des essais.
                0
                1. Contributeur
                  re,

                  si tu n´y arrive pas on peux le faire autrement.

                  tu veux?
                  0
                  1. ben oui mais je comprend pas pourquoi combofix ne demarre pas comme voulu
                    0
                    1. premier log

                      File/Folder C:\WINDOWS\mrofinu2000351.exe not found.
                      File/Folder C:\WINDOWS\system32\DRIVERS\nvsmu.sys not found.
                      File/Folder C:\WINDOWS\system32\spoolsvv.exe not found.

                      OTMoveIt2 v1.0.18 log created on 02072008_130700

                      deuxieme 1ERE partie

                      Deckard's System Scanner v20071014.68
                      Run by nadgy on 2008-02-07 13:11:33
                      Computer is in Normal Mode.
                      --------------------------------------------------------------------------------

                      -- System Restore --------------------------------------------------------------

                      Successfully created a Deckard's System Scanner Restore Point.

                      -- Last 5 Restore Point(s) --
                      9: 2008-02-07 12:11:36 UTC - RP9 - Deckard's System Scanner Restore Point
                      8: 2008-02-07 11:52:55 UTC - RP8 - ComboFix created restore point
                      7: 2008-02-07 11:13:44 UTC - RP7 - ComboFix created restore point
                      6: 2008-02-07 11:05:29 UTC - RP6 - ComboFix created restore point
                      5: 2008-02-07 11:02:09 UTC - RP5 - ComboFix created restore point

                      -- First Restore Point --
                      1: 2008-02-06 17:03:54 UTC - RP1 - Point de vérification système

                      Backed up registry hives.
                      Performed disk cleanup.

                      -- HijackThis (run as nadgy.exe) -----------------------------------------------

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 13:12, on 2008-02-07
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                      C:\Program Files\Windows NT\Accessoires\WORDPAD.EXE
                      C:\WINDOWS\system32\NOTEPAD.EXE
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Documents and Settings\nadgy\Bureau\dss.exe
                      C:\PROGRA~1\TRENDM~1\HIJACK~1\nadgy.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKCU\..\Run: [UberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"
                      O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
                      O4 - Startup: RocketDock.lnk.disabled
                      O4 - Startup: UberIcon.lnk.disabled
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O14 - IERESET.INF: START_PAGE_URL=https://www.msn.com/fr-fr?cobrand=hp-notebook.msn.com&ocid=HPDHP&pc=HPNTDF
                      O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      0
                      1. Contributeur
                        re,

                        j´ai oublié un detail qui a son importance...

                        fais ceci :

                        demarrer > executer > dans la boite de dialogue tape ceci : combofix /u et valide par ok ( respect l´espace ); cela aura pour effet de supprimer combofix

                        puis retelecharge le ici et post son rapport stp

                        Télécharge combofix.exe (par sUBs) sur ton Bureau.

                        -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                        -> Double clique combofix.exe.
                        -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                        -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                        NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                        @+
                        0
                        1. voici le log ce que je trouve bizarre c que le scan se lance tout seul il me demande pas de taper 1 enfin bon

                          ComboFix 08-02.05.3 - nadgy 2008-02-07 14:03:36.5 - NTFSx86
                          Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.633 [GMT 1:00]
                          Endroit: C:\Documents and Settings\nadgy\Bureau\ComboFix.exe

                          [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                          .

                          ((((((((((((((((((((((((((((( Fichiers créés 2008-01-07 to 2008-02-07 ))))))))))))))))))))))))))))))))))))
                          .

                          2008-02-07 12:46 . 2008-02-07 12:46 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\OpenOffice.org2
                          2008-02-07 12:01 . 2006-03-25 05:00 428,032 --a------ C:\kmd.exe
                          2008-02-07 11:27 . 2006-03-25 05:00 578,048 --a------ C:\WINDOWS\system32\dllcache\user32.dll
                          2008-02-07 11:26 . 2008-02-07 11:26 <REP> d-------- C:\WINDOWS\ERUNT
                          2008-02-06 15:39 . 2008-02-06 15:39 <REP> d-------- C:\Program Files\Trend Micro
                          2008-02-06 14:57 . 2008-02-06 14:57 <REP> d-------- C:\Program Files\Panda Security
                          2008-02-05 11:58 . 2008-02-05 11:49 691,545 --a------ C:\WINDOWS\unins000.exe
                          2008-02-05 11:58 . 2008-02-05 11:58 3,447 --a------ C:\WINDOWS\unins000.dat
                          2008-02-04 15:24 . 2008-02-04 15:24 <REP> d-------- C:\Documents and Settings\All Users\Application Data\TEMP
                          2008-02-04 15:22 . 2008-02-04 15:22 <REP> d-------- C:\Program Files\Sony
                          2008-02-04 15:22 . 2008-02-04 15:22 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sony
                          2008-02-04 15:20 . 2008-02-04 15:20 <REP> d-------- C:\Program Files\MSBuild
                          2008-02-04 15:17 . 2008-02-04 15:17 <REP> d-------- C:\WINDOWS\system32\XPSViewer
                          2008-02-04 15:16 . 2008-02-04 15:16 <REP> d-------- C:\Program Files\Reference Assemblies
                          2008-02-04 15:16 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
                          2008-02-04 15:12 . 2008-02-04 15:12 <REP> d-------- C:\Program Files\Sony Setup
                          2008-02-04 15:12 . 2008-02-04 15:12 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Sony Setup
                          2008-02-03 00:55 . 2008-02-04 15:22 <REP> d-------- C:\Program Files\VSTplugins
                          2008-02-03 00:55 . 2008-02-03 00:55 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Publish Providers
                          2008-02-03 00:54 . 2008-02-04 15:24 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Sony
                          2008-02-02 20:16 . 2008-02-02 20:16 <REP> dr-h----- C:\Documents and Settings\nadgy\Application Data\SecuROM
                          2008-02-02 20:16 . 2008-02-02 20:16 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
                          2008-02-02 01:17 . 2008-02-02 01:17 <REP> d-------- C:\Program Files\SystemRequirementsLab
                          2008-02-02 01:17 . 2008-02-02 01:17 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\SystemRequirementsLab
                          2008-02-02 01:14 . 2008-02-07 13:08 51,048 --a------ C:\WINDOWS\system32\nvapps.xml
                          2008-02-02 01:14 . 2006-08-18 09:00 17,056 --a------ C:\WINDOWS\system32\nvdisp.nvu
                          2008-02-02 01:11 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE
                          2008-02-02 01:10 . 2008-02-02 01:10 <REP> d-------- C:\NVIDIA
                          2008-01-26 17:36 . 2008-01-26 17:36 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\dvdcss
                          2008-01-26 14:00 . 2008-02-02 23:02 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
                          2008-01-26 13:52 . 2008-01-26 14:12 <REP> d-------- C:\Program Files\VirtualDJ
                          2008-01-26 13:42 . 2008-01-26 13:45 <REP> d-------- C:\Program Files\Windows Live
                          2008-01-25 15:28 . 2008-01-25 15:29 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\MMTVConfig
                          2008-01-25 15:27 . 2008-01-25 15:27 <REP> d-------- C:\Program Files\MMTVConfig
                          2008-01-24 21:48 . 2008-01-25 12:38 <REP> d-------- C:\Program Files\MeuhMeuhTV
                          2008-01-24 20:53 . 2008-01-24 20:53 <REP> d-------- C:\Program Files\DivX
                          2008-01-23 10:52 . 2008-01-23 10:52 <REP> d-------- C:\Program Files\DIFX
                          2008-01-23 10:50 . 2007-01-12 14:57 110,592 --a------ C:\WINDOWS\system32\SynTPCo4.dll
                          2008-01-23 10:46 . 2008-01-23 10:46 <REP> d-------- C:\Program Files\Broadcom
                          2008-01-23 10:38 . 2008-01-23 10:38 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\InstallShield
                          2008-01-21 14:17 . 2008-01-21 14:17 58 --a------ C:\WINDOWS\yesmessenger.ini
                          2008-01-19 23:54 . 2008-01-19 23:54 583 --a------ C:\WINDOWS\eReg.dat
                          2008-01-16 19:58 . 2008-01-16 19:58 <REP> d-------- C:\Program Files\Flagship Studios
                          2008-01-16 19:58 . 2007-05-16 16:45 3,497,832 --a------ C:\WINDOWS\system32\d3dx9_34.dll
                          2008-01-16 19:58 . 2007-05-16 16:45 1,124,720 --a------ C:\WINDOWS\system32\D3DCompiler_34.dll
                          2008-01-16 19:58 . 2007-05-16 16:45 443,752 --a------ C:\WINDOWS\system32\d3dx10_34.dll
                          2008-01-16 15:40 . 2008-01-16 15:40 528 -r-hs---- C:\WINDOWS\egirllic151
                          2008-01-16 15:38 . 2007-03-12 16:42 3,495,784 --a------ C:\WINDOWS\system32\d3dx9_33.dll
                          2008-01-16 15:38 . 2007-04-04 18:53 81,768 --a------ C:\WINDOWS\system32\xinput1_3.dll
                          2008-01-15 12:20 . 2008-02-07 12:55 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\OpenOffice.org2
                          2008-01-15 10:59 . 2008-01-15 10:59 <REP> d-------- C:\Program Files\OpenOffice.org 2.3
                          2008-01-15 10:58 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
                          2008-01-12 12:00 . 2008-01-12 12:00 <REP> d-------- C:\myinst
                          2008-01-12 11:59 . 2008-01-12 11:59 720,896 --a------ C:\WINDOWS\iun6002.exe
                          2008-01-12 09:59 . 2008-01-12 09:59 368,640 --a------ C:\WINDOWS\system32\ReWire.dll
                          2008-01-12 09:59 . 2008-01-12 09:59 233,472 --a------ C:\WINDOWS\system32\REX Shared Library.dll
                          2008-01-12 09:56 . 2008-01-12 10:27 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Propellerhead Software
                          2008-01-12 09:56 . 2008-01-12 09:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Propellerhead Software
                          2008-01-12 09:55 . 2008-01-12 09:55 <REP> d-------- C:\Program Files\Propellerhead
                          2008-01-11 23:41 . 2008-01-11 23:41 <REP> d-------- C:\WINDOWS\Downloaded Installations
                          2008-01-11 12:40 . 2008-01-11 12:40 <REP> d-------- C:\Program Files\KONAMI
                          2008-01-09 22:38 . 2008-02-02 22:23 <REP> d-------- C:\Program Files\eMule
                          2008-01-09 21:54 . 2008-01-09 21:54 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\HP
                          2008-01-09 12:14 . 2006-10-04 15:06 1,197,294 --------- C:\WINDOWS\system32\dllcache\sysmain.sdb
                          2008-01-09 12:14 . 2006-10-04 15:06 764,868 --------- C:\WINDOWS\system32\dllcache\apph_sp.sdb
                          2008-01-09 12:14 . 2006-10-04 15:06 217,118 --------- C:\WINDOWS\system32\dllcache\apphelp.sdb
                          2008-01-09 12:13 . 2008-02-06 16:05 <REP> d-------- C:\WINDOWS\system32\LogFiles
                          2008-01-09 12:13 . 2008-01-09 12:13 <REP> d-------- C:\WINDOWS\system32\drivers\UMDF
                          2008-01-09 11:06 . 2008-01-30 16:42 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\AdobeUM
                          2008-01-09 11:00 . 2008-01-09 11:00 <REP> d-------- C:\Documents and Settings\nadgy\Application Data\Steinberg
                          2008-01-09 10:45 . 2005-05-09 20:08 33,792 --a------ C:\WINDOWS\system32\drivers\cledx.sys
                          2008-01-09 10:38 . 2008-01-09 10:38 <REP> d-------- C:\Program Files\Steinberg
                          2008-01-09 10:35 . 2003-07-31 20:28 147,425 --a------ C:\WINDOWS\system32\SYNSOACC-Aide.chm
                          2008-01-09 10:35 . 2003-05-26 15:29 120,468 --a------ C:\WINDOWS\system32\SYNSOACC-Hilfe.chm
                          2008-01-09 10:35 . 2003-05-26 15:29 114,279 --a------ C:\WINDOWS\system32\SYNSOACC-Help.chm
                          2008-01-09 10:33 . 2008-01-09 10:43 <REP> d-------- C:\Program Files\Syncrosoft
                          2008-01-09 10:33 . 2005-10-17 09:35 704,512 --a------ C:\WINDOWS\system32\SYNSOACC.dll
                          2008-01-09 10:33 . 2004-05-10 15:58 147,456 --a------ C:\WINDOWS\system32\SynsoLChk.dll
                          2008-01-09 10:33 . 2002-11-25 08:36 45,056 --a------ C:\WINDOWS\system32\Synsopos.exe
                          2008-01-09 10:33 . 2002-11-25 05:46 16,896 --a------ C:\WINDOWS\system32\drivers\SynasUSB.sys
                          2008-01-09 10:27 . 2008-01-09 10:27 <REP> d-------- C:\Program Files\Alcohol Soft
                          2008-01-08 18:30 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
                          2008-01-08 18:30 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\dllcache\mouhid.sys
                          2008-01-08 17:03 . 2008-01-08 17:03 <REP> d-------- C:\Program Files\Codemasters
                          2008-01-07 18:47 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\drivers\MPE.sys
                          2008-01-07 18:47 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\dllcache\mpe.sys
                          2008-01-07 18:46 . 2008-01-07 18:46 <REP> d-------- C:\Program Files\MSXML 4.0
                          2008-01-07 18:46 . 2007-06-14 14:41 466,048 --a------ C:\WINDOWS\system32\drivers\Ltn_stk7070P.sys
                          2008-01-07 18:46 . 2004-08-04 00:55 18,432 --a------ C:\WINDOWS\system32\dllcache\bdaplgin.ax
                          2008-01-07 18:46 . 2004-08-04 00:55 18,432 --a------ C:\WINDOWS\system32\BdaPlgIn.ax
                          2008-01-07 18:46 . 2007-02-02 18:30 13,696 --a------ C:\WINDOWS\system32\drivers\PctvVirtualNdis.sys
                          2008-01-07 18:46 . 2007-06-13 19:30 13,440 --a------ C:\WINDOWS\system32\drivers\Ltn_stkrc.sys
                          2008-01-07 18:46 . 2004-08-03 23:10 11,776 --a------ C:\WINDOWS\system32\drivers\BdaSup.sys
                          2008-01-07 18:46 . 2004-08-03 23:10 11,776 --a------ C:\WINDOWS\system32\dllcache\bdasup.sys
                          2008-01-07 18:45 . 2006-12-01 23:54 626,688 --------- C:\WINDOWS\system32\msvcr80.dll
                          2008-01-07 18:45 . 2006-12-01 23:54 548,864 --------- C:\WINDOWS\system32\msvcp80.dll
                          2008-01-07 18:45 . 2004-07-23 09:00 446,464 --------- C:\WINDOWS\system32\HHActiveX.dll
                          2008-01-07 18:42 . 2008-01-24 20:51 <REP> d-------- C:\Program Files\Pinnacle
                          2008-01-07 18:40 . 2008-01-24 20:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
                          2008-01-07 17:28 . 2008-01-07 17:28 <REP> d-------- C:\Program Files\Hercules

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2008-02-05 11:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                          2008-02-05 11:06 --------- d-----w C:\Program Files\Spybot - Search & Destroy
                          2008-01-23 09:46 822,272 ----a-w C:\WINDOWS\system32\drivers\BCMWL5.SYS
                          2008-01-19 22:54 11,376 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
                          2008-01-19 22:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
                          2008-01-15 13:27 --------- d-----w C:\Program Files\Fichiers communs\LightScribe
                          2008-01-15 09:58 --------- d-----w C:\Program Files\Java
                          2008-01-09 11:14 --------- d-----w C:\Program Files\Windows Media Connect 2
                          2008-01-07 11:29 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
                          2008-01-07 11:08 --------- d-----w C:\Program Files\Hewlett-Packard
                          2008-01-07 10:49 --------- d-----w C:\Program Files\Wanadoo
                          2008-01-06 18:51 --------- d-----w C:\Program Files\Windows Plus
                          2008-01-06 18:50 --------- d-----w C:\Program Files\Synaptics
                          2008-01-06 18:49 --------- d-----w C:\Program Files\NetWaiting
                          2008-01-06 18:49 --------- d-----w C:\Program Files\microsoft frontpage
                          2008-01-06 18:48 --------- d-----w C:\Program Files\HP
                          2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\SpeechEngines
                          2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\MSSoap
                          2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\Java
                          2008-01-06 18:47 --------- d-----w C:\Program Files\Fichiers communs\Adobe
                          2008-01-06 18:47 --------- d-----w C:\Program Files\CONEXANT
                          2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
                          2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\SBSI
                          2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\InstallShield
                          2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
                          2008-01-06 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
                          2008-01-06 12:10 --------- d-----w C:\Documents and Settings\nadgy\Application Data\Talkback
                          2008-01-06 10:27 --------- d-----w C:\Program Files\Alwil Software
                          2008-01-06 10:22 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
                          2008-01-06 10:10 1,658 --sha-r C:\WINDOWS\system32\drivers\103C_HP_NTBK_HP PAVILION DV6000 (RP980EA#ABF)_YN_0Pavi_QCNF6472Z0M_E432250052_46_I30B8_SQuanta_V65.29_BF.3B_T071002_WXP2_L40C_M1023_J80_7AMD_8Turion 64 Technology MK-36_92.01_#060920_N14E44311_(RP980EA#ABF)_XMOBILE.MRK
                          2008-01-06 10:05 --------- d-----w C:\Program Files\HPQ
                          2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
                          2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
                          2007-11-14 07:28 450,560 ------w C:\WINDOWS\system32\dllcache\jscript.dll
                          2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
                          2007-11-07 09:28 728,576 ------w C:\WINDOWS\system32\dllcache\lsasrv.dll
                          .

                          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          REGEDIT4
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "UberIcon"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe" [2006-05-21 08:43 180224]
                          "RocketDock"="C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe" [2007-03-18 23:05 630784]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-01-12 14:36 827392]
                          "RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 09:23 1187840]
                          "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
                          "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-18 09:00 7585792]

                          C:\Documents and Settings\nadgy\Menu D‚marrer\Programmes\D‚marrage\
                          RocketDock.lnk.disabled [2008-01-07 12:29:08 842]
                          UberIcon.lnk.disabled [2008-01-07 12:29:11 862]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                          "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
                          "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

                          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Démarrage rapide de HP Photosmart Premier.lnk.disabled]
                          path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Démarrage rapide de HP Photosmart Premier.lnk.disabled
                          backup=C:\WINDOWS\pss\Démarrage rapide de HP Photosmart Premier.lnk.disabledCommon Startup

                          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Gamesurround Muse Pocket.lnk.disabled]
                          path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Gamesurround Muse Pocket.lnk.disabled
                          backup=C:\WINDOWS\pss\Gamesurround Muse Pocket.lnk.disabledCommon Startup

                          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^HP Pavilion Webcam Tray Icon.lnk]
                          path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\HP Pavilion Webcam Tray Icon.lnk
                          backup=C:\WINDOWS\pss\HP Pavilion Webcam Tray Icon.lnkCommon Startup

                          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
                          path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
                          backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

                          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^LoopBe1 Monitor.lnk]
                          path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\LoopBe1 Monitor.lnk
                          backup=C:\WINDOWS\pss\LoopBe1 Monitor.lnkCommon Startup

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
                          --a------ 2007-07-02 11:29 220544 C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
                          --a------ 2006-03-25 05:00 15360 C:\WINDOWS\system32\ctfmon.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray]
                          --a------ 2005-08-05 20:34 64512 C:\WINDOWS\ehome\ehtray.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\High Definition Audio Property Page Shortcut]
                          --a------ 2006-06-02 01:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
                          --a------ 2005-02-16 22:11 49152 C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpWirelessAssistant]
                          --a------ 2006-05-03 21:58 458752 C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
                          C:\WINDOWS\system32\dumprep 0 -k

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
                          --a------ 2004-08-04 08:07 1667584 C:\Program Files\Messenger\msmsgs.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
                          --a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\MsnMsgr.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
                          --a------ 2006-08-18 09:00 7585792 C:\WINDOWS\system32\NvCpl.dll

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
                          --a------ 2006-08-18 09:00 86016 C:\WINDOWS\system32\NvMcTray.dll

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
                          --a------ 2006-08-18 09:00 1617920 C:\WINDOWS\system32\nwiz.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PinnacleDriverCheck]
                          C:\WINDOWS\system32\PSDrvCheck.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCRemote]
                          C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PMCS]
                          C:\Program Files\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QlbCtrl]
                          --a------ 2006-06-19 10:33 163840 C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
                          -rahs---- 2008-01-28 11:43 2097488 C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
                          --a------ 2005-11-10 20:03 36975 C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
                          --------- 2006-11-03 09:59 204288 C:\Program Files\Windows Media Player\WMPNSCFG.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                          "LightScribeService"=2 (0x2)
                          "IDriverT"=3 (0x3)
                          "Nero BackItUp Scheduler 3"=2 (0x2)
                          "McrdSvc"=2 (0x2)
                          "hpqwmiex"=2 (0x2)
                          "WMPNetworkSvc"=2 (0x2)

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
                          "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe
                          "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe"
                          "PMCLoader"=C:\Program Files\Pinnacle\TVCenter Pro\PMCLoader.exe -checktasks
                          "PMCRemote"=C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
                          "AlcoholAutomount"="C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                          "Cpqset"=C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
                          "NvCplDaemon"=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          "nwiz"=nwiz.exe /installquiet /nodetect
                          "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                          "NeroFilterCheck"=C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                          "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
                          "H2O"=C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
                          "QPService"="C:\Program Files\HP\QuickPlay\QPService.exe"
                          "Pinnacle WebUpdater"="C:\Program Files\Pinnacle\Shared Files\Programs\WebUpdater\WebUpdater.exe" -s -f=UpdateVersion.xml -url=http://cdn.pinnaclesys.com/SupportFiles

                          R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 20:08]
                          R3 PctvVirtualNdis;Pinnacle Virtual Miniport;C:\WINDOWS\system32\DRIVERS\PctvVirtualNdis.sys [2007-02-02 18:30]
                          S3 Ltn_stk7070P;PCTV based TV tuner device;C:\WINDOWS\system32\DRIVERS\Ltn_stk7070P.sys [2007-06-14 14:41]
                          S3 Ltn_stkrc;PCTV Infrared Receiver;C:\WINDOWS\system32\DRIVERS\Ltn_stkrc.sys [2007-06-13 19:30]
                          S3 MPUSens;MPUSens;C:\WINDOWS\system32\drivers\MPUSens.sys [2004-04-26 09:49]
                          S3 USB28xxBGA;PCTV 100e/150e Device;C:\WINDOWS\system32\DRIVERS\emBDA.sys [2005-11-22 19:04]
                          S3 USB28xxOEM;USB 28xx OEM Filter;C:\WINDOWS\system32\DRIVERS\emOEM.sys [2005-11-22 19:04]
                          S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]

                          .
                          Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                          "2008-02-02 19:27:06 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
                          - C:\Program Files\TuneUp Utilities 2008\OneClick.exe
                          .
                          **************************************************************************

                          catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2008-02-07 14:05:11
                          Windows 5.1.2600 Service Pack 2 NTFS

                          Balayage processus cachés ...

                          Balayage caché autostart entries ...

                          Balayage des fichiers cachés ...

                          Scan terminé avec succès
                          Les fichiers cachés: 0

                          **************************************************************************
                          .
                          --------------------- DLLs a chargé sous des processus courants ---------------------

                          PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.2180]
                          -> C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.dll
                          .
                          Temps d'accomplissement: 2008-02-07 14:05:40
                          .
                          2008-01-10 09:59:12 --- E O F ---
                          0
                          1. Contributeur
                            re,

                            c´est un peu confu, mais les entrées que je voulais que tu supprime ainsi que les fichiers ne sont plus presents, tu as du reussir a le faire en fesant "tes essaies" lors de l´application du script dans combofix avant que je ne t´ecrive le script manuel (fix.reg)

                            peux tu reposter un hijack this pour repartir sur des base claires stp

                            supprime ceci avec ot_move it : C:\kmd.exe

                            * Double-clique sur OTMoveIt.exe pour lancer le programme,
                            * Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste Custom List of Files/Folders to Move" :

                            C:\kmd.exe

                            * Clique sur MoveIt! pour lancer la suppression,
                            * Le résultat appraraîtra dans le cadre Results.
                            * Clique sur Exit pour fermer le programme.
                            * Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
                            * Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.

                            post les deux rapports stp

                            @+
                            0
                            1. C:\kmd.exe moved successfully.

                              OTMoveIt2 v1.0.18 log created on 02072008_142543

                              voici le hjt

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 14:27, on 2008-02-07
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
                              C:\WINDOWS\system32\nvsvc32.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Windows Live\Messenger\usnsvc.exe
                              C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
                              C:\WINDOWS\explorer.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
                              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/...
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                              O4 - HKCU\..\Run: [UberIcon] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe"
                              O4 - HKCU\..\Run: [RocketDock] "C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe"
                              O4 - Startup: RocketDock.lnk.disabled
                              O4 - Startup: UberIcon.lnk.disabled
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/...
                              O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                              0
                              1. voila
                                enfait je voudrais savoir comment fonctionne ce trojan ca m'interresse je voudrais aussi savoir comment analiser le hjt si ca t'embete pas et si c pas trop long et compliquer a expliquer
                                0
                                1. Contributeur
                                  re,

                                  c´est beaucoups mieux qu´au debut ;-)

                                  maintenant fais ceci :

                                  telecharge et instales un par feu :

                                  par feu : kerio ne pas le mettre a jour

                                  http://www.malekal.com/kerio_firewall.php#mozTocId721480

                                  https://www.vulgarisation-informatique.com/kerio.php

                                  https://kerio.probb.fr/f2-sunbelt-kerio-personal-firewall

                                  ou zone alarm plus facil a configurer mais moins performant

                                  https://www.malekal.com/tutoriel-zonealarm-firewall/

                                  puis

                                  regarde ceci concernant avast :

                                  antivir vs avast :

                                  -> http://forum.malekal.com/ftopic3528.php

                                  alors je te conseille de le desinstaller et d´installer antivir a la place

                                  Telecharge et instal l'antivirus Antivir Personal Edition Classic :

                                  ->https://www.malekal.com/avira-free-security-antivirus-gratuit/

                                  https://www.avira.com/en/prime

                                  http://mickael.barroux.free.fr/securite/antivir.php
                                  http://speedweb1.free.fr/frames2.php?page=tuto5
                                  <- tutoriel configuration du scanner...

                                  une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
                                  puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
                                  coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
                                  puis sur la droite coche les case suivantes :
                                  scan boot sectors of selected drives
                                  scan master boot sectors
                                  scan memory
                                  search foe rootkit before scan
                                  decoche :
                                  ignore off line files
                                  toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

                                  je te dis ceci concernant avast et antivir car j´aimerais que tu fasse un scan complet de ta machine avec les regalges stipulés ci dessus
                                  a l´aide d´antivir et que tu post le rapport ici

                                  si toute fois tu voulais conserver avast pour quelques raisons?!

                                  fais ce scan en ligne et post son rapport ici

                                  Scan en ligne bitdefender :

                                  https://www.bitdefender.com/toolbox/

                                  Clicker sur " I agree " et suivre les indications

                                  A faire imperativement sous internet explorer, en acceptant l´activ x

                                  tutoriel en image en image

                                  http://pageperso.aol.fr/rginformatique/mapage/defender.htm

                                  @+
                                  0
                                  1. pourquoi tu veux me faire installer un parefeu j'ai deja celui de la livebox
                                    0
                                    1. Contributeur
                                      re,

                                      la live box n´as pas de par feu a proprement dis, c´est un proxy, pas pareil...
                                      0
                                      1. pourtant lors des test sur le lien que tu m'as donne tout est au vert
                                        et sur la page de configuration de la livebox j'ai bien un onglet parefeu ave controle d'acces politique nat
                                        j'au peur que si j'installe un pare feu il y ai des conflit

                                        voici le rapport de antivir

                                        AntiVir PersonalEdition Classic
                                        Report file date: 2008-02-07 15:26

                                        Scanning for 1095627 virus strains and unwanted programs.

                                        Licensed to: Avira AntiVir PersonalEdition Classic
                                        Serial number: 0000149996-ADJIE-0001
                                        Platform: Windows XP
                                        Windows version: (Service Pack 2) [5.1.2600]
                                        Username: SYSTEM
                                        Computer name: DEMOI

                                        Version information:
                                        BUILD.DAT : 270 15603 Bytes 2007-09-19 13:32:00
                                        AVSCAN.EXE : 7.0.6.1 290856 Bytes 2007-08-23 13:16:29
                                        AVSCAN.DLL : 7.0.6.0 49192 Bytes 2007-08-16 12:23:51
                                        LUKE.DLL : 7.0.5.3 147496 Bytes 2007-08-14 15:32:47
                                        LUKERES.DLL : 7.0.6.1 10280 Bytes 2007-08-21 12:35:20
                                        ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 14:27:15
                                        ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 2007-12-14 14:18:23
                                        ANTIVIR2.VDF : 7.0.2.49 1339904 Bytes 2008-01-25 14:18:23
                                        ANTIVIR3.VDF : 7.0.2.106 348160 Bytes 2008-02-07 14:18:23
                                        AVEWIN32.DLL : 7.6.0.62 3240448 Bytes 2008-02-07 14:18:24
                                        AVWINLL.DLL : 1.0.0.7 14376 Bytes 2007-02-26 10:36:26
                                        AVPREF.DLL : 7.0.2.2 25640 Bytes 2007-07-18 07:39:17
                                        AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 13:16:24
                                        AVPACK32.DLL : 7.6.0.3 360488 Bytes 2008-02-07 14:18:24
                                        AVREG.DLL : 7.0.1.6 30760 Bytes 2007-07-18 07:17:06
                                        AVARKT.DLL : 1.0.0.20 278568 Bytes 2007-08-28 12:26:33
                                        AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 2007-07-18 07:10:18
                                        NETNT.DLL : 7.0.0.0 7720 Bytes 2007-03-08 11:09:42
                                        RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 2007-08-07 12:38:13
                                        RCTEXT.DLL : 7.0.62.0 86056 Bytes 2007-08-21 12:50:37
                                        SQLITE3.DLL : 3.3.17.1 339968 Bytes 2007-07-23 09:37:21

                                        Configuration settings for the scan:
                                        Jobname..........................: Complete system scan
                                        Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                                        Logging..........................: low
                                        Primary action...................: interactive
                                        Secondary action.................: ignore
                                        Scan master boot sector..........: on
                                        Scan boot sector.................: on
                                        Boot sectors.....................: D:,
                                        Scan memory......................: on
                                        Process scan.....................: on
                                        Scan registry....................: on
                                        Search for rootkits..............: on
                                        Scan all files...................: All files
                                        Scan archives....................: on
                                        Recursion depth..................: 20
                                        Smart extensions.................: on
                                        Macro heuristic..................: on
                                        File heuristic...................: high

                                        Start of the scan: 2008-02-07 15:26

                                        Starting search for hidden objects.
                                        '46176' objects were checked, '0' hidden objects were found.

                                        The scan of running processes will be started
                                        Scan process 'avscan.exe' - '1' Module(s) have been scanned
                                        Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                                        Scan process 'sched.exe' - '1' Module(s) have been scanned
                                        Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                                        Scan process 'avguard.exe' - '1' Module(s) have been scanned
                                        Scan process 'alg.exe' - '1' Module(s) have been scanned
                                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                        Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
                                        Scan process 'firefox.exe' - '1' Module(s) have been scanned
                                        Scan process 'RocketDock.exe' - '1' Module(s) have been scanned
                                        Scan process 'UberIcon Manager.exe' - '1' Module(s) have been scanned
                                        Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
                                        Scan process 'explorer.exe' - '1' Module(s) have been scanned
                                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                        Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                        Scan process 'lsass.exe' - '1' Module(s) have been scanned
                                        Scan process 'services.exe' - '1' Module(s) have been scanned
                                        Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                                        Scan process 'csrss.exe' - '1' Module(s) have been scanned
                                        Scan process 'smss.exe' - '1' Module(s) have been scanned
                                        23 processes with 23 modules were scanned

                                        Starting master boot sector scan:
                                        Master boot sector HD0
                                        [NOTE] No virus was found!

                                        Start scanning boot sectors:
                                        Boot sector 'C:\'
                                        [NOTE] No virus was found!
                                        Boot sector 'D:\'
                                        [NOTE] No virus was found!

                                        Starting to scan the registry.
                                        The registry was scanned ( '22' files ).

                                        Starting the file scan:

                                        Begin scan in 'C:\'
                                        C:\hiberfil.sys
                                        [WARNING] The file could not be opened!
                                        C:\pagefile.sys
                                        [WARNING] The file could not be opened!
                                        C:\WINDOWS\system32\drivers\sptd.sys
                                        [WARNING] The file could not be opened!
                                        Begin scan in 'D:\' <HP_RECOVERY>

                                        End of the scan: 2008-02-07 15:57
                                        Used time: 31:01 min

                                        The scan has been done completely.

                                        4835 Scanning directories
                                        325114 Files were scanned
                                        0 viruses and/or unwanted programs were found
                                        0 Files were classified as suspicious:
                                        0 files were deleted
                                        0 files were repaired
                                        0 files were moved to quarantine
                                        0 files were renamed
                                        3 Files cannot be scanned
                                        325114 Files not concerned
                                        9655 Archives were scanned
                                        3 Warnings
                                        10 Notes
                                        46176 Objects were scanned with rootkit scan
                                        0 Hidden objects were found
                                        0
                                        • 1
                                        • 2