Probléme virus"ta tof fait koi sur ce site&qu

Résolu
peluche33 -  
 ZfoX -
Bonjour,
Et bien voilà comme beaucoup j'ai chopé ce virus de m...e!!!
Après avoir lu beaucoup de topic sur ce sujet, j'ai effectué les démarches suivantes:
_téléchargement de AVG anti-spyware + analyse
_téléchargement de HiJackThis +"Do a system scan and save logfile".

Voilà le rapport:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:01:22, on 06/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\htpatch.exe
C:\WINDOWS\system32\sistray.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\user\LOCALS~1\Temp\services.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\system32\khooker.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Flash Media] C:\DOCUME~1\user\LOCALS~1\Temp\services.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
A voir également:

15 réponses

jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
slt,

Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
• Redémarre ton ordinateur
• Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
• A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
• Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
• Choisis ton compte.
Déroule la liste des instructions ci-dessous :
• Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.cmd pour lancer le scrïpt.
• Appuie sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuie sur une touche pour redémarrer le PC.
• Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuie sur une touche pour finir l'exécution du scrïpt et charger les icônes de ton Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum,

____________

scan avec MalwareByte's Anti-Malware et colle un rapport

https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

______________

recolle un rapport hiajckthis et dis tes soucis
0
peluche33
 
Salut,
Ok je me lance dans tes indications, je te tiens au courant et te remercie pour ton aide.
0
peluche33
 
Voilà j'ai suivi tes instructions mais après avoir taper "Y" plus rien ne se passe, faut il que j'attende ou celà n'est pas normal???
0
peluche33
 
Non en fait je suis un peu trop impatient tout ce déroule comme tu me l'as indiqué.
Désolé
0
peluche33
 
[b]SDFix: Version 1.153 /b

Run by Administrateur on 06/03/2008 at 12:32

Microsoft Windows XP [version 5.1.2600]
Running From: C:\SDFix

[b]Checking Services /b:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


[b]Checking Files /b:

Trojan Files Found:

C:\DOCUME~1\user\LOCALS~1\Temp\services.exe - Deleted





Removing Temp Files

[b]ADS Check /b:



[b]Final Check /b:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 12:36:24
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

C:\DOCUME~1\user\LOCALS~1\Temp\services.exe [1156] 0x85302340

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...


scan completed successfully
hidden processes: 1
hidden services: 0
hidden files: 17


[b]Remaining Services /b:



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"="C:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe:*:Enabled:IncrediMail Installer"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\DOCUME~1\\user\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\user\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Media"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[b]Remaining Files /b:


File Backups: - C:\SDFix\backups\backups.zip

[b]Files with Hidden Attributes /b:

Thu 5 Jun 2003 24,576 A..H. --- "C:\Program Files\RamBoost XP\StopRam.exe"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Sat 13 Oct 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Thu 15 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Mon 7 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\ad213d081e2675ef87a62c73b8abf209\BIT3.tmp"

[b]Finished!/b

Voilà le paport.txt

J'attends la suite de tes indications
Merci
0
Nadia91 Messages postés 5 Statut Membre
 
jai fait la même démarche
voici mon rapport.


Rebooting


[b]Checking Files [/b]:

Trojan Files Found:

C:\DOCUME~1\PROPRI~1.NOM\LOCALS~1\Temp\services.exe - Deleted





Removing Temp Files

[b]ADS Check [/b]:



[b]Final Check [/b]:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 13:01:10
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

C:\DOCUME~1\PROPRI~1.NOM\LOCALS~1\Temp\services.exe [332] 0x82D24358

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:fa,7b,e8,6e,47,93,ab,b2,35,ba,75,a6,0c,19,7b,63,c1,0a,f1,1b,70,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:fa,7b,e8,6e,47,93,ab,b2,35,ba,75,a6,0c,19,7b,63,c1,0a,f1,1b,70,..

scanning hidden registry entries ...

scanning hidden files ...


scan completed successfully
hidden processes: 1
hidden services: 0
hidden files: 214


[b]Remaining Services [/b]:



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\backWeb-7681197.exe"="C:\\Program Files\\F-Secure\\BackWeb\\7681197\\program\\backWeb-7681197.exe:*:Disabled:backWeb-7681197"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
"C:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe"="C:\\Program Files\\Kerio\\Personal Firewall 4\\kpf4gui.exe:*:Disabled:Kerio Personal Firewall 4 - GUI"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"="C:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe:*:Disabled:BackWeb-137903"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\Documents and Settings\\Propri‚taire.NOM-JXZ6Q3Q4WHD\\Bureau\\adsltv.exe"="C:\\Documents and Settings\\Propri‚taire.NOM-JXZ6Q3Q4WHD\\Bureau\\adsltv.exe:*:Disabled:adsltv"
"C:\\Documents and Settings\\Propri‚taire.NOM-JXZ6Q3Q4WHD\\Bureau\\vlc.exe"="C:\\Documents and Settings\\Propri‚taire.NOM-JXZ6Q3Q4WHD\\Bureau\\vlc.exe:*:Enabled:VLC media player"
"C:\\Documents and Settings\\Propri‚taire.NOM-JXZ6Q3Q4WHD\\Bureau\\a controler\\papier a dounia_fichiers\\Nouveau dossier\\adsltv.exe"="C:\\Documents and Settings\\Propri‚taire.NOM-JXZ6Q3Q4WHD\\Bureau\\a controler\\papier a dounia_fichiers\\Nouveau dossier\\adsltv.exe:*:Enabled:adsltv"
"C:\\Documents and Settings\\Propri‚taire.NOM-JXZ6Q3Q4WHD\\Bureau\\a controler\\papier a dounia_fichiers\\Nouveau dossier\\vlc.exe"="C:\\Documents and Settings\\Propri‚taire.NOM-JXZ6Q3Q4WHD\\Bureau\\a controler\\papier a dounia_fichiers\\Nouveau dossier\\vlc.exe:*:Enabled:VLC media player"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
"C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"="C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe:*:Disabled:Veoh Client"
"C:\\Program Files\\Paltalk Messenger\\paltalk.exe"="C:\\Program Files\\Paltalk Messenger\\paltalk.exe:*:Enabled:PaltalkScene"
"C:\\Program Files\\adslTV\\adsltv.exe"="C:\\Program Files\\adslTV\\adsltv.exe:*:Disabled:adsltv"
"C:\\Program Files\\adslTV\\vlc.exe"="C:\\Program Files\\adslTV\\vlc.exe:*:Disabled:VLC media player"
"C:\\DOCUME~1\\PROPRI~1.NOM\\LOCALS~1\\Temp\\services.exe"="C:\\DOCUME~1\\PROPRI~1.NOM\\LOCALS~1\\Temp\\services.exe:*:Enabled:Flash Media"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[b]Remaining Files [/b]:


File Backups: - C:\DOCUME~1\PROPRI~1.NOM\Bureau\SDFix\backups\backups.zip

[b]Files with Hidden Attributes [/b]:

Wed 5 Mar 2008 11,270 A.SH. --- "C:\WINDOWS\SYSTEM32\KGyGaAvL.sys"
Thu 9 Aug 2001 64,512 A..H. --- "C:\WINDOWS\SYSTEM32\PackethSvc.exe"
Fri 17 Dec 2004 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Fri 28 Sep 2007 49,664 ...H. --- "C:\Documents and Settings\Propri‚taire.NOM-JXZ6Q3Q4WHD\Bureau\~WRL0004.tmp"
Sat 29 Sep 2007 61,440 ...H. --- "C:\Documents and Settings\Propri‚taire.NOM-JXZ6Q3Q4WHD\Bureau\~WRL0253.tmp"
Sat 29 Sep 2007 58,880 ...H. --- "C:\Documents and Settings\Propri‚taire.NOM-JXZ6Q3Q4WHD\Bureau\~WRL3065.tmp"
Wed 19 Dec 2007 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP771\A0920449.sys"
Mon 24 Dec 2007 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP778\A0920867.sys"
Wed 2 Jan 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP779\A0920884.sys"
Thu 3 Jan 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP788\A0921323.sys"
Fri 18 Jan 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP790\A0921399.sys"
Mon 21 Jan 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP791\A0921411.sys"
Mon 21 Jan 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP795\A0921553.sys"
Sun 27 Jan 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP798\A0921593.sys"
Tue 29 Jan 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP800\A0921809.sys"
Sat 2 Feb 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP802\A0921864.sys"
Tue 5 Feb 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP804\A0922176.sys"
Thu 7 Feb 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP804\A0922219.sys"
Sun 10 Feb 2008 11,270 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP808\A0922865.sys"
Thu 14 Feb 2008 10,646 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP813\A0922960.sys"
Tue 19 Feb 2008 10,646 A.SH. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP824\A0928387.sys"
Sat 13 Nov 2004 37,376 A..H. --- "C:\Program Files\Fichiers communs\Adobe\ESD\DLMCleanup.exe"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP770\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP770\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP771\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP771\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP772\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP772\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP773\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP773\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP774\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP774\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP775\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP775\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP776\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP776\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP777\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP777\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP778\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP778\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP779\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP779\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP780\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP780\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP781\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP781\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP782\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP782\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP783\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP783\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP784\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP784\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP785\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP785\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP786\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP786\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP787\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP787\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP788\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP788\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP789\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP789\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP790\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP790\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP791\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP791\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP792\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP792\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP793\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP793\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP794\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP794\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP795\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP795\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP796\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP796\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP797\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP797\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP798\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP798\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP799\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP799\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP800\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP800\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP801\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP801\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP802\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP802\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP803\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP803\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP804\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP804\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP805\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP805\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP806\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP806\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP807\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP807\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP808\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP808\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP809\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP809\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP810\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP810\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP811\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP811\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP812\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP812\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP813\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP813\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP814\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP814\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP815\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP815\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP816\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP816\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP817\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP817\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP818\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP818\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP819\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP819\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP820\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP820\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP821\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP821\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP822\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP822\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP823\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP823\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Sat 20 May 2006 3,145,728 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP824\snapshot\_REGISTRY_USER_NTUSER_S-1-5-21-955046455-183450923-720897496-1003.bak"
Mon 15 Sep 2003 262,144 A..H. --- "C:\System Volume Information\_restore{845A621C-47AF-4FF1-980D-74451E21E351}\RP824\snapshot\_REGISTRY_USER_USRCLASS_S-1-5-21-955046455-183450923-720897496-1003.bak"
Wed 21 Mar 2007 25,600 A..H. --- "C:\Documents and Settings\Propri‚taire.NOM-JXZ6Q3Q4WHD\Bureau\a controler\BTS1 Dossier Stage Nadia\Action professionnel Guy Hoquet\~WRL1792.tmp"

[b]Finished![/b]
0
peluche33
 
Voila mon nouveau rapport hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:34:58, on 06/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\system32\sistray.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\user\LOCALS~1\Temp\services.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\system32\khooker.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
slt c'est pas fini

Télécharge MsnCleaner.zip de ElPiedra et décompresse le sur ton bureau. (Clic droit sur le fichier .zip puis Extraire tout).
Copier l’adresse suivante dans ton lien :
https://forospyware.com
• Redémarre le PC en Mode sans échec et connecte toi sous ton nom d'utilisateur habituel.Pour démarrer en mode sans échec.
• Double-clique sur MsnCleaner.exe pour le lancer.
• Sous Language, clique sur la petite flèche et choisis French.
• Clique sur le bouton Analyse.
• A la fin du scan un rapport va être créé.
• Si l'outil trouve une infection, clique sur le bouton Supprimer.
• Redémarre en mode normal.
• Poste le rapport C:\MsnCleaner.txt dans ta prochaine réponse..

_______________

scan avec
MalwareByte's Anti-Malware et colle le rapport

https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

______________

recolle un rapport hijakchits
0
Nadia91 Messages postés 5 Statut Membre
 
moi ossi ?,,??? LOL sivouplé jai besoin d'aide
0
peluche33
 
J'ai un souci une fois redémarré en mode sans échec je ne trouve plus MSNcleanner.
Que dois je faire?
0
peluche33
 
voici le papport C:\MsnCleanner.txt

- Rapport MSNCleaner 1.5.8 by www.forospyware.com
- Rapport créé: 06/03/2008 on 15:36:39
- Système d'exploitation: Windows XP
- Mode de démarrage: Mode sans échec
_________________________________________

Fichiers détectés: 0
Fichiers supprimés: 0
Fichiers non supprimés: 0

<<<<<<< Pas de fichiers trouvés >>>>>>>

Maintenant je scan avec Malwarebyte's et je mets le rapport
0
peluche33
 
Voici le rapport avec Malwarebyte's:
Malwarebytes' Anti-Malware 1.07
Version de la base de données: 461

Type de recherche: Examen complet (A:\|C:\|)
Eléments examinés: 86662
Temps écoulé: 30 minute(s), 42 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 1
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\Trymedia Systems (Adware.Trymedia) -> No action taken.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)


Et le nouveau rapport avec hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:30:51, on 06/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\system32\sistray.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\user\LOCALS~1\Temp\services.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\system32\khooker.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
essaye de redemarrer , puis de refaire la procedure

ou sinon passe a
MalwareByte's Anti-Malware e
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
refaisMalwarebytes' Anti-Malware 1.07
et nettoie ce qui est trouvé

______________

telecharge combofix:

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

http://boards.cexx.org/index.php?topic=15787.msg65211

Ferme tout tes navigateurs (donc copie ou imprime les instructions avant)

Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

File::
C:\DOCUME~1\DIDIER~1\LOCALS~1\Temp\winlogon.exe

Enregistre ce fichier sous le nom CFscript

Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

Ne touche à rien tant que le scan n'est pas terminé.

Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

Remets aussi un rapport Hijackthis

Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
0
peluche33
 
Voici le rapport ComboFix:

ComboFix 08-03-05.3 - user 2008-03-06 17:19:51.2 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.170 [GMT 1:00]
Endroit: C:\Documents and Settings\user\Mes documents\ComboFix.exe
Command switches used :: C:\Documents and Settings\user\Bureau\CFscript.txt
* Création d'un nouveau point de restauration

[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.

((((((((((((((((((((((((((((( Fichiers créés 2008-02-06 to 2008-03-06 ))))))))))))))))))))))))))))))))))))
.

2008-03-06 15:49 . 2008-03-06 16:21 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-03-06 15:49 . 2008-03-06 15:49 <REP> d-------- C:\Documents and Settings\user\Application Data\Malwarebytes
2008-03-06 15:49 . 2008-03-06 15:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-03-06 15:31 . 2008-03-06 15:36 <REP> d-------- C:\MSNCleaner
2008-03-06 12:30 . 2008-03-06 12:30 <REP> d-------- C:\WINDOWS\ERUNT
2008-03-06 12:28 . 2006-10-31 09:56 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-03-06 12:28 . 2006-10-31 09:56 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-03-06 12:28 . 2006-10-31 10:00 <REP> d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-03-06 12:28 . 2006-10-31 09:56 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
2008-03-06 12:28 . 2006-10-31 09:56 <REP> dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-03-06 12:28 . 2006-10-31 09:56 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
2008-03-06 12:28 . 2008-03-06 15:38 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2008-03-06 12:24 . 2008-03-06 12:39 <REP> d-------- C:\SDFix
2008-03-05 21:43 . 2008-03-05 21:43 <REP> d-------- C:\Documents and Settings\user\Application Data\Grisoft
2008-03-05 21:43 . 2008-03-05 21:43 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-05 21:43 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-05 21:19 . 2008-03-05 21:19 <REP> d-------- C:\Program Files\Trend Micro
2008-03-04 10:08 . 2008-03-04 10:08 244 --ah----- C:\sqmnoopt00.sqm
2008-03-04 10:08 . 2008-03-04 10:08 232 --ah----- C:\sqmdata00.sqm
2008-02-20 17:48 . 2008-02-26 12:57 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-02-20 17:48 . 2008-02-20 17:48 1,409 --a------ C:\WINDOWS\QTFont.for
2008-02-17 20:53 . 2008-02-17 20:51 691,545 --a------ C:\WINDOWS\unins000.exe
2008-02-17 20:53 . 2008-02-17 20:53 3,456 --a------ C:\WINDOWS\unins000.dat

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-06 10:45 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-03-05 17:47 --------- d-----w C:\Program Files\Norton Security Scan
2008-02-17 20:07 --------- d-----w C:\Program Files\Spybot - Search & Destroy
2008-02-17 20:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-02-12 18:11 --------- d-----w C:\Program Files\eMule
2007-12-07 02:08 824,832 ----a-w C:\WINDOWS\system32\wininet.dll
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IncrediMail"="C:\Program Files\IncrediMail\bin\IncMail.exe" [2007-12-04 18:01 214456]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 16:09 15360]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-05 19:25 68856]
"updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 15:45 313472]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HTpatch"="C:\WINDOWS\htpatch.exe" [2002-10-30 10:40 28672]
"SiS Tray"="C:\WINDOWS\system32\sistray.EXE" [2002-11-17 10:36 303104]
"SiS KHooker"="C:\WINDOWS\system32\khooker.exe" [ ]
"Smapp"="C:\Program Files\Analog Devices\SoundMAX\SMTray.exe" [2002-10-11 18:26 98304]
"ShStatEXE"="C:\Program Files\Network Associates\VirusScan\SHSTAT.exe" [2004-09-22 20:00 94208]
"McAfeeUpdaterUI"="C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" [2004-08-06 03:50 139320]
"Network Associates Error Reporting Service"="C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe" [2003-10-07 09:48 147514]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"Lexmark 2200 Series"="C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe" [2004-02-13 14:13 57344]
"FaxCenterServer"="C:\Program Files\Lexmark Fax Solutions\fm3032.exe" [2004-02-04 15:33 294912]
"PinnacleDriverCheck"="C:\WINDOWS\system32\PSDrvCheck.exe" [2004-03-10 15:26 406016]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-09-27 17:27 155648]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 16:09 15360]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 21:05:26 29696]
NkbMonitor.exe.lnk - C:\Program Files\Nikon\PictureProject\NkbMonitor.exe [2007-05-13 12:11:20 118784]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll,

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\IncrediMail\\bin\\IncrediMail_Install.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

R3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
S3 KLSIENET;Pilote de carte Ethernet USB;C:\WINDOWS\system32\DRIVERS\usb101et.sys [2004-08-19 15:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]

.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-02-29 15:11:52 C:\WINDOWS\Tasks\Norton Security Scan.job"
- C:\Program Files\Norton Security Scan\Nss.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-06 17:21:44
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cachés ...

Balayage caché autostart entries ...

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HTpatch = C:\WINDOWS\htpatch.exe?ows\CurrentVersion\Run???\???/??[???????[???[???????????????????[???[?D?????[$??????[????????????S??[????????m??[???w????(???{??w???w???????w???w???[????????d???b6?[%??[???[????"??[A??[???[.??wZ??[?3?[?3?[????st.I?????? [????d???0=?[?K?[

Balayage des fichiers cachés ...

Scan terminé avec succès
Les fichiers cachés: 0

**************************************************************************
.
Temps d'accomplissement: 2008-03-06 17:22:37
ComboFix2.txt 2008-03-06 16:15:00
.
2008-02-13 22:36:22 --- E O F ---


Et là tu as le rapport Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:26:11, on 06/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\htpatch.exe
C:\WINDOWS\system32\sistray.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\system32\khooker.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Fichiers communs\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Service Framework McAfee (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
https://www.informatruc.com

desactive puis réactive ta restauration

_______________

tout est bon encore des soucis????
0
peluche33
 
voià maintenant c'est chose faite, je te remercie pour ton aide qui m'a été précieuse.
Par rapport à tout les programmes que j'ai du télécharger est ce que je peux les suprimer???
Ce sera ma dernière question.

Encore merci
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
tu peux tout virer!
0
peluche33
 
b un grand merci
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
de rien!
0
meganeandyou Messages postés 4 Statut Membre
 
G un probleme, lorsque je tape y sur sdfix RunThis, rien ne se passe ! Et j'attends depuis 30 minutes, que dois je faire ?
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
tu cré ton propre post et tu explique tes soucis et colle y un rapport msn fix

bonne continuation
0
zouzou05 Messages postés 26 Statut Membre > jlpjlp Messages postés 52399 Statut Contributeur sécurité
 
tu peux m'aidé?
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
0
zouzou05 Messages postés 26 Statut Membre
 
ben j'arrive pas a effacé le virus alors je vais le restauré c et le formaté c'est le mieux
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
• Redémarre ton ordinateur
• Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
• A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
• Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
• Choisis ton compte.
Déroule la liste des instructions ci-dessous :
• Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
• Appuie sur Y pour commencer le processus de nettoyage.
• Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
• Appuie sur une touche pour redémarrer le PC.
• Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
• Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
• Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
• Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
• Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum

___________

puis scan avec MalwareByte's Anti-Malware

https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
0
meganeandyou Messages postés 4 Statut Membre
 
- tu cré ton propre post et tu explique tes soucis et colle y un rapport msn fix

C'est fait, mais personne ne me répond ! AIDEZ MOI, svp !
0
jen ai marre de ce virus!
 
Salit a tous moi aussi le virus et g fait msnfix et g redémarrer lordinateur pi la g fait hijackthis et voila le rapport: je fais quoi maintenant?

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:26:12, on 13/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\sarra\LOCALS~1\Temp\Rar$EX00.859\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\DOCUME~1\sarra\LOCALS~1\Temp\Rar$EX00.844\services.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\PixArt\PAC207\Monitor.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [Flash Media] C:\DOCUME~1\sarra\LOCALS~1\Temp\Rar$EX00.844\services.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\S-1-5-21-1004336348-1767777339-725345543-1008\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User '?')
O4 - HKUS\S-1-5-21-1004336348-1767777339-725345543-1008\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (User '?')
O4 - HKUS\S-1-5-21-1004336348-1767777339-725345543-1008\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide (User '?')
O4 - HKUS\S-1-5-21-1004336348-1767777339-725345543-1008\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (User '?')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User '?')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
0
jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 040
 
slt

tu fais le message 32

et si ca persiste tu cré ton propre post!!!!!!!!!!!!!!!!!!
0
ZfoX
 
[b]SDFix: Version 1.158 [/b]

Run by Enfants on 16/03/2008 at 17:29

Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\Enfants\Bureau\SDFix

[b]Checking Services [/b]:

Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting

[b]Checking Files [/b]:

No Trojan Files Found

Removing Temp Files

[b]ADS Check [/b]:

[b]Final Check [/b]:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-16 17:35:55
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes ...

IPC error: 2 Le fichier spécifié est introuvable.
scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000001
"ujdew"=hex:c3,3c,23,03,2b,7f,ed,24,d4,24,60,7e,82,70,9f,29,44,8c,52,5d,35,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:cf,65,d1,4f,8b,8a,41,c6,5e,d7,1c,83,99,d0,74,c6,91,2a,d3,3d,9a,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,0f,0b,0d,f2,f4,97,a1,3c,63,00,72,86,71,49,5f,7d,51,..
"khjeh"=hex:37,98,04,92,c1,4a,4e,24,ae,58,63,e6,64,7b,34,b9,b7,75,7d,0c,4b,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:62,ad,fd,74,aa,87,fa,ee,59,62,08,94,00,e0,dc,26,a4,d0,d7,99,53,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
"p0"="C:\Program Files\Alcohol Soft\Alcohol 120\"
"h0"=dword:00000001
"ujdew"=hex:c3,3c,23,03,2b,7f,ed,24,d4,24,60,7e,82,70,9f,29,44,8c,52,5d,35,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"p0"="C:\Program Files\DAEMON Tools\"
"h0"=dword:00000000
"khjeh"=hex:cf,65,d1,4f,8b,8a,41,c6,5e,d7,1c,83,99,d0,74,c6,91,2a,d3,3d,9a,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,0f,0b,0d,f2,f4,97,a1,3c,63,00,72,86,71,49,5f,7d,51,..
"khjeh"=hex:37,98,04,92,c1,4a,4e,24,ae,58,63,e6,64,7b,34,b9,b7,75,7d,0c,4b,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:62,ad,fd,74,aa,87,fa,ee,59,62,08,94,00,e0,dc,26,a4,d0,d7,99,53,..

scanning hidden registry entries ...

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\CAVE\sY^y\xe2\x17d\37uI]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{AA21EAB8-8062-5968-D5D8-56A39B9A31D5}]
"iajbhbcjlacicfiokd"=hex:63,61,6d,64,68,68,00,7f

scanning hidden files ...

C:\WINDOWS\SoftwareDistribution\Download\222426828c4507f67ae73404f850464e
C:\WINDOWS\SoftwareDistribution\Download\222426828c4507f67ae73404f850464e\BIT3.tmp 618760 bytes executable
C:\WINDOWS\SoftwareDistribution\Download\222426828c4507f67ae73404f850464e\_downloadprogress_.state 4 bytes
C:\WINDOWS\SoftwareDistribution\Download\222426828c4507f67ae73404f850464e\_useselfcontained_.state 50 bytes

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 475

[b]Remaining Services [/b]:

Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[b]Remaining Files [/b]:

File Backups: - C:\DOCUME~1\Enfants\Bureau\SDFix\backups\backups.zip

[b]Files with Hidden Attributes [/b]:

Fri 22 Apr 2005 101,888 A..H. --- "C:\Fabrice\club_med\~WRL2452.tmp"
Sun 24 Apr 2005 100,864 A..H. --- "C:\Fabrice\club_med\~WRL3343.tmp"
Sat 1 Sep 2007 712,704 A..H. --- "C:\RECYCLER\S-1-5-21-1757981266-299502267-682003330-1005\Dc818.exe"
Wed 24 Oct 2007 712,704 ...H. --- "C:\Program Files\Lineage II\system\l2.exe"
Wed 24 Oct 2007 712,704 A..H. --- "C:\Program Files\Supreme system\system\L2.exe"
Wed 24 Oct 2007 712,704 A..H. --- "C:\RECYCLER\S-1-5-21-1757981266-299502267-682003330-1005\Dc944\L2.exe"
Wed 24 Oct 2007 712,704 A..H. --- "C:\RECYCLER\S-1-5-21-1757981266-299502267-682003330-1005\Dc974\l2.exe"
Wed 24 Oct 2007 712,704 A..H. --- "C:\RECYCLER\S-1-5-21-1757981266-299502267-682003330-1005\Dc975\L2.exe"
Wed 24 Oct 2007 712,704 A..H. --- "C:\RECYCLER\S-1-5-21-1757981266-299502267-682003330-1005\Dc982\L2.exe"
Sun 16 Mar 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\84c8ebea30ffe407ee908e9caa0bd074\BIT4.tmp"

[b]Finished![/b]

a quoi sa sert de copier/coller se rapport? merci beaucoup pour votre aide les gas !
0