[Virus] Fenêtre intempestive, blocage ...

Bonjour,
Je vous explique ma situation, j'ai attrapé un virus, depuis :

_ Mon pc rame
_ Mes pages explorer sont assalit par des pubs
_ " Explorer . exe " se ferme
_Mes fichier deviennent tous en lecture seul, je peut en supprimez quelque uns pas le mode sans échec
_ Ma vie devient agaçante ^^

Mon anti-virus : Securitoo, détecte un virus à chaque fois que j'allume mon pc ... Le virus n'est même pas aux même endroit ...

J'ai nettoyer avec Ccleaner, vider mes fichier Temp, smit fraud fix, ...

Pour ceux qui veulent m'aider , j'ai Hijack si vous désirer ...
Configuration: Windows XP
Internet Explorer 7.0

10 réponses


  1. Bonjour/Bonsoir
    • Ne pas surfer ailleurs que sur le site
    • Couper MSN ou tout autre connexion hormis celle sur le site
    • Appliquer exactement et dans l'ordre les procédures indiquées.
    • Au cas ou plusieurs intervenants se manifestent, en choisir un et un seul.

    • Rester devant la machine en rafraichissant souvent le forum pour voir les nouvelles réponses.
    • Répondre sans attendre à toutes les questions posées dans l'ordre ou elles ont étés posées
    • Soyez précis dans vos réponses. Tenez vous en au sujet et rien qu'au sujet.
    • A proscrire : le language SMS.

    • Ne pas quitter tant qu'il n'est pas dit explicitement que le problème est résolu ou qu'il
    dépasse les compétences de celui ou ceux qui vous aident.
    • N'ouvrez pas plusieurs discussions sur le même sujet sauf si on vous le demande
    (Problème non résolu. Ca arrive)

    • Ne pas s'impatienter. L'analyse d'un rapport et la recherche de solutions
    appropriées prends un certain temps.
    Inutile donc de reposter le même message. Nous ne vous oublions pas,
    nous vous cherchons une solution

    • Ne pas oublier : nous sommes bénévoles.
    Nous mangeons, nous dormons, nous travaillons, nous avons une vie de famille aussi.


    Préalable
    • Vider la corbeille
    • Fermer toutes les applications

    ================ PareFeu XP - Vista ===================
    • Si un autre pare-feu que celui de windows est installé, vérifier qu'il est actif et passer à l'étape CCleaner

    • Sinon

    pour activer/désactiver le Pare-feu Vista
    pour activer/désactiver le Pare-feu Xp le Pare-feu Vista

    • Activer le pare-Feu si ce n'est déjà fait

    ===================== CCLEANER ========================
    Pour le petit coup de polish.
    • Appliquer la procédure ci-dessous.
    • l'outil pourra être conservé pour faire le ménage de temps en temps en appliquant la même procédure.

    Nettoyage avec CCleaner
    On va commencer par faire un peu le ménage

    • Télécharger CCLeaner et l'installer sur le bureau en refusant l'installation de la barre Yahoo.

    • Fermer toutes les applications
    • Lancer CCLeaner
    S'il n'est pas en Français cliquer sur Options, Setting, Language
    et sélectionner Français
    • cocher dans le menu Nettoyeur - onglet Windows :
    Internet Explorer: Fichiers Internet Temporaires, Cookies
    • Système: Vider la Poubelle, Fichiers Temporaires, Presse-papiers
    • Avancé: Vieilles données du Prefetch
    • Décocher dans le menu Options - sous-menu Avancé :
    Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures
    • Cocher dans le menu Nettoyeur - onglet Applications : Internet: Sun Java
    • Cocher , si cela est possible, dans le menu Nettoyeur - onglet Applications :
    Firefox/Mozilla: Cache Internet, Cookies
    • Click sur Analyse
    • Click sur le bouton Lancer le nettoyage dans le menu Nettoyeur.
    • Click sur Registre
    • Sélectionner tout
    • Click sur Chercher des erreurs (En bas)

    Une fois le scan terminé sélectionner tout
    • Click sur Réparer les erreurs sélectionnées

    ==================== HIJACKTHIS ======================

    HijackThis

    • Télécharger HijackThis
    • Installer HijackThis en se laissant guider (Accepter le répertoire proposé sans rien changer)
    • Fermer HijackThis
    • Télécharger sur le bureau HJTNew (Si le Pare-Feu ou l'Anti-virus se manifeste, Ignorer)
    • Fermer toutes les applications
    • Se débrancher d'Internet (Enlever le cable, c'est encore la meilleure solution)
    • Lancer HJTNew.exe (Si le Pare-Feu ou l'Anti-virus se manifeste, Ignorer)
    Ne pas s'étonner pour HJTNew, rien ne s'affiche, juste une fenêtre qui s'ouvre et se ferme aussitôt. C'est normal.
    • Click sur Do a system scan and save a logfile
    • Copier/Coller le rapport dans le prochain message
    • Supprimer HJTNew.exe (sinon l'Anti-virus risque de se manifester souvent) puis
    • Attendre la suite
    _
    0
    1. Je tient à vous remercier de votre attention, j'ai donc exactement rspecter vos étapes ... Je tient à direque mon anti-virus c'est aussi activer et a supprimé de nombreux fichier ... Maintenant voilà le rapport Hijak :

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 01:24:25, on 29/03/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
      C:\WINDOWS\system32\hphmon05.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\Securitoo\av_fw\backweb\6588780\Program\fspex.exe
      C:\PROGRA~1\SECURI~1\av_fw\backweb\6588780\Program\SERVIC~1.EXE
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\WINDOWS\system32\cisvc.exe
      C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
      C:\Program Files\Securitoo\av_fw\backweb\6588780\program\fsbwsys.exe
      C:\Program Files\Securitoo\av_fw\Anti-Virus\FSGK32.EXE
      C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
      C:\Program Files\Securitoo\av_fw\Anti-Virus\fssm32.exe
      C:\Program Files\Securitoo\av_fw\Common\FSMB32.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Securitoo\av_fw\Common\FCH32.EXE
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Securitoo\av_fw\Common\FAMEH32.EXE
      C:\Program Files\Securitoo\av_fw\Anti-Virus\fsqh.exe
      C:\Program Files\Securitoo\av_fw\Anti-Virus\fsrw.exe
      C:\Program Files\Securitoo\av_fw\Anti-Virus\fsav32.exe
      C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
      C:\PROGRA~1\SECURI~1\av_fw\ANTI-S~1\fsaw.exe
      C:\Program Files\Securitoo\av_fw\FSGUI\fsguidll.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\cidaemon.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [Ins3DT] F:\INSTALL4\INS3DT.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Securitoo\av_fw\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Securitoo\av_fw\FSGUI\FSSW.EXE" /reboot
      O4 - HKLM\..\Run: [News Service] "C:\Program Files\Securitoo\av_fw\FSGUI\ispnews.exe"
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
      O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
      O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [dc5890c7] rundll32.exe "C:\WINDOWS\system32\wrnsdidg.dll",b
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\Securitoo\av_fw\backweb\6588780\Program\fspex.exe
      O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\Securitoo\av_fw\Anti-Spyware\blockpopups.htm
      O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
      O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
      O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Securitoo\av_fw\Anti-Spyware\ieshield.dll
      O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Securitoo\av_fw\Anti-Spyware\ieshield.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O15 - Trusted Zone: http://www.leaguexbox.fr
      O15 - Trusted Zone: https://lobby.ogame.gameforge.com/fr_FR/
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {33DFB28A-9792-4AFC-B594-D589365DF67D} (Bahu Photo Uploader) - https://bahu.com/BahuPhotoUploader.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {76EE578D-314B-4755-8365-6E1722C001A2} (Bahu Photo Uploader) - https://bahu.com/BahuPhotoUploader.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
      O22 - SharedTaskScheduler: jhsf8d984jief8dsfus98jkefn - {C5AF49A2-94F3-42BD-F434-2604812C897D} - (no file)
      O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\SECURI~1\av_fw\backweb\6588780\Program\SERVIC~1.EXE
      O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
      O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
      O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Securitoo\av_fw\backweb\6588780\program\fsbwsys.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      0
      1. Ok, merci pour ces informations

        Tu as au moins deux infections (ne pas se formaliser pour le tutoiement, c'est la règle sur Internet).

        ===================== COMBOFIX ========================

        Combofix

        • Imprimer ou sauvegarder avec le bloc-note cette procédure car la suite va se dérouler sans accès à Internet.
        • Installer ComboFix sur le bureau
        Note :
        Le serveur de téléchargement peut être en surcharge et renvoyer une page d'erreur. Il faut insister.

        • Renommer COMBOFIX.EXE en COMBO-FIX.EXE
        ------
        • Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
        • Attention, pas d’accès à internet dans ce mode. Enregistrer ou imprimer les consignes.

        • Relancer le Pc et tapoter la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
        • Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
        -------
        • Désactiver seulement pendant l'utilisation de ComboFix, la protection de l'antivirus et de l'antispyware ceux-ci pouvant entraver le bon fonctionnement de combofix
        • Fermer toutes les applications en cours
        • Double-click sur l'icône qui s'est installé sur le bureau
        • Appuyer sur la touche 1 puis sur entrée:
        • Laisser Combofix travailler sans se servir de la machine.
        • Si ComboFix a besoin de redémarrer la machine, laisser faire sinon redémarrer en mode normal.
        • Copier/Coller le rapport généré dans le bloc-note dans le prochain message
        (Ce fichier est automatiquement généré et enregistré sous C:\Combofix.txt)
        0
        1. Merci beaucoup, voilà le rapport :

          ComboFix 08-03-27.2 - Belloeil 2008-03-29 1:45:43.1 - NTFSx86 MINIMAL
          Endroit: C:\Documents and Settings\Belloeil\Mes documents\Dossier internet\Combo-Fix.exe

          [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr0.dat
          C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft\Network\Downloader\qmgr1.dat
          C:\Program Files\newdotnet
          C:\Program Files\newdotnet\nncore.dll
          C:\Program Files\newdotnet\nnrun.exe
          C:\Program Files\newdotnet\readme.html
          C:\Program Files\newdotnet\uninstall.exe
          C:\setup.exe
          C:\WINDOWS\cookies.ini
          C:\WINDOWS\dat.txt
          C:\WINDOWS\search_res.txt
          C:\WINDOWS\system32\byxvtqq.dll
          C:\WINDOWS\system32\eqlhkljm.dll
          C:\WINDOWS\system32\gdidsnrw.ini
          C:\WINDOWS\system32\hotwamdy.dll
          C:\WINDOWS\system32\hwjtynwb.dll
          C:\WINDOWS\system32\ihkmp.ini
          C:\WINDOWS\system32\ihkmp.ini2
          C:\WINDOWS\system32\invpsajo.dll
          C:\WINDOWS\system32\pmkhi.dll
          C:\WINDOWS\system32\sthsnvpk.dll
          C:\WINDOWS\system32\tldtlpdd.dll
          C:\WINDOWS\system32\ugmwdlop.dll
          C:\WINDOWS\system32\vdyevynh.dll
          C:\WINDOWS\system32\winsys.exe
          C:\WINDOWS\system32\wrnsdidg.dll

          ----- BITS: Possible sites infect‚s -----

          hxxp://softworldnetwork.com
          .
          ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
          .

          -------\Service_npf

          ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-02-28 to 2008-03-29 ))))))))))))))))))))))))))))))))))))
          .

          2008-03-29 01:35 . 2008-03-29 01:36 <REP> d-------- C:\ComboFix
          2008-03-28 22:09 . 2007-12-14 22:19 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
          2008-03-28 22:09 . 2007-12-14 22:19 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
          2008-03-28 22:09 . 2007-12-14 21:38 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
          2008-03-28 22:09 . 2007-12-14 22:19 <REP> d-------- C:\Documents and Settings\Administrateur\Mes documents
          2008-03-28 22:09 . 2007-12-14 22:19 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
          2008-03-28 22:09 . 2007-12-14 22:19 <REP> d-------- C:\Documents and Settings\Administrateur\Favoris
          2008-03-28 22:09 . 2007-12-14 22:19 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
          2008-03-28 20:40 . 2008-03-28 20:40 91,700 --a------ C:\WINDOWS\system32\drivers\klin.dat
          2008-03-28 20:40 . 2008-03-28 20:40 85,860 --a------ C:\WINDOWS\system32\drivers\klick.dat
          2008-03-28 20:37 . 2008-03-28 20:37 <REP> d-------- C:\Program Files\Kaspersky Lab
          2008-03-28 17:35 . 2008-03-28 23:08 1,377,918 ---hs---- C:\WINDOWS\system32\htbvadle.ini
          2008-03-28 17:22 . 2008-03-28 17:22 <REP> d-------- C:\Program Files\CCleaner
          2008-03-28 12:47 . 2008-03-28 12:47 4,096 --a------ C:\WINDOWS\system32\GLOCK32.0XE
          2008-03-27 20:59 . 2008-03-27 20:59 <REP> d-------- C:\Documents and Settings\NetworkService.AUTORITE NT\Mes documents
          2008-03-27 17:37 . 2008-03-28 17:37 1,380,080 ---hs---- C:\WINDOWS\system32\cfhkjmsi.ini
          2008-03-26 19:35 . 2008-03-26 19:36 <REP> d-------- C:\Program Files\Unlocker
          2008-03-26 17:35 . 2008-03-27 17:35 1,464,366 ---hs---- C:\WINDOWS\system32\evbanjlq.ini
          2008-03-25 17:33 . 2008-03-26 17:34 1,521,278 ---hs---- C:\WINDOWS\system32\yrgmdnpv.ini
          2008-03-24 17:19 . 2008-03-24 17:19 26,496 --a------ C:\WINDOWS\system32\drivers\MSX38.0YS
          2008-03-24 14:25 . 2008-03-24 14:25 26,496 --a------ C:\WINDOWS\system32\drivers\LRW73.0YS
          2008-03-24 14:20 . 2008-03-24 17:28 <REP> d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
          2008-03-24 13:58 . 2008-03-24 13:58 26,496 --a------ C:\WINDOWS\system32\drivers\KPU62.0YS
          2008-03-24 13:38 . 2008-03-25 17:32 1,579,604 ---hs---- C:\WINDOWS\system32\tgwtchdk.ini
          2008-03-23 20:55 . 2008-03-23 20:55 26,496 --a------ C:\WINDOWS\system32\drivers\CJE71.0YS
          2008-03-23 13:39 . 2008-03-24 13:38 1,544,077 ---hs---- C:\WINDOWS\system32\ajjbhfho.ini
          2008-03-22 22:10 . 2008-03-22 22:10 26,496 --a------ C:\WINDOWS\system32\drivers\AUA40.0YS
          2008-03-22 21:47 . 2008-03-22 15:49 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
          2008-03-22 21:15 . 2008-03-22 21:15 26,496 --a------ C:\WINDOWS\system32\drivers\FKP51.0YS
          2008-03-22 13:38 . 2008-03-23 13:38 1,543,759 ---hs---- C:\WINDOWS\system32\xhynjawd.ini
          2008-03-22 12:25 . 2008-03-22 12:25 26,496 --a------ C:\WINDOWS\system32\drivers\HNS05.0YS
          2008-03-22 01:28 . 2008-03-22 01:28 26,496 --a------ C:\WINDOWS\system32\drivers\AGL73.0YS
          2008-03-22 01:27 . 2008-03-22 01:27 6,144 --a------ C:\OVVBU.0XE
          2008-03-21 16:13 . 2008-03-21 16:13 <REP> d-------- C:\Program Files\uTorrent
          2008-03-21 16:13 . 2008-03-22 01:42 <REP> d-------- C:\Documents and Settings\Belloeil\Application Data\uTorrent
          2008-03-18 19:00 . 2008-03-19 14:52 <REP> d-------- C:\Program Files\Windows Live Safety Center
          2008-02-29 16:51 . 2008-02-29 16:51 <REP> d-------- C:\Documents and Settings\Belloeil\Application Data\Samsung
          2008-02-29 16:45 . 2006-05-03 22:53 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
          2008-02-29 16:44 . 2003-02-21 18:42 348,160 --a------ C:\WINDOWS\system32\msvcr71.dll
          2008-02-29 16:40 . 2005-08-30 17:59 94,000 --a------ C:\WINDOWS\system32\drivers\ss_mdm.sys
          2008-02-29 16:40 . 2005-08-30 17:57 58,320 --a------ C:\WINDOWS\system32\drivers\ss_bus.sys
          2008-02-29 16:40 . 2005-08-30 17:58 8,304 --a------ C:\WINDOWS\system32\drivers\ss_mdfl.sys
          2008-02-29 16:40 . 2005-08-30 17:58 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cmnt.sys
          2008-02-29 16:40 . 2005-08-30 17:58 6,144 --a------ C:\WINDOWS\system32\drivers\ss_cm.sys
          2008-02-29 16:40 . 2005-08-30 17:57 5,808 --a------ C:\WINDOWS\system32\drivers\ss_whnt.sys
          2008-02-29 16:40 . 2005-08-30 17:57 5,808 --a------ C:\WINDOWS\system32\drivers\ss_wh.sys
          2008-02-29 16:38 . 2005-08-28 20:51 766 --a------ C:\WINDOWS\system32\Uninstall.ico
          2008-02-29 16:35 . 2006-07-24 16:05 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-03-28 16:22 --------- d-----w C:\Program Files\Yahoo!
          2008-03-19 12:02 --------- d-----w C:\Program Files\Java
          2008-03-12 21:48 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Help
          2008-03-03 19:04 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
          2008-02-23 19:13 --------- d-----w C:\Program Files\Styler
          2008-02-20 16:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
          2008-02-20 15:58 --------- d-----w C:\Documents and Settings\All Users.WINDOWS\Application Data\InstallShield
          2008-02-20 15:39 --------- d-----w C:\Program Files\gPotato.eu
          2008-02-18 18:50 --------- d-----w C:\Program Files\LimeWire
          2008-02-18 18:50 --------- d-----w C:\Documents and Settings\Belloeil\Application Data\LimeWire
          2008-01-29 06:43 --------- d-----w C:\Program Files\Trend Micro
          2008-01-28 21:58 --------- d---a-w C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
          2008-01-28 20:22 --------- d-----w C:\Documents and Settings\Belloeil\Application Data\F-Secure
          2008-01-28 19:24 --------- d-----w C:\Program Files\OpenOffice.org 2.3
          2008-01-28 19:22 --------- d-----w C:\Documents and Settings\Belloeil\Application Data\OpenOffice.org2
          2008-01-28 18:49 --------- d-----w C:\Program Files\7-Zip
          2008-01-28 17:01 64,801 ----a-w C:\WINDOWS\BricoPackUninst.cmd
          2008-01-28 17:01 5,376 ----a-w C:\WINDOWS\BricoPackFoldersDelete.cmd
          2008-01-28 17:01 219,648 ----a-w C:\WINDOWS\system32\uxtheme.dll
          2008-01-28 16:33 --------- d-----w C:\Program Files\Wanadoo
          2008-01-28 16:19 --------- d-----w C:\Documents and Settings\Belloeil\Application Data\Styler
          2008-01-28 16:04 --------- d-----w C:\Documents and Settings\Belloeil\Application Data\OtakuSoftware
          2008-01-28 15:57 --------- d-----w C:\Program Files\Hewlett-Packard
          2008-01-27 13:37 81,920 ----a-w C:\WINDOWS\system32\IEDFix.exe
          .

          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          REGEDIT4
          *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
          "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 14:50 122880]
          "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 09:59 204288]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "SoundMan"="SOUNDMAN.EXE" [2004-05-14 08:47 67072 C:\WINDOWS\SOUNDMAN.EXE]
          "Ins3DT"="F:\INSTALL4\INS3DT.EXE" [ ]
          "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-07-01 09:12 4112384]
          "nwiz"="nwiz.exe" [2004-07-01 09:12 843776 C:\WINDOWS\system32\nwiz.exe]
          "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2004-07-01 09:12 81920]
          "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
          "F-Secure Manager"="C:\Program Files\Securitoo\av_fw\Common\FSM32.exe" [2005-10-26 02:51 122929]
          "F-Secure TNB"="C:\Program Files\Securitoo\av_fw\TNB\TNBUtil.exe" [2005-07-18 15:51 700416]
          "F-Secure Startup Wizard"="C:\Program Files\Securitoo\av_fw\FSGUI\FSSW.exe" [2005-10-18 09:29 372736]
          "News Service"="C:\Program Files\Securitoo\av_fw\FSGUI\ispnews.exe" [2005-05-31 13:45 356352]
          "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2004-05-04 15:21 176128]
          "HPHUPD05"="C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe" [2004-04-01 11:33 49152]
          "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 07:38 241664]
          "HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2003-12-05 14:41 49152]
          "HPHmon05"="C:\WINDOWS\system32\hphmon05.exe" [2004-05-05 06:18 491520]
          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
          "Nouvelle valeur #1"= 0 (0x0)

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
          "AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Agl73.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Aua40.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Bgl73.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Bhm73.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Cje71.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Fkp51.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Flq40.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Hns05.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Hns38.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Kpu62.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lrw73.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Msx16.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Msx38.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Rwc62.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Sye16.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ubg05.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wch16.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wch40.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wch62.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Xdi84.sys]
          @="Driver"

          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Yfk84.sys]
          @="Driver"

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
          "C:\\Program Files\\Securitoo\\av_fw\\backweb\\6588780\\Program\\fspex.exe"=
          "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
          "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
          "C:\\Program Files\\uTorrent\\uTorrent.exe"=

          R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2005-11-18 16:04]
          R2 BackWeb Plug-in - 6588780;Antivirus Firewall;C:\PROGRA~1\SECURI~1\av_fw\backweb\6588780\Program\SERVIC~1.EXE [2007-12-14 23:13]
          R2 F-Secure Filter;F-Secure File System Filter;C:\Program Files\Securitoo\av_fw\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 16:14]
          R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Program Files\Securitoo\av_fw\Anti-Virus\Win2K\FSgk.sys [2008-03-20 17:48]
          R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Program Files\Securitoo\av_fw\Anti-Virus\Win2K\FSrec.sys [2004-06-01 10:03]
          R3 klim5;Kaspersky Anti-Virus NDIS Filter;C:\WINDOWS\system32\DRIVERS\klim5.sys [2007-12-13 13:28]
          S3 Agl73;Agl73;C:\WINDOWS\System32\drivers\Agl73.sys []
          S3 Aua40;Aua40;C:\WINDOWS\System32\drivers\Aua40.sys []
          S3 Bgl73;Bgl73;C:\WINDOWS\System32\drivers\Bgl73.sys []
          S3 Bhm73;Bhm73;C:\WINDOWS\System32\drivers\Bhm73.sys []
          S3 Cje71;Cje71;C:\WINDOWS\System32\drivers\Cje71.sys []
          S3 Fkp51;Fkp51;C:\WINDOWS\System32\drivers\Fkp51.sys []
          S3 Flq40;Flq40;C:\WINDOWS\System32\drivers\Flq40.sys []
          S3 Hns05;Hns05;C:\WINDOWS\System32\drivers\Hns05.sys []
          S3 Hns38;Hns38;C:\WINDOWS\System32\drivers\Hns38.sys []
          S3 Kpu62;Kpu62;C:\WINDOWS\System32\drivers\Kpu62.sys []
          S3 Msx16;Msx16;C:\WINDOWS\System32\drivers\Msx16.sys []
          S3 Rwc62;Rwc62;C:\WINDOWS\System32\drivers\Rwc62.sys []
          S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 17:57]
          S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 17:58]
          S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 17:59]
          S3 Sye16;Sye16;C:\WINDOWS\System32\drivers\Sye16.sys []
          S3 Ubg05;Ubg05;C:\WINDOWS\System32\drivers\Ubg05.sys []
          S3 Wch16;Wch16;C:\WINDOWS\System32\drivers\Wch16.sys []
          S3 Wch40;Wch40;C:\WINDOWS\System32\drivers\Wch40.sys []
          S3 Xdi84;Xdi84;C:\WINDOWS\System32\drivers\Xdi84.sys []
          S3 Yfk84;Yfk84;C:\WINDOWS\System32\drivers\Yfk84.sys []

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f5c8cf40-ce61-11dc-bee6-811e665c9d37}]
          \Shell\AutoRun\command - G:\loader.exe

          .
          Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
          "2008-03-28 17:58:03 C:\WINDOWS\Tasks\HP Usg Daily.job"
          - C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\pexpress\hphped05.exe
          "2008-03-28 23:00:05 C:\WINDOWS\Tasks\HPpromotions hp photosmart 7700 series.job"
          - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqwrg.exe
          "2008-03-29 00:03:57 C:\WINDOWS\Tasks\Scheduled scanning task.job"
          - C:\PROGRA~1\SECURI~1\av_fw\ANTI-V~1\fsav.exe` /HARD /ARCHIVE /DISINF /SCHED /NOBREAK /REPORT=C:\PROGRA~1\SECURI~1\av_fw\ANTI-V~1\report.txt $C:\PROGRA~1\SECURI~1\av_fw\ANTI-V~1.SYSTEM'Tƒche ajout‚e par F-Secure Anti-Virus.
          .
          **************************************************************************

          catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-03-29 01:57:55
          Windows 5.1.2600 Service Pack 2 NTFS

          Balayage processus cach‚s ...

          Balayage cach‚ autostart entries ...

          Balayage des fichiers cach‚s ...

          Scan termin‚ avec succŠs
          Les fichiers cach‚s: 0

          **************************************************************************
          .
          ------------------------ Other Running Processes ------------------------
          .
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
          C:\Program Files\Securitoo\av_fw\backweb\6588780\program\fsbwsys.exe
          C:\Program Files\Securitoo\av_fw\Anti-Virus\FSGK32.EXE
          C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
          C:\Program Files\Securitoo\av_fw\Common\FSMB32.EXE
          C:\Program Files\Securitoo\av_fw\Anti-Virus\fssm32.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Securitoo\av_fw\backweb\6588780\Program\fspex.exe
          C:\Program Files\Securitoo\av_fw\Common\FCH32.EXE
          C:\Program Files\Securitoo\av_fw\Common\FAMEH32.EXE
          C:\Program Files\Securitoo\av_fw\Anti-Virus\fsqh.exe
          C:\Program Files\Securitoo\av_fw\Anti-Virus\fsrw.exe
          C:\Program Files\Windows Media Player\WMPNetwk.exe
          C:\Program Files\Securitoo\av_fw\Anti-Virus\fsav32.exe
          C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\PROGRA~1\SECURI~1\av_fw\ANTI-S~1\fsaw.exe
          C:\Program Files\Securitoo\av_fw\FSGUI\fsguidll.exe
          C:\WINDOWS\system32\HPZipm12.exe
          C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
          .
          **************************************************************************
          .
          Temps d'accomplissement: 2008-03-29 2:02:46 - machine was rebooted [Belloeil]
          ComboFix-quarantined-files.txt 2008-03-29 01:02:40
          Pre-Run: 29,582,352,384 octets libres
          Post-Run: 29,025,824,768 octets libres
          .
          2008-03-12 21:48:31 --- E O F ---
          0
          1. Remet un nouveau rapport HiJackThis stp
            0
            1. Voilà :

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 02:18:09, on 29/03/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16608)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\SECURI~1\av_fw\backweb\6588780\Program\SERVIC~1.EXE
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
              C:\Program Files\Securitoo\av_fw\backweb\6588780\program\fsbwsys.exe
              C:\Program Files\Securitoo\av_fw\Anti-Virus\FSGK32.EXE
              C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
              C:\Program Files\Securitoo\av_fw\Common\FSMB32.EXE
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Securitoo\av_fw\Anti-Virus\fssm32.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\Program Files\Securitoo\av_fw\backweb\6588780\Program\fspex.exe
              C:\Program Files\Securitoo\av_fw\Common\FCH32.EXE
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Securitoo\av_fw\Common\FAMEH32.EXE
              C:\Program Files\Securitoo\av_fw\Anti-Virus\fsqh.exe
              C:\Program Files\Securitoo\av_fw\Anti-Virus\fsrw.exe
              C:\Program Files\Securitoo\av_fw\Anti-Virus\fsav32.exe
              C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\WINDOWS\system32\RUNDLL32.EXE
              C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE
              C:\Program Files\Securitoo\av_fw\FSGUI\ispnews.exe
              C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
              C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
              C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
              C:\PROGRA~1\SECURI~1\av_fw\ANTI-S~1\fsaw.exe
              C:\WINDOWS\system32\hphmon05.exe
              C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\Program Files\Securitoo\av_fw\FSGUI\fsguidll.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
              C:\WINDOWS\explorer.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Windows Media Player\wmplayer.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Windows Media Player\wmpenc.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [Ins3DT] F:\INSTALL4\INS3DT.EXE
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE" /splash
              O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Securitoo\av_fw\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
              O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Securitoo\av_fw\FSGUI\FSSW.EXE" /reboot
              O4 - HKLM\..\Run: [News Service] "C:\Program Files\Securitoo\av_fw\FSGUI\ispnews.exe"
              O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
              O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
              O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
              O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\Securitoo\av_fw\backweb\6588780\Program\fspex.exe
              O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\Securitoo\av_fw\Anti-Spyware\blockpopups.htm
              O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
              O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
              O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Securitoo\av_fw\Anti-Spyware\ieshield.dll
              O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Securitoo\av_fw\Anti-Spyware\ieshield.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O15 - Trusted Zone: http://www.leaguexbox.fr
              O15 - Trusted Zone: https://lobby.ogame.gameforge.com/fr_FR/
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
              O16 - DPF: {33DFB28A-9792-4AFC-B594-D589365DF67D} (Bahu Photo Uploader) - https://bahu.com/BahuPhotoUploader.cab
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
              O16 - DPF: {76EE578D-314B-4755-8365-6E1722C001A2} (Bahu Photo Uploader) - https://bahu.com/BahuPhotoUploader.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
              O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
              O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\SECURI~1\av_fw\backweb\6588780\Program\SERVIC~1.EXE
              O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
              O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Securitoo\av_fw\backweb\6588780\program\fsbwsys.exe
              O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
              O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              0
              1. Mais comment faites-vous ôr détecter les lignes iltigieuses dans des rpports aussi longs?

                Vous server-vous d'un logiciel ou rst-ce l'expéience?

                ET je crois que récemment on a reproché à quelqu'un de supprimer des lignes alors qu'il s'aprêtait ensuiteà s'attaquer aux programmes qui comme vous le savez sont à l'ogine de la création de clés et non l'iverse.
                ammes associées aux clés.

                Hijack ne supprime pas, sauf exception l'essenyiel...

                Seriez-vous donc assez aimable pour partager avec moi votre "secret"?

                Merci
                0
              2. merci d'ignorer le messageil était destiné à un autre topic. Je pourrasi très bien vs aider mais d'autres s'en chargeront
                0
            2. + CCl
              + HJ
              + ComboFix
              MalwaresBytes
              ************* Ne pas tenir compte des lignes ci-dessus


              ================== MalwareBytes =====================

              Telecharger MalwareBytes

              Le Tutorial

              Poster le rapport MalwareByte + Rapport HiJackThis
              0
              1. Malwarebytes' Anti-Malware 1.09
                Version de la base de données: 563

                Type de recherche: Examen rapide
                Eléments examinés: 16609
                Temps écoulé: 8 minute(s), 23 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 1
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 0

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                HKEY_CLASSES_ROOT\Typelib\{50ccd00a-66b6-4d95-aaef-8ee959498f92} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                (Aucun élément nuisible détecté)
                0
                1. Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 12:57:21, on 29/03/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16608)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\WINDOWS\system32\RUNDLL32.EXE
                  C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE
                  C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                  C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                  C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                  C:\WINDOWS\system32\hphmon05.exe
                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
                  C:\PROGRA~1\SECURI~1\av_fw\backweb\6588780\Program\SERVIC~1.EXE
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
                  C:\Program Files\Securitoo\av_fw\backweb\6588780\program\fsbwsys.exe
                  C:\Program Files\Securitoo\av_fw\Anti-Virus\FSGK32.EXE
                  C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
                  C:\Program Files\Securitoo\av_fw\Anti-Virus\fssm32.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Securitoo\av_fw\Common\FSMB32.EXE
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\Program Files\Securitoo\av_fw\backweb\6588780\Program\fspex.exe
                  C:\Program Files\Securitoo\av_fw\Common\FCH32.EXE
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Securitoo\av_fw\Common\FAMEH32.EXE
                  C:\Program Files\Securitoo\av_fw\Anti-Virus\fsqh.exe
                  C:\Program Files\Securitoo\av_fw\Anti-Virus\fsrw.exe
                  C:\Program Files\Securitoo\av_fw\Anti-Virus\fsav32.exe
                  C:\WINDOWS\system32\HPZipm12.exe
                  C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
                  C:\PROGRA~1\SECURI~1\av_fw\ANTI-S~1\fsaw.exe
                  C:\Program Files\Securitoo\av_fw\FSGUI\fsguidll.exe
                  C:\Program Files\internet explorer\iexplore.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [Ins3DT] F:\INSTALL4\INS3DT.EXE
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Securitoo\av_fw\Common\FSM32.EXE" /splash
                  O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Securitoo\av_fw\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
                  O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Program Files\Securitoo\av_fw\FSGUI\FSSW.EXE" /reboot
                  O4 - HKLM\..\Run: [News Service] "C:\Program Files\Securitoo\av_fw\FSGUI\ispnews.exe"
                  O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
                  O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{5372B9A6-6E51-4f90-9B40-E0A3B8475C4E}\hphupd05.exe
                  O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                  O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
                  O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: Antivirus Firewall.lnk = C:\Program Files\Securitoo\av_fw\backweb\6588780\Program\fspex.exe
                  O8 - Extra context menu item: &Bloquer cette fenêtre publicitaire - C:\Program Files\Securitoo\av_fw\Anti-Spyware\blockpopups.htm
                  O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                  O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
                  O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                  O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                  O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll
                  O9 - Extra button: Protection Internet Explorer - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Securitoo\av_fw\Anti-Spyware\ieshield.dll
                  O9 - Extra 'Tools' menuitem: Protection Internet Explorer... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\Securitoo\av_fw\Anti-Spyware\ieshield.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O15 - Trusted Zone: http://www.leaguexbox.fr
                  O15 - Trusted Zone: https://lobby.ogame.gameforge.com/fr_FR/
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                  O16 - DPF: {33DFB28A-9792-4AFC-B594-D589365DF67D} (Bahu Photo Uploader) - https://bahu.com/BahuPhotoUploader.cab
                  O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                  O16 - DPF: {76EE578D-314B-4755-8365-6E1722C001A2} (Bahu Photo Uploader) - https://bahu.com/BahuPhotoUploader.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {D821DC4A-0814-435E-9820-661C543A4679} (CRLDownloadWrapper Class) - http://drmlicense.one.microsoft.com/crlupdate/en/crlocx.ocx
                  O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
                  O23 - Service: Antivirus Firewall (BackWeb Plug-in - 6588780) - Securitoo Portal - C:\PROGRA~1\SECURI~1\av_fw\backweb\6588780\Program\SERVIC~1.EXE
                  O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Anti-Virus\fsgk32st.exe
                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  O23 - Service: fsbwsys - F-Secure Corp. - C:\Program Files\Securitoo\av_fw\backweb\6588780\program\fsbwsys.exe
                  O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\FWES\Program\fsdfwd.exe
                  O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\Securitoo\av_fw\Common\FSMA32.EXE
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  0
                  1. ---------------- CORRECTION COMBOFIX ------------------

                    fais ceci :

                    • Copier le texte ci-dessous :


                    File::
                    f:\install4\ins3dt.exe

                    Registry::
                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                    "Ins3DT"=-


                    • Ouvrir le Bloc-Notes puis coller le texte copié. (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
                    • Sauvegarder ce fichier sous le nom de CFScript.txt.
                    • Glisser maintenant le fichier CFScript.txt dans Combofix.exe comme montré ici
                    • Cela va relancer Combofix,
                    • Une fenêtre bleue va apparaître: un message qui apparait ( Type 1 to continue, or 2 to abort)
                    • taper 1 puis valider.

                    • Patienter le temps du scan. Le bureau va disparaitre à plusieurs reprises: c'est normal!
                    • Ne toucher à rien tant que le scan n'est pas terminé.

                    • Après redémarrage, copier/coller le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

                    S'il n'y a pas de redémarrage, redémarrer et poster les rapports.
                    0