Rapport pour virus msn

Résolu
Bonjour,
j'ai donc moi aussi ce foutu virus (très jolie sur cette tof...), msn Fix ne marche pas (je ne comprends pas pourquoi) msn Cleaner ne trouve rien et Avast n'a encore rien trouvé. Je poste donc ici mon rappot Hi-jack, si quelqu'un peut m'aider...

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:32:39, on 04/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
E:\Logiciels\Avast\aswUpdSv.exe
E:\Logiciels\Avast\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\system32\spupdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\WINDOWS\system32\rundll32.exe
E:\Logiciels\Avast\ashMaiSv.exe
E:\Logiciels\Avast\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\%%%%%.exe
E:\Logiciels\Avast\ashSimpl.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\%%%%%.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKLM\..\Policies\Explorer\Run: [d1h55] rundll32 "C:\WINDOWS\Downlo~1\d1h55.dll",Run
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Logiciels\Avast\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - E:\Logiciels\Avast\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Logiciels\Avast\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - E:\Logiciels\Avast\ashWebSv.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 7158 bytes
Configuration: Windows XP
Firefox 2.0.0.13

17 réponses

  1. Contributeur
    salut

    Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
    • Redémarre ton ordinateur
    • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
    • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
    • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
    • Choisis ton compte.
    Déroule la liste des instructions ci-dessous :
    • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
    • Appuie sur Y pour commencer le processus de nettoyage.
    • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
    • Appuie sur une touche pour redémarrer le PC.
    • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
    • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
    • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
    • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

    @+
    0
    1. J'ai un soucis pour redémarrer en mode sans échec, je t'explique : j'ai linux installé sur mon ordi et donc un menu de sélection au démarrage. J'ai bien fait ce que tu m'as dit (F8), l'ordi au bout d'un moment faisait un "clic" à chaque fois que j'appuyais et le menu habituel s'est affiché, dedans je peux démarrer linux en mode sans échec, mais pas windows...
      0
      1. Contributeur
        salut

        c´est bien embetant...

        On va faire comme ca :

        Télécharge combofix.exe (par sUBs) sur ton Bureau.

        -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

        -> Double clique combofix.exe.
        -> Tape sur la touche 1 (Yes) pour démarrer le scan.
        -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

        NOTE : Le rapport se trouve également ici : C:\Combofix.txt

        Avant d'utiliser ComboFix :

        -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

        -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

        Une fois fait, sur ton bureau double-clic sur Combofix.exe.

        - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

        /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

        - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

        - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

        -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

        -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

        -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

        + un nouveau hijack this

        @+
        0
        1. Voici donc le rapport de ComboFix

          ComboFix 08-04-04.1 - Admin 2008-04-05 11:33:58.1 - NTFSx86
          Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.176 [GMT 2:00]
          Endroit: C:\Documents and Settings\Admin\Bureau\ComboFix.exe
          * Création d'un nouveau point de restauration

          [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          C:\Documents and Settings\Admin\Local Settings\Application Data\thbifrdsgt.dat
          C:\Documents and Settings\Admin\Local Settings\Application Data\thbifrdsgt_nav.dat
          C:\Documents and Settings\Admin\Local Settings\Application Data\thbifrdsgt_navps.dat
          C:\Documents and Settings\Admin\ravmonlog
          C:\Documents and Settings\All Users\Application Data\microsoft\pctools
          C:\Program Files\Fichiers communs\cpush
          C:\WINDOWS\system32\drivers\olesvy.sys
          C:\WINDOWS\system32\mstacim.sig
          C:\WINDOWS\system32\nvs2.inf

          .
          ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
          .

          -------\Legacy_OLESVY
          -------\Service_olesvy

          ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-05 to 2008-04-05 ))))))))))))))))))))))))))))))))))))
          .

          2008-04-05 11:34 . 2008-04-05 11:34 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
          2008-04-05 11:34 . 2008-04-05 11:34 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
          2008-04-04 21:43 . 2008-04-04 21:44 <REP> d-------- C:\SDFix
          2008-04-04 20:28 . 2008-04-04 20:28 <REP> d-------- C:\Program Files\Trend Micro
          2008-03-18 15:39 . 2008-03-18 15:48 <REP> d-------- C:\Program Files\EoRezo
          2008-03-13 21:37 . 2006-10-04 16:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
          2008-03-13 21:37 . 2006-10-04 16:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
          2008-03-13 21:37 . 2006-10-04 16:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-04-05 09:43 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
          2008-04-05 09:43 --------- d-----w C:\Program Files\Wanadoo
          2008-04-04 07:25 --------- d-----w C:\Program Files\Spyware Doctor
          2008-03-16 20:21 --------- d-----w C:\Documents and Settings\Admin\Application Data\Teleca
          2008-03-16 19:17 --------- d-----w C:\Program Files\Windows Media Connect 2
          2008-03-04 12:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
          2008-03-03 21:35 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
          2008-03-03 21:28 --------- d-----w C:\Program Files\Fichiers communs\Sony Ericsson Shared
          2008-03-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Teleca
          2008-03-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
          2008-03-03 21:27 --------- d-----w C:\Program Files\Sony Ericsson
          2008-03-03 20:50 --------- d-----w C:\Program Files\Windows Live
          2008-03-03 20:24 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
          2008-02-08 22:14 --------- d-----w C:\Documents and Settings\Admin\Application Data\Azureus
          2008-02-06 10:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
          2008-01-09 14:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
          .

          ------- Sigcheck -------

          2005-07-26 15:01 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\system32\user32.dll

          2007-06-26 16:12 663040 889269134af28b2142f47a337ca3a1cd C:\WINDOWS\system32\wininet.dll
          2007-06-26 16:12 663040 889269134af28b2142f47a337ca3a1cd C:\WINDOWS\system32\dllcache\wininet.dll

          2005-09-18 12:29 359936 0df628756fb71111955be60bac216a70 C:\WINDOWS\system32\drivers\tcpip.sys

          2005-10-12 10:33 2058880 73fa9c95d235844a36968c7852c7dbdd C:\WINDOWS\system32\ntkrnlpa.exe

          2005-07-26 15:01 2181376 63729dd0f2aae36cc52b89c05505146c C:\WINDOWS\system32\ntoskrnl.exe

          2005-07-26 15:01 1036288 0bee3b07ace3303ee57698808e1d2de3 C:\WINDOWS\explorer.exe
          .
          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          REGEDIT4
          *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 14:50 122880]
          "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2003-04-14 20:30 1491216]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 15:53 1103752]
          "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-07-12 07:19 7626752]
          "Flash Media"="C:\WINDOWS\system32\%%%%%.exe" [ ]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
          "Config"="C:\WINDOWS\system32\run.cmd" [2005-08-23 11:24 341]
          "nlsf"="cmd.exe" [2004-08-19 16:09 400896 C:\WINDOWS\system32\cmd.exe]
          "tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-19 15:52 44544]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
          "AllowLegacyWebView"= 1 (0x1)
          "AllowUnhashedWebView"= 1 (0x1)

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
          "d1h55"= rundll32 "C:\WINDOWS\Downlo~1\d1h55.dll",Run

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
          "NoSMHelp"= 1 (0x1)
          "MemCheckBoxInRunDlg"= 1 (0x1)
          "NoSMBalloonTip"= 1 (0x1)
          "NoDesktopCleanupWizard"= 1 (0x1)
          "NoWelcomeScreen"= 1 (0x1)
          "NoAutoUpdate"= 1 (0x1)

          [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
          "NoSMHelp"= 1 (0x1)
          "MemCheckBoxInRunDlg"= 1 (0x1)
          "NoSMBalloonTip"= 1 (0x1)
          "NoDesktopCleanupWizard"= 1 (0x1)
          "NoWelcomeScreen"= 1 (0x1)
          "NoAutoUpdate"= 1 (0x1)

          [HKEY_LOCAL_MACHINE\software\microsoft\security center]
          "AntiVirusOverride"=dword:00000001
          "FirewallOverride"=dword:00000001
          "AntiVirusDisableNotify"=dword:00000001
          "UpdatesDisableNotify"=dword:00000001

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
          "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
          "C:\\Program Files\\Messenger\\msmsgs.exe"=
          "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
          "C:\\WINDOWS\\system32\\rundll32.exe"=
          "C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\javaw.exe"=
          "E:\\Logiciels\\eMule\\emule.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
          "C:\\WINDOWS\\system32\\%%%%%.exe"=

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
          "16598:TCP"= 16598:TCP:*:Disabled:NortonAV

          R0 967mn7i;967mn7;C:\WINDOWS\system32\DRIVERS\967mn7i.sys [2004-08-19 16:09]
          R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2007-12-10 15:53]
          R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34]
          S2 5avoxh;5avoxh;C:\WINDOWS\system32\drivers\5avoxh.sys []
          S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-10-07 11:49]
          S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 09:42]
          S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 09:42]
          S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 09:42]
          S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 09:42]
          S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 09:42]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          bdx REG_MULTI_SZ scan

          .
          Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
          "2008-04-04 15:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
          - C:\Program Files\OneClick.exe
          .
          **************************************************************************

          catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-04-05 11:42:49
          Windows 5.1.2600 Service Pack 2 NTFS

          detected NTDLL code modification:
          ZwClose

          Balayage processus cach‚s ...

          Balayage cach‚ autostart entries ...

          Balayage des fichiers cach‚s ...

          Scan termin‚ avec succŠs
          Les fichiers cach‚s: 0

          **************************************************************************
          .
          ------------------------ Other Running Processes ------------------------
          .
          E:\Logiciels\Avast\aswUpdSv.exe
          E:\Logiciels\Avast\ashServ.exe
          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
          C:\WINDOWS\System32\FTRTSVC.exe
          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Spyware Doctor\pctsAuxs.exe
          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
          C:\Program Files\Spyware Doctor\pctsSvc.exe
          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
          C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          E:\Logiciels\Avast\ashMaiSv.exe
          E:\Logiciels\Avast\ashWebSv.exe
          .
          **************************************************************************
          .
          Temps d'accomplissement: 2008-04-05 11:47:32 - machine was rebooted
          ComboFix-quarantined-files.txt 2008-04-05 09:47:21
          Pre-Run: 4,173,271,040 octets libres
          Post-Run: 4,288,888,832 octets libres
          .
          2007-10-22 17:02:44 --- E O F ---

          Ensuite le rapport Hi-Jack

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 11:51:18, on 05/04/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          E:\Logiciels\Avast\aswUpdSv.exe
          E:\Logiciels\Avast\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
          C:\WINDOWS\System32\FTRTSVC.exe
          C:\Program Files\CDBurnerXP\NMSAccessU.exe
          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Spyware Doctor\pctsAuxs.exe
          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
          C:\Program Files\Spyware Doctor\pctsSvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Spyware Doctor\pctsTray.exe
          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
          C:\Program Files\Messenger\msmsgs.exe
          E:\Logiciels\Avast\ashMaiSv.exe
          E:\Logiciels\Avast\ashWebSv.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
          O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
          O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%%%.exe
          O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|DEFAULT=cnx|PARAM=
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKLM\..\Policies\Explorer\Run: [d1h55] rundll32 "C:\WINDOWS\Downlo~1\d1h55.dll",Run
          O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
          O4 - Global Startup: Adobe Gamma Loader.lnk = ?
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
          O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
          O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Logiciels\Avast\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - E:\Logiciels\Avast\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Logiciels\Avast\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - E:\Logiciels\Avast\ashWebSv.exe
          O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
          O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
          O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
          O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
          0
          1. Contributeur
            ok

            la suite :

            a l´aide de hijack this coche et fix :

            O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')

            comment fixer :

            Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

            -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

            Copie le texte ci-dessous :

            File::
            C:\WINDOWS\Downlo~1\d1h55.dll
            C:\WINDOWS\system32\drivers\5avoxh.sys
            C:\WINDOWS\system32\%%%%%.exe

            Folder::
            C:\Program Files\EoRezo

            Registry::
            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "Flash Media"=-
            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplicat­ions\List]
            "C:\\WINDOWS\\system32\\%%%%%.exe"=-
            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
            "d1h55"=-

            Driver::
            5avoxh

            Ouvre le Bloc-Notes puis colle le texte copié.
            (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
            Sauvegarde ce fichier sous le nom de CFScript.txt.

            Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

            http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

            Cela va relancer Combofix,

            Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

            Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

            Ne touche à rien tant que le scan n'est pas terminé.

            Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

            S'il n'y a pas de rédémarrage, poste quand même les rapports.

            @+
            0
            1. faut-il que je désactive mes anti-virus?

              lorsque que je met le fichier dans combo fix, il me dit que je n'ai pas le prgramme aproprié pour éxécuter pv.cfexe et mon antispyware se déclence : une applisation malveillante gnagnagna... Trojan-PWS.Bancos
              chemin d'accès : C:\327882RFJFW\PV.CFEXE
              0
              1. Contributeur
                oui coupe toi du net et arrete des protections

                reessaie et dis moi

                @+
                0
                1. Voici le rapport ComboFix

                  ComboFix 08-04-04.1 - Admin 2008-04-05 14:03:26.2 - NTFSx86
                  Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.87 [GMT 2:00]
                  Endroit: C:\Documents and Settings\Admin\Bureau\ComboFix.exe
                  Command switches used :: C:\Documents and Settings\Admin\Bureau\CFScript.txt
                  * Création d'un nouveau point de restauration

                  [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                  FILE ::
                  C:\WINDOWS\Downlo~1\d1h55.dll
                  C:\WINDOWS\system32\%%%%%.exe
                  C:\WINDOWS\system32\drivers\5avoxh.sys
                  .

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  C:\Program Files\EoRezo
                  C:\Program Files\EoRezo\EoAdv\eoAdv.url
                  C:\Program Files\EoRezo\EoAdv\EoRezoBho.old

                  .
                  ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  -------\Legacy_5AVOXH
                  -------\Service_5avoxh

                  ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-05 to 2008-04-05 ))))))))))))))))))))))))))))))))))))
                  .

                  2008-04-05 11:34 . 2008-04-05 11:34 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
                  2008-04-05 11:34 . 2008-04-05 11:34 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
                  2008-04-04 21:43 . 2008-04-04 21:44 <REP> d-------- C:\SDFix
                  2008-04-04 20:28 . 2008-04-04 20:28 <REP> d-------- C:\Program Files\Trend Micro
                  2008-03-13 21:37 . 2006-10-04 16:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
                  2008-03-13 21:37 . 2006-10-04 16:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
                  2008-03-13 21:37 . 2006-10-04 16:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-04-05 12:11 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
                  2008-04-05 11:11 --------- d-----w C:\Program Files\Wanadoo
                  2008-04-04 07:25 --------- d-----w C:\Program Files\Spyware Doctor
                  2008-03-16 20:21 --------- d-----w C:\Documents and Settings\Admin\Application Data\Teleca
                  2008-03-16 19:17 --------- d-----w C:\Program Files\Windows Media Connect 2
                  2008-03-04 12:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                  2008-03-03 21:35 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
                  2008-03-03 21:28 --------- d-----w C:\Program Files\Fichiers communs\Sony Ericsson Shared
                  2008-03-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Teleca
                  2008-03-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
                  2008-03-03 21:27 --------- d-----w C:\Program Files\Sony Ericsson
                  2008-03-03 20:50 --------- d-----w C:\Program Files\Windows Live
                  2008-03-03 20:24 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
                  2008-02-08 22:14 --------- d-----w C:\Documents and Settings\Admin\Application Data\Azureus
                  2008-02-06 10:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
                  2008-01-09 14:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
                  .

                  ------- Sigcheck -------

                  2005-07-26 15:01 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\system32\user32.dll

                  2007-06-26 16:12 663040 889269134af28b2142f47a337ca3a1cd C:\WINDOWS\system32\wininet.dll
                  2007-06-26 16:12 663040 889269134af28b2142f47a337ca3a1cd C:\WINDOWS\system32\dllcache\wininet.dll

                  2005-09-18 12:29 359936 0df628756fb71111955be60bac216a70 C:\WINDOWS\system32\drivers\tcpip.sys

                  2005-10-12 10:33 2058880 73fa9c95d235844a36968c7852c7dbdd C:\WINDOWS\system32\ntkrnlpa.exe

                  2005-07-26 15:01 2181376 63729dd0f2aae36cc52b89c05505146c C:\WINDOWS\system32\ntoskrnl.exe

                  2005-07-26 15:01 1036288 0bee3b07ace3303ee57698808e1d2de3 C:\WINDOWS\explorer.exe
                  .
                  ((((((((((((((((((((((((((((( snapshot@2008-04-05_11.46.50.53 )))))))))))))))))))))))))))))))))))))))))
                  .
                  + 2008-04-05 12:10:07 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5c0.dat
                  .
                  ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  REGEDIT4
                  *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2003-04-14 20:30 1491216]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 15:53 1103752]
                  "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-07-12 07:19 7626752]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                  "nlsf"="cmd.exe" [2004-08-19 16:09 400896 C:\WINDOWS\system32\cmd.exe]
                  "tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-19 15:52 44544]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                  "AllowLegacyWebView"= 1 (0x1)
                  "AllowUnhashedWebView"= 1 (0x1)

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                  "NoSMHelp"= 1 (0x1)
                  "MemCheckBoxInRunDlg"= 1 (0x1)
                  "NoSMBalloonTip"= 1 (0x1)
                  "NoDesktopCleanupWizard"= 1 (0x1)
                  "NoWelcomeScreen"= 1 (0x1)
                  "NoAutoUpdate"= 1 (0x1)

                  [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
                  "NoSMHelp"= 1 (0x1)
                  "MemCheckBoxInRunDlg"= 1 (0x1)
                  "NoSMBalloonTip"= 1 (0x1)
                  "NoDesktopCleanupWizard"= 1 (0x1)
                  "NoWelcomeScreen"= 1 (0x1)
                  "NoAutoUpdate"= 1 (0x1)

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flash Media]
                  C:\WINDOWS\system32\%%%%%.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOKIT]
                  --a------ 2004-08-23 14:50 122880 C:\PROGRA~1\Wanadoo\Shell.exe

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                  "AntiVirusOverride"=dword:00000001
                  "FirewallOverride"=dword:00000001
                  "AntiVirusDisableNotify"=dword:00000001
                  "UpdatesDisableNotify"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
                  "C:\\Program Files\\Messenger\\msmsgs.exe"=
                  "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
                  "C:\\WINDOWS\\system32\\rundll32.exe"=
                  "C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\javaw.exe"=
                  "E:\\Logiciels\\eMule\\emule.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                  "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                  "C:\\WINDOWS\\system32\\%%%%%.exe"=

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                  "16598:TCP"= 16598:TCP:*:Disabled:NortonAV

                  R0 967mn7i;967mn7;C:\WINDOWS\system32\DRIVERS\967mn7i.sys [2004-08-19 16:09]
                  R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2007-12-10 15:53]
                  R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34]
                  S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-10-07 11:49]
                  S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 09:42]
                  S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 09:42]
                  S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 09:42]
                  S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 09:42]
                  S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 09:42]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                  bdx REG_MULTI_SZ scan

                  .
                  Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
                  "2008-04-04 15:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
                  - C:\Program Files\OneClick.exe
                  .
                  **************************************************************************

                  catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-04-05 14:10:51
                  Windows 5.1.2600 Service Pack 2 NTFS

                  Balayage processus cach‚s ...

                  Balayage cach‚ autostart entries ...

                  Balayage des fichiers cach‚s ...

                  Scan termin‚ avec succŠs
                  Les fichiers cach‚s: 0

                  **************************************************************************
                  .
                  ------------------------ Other Running Processes ------------------------
                  .
                  E:\Logiciels\Avast\aswUpdSv.exe
                  E:\Logiciels\Avast\ashServ.exe
                  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                  C:\WINDOWS\System32\FTRTSVC.exe
                  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\Program Files\Spyware Doctor\pctsAuxs.exe
                  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                  C:\Program Files\Spyware Doctor\pctsSvc.exe
                  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                  C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  E:\Logiciels\Avast\ashMaiSv.exe
                  E:\Logiciels\Avast\ashWebSv.exe
                  .
                  **************************************************************************
                  .
                  Temps d'accomplissement: 2008-04-05 14:15:34 - machine was rebooted
                  ComboFix-quarantined-files.txt 2008-04-05 12:15:24
                  ComboFix2.txt 2008-04-05 09:47:34
                  Pre-Run: 4,393,701,376 octets libres
                  Post-Run: 4,385,439,744 octets libres
                  .
                  2007-10-22 17:02:44 --- E O F ---

                  Une erreur s'est produite après le démarrage : "l'exeption Exeption logicielle inconnue (0x0eedfade) s'est produite dans l'application à l'emplacement 0x7c812a5b"

                  sinon voilà le rapport Hi-Jack :

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 14:20:27, on 05/04/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  E:\Logiciels\Avast\aswUpdSv.exe
                  E:\Logiciels\Avast\ashServ.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                  C:\WINDOWS\System32\FTRTSVC.exe
                  C:\Program Files\CDBurnerXP\NMSAccessU.exe
                  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\Program Files\Spyware Doctor\pctsAuxs.exe
                  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                  C:\Program Files\Spyware Doctor\pctsSvc.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Spyware Doctor\pctsTray.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  E:\Logiciels\Avast\ashMaiSv.exe
                  E:\Logiciels\Avast\ashWebSv.exe
                  C:\WINDOWS\System32\alg.exe
                  C:\WINDOWS\explorer.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
                  O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
                  O4 - Global Startup: Adobe Gamma Loader.lnk = ?
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                  O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                  O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Logiciels\Avast\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - E:\Logiciels\Avast\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Logiciels\Avast\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - E:\Logiciels\Avast\ashWebSv.exe
                  O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                  O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                  O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                  O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                  O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                  O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                  0
                  1. Contributeur
                    ok

                    ca a marché qu´a moitié...

                    Télécharge OAD http://sosvirus.changelog.fr/OAD.exe
                    - Enregistre le sur ton bureau

                    Double clique sur le OAD pour le lancer

                    - nom de fichier à rechercher tape ou fais un copier coller de :

                    %%%%%

                    - Type de recherche : sélectionne l'option 6 puis valide

                    OAD va maintenant rechercher le fichier. Laisse le travailler jusqu'à ce qu'il en ait terminé.
                    Le rapport de recherche s'affichera automatiquement à l’écran dès qu'il aura terminé.

                    - Fais un copier / coller de ce rapport dans ton prochain post.

                    Note importante : Suivant la taille des disques durs cette recherche peut prendre plusieurs minutes. Sois patient

                    @+
                    0
                    1. Voilà donc :

                      05/04/2008 ---- 17:01:46,17

                      ----------------------------------
                      §§§§§§ [%%%%%] §§§§§§
                      ----------------------------------
                      [X] Registre

                      -------------- [ ] rapide
                      -- Fichier --- [ ] disque systeme
                      ------------- [X] complete

                      ********************
                      [Registre]
                      ********************

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Flash Media]
                      "item"="%%%%%"

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Flash Media]
                      "command"="C:\\WINDOWS\\system32\\%%%%%.exe"

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
                      "C:\\WINDOWS\\system32\\%%%%%.exe"="C:\\WINDOWS\\system32\\%%%%%.exe:*:Enabled:Flash Media"

                      [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
                      "C:\\WINDOWS\\system32\\%%%%%.exe"="C:\\WINDOWS\\system32\\%%%%%.exe:*:Enabled:Flash Media"

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
                      "C:\\WINDOWS\\system32\\%%%%%.exe"="C:\\WINDOWS\\system32\\%%%%%.exe:*:Enabled:Flash Media"

                      [HKEY_USERS\S-1-5-21-789336058-2147160303-839522115-1003\SOFTWARE\Microsoft\Windows\ShellNoRoam\MUICache]
                      "C:\\WINDOWS\\system32\\%%%%%.exe"="%%%%%"

                      *******************
                      [Fichier]
                      *******************

                      c:\WINDOWS\Prefetch\%%%%%.EXE-1733D2D6.pf

                      *********************
                      [Même date]
                      *********************

                      [04/04/2008 ] --- REP ---> C:\Program Files\Trend Micro
                      [04/04/2008 ] ---> C:\WINDOWS\0.log
                      [04/04/2008 ] ---> C:\WINDOWS\system32\real.txt

                      Outil Aide Diagnostic By !aur3n7 Version 1.1
                      ----------------------------------
                      §§§§§ Fin Rapport §§§§§
                      ----------------------------------
                      0
                      1. Contributeur
                        ok

                        une vrai saloperie ce truc !

                        vide le dossier prefetch : c:\WINDOWS\Prefetch

                        Pour vider le contenu du fichier prefetch il faut afficher les fichiers et dossiers cachés :

                        Affiche tous les fichiers et dossiers :

                        Pour cela :

                        Clique sur démarrer/panneau de configuration/option des dossiers/affichage

                        Cocher afficher les dossiers cacher

                        Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                        Décocher masquer les extensions dont le type est connu

                        Puis fais «Ok» pour valider les changements.

                        Et appliquer !

                        Copie le texte ci-dessous :

                        File::
                        C:\WINDOWS\system32\%%%%%.exe
                        c:\WINDOWS\Prefetch\%%%%%.EXE-1733D2D6.pf
                        C:\WINDOWS\system32\real.txt
                        C:\WINDOWS\0.log

                        Registry::
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Flash Media]
                        "item"=-
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\Flash Media]
                        "command"=-
                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\S­tandardProfile\AuthorizedApplications\List]
                        "C:\\WINDOWS\\system32\\%%%%%.exe"=-
                        [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\S­tandardProfile\AuthorizedApplications\List]
                        "C:\\WINDOWS\\system32\\%%%%%.exe"=-
                        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPoli­cy\StandardProfile\AuthorizedApplications\List]
                        "C:\\WINDOWS\\system32\\%%%%%.exe"=-
                        [HKEY_USERS\S-1-5-21-789336058-2147160303-839522115-1003\SOFTWARE\Microsoft\Windows\ShellN­oRoam\MUICache]
                        "C:\\WINDOWS\\system32\\%%%%%.exe"=-
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "Flash Media"=-

                        Ouvre le Bloc-Notes puis colle le texte copié.
                        (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
                        Sauvegarde ce fichier sous le nom de CFScript.txt.

                        Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

                        http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

                        Cela va relancer Combofix,

                        Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                        Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                        Ne touche à rien tant que le scan n'est pas terminé.

                        Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

                        S'il n'y a pas de rédémarrage, poste quand même les rapports.

                        @+
                        0
                        1. Voici le rapport ComboFix :

                          ComboFix 08-04-04.1 - Admin 2008-04-05 17:30:27.3 - NTFSx86
                          Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.150 [GMT 2:00]
                          Endroit: C:\Documents and Settings\Admin\Bureau\ComboFix.exe
                          Command switches used :: C:\Documents and Settings\Admin\Bureau\CFScript.txt
                          * Création d'un nouveau point de restauration

                          [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                          FILE ::
                          C:\WINDOWS\[u]0[/u].log
                          c:\WINDOWS\Prefetch\%%%%%.EXE-1733D2D6.pf
                          C:\WINDOWS\system32\%%%%%.exe
                          C:\WINDOWS\system32\real.txt
                          .

                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          C:\WINDOWS\[u]0[/u].log
                          C:\WINDOWS\system32\real.txt

                          .
                          ((((((((((((((((((((((((((((( Fichiers créés 2008-03-05 to 2008-04-05 ))))))))))))))))))))))))))))))))))))
                          .

                          2008-04-05 11:34 . 2008-04-05 11:34 23,392 --a------ C:\WINDOWS\system32\nscompat.tlb
                          2008-04-05 11:34 . 2008-04-05 11:34 16,832 --a------ C:\WINDOWS\system32\amcompat.tlb
                          2008-04-04 21:43 . 2008-04-04 21:44 <REP> d-------- C:\SDFix
                          2008-04-04 20:28 . 2008-04-04 20:28 <REP> d-------- C:\Program Files\Trend Micro
                          2008-03-13 21:37 . 2006-10-04 16:06 1,197,294 -----c--- C:\WINDOWS\system32\dllcache\sysmain.sdb
                          2008-03-13 21:37 . 2006-10-04 16:06 764,868 -----c--- C:\WINDOWS\system32\dllcache\apph_sp.sdb
                          2008-03-13 21:37 . 2006-10-04 16:06 217,118 -----c--- C:\WINDOWS\system32\dllcache\apphelp.sdb

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2008-04-05 12:36 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
                          2008-04-05 11:11 --------- d-----w C:\Program Files\Wanadoo
                          2008-04-04 07:25 --------- d-----w C:\Program Files\Spyware Doctor
                          2008-03-16 20:21 --------- d-----w C:\Documents and Settings\Admin\Application Data\Teleca
                          2008-03-16 19:17 --------- d-----w C:\Program Files\Windows Media Connect 2
                          2008-03-04 12:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                          2008-03-03 21:35 --------- d-----w C:\Program Files\Fichiers communs\Teleca Shared
                          2008-03-03 21:28 --------- d-----w C:\Program Files\Fichiers communs\Sony Ericsson Shared
                          2008-03-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Teleca
                          2008-03-03 21:28 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sony Ericsson
                          2008-03-03 21:27 --------- d-----w C:\Program Files\Sony Ericsson
                          2008-03-03 20:50 --------- d-----w C:\Program Files\Windows Live
                          2008-03-03 20:24 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
                          2008-02-08 22:14 --------- d-----w C:\Documents and Settings\Admin\Application Data\Azureus
                          2008-02-06 10:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
                          2008-01-27 13:37 81,920 ----a-w C:\WINDOWS\system32\IEDFix.exe
                          2008-01-09 14:01 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
                          .

                          ------- Sigcheck -------

                          2005-07-26 15:01 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\system32\user32.dll

                          2007-06-26 16:12 663040 889269134af28b2142f47a337ca3a1cd C:\WINDOWS\system32\wininet.dll
                          2007-06-26 16:12 663040 889269134af28b2142f47a337ca3a1cd C:\WINDOWS\system32\dllcache\wininet.dll

                          2005-09-18 12:29 359936 0df628756fb71111955be60bac216a70 C:\WINDOWS\system32\drivers\tcpip.sys

                          2005-10-12 10:33 2058880 73fa9c95d235844a36968c7852c7dbdd C:\WINDOWS\system32\ntkrnlpa.exe

                          2005-07-26 15:01 2181376 63729dd0f2aae36cc52b89c05505146c C:\WINDOWS\system32\ntoskrnl.exe

                          2005-07-26 15:01 1036288 0bee3b07ace3303ee57698808e1d2de3 C:\WINDOWS\explorer.exe
                          .
                          ((((((((((((((((((((((((((((( snapshot@2008-04-05_11.46.50.53 )))))))))))))))))))))))))))))))))))))))))
                          .
                          + 2008-04-05 12:10:07 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_5c0.dat
                          .
                          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          REGEDIT4
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2003-04-14 20:30 1491216]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2007-12-10 15:53 1103752]
                          "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-07-12 07:19 7626752]

                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                          "nlsf"="cmd.exe" [2004-08-19 16:09 400896 C:\WINDOWS\system32\cmd.exe]
                          "tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-19 15:52 44544]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                          "AllowLegacyWebView"= 1 (0x1)
                          "AllowUnhashedWebView"= 1 (0x1)

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                          "NoSMHelp"= 1 (0x1)
                          "MemCheckBoxInRunDlg"= 1 (0x1)
                          "NoSMBalloonTip"= 1 (0x1)
                          "NoDesktopCleanupWizard"= 1 (0x1)
                          "NoWelcomeScreen"= 1 (0x1)
                          "NoAutoUpdate"= 1 (0x1)

                          [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
                          "NoSMHelp"= 1 (0x1)
                          "MemCheckBoxInRunDlg"= 1 (0x1)
                          "NoSMBalloonTip"= 1 (0x1)
                          "NoDesktopCleanupWizard"= 1 (0x1)
                          "NoWelcomeScreen"= 1 (0x1)
                          "NoAutoUpdate"= 1 (0x1)

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flash Media]

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOKIT]
                          --a------ 2004-08-23 14:50 122880 C:\PROGRA~1\Wanadoo\Shell.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                          "AntiVirusOverride"=dword:00000001
                          "FirewallOverride"=dword:00000001
                          "AntiVirusDisableNotify"=dword:00000001
                          "UpdatesDisableNotify"=dword:00000001

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                          "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                          "%windir%\\system32\\sessmgr.exe"=
                          "C:\\Program Files\\NVIDIA Corporation\\NetworkAccessManager\\Apache Group\\Apache2\\bin\\Apache.exe"=
                          "C:\\Program Files\\Messenger\\msmsgs.exe"=
                          "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
                          "C:\\WINDOWS\\system32\\rundll32.exe"=
                          "C:\\Program Files\\Java\\j2re1.4.2_06\\bin\\javaw.exe"=
                          "E:\\Logiciels\\eMule\\emule.exe"=
                          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                          "C:\\WINDOWS\\system32\\%%%%%.exe"=

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                          "16598:TCP"= 16598:TCP:*:Disabled:NortonAV

                          R0 967mn7i;967mn7;C:\WINDOWS\system32\DRIVERS\967mn7i.sys [2004-08-19 16:09]
                          R1 pctfw2;pctfw2;C:\WINDOWS\system32\drivers\pctfw2.sys [2007-12-10 15:53]
                          R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2007-10-12 09:34]
                          S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-10-07 11:49]
                          S3 w200bus;Sony Ericsson W200 driver (WDM);C:\WINDOWS\system32\DRIVERS\w200bus.sys [2006-11-07 09:42]
                          S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\w200mdfl.sys [2006-11-07 09:42]
                          S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\w200mdm.sys [2006-11-07 09:42]
                          S3 w200mgmt;Sony Ericsson W200 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\w200mgmt.sys [2006-11-07 09:42]
                          S3 w200obex;Sony Ericsson W200 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\w200obex.sys [2006-11-07 09:42]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                          bdx REG_MULTI_SZ scan

                          .
                          Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                          "2008-04-04 15:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
                          - C:\Program Files\OneClick.exe
                          .
                          **************************************************************************

                          catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2008-04-05 17:33:13
                          Windows 5.1.2600 Service Pack 2 NTFS

                          detected NTDLL code modification:
                          ZwClose

                          Balayage processus cachés ...

                          Balayage caché autostart entries ...

                          Balayage des fichiers cachés ...

                          Scan terminé avec succès
                          Les fichiers cachés: 0

                          **************************************************************************
                          .
                          Temps d'accomplissement: 2008-04-05 17:34:26
                          ComboFix-quarantined-files.txt 2008-04-05 15:34:15
                          ComboFix2.txt 2008-04-05 12:15:36
                          ComboFix3.txt 2008-04-05 09:47:34
                          Pre-Run: 4,378,636,288 octets libres
                          Post-Run: 4,369,072,128 octets libres
                          .
                          2007-10-22 17:02:44 --- E O F ---

                          et le rapport Hi-Jack :

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 17:40:24, on 05/04/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\csrss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          E:\Logiciels\Avast\aswUpdSv.exe
                          E:\Logiciels\Avast\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                          C:\WINDOWS\System32\FTRTSVC.exe
                          C:\Program Files\CDBurnerXP\NMSAccessU.exe
                          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\Program Files\Spyware Doctor\pctsAuxs.exe
                          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                          C:\Program Files\Spyware Doctor\pctsSvc.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Spyware Doctor\pctsTray.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                          C:\Program Files\Messenger\msmsgs.exe
                          C:\WINDOWS\System32\alg.exe
                          C:\WINDOWS\explorer.exe
                          E:\Logiciels\Avast\ashMaiSv.exe
                          E:\Logiciels\Avast\ashWebSv.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                          C:\WINDOWS\system32\wbem\wmiprvse.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
                          O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
                          O4 - Global Startup: Adobe Gamma Loader.lnk = ?
                          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                          O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                          O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                          O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Logiciels\Avast\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - E:\Logiciels\Avast\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Logiciels\Avast\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - E:\Logiciels\Avast\ashWebSv.exe
                          O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                          O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                          O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                          O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                          0
                          1. Contributeur
                            merde y reste cette cle :

                            fais ceci :

                            Fix.reg

                            Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(x)) :

                            XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
                            REGEDIT4

                            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplicat­ions\List]
                            "C:\\WINDOWS\\system32\\%%%%%.exe"=-

                            XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
                            Note : Regedit4 est sur la premiere ligne dans le bloc note et il y a une ligne blanche a la fin.
                            Puis click sur "fichier"/"enregistrer sous" :
                            dans : sur le bureau
                            Nom du fichier : fix.reg
                            Type de fichier : "tous les fichiers"
                            clique sur "enregistrer"

                            ca doit ressembler a ca une fois enrregistré :

                            http://img520.imageshack.us/img520/4251/screenshot005ps2.png

                            quitte internet et double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
                            Si c'est bien le cas, clique sur "oui"

                            redemarre le pc

                            et post ceci :

                            Télécharge ComboScan sur ton Bureau en bas de cette pae en clickant sur download file

                            -> http://www.geekstogo.com/forum/files/

                            Ferme toutes les applications en cours : antivirus, pare-feu, etc ..
                            Double-clic sur comboscan.exe, dans la fenêtre qui s'affiche, clic sur OK.
                            Soit patient...
                            Le rapport Comboscan.txt s'affichera, copie et colle le contenu de ce fichier ici.

                            Le rapport peut-être long et en deux morceaux vérifie qu'il soit en entier.

                            @+
                            0
                            1. voivi le rapport, désolé pour le temps que j'ai mis je n'étais pas trop devant mon ordi en ce moment

                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\csrss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              E:\Logiciels\Avast\aswUpdSv.exe
                              E:\Logiciels\Avast\ashServ.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                              C:\WINDOWS\System32\FTRTSVC.exe
                              C:\Program Files\CDBurnerXP\NMSAccessU.exe
                              C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                              C:\Program Files\Spyware Doctor\pctsTray.exe
                              C:\WINDOWS\system32\nvsvc32.exe
                              C:\Program Files\Spyware Doctor\pctsAuxs.exe
                              C:\Program Files\Messenger\msmsgs.exe
                              C:\Program Files\Spyware Doctor\pctsSvc.exe
                              C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              E:\Logiciels\Avast\ashMaiSv.exe
                              E:\Logiciels\Avast\ashWebSv.exe
                              C:\WINDOWS\System32\alg.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\notepad.exe
                              C:\Documents and Settings\Admin\Bureau\dss.exe
                              C:\PROGRA~1\TRENDM~1\HIJACK~1\Admin.exe
                              C:\WINDOWS\system32\wbem\wmiprvse.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O3 - Toolbar: (no name) - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - (no file)
                              O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                              O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
                              O4 - Global Startup: Adobe Gamma Loader.lnk = ?
                              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              O8 - Extra context menu item: Download Link Using Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Messager Wanadoo - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
                              O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - E:\Logiciels\Avast\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - E:\Logiciels\Avast\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - E:\Logiciels\Avast\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - E:\Logiciels\Avast\ashWebSv.exe
                              O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
                              O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                              O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                              O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                              O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                              O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                              0
                              1. Contributeur
                                bonsoir,

                                moi aussi tu voie je suis en retard...

                                fais ceci :

                                regarde ceci concernant avast :

                                antivir vs avast :

                                -> http://forum.malekal.com/ftopic3528.php

                                alors je te conseille de le desinstaller et d´installer antivir a la place

                                Telecharge et instales l'antivirus Antivir Personal Edition Classic :

                                ->https://www.malekal.com/avira-free-security-antivirus-gratuit/

                                https://www.avira.com/en/prime

                                http://mickael.barroux.free.fr/securite/antivir.php
                                http://speedweb1.free.fr/frames2.php?page=tuto5
                                <- tutoriel configuration du scanner...

                                une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
                                puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
                                coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
                                puis sur la droite coche les case suivantes :
                                scan boot sectors of selected drives
                                scan master boot sectors
                                scan memory
                                search foe rootkit before scan
                                decoche :
                                ignore off line files
                                toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

                                Je te dis tous ca car j´aimerais que tu performes un scan entier de ta machine a l´aide d´antivir avec les reglages stipulés ci dessus et que tu post le rapport généré ici stp

                                juste un conseil que j´espere tu appliqueras a la lettre...

                                @?
                                0
                                1. Avira AntiVir Personal
                                  Report file date: jeudi 1 mai 2008 14:59

                                  Scanning for 1245960 virus strains and unwanted programs.

                                  Licensed to: Avira AntiVir PersonalEdition Classic
                                  Serial number: 0000149996-ADJIE-0001
                                  Platform: Windows XP
                                  Windows version: (Service Pack 2) [5.1.2600]
                                  Boot mode: Normally booted
                                  Username: SYSTEM
                                  Computer name: XPSP2-D80C355D0

                                  Version information:
                                  BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
                                  AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
                                  AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
                                  LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
                                  LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
                                  ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
                                  ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
                                  ANTIVIR2.VDF : 7.0.3.197 1260032 Bytes 22/04/2008 12:48:15
                                  ANTIVIR3.VDF : 7.0.3.235 248832 Bytes 30/04/2008 12:48:19
                                  Engineversion : 8.1.0.37
                                  AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
                                  AESCRIPT.DLL : 8.1.0.28 233851 Bytes 01/05/2008 12:48:34
                                  AESCN.DLL : 8.1.0.15 119157 Bytes 01/05/2008 12:48:33
                                  AERDL.DLL : 8.1.0.20 418165 Bytes 01/05/2008 12:48:32
                                  AEPACK.DLL : 8.1.1.4 364918 Bytes 01/05/2008 12:48:30
                                  AEOFFICE.DLL : 8.1.0.18 192890 Bytes 01/05/2008 12:48:28
                                  AEHEUR.DLL : 8.1.0.21 1196407 Bytes 01/05/2008 12:48:27
                                  AEHELP.DLL : 8.1.0.14 115063 Bytes 01/05/2008 12:48:22
                                  AEGEN.DLL : 8.1.0.18 299381 Bytes 01/05/2008 12:48:21
                                  AEEMU.DLL : 8.1.0.5 430450 Bytes 07/04/2008 15:34:43
                                  AECORE.DLL : 8.1.0.27 168310 Bytes 01/05/2008 12:48:20
                                  AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
                                  AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
                                  AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
                                  AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
                                  AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                                  AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
                                  SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                                  SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
                                  NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                                  RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
                                  RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11

                                  Configuration settings for the scan:
                                  Jobname..........................: Complete system scan
                                  Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                                  Logging..........................: low
                                  Primary action...................: interactive
                                  Secondary action.................: ignore
                                  Scan master boot sector..........: on
                                  Scan boot sector.................: on
                                  Boot sectors.....................: C:, E:,
                                  Scan memory......................: on
                                  Process scan.....................: on
                                  Scan registry....................: on
                                  Search for rootkits..............: off
                                  Scan all files...................: All files
                                  Scan archives....................: on
                                  Recursion depth..................: 20
                                  Smart extensions.................: on
                                  Macro heuristic..................: on
                                  File heuristic...................: high

                                  Start of the scan: jeudi 1 mai 2008 14:59

                                  The scan of running processes will be started
                                  Scan process 'avscan.exe' - '1' Module(s) have been scanned
                                  Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
                                  Scan process 'kpf4gui.exe' - '1' Module(s) have been scanned
                                  Scan process 'kpf4ss.exe' - '1' Module(s) have been scanned
                                  Scan process 'firefox.exe' - '1' Module(s) have been scanned
                                  Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                                  Scan process 'emule.exe' - '1' Module(s) have been scanned
                                  Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                                  Scan process 'avguard.exe' - '1' Module(s) have been scanned
                                  Scan process 'sched.exe' - '1' Module(s) have been scanned
                                  Scan process 'alg.exe' - '1' Module(s) have been scanned
                                  Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
                                  Scan process 'realsched.exe' - '1' Module(s) have been scanned
                                  Scan process 'nSvcIp.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'pctsTray.exe' - '1' Module(s) have been scanned
                                  Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned
                                  Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned
                                  Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
                                  Scan process 'Apache.exe' - '1' Module(s) have been scanned
                                  Scan process 'nSvcLog.exe' - '1' Module(s) have been scanned
                                  Scan process 'NMSAccessU.exe' - '1' Module(s) have been scanned
                                  Scan process 'Apache.exe' - '1' Module(s) have been scanned
                                  Scan process 'explorer.exe' - '1' Module(s) have been scanned
                                  Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'svchost.exe' - '1' Module(s) have been scanned
                                  Scan process 'lsass.exe' - '1' Module(s) have been scanned
                                  Scan process 'services.exe' - '1' Module(s) have been scanned
                                  Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                                  Scan process 'csrss.exe' - '1' Module(s) have been scanned
                                  Scan process 'smss.exe' - '1' Module(s) have been scanned
                                  35 processes with 35 modules were scanned

                                  Starting master boot sector scan:
                                  Master boot sector HD0
                                  [INFO] No virus was found!

                                  Start scanning boot sectors:
                                  Boot sector 'C:\'
                                  [INFO] No virus was found!
                                  Boot sector 'E:\'
                                  [INFO] No virus was found!

                                  Starting to scan the registry.
                                  The registry was scanned ( '27' files ).

                                  Starting the file scan:

                                  Begin scan in 'C:\'
                                  C:\pagefile.sys
                                  [WARNING] The file could not be opened!
                                  C:\QooBox\Quarantine\catchme2008-04-05_114228.42.zip
                                  [0] Archive type: ZIP
                                  --> Documents and Settings/Admin/Bureau/catchme.zip
                                  [1] Archive type: ZIP
                                  --> olesvy.sys
                                  [DETECTION] Is the Trojan horse TR/Zapchast.DM
                                  [NOTE] The file was moved to '488dc350.qua'!
                                  C:\WINDOWS\system32\e0ju5vo6.dll
                                  [WARNING] The file could not be opened!
                                  C:\WINDOWS\system32\drivers\967mn7i.sys
                                  [WARNING] The file could not be opened!
                                  Begin scan in 'E:\'
                                  E:\Lys\Emule incomming\Manga Studio EX 3.0 serial keygen.zip
                                  [0] Archive type: ZIP
                                  --> efrontier Manga Studio EX 3.0.exe
                                  [DETECTION] Contains detection pattern of the dropper DR/Shelled.Gen
                                  [NOTE] The file was moved to '4887c827.qua'!

                                  End of the scan: jeudi 1 mai 2008 15:47
                                  Used time: 48:32 min

                                  The scan has been done completely.

                                  12535 Scanning directories
                                  326686 Files were scanned
                                  2 viruses and/or unwanted programs were found
                                  0 Files were classified as suspicious:
                                  0 files were deleted
                                  0 files were repaired
                                  2 files were moved to quarantine
                                  0 files were renamed
                                  3 Files cannot be scanned
                                  326684 Files not concerned
                                  7462 Archives were scanned
                                  3 Warnings
                                  2 Notes

                                  voilà voilà...

                                  Quand aux anti virus, j'ai du mal àtrouver celui qu'il faut parce que chacun y va de son petit avis personnel alors il n'est pas possible de savoir à qui se fier...
                                  0