Spyware secure

Bonjour,
Ma machine est infectée par spyware secure.Aidez moi à m'en débarraser svp.Merci
Voici le rapport

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:10:38, on 08/08/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\program files\rnamfler\naomf.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\program files\rnamfler\radprcmp.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\rnamfler\naofsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.com/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: (no name) - {0A94B111-4504-4e26-AB05-E61E474AA38B} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {F4D76F01-7896-458a-890F-E1F05C46069F} - (no file)
O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [wrna3ls] C:\program files\rnamfler\naomf.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.13\AMVConverter\grab.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.13\MediaManager\grab.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {AA59202C-5E41-48FC-AF7D-324F5FD6A9F1} -
O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: RdnaoFlSvc - Unknown owner - C:\Program Files\rnamfler\naofsvc.exe
O23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
O24 - Desktop Component 0: (no name) - http://us.js2.yimg.com/us.js.yimg.com/lib/pim/r/medici/16_11/mail/mailcommonlib.js

--
End of file - 7204 bytes
Configuration: Windows XP
Firefox 3.0.1

54 réponses

Résumé de la discussion

Une machine Windows est infectée par un spyware nommé Secure et l’utilisateur recherche des méthodes pour s’en débarrasser, après avoir fourni des rapports de HijackThis et des scans antivirus. Plusieurs éléments évoquent des nettoyages manuels et des recommandations pour désinfecter le système, notamment via des outils anti-malware et des nettoyages de disque, plus une éventuelle restauration système. Des propositions concrètes apparaissent: utilisation de Malwarebytes, nettoyage des éléments DLL et des clés de registre associées, et analyses en ligne avec BitDefender ou des tutoriels sur Zeb-Restore pour restaurer certains paramètres. Certaines solutions exigent des redémarrages et des privilèges élevés, et les résultats des analyses dépendent des outils utilisés et du niveau d'infection persistant dans le système.

Bobot (l’IA à votre service)
  1. spyware secure est un anti spyware pas un virus
    0
    1. Contributeur sécurité
      spyware secure est un anti spyware pas un virus
      --> FAUX !!!!

      spyware secure est un rogue ( = faux logiciel ) qui pourri ton PC de fausses alertes de sécurité ...

      C'est une salté ...

      Fais ce-ci pour commencer :

      Télécharges SmitfraudFix (de S!Ri, balltrap34 et moe31 ) :
      http://siri.urz.free.fr/Fix/SmitfraudFix.exe

      !! Déconnectes toi, fermes toute tes applications et désactives tes défenses ( anti-virus ,anti-spyware,...) le temps de la manipe !!

      Installes le soft à la racine de C\ ( et pas ailleurs! --->"C\:SmitfraudFix.exe" ) .

      Tuto ( aide ) : http://siri.urz.free.fr/Fix/SmitfraudFix.php

      Utilisation ---> option 1 / Recherche :
      Double clique sur l'icône "Smitfraudfix.exe" et sélectionnes 1 (et pas sur autre chose sans notre accord !) pour créer un rapport des fichiers responsables de l'infection.

      Postes le rapport ( "rapport.txt" qui se trouve sous C\: ) et attends la suite .

      (Attention : process.exe est détecté par certains antivirus comme étant un RiskTool. Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité.)

      0
    2. @sKe69MErci dem'avoir répondu . voici le rapport

      SmitFraudFix v2.333

      Rapport fait à 22:52:05,47, 08/08/2008
      Executé à partir de C:\Documents and Settings\xx\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      C:\program files\rnamfler\naomf.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\documents and settings\xx\local settings\application data\cagscuo.exe
      c:\program files\rnamfler\radprcmp.exe
      C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\rnamfler\naofsvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\system32\cmd.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\xx

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\xx\Application Data

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\xx\Favoris

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="http://us.js2.yimg.com/us.js.yimg.com/lib/pim/r/medici/16_11/mail/mailcommonlib.js"
      "SubscribedURL"="http://us.js2.yimg.com/us.js.yimg.com/lib/pim/r/medici/16_11/mail/mailcommonlib.js"
      "FriendlyName"=""

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"="sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll"
      "LoadAppInit_DLLs"=dword:00000001

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Rustock

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Contrôleur Fast Ethernet intégré 3Com 3C920 (compatible 3C905C-TX)
      DNS Server Search Order: 10.0.0.2

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{4F2170EC-19D8-43E7-B1AA-08BE855223FA}: DhcpNameServer=10.0.0.2
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{4F2170EC-19D8-43E7-B1AA-08BE855223FA}: DhcpNameServer=10.0.0.2
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{4F2170EC-19D8-43E7-B1AA-08BE855223FA}: DhcpNameServer=10.0.0.2
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
  2. Contributeur sécurité
    Bien ... la suite :

    Suite de la manipe ( nettoyage ), fais exactement ce qui suit :

    * Impératif : Redémarrer l'ordinateur en mode sans échec .
    Comment aller en Mode sans échec
    1) Redémarre ton ordi
    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
    3) Tu verras un écran avec options de démarrage apparaître
    4) Choisis la première option : Sans Échec, et valide avec "Entrée"
    5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
    ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copies ou imprimes bien les info ci-dessous ...)

    *Double click sur SmitfraudFix.exe

    * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

    * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presser Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

    ( Le correctif déterminera si le fichier wininet.dll est infecté.)

    * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
    pour remplacer le fichier corrompu.

    * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

    Le rapport se trouve à la racine de C\:
    (dans le fichier "rapport.txt")

    Postes moi ce dernier rapport accompagné, dans la même réponse, d'un nouveau rapport
    hijackthis ( fais en mode normal ) et attends les instructions ...
    0
    1. ici http://www.malekal.com/Adware.Magic_Control.php

      désolé je pensais que c'etait un anti spy
      0
      1. Contributeur sécurité
        Et oui ^^ ... bonne recherche ...
        0
    2. VOici le rapport

      SmitFraudFix v2.333

      Rapport fait à 23:12:29,57, 08/08/2008
      Executé à partir de C:\Documents and Settings\xx\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode sans echec

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      127.0.0.1 localhost

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

      S!Ri's WS2Fix: LSP not Found.

      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

      GenericRenosFix by S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{4F2170EC-19D8-43E7-B1AA-08BE855223FA}: DhcpNameServer=10.0.0.2
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{4F2170EC-19D8-43E7-B1AA-08BE855223FA}: DhcpNameServer=10.0.0.2
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{4F2170EC-19D8-43E7-B1AA-08BE855223FA}: DhcpNameServer=10.0.0.2
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=10.0.0.2

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

      Nettoyage terminé.

      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin

      la RApport hijackthis

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 23:26:24, on 08/08/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      C:\program files\rnamfler\naomf.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\WINDOWS\VM_STI.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      c:\program files\rnamfler\radprcmp.exe
      C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\rnamfler\naofsvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe

      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
      R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - (no file)
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
      O2 - BHO: (no name) - {0A94B111-4504-4e26-AB05-E61E474AA38B} - (no file)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O2 - BHO: (no name) - {F4D76F01-7896-458a-890F-E1F05C46069F} - (no file)
      O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [wrna3ls] C:\program files\rnamfler\naomf.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
      O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.13\AMVConverter\grab.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.13\MediaManager\grab.html
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
      O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
      O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
      O16 - DPF: {AA59202C-5E41-48FC-AF7D-324F5FD6A9F1} -
      O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
      O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: RdnaoFlSvc - Unknown owner - C:\Program Files\rnamfler\naofsvc.exe
      O23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
      0
      1. Contributeur sécurité
        Ok ...

        continuons

        Télécharges Navilog1 sur ton bureau :

        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

        !! Déconnectes toi,désactives tes défences( anti-virus,anti-spyware ) et fermes bien toutes tes applications le temps de la manipe !!

        Ensuite double clique sur navilog1.exe pour lancer l'installation.
        Une fois l'installation terminée, le fix s'exécutera automatiquement.
        (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

        Laisses-toi guider. Au menu principal, choisis 1 et valides.
        (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

        Patiente jusqu'au message :
        *** Analyse Termine le ..... ***

        Appuies sur une touche comme demandé, le bloc-note va s'ouvrir.
        Copie-colle l'intégralité de son contenu dans ta prochaine réponse et attends la suite .

        (Le rapport est en outre sauvegardé à la racine du disque "C\:fixnavi.txt" )

        TUTO (aide) : http://www.malekal.com/Adware.Magic_Control.php#mozTocId595901
        0
        1. oivi le rapport de navilog

          Search Navipromo version 3.6.2 commencé le 09/08/2008 à 0:00:40,98

          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1
          Session actuelle : "xx"

          Mise à jour le 07.08.2008 à 20h00 par IL-MAFIOSO

          Microsoft Windows XP [version 5.1.2600]
          Internet Explorer : 7.0.5730.13
          Système de fichiers : NTFS

          Recherche executé en mode normal

          *** Recherche Programmes installés ***

          *** Recherche dossiers dans "C:\WINDOWS" ***

          *** Recherche dossiers dans "C:\Program Files" ***

          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

          *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\xx\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\xx\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

          *** Recherche dossiers dans "C:\Documents and Settings\xx\menudm~1\progra~1" ***

          *** Recherche dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          Fichier(s) caché(s) :

          C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo.dat
          C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo.exe
          C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo_nav.dat
          C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo_navps.dat

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans "C:\WINDOWS\system32" *

          * Recherche dans "C:\Documents and Settings\xx\locals~1\applic~1" *

          Fichiers suspects :

          miuesmrer.exe trouvé !
          miuesmrer.exe trouvé !

          * Recherche dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

          *** Recherche fichiers ***

          C:\WINDOWS\Downloaded Program Files\IaLdr32.inf trouvé !

          *** Recherche clés spécifiques dans le Registre ***

          HKEY_CURRENT_USER\Software\Lanconfig trouvé !

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche nouveaux fichiers Instant Access :

          2)Recherche Heuristique :

          * Dans "C:\WINDOWS\system32" :

          hkcmrsf_navps.dat trouvé !

          * Dans "C:\Documents and Settings\xx\locals~1\applic~1" :

          * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" :

          3)Recherche Certificats :

          Certificat Egroup trouvé !
          Certificat Electronic-Group trouvé !
          Certificat OOO-Favorit trouvé !
          Certificat Sunny-Day-Design-Ltd absent !

          4)Recherche fichiers connus :

          *** Analyse terminée le 09/08/2008 à 0:09:15,05 ***
          0
          1. Contributeur sécurité
            Impec ... la suite :

            !! Déconnectes toi, désactives tes défences ( anti-virus,anti-spyware ) et fermes bien toutes tes applications le temps de la manipe !!

            --->Double-cliques sur le raccourci Navilog1

            Arriver au menu principal, choisir l'option 2 et valider (nettoyage "automatique" ).

            Le fix demandera ensuite de "redémarrer le PC", fermer toutes les fenêtres ouvertes
            et appuyer sur une touche comme demandé.( important : si le PC ne redémarre pas automatiquement, le faire manuellement )
            Au redémarrage du PC, choisir la session habituelle si nécessaire.

            Patienter jusqu'au message : "Nettoyage Terminé le ..."

            Le bureau revient, puis le bloc-note s'ouvre .
            Sauvegarder ce rapport de manière à le retrouver, puis fermer le bloc-note ...
            (Le rapport sera en outre sauvegardé à la racine du disque "C\:cleannavi.txt")

            Postes ce rapport dans ta nouvelle réponse accompagné d'un nouveau rapport hijacthis pour analyse et attends la suite ...

            (PS : Si le bureau ne réapparaît pas, faire CTRL+ALT+SUPPR pour ouvrir le gestionnaire de tâches.
            Choisir l'onglet processus. Cliquer en haut à gauche sur fichiers et choisir exécuter,
            Taper explorer et valider.)

            **************

            Postes moi les rapports demandés , je les analyserai demain ... pour moi , c'est l'heure d'aller dormir ;)

            A demain donc pour la suite ....
            0
            1. dernier rapport
              Clean Navipromo version 3.6.2 commencé le 09/08/2008 à 0:29:18,90

              Outil exécuté depuis C:\Program Files\navilog1
              Session actuelle : "xx"

              Mise à jour le 07.08.2008 à 20h00 par IL-MAFIOSO

              Microsoft Windows XP [version 5.1.2600]
              Internet Explorer : 7.0.5730.13
              Système de fichiers : NTFS

              Mode suppression automatique
              avec prise en charge résultats Catchme et GNS

              Nettoyage exécuté au redémarrage de l'ordinateur

              *** Creation backups fichiers trouvés par Catchme ***

              Copie vers "C:\Program Files\navilog1\Backupnavi"

              Copie C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo.dat réalisée avec succès !
              Copie C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo.exe réalisée avec succès !
              Copie C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo_nav.dat réalisée avec succès !
              Copie C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo_navps.dat réalisée avec succès !

              *** Suppression des fichiers trouvés avec Catchme ***

              C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo.dat supprimé !
              C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo.exe supprimé !
              C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo_nav.dat supprimé !
              C:\Documents and Settings\xx\Local Settings\Application Data\cagscuo_navps.dat supprimé !

              ** 2ème passage avec résultats Catchme **

              * Dans "C:\WINDOWS\system32" *

              * Dans "C:\Documents and Settings\xx\locals~1\applic~1" *

              *** Suppression avec sauvegardes résultats GenericNaviSearch ***

              * Suppression dans "C:\WINDOWS\System32" *

              * Suppression dans "C:\Documents and Settings\xx\locals~1\applic~1" *

              * Suppression dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

              *** Suppression dossiers dans "C:\WINDOWS" ***

              *** Suppression dossiers dans "C:\Program Files" ***

              *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

              *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

              *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

              *** Suppression dossiers dans "C:\Documents and Settings\xx\applic~1" ***

              *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\applic~1" ***

              *** Suppression dossiers dans "C:\Documents and Settings\xx\locals~1\applic~1" ***

              *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" ***

              *** Suppression dossiers dans "C:\Documents and Settings\xx\menudm~1\progra~1" ***

              *** Suppression dossiers dans "C:\DOCUME~1\ADMINI~1\menudm~1\progra~1" ***

              *** Suppression fichiers ***

              C:\WINDOWS\Downloaded Program Files\IaLdr32.inf supprimé !

              *** Suppression fichiers temporaires ***

              Nettoyage contenu C:\WINDOWS\Temp effectué !
              Nettoyage contenu C:\Documents and Settings\xx\locals~1\Temp effectué !

              *** Traitement Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

              2)Recherche, création sauvegardes et suppression Heuristique :

              * Dans "C:\WINDOWS\system32" *

              hkcmrsf_navps.dat trouvé !
              Copie hkcmrsf_navps.dat réalisée avec succès !
              hkcmrsf_navps.dat supprimé !

              * Dans "C:\Documents and Settings\xx\locals~1\applic~1" *

              * Dans "C:\DOCUME~1\ADMINI~1\locals~1\applic~1" *

              *** Sauvegarde du Registre vers dossier Safebackup ***

              sauvegarde du Registre réalisée avec succès !

              *** Nettoyage Registre ***

              Nettoyage Registre Ok

              *** Certificats ***

              Certificat Egroup supprimé !
              Certificat Electronic-Group supprimé !
              Certificat OOO-Favorit supprimé !
              Certificat Sunny-Day-Design-Ltdt absent !

              *** Fichiers suspects non supprimés par Navilog1 ***
              !! Fichiers légitimes possibles, à contrôler avant suppression !!

              Fichiers suspects dans "C:\Documents and Settings\xx\locals~1\applic~1" :

              miuesmrer.exe trouvé !

              miuesmrer.exe trouvé !

              *** Nettoyage terminé le 09/08/2008 à 0:35:09,99 ***

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 00:37:39, on 09/08/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
              C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\rnamfler\naofsvc.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\program files\rnamfler\naomf.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\WINDOWS\VM_STI.EXE
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              c:\program files\rnamfler\radprcmp.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
              R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - (no file)
              O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
              O2 - BHO: (no name) - {0A94B111-4504-4e26-AB05-E61E474AA38B} - (no file)
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
              O2 - BHO: (no name) - {F4D76F01-7896-458a-890F-E1F05C46069F} - (no file)
              O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [wrna3ls] C:\program files\rnamfler\naomf.exe
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
              O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.13\AMVConverter\grab.html
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
              O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.13\MediaManager\grab.html
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
              O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
              O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
              O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
              O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
              O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll
              O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
              O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
              O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: RdnaoFlSvc - Unknown owner - C:\Program Files\rnamfler\naofsvc.exe
              O23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
              0
              1. Contributeur sécurité
                Salut,

                fais ce-ci maintenant :

                1-Télécharges : - CCleaner
                https://www.pcastuces.com/logitheque/ccleaner.htm
                Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
                Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).

                Un tuto ( aide ):
                http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

                ---> Utilisation:
                vas dans "nettoyeur" : fait analyse puis nettoyage
                et vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

                ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

                2-Télécharges SDFix sur ton bureau :
                http://downloads.andymanchesta.com/RemovalTools/SDFix.exe.

                --->Double-cliques sur SDFix.exe et choisis "Install" .

                ( tuto ici : https://www.malekal.com/slenfbot-still-an-other-irc-bot/ )

                Puis une fois l'installe faite ,redémarres en mode sans échec .
                Comment aller en Mode sans échec :
                1) Redémarres ton ordi
                2) Tapotes la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                3) Tu verras un écran avec options de démarrage apparaître
                4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copies ou imprimes bien les info ci-dessous ...)

                Ouvres le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double cliques sur RunThis.bat pour lancer le script.
                --->Tapes Y pour lancer le script ...
                Le Fix supprime les services du virus et nettoie le registre, de ce fait un redémarrage est nécessaire , donc :
                presses une touche pour redémarrer quand il te le sera demandé .

                Le PC va mettre du temps avant de démarrer ( c'est normale ), après le chargement du Bureau presses une touche lorsque "Finished" s'affiche .

                Le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier C:\SDFix sous le nom "Report.txt".
                Postes ce dernier dans ta prochaine réponse accompagné d'un nouveau rapport Hijakcthis pour analyse ...
                0
                1. salut

                  [b]SDFix: Version 1.214 [/b]
                  Run by xx on 09/08/2008 at 13:24

                  Microsoft Windows XP [version 5.1.2600]
                  Running From: C:\SDFix

                  [b]Checking Services [/b]:

                  Restoring Default Security Values
                  Restoring Default Hosts File
                  Restoring Missing Security Center Service

                  Rebooting

                  [b]Checking Files [/b]:

                  Trojan Files Found:

                  C:\WINDOWS\search_res.txt - Deleted

                  Removing Temp Files

                  [b]ADS Check [/b]:

                  [b]Final Check [/b]:

                  catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-08-09 13:38:26
                  Windows 5.1.2600 Service Pack 2 NTFS

                  scanning hidden processes ...

                  scanning hidden services & system hive ...

                  scanning hidden registry entries ...

                  scanning hidden files ...

                  scan completed successfully
                  hidden processes: 0
                  hidden services: 0
                  hidden files: 0

                  [b]Remaining Services [/b]:

                  Authorized Application Key Export:

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                  "D:\\VLC\\vlc.exe"="D:\\VLC\\vlc.exe:*:Enabled:VLC media player"
                  "C:\\Program Files\\realplay.exe"="C:\\Program Files\\realplay.exe:*:Enabled:RealPlayer"
                  "C:\\Program Files\\Windows Media Player\\wmplayer.exe"="C:\\Program Files\\Windows Media Player\\wmplayer.exe:*:Enabled:Lecteur Windows Media"
                  "C:\\Program Files\\Paltalk Messenger\\paltalk.exe"="C:\\Program Files\\Paltalk Messenger\\paltalk.exe:*:Enabled:Paltalk 9.0"
                  "C:\\Program Files\\Google\\Google Talk\\googletalk.exe"="C:\\Program Files\\Google\\Google Talk\\googletalk.exe:*:Disabled:Google Talk"
                  "C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
                  "D:\\Podmailing\\podmailing.exe"="D:\\Podmailing\\podmailing.exe:*:Disabled:Podmailing Beta"
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                  "C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
                  "C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
                  "C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
                  "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
                  "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                  "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
                  "C:\\Documents and Settings\\xx\\Mes documents\\Downloads\\Music\\LimeWire\\LimeWire.exe"="C:\\Documents and Settings\\xx\\Mes documents\\Downloads\\Music\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                  "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
                  "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
                  "D:\\VeohClient.exe"="D:\\VeohClient.exe:*:Enabled:Veoh Client"
                  "C:\\WINDOWS\\system32\\rundll32.exe"="C:\\WINDOWS\\system32\\rundll32.exe:*:Enabled:Ex‚cuter une DLL en tant qu'application"
                  "C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
                  "D:\\eMule\\emule.exe"="D:\\eMule\\emule.exe:*:Enabled:eMule"
                  "D:\\bittorrent.exe"="D:\\bittorrent.exe:*:Enabled:BitTorrent"
                  "D:\\kazaa.exe"="D:\\kazaa.exe:*:Enabled:Kazaa"
                  "D:\\Temporary Internet Files\\Temporary Internet Files\\Content.IE5\\Q3XTDT8Z\\incredimail_install[1].exe"="D:\\Temporary Internet Files\\Temporary Internet Files\\Content.IE5\\Q3XTDT8Z\\incredimail_install[1].exe:*:Enabled:IncrediMail Installer"
                  "C:\\Program Files\\IncrediMail\\bin\\ImApp.exe"="C:\\Program Files\\IncrediMail\\bin\\ImApp.exe:*:Enabled:IncrediMail"
                  "C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
                  "C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
                  "C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"="C:\\Program Files\\MySpace\\IM\\MySpaceIM.exe:*:Enabled:MySpaceIM"
                  "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
                  "C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
                  "D:\\BitTorrent\\bittorrent.exe"="D:\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
                  "D:\\MEDIA\\Flashget\\flashget.exe"="D:\\MEDIA\\Flashget\\flashget.exe:*:Enabled:Flashget"
                  "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
                  "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                  "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                  "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                  [b]Remaining Files [/b]:

                  File Backups: - C:\SDFix\backups\backups.zip

                  [b]Files with Hidden Attributes [/b]:

                  Sat 7 Jul 2007 418,318 A..H. --- "C:\WINDOWS\system32\ne0kS.exe"
                  Sat 10 Nov 2007 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                  Thu 1 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                  Sun 20 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\0a67b6c406b1d7e0f5c1e6f6d44a3f6e\BIT2.tmp"
                  Sun 20 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\18b19374451d28a8fbaf1939cf31ff45\BIT5.tmp"
                  Sat 15 Dec 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\22fb973e059470cc1b5d76c4ae605351\BIT1.tmp"
                  Sun 20 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\26924cbc8132a10b438ce6e2b49d4652\BIT1.tmp"
                  Sun 20 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\2769b111678c52099a3b3123b12f2325\BIT6.tmp"
                  Sun 20 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\30285791903730fbf957a83562db4ff4\BIT3.tmp"
                  Wed 16 Jul 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\405ae8e48aa46e265982686e1678047b\BIT4.tmp"
                  Sat 22 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\778fd2fc3fe6b905e366b5ddbba384c8\BIT2.tmp"
                  Sat 22 Sep 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\8716c608174f1f63561ea4abedb6bf9b\BIT1.tmp"
                  Sun 20 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9e870549834e2bceb796e44a1e3ac6f5\BIT8.tmp"
                  Sat 19 Jan 2008 1,123,880 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\9ef9933da35bdbcb8d9cd93868ba3092\BITDA.tmp"
                  Thu 4 Oct 2007 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\b8426e25532eb668f59dd4d969b4a550\BIT1.tmp"
                  Sun 20 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\cb8921d0c7830b2f33c00fa4c8a10d17\BIT4.tmp"
                  Sun 20 Jan 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\d77b9b5b8fed23dd91f50d167cce60d3\BIT7.tmp"

                  [b]Finished![/b]

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 13:44:53, on 09/08/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\rnamfler\naofsvc.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\alg.exe
                  C:\WINDOWS\system32\notepad.exe
                  C:\program files\rnamfler\naomf.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\WINDOWS\VM_STI.EXE
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  c:\program files\rnamfler\radprcmp.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe

                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
                  R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - (no file)
                  O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
                  O2 - BHO: (no name) - {0A94B111-4504-4e26-AB05-E61E474AA38B} - (no file)
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                  O2 - BHO: (no name) - {F4D76F01-7896-458a-890F-E1F05C46069F} - (no file)
                  O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [wrna3ls] C:\program files\rnamfler\naomf.exe
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
                  O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.13\AMVConverter\grab.html
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.13\MediaManager\grab.html
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                  O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
                  O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                  O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
                  O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                  O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
                  O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll
                  O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: RdnaoFlSvc - Unknown owner - C:\Program Files\rnamfler\naofsvc.exe
                  O23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
                  0
                  1. Contributeur sécurité
                    Bien ...

                    Voilà la suite du programme :

                    Télécharges MalwareByte's :
                    ici ftp://ftp.commentcamarche.com/download/mbam-setup.exe
                    ou ici : http://www.malwarebytes.org/mbam.php

                    Installes le ( choisis bien "francais" ; ne modifies pas les paramètres d'installe ) et mets le à jour .

                    (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharges le ici : https://www.malekal.com/tutorial-aboutbuster/ )

                    Potasses le tuto pour te familiariser avec le prg : https://forum.pcastuces.com/sujet.asp?f=31&s=3
                    ( cela dis, il est très simple d'utilisation ).

                    Impératif : redémarres en mode sans échec :
                    Comment aller en Mode sans échec
                    1) Redémarres ton ordi
                    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                    3) Tu verras un écran avec options de démarrage apparaître
                    4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                    5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                    (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

                    Lances Malwarebyte's .

                    Fais un scan dit "complet" ( sélectionnes bien tout tes disks avant le scan ) et supprimes tout ce qu'il peut trouver :
                    --->une fois le scan terminé , click sur "résultat" : puis vérifies que tous les objets infectés soient validés, puis click sur " suppression " .

                    Redémarres ton PC ( mode normal ).

                    Postes le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes) accompagné d'un nouvel hijackthis ( fait en mode normal ) ...
                    0
                    1. Salut

                      voici le rappot de malwre

                      Malwarebytes' Anti-Malware 1.24
                      Version de la base de données: 1034
                      Windows 5.1.2600 Service Pack 2

                      14:49:08 09/08/2008
                      mbam-log-8-9-2008 (14-49-08).txt

                      Type de recherche: Examen complet (C:\|D:\|)
                      Eléments examinés: 74000
                      Temps écoulé: 40 minute(s), 52 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 1
                      Valeur(s) du Registre infectée(s): 1
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 0

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                      Valeur(s) du Registre infectée(s):
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully.

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      rapport hijackthis

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 14:57:21, on 09/08/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\csrss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                      C:\program files\rnamfler\naomf.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\WINDOWS\VM_STI.EXE
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      c:\program files\rnamfler\radprcmp.exe
                      C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\rnamfler\naofsvc.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\alg.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\WINDOWS\system32\NOTEPAD.EXE
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: (no name) - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
                      R3 - URLSearchHook: (no name) - {0A94B116-4504-4e26-AB05-E61E474AA38B} - (no file)
                      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
                      O2 - BHO: (no name) - {0A94B111-4504-4e26-AB05-E61E474AA38B} - (no file)
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                      O2 - BHO: (no name) - {F4D76F01-7896-458a-890F-E1F05C46069F} - (no file)
                      O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [wrna3ls] C:\program files\rnamfler\naomf.exe
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
                      O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.13\AMVConverter\grab.html
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
                      O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.13\MediaManager\grab.html
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                      O9 - Extra button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - C:\Program Files\Paltalk Messenger\Paltalk.exe (file missing)
                      O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
                      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
                      O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                      O18 - Filter hijack: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - (no file)
                      O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll
                      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: RdnaoFlSvc - Unknown owner - C:\Program Files\rnamfler\naofsvc.exe
                      O23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
                      0
                      1. Contributeur sécurité
                        très bien ...

                        il reste encore une bestiole :-/

                        fait exactement ce qui suit :

                        Télécharges ComboFix (par sUBs) sur ton Bureau (et pas ailleur !):
                        http://download.bleepingcomputer.com/sUBs/ComboFix.exe <--- clik droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix et valide .

                        --------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
                        !! déconnectes toi,fermes tes applications en cours et DESACTIVES TOUTES TES DEFENSES (anti-virus, guardes anti spy-ware, pare-feu) le temps de la manipe :
                        en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!
                        --->Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...
                        Tuto ( aide ) ici : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                        ---------------------------------------------------------------------------------------------------------------------------------

                        Ensuite :
                        double-cliques C-Fix.exe ( = combofix.exe ) .

                        Appuyes sur la touche Y (Yes) pour démarrer le scan .

                        Attention : n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.
                        ---> si un message d'erreur windows apparait à un momment : clik sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

                        Le rapport sera crée dans: C:\Combofix.txt

                        Postes le rapport Combofix accompagné d'un nouveau rapport hijackthis pour analyse ...
                        0
                        1. voici les rapports

                          ComboFix 08-08-08.08 - xx 2008-08-09 15:42:44.1 - NTFSx86
                          Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.190 [GMT 2:00]
                          Endroit: C:\Documents and Settings\xx\Bureau\ComboFix.exe

                          [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                          .

                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          C:\Documents and Settings\xx\err.log
                          C:\WA6P
                          C:\WINDOWS\smdat32m.sys
                          C:\WINDOWS\system32\drivers\npf.sys
                          C:\WINDOWS\system32\Packet.dll
                          C:\WINDOWS\system32\pthreadVC.dll
                          C:\WINDOWS\system32\stera.log
                          C:\WINDOWS\system32\WanPacket.dll
                          C:\WINDOWS\system32\wpcap.dll

                          .
                          ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          -------\Legacy_FOPN
                          -------\Legacy_NPF
                          -------\Legacy_VSPF
                          -------\Legacy_VSPF_HK
                          -------\Service_NPF

                          ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-09 to 2008-08-09 ))))))))))))))))))))))))))))))))))))
                          .

                          2008-08-09 15:07 . 2008-08-09 15:07 <REP> d-------- C:\Program Files\Avira
                          2008-08-09 15:07 . 2008-08-09 15:07 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
                          2008-08-09 14:01 . 2008-08-09 14:01 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                          2008-08-09 14:01 . 2008-08-09 14:01 <REP> d-------- C:\Documents and Settings\xx\Application Data\Malwarebytes
                          2008-08-09 14:01 . 2008-08-09 14:01 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                          2008-08-09 14:01 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
                          2008-08-09 14:01 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                          2008-08-09 13:19 . 2008-08-09 13:19 <REP> d-------- C:\WINDOWS\ERUNT
                          2008-08-09 13:12 . 2008-08-09 13:42 <REP> d----c--- C:\SDFix
                          2008-08-08 23:12 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
                          2008-08-08 23:12 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
                          2008-08-08 23:12 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
                          2008-08-08 23:12 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
                          2008-08-08 23:12 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
                          2008-08-08 23:12 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
                          2008-08-08 23:12 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
                          2008-08-08 23:12 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
                          2008-08-08 22:52 . 2008-08-08 23:45 1,560 --a------ C:\WINDOWS\system32\tmp.reg
                          2008-08-08 21:54 . 2008-08-08 21:54 <REP> d-------- C:\Program Files\Trend Micro
                          2008-08-05 21:46 . 2008-08-07 23:13 <REP> d-------- C:\Documents and Settings\xx\dwhelper
                          2008-08-05 14:13 . 2008-08-05 14:13 <REP> d-------- C:\Program Files\Zoom
                          2008-08-05 14:13 . 1999-08-10 19:21 598,528 --------- C:\WINDOWS\system32\Atx45.ocx
                          2008-08-05 14:13 . 2004-05-19 12:18 221,184 --------- C:\WINDOWS\system32\DartSock.dll
                          2008-08-05 14:13 . 2004-05-27 11:08 118,784 --------- C:\WINDOWS\system32\DartTelnet.dll
                          2008-08-05 14:13 . 2006-03-17 11:06 15,666 --------- C:\WINDOWS\wwdslcfg.ini
                          2008-08-05 13:35 . 2008-08-05 13:35 62,847 --a--c--- C:\Zoom.icfconfig routeur.icf
                          2008-08-04 14:08 . 2004-08-31 07:26 233,539 -ra------ C:\WINDOWS\system32\VM31bPrp.Ax
                          2008-08-04 14:08 . 2002-08-22 10:34 147,456 -ra------ C:\WINDOWS\VMCap.exe
                          2008-08-04 14:08 . 2004-09-07 10:11 90,568 -ra------ C:\WINDOWS\system32\drivers\usbVM31b.sys
                          2008-08-04 14:08 . 2003-05-15 11:17 61,440 -ra------ C:\WINDOWS\system32\VM31bSTI.dll
                          2008-08-04 14:08 . 2002-10-16 03:29 49,152 -ra------ C:\WINDOWS\amcap.exe
                          2008-08-04 14:08 . 2004-06-09 09:37 40,960 --a------ C:\WINDOWS\VM_STI.EXE
                          2008-08-04 06:31 . 2008-08-04 06:31 51,452 --ah----- C:\WINDOWS\system32\mlfcache.dat
                          2008-08-03 16:29 . 2008-08-03 16:30 <REP> d-------- C:\Program Files\Bandoo
                          2008-08-02 23:35 . 2008-08-02 23:36 <REP> d-------- C:\Documents and Settings\xx\Application Data\Apple Computer
                          2008-08-02 23:33 . 2008-08-02 23:33 <REP> d-------- C:\Program Files\Bonjour
                          2008-08-02 23:33 . 2008-08-02 23:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
                          2008-07-31 13:07 . 2008-07-31 13:07 <REP> d-------- C:\Documents and Settings\xx\Application Data\Yahoo!
                          2008-07-26 17:11 . 2008-07-26 17:11 244 --ah-c--- C:\sqmnoopt04.sqm
                          2008-07-26 17:11 . 2008-07-26 17:11 232 --ah-c--- C:\sqmdata04.sqm
                          2008-07-13 00:32 . 2008-07-13 00:32 565,170 --a------ C:\WINDOWS\system32\large.bnk
                          2008-07-13 00:32 . 2008-07-13 00:32 278,528 --a------ C:\WINDOWS\system32\livesnth.dll
                          2008-07-12 07:27 . 2008-07-12 07:27 <REP> d-------- C:\Documents and Settings\xx\Application Data\FlashGet

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2008-08-09 13:16 --------- d--h--r C:\Program Files\rnamfler
                          2008-08-08 22:35 --------- d-----w C:\Program Files\Navilog1
                          2008-08-06 05:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                          2008-08-05 12:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
                          2008-08-04 12:03 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
                          2008-08-01 18:29 --------- d-----w C:\Program Files\Yahoo!
                          2008-07-29 22:37 --------- d-----w C:\Documents and Settings\xx\Application Data\Skype
                          2008-07-23 12:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
                          2008-07-21 16:15 --------- d-----w C:\Program Files\DDFRA
                          2008-07-17 16:16 --------- d-----w C:\Program Files\Opera
                          2008-07-16 17:36 --------- d-----w C:\Program Files\Google
                          2008-07-12 05:09 --------- d-----w C:\Documents and Settings\xx\Application Data\BitTorrent
                          2008-06-30 20:23 --------- d-----w C:\Program Files\iMesh Applications
                          2008-06-29 11:08 --------- d-----w C:\Documents and Settings\xx\Application Data\iMesh
                          2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
                          2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
                          2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
                          2008-06-14 17:59 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
                          2008-06-12 15:48 --------- d-----w C:\Program Files\Spybot - Search & Destroy
                          2008-04-02 18:04 49,771 ----a-w C:\Program Files\Delacou.exe
                          2007-02-21 19:41 977,375 ----a-w C:\Program Files\realplay.chm
                          2007-02-19 16:19 14 ----a-w C:\Documents and Settings\xx\getfile.dat
                          .

                          ------- Sigcheck -------

                          2007-06-13 15:22 979456 80a5400514eb32d393654768c4017e46 C:\WINDOWS\explorer.exe
                          2007-06-13 15:22 1037312 d0288319660edcfed07c7e74c4ea38a5 C:\WINDOWS\system32\DllCache\explorer.exe
                          .
                          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          REGEDIT4
                          *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2005-07-09 21:39 15360]
                          "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-29 22:19 68856]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-02-21 21:40 185896]
                          "BigDogPath"="C:\WINDOWS\VM_STI.EXE" [2004-06-09 09:37 40960]
                          "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                          "WIAWizardMenu"="C:\WINDOWS\system32\sti_ci.dll" [2005-07-09 21:40 138240]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                          "NoDesktopCleanupWizard"= 1 (0x1)

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                          "ForceClassicControlPanel"= 1 (0x1)
                          "NoSMBalloonTip"= 0 (0x0)

                          [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
                          "ForceClassicControlPanel"= 1 (0x1)
                          "NoSMBalloonTip"= 0 (0x0)

                          [HKLM\~\startupfolder\C:^Documents and Settings^xx^Menu Démarrer^Programmes^Démarrage^UberIcon.lnk]
                          path=C:\Documents and Settings\xx\Menu Démarrer\Programmes\Démarrage\UberIcon.lnk
                          backup=C:\WINDOWS\pss\UberIcon.lnkStartup

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
                          --a------ 2008-01-11 22:16 39792 D:\Reader\reader_sl.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BigDogPath]
                          --a------ 2004-06-09 09:37 40960 C:\WINDOWS\VM_STI.EXE

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CoolSwitch]
                          --a------ 2002-03-19 18:30 45632 C:\WINDOWS\system32\TaskSwitch.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
                          --a------ 2005-07-09 21:39 15360 C:\WINDOWS\system32\ctfmon.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\System12]
                          --ah----- 2007-07-07 09:07 418318 C:\WINDOWS\system32\ne0kS.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
                          --a------ 2007-02-21 21:40 185896 C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WIAWizardMenu]
                          --a------ 2005-07-09 21:40 138240 C:\WINDOWS\system32\sti_ci.dll

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wrna3ls]
                          --a------ 2006-04-01 10:45 1253960 C:\Program Files\rnamfler\naomf.exe

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
                          "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                          "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                          "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          "SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                          "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                          "D:\\VLC\\vlc.exe"=
                          "C:\\Program Files\\realplay.exe"=
                          "C:\\WINDOWS\\system32\\sessmgr.exe"=
                          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                          "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                          "C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
                          "C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
                          "C:\\WINDOWS\\system32\\dpvsetup.exe"=
                          "C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"=
                          "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
                          "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=

                          R3 ZSMC302;VIMICRO USB PC Camera;C:\WINDOWS\system32\Drivers\usbVM31b.sys [2004-09-07 10:11]
                          S2 Bandoo Coordinator;Bandoo Coordinator;C:\PROGRA~1\Bandoo\Bandoo.exe [2008-06-26 18:31]
                          S2 FILESpy;FILESpy;C:C:\Program Files\Softwin\BitDefender8\filespy.sys []

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17ad4340-14a4-11dd-8123-000e50f11865}]
                          \Shell\Auto\command - wscript "Sex City.jpg.wsf"
                          \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript "Sex City.jpg.wsf"

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{31799a11-2b01-11dc-b68d-000e50f11865}]
                          \Shell\Auto\command - sxs.exe
                          \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL sxs.exe

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4f4f23b0-15c8-11dc-b5cb-000e50f11865}]
                          \Shell\AutoRun\command - F:\fooool.exe
                          \Shell\explore\Command - F:\fooool.exe
                          \Shell\open\Command - F:\fooool.exe

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5ba2a73e-b3a3-11db-b266-000e50f11865}]
                          \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Setup.pif

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b72b61e0-210d-11dd-8179-000e50f11865}]
                          \Shell\AutoRun\command - 8e9gmih.bat
                          \Shell\explore\Command - 8e9gmih.bat
                          \Shell\open\Command - 8e9gmih.bat

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{fe22e287-1368-11dc-b5b6-000e50f11865}]
                          \Shell\AutoRun\command - fooool.exe
                          \Shell\explore\Command - fooool.exe
                          \Shell\open\Command - fooool.exe

                          *Newly Created Service* - AVGIO
                          *Newly Created Service* - AVIPBB
                          *Newly Created Service* - SSMDRV
                          .
                          Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'

                          2007-12-14 C:\WINDOWS\Tasks\CCleaner.job
                          - D:\CCleaner\ccleaner.exe [2008-07-29 15:41]

                          2007-02-17 C:\WINDOWS\Tasks\MP Scheduled Quick Scan.job
                          - C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MpCmdRun.exe []
                          .
                          - - - - ORPHANS REMOVED - - - -

                          URLSearchHooks-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
                          URLSearchHooks-{0A94B116-4504-4e26-AB05-E61E474AA38B} - (no file)
                          WebBrowser-{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - (no file)
                          MSConfigStartUp-avgnt - C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
                          MSConfigStartUp-iymflm - c:\documents and settings\xx\local settings\application data\iymflm.exe
                          MSConfigStartUp-speedtouch - E:\speedtouch\WAN\PPPoE\setup.exe
                          MSConfigStartUp-SpeedTouch USB Diagnostics - C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
                          MSConfigStartUp-Windows update loader - C:\Windows\xpupdate.exe

                          .
                          ------- Supplementary Scan -------
                          .
                          FireFox -: Profile - C:\Documents and Settings\xx\Application Data\Mozilla\Firefox\Profiles\r67hgcbl.default\
                          FireFox -: prefs.js - STARTUP.HOMEPAGE - www.rewmi.com
                          FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava11.dll
                          FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava12.dll
                          FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava13.dll
                          FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava14.dll
                          FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJava32.dll
                          FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPJPI150.dll
                          FF -: plugin - C:\Program Files\Java\jre1.5.0\bin\NPOJI610.dll
                          FF -: plugin - C:\Program Files\Yahoo!\Common\npyaxmpb.dll
                          FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
                          FF -: plugin - D:\Reader\browser\nppdf32.dll

                          **************************************************************************

                          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2008-08-09 15:50:22
                          Windows 5.1.2600 Service Pack 2 NTFS

                          Balayage processus cach‚s ...

                          Balayage cach‚ autostart entries ...

                          Balayage des fichiers cach‚s ...

                          Scan termin‚ avec succŠs
                          Les fichiers cach‚s: 0

                          **************************************************************************
                          .
                          ------------------------ Other Running Processes ------------------------
                          .
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          .
                          **************************************************************************
                          .
                          Temps d'accomplissement: 2008-08-09 15:59:37 - machine was rebooted
                          ComboFix-quarantined-files.txt 2008-08-09 13:59:03

                          Pre-Run: 3,604,742,144 octets libres
                          Post-Run: 3,546,066,944 octets libres

                          242 --- E O F --- 2008-07-23 12:31:40

                          moLogfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 16:01:14, on 09/08/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\WINDOWS\VM_STI.EXE
                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\WINDOWS\explorer.exe
                          C:\WINDOWS\system32\notepad.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing)
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                          O3 - Toolbar: (no name) - {F4D76F09-7896-458a-890F-E1F05C46069F} - (no file)
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE VIMICRO USB PC Camera
                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                          O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\system32\sti_ci.dll,WiaCreateWizardMenu
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.13\AMVConverter\grab.html
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
                          O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.13\MediaManager\grab.html
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
                          O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
                          O16 - DPF: CabBuilder - http://ak.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
                          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                          O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
                          O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab
                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                          O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                          O23 - Service: Bandoo Coordinator - Discordia Limited - C:\PROGRA~1\Bandoo\Bandoo.exe
                          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: Uninterruptible Power Supply (UPS) - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
                          0
                          1. Contributeur sécurité
                            très bien ...

                            1- refais un coup de Ccleaner ( registre compris )

                            2- Rends toi sur ce site :

                            https://www.virustotal.com/gui/

                            Copies ce qui suit et colles le dans l'espace pour la recherche :
                            C:\documents and settings\xx\local settings\application data\iymflm.exe

                            Cliques sur Send File.

                            Un rapport va s'élaborer ligne à ligne.

                            Attends bien la fin ... Il doit comprendre la taille du fichier envoyé.

                            Sauvegarde le rapport avec le bloc-note.

                            Copies le dans ta prochaine réponse ...

                            ( Si VirusTotal indique que le fichier a déjà été analysé, clique sur le bouton Ré-analyse le fichier maintenant )

                            Fais de même pour :
                            C:\Windows\xpupdate.exe
                            F:\fooool.exe


                            ---> postes moi donc ces 3 rapports ( en précisant bien au début de chacuns à quel fichier ils correspondent ) et attends la suite ...

                            0
                            1. Contributeur sécurité
                              Pour aucun des 3 ?
                              0
                              1. Contributeur sécurité
                                voilà ce que tu vas faire ( dans l'ordre ) :

                                1- Télécharges OTMoveIt (de Old_Timer) sur ton Bureau (et pas ailleurs !).

                                http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
                                ou http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

                                * Impératif : Redémarrer l'ordinateur en mode sans échec .
                                Comment aller en Mode sans échec
                                1) Redémarre ton ordi
                                2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                                3) Tu verras un écran avec options de démarrage apparaître
                                4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                                5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                                ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copies ou imprimes bien les info ci-dessous ...)

                                clic double sur OTMoveIt.exe pour le lancer.
                                Copies ce qui trouve en citation ci-dessous :

                                C:\Windows\xpupdate.exe

                                et colles-la dans le cadre de gauche de OTMoveIt2 :
                                Paste standard List of Files/Folders to be moved.

                                cliques sur MoveIt! pour lancer la suppression.
                                le résultat apparaîtra dans le cadre Results.

                                cliques sur Exit pour fermer.

                                il te sera peut-être demandé de redémarrer le pc pour achever la suppression.
                                si c'est le cas acceptes par "Yes". Sinon , redémarres manuellement pour retourner
                                en mode normal ...

                                --->postes le rapport situé dans " C:\OTMoveIt\MovedFiles."

                                2- Télécharges RavAntivirus d'Evosla sur ton bureau :
                                http://ww25.evosla.com/compteur.php?soft=rav_antivirus

                                ! Déconnectes toi et fermes toutes tes applications en cours !

                                !!IMPORTANT : Si tu as une clé USB, disque dur externe, etc, branches-les à ton PC (sans les ouvrir) avant de lancer ce FIX !!

                                --->Fais un clic droit sur le fichier .ZIP : "Extraire tout" --> sur le Bureau

                                Puis doucle-cliques sur RAV.exe afin de lancer l'outil.

                                Une fois RAV ANTIVIRUS lancé, laisses le faire : il scanne automatiquement tout les lecteurs (disques dur et amovibles)

                                * Si il détecte une infection : un rapport s'établira --> sauvegardes le ...
                                * Sinon le soft affichera (rapidement) ce-ci "Votre Ordinateur est sain" --> dans ce cas , tu peux fermé le prg ...

                                Enfin ,tu retires tes disques amovibles et redémarres PC .

                                Puis postes le rapport si il y a infection ...

                                3- Télécharges DSS (Deckard's System Scanner de Deckard) sur ton Bureau :

                                http://www.techsupportforum.com/sectools/Deckard/dss.exe

                                !! Fermes toutes les applications en cours (très important, sinon l'ordi peut planter) !!

                                Double-clique sur DSS.exe pour lancer l'outil.
                                (S'il ne trouve pas HijackThis, clique sur Oui )

                                Clique sur OK à chaque fois que cela sera demandé.

                                Le scan peut durer un certain temps suivant les cas , sois patient ...

                                L'analyse finis, un fichier texte s'affichera --->postes ce rapport dans ta prochaine
                                réponse pour analyse ...

                                (Le rapport se trouve en outre ici : C:\Deckard\System Scanner\main.txt.)

                                Important : Si tu obtiens deux rapports ("main.txt" + "extra.txt") alors poste les deux stp.
                                Attention --> les rapports peuvent être long donc envoie chacun d'eux dans un poste différent (sinon il risque de manquer la fin).

                                0
                                1. Voici le rapport deMoveit
                                  File/Folder C:\Windows\xpupdate.exe not found.

                                  OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08092008_171928

                                  RAv n' rien donné
                                  0
                                  • 1
                                  • 2
                                  • 3