Virus :cryp fake av not cleanable

Résolu
Bonjour,
j ai un virus :cryp fake av not cleanable avec secuser et avast ne le voit pas ....quelqu un serai assez sympa pour m aider merci d avance
Configuration: Windows XP
Internet Explorer 7.0

18 réponses

  1. Contributeur
    Télécharge HijackThis ici :

    -> http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

    Tutoriel d´instalation : (Merci a Balltrap34 pour cette réalisation)

    -> http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

    -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    Post le rapport généré ici stp...
    0
    1. bon soir girly merci de maccorder un peu de temps voila le rapport:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:59:25, on 29/08/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\Mixer.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe
      C:\Program Files\Poste de Travail Sans Fil Labtec\MagicKey.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
      C:\Program Files\uTorrent\uTorrent.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
      O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Activer le Poste de Travail Sans Fil Labtec.lnk = C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe
      O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
      O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - https://www.f-secure.com/en/home/support
      O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
      O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - https://www.eset.com/
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
      O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
      O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
      0
      1. Contributeur
        samuel,

        moi non plus je ne voie rien...

        a part boonty etun plug de winanp inofenssif...

        passe ceci on va etre fixé :

        Télécharge combofix.exe (par sUBs) sur ton Bureau.

        -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

        -> Double clique combofix.exe.
        -> Tape sur la touche 1 (Yes) pour démarrer le scan.
        -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

        NOTE : Le rapport se trouve également ici : C:\Combofix.txt

        Avant d'utiliser ComboFix :

        -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

        -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

        Une fois fait, sur ton bureau double-clic sur Combofix.exe.

        - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

        /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

        - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

        - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

        -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

        -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

        -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

        @+
        0
        1. voila le rapport :
          ComboFix 08-08-29.01 - moi 2008-08-29 21:19:51.1 - [color=red][b]FAT32[/b][/color]x86
          Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.445 [GMT 2:00]
          Endroit: C:\Documents and Settings\moi\Mes documents\ComboFix.exe
          * Création d'un nouveau point de restauration

          [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
          C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
          C:\WINDOWS\Downloaded Program Files\setup.inf
          C:\WINDOWS\system32\_000005_.tmp.dll
          C:\WINDOWS\system32\ektedcpb.ini
          C:\WINDOWS\system32\MSINET.oca

          ----- BITS: Possible sites infectés -----

          http://freefile.kristopherw.us
          .
          ((((((((((((((((((((((((((((( Fichiers créés 2008-07-28 to 2008-08-29 ))))))))))))))))))))))))))))))))))))
          .

          2008-08-29 20:58 . 2008-08-29 20:58 <REP> d-------- C:\Program Files\Trend Micro
          2008-08-29 20:30 . 2008-08-29 20:30 <REP> d-------- C:\WINDOWS\AU_Temp
          2008-08-29 19:42 . 2008-08-29 19:41 23,249,241 --a------ C:\WINDOWS\LPT$VPN.507
          2008-08-29 19:41 . 2008-08-29 19:41 23,249,241 --a------ C:\WINDOWS\VPTNFILE.507
          2008-08-29 18:33 . 2008-08-29 18:33 <REP> d-------- C:\Program Files\SAV
          2008-08-29 18:33 . 2008-08-29 18:33 110,596 --a------ C:\WINDOWS\system32\msxml71.dll
          2008-08-29 15:16 . 2008-08-29 15:16 25 --a------ C:\WINDOWS\mixerdef.ini
          2008-08-29 15:06 . 2008-04-13 20:45 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys
          2008-08-29 15:06 . 2008-04-13 20:45 10,624 --a------ C:\WINDOWS\system32\dllcache\gameenum.sys
          2008-08-29 15:05 . 2002-01-28 10:16 1,228,800 -ra------ C:\WINDOWS\mixer.exe
          2008-08-29 15:05 . 2002-01-29 03:43 370,382 -ra------ C:\WINDOWS\system32\drivers\cmaudio.sys
          2008-08-29 15:05 . 2002-01-11 07:54 135,168 -ra------ C:\WINDOWS\cmuninst.exe
          2008-08-29 15:05 . 2001-11-12 04:38 32,768 -ra------ C:\WINDOWS\system32\cmnprop.dll
          2008-08-28 19:31 . 2008-08-28 19:31 169 --a------ C:\WINDOWS\RtlRack.ini
          2008-08-27 11:45 . 2008-08-27 11:45 <REP> d-------- C:\Program Files\MSN Messenger
          2008-08-27 10:56 . 2008-08-27 10:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SymplisIT
          2008-08-26 18:01 . 2008-08-26 18:01 <REP> d--hs---- C:\FOUND.052
          2008-08-24 19:41 . 2008-08-24 19:41 <REP> d--hs---- C:\FOUND.051
          2008-08-19 08:42 . 2008-08-19 08:42 <REP> d-------- C:\WINDOWS\system32\fr
          2008-08-19 08:42 . 2008-08-19 08:42 <REP> d-------- C:\WINDOWS\l2schemas
          2008-08-19 07:33 . 2008-04-14 04:33 200,704 --------- C:\WINDOWS\system32\napmontr.dll
          2008-08-19 07:32 . 2006-12-28 21:01 19,569 --a------ C:\WINDOWS\[u]0[/u]05444_.tmp
          2008-08-19 07:32 . 2008-04-14 04:10 2,524 --------- C:\WINDOWS\system32\pid.inf
          2008-08-15 08:36 . 2008-05-01 16:36 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
          2008-08-15 08:35 . 2008-04-11 21:05 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
          2008-07-31 20:44 . 2008-07-31 20:44 <REP> d-------- C:\Documents and Settings\moi\Application Data\Sony Corporation
          2008-07-31 20:41 . 2003-08-26 17:03 757,760 --a------ C:\WINDOWS\system32\CDDBUI.dll
          2008-07-31 20:41 . 2003-08-26 17:01 630,784 --a------ C:\WINDOWS\system32\CDDBControl.dll
          2008-07-31 20:41 . 2003-07-11 14:23 110,592 --a------ C:\WINDOWS\system32\CddbLangFR.dll
          2008-07-31 20:40 . 2008-07-31 20:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sony Corporation
          2008-07-31 20:39 . 2008-07-31 20:39 <REP> d-------- C:\Program Files\Sony
          2008-07-31 20:39 . 2008-07-31 20:39 <REP> d-------- C:\Program Files\Fichiers communs\Sony Shared
          2008-07-31 20:39 . 2001-10-24 16:00 524,288 --a------ C:\WINDOWS\system32\TDI-SonyOMG.dll
          2008-07-31 20:39 . 2001-10-24 16:00 2,271 --a------ C:\WINDOWS\system32\TDI-SonyOMG.sc

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-08-29 18:30 91,744 ----a-w C:\WINDOWS\BPMNT.dll
          2008-08-29 18:30 1,213,784 ----a-w C:\WINDOWS\vsapi32.dll
          2008-08-29 17:41 71,749 ----a-w C:\WINDOWS\hcextoutput.dll
          2008-08-29 17:41 333,576 ----a-w C:\WINDOWS\tsc.exe
          2008-08-26 22:39 12,642 ----a-w C:\Documents and Settings\moi\Application Data\wklnhst.dat
          2008-07-26 14:51 --------- d-----w C:\Program Files\Poste de Travail Sans Fil Labtec
          2008-07-23 15:30 --------- d-----w C:\Program Files\Windows Media Connect 2
          2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
          2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
          2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
          2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
          2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
          2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
          2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
          2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
          2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
          2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
          2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
          2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
          2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
          2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
          2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
          2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
          2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
          2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
          2008-07-07 20:28 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
          2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
          2008-06-24 16:44 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
          2008-06-24 08:28 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
          2008-06-23 09:21 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
          2008-06-23 09:21 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
          2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
          2008-06-21 05:23 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
          2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
          2008-06-20 17:47 247,808 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
          2008-06-20 17:47 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
          2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
          2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
          2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
          2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
          2007-06-09 13:02 58,272 ----a-w C:\Documents and Settings\moi\Application Data\GDIPFONTCACHEV1.DAT
          .

          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
          "{de44fda9-805d-413c-8322-65a08f7c99b9}"= "C:\Program Files\fullanimes.free.fr\tbful1.dll" [2008-03-03 07:42 1470488]

          [HKEY_CLASSES_ROOT\clsid\{de44fda9-805d-413c-8322-65a08f7c99b9}]

          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{de44fda9-805d-413c-8322-65a08f7c99b9}]
          2008-03-03 07:42 1470488 --a------ C:\Program Files\fullanimes.free.fr\tbful1.dll

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
          "{de44fda9-805d-413c-8322-65a08f7c99b9}"= "C:\Program Files\fullanimes.free.fr\tbful1.dll" [2008-03-03 07:42 1470488]

          [HKEY_CLASSES_ROOT\clsid\{de44fda9-805d-413c-8322-65a08f7c99b9}]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
          "{DE44FDA9-805D-413C-8322-65A08F7C99B9}"= "C:\Program Files\fullanimes.free.fr\tbful1.dll" [2008-03-03 07:42 1470488]

          [HKEY_CLASSES_ROOT\clsid\{de44fda9-805d-413c-8322-65a08f7c99b9}]

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:34 15360]
          "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 18:41 1832272]
          "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 16:38 78008]
          "SoundMan"="SOUNDMAN.EXE" [2003-09-23 02:09 57344 C:\WINDOWS\SOUNDMAN.EXE]
          "C-Media Mixer"="Mixer.exe" [2002-01-28 10:16 1228800 C:\WINDOWS\mixer.exe]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 04:34 15360]

          C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
          HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]
          Activer le Poste de Travail Sans Fil Labtec.lnk - C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe [2008-07-26 16:51:50 253952]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
          "VIDC.YV12"= yv12vfw.dll

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "C:\\Program Files\\Messenger\\msmsgs.exe"=
          "C:\\StubInstaller.exe"=
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
          "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
          "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
          "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
          "C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
          "C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
          "C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
          "C:\\Program Files\\LimeWire\\LimeWire.exe"=
          "C:\\Program Files\\uTorrent\\uTorrent.exe"=
          "C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
          "C:\\Program Files\\MSN Messenger\\MSNMSGR.EXE"=
          "C:\\Program Files\\MSN Messenger\\livecall.exe"=

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
          "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

          R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
          R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2002-10-15 14:48]
          R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
          R3 C4C_BSC2;C4C_BSC2;C:\WINDOWS\system32\DRIVERS\C4C_BSC2.sys [2002-07-08 19:32]
          R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 20:45]
          S3 amdtools;AMD Special Tools Driver;C:\WINDOWS\system32\DRIVERS\AmdTools.sys []
          S3 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe []
          S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2007-05-02 11:11]
          S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2007-05-02 11:11]
          S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2007-05-02 11:11]
          S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 20:45]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
          hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
          \Shell\Auto\command - msnmsgr_plus.exe
          \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL msnmsgr_plus.exe

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d6a2f22-e677-11da-9fa2-806d6172696f}]
          \Shell\AutoRun\command - D:\autorun.exe

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{327b964a-51b4-11dd-82fd-003054c37b0c}]
          \Shell\Auto\command - msnmsgr_plus.exe
          \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL msnmsgr_plus.exe

          *Newly Created Service* - CATCHME
          *Newly Created Service* - PROCEXP90
          .
          Contenu du dossier 'Scheduled Tasks/Tâches planifiées'

          2008-08-29 C:\WINDOWS\Tasks\User_Feed_Synchronization-{A1584641-0D50-4433-BE61-7A3F6D9FBD6C}.job
          - C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 11:58]

          2008-08-29 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
          - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
          .
          .
          ------- Supplementary Scan -------
          .
          FireFox -: Profile - C:\Documents and Settings\moi\Application Data\Mozilla\Firefox\Profiles\pixslb5u.default\
          FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://lo.st
          FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://french.icrfast.com/index.php?rvs=hompag
          FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://french.icrfast.com/index.php?rvs=hompag
          FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://french.icrfast.com/index.php?rvs=hompag
          .

          **************************************************************************

          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-08-29 21:23:03
          Windows 5.1.2600 Service Pack 3 FAT NTAPI

          Balayage processus cachés ...

          Balayage caché autostart entries ...

          Balayage des fichiers cachés ...

          Scan terminé avec succès
          Les fichiers cachés: 0

          **************************************************************************
          .
          Temps d'accomplissement: 2008-08-29 21:23:43
          ComboFix-quarantined-files.txt 2008-08-29 19:23:42

          Pre-Run: 35,163,013,120 octets libres
          Post-Run: 35,201,777,664 octets libres

          204 --- E O F --- 2008-08-20 07:04:46
          0
          1. o fait girly combofix et un antivir ou un nettoyeur de registre ,c est juste par curriositee merci
            0
            1. Contributeur
              passe celui la encore :

              Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
              http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
              Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
              • Redémarre ton ordinateur
              • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
              • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
              • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
              • Choisis ton compte.
              Déroule la liste des instructions ci-dessous :
              • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
              • Appuie sur Y pour commencer le processus de nettoyage.
              • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
              • Appuie sur une touche pour redémarrer le PC.
              • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
              • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
              • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
              • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
              • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

              @+
              0
              1. Contributeur
                combofix est un nettoyeur bien particulier, il a beaucoup de malware dans sa base de donnée, là je peux voir; c´est pour cela que je te demande de passer sdfix, pour affiner...
                0
                1. voila girly le rapport de sd:

                  [b]SDFix: Version 1.220 [/b]
                  Run by moi on 29/08/2008 at 21:45

                  Microsoft Windows XP [version 5.1.2600]
                  Running From: C:\SDFix

                  [b]Checking Services [/b]:

                  Restoring Default Security Values
                  Restoring Default Hosts File

                  Rebooting

                  [b]Checking Files [/b]:

                  Trojan Files Found:

                  C:\WINDOWS\SYSTEM32\55073.EXE - Deleted
                  C:\WINDOWS\system32\msxml71.dll - Deleted

                  Removing Temp Files

                  [b]ADS Check [/b]:

                  [b]Final Check [/b]:

                  catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-08-29 21:51:50
                  Windows 5.1.2600 Service Pack 3 FAT NTAPI

                  scanning hidden processes ...

                  scanning hidden services ...

                  scanning hidden autostart entries ...

                  scanning hidden files ...

                  scan completed successfully
                  hidden processes: 0
                  hidden services: 0
                  hidden files: 0

                  [b]Remaining Services [/b]:

                  Authorized Application Key Export:

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                  "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
                  "C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                  "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"="C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
                  "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"="C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword"
                  "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"="C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss"
                  "C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
                  "C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
                  "C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
                  "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                  "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
                  "C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"="C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe:*:Enabled:avast! Antivirus"
                  "C:\\Program Files\\MSN Messenger\\MSNMSGR.EXE"="C:\\Program Files\\MSN Messenger\\MSNMSGR.EXE:*:Enabled:Windows Live Messenger 8.1"
                  "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                  "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                  "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
                  "C:\\Program Files\\MSN Messenger\\MSNMSGR.EXE"="C:\\Program Files\\MSN Messenger\\MSNMSGR.EXE:*:Enabled:Windows Live Messenger 8.1"
                  "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                  [b]Remaining Files [/b]:

                  File Backups: - C:\SDFix\backups\backups.zip

                  [b]Files with Hidden Attributes [/b]:

                  Wed 17 May 2006 1,024 ...HR --- "C:\WINDOWS\system32\NTICDMK32.dll"
                  Mon 22 May 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                  Fri 29 Aug 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
                  Fri 4 May 2007 20 A..H. --- "C:\Documents and Settings\Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
                  Mon 22 May 2006 4,348 ...H. --- "C:\Documents and Settings\Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
                  Wed 28 Jun 2006 400 A.SH. --- "C:\Documents and Settings\Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"

                  [b]Finished![/b]

                  et celui d hijack :
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 21:53:14, on 29/08/2008
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\notepad.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\WINDOWS\Mixer.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\MSN Messenger\msnmsgr.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe
                  C:\Program Files\Poste de Travail Sans Fil Labtec\MagicKey.exe
                  C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  R3 - URLSearchHook: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
                  O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O2 - BHO: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                  O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                  O3 - Toolbar: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
                  O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: Activer le Poste de Travail Sans Fil Labtec.lnk = C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe
                  O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                  O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                  O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O14 - IERESET.INF: START_PAGE_URL=https://www.acer.com/worldwide/selection.html
                  O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - https://www.f-secure.com/en/home/support
                  O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
                  O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - https://www.eset.com/
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                  O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
                  O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
                  O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
                  0
                  1. Contributeur
                    je me disais bien aussi :)

                    maintenant plus long

                    Fais un scan avec cet antispyware :

                    Telecharge malwarebytes + tutoriel :

                    -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                    Tu l´instale; le programme va se mettre automatiquement a jour.

                    Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

                    Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

                    Puis click sur "rechercher".

                    Laisse le scanner le pc...

                    Si des elements on ete trouvés > click sur supprimer la selection.

                    si il t´es demandé de redemarrer > click sur "yes".

                    A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

                    Copie et colle le rapport stp.

                    @+
                    0
                    1. voila le rapport girly :
                      Malwarebytes' Anti-Malware 1.25
                      Version de la base de données: 1096
                      Windows 5.1.2600 Service Pack 3

                      22:53:21 29/08/2008
                      mbam-log-08-29-2008 (22-53-21).txt

                      Type de recherche: Examen complet (C:\|K:\|)
                      Eléments examinés: 158446
                      Temps écoulé: 39 minute(s), 51 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 1
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 2

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Adware.Agent) -> Quarantined and deleted successfully.

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      C:\Program Files\SAV\sav0.dat (Rogue.SystemAntivirus) -> Quarantined and deleted successfully.
                      C:\Program Files\SAV\sav1.dat (Rogue.SystemAntivirus) -> Quarantined and deleted successfully.
                      0
                      1. on dirai que tou est propre faut il redemarer sans restauration de systeme ?
                        merci
                        0
                        1. non parler trop vite secuser en a trouve encore 2 mais ne peux rien en faire
                          s il y a encore quelqu unn debout pour maider merci
                          0
                          1. Contributeur
                            Salut,

                            repost un nouveau rapport hijack this stp

                            @+
                            0
                            1. comment ces tu le virus que tu a si ton anti-virus ne le trouve pas?
                              0