Probleme avec micro av antivirus

Bonjour,
y'a des fenetres qui sorte pour me dire d'analyser mon pc j'ai utiliser mon antivirus mais sa marche pas aider moi svp
Configuration: Windows Vista
Firefox 2.0.0.16

26 réponses

Résumé de la discussion

Des virus et des logiciels indésirables perturbent l’ordinateur sous Windows Vista et Windows XP, affichant des fenêtres d’alerte et des redirections, et nécessitent une détection approfondie via des outils spécialisés. Plusieurs utilisateurs recommandent des scans avec Malwarebytes ou HijackThis et des nettoyages avancés comme SmitFraudFix ou Lop S&D, suivis de redémarrages en mode sans échec et de rapports à partager. Les réponses documentent des infections telles que Trojans et Rogue.MicroAntivirus, avec des éléments à supprimer, des services à désactiver et des clés de registre à nettoyer, selon les outils employés. Enfin, certains échanges indiquent qu’un seul outil peut ne pas suffire et qu’une approche multi-outils avec des rapports permettra d’évaluer les restes d’infection et d’améliorer la sécurité.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut,

    - Télécharge HijackThis V 2.02 (HijackThis Installer) :
    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

    - Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

    - Clique sur Install ensuite sur I Accept

    - Clique sur Do a scan system and save log file

    - Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 16:57:16, on 12/09/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16711)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Windows\RtHDVCpl.exe
      C:\Users\asma\AppData\Local\Temp\RtkBtMnt.exe
      C:\Program Files\Launch Manager\LManager.exe
      C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
      C:\Acer\Empowering Technology\eAudio\eAudio.exe
      C:\Windows\System32\igfxtray.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\Apoint2K\Apoint.exe
      C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
      C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\SweetIM\Messenger\SweetIM.exe
      C:\Windows\System32\YUR2F3A.exe
      C:\Windows\System32\YURD1A.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Skype\Phone\Skype.exe
      C:\Program Files\Apoint2K\ApMsgFwd.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Eset\nod32kui.exe
      C:\Users\asma\AppData\Roaming\Adobe\Manager.exe
      C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
      C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
      C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
      C:\Windows\system32\igfxext.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
      C:\Program Files\Skype\Plugin Manager\skypePM.exe
      C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
      C:\Program Files\Eset\nod32.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Internet Explorer\IEUser.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
      O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
      O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
      O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
      O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
      O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
      O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
  2. Modérateur
    Le rapport n'est pas complet.
    0
    1. Modérateur
      Quand tu copies/colles le rapport, fais bien attention de le prendre entièrement.
      0
      1. Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 16:57:16, on 12/09/2008
        Platform: Windows Vista (WinNT 6.00.1904)
        MSIE: Internet Explorer v7.00 (7.00.6000.16711)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\Windows\RtHDVCpl.exe
        C:\Users\asma\AppData\Local\Temp\RtkBtMnt.exe
        C:\Program Files\Launch Manager\LManager.exe
        C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
        C:\Acer\Empowering Technology\eAudio\eAudio.exe
        C:\Windows\System32\igfxtray.exe
        C:\Windows\System32\hkcmd.exe
        C:\Windows\System32\igfxpers.exe
        C:\Program Files\Apoint2K\Apoint.exe
        C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
        C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\Program Files\Common Files\Real\Update_OB\realsched.exe
        C:\Program Files\SweetIM\Messenger\SweetIM.exe
        C:\Windows\System32\YUR2F3A.exe
        C:\Windows\System32\YURD1A.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Skype\Phone\Skype.exe
        C:\Program Files\Apoint2K\ApMsgFwd.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Eset\nod32kui.exe
        C:\Users\asma\AppData\Roaming\Adobe\Manager.exe
        C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
        C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
        C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
        C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Apoint2K\Apntex.exe
        C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
        C:\Windows\system32\igfxext.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
        C:\Program Files\Skype\Plugin Manager\skypePM.exe
        C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
        C:\Program Files\Eset\nod32.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Internet Explorer\IEUser.exe
        C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Windows\system32\igfxsrvc.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
        O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
        O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
        O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
        O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
        O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
        O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
        O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
        O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
        0
        1. Modérateur
          Bon, tant pis.

          ---> Désactive l'UAC le temps de la désinfection :
          https://www.zebulon.fr/astuces/pratique/220-desactiver-l-uac-dans-vista.html

          - Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31) :
          http://siri.urz.free.fr/Fix/SmitfraudFix.exe ou http://www.geekstogo.com/forum/files/file/6-smitfraudfix/

          - Enregistre-le sur le bureau

          - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée

          - Un rapport sera généré, poste-le dans ta prochaine réponse.

          [*] process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus.[*]

          ** Ne fais l'étape 2 que si on te le demande, on doit d'abord examiner le premier rapport de SmitfraudFix
          0
          1. Bonjour, j'ai le meme probleme avec micro av peux tu m'aider? voici le rapport et merci d'avance!

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 02:27:05, on 25/09/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16705)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
            C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
            C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            C:\Program Files\Norton AntiVirus\navapsvc.exe
            C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
            C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\WINDOWS\ehome\ehtray.exe
            C:\Program Files\Java\jre1.5.0\bin\jusched.exe
            C:\WINDOWS\system32\igfxtray.exe
            C:\WINDOWS\system32\hkcmd.exe
            C:\WINDOWS\system32\igfxpers.exe
            C:\Program Files\Analog Devices\Core\smax4pnp.exe
            C:\WINDOWS\system32\igfxsrvc.exe
            C:\WINDOWS\AGRSMMSG.exe
            C:\WINDOWS\eHome\ehmsas.exe
            C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\PROGRA~1\CYBERL~1\INSTAN~1\Win2K\IBurn.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
            C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
            C:\WINDOWS\VM_STI.EXE
            C:\Windows\system32\YUR32.exe
            C:\Windows\system32\YUR33.exe
            C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
            C:\Windows\system32\YUR35.exe
            C:\WINDOWS\system32\igfxext.exe
            C:\Windows\system32\YUR36.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            C:\Program Files\DNA\btdna.exe
            C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
            C:\PROGRA~1\WIDCOMM\LOGICI~1\BTSTAC~1.EXE
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
            C:\Program Files\Internet Explorer\IEXPLORE.EXE
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
            O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
            O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
            O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
            O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
            O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
            O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
            O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\CYBERL~1\INSTAN~1\Win2K\IBurn.exe
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [MagicKeyboard] C:\Program Files\SAMSUNG\MagicKBD\PreMKBD.exe
            O4 - HKLM\..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DMLoader.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Vimicro USB PC Camera (VC0305)
            O4 - HKLM\..\Run: [\YUR32.exe] C:\Windows\system32\YUR32.exe
            O4 - HKLM\..\Run: [\YUR33.exe] C:\Windows\system32\YUR33.exe
            O4 - HKLM\..\Run: [\YUR34.exe] C:\Windows\system32\YUR34.exe
            O4 - HKLM\..\Run: [\YUR35.exe] C:\Windows\system32\YUR35.exe
            O4 - HKLM\..\Run: [ANTIVIRUS] C:\Program Files\MicroAV\MicroAV.exe
            O4 - HKLM\..\Run: [\YUR36.exe] C:\Windows\system32\YUR36.exe
            O4 - HKLM\..\Run: [6ce03cab] rundll32.exe "C:\WINDOWS\system32\kwalwkrm.dll",b
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [\YUR1.exe] C:\Windows\system32\YUR1.exe
            O4 - HKLM\..\Run: [\YUR2.exe] C:\Windows\system32\YUR2.exe
            O4 - HKLM\..\Run: [\YUR3.exe] C:\Windows\system32\YUR3.exe
            O4 - HKLM\..\Run: [\YUR4.exe] C:\Windows\system32\YUR4.exe
            O4 - HKLM\..\Run: [\YUR8.exe] C:\Windows\system32\YUR8.exe
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [Power2GoExpress] NA
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
            O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_1_0
            O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
            O4 - HKCU\..\Run: [\YUR32.exe] C:\Windows\system32\YUR32.exe
            O4 - HKCU\..\Run: [\YUR33.exe] C:\Windows\system32\YUR33.exe
            O4 - HKCU\..\Run: [\YUR34.exe] C:\Windows\system32\YUR34.exe
            O4 - HKCU\..\Run: [\YUR35.exe] C:\Windows\system32\YUR35.exe
            O4 - HKCU\..\Run: [ANTIVIRUS] C:\Program Files\MicroAV\MicroAV.exe
            O4 - HKCU\..\Run: [\YUR36.exe] C:\Windows\system32\YUR36.exe
            O4 - HKCU\..\Run: [\YUR1.exe] C:\Windows\system32\YUR1.exe
            O4 - HKCU\..\Run: [\YUR2.exe] C:\Windows\system32\YUR2.exe
            O4 - HKCU\..\Run: [\YUR3.exe] C:\Windows\system32\YUR3.exe
            O4 - HKCU\..\Run: [\YUR4.exe] C:\Windows\system32\YUR4.exe
            O4 - HKCU\..\Run: [\YUR8.exe] C:\Windows\system32\YUR8.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: BTTray.lnk = ?
            O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
            O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
            O20 - AppInit_DLLs: gnmvfo.dll
            O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
            O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
            O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
            O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
            O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
            O23 - Service: SRS PostInstaller Service (SRS_PostInstaller) - SRS Labs, Inc. - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
            0
        2. salut je n'arrive pas à écouter les sons sur mon pc comment faire pour remedier à cela? merci d'avance
          0
          1. j'arrive pas a obtenir des analyse je fai 1 mais sa me sort rien
            0
            1. mitFraudFix v2.349

              Scan done at 19:40:21,91, 12/09/2008
              Run from C:\Users\asma\Desktop\SmitfraudFix
              OS: Microsoft Windows [version 6.0.6000] - Windows_NT
              The filesystem type is NTFS
              Fix run in normal mode

              »»»»»»»»»»»»»»»»»»»»»»»» Process

              C:\Windows\system32\csrss.exe
              C:\Windows\system32\wininit.exe
              C:\Windows\system32\csrss.exe
              C:\Windows\system32\winlogon.exe
              C:\Windows\system32\services.exe
              C:\Windows\system32\lsass.exe
              C:\Windows\system32\lsm.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\SLsvc.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\spoolsv.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
              C:\Windows\RtHDVCpl.exe
              C:\Program Files\Launch Manager\LManager.exe
              C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
              C:\Acer\Empowering Technology\eAudio\eAudio.exe
              C:\Windows\System32\igfxtray.exe
              C:\Windows\System32\hkcmd.exe
              C:\Windows\System32\igfxpers.exe
              C:\Program Files\Apoint2K\Apoint.exe
              C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
              C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
              C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
              C:\Program Files\ESET\nod32kui.exe
              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
              C:\Program Files\SweetIM\Messenger\SweetIM.exe
              C:\Windows\System32\YUR2F3A.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Skype\Phone\Skype.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Users\asma\AppData\Roaming\Adobe\Manager.exe
              C:\Program Files\MicroAV\MicroAV.exe
              C:\Windows\System32\YURD1A.exe
              C:\Windows\System32\rundll32.exe
              C:\Windows\System32\rundll32.exe
              C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
              C:\Windows\system32\cmd.exe
              C:\Windows\system32\igfxsrvc.exe
              C:\Program Files\Apoint2K\ApMsgFwd.exe
              C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
              C:\Acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
              C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
              C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
              C:\Acer\ALaunch\ALaunchSvc.exe
              C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
              C:\Windows\system32\svchost.exe
              C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
              C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
              C:\Acer\Empowering Technology\eNet\eNet Service.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
              C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
              C:\Acer\Mobility Center\MobilityService.exe
              C:\Program Files\Eset\nod32krn.exe
              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Windows\System32\svchost.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Windows\system32\svchost.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
              C:\Users\asma\AppData\Local\Temp\RtkBtMnt.exe
              C:\Program Files\CyberLink\Shared Files\RichVideo.exe
              C:\Program Files\Apoint2K\Apntex.exe
              C:\Windows\system32\igfxext.exe
              C:\Windows\system32\svchost.exe
              C:\Windows\System32\svchost.exe
              C:\Windows\system32\SearchIndexer.exe
              C:\Windows\system32\DRIVERS\xaudio.exe
              C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
              C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
              C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
              C:\Windows\system32\wbem\wmiprvse.exe
              C:\Windows\system32\wbem\unsecapp.exe
              C:\Program Files\Mozilla Firefox\firefox.exe

              »»»»»»»»»»»»»»»»»»»»»»»» hosts

              »»»»»»»»»»»»»»»»»»»»»»»» C:\

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

              C:\Windows\system32\1.ico FOUND !
              C:\Windows\system32\2.ico FOUND !
              C:\Windows\system32\MicroAV.cpl FOUND !

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\asma

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\asma\Application Data

              »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\asma\FAVORI~1

              »»»»»»»»»»»»»»»»»»»»»»»» Desktop

              »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

              C:\Program Files\PCHealthCenter\ FOUND !

              »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

              »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
              !!!Attention, following keys are not inevitably infected!!!

              IEDFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» VACFix
              !!!Attention, following keys are not inevitably infected!!!

              VACFix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
              !!!Attention, following keys are not inevitably infected!!!

              404Fix
              Credits: Malware Analysis & Diagnostic
              Code: S!Ri

              »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
              !!!Attention, following keys are not inevitably infected!!!

              »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
              !!!Attention, following keys are not inevitably infected!!!

              SrchSTS.exe by S!Ri
              Search SharedTaskScheduler's .dll

              »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
              !!!Attention, following keys are not inevitably infected!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
              "AppInit_DLLs"="eNetHook.dll"
              "LoadAppInit_DLLs"=dword:00000001

              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
              !!!Attention, following keys are not inevitably infected!!!

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
              "Userinit"="C:\\Windows\\system32\\userinit.exe,"

              »»»»»»»»»»»»»»»»»»»»»»»» RK

              »»»»»»»»»»»»»»»»»»»»»»»» DNS

              Description: Carte réseau Broadcom 802.11g
              DNS Server Search Order: 89.2.0.1
              DNS Server Search Order: 89.2.0.2

              HKLM\SYSTEM\CCS\Services\Tcpip\..\{70E7CF6F-28BE-40B9-A8BF-4FFBB19AD06A}: DhcpNameServer=89.2.0.1 89.2.0.2

              »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

              »»»»»»»»»»»»»»»»»»»»»»»» End
              0
              1. Modérateur
                - Redémarre ton ordinateur en mode sans échec :
                https://blog.sosordi.net/

                - Double-clique sur SmitfraudFix.exe, choisis l'option 2 et Entrée

                - Réponds O(oui) à ces deux questions si elles te sont posées

                Voulez-vous nettoyer le registre ?
                Corriger le fichier infecté ?

                - Un rapport sera généré, sauvegarde-le sur le bureau

                - Redémarre en mode normal

                - Poste le rapport SmitfraudFix
                0
                1. SmitFraudFix v2.349

                  Scan done at 20:03:44,54, 12/09/2008
                  Run from C:\Users\asma\Desktop\SmitfraudFix
                  OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                  The filesystem type is NTFS
                  Fix run in normal mode

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                  !!!Attention, following keys are not inevitably infected!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  127.0.0.1 localhost
                  ::1 localhost

                  »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                  VACFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                  S!Ri's WS2Fix: LSP not Found.

                  »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                  GenericRenosFix by S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                  IEDFix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                  404Fix
                  Credits: Malware Analysis & Diagnostic
                  Code: S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                  »»»»»»»»»»»»»»»»»»»»»»»» RK

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  Description: Carte réseau Broadcom 802.11g
                  DNS Server Search Order: 89.2.0.1
                  DNS Server Search Order: 89.2.0.2

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{70E7CF6F-28BE-40B9-A8BF-4FFBB19AD06A}: DhcpNameServer=89.2.0.1 89.2.0.2

                  »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, following keys are not inevitably infected!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                  »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                  Registry Cleaning not selected.

                  »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                  !!!Attention, following keys are not inevitably infected!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  »»»»»»»»»»»»»»»»»»»»»»»» End
                  0
                  1. Modérateur
                    ---> Fais un scan rapide avec MBAM, supprime tout ce qu'il trouve et poste le rapport :
                    http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
                    0
                    1. Malwarebytes' Anti-Malware 1.28
                      Version de la base de données: 1142
                      Windows 6.0.6000

                      12/09/2008 20:53:07
                      mbam-log-2008-09-12 (20-53-07).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 43889
                      Temps écoulé: 15 minute(s), 27 second(s)

                      Processus mémoire infecté(s): 2
                      Module(s) mémoire infecté(s): 2
                      Clé(s) du Registre infectée(s): 9
                      Valeur(s) du Registre infectée(s): 28
                      Elément(s) de données du Registre infecté(s): 1
                      Dossier(s) infecté(s): 1
                      Fichier(s) infecté(s): 13

                      Processus mémoire infecté(s):
                      C:\Windows\System32\YURC6E6.exe (Trojan.FakeAlert) -> Unloaded process successfully.
                      C:\Users\asma\AppData\Roaming\Adobe\Manager.exe (Trojan.Agent) -> Unloaded process successfully.

                      Module(s) mémoire infecté(s):
                      C:\Users\asma\AppData\Local\Temp\fccdbYQh.dll (Trojan.Vundo) -> Delete on reboot.
                      C:\Windows\System32\mmx55363.dll (Trojan.FakeAlert) -> Delete on reboot.

                      Clé(s) du Registre infectée(s):
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ae0ddef1-8907-46e7-9ab3-5a4a19dde1a0} (Trojan.BHO.H) -> Delete on reboot.
                      HKEY_CLASSES_ROOT\CLSID\{ae0ddef1-8907-46e7-9ab3-5a4a19dde1a0} (Trojan.BHO.H) -> Delete on reboot.
                      HKEY_CLASSES_ROOT\TypeLib\{5a0e9afe-1370-306a-961a-74b9daba606e} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{5610df2f-e68e-3419-9826-60cbc835c0d5} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\CLSID\{209bae3c-528b-369c-b9e8-2264becad722} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{209bae3c-528b-369c-b9e8-2264becad722} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\MicroAV (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.

                      Valeur(s) du Registre infectée(s):
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurc6e6.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurc6e6.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurb856.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurb856.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\run (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur2f3a.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurd1a.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurf6ad.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur7edf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur2f3a.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurd1a.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur9971.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur758c.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur758d.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yure204.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur1756.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur9423.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurda18.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurc042.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur2fb7.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yurf6ad.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\yur7edf.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.host-domain-lookup.com (Malware.Trace) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully.

                      Elément(s) de données du Registre infecté(s):
                      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\users\asma\appdata\local\temp\fccdbyqh -> Delete on reboot.

                      Dossier(s) infecté(s):
                      C:\Program Files\MicroAV (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.

                      Fichier(s) infecté(s):
                      C:\Users\asma\AppData\Local\Temp\fccdbYQh.dll (Trojan.BHO.H) -> Delete on reboot.
                      C:\Windows\System32\YURC6E6.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\Windows\System32\YURB856.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\Windows\System32\mmx55363.dll (Trojan.FakeAlert) -> Delete on reboot.
                      C:\Windows\System32\mx55363.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\x (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\Program Files\MicroAV\MicroAV.cpl (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.
                      C:\Program Files\MicroAV\MicroAV.exe (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.
                      C:\Program Files\MicroAV\MicroAV.ooo (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.
                      C:\Program Files\MicroAV\MicroAV0.dat (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.
                      C:\Program Files\MicroAV\MicroAV1.dat (Rogue.MicroAntivirus) -> Quarantined and deleted successfully.
                      C:\Users\asma\AppData\Roaming\Adobe\Manager.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                      C:\Windows\17PHolmes2000206.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
                      0
                      1. Modérateur
                        ---> Supprime SmitFraudFix

                        ---> Relance MBAM, va dans Quarantaine et supprime tout

                        ---> Poste un nouveau rapport HijackThis
                        0
                        1. Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 21:09:02, on 12/09/2008
                          Platform: Windows Vista (WinNT 6.00.1904)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16711)
                          Boot mode: Normal

                          Running processes:
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Program Files\Windows Defender\MSASCui.exe
                          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                          C:\Windows\RtHDVCpl.exe
                          C:\Program Files\Launch Manager\LManager.exe
                          C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
                          C:\Acer\Empowering Technology\eAudio\eAudio.exe
                          C:\Windows\System32\igfxtray.exe
                          C:\Windows\System32\hkcmd.exe
                          C:\Windows\System32\igfxpers.exe
                          C:\Program Files\Apoint2K\Apoint.exe
                          C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
                          C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                          C:\Program Files\SweetIM\Messenger\SweetIM.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Program Files\Skype\Phone\Skype.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                          C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
                          C:\Windows\system32\igfxsrvc.exe
                          C:\Program Files\Apoint2K\ApMsgFwd.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Acer\Empowering Technology\ENET\ENMTRAY.EXE
                          C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                          C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                          C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
                          C:\Users\asma\AppData\Local\Temp\RtkBtMnt.exe
                          C:\Program Files\Apoint2K\Apntex.exe
                          C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
                          C:\Windows\system32\igfxext.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
                          C:\Program Files\Skype\Plugin Manager\skypePM.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                          O1 - Hosts: ::1 localhost
                          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                          O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Windows\system32\ActiveToolBand.dll
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
                          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                          O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                          O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                          O4 - HKLM\..\Run: [eAudio] "C:\Acer\Empowering Technology\eAudio\eAudio.exe"
                          O4 - HKLM\..\Run: [ALaunch] C:\Acer\ALaunch\AlaunchClient.exe
                          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                          O4 - HKLM\..\Run: [PLFSet] rundll32.exe C:\Windows\PLFSet.dll,PLFDefSetting
                          O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe"
                          O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                          O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                          O4 - HKLM\..\Run: [SetPanel] C:\Acer\APanel\APanel.cmd
                          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                          O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
                          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          O4 - HKCU\..\Run: [Yahoo! Pager] ~"C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
                          O4 - HKCU\..\Run: [Bags Else Hole Lite] "C:\ProgramData\Barb Seek Plan.9gstkea"
                          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                          O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_0
                          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                          O4 - HKCU\..\Run: [Free nurb] "C:\ProgramData\Chic Dale Dale.m22eq"
                          O4 - HKCU\..\Run: [Four file program mode] "C:\ProgramData\tick that bits.s60za"
                          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                          O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                          O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
                          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                          O4 - Global Startup: Empowering Technology Launcher.lnk = ?
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                          O13 - Gopher Prefix:
                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                          O20 - AppInit_DLLs: eNetHook.dll
                          O23 - Service: ALaunch Service (ALaunchService) - Unknown owner - C:\Acer\ALaunch\ALaunchSvc.exe
                          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                          O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                          O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                          O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
                          O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                          O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                          O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                          O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
                          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                          O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                          0
                          1. Modérateur
                            ---> Télécharge Lop S&D sur ton Bureau
                            https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/LopSD.exe?attachauth=ANoY7co3ntqUavpZ3q1BG-h4pc13vqDZmhcNeEPChtsyrgAykRbhE8bZzhk979EfQD4AgwtQUHCaQ7ZQwNYMo3_0kA8htAspckDJtu2K5t6J9z6dLW4fpZyH4FpFL1tVMBZ8H-KnN7afZ5vt-WxZRpnynk-a0XmV_Y0C0q6DxGEDKie1TnPT7gFoZnoCnspzBmbW6ZzxA4fNr3oEDlbelNZON-LjF8nOmQ%3D%3D&attredirects=2
                            ---> Double-clique dessus pour lancer l'installation
                            ---> Puis double-clique sur le raccourci Lop S&D présent sur ton Bureau
                            ---> Séléctionne la langue souhaitée, puis choisis l'option 1 (Recherche)
                            ---> Patiente jusqu'à la fin du scan
                            ---> Poste le rapport généré (C:\lopR.txt)
                            0
                            1. --------------------\\ Lop S&D 4.2.4-2 XP/Vista

                              Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6000 )
                              X86-based PC ( Multiprocessor Free : Intel(R) Celeron(R) M CPU 520 @ 1.60GHz )
                              BIOS : Ver 1.00PARTTBL
                              USER : asma ( Administrator )
                              BOOT : Normal boot
                              Antivirus : Norton Internet Security 2007 (Activated)
                              Firewall : Norton Internet Security 2007 (Activated)

                              "C:\Lop SD" ( MAJ : 08-09-2008|21:40 )
                              Option : [1] ( 12/09/2008|21:16 )

                              [ UAC => 1 ]

                              --------------------\\ Listing des dossiers dans Local

                              [17/11/2007|22:39] C:\Users\asma\AppData\Local\Acer Arcade Deluxe
                              [17/11/2007|12:09] C:\Users\asma\AppData\Local\acer eNM
                              [22/11/2007|14:06] C:\Users\asma\AppData\Local\Adobe
                              [17/11/2007|12:07] C:\Users\asma\AppData\Local\Application Data
                              [16/06/2008|18:52] C:\Users\asma\AppData\Local\d3d9caps.dat
                              [11/09/2008|18:42] C:\Users\asma\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
                              [17/02/2008|19:56] C:\Users\asma\AppData\Local\eMule
                              [25/12/2007|17:13] C:\Users\asma\AppData\Local\ESET
                              [14/05/2008|14:25] C:\Users\asma\AppData\Local\GDIPFONTCACHEV1.DAT
                              [16/02/2008|20:15] C:\Users\asma\AppData\Local\Google
                              [17/11/2007|12:07] C:\Users\asma\AppData\Local\Historique
                              [12/09/2008|20:55] C:\Users\asma\AppData\Local\IconCache.db
                              [22/05/2008|14:24] C:\Users\asma\AppData\Local\Microsoft
                              [29/12/2007|22:08] C:\Users\asma\AppData\Local\Microsoft Games
                              [19/12/2007|15:00] C:\Users\asma\AppData\Local\Microsoft Help
                              [23/11/2007|12:46] C:\Users\asma\AppData\Local\MigWiz
                              [23/11/2007|12:30] C:\Users\asma\AppData\Local\Mozilla
                              [17/11/2007|12:08] C:\Users\asma\AppData\Local\PlayMovie
                              [17/11/2007|22:38] C:\Users\asma\AppData\Local\PowerCinema
                              [12/09/2008|21:14] C:\Users\asma\AppData\Local\Temp
                              [17/11/2007|12:07] C:\Users\asma\AppData\Local\Temporary Internet Files
                              [15/12/2007|11:44] C:\Users\asma\AppData\Local\VirtualStore

                              --------------------\\ Tâches planifiées dans C:\Windows\tasks

                              [12/09/2008 20:56][--ah-----] C:\Windows\tasks\SA.DAT
                              [12/09/2008 20:55][--a------] C:\Windows\tasks\SCHEDLGU.TXT

                              --------------------\\ Listing des dossiers dans C:\ProgramData

                              [18/05/2007|20:25] C:\ProgramData\{174892B1-CBE7-44F5-86FF-AB555EFD73A3}
                              [18/05/2007|18:53] C:\ProgramData\Adobe
                              [02/11/2006|14:02] C:\ProgramData\Application Data
                              [10/09/2008|09:17] C:\ProgramData\Bags Browse Face
                              [13/02/2008|19:44] C:\ProgramData\Barb Seek Plan.9gstkea
                              [17/11/2007|12:02] C:\ProgramData\Bureau
                              [01/02/2008|13:22] C:\ProgramData\Chic Dale Dale.653244
                              [28/12/2007|22:40] C:\ProgramData\Chic Dale Dale.6gvvh73
                              [10/09/2008|09:16] C:\ProgramData\Chic Dale Dale.a6vbcn
                              [29/04/2008|18:53] C:\ProgramData\Chic Dale Dale.co1f2
                              [12/05/2008|16:29] C:\ProgramData\Chic Dale Dale.fixuhns
                              [13/02/2008|19:43] C:\ProgramData\Chic Dale Dale.gel9k08
                              [03/01/2008|11:00] C:\ProgramData\Chic Dale Dale.j6gyzz
                              [10/09/2008|09:16] C:\ProgramData\Chic Dale Dale.m22eq
                              [18/11/2007|15:56] C:\ProgramData\CyberLink
                              [02/11/2006|14:02] C:\ProgramData\Desktop
                              [02/11/2006|14:02] C:\ProgramData\Documents
                              [17/02/2008|19:58] C:\ProgramData\eMule
                              [25/12/2007|11:27] C:\ProgramData\ESET
                              [16/02/2008|20:20] C:\ProgramData\ezsid.dat
                              [17/11/2007|12:02] C:\ProgramData\Favoris
                              [02/11/2006|14:02] C:\ProgramData\Favorites
                              [10/09/2008|09:17] C:\ProgramData\Ford drive four file
                              [05/05/2008|17:16] C:\ProgramData\Google
                              [18/11/2007|16:06] C:\ProgramData\hpzinstall.log
                              [24/05/2008|21:08] C:\ProgramData\Iso Web Bags Else
                              [25/12/2007|19:00] C:\ProgramData\LUUnInstall.LiveUpdate
                              [12/09/2008|20:18] C:\ProgramData\Malwarebytes
                              [17/11/2007|12:02] C:\ProgramData\Menu D‚marrer
                              [28/12/2007|22:43] C:\ProgramData\Messenger Plus!
                              [14/05/2008|09:54] C:\ProgramData\Microsoft
                              [11/09/2008|12:06] C:\ProgramData\Microsoft Help
                              [17/11/2007|12:02] C:\ProgramData\ModŠles
                              [16/02/2008|20:15] C:\ProgramData\Skype
                              [02/11/2006|14:02] C:\ProgramData\Start Menu
                              [30/04/2008|12:12] C:\ProgramData\SweetIM
                              [25/12/2007|19:00] C:\ProgramData\Symantec
                              [02/11/2006|14:02] C:\ProgramData\Templates
                              [10/09/2008|09:17] C:\ProgramData\tick that bits.s60za
                              [07/05/2008|18:35] C:\ProgramData\WLInstaller
                              [08/02/2008|20:29] C:\ProgramData\Yahoo!
                              [12/09/2008|19:44] C:\ProgramData\Yahoo! Companion

                              --------------------\\ Listing des dossiers dans C:\Program Files

                              [21/07/2007|17:44] C:\Program Files\Acer Arcade Deluxe
                              [21/07/2007|17:38] C:\Program Files\ACER Crystal Eye webcam
                              [18/05/2007|18:52] C:\Program Files\Acer GameZone
                              [21/07/2007|17:46] C:\Program Files\Acer Inc
                              [18/05/2007|20:25] C:\Program Files\Activation Assistant for the 2007 Microsoft Office suites
                              [18/05/2007|18:52] C:\Program Files\Adobe
                              [20/11/2007|20:37] C:\Program Files\Alwil Software
                              [21/07/2007|17:39] C:\Program Files\Apoint2K
                              [18/05/2007|18:36] C:\Program Files\Broadcom
                              [23/04/2008|16:01] C:\Program Files\CambridgeSoft
                              [12/09/2008|17:05] C:\Program Files\CCleaner
                              [23/04/2008|16:21] C:\Program Files\chemoffice
                              [28/12/2007|22:39] C:\Program Files\Circle Developement
                              [23/04/2008|11:59] C:\Program Files\Common Files
                              [18/05/2007|18:36] C:\Program Files\CONEXANT
                              [18/05/2007|18:43] C:\Program Files\CyberLink
                              [17/02/2008|19:56] C:\Program Files\eMule
                              [12/09/2008|18:04] C:\Program Files\ESET
                              [17/11/2007|12:02] C:\Program Files\Fichiers communs [C:\Program Files\Common Files]
                              [05/05/2008|19:02] C:\Program Files\Google
                              [14/03/2008|21:00] C:\Program Files\InstallShield Installation Information
                              [18/05/2007|18:33] C:\Program Files\Intel
                              [11/09/2008|12:06] C:\Program Files\Internet Explorer
                              [23/04/2008|15:30] C:\Program Files\ISIS Draw 2.3
                              [31/03/2008|21:59] C:\Program Files\Java
                              [18/05/2007|18:38] C:\Program Files\Launch Manager
                              [12/09/2008|20:18] C:\Program Files\Malwarebytes' Anti-Malware
                              [10/09/2008|21:37] C:\Program Files\Messenger Plus! Live
                              [02/11/2006|13:37] C:\Program Files\Microsoft Games
                              [14/05/2008|09:55] C:\Program Files\Microsoft Office
                              [14/05/2008|09:56] C:\Program Files\Microsoft Visual Studio
                              [14/05/2008|09:46] C:\Program Files\Microsoft Visual Studio 8
                              [10/09/2008|09:23] C:\Program Files\Microsoft Works
                              [18/05/2007|20:22] C:\Program Files\Microsoft.NET
                              [02/11/2006|13:42] C:\Program Files\Movie Maker
                              [11/09/2008|22:16] C:\Program Files\Mozilla Firefox
                              [14/05/2008|09:57] C:\Program Files\MSBuild
                              [02/11/2006|13:37] C:\Program Files\MSN
                              [26/11/2007|22:02] C:\Program Files\MSXML 4.0
                              [18/05/2007|18:42] C:\Program Files\NewTech Infosystems
                              [19/12/2007|15:26] C:\Program Files\OpenOffice.org 2.3
                              [29/12/2007|18:07] C:\Program Files\Real
                              [18/05/2007|18:34] C:\Program Files\Realtek
                              [02/11/2006|13:37] C:\Program Files\Reference Assemblies
                              [16/02/2008|20:15] C:\Program Files\Skype
                              [21/07/2007|17:38] C:\Program Files\SUYIN
                              [05/05/2008|17:22] C:\Program Files\SweetIM
                              [25/12/2007|18:59] C:\Program Files\Symantec
                              [12/09/2008|16:47] C:\Program Files\Trend Micro
                              [02/11/2006|14:01] C:\Program Files\Uninstall Information
                              [11/09/2008|20:03] C:\Program Files\uTorrent
                              [26/11/2007|22:20] C:\Program Files\Windows Calendar
                              [02/11/2006|13:42] C:\Program Files\Windows Collaboration
                              [26/11/2007|22:20] C:\Program Files\Windows Defender
                              [02/11/2006|13:42] C:\Program Files\Windows Journal
                              [15/12/2007|11:41] C:\Program Files\Windows Live
                              [11/09/2008|11:47] C:\Program Files\Windows Mail
                              [26/11/2007|22:20] C:\Program Files\Windows Media Player
                              [17/11/2007|12:02] C:\Program Files\Windows NT
                              [02/11/2006|13:42] C:\Program Files\Windows Photo Gallery
                              [13/01/2008|12:24] C:\Program Files\Windows Sidebar
                              [24/12/2007|21:51] C:\Program Files\WinRAR
                              [08/02/2008|18:01] C:\Program Files\Yahoo!

                              --------------------\\ Listing des dossiers dans C:\Program Files\Common Files

                              [18/05/2007|18:53] C:\Program Files\Common Files\Adobe
                              [18/05/2007|20:22] C:\Program Files\Common Files\DESIGNER
                              [18/05/2007|18:41] C:\Program Files\Common Files\InstallShield
                              [19/12/2007|15:23] C:\Program Files\Common Files\Java
                              [18/05/2007|18:42] C:\Program Files\Common Files\LightScribe
                              [23/04/2008|11:59] C:\Program Files\Common Files\MDL Shared
                              [14/05/2008|09:57] C:\Program Files\Common Files\microsoft shared
                              [18/05/2007|18:42] C:\Program Files\Common Files\muvee Technologies
                              [18/05/2007|18:42] C:\Program Files\Common Files\NewTech Infosystems
                              [18/05/2007|18:49] C:\Program Files\Common Files\Oberon Media
                              [29/12/2007|18:08] C:\Program Files\Common Files\Real
                              [02/11/2006|12:18] C:\Program Files\Common Files\Services
                              [16/02/2008|20:15] C:\Program Files\Common Files\Skype
                              [21/07/2007|17:38] C:\Program Files\Common Files\snp2uvc
                              [02/11/2006|12:18] C:\Program Files\Common Files\SpeechEngines
                              [25/12/2007|19:23] C:\Program Files\Common Files\Symantec Shared
                              [14/05/2008|09:45] C:\Program Files\Common Files\System
                              [15/12/2007|11:40] C:\Program Files\Common Files\WindowsLiveInstaller
                              [29/12/2007|18:08] C:\Program Files\Common Files\xing shared

                              --------------------\\ Process

                              ( 90 Processes )

                              iexplore.exe ~ [PID:2280]
                              iexplore.exe ~ [PID:2292]

                              --------------------\\ Recherche avec S_Lop

                              C:\ProgramData\Chic Dale Dale.co1f2
                              C:\ProgramData\Chic Dale Dale.m22eq
                              C:\ProgramData\tick that bits.s60za
                              C:\ProgramData\Chic Dale Dale.653244
                              C:\ProgramData\Chic Dale Dale.a6vbcn
                              C:\ProgramData\Chic Dale Dale.j6gyzz
                              C:\ProgramData\Barb Seek Plan.9gstkea
                              C:\ProgramData\Chic Dale Dale.6gvvh73
                              C:\ProgramData\Chic Dale Dale.fixuhns
                              C:\ProgramData\Chic Dale Dale.gel9k08

                              --------------------\\ Recherche de Fichiers / Dossiers Lop

                              C:\ProgramData\Bags Browse Face
                              C:\ProgramData\Bags Browse Face\audiosafedebug.exe
                              C:\ProgramData\Bags Browse Face\eksdibmq.exe
                              C:\ProgramData\Bags Browse Face\jwmgccns.exe
                              C:\ProgramData\Bags Browse Face\pekygtuw.exe
                              C:\ProgramData\Bags Browse Face\RectExtraAmokVga.exe
                              C:\ProgramData\Bags Browse Face\xhwsmhwg.exe
                              C:\ProgramData\Bags Browse Face\ygksryct.exe
                              C:\ProgramData\Bags Browse Face\zbldhuvl.exe
                              C:\ProgramData\Bags Browse Face\zrhnbnfk.exe
                              C:\ProgramData\Ford drive four file
                              C:\ProgramData\Ford drive four file\anti tool.exe
                              C:\ProgramData\Iso Web Bags Else
                              C:\ProgramData\Iso Web Bags Else\glue roam.exe
                              C:\Program Files\Circle Developement
                              C:\Program Files\Circle Developement\Uninstall.exe
                              C:\Users\asma\AppData\Roaming\MICROS~1\Windows\Cookies\asma@bigpoint[1].txt
                              C:\Users\asma\AppData\Roaming\MICROS~1\Windows\Cookies\asma@fr.xblaster.bigpoint[1].txt
                              C:\Users\asma\AppData\Roaming\MICROS~1\Windows\Cookies\asma@adopt.euroclick[1].txt
                              C:\Users\asma\AppData\Roaming\MICROS~1\Windows\Cookies\asma@32vegas[1].txt
                              C:\Users\asma\AppData\Roaming\MICROS~1\Windows\Cookies\asma@banner.32vegas[2].txt

                              --------------------\\ Verification du Registre

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "Free nurb"="\"C:\\ProgramData\\Chic Dale Dale.m22eq\""
                              "Four file program mode"="\"C:\\ProgramData\\tick that bits.s60za\""
                              "Bags Else Hole Lite"="\"C:\\ProgramData\\Barb Seek Plan.9gstkea\""

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

                              --------------------\\ Verification du fichier Hosts

                              Fichier Hosts PROPRE

                              --------------------\\ Recherche de fichiers avec Catchme

                              catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2008-09-12 21:16:32
                              Windows 6.0.6000 NTFS
                              scanning hidden processes ...
                              scanning hidden files ...
                              scan completed successfully
                              hidden processes: 0
                              hidden files: 126

                              --------------------\\ Recherche d'autres infections

                              --------------------\\ Cracks & Keygens ..

                              C:\Users\asma\AppData\Roaming\uTorrent\BitDefender.Total.Security.2009.v12.0.10.Incl.Keygen.torrent

                              [F:98][D:16]-> C:\Users\asma\AppData\Local\Temp
                              [F:38][D:1]-> C:\Users\asma\AppData\Roaming\MICROS~1\Windows\Cookies
                              [F:470][D:5]-> C:\Users\asma\AppData\Local\MICROS~1\Windows\TEMPOR~1\content.IE5
                              [F:30][D:8]-> C:\$Recycle.Bin

                              1 - "C:\Lop SD\LopR_1.txt" - 12/09/2008|21:15 - Option : [1]
                              2 - "C:\Lop SD\LopR_2.txt" - 12/09/2008|21:17 - Option : [1]

                              --------------------\\ Fin du rapport a 21:17:43
                              [ UAC => 1 ]
                              0
                              1. Modérateur
                                ---> Relance Lop S&D
                                ---> Choisis cette fois-ci l'option 2 (Suppression)
                                ---> Ne ferme pas la fenêtre lors de la suppression !
                                ---> Poste le rapport généré (C:\lopR.txt)
                                0
                                1. c bon j'ai fait l'analyse
                                  0
                                2. T4ES la destrio5
                                  0
                              • 1
                              • 2