Problème virus... vundo

Résolu
StarRain -  
 Utilisateur anonyme -
Bonjour,

J'ai essayé de me débarasser de ce virus, mais il revient toujours!!! J'ai passé vundofix (qui ne détecte rien), virtuabegone (qui ne détecte rien non plus) et combofix, qui efface des fichiers, mais 2 jours plus tard, le virus revient.. J'aurais besoin de votre aide svp... Je vous copie colle un hijackthis ainsi que ce qui est sorti du rapport combofix.. C'est spybot qui m'a indiqué que c'était virtuamonde, mais, lui non plus, ne répare qu'en superficie

Merci,

Logfile of HijackThis v1.99.1
Scan saved at 12:39:28, on 2008-09-15
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Users\Propriétaire\Downloads\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {079C9F8A-69E2-450C-8D29-D869A2D06638} - C:\Windows\system32\cmcofild.dll
O2 - BHO: {2c351262-e16b-0d28-fd64-120015acfd84} - {48dfca51-0021-46df-82d0-b61e262153c2} - C:\Windows\system32\jvwlqo.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {868392E6-B49D-463E-8CE2-E3541C792556} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {B5D90D1F-0732-416F-BF8C-B356B6B0EB13} - C:\Windows\system32\fccccArp.dll
O3 - Toolbar: Systran40premi.IEPlugIn - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\Premium\IEPlugIn.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [BM913d78b0] Rundll32.exe "C:\Windows\system32\fsebttdx.dll",s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Hyperappel du Petit Larousse 2009.lnk = C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: vlcvca.dll mxhsom.dll qvqawl.dll gnsmfq.dll jvwlqo.dll
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

ComboFix 08-09-14.01 - Propriétaire 2008-09-14 22:09:58.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2004 [GMT -4:00]
Lancé depuis: C:\Users\Propriétaire\Downloads\ComboFix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active

.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\system32\edslkyto.dll
C:\Windows\system32\modufstm.dll
C:\Windows\System32\prAccccf.ini
C:\Windows\System32\prAccccf.ini2
C:\Windows\system32\rtlfhejt.ini
C:\Windows\system32\tjehfltr.dll

.
((((((((((((((((((((((((((((( Fichiers cr‚‚s du 2008-08-15 au 2008-09-15 ))))))))))))))))))))))))))))))))))))
.

2008-09-14 22:13 . 2008-09-14 22:14 259,357,973 --a------ C:\Windows\MEMORY.DMP
2008-09-14 20:28 . 2008-09-14 20:28 111,616 --a------ C:\Windows\System32\uxctnhyu.dll
2008-09-14 20:28 . 2008-09-14 20:28 111,616 --a------ C:\Windows\System32\gnsmfq.dll
2008-09-14 15:50 . 2008-09-14 15:50 111,616 --a------ C:\Windows\System32\txowijmk.dll
2008-09-14 15:50 . 2008-09-14 15:50 111,616 --a------ C:\Windows\System32\qvqawl.dll
2008-09-13 17:29 . 2008-09-13 17:30 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-13 17:25 . 2008-09-13 17:25 <REP> d-------- C:\VundoFix Backups
2008-09-13 15:59 . 2008-09-13 15:59 268 --ah----- C:\sqmdata02.sqm
2008-09-13 15:59 . 2008-09-13 15:59 244 --ah----- C:\sqmnoopt02.sqm
2008-09-13 15:10 . 2008-09-13 18:16 <REP> d-------- C:\Program Files\Opera
2008-09-13 15:01 . 2008-09-13 15:01 244 --ah----- C:\sqmnoopt01.sqm
2008-09-13 15:01 . 2008-09-13 15:01 232 --ah----- C:\sqmdata01.sqm
2008-09-13 14:02 . 2008-09-13 14:02 0 --ah----- C:\ntuser.dat.LOG2
2008-09-13 14:02 . 2008-09-13 14:02 0 --ah----- C:\ntuser.dat.LOG1
2008-09-13 14:02 . 2008-09-13 14:02 0 --a------ C:\ntuser.dat
2008-09-13 13:35 . 2008-09-13 13:35 <REP> d-------- C:\temp
2008-09-13 13:34 . 2006-11-01 13:06 170,808 --a------ C:\temp\Listdlls.exe
2008-09-13 13:12 . 2008-09-13 13:12 244 --ah----- C:\sqmnoopt00.sqm
2008-09-13 13:12 . 2008-09-13 13:12 232 --ah----- C:\sqmdata00.sqm
2008-09-13 11:34 . 2008-09-13 12:56 <REP> d-------- C:\Users\All Users\Uniblue
2008-09-13 11:34 . 2008-09-13 12:56 <REP> d-------- C:\ProgramData\Uniblue
2008-09-13 11:29 . 2008-09-13 12:56 <REP> d-------- C:\Program Files\Uniblue
2008-09-08 17:14 . 2008-09-08 17:14 91 --a------ C:\Windows\wininit.ini
2008-09-08 16:51 . 2008-09-13 19:23 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-09-08 16:51 . 2008-09-13 19:23 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-09-08 16:22 . 2008-09-08 16:22 <REP> d-------- C:\Windows\Sun
2008-09-08 16:21 . 2008-09-08 16:22 <REP> d-------- C:\Program Files\Java
2008-09-08 16:21 . 2008-09-08 16:21 <REP> d-------- C:\Program Files\Common Files\Java
2008-09-07 15:05 . 2008-09-07 15:05 237,056 --a------ C:\Windows\System32\jkkLBrrP.dll
2008-09-07 13:51 . 1999-12-17 10:13 86,016 --a------ C:\Windows\unvise32.exe
2008-09-07 13:50 . 2008-09-07 13:50 <REP> d-------- C:\Program Files\Systran
2008-09-07 13:41 . 2008-09-07 13:41 <REP> d-------- C:\Program Files\Larousse
2008-09-07 13:41 . 2008-09-07 13:41 <REP> d-------- C:\Program Files\directx
2008-09-07 13:41 . 1998-06-17 19:07 57,344 --a------ C:\Windows\System32\Mfc42loc.dll
2008-09-07 13:38 . 2008-09-07 13:38 <REP> d-------- C:\Program Files\Alcohol Soft
2008-09-07 13:34 . 2008-09-07 13:34 685,816 --a------ C:\Windows\System32\drivers\sptd.sys
2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\Users\All Users\SlySoft
2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\ProgramData\SlySoft
2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\Program Files\SlySoft
2008-09-06 19:03 . 2008-09-06 19:03 237,056 --a------ C:\Windows\System32\awtrqPgg.dll
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Users\All Users\Apple Computer
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Users\All Users\Apple
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\ProgramData\Apple Computer
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\ProgramData\Apple
2008-09-06 17:54 . 2008-09-06 17:56 <REP> d-------- C:\Program Files\QuickTime
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Program Files\Apple Software Update
2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\Windows\LHSP
2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\Windows\IUConnect
2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\HGASRAPI
2008-09-06 17:34 . 2002-08-18 22:28 96,256 --a------ C:\Windows\System32\SMACKW32.DLL
2008-09-06 17:34 . 1997-12-19 16:18 77,824 --a------ C:\Windows\asr32312.dll
2008-09-06 17:34 . 2008-09-06 17:34 70 --a------ C:\Windows\HGSpeech.ini
2008-09-06 17:33 . 2008-09-06 17:33 <REP> d-------- C:\Program Files\The Learning Company
2008-09-06 17:31 . 1997-05-12 17:53 314,368 --a------ C:\Windows\IsUninst.exe
2008-09-06 17:26 . 2008-09-06 17:26 0 --a------ C:\Windows\setup32.INI
2008-09-06 17:13 . 2008-09-06 17:13 237,056 --------- C:\Windows\System32\fccccArp.dll
2008-09-06 17:07 . 2008-09-06 17:07 <REP> d-------- C:\Program Files\PowerISO
2008-09-06 17:04 . 2008-09-06 17:04 <REP> d-------- C:\Program Files\MagicISO
2008-09-06 13:14 . 2008-09-06 13:14 <REP> d-------- C:\Users\All Users\vsosdk
2008-09-06 13:14 . 2008-09-06 13:14 <REP> d-------- C:\ProgramData\vsosdk
2008-09-06 12:23 . 2008-09-06 12:23 <REP> d-------- C:\Users\All Users\Real
2008-09-06 12:23 . 2008-09-06 12:23 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2008-08-31 21:11 . 2008-08-31 21:20 <REP> d-------- C:\Program Files\Windows Live
2008-08-31 21:00 . 2003-03-18 22:20 1,060,864 --a------ C:\Windows\System32\MFC71.dll
2008-08-31 20:59 . 2008-08-31 21:15 <REP> d-------- C:\Program Files\Logitech
2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\Users\All Users\ma-config.com
2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\ProgramData\ma-config.com
2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\Program Files\ma-config.com
2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\Users\All Users\DVD Shrink
2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\ProgramData\DVD Shrink
2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\Program Files\DVD Shrink
2008-08-31 09:50 . 2008-08-31 09:50 <REP> d-------- C:\Users\All Users\Elaborate Bytes
2008-08-31 09:50 . 2008-08-31 09:50 <REP> d-------- C:\ProgramData\Elaborate Bytes
2008-08-31 09:50 . 2008-08-31 09:50 24 ---hs---- C:\Windows\S18FF1045.tmp
2008-08-31 09:49 . 2008-08-31 09:49 <REP> d-------- C:\Program Files\Elaborate Bytes
2008-08-31 03:01 . 2008-08-31 03:01 <REP> d-------- C:\Program Files\MSXML 4.0
2008-08-30 19:33 . 2003-06-26 23:05 472,332 --a------ C:\Windows\System32\drivers\lvcm.sys
2008-08-30 19:33 . 2003-06-26 23:12 327,680 --a------ C:\Windows\System32\LVUI2RC.dll
2008-08-30 19:33 . 2003-06-26 23:11 172,032 --a------ C:\Windows\System32\lvcodec2.dll
2008-08-30 19:33 . 2003-06-26 23:09 135,214 --a------ C:\Windows\System32\LVComS.exe
2008-08-30 19:33 . 2003-06-26 23:11 122,880 --a------ C:\Windows\System32\LVUI2.dll
2008-08-30 19:33 . 2003-06-26 23:14 77,824 --a------ C:\Windows\System32\lvcoinst.dll
2008-08-30 19:33 . 2003-06-26 23:10 57,344 --a------ C:\Windows\System32\LVComC.dll
2008-08-30 19:33 . 2003-06-26 22:40 14,938 --a------ C:\Windows\System32\lvcoinst.ini
2008-08-30 19:33 . 2003-06-26 23:03 12,112 --a------ C:\Windows\System32\drivers\LVUSBSta.sys
2008-08-30 16:14 . 2008-08-30 16:14 <REP> d-------- C:\Program Files\Druide
2008-08-30 16:14 . 1999-03-23 09:12 304,128 --a------ C:\Windows\unin040c.exe
2008-08-30 16:14 . 2008-08-30 16:19 3,554 --a------ C:\Windows\Antidote.ini
2008-08-30 16:14 . 2008-08-30 16:14 0 --a------ C:\Windows\PROTOCOL.INI
2008-08-30 16:06 . 2008-08-30 16:06 <REP> d-------- C:\Program Files\VSO
2008-08-30 16:06 . 2006-09-29 11:24 217,127 --a------ C:\Windows\System32\drv43260.dll
2008-08-30 16:06 . 2006-09-29 11:25 208,935 --a------ C:\Windows\System32\drv33260.dll
2008-08-30 16:06 . 2006-09-29 11:26 176,165 --a------ C:\Windows\System32\drv23260.dll
2008-08-30 16:06 . 2008-08-30 16:06 47,360 --a------ C:\Windows\System32\drivers\pcouffin.sys
2008-08-30 15:52 . 2008-08-30 15:52 <REP> d-------- C:\Binarema
2008-08-30 15:15 . 2008-08-30 15:15 <REP> d-------- C:\Users\All Users\Nero
2008-08-30 15:15 . 2008-08-30 15:15 <REP> d-------- C:\ProgramData\Nero
2008-08-30 15:15 . 2008-08-30 15:17 <REP> d-------- C:\Program Files\Common Files\Nero
2008-08-30 14:50 . 2008-08-30 14:50 <REP> d-------- C:\Users\All Users\WindowsSearch
2008-08-30 14:50 . 2008-08-30 14:50 <REP> d-------- C:\ProgramData\WindowsSearch
2008-08-30 14:25 . 2008-08-30 14:25 <REP> d-------- C:\Program Files\Microsoft Office Outlook Connector
2008-08-30 14:24 . 2008-08-30 14:24 <REP> d-------- C:\Program Files\MSECache
2008-08-30 11:13 . 2008-08-30 11:13 <REP> d-------- C:\Users\PropriǸtaire
2008-08-30 11:12 . 2008-08-30 11:14 <REP> d-------- C:\Program Files\SecondLife
2008-08-25 22:19 . 2008-08-25 18:16 <REP> d-------- C:\Windows\Debug
2008-08-25 18:45 . 2008-08-25 18:49 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-25 18:44 . 2008-08-31 21:16 <REP> d-------- C:\Users\All Users\WLInstaller
2008-08-25 18:44 . 2008-08-31 21:16 <REP> d-------- C:\ProgramData\WLInstaller
2008-08-25 18:38 . 2008-08-25 18:38 <REP> d-------- C:\Users\All Users\CyberLink
2008-08-25 18:38 . 2008-08-25 18:38 <REP> d-------- C:\ProgramData\CyberLink
2008-08-25 18:30 . 2008-09-10 16:57 <REP> d-------- C:\Downloads
2008-08-25 18:29 . 2008-09-06 11:38 <REP> d-------- C:\Program Files\BitComet
2008-08-25 18:26 . 2008-09-10 16:22 <REP> d-------- C:\Users\All Users\SiteAdvisor
2008-08-25 18:26 . 2008-09-10 16:22 <REP> d-------- C:\ProgramData\SiteAdvisor
2008-08-25 18:26 . 2008-09-14 22:14 5,995 --a------ C:\Windows\System32\Config.MPF
2008-08-25 18:25 . 2008-08-25 18:25 <REP> d-------- C:\Program Files\McAfee.com
2008-08-25 18:25 . 2008-09-12 16:12 <REP> d-------- C:\Program Files\McAfee
2008-08-25 18:25 . 2008-08-25 18:25 <REP> d-------- C:\Program Files\Common Files\McAfee
2008-08-25 18:25 . 2007-11-22 06:44 201,320 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-08-25 18:25 . 2007-07-13 06:21 125,728 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-08-25 18:25 . 2007-11-22 06:44 79,304 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-08-25 18:25 . 2007-12-02 12:51 40,488 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-08-25 18:25 . 2007-11-22 06:44 35,240 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-08-25 18:25 . 2007-11-22 06:44 33,832 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-08-25 18:20 . 2008-09-10 16:22 <REP> d-------- C:\Users\All Users\McAfee

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-25 15:22 --------- d-----w C:\Program Files\Windows Mail
2008-08-25 14:30 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-08-25 14:30 315,392 ----a-w C:\Windows\HideWin.exe
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Modèles
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Menu Démarrer
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Favoris
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Bureau
2008-08-25 14:17 --------- d-sh--w C:\Program Files\Fichiers communs
2008-07-21 12:11 24,392 ----a-w C:\Windows\system32\drivers\ElbyCDIO.sys
2008-06-24 20:06 972,072 ----a-w C:\Windows\UNNeroMediaHome.exe
2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((( snapshot@2008-09-13_20.06.14.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-14 00:04:27 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-09-15 02:13:58 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-09-14 00:04:27 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-09-15 02:13:46 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-09-15 02:13:46 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-09-14 00:00:36 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-14 14:51:23 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-09-14 00:00:36 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-14 14:51:23 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-14 00:00:36 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-14 14:51:23 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-15 02:06:13 5,862 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\18416CE8A96446C112DCE8009282548E784E7F84\973BC48B576C8188F2CEF3650B160AE03BD729D1\Data.dat
- 2008-09-13 22:08:47 6,276 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\4D5367EBDE22F22AB910D2E11BF07B236BD5EB37\4D5367EBDE22F22AB910D2E11BF07B236BD5EB37\Data.dat
+ 2008-09-15 02:06:36 6,276 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\4D5367EBDE22F22AB910D2E11BF07B236BD5EB37\4D5367EBDE22F22AB910D2E11BF07B236BD5EB37\Data.dat
- 2008-09-13 23:24:07 6,996 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\4E1D50A4EAD3C2690DE40E56982070589075DB82\4E1D50A4EAD3C2690DE40E56982070589075DB82\Data.dat
+ 2008-09-15 02:06:10 6,996 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\4E1D50A4EAD3C2690DE40E56982070589075DB82\4E1D50A4EAD3C2690DE40E56982070589075DB82\Data.dat
+ 2008-09-15 00:28:58 4,970 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\76E4EF5A79EAB98F93EF5ED761278B478EC5EF77\76E4EF5A79EAB98F93EF5ED761278B478EC5EF77\Data.dat
+ 2008-09-15 00:28:56 3,468 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\BE9922FA3E7D2ECAE929B718CA2D14473CB81E07\BE9922FA3E7D2ECAE929B718CA2D14473CB81E07\Data.dat
- 2008-09-14 00:00:52 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-09-15 02:09:52 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-09-15 02:09:52 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2008-09-13 23:27:38 101,896 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-09-14 14:55:37 101,896 ----a-w C:\Windows\System32\perfc009.dat
- 2008-09-13 23:27:38 124,228 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-09-14 14:55:37 124,228 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-09-13 23:27:38 589,884 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-09-14 14:55:37 589,884 ----a-w C:\Windows\System32\perfh009.dat
- 2008-09-13 23:27:38 672,084 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-09-14 14:55:37 672,084 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-09-13 19:18:04 5,222 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-295252437-1548751239-3619892269-1000_UserData.bin
+ 2008-09-14 14:50:55 5,556 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-295252437-1548751239-3619892269-1000_UserData.bin
- 2008-09-13 19:18:04 64,716 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-09-14 14:50:55 64,926 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-09-13 23:23:04 35,752 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-09-14 14:50:54 36,222 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5E1A1870-827E-4B7E-94BB-224E599A1C79}]
2008-09-06 17:13 237056 --------- C:\Windows\system32\fccccArp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-20 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Gestionnaire Antidote.exe"="C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe" [2002-11-07 143360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"Uniblue RegistryBooster 2009"="c:\program files\uniblue\registrybooster\StartRegistryBooster.exe" [BU]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-16 13535776]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-16 92704]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-20 C:\Windows\RtHDVCpl.exe]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Hyperappel du Petit Larousse 2009.lnk - C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe [2008-09-07 237568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=vlcvca.dll mxhsom.dll qvqawl.dll gnsmfq.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-295252437-1548751239-3619892269-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{DAC81081-FBB4-4452-84A1-CBFA60292391}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{7307F9B1-37A9-4DB4-8B00-D6964BA564D7}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"{08AE761A-9F8B-4A3B-A942-B1E34F72215A}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{9E46F0BB-4775-4746-B085-42D175881C9C}"= UDP:17842:BitComet 17842 TCP
"{1E7F9CC7-38AA-4238-958F-041D7FA3B6F5}"= TCP:17842:BitComet 17842 UDP
"{72C072DE-6190-46E9-9441-345FACE1834F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{961772C2-CC22-414B-8357-9D49E3020317}"= UDP:25937:BitComet 25937 TCP
"{0BD1CE4F-8154-4B05-AD04-30104AB8C4DE}"= TCP:25937:BitComet 25937 UDP
"{AD7218B8-1B4E-4C5D-B875-85C47996B946}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{01D01E03-D7CD-47C3-8AED-A691F9909402}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{A1F003DC-A7EF-43D4-8C73-27BDFA6301BD}"= UDP:C:\Program Files\ma-config.com\maconfservice.exe:maconfservice
"{F375F858-47CF-47BE-8D26-1D9397D75326}"= TCP:C:\Program Files\ma-config.com\maconfservice.exe:maconfservice
"{2A538FDB-ADFB-44ED-A190-585F7A2F1529}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 mv61xx;mv61xx;C:\Windows\system32\DRIVERS\mv61xx.sys [2008-06-10 150568]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113 PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1E60x86.sys [2008-02-02 47616]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-07-25 191656]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]
.
Contenu du dossier 'Tƒches planifi‚es'
.
- - - - ORPHELINS SUPPRIMES - - - -

BHO-{7FF2E2EB-7BC1-49F1-83D4-5772C4414E2A} - (no file)

.
------- Examen suppl‚mentaire -------
.
FireFox -: Profile - C:\Users\Propriétaire\AppData\Roaming\Mozilla\Firefox\Profiles\uanfayrj.default\
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-14 22:14:31
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cach‚s ...

Recherche d'‚l‚ments en d‚marrage automatique cach‚s ...

Recherche de fichiers cach‚s ...

C:\Users\Propriétaire\AppData\Local\Microsoft\Windows\WER\ReportArchive\store.lock 0 bytes
C:\Users\Propriétaire\AppData\Local\Microsoft\Windows\WER\ReportQueue\store.lock 0 bytes
C:\Users\Propriétaire\AppData\Local\Temp\WER-64241-0.sysdata.xml 229106 bytes

Scan termin‚ avec succŠs
Fichiers cach‚s: 3

**************************************************************************
.
--------------------- DLLs charg‚es dans les processus actifs ---------------------

PROCESSUS: C:\Windows\Explorer.exe
-> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
-> ?:\Windows\system32\iertutil.dll
.
------------------------ Autres processus actifs ------------------------
.
C:\Windows\System32\nvvsvc.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\McAfee\VirusScan\mcsysmon.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Windows\System32\dllhost.exe
C:\PROGRA~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Heure de fin: 2008-09-14 22:17:20 - La machine a red‚marr‚
ComboFix-quarantined-files.txt 2008-09-15 02:17:10
ComboFix2.txt 2008-09-14 00:07:21

Avant-CF: 461,749,342,208 octets libres
AprŠs-CF: 462,095,048,704 octets libres

319 --- E O F --- 2008-09-01 01:13:52
A voir également:

13 réponses

fred
 
Salut
Il parait que spywareblaster évite l' installation de vundo.
Une fois par mois, mettre à jour, "énable all protections", et fermer le programme. Ne pas mettre les mises à jour automatiques et il n' utilise pas de mémoire au quotidien.
https://jesses.pagesperso-orange.fr/Docs/Logiciels/SpywareBlaster.htm
1
StarRain
 
Bonjour Chiquitine,

Merci bcp de ton aide, c'est très très apprécié :-)

Voici mon rapport combofix ainsi qu'un rapport hijackthis passer après que j'ai fais le combo..

Merci, j'Attends de tes nouvelles!!

ComboFix 08-09-14.01 - Propriétaire 2008-09-15 16:28:16.3 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2002 [GMT -4:00]
Lancé depuis: C:\Users\Propriétaire\Downloads\ComboFix.exe
Command switches used :: C:\Users\Propriétaire\Downloads\CFScript.txt
* Un nouveau point de restauration a été créé
* Resident AV is active

.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\temp\Listdlls.exe
C:\VundoFix Backups
C:\Windows\S18FF1045.tmp
C:\Windows\System32\awtrqPgg.dll
C:\Windows\system32\ccndgaim.dll
C:\Windows\system32\cmcofild.dll
C:\Windows\system32\cxywxgna.dll
C:\Windows\system32\efofngxm.dll
C:\Windows\system32\fccccArp.dll
C:\Windows\system32\fcwnkwek.dll
C:\Windows\system32\fsebttdx.dll
C:\Windows\System32\gnsmfq.dll
C:\Windows\System32\jkkLBrrP.dll
C:\Windows\system32\jtfglbhp.dll
C:\Windows\system32\lasxquyu.dll
C:\Windows\system32\luvcdsdn.dll
C:\Windows\system32\ngicirxw.dll
C:\Windows\System32\prAccccf.ini
C:\Windows\System32\prAccccf.ini2
C:\Windows\System32\qvqawl.dll
C:\Windows\system32\rrwfkghx.ini
C:\Windows\System32\txowijmk.dll
C:\Windows\system32\uuvwdyhk.dll
C:\Windows\System32\uxctnhyu.dll
C:\Windows\system32\vwdlwsld.dll
C:\Windows\system32\xhgkfwrr.dll
C:\Windows\unvise32.exe
C:\WINDOWS\wininit.ini

.
((((((((((((((((((((((((((((( Fichiers cr‚‚s du 2008-08-15 au 2008-09-15 ))))))))))))))))))))))))))))))))))))
.

2008-09-14 22:35 . 2008-09-14 22:35 111,616 --a------ C:\Windows\System32\jvwlqo.dll
2008-09-14 22:35 . 2008-09-14 22:35 111,616 --a------ C:\Windows\System32\gmdvhxsy.dll
2008-09-14 22:25 . 2008-08-01 21:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
2008-09-14 22:25 . 2008-06-25 23:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
2008-09-14 22:25 . 2008-05-08 15:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
2008-09-14 22:25 . 2008-05-19 22:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
2008-09-14 22:25 . 2008-06-25 23:29 45,056 --a------ C:\Windows\System32\dataclen.dll
2008-09-14 22:25 . 2008-08-01 23:26 36,864 --a------ C:\Windows\System32\cdd.dll
2008-09-14 22:13 . 2008-09-14 22:14 259,357,973 --a------ C:\Windows\MEMORY.DMP
2008-09-13 17:29 . 2008-09-13 17:30 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-13 15:59 . 2008-09-13 15:59 268 --ah----- C:\sqmdata02.sqm
2008-09-13 15:59 . 2008-09-13 15:59 244 --ah----- C:\sqmnoopt02.sqm
2008-09-13 15:10 . 2008-09-13 18:16 <REP> d-------- C:\Program Files\Opera
2008-09-13 15:01 . 2008-09-13 15:01 244 --ah----- C:\sqmnoopt01.sqm
2008-09-13 15:01 . 2008-09-13 15:01 232 --ah----- C:\sqmdata01.sqm
2008-09-13 14:02 . 2008-09-13 14:02 0 --ah----- C:\ntuser.dat.LOG2
2008-09-13 14:02 . 2008-09-13 14:02 0 --ah----- C:\ntuser.dat.LOG1
2008-09-13 14:02 . 2008-09-13 14:02 0 --a------ C:\ntuser.dat
2008-09-13 13:35 . 2008-09-15 16:28 <REP> d-------- C:\temp
2008-09-13 13:12 . 2008-09-13 13:12 244 --ah----- C:\sqmnoopt00.sqm
2008-09-13 13:12 . 2008-09-13 13:12 232 --ah----- C:\sqmdata00.sqm
2008-09-13 11:34 . 2008-09-13 12:56 <REP> d-------- C:\Users\All Users\Uniblue
2008-09-13 11:34 . 2008-09-13 12:56 <REP> d-------- C:\ProgramData\Uniblue
2008-09-13 11:29 . 2008-09-13 12:56 <REP> d-------- C:\Program Files\Uniblue
2008-09-08 16:51 . 2008-09-13 19:23 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-09-08 16:51 . 2008-09-13 19:23 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-09-08 16:22 . 2008-09-08 16:22 <REP> d-------- C:\Windows\Sun
2008-09-08 16:21 . 2008-09-08 16:22 <REP> d-------- C:\Program Files\Java
2008-09-08 16:21 . 2008-09-08 16:21 <REP> d-------- C:\Program Files\Common Files\Java
2008-09-07 13:50 . 2008-09-07 13:50 <REP> d-------- C:\Program Files\Systran
2008-09-07 13:41 . 2008-09-07 13:41 <REP> d-------- C:\Program Files\Larousse
2008-09-07 13:41 . 2008-09-07 13:41 <REP> d-------- C:\Program Files\directx
2008-09-07 13:41 . 1998-06-17 19:07 57,344 --a------ C:\Windows\System32\Mfc42loc.dll
2008-09-07 13:38 . 2008-09-07 13:38 <REP> d-------- C:\Program Files\Alcohol Soft
2008-09-07 13:34 . 2008-09-07 13:34 685,816 --a------ C:\Windows\System32\drivers\sptd.sys
2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\Users\All Users\SlySoft
2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\ProgramData\SlySoft
2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\Program Files\SlySoft
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Users\All Users\Apple Computer
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Users\All Users\Apple
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\ProgramData\Apple Computer
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\ProgramData\Apple
2008-09-06 17:54 . 2008-09-06 17:56 <REP> d-------- C:\Program Files\QuickTime
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Program Files\Apple Software Update
2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\Windows\LHSP
2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\Windows\IUConnect
2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\HGASRAPI
2008-09-06 17:34 . 2002-08-18 22:28 96,256 --a------ C:\Windows\System32\SMACKW32.DLL
2008-09-06 17:34 . 1997-12-19 16:18 77,824 --a------ C:\Windows\asr32312.dll
2008-09-06 17:34 . 2008-09-06 17:34 70 --a------ C:\Windows\HGSpeech.ini
2008-09-06 17:33 . 2008-09-06 17:33 <REP> d-------- C:\Program Files\The Learning Company
2008-09-06 17:31 . 1997-05-12 17:53 314,368 --a------ C:\Windows\IsUninst.exe
2008-09-06 17:26 . 2008-09-06 17:26 0 --a------ C:\Windows\setup32.INI
2008-09-06 17:07 . 2008-09-06 17:07 <REP> d-------- C:\Program Files\PowerISO
2008-09-06 17:04 . 2008-09-06 17:04 <REP> d-------- C:\Program Files\MagicISO
2008-09-06 13:14 . 2008-09-06 13:14 <REP> d-------- C:\Users\All Users\vsosdk
2008-09-06 13:14 . 2008-09-06 13:14 <REP> d-------- C:\ProgramData\vsosdk
2008-09-06 12:23 . 2008-09-06 12:23 <REP> d-------- C:\Users\All Users\Real
2008-09-06 12:23 . 2008-09-06 12:23 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2008-08-31 21:11 . 2008-08-31 21:20 <REP> d-------- C:\Program Files\Windows Live
2008-08-31 21:00 . 2003-03-18 22:20 1,060,864 --a------ C:\Windows\System32\MFC71.dll
2008-08-31 20:59 . 2008-08-31 21:15 <REP> d-------- C:\Program Files\Logitech
2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\Users\All Users\ma-config.com
2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\ProgramData\ma-config.com
2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\Program Files\ma-config.com
2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\Users\All Users\DVD Shrink
2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\ProgramData\DVD Shrink
2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\Program Files\DVD Shrink
2008-08-31 09:50 . 2008-08-31 09:50 <REP> d-------- C:\Users\All Users\Elaborate Bytes
2008-08-31 09:50 . 2008-08-31 09:50 <REP> d-------- C:\ProgramData\Elaborate Bytes
2008-08-31 09:49 . 2008-08-31 09:49 <REP> d-------- C:\Program Files\Elaborate Bytes
2008-08-31 03:01 . 2008-08-31 03:01 <REP> d-------- C:\Program Files\MSXML 4.0
2008-08-30 19:33 . 2003-06-26 23:05 472,332 --a------ C:\Windows\System32\drivers\lvcm.sys
2008-08-30 19:33 . 2003-06-26 23:12 327,680 --a------ C:\Windows\System32\LVUI2RC.dll
2008-08-30 19:33 . 2003-06-26 23:11 172,032 --a------ C:\Windows\System32\lvcodec2.dll
2008-08-30 19:33 . 2003-06-26 23:09 135,214 --a------ C:\Windows\System32\LVComS.exe
2008-08-30 19:33 . 2003-06-26 23:11 122,880 --a------ C:\Windows\System32\LVUI2.dll
2008-08-30 19:33 . 2003-06-26 23:14 77,824 --a------ C:\Windows\System32\lvcoinst.dll
2008-08-30 19:33 . 2003-06-26 23:10 57,344 --a------ C:\Windows\System32\LVComC.dll
2008-08-30 19:33 . 2003-06-26 22:40 14,938 --a------ C:\Windows\System32\lvcoinst.ini
2008-08-30 19:33 . 2003-06-26 23:03 12,112 --a------ C:\Windows\System32\drivers\LVUSBSta.sys
2008-08-30 16:14 . 2008-08-30 16:14 <REP> d-------- C:\Program Files\Druide
2008-08-30 16:14 . 1999-03-23 09:12 304,128 --a------ C:\Windows\unin040c.exe
2008-08-30 16:14 . 2008-08-30 16:19 3,554 --a------ C:\Windows\Antidote.ini
2008-08-30 16:14 . 2008-08-30 16:14 0 --a------ C:\Windows\PROTOCOL.INI
2008-08-30 16:06 . 2008-08-30 16:06 <REP> d-------- C:\Program Files\VSO
2008-08-30 16:06 . 2006-09-29 11:24 217,127 --a------ C:\Windows\System32\drv43260.dll
2008-08-30 16:06 . 2006-09-29 11:25 208,935 --a------ C:\Windows\System32\drv33260.dll
2008-08-30 16:06 . 2006-09-29 11:26 176,165 --a------ C:\Windows\System32\drv23260.dll
2008-08-30 16:06 . 2008-08-30 16:06 47,360 --a------ C:\Windows\System32\drivers\pcouffin.sys
2008-08-30 15:52 . 2008-08-30 15:52 <REP> d-------- C:\Binarema
2008-08-30 15:15 . 2008-08-30 15:15 <REP> d-------- C:\Users\All Users\Nero
2008-08-30 15:15 . 2008-08-30 15:15 <REP> d-------- C:\ProgramData\Nero
2008-08-30 15:15 . 2008-08-30 15:17 <REP> d-------- C:\Program Files\Common Files\Nero
2008-08-30 14:50 . 2008-08-30 14:50 <REP> d-------- C:\Users\All Users\WindowsSearch
2008-08-30 14:50 . 2008-08-30 14:50 <REP> d-------- C:\ProgramData\WindowsSearch
2008-08-30 14:25 . 2008-08-30 14:25 <REP> d-------- C:\Program Files\Microsoft Office Outlook Connector
2008-08-30 14:24 . 2008-08-30 14:24 <REP> d-------- C:\Program Files\MSECache
2008-08-30 11:13 . 2008-08-30 11:13 <REP> d-------- C:\Users\PropriǸtaire
2008-08-30 11:12 . 2008-08-30 11:14 <REP> d-------- C:\Program Files\SecondLife
2008-08-25 22:19 . 2008-08-25 18:16 <REP> d-------- C:\Windows\Debug
2008-08-25 18:45 . 2008-08-25 18:49 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-25 18:44 . 2008-08-31 21:16 <REP> d-------- C:\Users\All Users\WLInstaller
2008-08-25 18:44 . 2008-08-31 21:16 <REP> d-------- C:\ProgramData\WLInstaller
2008-08-25 18:38 . 2008-08-25 18:38 <REP> d-------- C:\Users\All Users\CyberLink
2008-08-25 18:38 . 2008-08-25 18:38 <REP> d-------- C:\ProgramData\CyberLink
2008-08-25 18:30 . 2008-09-10 16:57 <REP> d-------- C:\Downloads
2008-08-25 18:29 . 2008-09-06 11:38 <REP> d-------- C:\Program Files\BitComet
2008-08-25 18:26 . 2008-09-10 16:22 <REP> d-------- C:\Users\All Users\SiteAdvisor
2008-08-25 18:26 . 2008-09-10 16:22 <REP> d-------- C:\ProgramData\SiteAdvisor
2008-08-25 18:26 . 2008-09-15 16:32 5,995 --a------ C:\Windows\System32\Config.MPF
2008-08-25 18:25 . 2008-08-25 18:25 <REP> d-------- C:\Program Files\McAfee.com
2008-08-25 18:25 . 2008-09-12 16:12 <REP> d-------- C:\Program Files\McAfee
2008-08-25 18:25 . 2008-08-25 18:25 <REP> d-------- C:\Program Files\Common Files\McAfee
2008-08-25 18:25 . 2007-11-22 06:44 201,320 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-08-25 18:25 . 2007-07-13 06:21 125,728 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-08-25 18:25 . 2007-11-22 06:44 79,304 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-08-25 18:25 . 2007-12-02 12:51 40,488 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-08-25 18:25 . 2007-11-22 06:44 35,240 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-08-25 18:25 . 2007-11-22 06:44 33,832 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-08-25 18:20 . 2008-09-10 16:22 <REP> d-------- C:\Users\All Users\McAfee
2008-08-25 18:20 . 2008-09-10 16:22 <REP> d-------- C:\ProgramData\McAfee
2008-08-25 18:15 . 2007-04-09 13:23 28,040 --a------ C:\Windows\System32\mdimon.dll
2008-08-25 18:15 . 2008-08-25 18:15 382 --a------ C:\Windows\ODBC.INI
2008-08-25 18:13 . 2008-08-25 18:13 <REP> d-------- C:\Windows\PCHEALTH

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-25 15:22 --------- d-----w C:\Program Files\Windows Mail
2008-08-25 14:30 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-08-25 14:30 315,392 ----a-w C:\Windows\HideWin.exe
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Modèles
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Menu Démarrer
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Favoris
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Bureau
2008-08-25 14:17 --------- d-sh--w C:\Program Files\Fichiers communs
2008-07-25 08:34 81,920 ----a-w C:\Windows\System32\dpl100.dll
2008-07-25 08:34 683,520 ----a-w C:\Windows\System32\divx.dll
2008-07-23 16:50 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
2008-07-21 12:11 24,392 ----a-w C:\Windows\system32\drivers\ElbyCDIO.sys
2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll
2008-06-26 11:06 93,128 ----a-w C:\Windows\System32\ElbyCDIO.dll
2008-06-24 20:06 972,072 ----a-w C:\Windows\UNNeroMediaHome.exe
2008-06-19 03:31 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((( snapshot_2008-09-14_22.16.15.94 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-09-15 20:28:04 6,258,688 ----a-w C:\Windows\erdnt\Hiv-backup\SCHEMA.DAT
+ 2008-09-15 20:30:18 6,258,688 ----a-w C:\Windows\erdnt\subs\SCHEMA.DAT
- 2008-09-15 02:13:58 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-09-15 20:32:11 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-09-15 20:32:11 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-09-15 02:13:46 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-09-15 20:32:03 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-09-15 20:32:03 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-09-14 14:51:23 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-15 16:14:34 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-09-14 14:51:23 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-15 16:14:34 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-14 14:51:23 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-15 16:14:34 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-15 20:24:12 6,384 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\BA73419CB1C7E95D312F7EAF9967147ADD5FC0F1\BA73419CB1C7E95D312F7EAF9967147ADD5FC0F1\Data.dat
+ 2008-09-15 20:22:42 7,148 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\E6D66408E2E8C41284F6F3818922AE0585617EED\E6D66408E2E8C41284F6F3818922AE0585617EED\Data.dat
- 2008-09-14 14:55:37 101,896 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-09-15 16:18:44 101,896 ----a-w C:\Windows\System32\perfc009.dat
- 2008-09-14 14:55:37 124,228 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-09-15 16:18:44 124,228 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-09-14 14:55:37 589,884 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-09-15 16:18:44 589,884 ----a-w C:\Windows\System32\perfh009.dat
- 2008-09-14 14:55:37 672,084 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-09-15 16:18:44 672,084 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-09-06 21:29:49 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2008-09-15 20:30:18 6,258,688 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2008-09-14 14:50:55 5,556 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-295252437-1548751239-3619892269-1000_UserData.bin
+ 2008-09-15 02:16:01 5,882 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-295252437-1548751239-3619892269-1000_UserData.bin
- 2008-09-14 14:50:55 64,926 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-09-15 16:14:20 65,050 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-09-14 14:50:54 36,222 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-09-15 16:14:19 36,270 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-09-01 01:13:09 28,223,113 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-09-15 02:24:57 29,133,893 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
+ 2008-03-08 01:58:43 2,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.18112_none_0c196ab7f252b793\AcRes.dll
+ 2008-06-12 05:28:53 541,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.18112_none_0c1d6bdff24f1cef\AcLayers.dll
+ 2008-06-26 03:29:02 45,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-dataclen_31bf3856ad364e35_6.0.6001.18098_none_f64ce87593b7801f\dataclen.dll
+ 2008-06-26 03:15:06 45,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-dataclen_31bf3856ad364e35_6.0.6001.22211_none_f7260480ac9a8c27\dataclen.dll
+ 2008-06-26 03:29:02 565,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18098_none_9e329f52f6fc276d\emdmgmt.dll
+ 2008-06-26 03:15:30 565,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.22211_none_9f0bbb5e0fdf3375\emdmgmt.dll
+ 2008-03-08 04:21:55 1,695,744 ----a-w C:\Windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18112_none_41f7819cc1434d41\gameux.dll
+ 2008-08-02 03:26:00 36,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.18114_none_abc1cbc0e39143f0\cdd.dll
+ 2008-08-02 01:01:23 625,152 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.18114_none_abc1cbc0e39143f0\dxgkrnl.sys
+ 2008-08-02 03:20:51 36,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.22235_none_ac36c8fdfcbe34f3\cdd.dll
+ 2008-08-02 00:59:11 625,152 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.22235_none_ac36c8fdfcbe34f3\dxgkrnl.sys
+ 2008-05-20 02:07:31 148,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-native-80211_31bf3856ad364e35_6.0.6001.18075_none_4ec1fb0e8f26c88a\nwifi.sys
+ 2008-05-20 02:00:06 148,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-native-80211_31bf3856ad364e35_6.0.6001.22183_none_4f3ec759a84e5197\nwifi.sys
+ 2008-06-30 23:00:26 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16730_none_f0816da06e6c1330\OESpamFilter.dat
+ 2008-06-30 23:00:26 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20895_none_f0cf2c5587b5d953\OESpamFilter.dat
+ 2008-06-30 23:00:26 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18121_none_f2737c7c6b89a187\OESpamFilter.dat
+ 2008-06-30 23:00:26 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22243_none_f2e97a0384b5abe1\OESpamFilter.dat
+ 2008-05-08 19:21:56 211,968 ----a-w C:\Windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6001.18068_none_886bae514b981fe3\mrxsmb10.sys
+ 2008-05-08 02:47:34 211,968 ----a-w C:\Windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6001.22175_none_88e77a5264c08f99\mrxsmb10.sys
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{48dfca51-0021-46df-82d0-b61e262153c2}]
2008-09-14 22:35 111616 --a------ C:\Windows\system32\jvwlqo.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-20 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Gestionnaire Antidote.exe"="C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe" [2002-11-07 143360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"Uniblue RegistryBooster 2009"="c:\program files\uniblue\registrybooster\StartRegistryBooster.exe" [BU]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-16 13535776]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-16 92704]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-20 C:\Windows\RtHDVCpl.exe]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Hyperappel du Petit Larousse 2009.lnk - C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe [2008-09-07 237568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-295252437-1548751239-3619892269-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{DAC81081-FBB4-4452-84A1-CBFA60292391}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{7307F9B1-37A9-4DB4-8B00-D6964BA564D7}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"{08AE761A-9F8B-4A3B-A942-B1E34F72215A}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{9E46F0BB-4775-4746-B085-42D175881C9C}"= UDP:17842:BitComet 17842 TCP
"{1E7F9CC7-38AA-4238-958F-041D7FA3B6F5}"= TCP:17842:BitComet 17842 UDP
"{72C072DE-6190-46E9-9441-345FACE1834F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{961772C2-CC22-414B-8357-9D49E3020317}"= UDP:25937:BitComet 25937 TCP
"{0BD1CE4F-8154-4B05-AD04-30104AB8C4DE}"= TCP:25937:BitComet 25937 UDP
"{AD7218B8-1B4E-4C5D-B875-85C47996B946}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{01D01E03-D7CD-47C3-8AED-A691F9909402}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{A1F003DC-A7EF-43D4-8C73-27BDFA6301BD}"= UDP:C:\Program Files\ma-config.com\maconfservice.exe:maconfservice
"{F375F858-47CF-47BE-8D26-1D9397D75326}"= TCP:C:\Program Files\ma-config.com\maconfservice.exe:maconfservice
"{2A538FDB-ADFB-44ED-A190-585F7A2F1529}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 mv61xx;mv61xx;C:\Windows\system32\DRIVERS\mv61xx.sys [2008-06-10 150568]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113 PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1E60x86.sys [2008-02-02 47616]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-07-25 191656]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]
.
Contenu du dossier 'Tƒches planifi‚es'
.
- - - - ORPHELINS SUPPRIMES - - - -

BHO-{079C9F8A-69E2-450C-8D29-D869A2D06638} - C:\Windows\system32\cmcofild.dll
BHO-{868392E6-B49D-463E-8CE2-E3541C792556} - (no file)
BHO-{B5D90D1F-0732-416F-BF8C-B356B6B0EB13} - C:\Windows\system32\fccccArp.dll

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-15 16:32:26
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cach‚s ...

Recherche d'‚l‚ments en d‚marrage automatique cach‚s ...

Recherche de fichiers cach‚s ...

Scan termin‚ avec succŠs
Fichiers cach‚s: 0

**************************************************************************
.
--------------------- DLLs charg‚es dans les processus actifs ---------------------

PROCESSUS: C:\Windows\Explorer.exe
-> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
.
------------------------ Autres processus actifs ------------------------
.
C:\Windows\System32\nvvsvc.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\Windows\System32\rundll32.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\Windows\System32\rundll32.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\System32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\McAfee\VirusScan\mcsysmon.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Heure de fin: 2008-09-15 16:35:27 - La machine a red‚marr‚
ComboFix-quarantined-files.txt 2008-09-15 20:35:24
ComboFix2.txt 2008-09-15 02:17:22
ComboFix3.txt 2008-09-14 00:07:21

Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
AprŠs-CF: 463,961,817,088 octets libres

357 --- E O F --- 2008-09-15 02:28:35

Logfile of HijackThis v1.99.1
Scan saved at 16:36:24, on 2008-09-15
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
C:\Windows\Explorer.exe
C:\Windows\system32\notepad.exe
C:\Users\Propriétaire\Downloads\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: {2c351262-e16b-0d28-fd64-120015acfd84} - {48dfca51-0021-46df-82d0-b61e262153c2} - C:\Windows\system32\jvwlqo.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Systran40premi.IEPlugIn - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\Premium\IEPlugIn.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Hyperappel du Petit Larousse 2009.lnk = C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
0
StarRain
 
Bonjour Chiquitine,

Voici le rapport de Malaware

J'attends de tes nouvelles!

StarRain

Malwarebytes' Anti-Malware 1.28
Version de la base de données: 1157
Windows 6.0.6001 Service Pack 1

2008-09-15 17:57:32
mbam-log-2008-09-15 (17-57-32).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 118891
Temps écoulé: 39 minute(s), 38 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 1
Clé(s) du Registre infectée(s): 2
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 29

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
C:\Windows\System32\jvwlqo.dll (Trojan.Vundo) -> Delete on reboot.

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48dfca51-0021-46df-82d0-b61e262153c2} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{48dfca51-0021-46df-82d0-b61e262153c2} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\Windows\System32\jvwlqo.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\QooBox\Quarantine\C\Windows\System32\awtrqPgg.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\ccndgaim.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\cmcofild.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\cxywxgna.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\edslkyto.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\efofngxm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\fccccArp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\fcwnkwek.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\fsebttdx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\gcmvlhpf.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\modufstm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\mxhsom.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\ngicirxw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\qvqawl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\gnsmfq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\hqskqolv.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\jkkLBrrP.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\jsymbend.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\jtfglbhp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\lasxquyu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\luvcdsdn.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\tjehfltr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\txowijmk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\uuvwdyhk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\uxctnhyu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\vwdlwsld.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\Windows\System32\xhgkfwrr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Windows\System32\gmdvhxsy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
0
StarRain
 
Rebonsoir,

Voici le rapport après la suppression de la quarantaine de malaware

Merci

Logfile of HijackThis v1.99.1
Scan saved at 18:13:38, on 2008-09-15
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\Windows\Explorer.EXE
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Propriétaire\Downloads\hijackthis.exe
C:\Windows\system32\WerCon.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Systran40premi.IEPlugIn - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\Premium\IEPlugIn.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Hyperappel du Petit Larousse 2009.lnk = C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
StarRain
 
Bonjour,

J'imagine que si vous me faites supprimer c'est que tout est correct maintenant sur mon ordinateur! Merci bcp de votre aide. Tous les résidus du virus sont maintenant partis?? Si oui, comment s'assurer qu'il ne revienne pas, je n'ai portant rien fait de risqué sur mon ordi...

Merci et voici le rapport:

[ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

C:\VundoFix.txt: trouvé !
C:\Combofix.txt: trouvé !
C:\Qoobox: trouvé !
C:\Users\Propriétaire\Downloads\VirtumundoBeGone.exe: trouvé !
C:\Users\Propriétaire\Downloads\ComboFix.exe: trouvé !
C:\Users\Propriétaire\Downloads\vundoFix.exe: trouvé !
C:\Users\Propriétaire\Downloads\HijackThis.exe: trouvé !
C:\Users\Propriétaire\Downloads\hijackthis.log: trouvé !

---------------------------------
-->- Suppression:

C:\Users\Propriétaire\Downloads\VirtumundoBeGone.exe: supprimé !
C:\Users\Propriétaire\Downloads\ComboFix.exe: ERREUR DE SUPPRESSION !!
C:\Users\Propriétaire\Downloads\vundoFix.exe: supprimé !
C:\Users\Propriétaire\Downloads\HijackThis.exe: supprimé !
C:\VundoFix.txt: supprimé !
C:\Combofix.txt: supprimé !
C:\Users\Propriétaire\Downloads\hijackthis.log: supprimé !
C:\Qoobox: supprimé !

Corbeille vidée!
Fichiers temporaires nettoyés !
0
StarRain
 
Salut Chiquitine,

Je voulais te remercier pour ta précieuse aide. Souhaitant qu'ils ne reviennent pas ces maudits spyware. J'ai installé les deux logiciels dont tu m'as parler. De plus, j'ai supprimer combofix.exe...

Je ne suis pas un membre inscrit.. donc je ne peux pas mettre résolu moi même comme c'est inscrit dans le lien. Qui je dois contacter en particuler (un contributeur ou un modérateur) pour qu'il le fasse à ma place?

Merci bcp encore!!

StarRain
0
Utilisateur anonyme
 
Salut,

je regarde tes rapports

@+
-1
Utilisateur anonyme
 
re

désolé du retard :

Copie le texte ci-dessous :

File::
C:\WINDOWS\wininit.ini
C:\Windows\System32\uxctnhyu.dll
C:\Windows\System32\gnsmfq.dll
C:\Windows\System32\txowijmk.dll
C:\Windows\System32\qvqawl.dll
C:\temp\Listdlls.exe
C:\Windows\System32\jkkLBrrP.dll
C:\Windows\unvise32.exe
C:\Windows\System32\awtrqPgg.dll
C:\Windows\S18FF1045.tmp
C:\Windows\system32\fccccArp.dll

Folder::
C:\VundoFix Backups

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5E1A1870-827E-4B7E-94BB-224E599A1C79}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=""


Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt

Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :

Cela va relancer Combofix,

Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

Ne touche à rien tant que le scan n'est pas terminé.

Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

S'il n'y a pas de rédémarrage, poste quand même les rapports.
-1
Utilisateur anonyme
 
Telecharge malwarebytes

Tu l´instale; le programme va se mettre automatiquement a jour.

Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

Puis click sur "rechercher".

Laisse le scanner le pc...

Si des elements on ete trouvés > click sur supprimer la selection.

si il t´es demandé de redemarrer > click sur "yes".

A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
Copie et colle le rapport stp.

PS : les rapport sont aussi rangé dans l onglet rapport/log
-1
Utilisateur anonyme
 
réouvre malewarebyte
va sur quarantaine
supprime tout

refais un scan hijackthis et post le rapport stp
-1
Utilisateur anonyme
 
fais un clic droit sur hijackthis
choisi executer en tant qu administrateur
fais scan only
coches ces lignes :

O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)

O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

tu les coches et tu clic sur fix checked

ensuite ;

-> Télécharge Ccleaner (n'installe pas la barre d'outil Yahoo):

http://download.piriform.com/ccsetup210.exe

https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

-> Tuto : https://www.malekal.com/tutoriel-ccleaner/

* pour supprimer les outils/fix utilisés :

Télécharge ToolsCleaner sur ton bureau.
-->
ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
http://pc-system.fr/

# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
-1
Utilisateur anonyme
 
supprime combofix de : Downloads

pour te securiser garde malewarebyte et ajoute si tu le desire

spywareblaster :

http://www.brightfort.com/spywareblaster.html

c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

tuto : https://www.malekal.com/tutorial-spywareblaster/

Pour completer spywareblaster rajoute spywareguard :

http://www.javacoolsoftware.net.nyud.net:8090/downloads/spywareguardsetup.exe

avis spywareblaster :

http://www.commentcamarche.net/telecharger/spyware blaster 226 avis opinions.php3#avis jalobservateur

avis spywareguard:

http://www.commentcamarche.net/telecharger/spywareguard 34055277 avis opinions.php3#avis jalobservateur

puis un bonus :

plugins Firefox : ad block plus, no script ect...

https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

si tu n as pas d autres soucis change le statut du sujet en resolu stp

http://www.commentcamarche.net/faq/sujet 11365 marquer un fil de discussion comme etant resolu
-1
Utilisateur anonyme
 
de rien pas de soucis

pour mettre resolu dans ton cas tu clic sur le point d exclamation jaune et tu signal

@++ en esperant pas te revoir -;)

bonne semaine
-1