Problème virus... vundo

Résolu
StarRain -  
 Utilisateur anonyme -
Bonjour,

J'ai essayé de me débarasser de ce virus, mais il revient toujours!!! J'ai passé vundofix (qui ne détecte rien), virtuabegone (qui ne détecte rien non plus) et combofix, qui efface des fichiers, mais 2 jours plus tard, le virus revient.. J'aurais besoin de votre aide svp... Je vous copie colle un hijackthis ainsi que ce qui est sorti du rapport combofix.. C'est spybot qui m'a indiqué que c'était virtuamonde, mais, lui non plus, ne répare qu'en superficie

Merci,

Logfile of HijackThis v1.99.1
Scan saved at 12:39:28, on 2008-09-15
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Users\Propriétaire\Downloads\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {079C9F8A-69E2-450C-8D29-D869A2D06638} - C:\Windows\system32\cmcofild.dll
O2 - BHO: {2c351262-e16b-0d28-fd64-120015acfd84} - {48dfca51-0021-46df-82d0-b61e262153c2} - C:\Windows\system32\jvwlqo.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {868392E6-B49D-463E-8CE2-E3541C792556} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: (no name) - {B5D90D1F-0732-416F-BF8C-B356B6B0EB13} - C:\Windows\system32\fccccArp.dll
O3 - Toolbar: Systran40premi.IEPlugIn - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\Premium\IEPlugIn.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [BM913d78b0] Rundll32.exe "C:\Windows\system32\fsebttdx.dll",s
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Hyperappel du Petit Larousse 2009.lnk = C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - AppInit_DLLs: vlcvca.dll mxhsom.dll qvqawl.dll gnsmfq.dll jvwlqo.dll
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

ComboFix 08-09-14.01 - Propriétaire 2008-09-14 22:09:58.2 - NTFSx86
Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2004 [GMT -4:00]
Lancé depuis: C:\Users\Propriétaire\Downloads\ComboFix.exe
* Un nouveau point de restauration a été créé
* Resident AV is active

.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\system32\edslkyto.dll
C:\Windows\system32\modufstm.dll
C:\Windows\System32\prAccccf.ini
C:\Windows\System32\prAccccf.ini2
C:\Windows\system32\rtlfhejt.ini
C:\Windows\system32\tjehfltr.dll

.
((((((((((((((((((((((((((((( Fichiers cr‚‚s du 2008-08-15 au 2008-09-15 ))))))))))))))))))))))))))))))))))))
.

2008-09-14 22:13 . 2008-09-14 22:14 259,357,973 --a------ C:\Windows\MEMORY.DMP
2008-09-14 20:28 . 2008-09-14 20:28 111,616 --a------ C:\Windows\System32\uxctnhyu.dll
2008-09-14 20:28 . 2008-09-14 20:28 111,616 --a------ C:\Windows\System32\gnsmfq.dll
2008-09-14 15:50 . 2008-09-14 15:50 111,616 --a------ C:\Windows\System32\txowijmk.dll
2008-09-14 15:50 . 2008-09-14 15:50 111,616 --a------ C:\Windows\System32\qvqawl.dll
2008-09-13 17:29 . 2008-09-13 17:30 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
2008-09-13 17:25 . 2008-09-13 17:25 <REP> d-------- C:\VundoFix Backups
2008-09-13 15:59 . 2008-09-13 15:59 268 --ah----- C:\sqmdata02.sqm
2008-09-13 15:59 . 2008-09-13 15:59 244 --ah----- C:\sqmnoopt02.sqm
2008-09-13 15:10 . 2008-09-13 18:16 <REP> d-------- C:\Program Files\Opera
2008-09-13 15:01 . 2008-09-13 15:01 244 --ah----- C:\sqmnoopt01.sqm
2008-09-13 15:01 . 2008-09-13 15:01 232 --ah----- C:\sqmdata01.sqm
2008-09-13 14:02 . 2008-09-13 14:02 0 --ah----- C:\ntuser.dat.LOG2
2008-09-13 14:02 . 2008-09-13 14:02 0 --ah----- C:\ntuser.dat.LOG1
2008-09-13 14:02 . 2008-09-13 14:02 0 --a------ C:\ntuser.dat
2008-09-13 13:35 . 2008-09-13 13:35 <REP> d-------- C:\temp
2008-09-13 13:34 . 2006-11-01 13:06 170,808 --a------ C:\temp\Listdlls.exe
2008-09-13 13:12 . 2008-09-13 13:12 244 --ah----- C:\sqmnoopt00.sqm
2008-09-13 13:12 . 2008-09-13 13:12 232 --ah----- C:\sqmdata00.sqm
2008-09-13 11:34 . 2008-09-13 12:56 <REP> d-------- C:\Users\All Users\Uniblue
2008-09-13 11:34 . 2008-09-13 12:56 <REP> d-------- C:\ProgramData\Uniblue
2008-09-13 11:29 . 2008-09-13 12:56 <REP> d-------- C:\Program Files\Uniblue
2008-09-08 17:14 . 2008-09-08 17:14 91 --a------ C:\Windows\wininit.ini
2008-09-08 16:51 . 2008-09-13 19:23 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
2008-09-08 16:51 . 2008-09-13 19:23 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
2008-09-08 16:22 . 2008-09-08 16:22 <REP> d-------- C:\Windows\Sun
2008-09-08 16:21 . 2008-09-08 16:22 <REP> d-------- C:\Program Files\Java
2008-09-08 16:21 . 2008-09-08 16:21 <REP> d-------- C:\Program Files\Common Files\Java
2008-09-07 15:05 . 2008-09-07 15:05 237,056 --a------ C:\Windows\System32\jkkLBrrP.dll
2008-09-07 13:51 . 1999-12-17 10:13 86,016 --a------ C:\Windows\unvise32.exe
2008-09-07 13:50 . 2008-09-07 13:50 <REP> d-------- C:\Program Files\Systran
2008-09-07 13:41 . 2008-09-07 13:41 <REP> d-------- C:\Program Files\Larousse
2008-09-07 13:41 . 2008-09-07 13:41 <REP> d-------- C:\Program Files\directx
2008-09-07 13:41 . 1998-06-17 19:07 57,344 --a------ C:\Windows\System32\Mfc42loc.dll
2008-09-07 13:38 . 2008-09-07 13:38 <REP> d-------- C:\Program Files\Alcohol Soft
2008-09-07 13:34 . 2008-09-07 13:34 685,816 --a------ C:\Windows\System32\drivers\sptd.sys
2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\Users\All Users\SlySoft
2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\ProgramData\SlySoft
2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\Program Files\SlySoft
2008-09-06 19:03 . 2008-09-06 19:03 237,056 --a------ C:\Windows\System32\awtrqPgg.dll
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Users\All Users\Apple Computer
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Users\All Users\Apple
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\ProgramData\Apple Computer
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\ProgramData\Apple
2008-09-06 17:54 . 2008-09-06 17:56 <REP> d-------- C:\Program Files\QuickTime
2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Program Files\Apple Software Update
2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\Windows\LHSP
2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\Windows\IUConnect
2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\HGASRAPI
2008-09-06 17:34 . 2002-08-18 22:28 96,256 --a------ C:\Windows\System32\SMACKW32.DLL
2008-09-06 17:34 . 1997-12-19 16:18 77,824 --a------ C:\Windows\asr32312.dll
2008-09-06 17:34 . 2008-09-06 17:34 70 --a------ C:\Windows\HGSpeech.ini
2008-09-06 17:33 . 2008-09-06 17:33 <REP> d-------- C:\Program Files\The Learning Company
2008-09-06 17:31 . 1997-05-12 17:53 314,368 --a------ C:\Windows\IsUninst.exe
2008-09-06 17:26 . 2008-09-06 17:26 0 --a------ C:\Windows\setup32.INI
2008-09-06 17:13 . 2008-09-06 17:13 237,056 --------- C:\Windows\System32\fccccArp.dll
2008-09-06 17:07 . 2008-09-06 17:07 <REP> d-------- C:\Program Files\PowerISO
2008-09-06 17:04 . 2008-09-06 17:04 <REP> d-------- C:\Program Files\MagicISO
2008-09-06 13:14 . 2008-09-06 13:14 <REP> d-------- C:\Users\All Users\vsosdk
2008-09-06 13:14 . 2008-09-06 13:14 <REP> d-------- C:\ProgramData\vsosdk
2008-09-06 12:23 . 2008-09-06 12:23 <REP> d-------- C:\Users\All Users\Real
2008-09-06 12:23 . 2008-09-06 12:23 <REP> d-------- C:\Program Files\K-Lite Codec Pack
2008-08-31 21:11 . 2008-08-31 21:20 <REP> d-------- C:\Program Files\Windows Live
2008-08-31 21:00 . 2003-03-18 22:20 1,060,864 --a------ C:\Windows\System32\MFC71.dll
2008-08-31 20:59 . 2008-08-31 21:15 <REP> d-------- C:\Program Files\Logitech
2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\Users\All Users\ma-config.com
2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\ProgramData\ma-config.com
2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\Program Files\ma-config.com
2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\Users\All Users\DVD Shrink
2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\ProgramData\DVD Shrink
2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\Program Files\DVD Shrink
2008-08-31 09:50 . 2008-08-31 09:50 <REP> d-------- C:\Users\All Users\Elaborate Bytes
2008-08-31 09:50 . 2008-08-31 09:50 <REP> d-------- C:\ProgramData\Elaborate Bytes
2008-08-31 09:50 . 2008-08-31 09:50 24 ---hs---- C:\Windows\S18FF1045.tmp
2008-08-31 09:49 . 2008-08-31 09:49 <REP> d-------- C:\Program Files\Elaborate Bytes
2008-08-31 03:01 . 2008-08-31 03:01 <REP> d-------- C:\Program Files\MSXML 4.0
2008-08-30 19:33 . 2003-06-26 23:05 472,332 --a------ C:\Windows\System32\drivers\lvcm.sys
2008-08-30 19:33 . 2003-06-26 23:12 327,680 --a------ C:\Windows\System32\LVUI2RC.dll
2008-08-30 19:33 . 2003-06-26 23:11 172,032 --a------ C:\Windows\System32\lvcodec2.dll
2008-08-30 19:33 . 2003-06-26 23:09 135,214 --a------ C:\Windows\System32\LVComS.exe
2008-08-30 19:33 . 2003-06-26 23:11 122,880 --a------ C:\Windows\System32\LVUI2.dll
2008-08-30 19:33 . 2003-06-26 23:14 77,824 --a------ C:\Windows\System32\lvcoinst.dll
2008-08-30 19:33 . 2003-06-26 23:10 57,344 --a------ C:\Windows\System32\LVComC.dll
2008-08-30 19:33 . 2003-06-26 22:40 14,938 --a------ C:\Windows\System32\lvcoinst.ini
2008-08-30 19:33 . 2003-06-26 23:03 12,112 --a------ C:\Windows\System32\drivers\LVUSBSta.sys
2008-08-30 16:14 . 2008-08-30 16:14 <REP> d-------- C:\Program Files\Druide
2008-08-30 16:14 . 1999-03-23 09:12 304,128 --a------ C:\Windows\unin040c.exe
2008-08-30 16:14 . 2008-08-30 16:19 3,554 --a------ C:\Windows\Antidote.ini
2008-08-30 16:14 . 2008-08-30 16:14 0 --a------ C:\Windows\PROTOCOL.INI
2008-08-30 16:06 . 2008-08-30 16:06 <REP> d-------- C:\Program Files\VSO
2008-08-30 16:06 . 2006-09-29 11:24 217,127 --a------ C:\Windows\System32\drv43260.dll
2008-08-30 16:06 . 2006-09-29 11:25 208,935 --a------ C:\Windows\System32\drv33260.dll
2008-08-30 16:06 . 2006-09-29 11:26 176,165 --a------ C:\Windows\System32\drv23260.dll
2008-08-30 16:06 . 2008-08-30 16:06 47,360 --a------ C:\Windows\System32\drivers\pcouffin.sys
2008-08-30 15:52 . 2008-08-30 15:52 <REP> d-------- C:\Binarema
2008-08-30 15:15 . 2008-08-30 15:15 <REP> d-------- C:\Users\All Users\Nero
2008-08-30 15:15 . 2008-08-30 15:15 <REP> d-------- C:\ProgramData\Nero
2008-08-30 15:15 . 2008-08-30 15:17 <REP> d-------- C:\Program Files\Common Files\Nero
2008-08-30 14:50 . 2008-08-30 14:50 <REP> d-------- C:\Users\All Users\WindowsSearch
2008-08-30 14:50 . 2008-08-30 14:50 <REP> d-------- C:\ProgramData\WindowsSearch
2008-08-30 14:25 . 2008-08-30 14:25 <REP> d-------- C:\Program Files\Microsoft Office Outlook Connector
2008-08-30 14:24 . 2008-08-30 14:24 <REP> d-------- C:\Program Files\MSECache
2008-08-30 11:13 . 2008-08-30 11:13 <REP> d-------- C:\Users\PropriǸtaire
2008-08-30 11:12 . 2008-08-30 11:14 <REP> d-------- C:\Program Files\SecondLife
2008-08-25 22:19 . 2008-08-25 18:16 <REP> d-------- C:\Windows\Debug
2008-08-25 18:45 . 2008-08-25 18:49 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-25 18:44 . 2008-08-31 21:16 <REP> d-------- C:\Users\All Users\WLInstaller
2008-08-25 18:44 . 2008-08-31 21:16 <REP> d-------- C:\ProgramData\WLInstaller
2008-08-25 18:38 . 2008-08-25 18:38 <REP> d-------- C:\Users\All Users\CyberLink
2008-08-25 18:38 . 2008-08-25 18:38 <REP> d-------- C:\ProgramData\CyberLink
2008-08-25 18:30 . 2008-09-10 16:57 <REP> d-------- C:\Downloads
2008-08-25 18:29 . 2008-09-06 11:38 <REP> d-------- C:\Program Files\BitComet
2008-08-25 18:26 . 2008-09-10 16:22 <REP> d-------- C:\Users\All Users\SiteAdvisor
2008-08-25 18:26 . 2008-09-10 16:22 <REP> d-------- C:\ProgramData\SiteAdvisor
2008-08-25 18:26 . 2008-09-14 22:14 5,995 --a------ C:\Windows\System32\Config.MPF
2008-08-25 18:25 . 2008-08-25 18:25 <REP> d-------- C:\Program Files\McAfee.com
2008-08-25 18:25 . 2008-09-12 16:12 <REP> d-------- C:\Program Files\McAfee
2008-08-25 18:25 . 2008-08-25 18:25 <REP> d-------- C:\Program Files\Common Files\McAfee
2008-08-25 18:25 . 2007-11-22 06:44 201,320 --a------ C:\Windows\System32\drivers\mfehidk.sys
2008-08-25 18:25 . 2007-07-13 06:21 125,728 --a------ C:\Windows\System32\drivers\Mpfp.sys
2008-08-25 18:25 . 2007-11-22 06:44 79,304 --a------ C:\Windows\System32\drivers\mfeavfk.sys
2008-08-25 18:25 . 2007-12-02 12:51 40,488 --a------ C:\Windows\System32\drivers\mfesmfk.sys
2008-08-25 18:25 . 2007-11-22 06:44 35,240 --a------ C:\Windows\System32\drivers\mfebopk.sys
2008-08-25 18:25 . 2007-11-22 06:44 33,832 --a------ C:\Windows\System32\drivers\mferkdk.sys
2008-08-25 18:20 . 2008-09-10 16:22 <REP> d-------- C:\Users\All Users\McAfee

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-25 15:22 --------- d-----w C:\Program Files\Windows Mail
2008-08-25 14:30 319,456 ----a-w C:\Windows\DIFxAPI.dll
2008-08-25 14:30 315,392 ----a-w C:\Windows\HideWin.exe
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Modèles
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Menu Démarrer
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Favoris
2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Bureau
2008-08-25 14:17 --------- d-sh--w C:\Program Files\Fichiers communs
2008-07-21 12:11 24,392 ----a-w C:\Windows\system32\drivers\ElbyCDIO.sys
2008-06-24 20:06 972,072 ----a-w C:\Windows\UNNeroMediaHome.exe
2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
.

((((((((((((((((((((((((((((( snapshot@2008-09-13_20.06.14.31 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-09-14 00:04:27 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-09-15 02:13:58 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-09-14 00:04:27 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-09-15 02:13:46 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-09-15 02:13:46 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-09-14 00:00:36 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-09-14 14:51:23 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-09-14 00:00:36 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-09-14 14:51:23 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-09-14 00:00:36 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-14 14:51:23 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-09-15 02:06:13 5,862 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\18416CE8A96446C112DCE8009282548E784E7F84\973BC48B576C8188F2CEF3650B160AE03BD729D1\Data.dat
- 2008-09-13 22:08:47 6,276 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\4D5367EBDE22F22AB910D2E11BF07B236BD5EB37\4D5367EBDE22F22AB910D2E11BF07B236BD5EB37\Data.dat
+ 2008-09-15 02:06:36 6,276 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\4D5367EBDE22F22AB910D2E11BF07B236BD5EB37\4D5367EBDE22F22AB910D2E11BF07B236BD5EB37\Data.dat
- 2008-09-13 23:24:07 6,996 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\4E1D50A4EAD3C2690DE40E56982070589075DB82\4E1D50A4EAD3C2690DE40E56982070589075DB82\Data.dat
+ 2008-09-15 02:06:10 6,996 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\4E1D50A4EAD3C2690DE40E56982070589075DB82\4E1D50A4EAD3C2690DE40E56982070589075DB82\Data.dat
+ 2008-09-15 00:28:58 4,970 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\76E4EF5A79EAB98F93EF5ED761278B478EC5EF77\76E4EF5A79EAB98F93EF5ED761278B478EC5EF77\Data.dat
+ 2008-09-15 00:28:56 3,468 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\BE9922FA3E7D2ECAE929B718CA2D14473CB81E07\BE9922FA3E7D2ECAE929B718CA2D14473CB81E07\Data.dat
- 2008-09-14 00:00:52 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-09-15 02:09:52 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-09-15 02:09:52 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
- 2008-09-13 23:27:38 101,896 ----a-w C:\Windows\System32\perfc009.dat
+ 2008-09-14 14:55:37 101,896 ----a-w C:\Windows\System32\perfc009.dat
- 2008-09-13 23:27:38 124,228 ----a-w C:\Windows\System32\perfc00C.dat
+ 2008-09-14 14:55:37 124,228 ----a-w C:\Windows\System32\perfc00C.dat
- 2008-09-13 23:27:38 589,884 ----a-w C:\Windows\System32\perfh009.dat
+ 2008-09-14 14:55:37 589,884 ----a-w C:\Windows\System32\perfh009.dat
- 2008-09-13 23:27:38 672,084 ----a-w C:\Windows\System32\perfh00C.dat
+ 2008-09-14 14:55:37 672,084 ----a-w C:\Windows\System32\perfh00C.dat
- 2008-09-13 19:18:04 5,222 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-295252437-1548751239-3619892269-1000_UserData.bin
+ 2008-09-14 14:50:55 5,556 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-295252437-1548751239-3619892269-1000_UserData.bin
- 2008-09-13 19:18:04 64,716 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-09-14 14:50:55 64,926 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-09-13 23:23:04 35,752 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-09-14 14:50:54 36,222 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5E1A1870-827E-4B7E-94BB-224E599A1C79}]
2008-09-06 17:13 237056 --------- C:\Windows\system32\fccccArp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-20 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"Gestionnaire Antidote.exe"="C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe" [2002-11-07 143360]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
"Uniblue RegistryBooster 2009"="c:\program files\uniblue\registrybooster\StartRegistryBooster.exe" [BU]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
"LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-16 13535776]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-16 92704]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"RtHDVCpl"="RtHDVCpl.exe" [2008-05-20 C:\Windows\RtHDVCpl.exe]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Hyperappel du Petit Larousse 2009.lnk - C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe [2008-09-07 237568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=vlcvca.dll mxhsom.dll qvqawl.dll gnsmfq.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.YV12"= yv12vfw.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-295252437-1548751239-3619892269-1000]
"EnableNotificationsRef"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"TCP Query User{DAC81081-FBB4-4452-84A1-CBFA60292391}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{7307F9B1-37A9-4DB4-8B00-D6964BA564D7}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"{08AE761A-9F8B-4A3B-A942-B1E34F72215A}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{9E46F0BB-4775-4746-B085-42D175881C9C}"= UDP:17842:BitComet 17842 TCP
"{1E7F9CC7-38AA-4238-958F-041D7FA3B6F5}"= TCP:17842:BitComet 17842 UDP
"{72C072DE-6190-46E9-9441-345FACE1834F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{961772C2-CC22-414B-8357-9D49E3020317}"= UDP:25937:BitComet 25937 TCP
"{0BD1CE4F-8154-4B05-AD04-30104AB8C4DE}"= TCP:25937:BitComet 25937 UDP
"{AD7218B8-1B4E-4C5D-B875-85C47996B946}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
"{01D01E03-D7CD-47C3-8AED-A691F9909402}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
"{A1F003DC-A7EF-43D4-8C73-27BDFA6301BD}"= UDP:C:\Program Files\ma-config.com\maconfservice.exe:maconfservice
"{F375F858-47CF-47BE-8D26-1D9397D75326}"= TCP:C:\Program Files\ma-config.com\maconfservice.exe:maconfservice
"{2A538FDB-ADFB-44ED-A190-585F7A2F1529}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R0 mv61xx;mv61xx;C:\Windows\system32\DRIVERS\mv61xx.sys [2008-06-10 150568]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296]
R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113 PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1E60x86.sys [2008-02-02 47616]
S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-07-25 191656]
S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656]
S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]
.
Contenu du dossier 'Tƒches planifi‚es'
.
- - - - ORPHELINS SUPPRIMES - - - -

BHO-{7FF2E2EB-7BC1-49F1-83D4-5772C4414E2A} - (no file)

.
------- Examen suppl‚mentaire -------
.
FireFox -: Profile - C:\Users\Propriétaire\AppData\Roaming\Mozilla\Firefox\Profiles\uanfayrj.default\
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-14 22:14:31
Windows 6.0.6001 Service Pack 1 NTFS

Recherche de processus cach‚s ...

Recherche d'‚l‚ments en d‚marrage automatique cach‚s ...

Recherche de fichiers cach‚s ...

C:\Users\Propriétaire\AppData\Local\Microsoft\Windows\WER\ReportArchive\store.lock 0 bytes
C:\Users\Propriétaire\AppData\Local\Microsoft\Windows\WER\ReportQueue\store.lock 0 bytes
C:\Users\Propriétaire\AppData\Local\Temp\WER-64241-0.sysdata.xml 229106 bytes

Scan termin‚ avec succŠs
Fichiers cach‚s: 3

**************************************************************************
.
--------------------- DLLs charg‚es dans les processus actifs ---------------------

PROCESSUS: C:\Windows\Explorer.exe
-> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
-> ?:\Windows\system32\iertutil.dll
.
------------------------ Autres processus actifs ------------------------
.
C:\Windows\System32\nvvsvc.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\ASUS\Six Engine\SixEngine.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\IoctlSvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
C:\Program Files\McAfee\VirusScan\mcsysmon.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\Windows\System32\dllhost.exe
C:\PROGRA~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Heure de fin: 2008-09-14 22:17:20 - La machine a red‚marr‚
ComboFix-quarantined-files.txt 2008-09-15 02:17:10
ComboFix2.txt 2008-09-14 00:07:21

Avant-CF: 461,749,342,208 octets libres
AprŠs-CF: 462,095,048,704 octets libres

319 --- E O F --- 2008-09-01 01:13:52
Configuration: Windows Vista
Firefox 3.0.1

13 réponses

  1. StarRain
     
    Bonjour Chiquitine,

    Merci bcp de ton aide, c'est très très apprécié :-)

    Voici mon rapport combofix ainsi qu'un rapport hijackthis passer après que j'ai fais le combo..

    Merci, j'Attends de tes nouvelles!!

    ComboFix 08-09-14.01 - Propriétaire 2008-09-15 16:28:16.3 - NTFSx86
    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.2002 [GMT -4:00]
    Lancé depuis: C:\Users\Propriétaire\Downloads\ComboFix.exe
    Command switches used :: C:\Users\Propriétaire\Downloads\CFScript.txt
    * Un nouveau point de restauration a été créé
    * Resident AV is active

    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\temp\Listdlls.exe
    C:\VundoFix Backups
    C:\Windows\S18FF1045.tmp
    C:\Windows\System32\awtrqPgg.dll
    C:\Windows\system32\ccndgaim.dll
    C:\Windows\system32\cmcofild.dll
    C:\Windows\system32\cxywxgna.dll
    C:\Windows\system32\efofngxm.dll
    C:\Windows\system32\fccccArp.dll
    C:\Windows\system32\fcwnkwek.dll
    C:\Windows\system32\fsebttdx.dll
    C:\Windows\System32\gnsmfq.dll
    C:\Windows\System32\jkkLBrrP.dll
    C:\Windows\system32\jtfglbhp.dll
    C:\Windows\system32\lasxquyu.dll
    C:\Windows\system32\luvcdsdn.dll
    C:\Windows\system32\ngicirxw.dll
    C:\Windows\System32\prAccccf.ini
    C:\Windows\System32\prAccccf.ini2
    C:\Windows\System32\qvqawl.dll
    C:\Windows\system32\rrwfkghx.ini
    C:\Windows\System32\txowijmk.dll
    C:\Windows\system32\uuvwdyhk.dll
    C:\Windows\System32\uxctnhyu.dll
    C:\Windows\system32\vwdlwsld.dll
    C:\Windows\system32\xhgkfwrr.dll
    C:\Windows\unvise32.exe
    C:\WINDOWS\wininit.ini

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s du 2008-08-15 au 2008-09-15 ))))))))))))))))))))))))))))))))))))
    .

    2008-09-14 22:35 . 2008-09-14 22:35 111,616 --a------ C:\Windows\System32\jvwlqo.dll
    2008-09-14 22:35 . 2008-09-14 22:35 111,616 --a------ C:\Windows\System32\gmdvhxsy.dll
    2008-09-14 22:25 . 2008-08-01 21:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
    2008-09-14 22:25 . 2008-06-25 23:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
    2008-09-14 22:25 . 2008-05-08 15:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
    2008-09-14 22:25 . 2008-05-19 22:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
    2008-09-14 22:25 . 2008-06-25 23:29 45,056 --a------ C:\Windows\System32\dataclen.dll
    2008-09-14 22:25 . 2008-08-01 23:26 36,864 --a------ C:\Windows\System32\cdd.dll
    2008-09-14 22:13 . 2008-09-14 22:14 259,357,973 --a------ C:\Windows\MEMORY.DMP
    2008-09-13 17:29 . 2008-09-13 17:30 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-09-13 15:59 . 2008-09-13 15:59 268 --ah----- C:\sqmdata02.sqm
    2008-09-13 15:59 . 2008-09-13 15:59 244 --ah----- C:\sqmnoopt02.sqm
    2008-09-13 15:10 . 2008-09-13 18:16 <REP> d-------- C:\Program Files\Opera
    2008-09-13 15:01 . 2008-09-13 15:01 244 --ah----- C:\sqmnoopt01.sqm
    2008-09-13 15:01 . 2008-09-13 15:01 232 --ah----- C:\sqmdata01.sqm
    2008-09-13 14:02 . 2008-09-13 14:02 0 --ah----- C:\ntuser.dat.LOG2
    2008-09-13 14:02 . 2008-09-13 14:02 0 --ah----- C:\ntuser.dat.LOG1
    2008-09-13 14:02 . 2008-09-13 14:02 0 --a------ C:\ntuser.dat
    2008-09-13 13:35 . 2008-09-15 16:28 <REP> d-------- C:\temp
    2008-09-13 13:12 . 2008-09-13 13:12 244 --ah----- C:\sqmnoopt00.sqm
    2008-09-13 13:12 . 2008-09-13 13:12 232 --ah----- C:\sqmdata00.sqm
    2008-09-13 11:34 . 2008-09-13 12:56 <REP> d-------- C:\Users\All Users\Uniblue
    2008-09-13 11:34 . 2008-09-13 12:56 <REP> d-------- C:\ProgramData\Uniblue
    2008-09-13 11:29 . 2008-09-13 12:56 <REP> d-------- C:\Program Files\Uniblue
    2008-09-08 16:51 . 2008-09-13 19:23 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
    2008-09-08 16:51 . 2008-09-13 19:23 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
    2008-09-08 16:22 . 2008-09-08 16:22 <REP> d-------- C:\Windows\Sun
    2008-09-08 16:21 . 2008-09-08 16:22 <REP> d-------- C:\Program Files\Java
    2008-09-08 16:21 . 2008-09-08 16:21 <REP> d-------- C:\Program Files\Common Files\Java
    2008-09-07 13:50 . 2008-09-07 13:50 <REP> d-------- C:\Program Files\Systran
    2008-09-07 13:41 . 2008-09-07 13:41 <REP> d-------- C:\Program Files\Larousse
    2008-09-07 13:41 . 2008-09-07 13:41 <REP> d-------- C:\Program Files\directx
    2008-09-07 13:41 . 1998-06-17 19:07 57,344 --a------ C:\Windows\System32\Mfc42loc.dll
    2008-09-07 13:38 . 2008-09-07 13:38 <REP> d-------- C:\Program Files\Alcohol Soft
    2008-09-07 13:34 . 2008-09-07 13:34 685,816 --a------ C:\Windows\System32\drivers\sptd.sys
    2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\Users\All Users\SlySoft
    2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\ProgramData\SlySoft
    2008-09-07 13:24 . 2008-09-07 13:24 <REP> d-------- C:\Program Files\SlySoft
    2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Users\All Users\Apple Computer
    2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Users\All Users\Apple
    2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\ProgramData\Apple Computer
    2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\ProgramData\Apple
    2008-09-06 17:54 . 2008-09-06 17:56 <REP> d-------- C:\Program Files\QuickTime
    2008-09-06 17:54 . 2008-09-06 17:54 <REP> d-------- C:\Program Files\Apple Software Update
    2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\Windows\LHSP
    2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\Windows\IUConnect
    2008-09-06 17:34 . 2008-09-06 17:34 <REP> d-------- C:\HGASRAPI
    2008-09-06 17:34 . 2002-08-18 22:28 96,256 --a------ C:\Windows\System32\SMACKW32.DLL
    2008-09-06 17:34 . 1997-12-19 16:18 77,824 --a------ C:\Windows\asr32312.dll
    2008-09-06 17:34 . 2008-09-06 17:34 70 --a------ C:\Windows\HGSpeech.ini
    2008-09-06 17:33 . 2008-09-06 17:33 <REP> d-------- C:\Program Files\The Learning Company
    2008-09-06 17:31 . 1997-05-12 17:53 314,368 --a------ C:\Windows\IsUninst.exe
    2008-09-06 17:26 . 2008-09-06 17:26 0 --a------ C:\Windows\setup32.INI
    2008-09-06 17:07 . 2008-09-06 17:07 <REP> d-------- C:\Program Files\PowerISO
    2008-09-06 17:04 . 2008-09-06 17:04 <REP> d-------- C:\Program Files\MagicISO
    2008-09-06 13:14 . 2008-09-06 13:14 <REP> d-------- C:\Users\All Users\vsosdk
    2008-09-06 13:14 . 2008-09-06 13:14 <REP> d-------- C:\ProgramData\vsosdk
    2008-09-06 12:23 . 2008-09-06 12:23 <REP> d-------- C:\Users\All Users\Real
    2008-09-06 12:23 . 2008-09-06 12:23 <REP> d-------- C:\Program Files\K-Lite Codec Pack
    2008-08-31 21:11 . 2008-08-31 21:20 <REP> d-------- C:\Program Files\Windows Live
    2008-08-31 21:00 . 2003-03-18 22:20 1,060,864 --a------ C:\Windows\System32\MFC71.dll
    2008-08-31 20:59 . 2008-08-31 21:15 <REP> d-------- C:\Program Files\Logitech
    2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\Users\All Users\ma-config.com
    2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\ProgramData\ma-config.com
    2008-08-31 20:54 . 2008-08-31 20:54 <REP> d-------- C:\Program Files\ma-config.com
    2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\Users\All Users\DVD Shrink
    2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\ProgramData\DVD Shrink
    2008-08-31 09:57 . 2008-08-31 09:57 <REP> d-------- C:\Program Files\DVD Shrink
    2008-08-31 09:50 . 2008-08-31 09:50 <REP> d-------- C:\Users\All Users\Elaborate Bytes
    2008-08-31 09:50 . 2008-08-31 09:50 <REP> d-------- C:\ProgramData\Elaborate Bytes
    2008-08-31 09:49 . 2008-08-31 09:49 <REP> d-------- C:\Program Files\Elaborate Bytes
    2008-08-31 03:01 . 2008-08-31 03:01 <REP> d-------- C:\Program Files\MSXML 4.0
    2008-08-30 19:33 . 2003-06-26 23:05 472,332 --a------ C:\Windows\System32\drivers\lvcm.sys
    2008-08-30 19:33 . 2003-06-26 23:12 327,680 --a------ C:\Windows\System32\LVUI2RC.dll
    2008-08-30 19:33 . 2003-06-26 23:11 172,032 --a------ C:\Windows\System32\lvcodec2.dll
    2008-08-30 19:33 . 2003-06-26 23:09 135,214 --a------ C:\Windows\System32\LVComS.exe
    2008-08-30 19:33 . 2003-06-26 23:11 122,880 --a------ C:\Windows\System32\LVUI2.dll
    2008-08-30 19:33 . 2003-06-26 23:14 77,824 --a------ C:\Windows\System32\lvcoinst.dll
    2008-08-30 19:33 . 2003-06-26 23:10 57,344 --a------ C:\Windows\System32\LVComC.dll
    2008-08-30 19:33 . 2003-06-26 22:40 14,938 --a------ C:\Windows\System32\lvcoinst.ini
    2008-08-30 19:33 . 2003-06-26 23:03 12,112 --a------ C:\Windows\System32\drivers\LVUSBSta.sys
    2008-08-30 16:14 . 2008-08-30 16:14 <REP> d-------- C:\Program Files\Druide
    2008-08-30 16:14 . 1999-03-23 09:12 304,128 --a------ C:\Windows\unin040c.exe
    2008-08-30 16:14 . 2008-08-30 16:19 3,554 --a------ C:\Windows\Antidote.ini
    2008-08-30 16:14 . 2008-08-30 16:14 0 --a------ C:\Windows\PROTOCOL.INI
    2008-08-30 16:06 . 2008-08-30 16:06 <REP> d-------- C:\Program Files\VSO
    2008-08-30 16:06 . 2006-09-29 11:24 217,127 --a------ C:\Windows\System32\drv43260.dll
    2008-08-30 16:06 . 2006-09-29 11:25 208,935 --a------ C:\Windows\System32\drv33260.dll
    2008-08-30 16:06 . 2006-09-29 11:26 176,165 --a------ C:\Windows\System32\drv23260.dll
    2008-08-30 16:06 . 2008-08-30 16:06 47,360 --a------ C:\Windows\System32\drivers\pcouffin.sys
    2008-08-30 15:52 . 2008-08-30 15:52 <REP> d-------- C:\Binarema
    2008-08-30 15:15 . 2008-08-30 15:15 <REP> d-------- C:\Users\All Users\Nero
    2008-08-30 15:15 . 2008-08-30 15:15 <REP> d-------- C:\ProgramData\Nero
    2008-08-30 15:15 . 2008-08-30 15:17 <REP> d-------- C:\Program Files\Common Files\Nero
    2008-08-30 14:50 . 2008-08-30 14:50 <REP> d-------- C:\Users\All Users\WindowsSearch
    2008-08-30 14:50 . 2008-08-30 14:50 <REP> d-------- C:\ProgramData\WindowsSearch
    2008-08-30 14:25 . 2008-08-30 14:25 <REP> d-------- C:\Program Files\Microsoft Office Outlook Connector
    2008-08-30 14:24 . 2008-08-30 14:24 <REP> d-------- C:\Program Files\MSECache
    2008-08-30 11:13 . 2008-08-30 11:13 <REP> d-------- C:\Users\PropriǸtaire
    2008-08-30 11:12 . 2008-08-30 11:14 <REP> d-------- C:\Program Files\SecondLife
    2008-08-25 22:19 . 2008-08-25 18:16 <REP> d-------- C:\Windows\Debug
    2008-08-25 18:45 . 2008-08-25 18:49 <REP> d--hsc--- C:\Program Files\Common Files\WindowsLiveInstaller
    2008-08-25 18:44 . 2008-08-31 21:16 <REP> d-------- C:\Users\All Users\WLInstaller
    2008-08-25 18:44 . 2008-08-31 21:16 <REP> d-------- C:\ProgramData\WLInstaller
    2008-08-25 18:38 . 2008-08-25 18:38 <REP> d-------- C:\Users\All Users\CyberLink
    2008-08-25 18:38 . 2008-08-25 18:38 <REP> d-------- C:\ProgramData\CyberLink
    2008-08-25 18:30 . 2008-09-10 16:57 <REP> d-------- C:\Downloads
    2008-08-25 18:29 . 2008-09-06 11:38 <REP> d-------- C:\Program Files\BitComet
    2008-08-25 18:26 . 2008-09-10 16:22 <REP> d-------- C:\Users\All Users\SiteAdvisor
    2008-08-25 18:26 . 2008-09-10 16:22 <REP> d-------- C:\ProgramData\SiteAdvisor
    2008-08-25 18:26 . 2008-09-15 16:32 5,995 --a------ C:\Windows\System32\Config.MPF
    2008-08-25 18:25 . 2008-08-25 18:25 <REP> d-------- C:\Program Files\McAfee.com
    2008-08-25 18:25 . 2008-09-12 16:12 <REP> d-------- C:\Program Files\McAfee
    2008-08-25 18:25 . 2008-08-25 18:25 <REP> d-------- C:\Program Files\Common Files\McAfee
    2008-08-25 18:25 . 2007-11-22 06:44 201,320 --a------ C:\Windows\System32\drivers\mfehidk.sys
    2008-08-25 18:25 . 2007-07-13 06:21 125,728 --a------ C:\Windows\System32\drivers\Mpfp.sys
    2008-08-25 18:25 . 2007-11-22 06:44 79,304 --a------ C:\Windows\System32\drivers\mfeavfk.sys
    2008-08-25 18:25 . 2007-12-02 12:51 40,488 --a------ C:\Windows\System32\drivers\mfesmfk.sys
    2008-08-25 18:25 . 2007-11-22 06:44 35,240 --a------ C:\Windows\System32\drivers\mfebopk.sys
    2008-08-25 18:25 . 2007-11-22 06:44 33,832 --a------ C:\Windows\System32\drivers\mferkdk.sys
    2008-08-25 18:20 . 2008-09-10 16:22 <REP> d-------- C:\Users\All Users\McAfee
    2008-08-25 18:20 . 2008-09-10 16:22 <REP> d-------- C:\ProgramData\McAfee
    2008-08-25 18:15 . 2007-04-09 13:23 28,040 --a------ C:\Windows\System32\mdimon.dll
    2008-08-25 18:15 . 2008-08-25 18:15 382 --a------ C:\Windows\ODBC.INI
    2008-08-25 18:13 . 2008-08-25 18:13 <REP> d-------- C:\Windows\PCHEALTH

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-08-25 15:22 --------- d-----w C:\Program Files\Windows Mail
    2008-08-25 14:30 319,456 ----a-w C:\Windows\DIFxAPI.dll
    2008-08-25 14:30 315,392 ----a-w C:\Windows\HideWin.exe
    2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Modèles
    2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Menu Démarrer
    2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Favoris
    2008-08-25 14:17 --------- d-sh--w C:\ProgramData\Bureau
    2008-08-25 14:17 --------- d-sh--w C:\Program Files\Fichiers communs
    2008-07-25 08:34 81,920 ----a-w C:\Windows\System32\dpl100.dll
    2008-07-25 08:34 683,520 ----a-w C:\Windows\System32\divx.dll
    2008-07-23 16:50 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
    2008-07-21 12:11 24,392 ----a-w C:\Windows\system32\drivers\ElbyCDIO.sys
    2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll
    2008-06-26 11:06 93,128 ----a-w C:\Windows\System32\ElbyCDIO.dll
    2008-06-24 20:06 972,072 ----a-w C:\Windows\UNNeroMediaHome.exe
    2008-06-19 03:31 361,984 ----a-w C:\Windows\System32\IPSECSVC.DLL
    2008-01-21 02:43 174 --sha-w C:\Program Files\desktop.ini
    .

    ((((((((((((((((((((((((((((( snapshot_2008-09-14_22.16.15.94 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-09-15 20:28:04 6,258,688 ----a-w C:\Windows\erdnt\Hiv-backup\SCHEMA.DAT
    + 2008-09-15 20:30:18 6,258,688 ----a-w C:\Windows\erdnt\subs\SCHEMA.DAT
    - 2008-09-15 02:13:58 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
    + 2008-09-15 20:32:11 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
    + 2008-09-15 20:32:11 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
    - 2008-09-15 02:13:46 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
    + 2008-09-15 20:32:03 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
    + 2008-09-15 20:32:03 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
    - 2008-09-14 14:51:23 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-09-15 16:14:34 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2008-09-14 14:51:23 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-09-15 16:14:34 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-09-14 14:51:23 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-09-15 16:14:34 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-09-15 20:24:12 6,384 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\BA73419CB1C7E95D312F7EAF9967147ADD5FC0F1\BA73419CB1C7E95D312F7EAF9967147ADD5FC0F1\Data.dat
    + 2008-09-15 20:22:42 7,148 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\SACore\Cache\DA39A3EE5E6B4B0D3255BFEF95601890AFD80709\E6D66408E2E8C41284F6F3818922AE0585617EED\E6D66408E2E8C41284F6F3818922AE0585617EED\Data.dat
    - 2008-09-14 14:55:37 101,896 ----a-w C:\Windows\System32\perfc009.dat
    + 2008-09-15 16:18:44 101,896 ----a-w C:\Windows\System32\perfc009.dat
    - 2008-09-14 14:55:37 124,228 ----a-w C:\Windows\System32\perfc00C.dat
    + 2008-09-15 16:18:44 124,228 ----a-w C:\Windows\System32\perfc00C.dat
    - 2008-09-14 14:55:37 589,884 ----a-w C:\Windows\System32\perfh009.dat
    + 2008-09-15 16:18:44 589,884 ----a-w C:\Windows\System32\perfh009.dat
    - 2008-09-14 14:55:37 672,084 ----a-w C:\Windows\System32\perfh00C.dat
    + 2008-09-15 16:18:44 672,084 ----a-w C:\Windows\System32\perfh00C.dat
    - 2008-09-06 21:29:49 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
    + 2008-09-15 20:30:18 6,258,688 ----a-w C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT
    - 2008-09-14 14:50:55 5,556 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-295252437-1548751239-3619892269-1000_UserData.bin
    + 2008-09-15 02:16:01 5,882 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-295252437-1548751239-3619892269-1000_UserData.bin
    - 2008-09-14 14:50:55 64,926 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2008-09-15 16:14:20 65,050 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2008-09-14 14:50:54 36,222 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-09-15 16:14:19 36,270 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    - 2008-09-01 01:13:09 28,223,113 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
    + 2008-09-15 02:24:57 29,133,893 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
    + 2008-03-08 01:58:43 2,560 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.18112_none_0c196ab7f252b793\AcRes.dll
    + 2008-06-12 05:28:53 541,696 ----a-w C:\Windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c5_31bf3856ad364e35_6.0.6001.18112_none_0c1d6bdff24f1cef\AcLayers.dll
    + 2008-06-26 03:29:02 45,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-dataclen_31bf3856ad364e35_6.0.6001.18098_none_f64ce87593b7801f\dataclen.dll
    + 2008-06-26 03:15:06 45,056 ----a-w C:\Windows\winsxs\x86_microsoft-windows-dataclen_31bf3856ad364e35_6.0.6001.22211_none_f7260480ac9a8c27\dataclen.dll
    + 2008-06-26 03:29:02 565,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.18098_none_9e329f52f6fc276d\emdmgmt.dll
    + 2008-06-26 03:15:30 565,248 ----a-w C:\Windows\winsxs\x86_microsoft-windows-e..emorydevicesservice_31bf3856ad364e35_6.0.6001.22211_none_9f0bbb5e0fdf3375\emdmgmt.dll
    + 2008-03-08 04:21:55 1,695,744 ----a-w C:\Windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18112_none_41f7819cc1434d41\gameux.dll
    + 2008-08-02 03:26:00 36,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.18114_none_abc1cbc0e39143f0\cdd.dll
    + 2008-08-02 01:01:23 625,152 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.18114_none_abc1cbc0e39143f0\dxgkrnl.sys
    + 2008-08-02 03:20:51 36,864 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.22235_none_ac36c8fdfcbe34f3\cdd.dll
    + 2008-08-02 00:59:11 625,152 ----a-w C:\Windows\winsxs\x86_microsoft-windows-lddmcore_31bf3856ad364e35_6.0.6001.22235_none_ac36c8fdfcbe34f3\dxgkrnl.sys
    + 2008-05-20 02:07:31 148,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-native-80211_31bf3856ad364e35_6.0.6001.18075_none_4ec1fb0e8f26c88a\nwifi.sys
    + 2008-05-20 02:00:06 148,480 ----a-w C:\Windows\winsxs\x86_microsoft-windows-native-80211_31bf3856ad364e35_6.0.6001.22183_none_4f3ec759a84e5197\nwifi.sys
    + 2008-06-30 23:00:26 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16730_none_f0816da06e6c1330\OESpamFilter.dat
    + 2008-06-30 23:00:26 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20895_none_f0cf2c5587b5d953\OESpamFilter.dat
    + 2008-06-30 23:00:26 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18121_none_f2737c7c6b89a187\OESpamFilter.dat
    + 2008-06-30 23:00:26 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22243_none_f2e97a0384b5abe1\OESpamFilter.dat
    + 2008-05-08 19:21:56 211,968 ----a-w C:\Windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6001.18068_none_886bae514b981fe3\mrxsmb10.sys
    + 2008-05-08 02:47:34 211,968 ----a-w C:\Windows\winsxs\x86_microsoft-windows-smb10-minirdr_31bf3856ad364e35_6.0.6001.22175_none_88e77a5264c08f99\mrxsmb10.sys
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{48dfca51-0021-46df-82d0-b61e262153c2}]
    2008-09-14 22:35 111616 --a------ C:\Windows\system32\jvwlqo.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-20 1233920]
    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
    "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
    "Gestionnaire Antidote.exe"="C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe" [2002-11-07 143360]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
    "Uniblue RegistryBooster 2009"="c:\program files\uniblue\registrybooster\StartRegistryBooster.exe" [BU]
    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-20 202240]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2006-11-23 56928]
    "LanguageShortcut"="C:\Program Files\CyberLink\PowerDVD\Language\Language.exe" [2006-12-05 54832]
    "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-16 13535776]
    "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-16 92704]
    "mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
    "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 413696]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "RtHDVCpl"="RtHDVCpl.exe" [2008-05-20 C:\Windows\RtHDVCpl.exe]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    Hyperappel du Petit Larousse 2009.lnk - C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe [2008-09-07 237568]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.YV12"= yv12vfw.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-295252437-1548751239-3619892269-1000]
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "TCP Query User{DAC81081-FBB4-4452-84A1-CBFA60292391}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
    "UDP Query User{7307F9B1-37A9-4DB4-8B00-D6964BA564D7}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
    "{08AE761A-9F8B-4A3B-A942-B1E34F72215A}"= Profile=Private|Profile=Public|C:\Program Files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
    "{9E46F0BB-4775-4746-B085-42D175881C9C}"= UDP:17842:BitComet 17842 TCP
    "{1E7F9CC7-38AA-4238-958F-041D7FA3B6F5}"= TCP:17842:BitComet 17842 UDP
    "{72C072DE-6190-46E9-9441-345FACE1834F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
    "{961772C2-CC22-414B-8357-9D49E3020317}"= UDP:25937:BitComet 25937 TCP
    "{0BD1CE4F-8154-4B05-AD04-30104AB8C4DE}"= TCP:25937:BitComet 25937 UDP
    "{AD7218B8-1B4E-4C5D-B875-85C47996B946}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
    "{01D01E03-D7CD-47C3-8AED-A691F9909402}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
    "{A1F003DC-A7EF-43D4-8C73-27BDFA6301BD}"= UDP:C:\Program Files\ma-config.com\maconfservice.exe:maconfservice
    "{F375F858-47CF-47BE-8D26-1D9397D75326}"= TCP:C:\Program Files\ma-config.com\maconfservice.exe:maconfservice
    "{2A538FDB-ADFB-44ED-A190-585F7A2F1529}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    R0 mv61xx;mv61xx;C:\Windows\system32\DRIVERS\mv61xx.sys [2008-06-10 150568]
    R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [2008-09-08 198944]
    R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296]
    R3 L1E;NDIS Miniport Driver for Atheros AR8121/AR8113 PCI-E Ethernet Controller;C:\Windows\system32\DRIVERS\L1E60x86.sys [2008-02-02 47616]
    S3 maconfservice;Ma-Config Service;C:\Program Files\ma-config.com\maconfservice.exe [2008-07-25 191656]
    S4 ErrDev;Microsoft Hardware Error Device Driver;C:\Windows\system32\drivers\errdev.sys [2008-01-20 6656]
    S4 MegaSR;MegaSR;C:\Windows\system32\drivers\megasr.sys [2008-01-20 386616]
    .
    Contenu du dossier 'Tƒches planifi‚es'
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    BHO-{079C9F8A-69E2-450C-8D29-D869A2D06638} - C:\Windows\system32\cmcofild.dll
    BHO-{868392E6-B49D-463E-8CE2-E3541C792556} - (no file)
    BHO-{B5D90D1F-0732-416F-BF8C-B356B6B0EB13} - C:\Windows\system32\fccccArp.dll

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-09-15 16:32:26
    Windows 6.0.6001 Service Pack 1 NTFS

    Recherche de processus cach‚s ...

    Recherche d'‚l‚ments en d‚marrage automatique cach‚s ...

    Recherche de fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Fichiers cach‚s: 0

    **************************************************************************
    .
    --------------------- DLLs charg‚es dans les processus actifs ---------------------

    PROCESSUS: C:\Windows\Explorer.exe
    -> C:\Program Files\McAfee\SiteAdvisor\saHook.dll
    .
    ------------------------ Autres processus actifs ------------------------
    .
    C:\Windows\System32\nvvsvc.exe
    C:\Windows\System32\audiodg.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\ASUS\Six Engine\SixEngine.exe
    C:\Windows\System32\rundll32.exe
    C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
    C:\Windows\System32\rundll32.exe
    C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
    C:\Program Files\McAfee\MPF\MpfSrv.exe
    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    C:\Windows\System32\IoctlSvc.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\McAfee\VirusScan\mcsysmon.exe
    C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
    C:\Windows\System32\dllhost.exe
    .
    **************************************************************************
    .
    Heure de fin: 2008-09-15 16:35:27 - La machine a red‚marr‚
    ComboFix-quarantined-files.txt 2008-09-15 20:35:24
    ComboFix2.txt 2008-09-15 02:17:22
    ComboFix3.txt 2008-09-14 00:07:21

    Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
    AprŠs-CF: 463,961,817,088 octets libres

    357 --- E O F --- 2008-09-15 02:28:35

    Logfile of HijackThis v1.99.1
    Scan saved at 16:36:24, on 2008-09-15
    Platform: Unknown Windows (WinNT 6.00.1905 SP1)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files\ASUS\Six Engine\SixEngine.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\notepad.exe
    C:\Users\Propriétaire\Downloads\hijackthis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: {2c351262-e16b-0d28-fd64-120015acfd84} - {48dfca51-0021-46df-82d0-b61e262153c2} - C:\Windows\system32\jvwlqo.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O3 - Toolbar: Systran40premi.IEPlugIn - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\Premium\IEPlugIn.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
    O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Global Startup: Hyperappel du Petit Larousse 2009.lnk = C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
    O11 - Options group: [INTERNATIONAL] International*
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
    0
  2. StarRain
     
    Bonjour Chiquitine,

    Voici le rapport de Malaware

    J'attends de tes nouvelles!

    StarRain

    Malwarebytes' Anti-Malware 1.28
    Version de la base de données: 1157
    Windows 6.0.6001 Service Pack 1

    2008-09-15 17:57:32
    mbam-log-2008-09-15 (17-57-32).txt

    Type de recherche: Examen complet (C:\|)
    Eléments examinés: 118891
    Temps écoulé: 39 minute(s), 38 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 1
    Clé(s) du Registre infectée(s): 2
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 29

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    C:\Windows\System32\jvwlqo.dll (Trojan.Vundo) -> Delete on reboot.

    Clé(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{48dfca51-0021-46df-82d0-b61e262153c2} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\CLSID\{48dfca51-0021-46df-82d0-b61e262153c2} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    C:\Windows\System32\jvwlqo.dll (Trojan.Vundo.H) -> Delete on reboot.
    C:\QooBox\Quarantine\C\Windows\System32\awtrqPgg.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\ccndgaim.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\cmcofild.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\cxywxgna.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\edslkyto.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\efofngxm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\fccccArp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\fcwnkwek.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\fsebttdx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\gcmvlhpf.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\modufstm.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\mxhsom.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\ngicirxw.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\qvqawl.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\gnsmfq.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\hqskqolv.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\jkkLBrrP.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\jsymbend.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\jtfglbhp.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\lasxquyu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\luvcdsdn.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\tjehfltr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\txowijmk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\uuvwdyhk.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\uxctnhyu.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\vwdlwsld.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Windows\System32\xhgkfwrr.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\Windows\System32\gmdvhxsy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    0
  3. StarRain
     
    Rebonsoir,

    Voici le rapport après la suppression de la quarantaine de malaware

    Merci

    Logfile of HijackThis v1.99.1
    Scan saved at 18:13:38, on 2008-09-15
    Platform: Unknown Windows (WinNT 6.00.1905 SP1)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Program Files\ASUS\Six Engine\SixEngine.exe
    C:\Windows\Explorer.EXE
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\McAfee.com\Agent\mcagent.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\wuauclt.exe
    C:\Users\Propriétaire\Downloads\hijackthis.exe
    C:\Windows\system32\WerCon.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O3 - Toolbar: Systran40premi.IEPlugIn - {CFB25594-4D5F-11D6-AB7B-00B0D094B576} - C:\Program Files\Systran\4_0\Premium\IEPlugIn.dll
    O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
    O4 - HKCU\..\Run: [Gestionnaire Antidote.exe] C:\Program Files\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - Global Startup: Hyperappel du Petit Larousse 2009.lnk = C:\Program Files\Larousse\Petit Larousse 2009\bin\Hyperappel.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
    O11 - Options group: [INTERNATIONAL] International*
    O13 - Gopher Prefix:
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
    O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
    O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
    O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
    O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
    O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. StarRain
     
    Bonjour,

    J'imagine que si vous me faites supprimer c'est que tout est correct maintenant sur mon ordinateur! Merci bcp de votre aide. Tous les résidus du virus sont maintenant partis?? Si oui, comment s'assurer qu'il ne revienne pas, je n'ai portant rien fait de risqué sur mon ordi...

    Merci et voici le rapport:

    [ Rapport ToolsCleaner version 2.2.3 (par A.Rothstein & dj QUIOU) ]

    -->- Recherche:

    C:\VundoFix.txt: trouvé !
    C:\Combofix.txt: trouvé !
    C:\Qoobox: trouvé !
    C:\Users\Propriétaire\Downloads\VirtumundoBeGone.exe: trouvé !
    C:\Users\Propriétaire\Downloads\ComboFix.exe: trouvé !
    C:\Users\Propriétaire\Downloads\vundoFix.exe: trouvé !
    C:\Users\Propriétaire\Downloads\HijackThis.exe: trouvé !
    C:\Users\Propriétaire\Downloads\hijackthis.log: trouvé !

    ---------------------------------
    -->- Suppression:

    C:\Users\Propriétaire\Downloads\VirtumundoBeGone.exe: supprimé !
    C:\Users\Propriétaire\Downloads\ComboFix.exe: ERREUR DE SUPPRESSION !!
    C:\Users\Propriétaire\Downloads\vundoFix.exe: supprimé !
    C:\Users\Propriétaire\Downloads\HijackThis.exe: supprimé !
    C:\VundoFix.txt: supprimé !
    C:\Combofix.txt: supprimé !
    C:\Users\Propriétaire\Downloads\hijackthis.log: supprimé !
    C:\Qoobox: supprimé !

    Corbeille vidée!
    Fichiers temporaires nettoyés !
    0
  6. StarRain
     
    Salut Chiquitine,

    Je voulais te remercier pour ta précieuse aide. Souhaitant qu'ils ne reviennent pas ces maudits spyware. J'ai installé les deux logiciels dont tu m'as parler. De plus, j'ai supprimer combofix.exe...

    Je ne suis pas un membre inscrit.. donc je ne peux pas mettre résolu moi même comme c'est inscrit dans le lien. Qui je dois contacter en particuler (un contributeur ou un modérateur) pour qu'il le fasse à ma place?

    Merci bcp encore!!

    StarRain
    0
  7. Utilisateur anonyme
     
    Salut,

    je regarde tes rapports

    @+
    -1
  8. Utilisateur anonyme
     
    re

    désolé du retard :

    Copie le texte ci-dessous :

    File::
    C:\WINDOWS\wininit.ini
    C:\Windows\System32\uxctnhyu.dll
    C:\Windows\System32\gnsmfq.dll
    C:\Windows\System32\txowijmk.dll
    C:\Windows\System32\qvqawl.dll
    C:\temp\Listdlls.exe
    C:\Windows\System32\jkkLBrrP.dll
    C:\Windows\unvise32.exe
    C:\Windows\System32\awtrqPgg.dll
    C:\Windows\S18FF1045.tmp
    C:\Windows\system32\fccccArp.dll

    Folder::
    C:\VundoFix Backups

    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5E1A1870-827E-4B7E-94BB-224E599A1C79}]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""


    Ouvre le Bloc-Notes puis colle le texte copié.
    (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
    Sauvegarde ce fichier sous le nom de CFScript.txt

    Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ceci :

    Cela va relancer Combofix,

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

    S'il n'y a pas de rédémarrage, poste quand même les rapports.
    -1
  9. Utilisateur anonyme
     
    Telecharge malwarebytes

    Tu l´instale; le programme va se mettre automatiquement a jour.

    Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

    Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

    Puis click sur "rechercher".

    Laisse le scanner le pc...

    Si des elements on ete trouvés > click sur supprimer la selection.

    si il t´es demandé de redemarrer > click sur "yes".

    A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.
    Copie et colle le rapport stp.

    PS : les rapport sont aussi rangé dans l onglet rapport/log
    -1
  10. Utilisateur anonyme
     
    réouvre malewarebyte
    va sur quarantaine
    supprime tout

    refais un scan hijackthis et post le rapport stp
    -1
  11. Utilisateur anonyme
     
    fais un clic droit sur hijackthis
    choisi executer en tant qu administrateur
    fais scan only
    coches ces lignes :

    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)

    O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)

    O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)

    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

    tu les coches et tu clic sur fix checked

    ensuite ;

    -> Télécharge Ccleaner (n'installe pas la barre d'outil Yahoo):

    http://download.piriform.com/ccsetup210.exe

    https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

    -> Tuto : https://www.malekal.com/tutoriel-ccleaner/

    * pour supprimer les outils/fix utilisés :

    Télécharge ToolsCleaner sur ton bureau.
    -->
    ftp://ftp.commentcamarche.com/download/ToolsCleaner2.exe
    http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
    http://pc-system.fr/

    # Clique sur Recherche et laisse le scan agir ...
    # Clique sur Suppression pour finaliser.
    # Tu peux, si tu le souhaites, te servir des Options facultatives.
    # Clique sur Quitter pour obtenir le rapport.
    # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
    -1
  12. Utilisateur anonyme
     
    supprime combofix de : Downloads

    pour te securiser garde malewarebyte et ajoute si tu le desire

    spywareblaster :

    http://www.brightfort.com/spywareblaster.html

    c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

    tuto : https://www.malekal.com/tutorial-spywareblaster/

    Pour completer spywareblaster rajoute spywareguard :

    http://www.javacoolsoftware.net.nyud.net:8090/downloads/spywareguardsetup.exe

    avis spywareblaster :

    http://www.commentcamarche.net/telecharger/spyware blaster 226 avis opinions.php3#avis jalobservateur

    avis spywareguard:

    http://www.commentcamarche.net/telecharger/spywareguard 34055277 avis opinions.php3#avis jalobservateur

    puis un bonus :

    plugins Firefox : ad block plus, no script ect...

    https://www.hugedomains.com/domain_profile.cfm?d=geckozone&e=org

    si tu n as pas d autres soucis change le statut du sujet en resolu stp

    http://www.commentcamarche.net/faq/sujet 11365 marquer un fil de discussion comme etant resolu
    -1
  13. Utilisateur anonyme
     
    de rien pas de soucis

    pour mettre resolu dans ton cas tu clic sur le point d exclamation jaune et tu signal

    @++ en esperant pas te revoir -;)

    bonne semaine
    -1