Problème avec empa.exe et microav

Bonjour,

j'ai allumé mon ordi ce matin e j ai eu des fenêtres qui s ouvraient toutes les 5 min plus des icones qui n ont pas lieu d être sur mon bureau, ainsi que des message d'alerte comme quoi j avais des détections d'attaque

j ai fait une analyse avec AVG internet security et il en est ressorti que les problèmes les plus trouvés étaient:

empa.exe et microav

si quelqu un avait ce problème ou quelqu un qui si connait pour m'aider à enlever ces pu.... de me...

merci d'avance pour vos réponse

cordialement
Configuration: Windows XP
Firefox 2.0.0.16

29 réponses

Résumé de la discussion

Des symptômes d'infection apparaissent sur Windows XP avec des fenêtres contextuelles récurrentes, des icônes intempestives et des alertes d'attaque liées à des processus empa.exe et microav. Une réponse recommande de redémarrer en mode sans échec, puis d'exécuter SmitfraudFix.exe, de choisir l'option 2, de nettoyer le registre, remplacer les fichiers infectés et redémarrer si nécessaire. Le processus nécessite ensuite l’examen des rapports générés par RSIT et HijackThis, qui révèlent de nombreuses entrées malveillantes, des modifications des pages d'accueil et des éléments de démarrage non autorisés. D'autres éléments utiles incluent la présence de compléments et de services suspects dans les chemins system32 et les clés de démarrage, nécessitant une suppression ciblée pour rétablir la stabilité.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Suite de la manipe ( nettoyage ), fais exactement ce qui suit :

    * Impératif : Redémarrer l'ordinateur en mode sans échec .
    Comment aller en Mode sans échec
    1) Redémarre ton ordi
    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
    3) Tu verras un écran avec options de démarrage apparaître
    4) Choisis la première option : Sans Échec, et valide avec "Entrée"
    5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
    ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copies ou imprimes bien les info ci-dessous ...)

    *Double click sur SmitfraudFix.exe

    * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

    -> Si besion :
    * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presser Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

    ( Le correctif déterminera si le fichier wininet.dll est infecté.)

    * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
    pour remplacer le fichier corrompu.

    * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

    Le rapport se trouve à la racine de C\:
    (dans le fichier "rapport.txt")

    Postes moi ce dernier ... Puis dans ta réponse suivante , postes un nouveau rapport RSIT ( fait en mode normal ) pour analise et attends la suite ....
    1
    1. voila pour le fichier log.txt:

      Logfile of random's system information tool 1.02 (written by random/random)
      Run by Propriétaire at 2008-09-19 19:34:00
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 33 GB (67%) free of 50 GB
      Total RAM: 1023 MB (47% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 19:34:06, on 19/09/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\SOUNDMAN.EXE
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\WINDOWS\ALCWZRD.EXE
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      C:\Program Files\Microsoft IntelliType Pro\itype.exe
      C:\Program Files\Winamp\winampa.exe
      C:\Windows\system32\YUR442.exe
      C:\WINDOWS\system32\IoctlSvc.exe
      C:\Windows\system32\YUR445.exe
      C:\Windows\system32\YUR446.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
      C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
      C:\PROGRA~1\AVG\AVG8\avgam.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\PCHealthCenter\2.exe
      C:\Program Files\PCHealthCenter\3.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\system32\SearchProtocolHost.exe
      C:\Documents and Settings\Propriétaire\Bureau\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\Propriétaire.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      F2 - REG:system.ini: Shell=explorer.exe
      O2 - BHO: D - {1109C88B-2081-30A9-8C6D-9BF211755EA7} - C:\WINDOWS\system32\mmx89564.dll (file missing)
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
      O2 - BHO: {167b5bf0-3527-734b-d824-9df3867b0c1c} - {c1c0b768-3fd9-428d-b437-72530fb5b761} - C:\WINDOWS\system32\snmgfr.dll
      O2 - BHO: (no name) - {FC5417E1-122F-451C-B0F1-F7E748BE955A} - C:\WINDOWS\system32\qoMeBTnn.dll (file missing)
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
      O4 - HKLM\..\Run: [\YUR442.exe] C:\Windows\system32\YUR442.exe
      O4 - HKLM\..\Run: [\YUR443.exe] C:\Windows\system32\YUR443.exe
      O4 - HKLM\..\Run: [\YUR444.exe] C:\Windows\system32\YUR444.exe
      O4 - HKLM\..\Run: [\YUR445.exe] C:\Windows\system32\YUR445.exe
      O4 - HKLM\..\Run: [\YUR446.exe] C:\Windows\system32\YUR446.exe
      O4 - HKLM\..\Run: [20cf04bc] rundll32.exe "C:\WINDOWS\system32\kejiwxib.dll",b
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKLM\..\Run: [\YUR2.exe] C:\Windows\system32\YUR2.exe
      O4 - HKLM\..\Run: [\YUR3.exe] C:\Windows\system32\YUR3.exe
      O4 - HKLM\..\Run: [\YUR4.exe] C:\Windows\system32\YUR4.exe
      O4 - HKLM\..\Run: [\YUR5.exe] C:\Windows\system32\YUR5.exe
      O4 - HKLM\..\Run: [\YUR16.exe] C:\Windows\system32\YUR16.exe
      O4 - HKLM\..\Run: [\YUR29.exe] C:\Windows\system32\YUR29.exe
      O4 - HKLM\..\Run: [\YUR2A.exe] C:\Windows\system32\YUR2A.exe
      O4 - HKLM\..\Run: [\YUR2B.exe] C:\Windows\system32\YUR2B.exe
      O4 - HKLM\..\Run: [\YUR2C.exe] C:\Windows\system32\YUR2C.exe
      O4 - HKLM\..\Run: [\YUR52.exe] C:\Windows\system32\YUR52.exe
      O4 - HKLM\..\Run: [\YUR53.exe] C:\Windows\system32\YUR53.exe
      O4 - HKLM\..\Run: [\YUR54.exe] C:\Windows\system32\YUR54.exe
      O4 - HKLM\..\Run: [\YUR55.exe] C:\Windows\system32\YUR55.exe
      O4 - HKLM\..\Run: [\YUR58.exe] C:\Windows\system32\YUR58.exe
      O4 - HKLM\..\Run: [\YUR91.exe] C:\Windows\system32\YUR91.exe
      O4 - HKLM\..\Run: [\YUR97.exe] C:\Windows\system32\YUR97.exe
      O4 - HKLM\..\Run: [\YUR98.exe] C:\Windows\system32\YUR98.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
      O4 - HKCU\..\Run: [\YUR442.exe] C:\Windows\system32\YUR442.exe
      O4 - HKCU\..\Run: [\YUR443.exe] C:\Windows\system32\YUR443.exe
      O4 - HKCU\..\Run: [\YUR444.exe] C:\Windows\system32\YUR444.exe
      O4 - HKCU\..\Run: [\YUR445.exe] C:\Windows\system32\YUR445.exe
      O4 - HKCU\..\Run: [\YUR446.exe] C:\Windows\system32\YUR446.exe
      O4 - HKCU\..\Run: [\YUR2.exe] C:\Windows\system32\YUR2.exe
      O4 - HKCU\..\Run: [\YUR3.exe] C:\Windows\system32\YUR3.exe
      O4 - HKCU\..\Run: [\YUR4.exe] C:\Windows\system32\YUR4.exe
      O4 - HKCU\..\Run: [\YUR5.exe] C:\Windows\system32\YUR5.exe
      O4 - HKCU\..\Run: [\YUR16.exe] C:\Windows\system32\YUR16.exe
      O4 - HKCU\..\Run: [\YUR29.exe] C:\Windows\system32\YUR29.exe
      O4 - HKCU\..\Run: [\YUR2A.exe] C:\Windows\system32\YUR2A.exe
      O4 - HKCU\..\Run: [\YUR2B.exe] C:\Windows\system32\YUR2B.exe
      O4 - HKCU\..\Run: [\YUR2C.exe] C:\Windows\system32\YUR2C.exe
      O4 - HKCU\..\Run: [\YUR52.exe] C:\Windows\system32\YUR52.exe
      O4 - HKCU\..\Run: [\YUR53.exe] C:\Windows\system32\YUR53.exe
      O4 - HKCU\..\Run: [\YUR54.exe] C:\Windows\system32\YUR54.exe
      O4 - HKCU\..\Run: [\YUR55.exe] C:\Windows\system32\YUR55.exe
      O4 - HKCU\..\Run: [\YUR58.exe] C:\Windows\system32\YUR58.exe
      O4 - HKCU\..\Run: [\YUR91.exe] C:\Windows\system32\YUR91.exe
      O4 - HKCU\..\Run: [\YUR97.exe] C:\Windows\system32\YUR97.exe
      O4 - HKCU\..\Run: [\YUR98.exe] C:\Windows\system32\YUR98.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: snmgfr.dll,avgrsstx.dll
      O20 - Winlogon Notify: byXOhHYp - byXOhHYp.dll (file missing)
      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      0
      1. Contributeur sécurité
        bon ....

        c'est bien chargé ....

        Commences par ceci :

        Télécharges SmitfraudFix (de S!Ri, balltrap34 et moe31 ) :
        http://siri.urz.free.fr/Fix/SmitfraudFix.exe

        Installes le soft sur ton bureau ( et pas ailleurs! ) .

        !! Déconnectes toi, fermes toute tes applications et désactives tes défenses ( anti-virus ,anti-spyware,...) le temps de la manipe !!

        Tuto ( aide ) : http://siri.urz.free.fr/Fix/SmitfraudFix.php

        Utilisation ---> option 1 / Recherche :
        Double cliques sur l'icône "Smitfraudfix.exe" et sélectionnes 1 (et pas sur autre chose sans notre accord !) pour créer un rapport des fichiers responsables de l'infection.

        Postes le rapport ( "rapport.txt" qui se trouve sous C\: ) et attends la suite ...

        (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool". Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité.)

        -1
    2. voila les derniers rapports:

      Logfile of random's system information tool 1.02 (written by random/random)
      Run by Propriétaire at 2008-09-20 00:18:38
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 39 GB (78%) free of 50 GB
      Total RAM: 1023 MB (51% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 00:19:23, on 20/09/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\ALCWZRD.EXE
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
      C:\Program Files\Microsoft IntelliType Pro\itype.exe
      C:\Program Files\Winamp\winampa.exe
      C:\PROGRA~1\AVG\AVG8\avgtray.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      C:\WINDOWS\system32\IoctlSvc.exe
      C:\WINDOWS\system32\HPZipm12.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\SearchIndexer.exe
      C:\PROGRA~1\AVG\AVG8\avgam.exe
      C:\PROGRA~1\AVG\AVG8\avgrsx.exe
      C:\PROGRA~1\AVG\AVG8\avgnsx.exe
      C:\PROGRA~1\AVG\AVG8\avgemc.exe
      C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\Propriétaire\Bureau\RSIT.exe
      C:\Program Files\Trend Micro\HijackThis\Propriétaire.exe

      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      F2 - REG:system.ini: Shell=explorer.exe
      O2 - BHO: (no name) - {1109C88B-2081-30A9-8C6D-9BF211755EA7} - (no file)
      O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
      O2 - BHO: {167b5bf0-3527-734b-d824-9df3867b0c1c} - {c1c0b768-3fd9-428d-b437-72530fb5b761} - C:\WINDOWS\system32\snmgfr.dll
      O2 - BHO: (no name) - {FC5417E1-122F-451C-B0F1-F7E748BE955A} - (no file)
      O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
      O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
      O20 - AppInit_DLLs: snmgfr.dll,avgrsstx.dll
      O20 - Winlogon Notify: byXOhHYp - byXOhHYp.dll (file missing)
      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
      O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
      O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
      0
      1. Malwarebytes' Anti-Malware 1.28
        Version de la base de données: 1181
        Windows 5.1.2600 Service Pack 3

        20/09/2008 19:03:58
        mbam-log-2008-09-20 (19-03-58).txt

        Type de recherche: Examen complet (C:\|D:\|)
        Eléments examinés: 88785
        Temps écoulé: 29 minute(s), 13 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 1
        Clé(s) du Registre infectée(s): 8
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 20

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        C:\WINDOWS\system32\snmgfr.dll (Trojan.Vundo) -> Delete on reboot.

        Clé(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c1c0b768-3fd9-428d-b437-72530fb5b761} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\CLSID\{c1c0b768-3fd9-428d-b437-72530fb5b761} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
        HKEY_CLASSES_ROOT\Typelib\{cce1e84e-55a8-4f3b-b590-20c06119de57} (Trojan.BHO) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        C:\WINDOWS\system32\snmgfr.dll (Trojan.Vundo.H) -> Delete on reboot.
        C:\x (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019662.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019690.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019657.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019698.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019729.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019751.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019741.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019742.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019743.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019744.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019745.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019746.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019747.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019748.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019749.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019750.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\System Volume Information\_restore{4995C394-3EE5-4888-9164-81FD21058669}\RP69\A0019757.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\hiuktkfa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

        Logfile of random's system information tool 1.02 (written by random/random)
        Run by Propriétaire at 2008-09-20 19:08:18
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 39 GB (78%) free of 50 GB
        Total RAM: 1023 MB (46% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 19:08:43, on 20/09/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16705)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\explorer.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\WINDOWS\ALCWZRD.EXE
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
        C:\Program Files\Microsoft IntelliType Pro\itype.exe
        C:\Program Files\Winamp\winampa.exe
        C:\PROGRA~1\AVG\AVG8\avgtray.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
        C:\Program Files\Windows Desktop Search\WindowsSearch.exe
        C:\WINDOWS\system32\IoctlSvc.exe
        C:\WINDOWS\system32\HPZipm12.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\SearchIndexer.exe
        C:\PROGRA~1\AVG\AVG8\avgam.exe
        C:\PROGRA~1\AVG\AVG8\avgrsx.exe
        C:\PROGRA~1\AVG\AVG8\avgnsx.exe
        C:\PROGRA~1\AVG\AVG8\avgemc.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Documents and Settings\Propriétaire\Bureau\RSIT.exe
        C:\Program Files\Trend Micro\HijackThis\Propriétaire.exe

        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        F2 - REG:system.ini: Shell=explorer.exe
        O2 - BHO: (no name) - {1109C88B-2081-30A9-8C6D-9BF211755EA7} - (no file)
        O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
        O2 - BHO: (no name) - {FC5417E1-122F-451C-B0F1-F7E748BE955A} - (no file)
        O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
        O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
        O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
        O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
        O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
        O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
        O20 - AppInit_DLLs: snmgfr.dll,avgrsstx.dll
        O20 - Winlogon Notify: byXOhHYp - byXOhHYp.dll (file missing)
        O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
        O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
        O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
        O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
        O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
        0
        1. Logfile of random's system information tool 1.02 (written by random/random)
          Run by Propriétaire at 2008-09-21 12:03:28
          Microsoft Windows XP Édition familiale Service Pack 3
          System drive C: has 39 GB (77%) free of 50 GB
          Total RAM: 1023 MB (55% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 12:03, on 2008-09-21
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16705)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\savedump.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          C:\WINDOWS\system32\IoctlSvc.exe
          C:\WINDOWS\system32\HPZipm12.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\SearchIndexer.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\SOUNDMAN.EXE
          C:\WINDOWS\ALCWZRD.EXE
          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
          C:\Program Files\Microsoft IntelliType Pro\itype.exe
          C:\Program Files\Winamp\winampa.exe
          C:\PROGRA~1\AVG\AVG8\avgtray.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Windows Desktop Search\WindowsSearch.exe
          C:\PROGRA~1\AVG\AVG8\avgam.exe
          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
          C:\PROGRA~1\AVG\AVG8\avgnsx.exe
          C:\PROGRA~1\AVG\AVG8\avgemc.exe
          C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
          C:\WINDOWS\system32\SearchProtocolHost.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Documents and Settings\Propriétaire\Bureau\RSIT.exe
          C:\Program Files\Trend Micro\HijackThis\Propriétaire.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: (no name) - {1109C88B-2081-30A9-8C6D-9BF211755EA7} - (no file)
          O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
          O2 - BHO: (no name) - {FC5417E1-122F-451C-B0F1-F7E748BE955A} - (no file)
          O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
          O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
          O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
          O20 - Winlogon Notify: byXOhHYp - byXOhHYp.dll (file missing)
          O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
          O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
          O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
          O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
          0
          1. ComboFix 08-09-20.05 - Propri‚taire 2008-09-21 18:22:40.2 - NTFSx86
            Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.547 [GMT 2:00]
            Lancé depuis: C:\Documents and Settings\Propri‚taire\Bureau\C-Fix.exe
            Commutateurs utilisés :: C:\Documents and Settings\Propri‚taire\Bureau\CFScript.doc
            * Un nouveau point de restauration a été créé

            [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
            .

            ((((((((((((((((((((((((((((( Fichiers créés du 2008-08-21 au 2008-09-21 ))))))))))))))))))))))))))))))))))))
            .

            2008-09-21 15:45 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Media Player Classic
            2008-09-21 13:57 . 2008-09-21 13:57 <REP> d-------- C:\Program Files\Fichiers communs\Macrovision Shared
            2008-09-21 13:57 . 2008-09-21 13:57 54,784 --a------ C:\WINDOWS\system32\drivers\CDAC11BA.EXE
            2008-09-21 13:57 . 2008-09-21 13:57 12,464 --a------ C:\WINDOWS\system32\drivers\CDAC15BA.SYS
            2008-09-21 13:56 . 2008-09-21 13:57 <REP> d-------- C:\Program Files\Fichiers communs\Autodesk Shared
            2008-09-21 13:56 . 2008-09-21 13:56 <REP> d-------- C:\Program Files\backburner 2
            2008-09-21 13:54 . 2008-09-21 13:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
            2008-09-21 13:53 . 2008-09-21 13:53 40,960 --a------ C:\WINDOWS\_ds40.tmp
            2008-09-20 18:29 . 2008-09-20 18:29 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
            2008-09-20 18:29 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Malwarebytes
            2008-09-20 18:29 . 2008-09-20 18:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
            2008-09-20 18:29 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
            2008-09-20 18:29 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
            2008-09-19 23:31 . 2008-09-19 23:31 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
            2008-09-19 23:31 . 2008-09-20 00:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
            2008-09-19 23:30 . 2008-09-19 23:30 <REP> d-------- C:\Program Files\CCleaner
            2008-09-19 21:10 . 2008-09-19 22:42 4,976 --a------ C:\WINDOWS\system32\tmp.reg
            2008-09-19 19:28 . 2008-09-19 19:28 <REP> d-------- C:\rsit
            2008-09-19 19:24 . 2008-09-19 19:24 <REP> d-------- C:\Program Files\Trend Micro
            2008-09-19 18:47 . 2008-09-19 18:47 <REP> d-------- C:\Program Files\Navilog1
            2008-09-18 21:01 . 2008-09-20 04:36 <REP> d--h----- C:\$AVG8.VAULT$
            2008-09-18 20:58 . 2008-09-20 15:28 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
            2008-09-18 20:58 . 2008-09-18 20:58 <REP> d-------- C:\Program Files\AVG
            2008-09-18 20:58 . <REP> C:\Documents and Settings\Propriétaire\Application Data\AVGTOOLBAR
            2008-09-18 20:58 . 2008-09-18 20:58 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
            2008-09-18 20:58 . 2008-09-18 20:58 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
            2008-09-18 20:58 . 2008-09-18 20:58 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
            2008-09-18 20:58 . 2008-09-18 20:58 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
            2008-09-18 20:58 . 2008-09-18 20:58 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
            2008-09-18 20:56 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Windows Search
            2008-09-18 20:35 . 2008-09-18 20:35 977,361 ---hs---- C:\WINDOWS\system32\bixwijek.ini
            2008-09-18 20:34 . 2008-09-18 22:16 4,996 --ahs---- C:\WINDOWS\system32\nnTBeMoq.ini2
            2008-09-18 20:34 . 2008-09-18 22:17 4,996 --ahs---- C:\WINDOWS\system32\nnTBeMoq.ini
            2008-09-03 22:39 . 2008-09-21 15:45 69 --a------ C:\WINDOWS\NeroDigital.ini
            2008-08-25 23:38 . 2008-08-25 23:39 38 --a------ C:\WINDOWS\avisplitter.INI
            2008-08-24 20:08 . <REP> C:\Documents and Settings\Propriétaire\Application Data\vlc
            2008-08-24 20:05 . 2008-08-24 20:05 <REP> d-------- C:\Program Files\VideoLAN

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2008-09-21 11:07 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\uTorrent
            2008-09-21 00:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
            2008-09-18 18:57 --------- d-s---w C:\Documents and Settings\Propriétaire\Application Data\Microsoft
            2008-09-15 19:17 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Adobe
            2008-08-14 13:11 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\LG Electronics
            2008-08-14 13:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
            2008-08-14 13:10 --------- d-----w C:\Program Files\LG PC Suite 2
            2008-08-14 13:10 --------- d-----w C:\Program Files\LG Electronics
            2008-08-14 13:09 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\InstallShield
            2008-08-07 11:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
            2008-08-06 20:55 --------- d-----w C:\Program Files\OpenOffice.org 2.4
            2008-08-06 20:51 --------- d-----w C:\Program Files\Fichiers communs\Hewlett-Packard
            2008-08-06 20:49 --------- d-----w C:\Program Files\HP
            2008-08-06 20:22 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\OpenOffice.org2
            2008-08-06 11:00 --------- d-----w C:\Program Files\MSXML 4.0
            2008-08-05 21:21 --------- d-----w C:\Program Files\Microsoft.NET
            2008-08-05 17:17 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Nero
            2008-08-05 17:16 --------- d-----w C:\Program Files\Fichiers communs\Nero
            2008-08-05 17:14 --------- d-----w C:\Program Files\Nero
            2008-08-05 17:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
            2008-08-05 05:21 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\WinRAR
            2008-08-04 22:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
            2008-08-04 22:34 --------- d-----w C:\Program Files\Winamp Remote
            2008-08-04 22:34 --------- d-----w C:\Program Files\Winamp
            2008-08-04 21:36 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Real
            2008-08-03 17:01 --------- d-----w C:\Program Files\uTorrent
            2008-08-03 16:58 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Talkback
            2008-08-03 16:57 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Mozilla
            2008-08-02 16:01 --------- d-----w C:\Program Files\Fichiers communs\Adobe Systems Shared
            2008-08-02 16:01 --------- d-----w C:\Program Files\Fichiers communs\Adobe
            2008-08-02 16:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Macrovision
            2008-08-02 16:00 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
            2008-08-02 15:44 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Winamp
            2008-08-02 09:26 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\MSNInstaller
            2008-08-02 09:05 --------- d-----w C:\Program Files\Microsoft IntelliType Pro
            2008-08-02 08:42 --------- d-----w C:\Program Files\Microsoft IntelliType Pro 6.02
            2008-07-30 15:10 --------- d-----w C:\Program Files\Java
            2008-07-30 15:04 --------- d-----w C:\Program Files\Windows Live
            2008-07-30 15:03 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
            2008-07-30 15:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
            2008-07-30 14:45 --------- d-----w C:\Program Files\Real
            2008-07-30 14:45 --------- d-----w C:\Program Files\Fichiers communs\xing shared
            2008-07-30 14:45 --------- d-----w C:\Program Files\Fichiers communs\Real
            2008-07-30 14:44 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Macromedia
            2008-07-30 14:43 --------- d-----w C:\Program Files\Google
            2008-07-30 14:32 --------- d-----w C:\Program Files\Fichiers communs\Java
            2008-07-30 14:32 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Sun
            2008-07-30 14:30 --------- d-----w C:\Program Files\K-Lite Codec Pack
            2008-07-30 13:57 --------- d-----w C:\Program Files\DIFX
            2008-07-30 13:05 --------- d-----w C:\Program Files\Windows Desktop Search
            2008-07-30 13:05 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Windows Desktop Search
            2008-07-30 10:14 --------- d-----w C:\Program Files\Windows Media Connect 2
            2008-07-29 14:15 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Identities
            2008-07-29 14:03 --------- d-----w C:\Program Files\microsoft frontpage
            2008-07-29 14:01 --------- d-----w C:\Program Files\Services en ligne
            2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
            2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
            2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
            2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
            2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
            2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
            2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
            2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
            2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
            2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
            2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
            2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
            2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
            2008-06-24 14:06 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
            2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
            .

            ((((((((((((((((((((((((((((( snapshot@2008-09-21_11.58.22.96 )))))))))))))))))))))))))))))))))))))))))
            .
            + 2003-09-29 11:23:26 1,706,800 ----a-w C:\WINDOWS\Downloaded Program Files\gdiplus.dll
            + 2003-09-29 11:23:26 114,848 ----a-w C:\WINDOWS\Downloaded Program Files\IDropENU.dll
            + 2003-03-13 05:58:22 114,600 ----a-w C:\WINDOWS\Downloaded Program Files\IDropFRA.dll
            .
            ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
            "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
            "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
            "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
            "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-07-30 185632]
            "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
            "itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-09-22 793408]
            "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-07-09 36352]
            "NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
            "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
            "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-18 1235736]
            "SoundMan"="SOUNDMAN.EXE" [2005-06-21 C:\WINDOWS\SOUNDMAN.EXE]
            "AlcWzrd"="ALCWZRD.EXE" [2005-06-29 C:\WINDOWS\ALCWZRD.EXE]

            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 15360]

            [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
            "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXOhHYp]
            byXOhHYp.dll [BU]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
            "AppInit_DLLs"=snmgfr.dll,avgrsstx.dll

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
            "VIDC.YV12"= yv12vfw.dll

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
            "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
            "C:\\Program Files\\uTorrent\\uTorrent.exe"=
            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
            "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
            "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
            "C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
            "J:\\3dsmax6\\3dsmax.exe"=

            R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-09-18 12936]
            R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-18 97928]
            R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-18 875288]
            R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-18 231704]
            R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-18 76040]
            R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-03 710144]

            *Newly Created Service* - C-DILLACDAC11BA
            *Newly Created Service* - CDAC15BA
            .
            - - - - ORPHELINS SUPPRIMES - - - -

            BHO-{1109C88B-2081-30A9-8C6D-9BF211755EA7} - (no file)
            BHO-{FC5417E1-122F-451C-B0F1-F7E748BE955A} - (no file)
            ShellExecuteHooks-{52A96517-3690-45C7-98A9-1DD379F9D9B5} - (no file)

            **************************************************************************

            catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2008-09-21 18:24:46
            Windows 5.1.2600 Service Pack 3 NTFS

            Recherche de processus cachés ...

            Recherche d'éléments en démarrage automatique cachés ...

            Recherche de fichiers cachés ...

            Scan terminé avec succès
            Fichiers cachés: 0

            **************************************************************************
            .
            Heure de fin: 2008-09-21 18:25:33
            ComboFix-quarantined-files.txt 2008-09-21 16:25:26

            Avant-CF: 40ÿ321ÿ986ÿ560 octets libres
            Après-CF: 40,322,195,456 octets libres

            197 --- E O F --- 2008-09-12 16:54:14
            0
            1. Logfile of random's system information tool 1.02 (written by random/random)
              Run by Propriétaire at 2008-09-21 21:30:49
              Microsoft Windows XP Édition familiale Service Pack 3
              System drive C: has 38 GB (77%) free of 50 GB
              Total RAM: 1023 MB (43% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:31:09, on 21/09/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16705)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              C:\WINDOWS\system32\IoctlSvc.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\SearchIndexer.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\ALCWZRD.EXE
              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\Microsoft IntelliType Pro\itype.exe
              C:\Program Files\Winamp\winampa.exe
              C:\PROGRA~1\AVG\AVG8\avgtray.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
              C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              C:\PROGRA~1\AVG\AVG8\avgam.exe
              C:\PROGRA~1\AVG\AVG8\avgrsx.exe
              C:\PROGRA~1\AVG\AVG8\avgnsx.exe
              C:\PROGRA~1\AVG\AVG8\avgemc.exe
              C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\WINDOWS\system32\drivers\CDAC11BA.EXE
              C:\WINDOWS\explorer.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\WINDOWS\system32\wscntfy.exe
              C:\Documents and Settings\Propriétaire\Bureau\RSIT.exe
              C:\WINDOWS\system32\SearchProtocolHost.exe
              C:\Program Files\Trend Micro\HijackThis\Propriétaire.exe

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: (no name) - {1109C88B-2081-30A9-8C6D-9BF211755EA7} - (no file)
              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
              O2 - BHO: (no name) - {FC5417E1-122F-451C-B0F1-F7E748BE955A} - (no file)
              O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
              O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
              O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
              O20 - AppInit_DLLs: snmgfr.dll,avgrsstx.dll
              O20 - Winlogon Notify: byXOhHYp - byXOhHYp.dll (file missing)
              O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
              O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
              O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
              O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
              O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              0
              1. ComboFix 08-09-20.05 - Propri‚taire 2008-09-22 23:25:23.3 - NTFSx86
                Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.558 [GMT 2:00]
                Lancé depuis: C:\Documents and Settings\Propri‚taire\Bureau\Combofix.exe
                Commutateurs utilisés :: C:\Documents and Settings\Propri‚taire\Bureau\CFScript.txt
                * Un nouveau point de restauration a été créé

                [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                FILE ::
                C:\WINDOWS\system32\2becc0c2-.txt
                C:\WINDOWS\system32\bixwijek.ini
                C:\WINDOWS\system32\nnTBeMoq.ini
                C:\WINDOWS\system32\nnTBeMoq.ini2
                C:\WINDOWS\system32\snmgfr.dll
                .

                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                .

                C:\WINDOWS\system32\2becc0c2-.txt
                C:\WINDOWS\system32\bixwijek.ini
                C:\WINDOWS\system32\nnTBeMoq.ini
                C:\WINDOWS\system32\nnTBeMoq.ini2

                .
                ((((((((((((((((((((((((((((( Fichiers créés du 2008-08-22 au 2008-09-22 ))))))))))))))))))))))))))))))))))))
                .

                2008-09-22 23:23 . 2008-09-22 23:23 <REP> d-------- C:\C-Fix
                2008-09-22 22:46 . 2008-09-22 22:46 <REP> d-------- C:\Program Files\Ghostgum
                2008-09-21 15:45 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Media Player Classic
                2008-09-21 13:57 . 2008-09-21 13:57 <REP> d-------- C:\Program Files\Fichiers communs\Macrovision Shared
                2008-09-21 13:57 . 2008-09-21 13:57 54,784 --a------ C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                2008-09-21 13:57 . 2008-09-21 13:57 12,464 --a------ C:\WINDOWS\system32\drivers\CDAC15BA.SYS
                2008-09-21 13:56 . 2008-09-21 13:57 <REP> d-------- C:\Program Files\Fichiers communs\Autodesk Shared
                2008-09-21 13:56 . 2008-09-21 13:56 <REP> d-------- C:\Program Files\backburner 2
                2008-09-21 13:54 . 2008-09-21 13:54 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Autodesk
                2008-09-20 18:29 . 2008-09-20 18:29 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                2008-09-20 18:29 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Malwarebytes
                2008-09-20 18:29 . 2008-09-20 18:29 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                2008-09-20 18:29 . 2008-09-10 00:04 38,528 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
                2008-09-20 18:29 . 2008-09-10 00:03 17,200 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                2008-09-19 23:31 . 2008-09-19 23:31 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
                2008-09-19 23:31 . 2008-09-20 00:09 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                2008-09-19 23:30 . 2008-09-19 23:30 <REP> d-------- C:\Program Files\CCleaner
                2008-09-19 21:10 . 2008-09-19 22:42 4,976 --a------ C:\WINDOWS\system32\tmp.reg
                2008-09-19 19:28 . 2008-09-19 19:28 <REP> d-------- C:\rsit
                2008-09-19 19:24 . 2008-09-19 19:24 <REP> d-------- C:\Program Files\Trend Micro
                2008-09-19 18:47 . 2008-09-19 18:47 <REP> d-------- C:\Program Files\Navilog1
                2008-09-18 21:01 . 2008-09-22 07:22 <REP> d--h----- C:\$AVG8.VAULT$
                2008-09-18 20:58 . 2008-09-21 21:25 <REP> d-------- C:\WINDOWS\system32\drivers\Avg
                2008-09-18 20:58 . 2008-09-18 20:58 <REP> d-------- C:\Program Files\AVG
                2008-09-18 20:58 . <REP> C:\Documents and Settings\Propriétaire\Application Data\AVGTOOLBAR
                2008-09-18 20:58 . 2008-09-18 20:58 <REP> d-------- C:\Documents and Settings\All Users\Application Data\avg8
                2008-09-18 20:58 . 2008-09-18 20:58 97,928 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
                2008-09-18 20:58 . 2008-09-18 20:58 76,040 --a------ C:\WINDOWS\system32\drivers\avgtdix.sys
                2008-09-18 20:58 . 2008-09-18 20:58 12,936 --a------ C:\WINDOWS\system32\drivers\avgrkx86.sys
                2008-09-18 20:58 . 2008-09-18 20:58 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
                2008-09-18 20:56 . <REP> C:\Documents and Settings\Propriétaire\Application Data\Windows Search
                2008-09-03 22:39 . 2008-09-21 15:45 69 --a------ C:\WINDOWS\NeroDigital.ini
                2008-08-25 23:38 . 2008-08-25 23:39 38 --a------ C:\WINDOWS\avisplitter.INI
                2008-08-24 20:08 . <REP> C:\Documents and Settings\Propriétaire\Application Data\vlc
                2008-08-24 20:05 . 2008-08-24 20:05 <REP> d-------- C:\Program Files\VideoLAN

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-09-22 01:48 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
                2008-09-21 11:07 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\uTorrent
                2008-09-18 18:57 --------- d-s---w C:\Documents and Settings\Propriétaire\Application Data\Microsoft
                2008-09-15 19:17 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Adobe
                2008-08-14 13:11 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\LG Electronics
                2008-08-14 13:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
                2008-08-14 13:10 --------- d-----w C:\Program Files\LG PC Suite 2
                2008-08-14 13:10 --------- d-----w C:\Program Files\LG Electronics
                2008-08-14 13:09 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\InstallShield
                2008-08-07 11:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Winamp Toolbar
                2008-08-06 20:55 --------- d-----w C:\Program Files\OpenOffice.org 2.4
                2008-08-06 20:51 --------- d-----w C:\Program Files\Fichiers communs\Hewlett-Packard
                2008-08-06 20:49 --------- d-----w C:\Program Files\HP
                2008-08-06 20:22 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\OpenOffice.org2
                2008-08-06 11:00 --------- d-----w C:\Program Files\MSXML 4.0
                2008-08-05 21:21 --------- d-----w C:\Program Files\Microsoft.NET
                2008-08-05 17:17 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Nero
                2008-08-05 17:16 --------- d-----w C:\Program Files\Fichiers communs\Nero
                2008-08-05 17:14 --------- d-----w C:\Program Files\Nero
                2008-08-05 17:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
                2008-08-05 05:21 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\WinRAR
                2008-08-04 22:39 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
                2008-08-04 22:34 --------- d-----w C:\Program Files\Winamp Remote
                2008-08-04 22:34 --------- d-----w C:\Program Files\Winamp
                2008-08-04 21:36 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Real
                2008-08-03 17:01 --------- d-----w C:\Program Files\uTorrent
                2008-08-03 16:58 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Talkback
                2008-08-03 16:57 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Mozilla
                2008-08-02 16:01 --------- d-----w C:\Program Files\Fichiers communs\Adobe Systems Shared
                2008-08-02 16:01 --------- d-----w C:\Program Files\Fichiers communs\Adobe
                2008-08-02 16:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Macrovision
                2008-08-02 16:00 --------- d-----w C:\Program Files\Fichiers communs\InstallShield
                2008-08-02 15:44 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Winamp
                2008-08-02 09:26 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\MSNInstaller
                2008-08-02 09:05 --------- d-----w C:\Program Files\Microsoft IntelliType Pro
                2008-08-02 08:42 --------- d-----w C:\Program Files\Microsoft IntelliType Pro 6.02
                2008-07-30 15:10 --------- d-----w C:\Program Files\Java
                2008-07-30 15:04 --------- d-----w C:\Program Files\Windows Live
                2008-07-30 15:03 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
                2008-07-30 15:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                2008-07-30 14:45 --------- d-----w C:\Program Files\Real
                2008-07-30 14:45 --------- d-----w C:\Program Files\Fichiers communs\xing shared
                2008-07-30 14:45 --------- d-----w C:\Program Files\Fichiers communs\Real
                2008-07-30 14:44 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Macromedia
                2008-07-30 14:43 --------- d-----w C:\Program Files\Google
                2008-07-30 14:32 --------- d-----w C:\Program Files\Fichiers communs\Java
                2008-07-30 14:32 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Sun
                2008-07-30 14:30 --------- d-----w C:\Program Files\K-Lite Codec Pack
                2008-07-30 13:57 --------- d-----w C:\Program Files\DIFX
                2008-07-30 13:05 --------- d-----w C:\Program Files\Windows Desktop Search
                2008-07-30 13:05 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Windows Desktop Search
                2008-07-30 10:14 --------- d-----w C:\Program Files\Windows Media Connect 2
                2008-07-29 14:15 --------- d-----w C:\Documents and Settings\Propriétaire\Application Data\Identities
                2008-07-29 14:03 --------- d-----w C:\Program Files\microsoft frontpage
                2008-07-29 14:01 --------- d-----w C:\Program Files\Services en ligne
                2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
                2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
                2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
                2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
                2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
                2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
                2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
                2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
                2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
                2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
                2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
                2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
                2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
                2008-06-24 14:06 972,072 ----a-w C:\WINDOWS\UNNeroMediaHome.exe
                2008-06-23 16:28 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
                .

                ((((((((((((((((((((((((((((( snapshot@2008-09-21_11.58.22.96 )))))))))))))))))))))))))))))))))))))))))
                .
                + 2003-09-29 11:23:26 1,706,800 ----a-w C:\WINDOWS\Downloaded Program Files\gdiplus.dll
                + 2003-09-29 11:23:26 114,848 ----a-w C:\WINDOWS\Downloaded Program Files\IDropENU.dll
                + 2003-03-13 05:58:22 114,600 ----a-w C:\WINDOWS\Downloaded Program Files\IDropFRA.dll
                .
                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                REGEDIT4

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 15360]
                "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-13 1695232]
                "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
                "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
                "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-07-30 185632]
                "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
                "itype"="C:\Program Files\Microsoft IntelliType Pro\itype.exe" [2006-09-22 793408]
                "WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2008-07-09 36352]
                "NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2008-06-19 570664]
                "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
                "AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-09-18 1235736]
                "SoundMan"="SOUNDMAN.EXE" [2005-06-21 C:\WINDOWS\SOUNDMAN.EXE]
                "AlcWzrd"="ALCWZRD.EXE" [2005-06-29 C:\WINDOWS\ALCWZRD.EXE]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 15360]

                [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                "AppInit_DLLs"=avgrsstx.dll

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                "VIDC.YV12"= yv12vfw.dll

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                "%windir%\\system32\\sessmgr.exe"=
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                "C:\\Program Files\\uTorrent\\uTorrent.exe"=
                "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                "C:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
                "C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
                "C:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

                R0 AvgRkx86;avgrkx86.sys;C:\WINDOWS\system32\Drivers\avgrkx86.sys [2008-09-18 12936]
                R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-09-18 97928]
                R2 avg8emc;AVG8 E-mail Scanner;C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-09-18 875288]
                R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-09-18 231704]
                R2 AvgTdiX;AVG8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [2008-09-18 76040]
                R3 3xHybrid;3xHybrid service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2005-05-03 710144]
                .
                - - - - ORPHELINS SUPPRIMES - - - -

                BHO-{1109C88B-2081-30A9-8C6D-9BF211755EA7} - (no file)
                BHO-{FC5417E1-122F-451C-B0F1-F7E748BE955A} - (no file)

                **************************************************************************

                catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-09-22 23:27:10
                Windows 5.1.2600 Service Pack 3 NTFS

                Recherche de processus cachés ...

                Recherche d'éléments en démarrage automatique cachés ...

                Recherche de fichiers cachés ...

                Scan terminé avec succès
                Fichiers cachés: 0

                **************************************************************************
                .
                Heure de fin: 2008-09-22 23:27:46
                ComboFix-quarantined-files.txt 2008-09-22 21:27:43
                ComboFix2.txt 2008-09-21 16:25:37

                Avant-CF: 40ÿ226ÿ242ÿ560 octets libres
                Après-CF: 40,236,617,728 octets libres

                203 --- E O F --- 2008-09-12 16:54:14
                0
                1. Logfile of random's system information tool 1.02 (written by random/random)
                  Run by Propriétaire at 2008-09-22 23:32:10
                  Microsoft Windows XP Édition familiale Service Pack 3
                  System drive C: has 38 GB (77%) free of 50 GB
                  Total RAM: 1023 MB (50% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 23:32:39, on 22/09/2008
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                  C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                  C:\WINDOWS\system32\IoctlSvc.exe
                  C:\WINDOWS\system32\HPZipm12.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\SearchIndexer.exe
                  C:\WINDOWS\system32\Ati2evxx.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\PROGRA~1\AVG\AVG8\avgam.exe
                  C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                  C:\WINDOWS\SOUNDMAN.EXE
                  C:\WINDOWS\ALCWZRD.EXE
                  C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                  C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                  C:\Program Files\Microsoft IntelliType Pro\itype.exe
                  C:\Program Files\Winamp\winampa.exe
                  C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                  C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  C:\WINDOWS\system32\SearchProtocolHost.exe
                  C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Documents and Settings\Propriétaire\Bureau\RSIT.exe
                  C:\Program Files\Trend Micro\HijackThis\Propriétaire.exe

                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                  O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                  O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
                  O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                  O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                  O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                  O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                  O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                  O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                  O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                  O20 - AppInit_DLLs: avgrsstx.dll
                  O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                  O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                  O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                  O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                  O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                  O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                  0
                  1. Contributeur sécurité
                    ...
                    -1
                2. salut en fait il ne sort pas de rapport il y a ça comme résultat:

                  Cible sélectionnée : Poste de travail
                  Source : C:\; D:\; E:\; F:\; G:\; H:\; I:\;

                  Le rapport est vide.
                  Note : le logiciel gratuit Kaspersky On-line Scanner n’offre pas une protection globale et ne peut empêcher les infections futures. Il ne détecte que les codes malveillants qui ont déjà pénétré dans vos disques de stockage. Nous vous conseillons vivement d’utiliser entièrement solution antivirus opérationnel afin de protéger votre ordinateur en permanence.

                  Patientez, car ce processus peut prendre un certain temps en fonction de la cible sélectionnée. Si vous souhaitez continuer à surfer, ouvrez une seconde fenêtre.

                  Progression de l'analyse [99%]:

                  Total de fichiers analysés : 46342
                  Nombre de virus trouvés : 0
                  Nombre d'objets infectés : 0
                  Nombre d'objets suspects : 0
                  Durée de l'analyse : 01:10:06

                  Terminer


                  donc je ne sais pas
                  voila
                  0
                  1. Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 12:56:29, on 24/09/2008
                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\system32\Ati2evxx.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\SOUNDMAN.EXE
                    C:\WINDOWS\ALCWZRD.EXE
                    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\Program Files\Microsoft IntelliType Pro\itype.exe
                    C:\Program Files\Winamp\winampa.exe
                    C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
                    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                    C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                    C:\WINDOWS\system32\IoctlSvc.exe
                    C:\WINDOWS\system32\HPZipm12.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\SearchIndexer.exe
                    C:\PROGRA~1\AVG\AVG8\avgam.exe
                    C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                    C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                    C:\PROGRA~1\AVG\AVG8\avgemc.exe
                    C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                    C:\WINDOWS\system32\msiexec.exe
                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                    O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                    O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
                    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                    O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                    O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                    O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                    O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
                    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                    O20 - AppInit_DLLs: avgrsstx.dll
                    O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                    O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                    O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                    O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                    0
                    1. je te remercie pour ton aide

                      je crois qu il manque des info sur ton dernier post
                      0
                      1. Contributeur sécurité
                        Salut,

                        commences par ceci :

                        1- Télécharges et installes le logiciel HijackThis :

                        ici ftp://ftp.commentcamarche.com/download/HJTInstall.exe
                        ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
                        ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

                        -->Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
                        A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
                        Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
                        "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

                        ( ne lance pas ce prg pour l'instant et fais la suite ... )

                        2- Télécharges Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                        -> http://images.malwareremoval.com/random/RSIT.exe

                        ! Déconnecte toi et fermes toutes tes applications en cours !

                        Double-clique sur " RSIT.exe " pour le lancer .

                        -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                        * Devant l'option "List files/folders created ..." , tu choisis : 3 months

                        * cliques ensuite sur " Continue " pour lancer l'analyse ...

                        -> laisses faire le scan et ne touche pas au PC ...

                        Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                        Postes le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                        ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
                        -1
                        1. SmitFraudFix v2.352

                          Rapport fait à 21:10:01,09, 19/09/2008
                          Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                          Le type du système de fichiers est NTFS
                          Fix executé en mode normal

                          »»»»»»»»»»»»»»»»»»»»»»»» Process

                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\SOUNDMAN.EXE
                          C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                          C:\WINDOWS\ALCWZRD.EXE
                          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                          C:\Program Files\Microsoft IntelliType Pro\itype.exe
                          C:\Program Files\Winamp\winampa.exe
                          C:\Windows\system32\YUR442.exe
                          C:\WINDOWS\system32\IoctlSvc.exe
                          C:\Windows\system32\YUR445.exe
                          C:\Windows\system32\YUR446.exe
                          C:\WINDOWS\system32\HPZipm12.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\WINDOWS\system32\SearchIndexer.exe
                          C:\Program Files\Messenger\msmsgs.exe
                          C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
                          C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                          C:\WINDOWS\system32\wscntfy.exe
                          C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                          C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                          C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                          C:\PROGRA~1\AVG\AVG8\avgam.exe
                          C:\PROGRA~1\AVG\AVG8\avgemc.exe
                          C:\Program Files\Windows Live\Messenger\usnsvc.exe
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\PCHealthCenter\2.exe
                          C:\Program Files\PCHealthCenter\3.exe
                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                          C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
                          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Documents and Settings\Propriétaire\Bureau\SmitfraudFix\Policies.exe
                          C:\WINDOWS\system32\SearchProtocolHost.exe
                          C:\WINDOWS\system32\cmd.exe

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                          C:\WINDOWS\system32\1.ico PRESENT !
                          C:\WINDOWS\system32\2.ico PRESENT !

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Propri‚taire

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Propri‚taire\Application Data

                          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PROPRI~1\Favoris

                          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                          C:\DOCUME~1\PROPRI~1\Bureau\BEST ZOO PORN.url PRESENT !

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                          C:\Program Files\PCHealthCenter\ PRESENT !

                          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                          "Source"="About:Home"
                          "SubscribedURL"="About:Home"
                          "FriendlyName"="Ma page d'accueil"

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          404Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                          "AppInit_DLLs"="snmgfr.dll,avgrsstx.dll"
                          "LoadAppInit_DLLs"=dword:00000001

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                          "System"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» RK

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          Description: Carte réseau Fast Ethernet PCI Realtek RTL8139 Family - Miniport d'ordonnancement de paquets
                          DNS Server Search Order: 192.168.1.1

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{A4564A10-C017-4114-B7C8-F916EE3A1B95}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{A4564A10-C017-4114-B7C8-F916EE3A1B95}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{A4564A10-C017-4114-B7C8-F916EE3A1B95}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin
                          -1
                          1. SmitFraudFix v2.352

                            Rapport fait à 22:42:14,75, 19/09/2008
                            Executé à partir de C:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
                            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                            Le type du système de fichiers est NTFS
                            Fix executé en mode normal

                            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            SrchSTS.exe by S!Ri
                            Search SharedTaskScheduler's .dll

                            »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                            »»»»»»»»»»»»»»»»»»»»»»»» hosts

                            127.0.0.1 localhost

                            »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                            VACFix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                            S!Ri's WS2Fix: LSP not Found.

                            »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                            GenericRenosFix by S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                            C:\WINDOWS\system32\1.ico supprimé
                            C:\WINDOWS\system32\2.ico supprimé
                            C:\Program Files\PCHealthCenter\ supprimé

                            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                            IEDFix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                            404Fix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                            AntiXPVSTFix
                            Credits: Malware Analysis & Diagnostic
                            Code: S!Ri

                            »»»»»»»»»»»»»»»»»»»»»»»» RK

                            »»»»»»»»»»»»»»»»»»»»»»»» DNS

                            Description: Carte réseau Fast Ethernet PCI Realtek RTL8139 Family - Miniport d'ordonnancement de paquets
                            DNS Server Search Order: 192.168.1.1

                            HKLM\SYSTEM\CCS\Services\Tcpip\..\{A4564A10-C017-4114-B7C8-F916EE3A1B95}: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS1\Services\Tcpip\..\{A4564A10-C017-4114-B7C8-F916EE3A1B95}: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS3\Services\Tcpip\..\{A4564A10-C017-4114-B7C8-F916EE3A1B95}: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                            »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                            "System"=""

                            »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                            Nettoyage terminé.

                            »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                            SrchSTS.exe by S!Ri
                            Search SharedTaskScheduler's .dll

                            »»»»»»»»»»»»»»»»»»»»»»»» Fin
                            -1
                            1. Contributeur sécurité
                              Bien ... Refais un scan RSIT comme je te l'ai demandé et postes moi le rapport obtenu pour analyse ...
                              -1
                              1. Logfile of random's system information tool 1.02 (written by random/random)
                                Run by Propriétaire at 2008-09-19 23:23:57
                                Microsoft Windows XP Édition familiale Service Pack 3
                                System drive C: has 34 GB (68%) free of 50 GB
                                Total RAM: 1023 MB (56% free)

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 23:24:06, on 19/09/2008
                                Platform: Windows XP SP3 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\WINDOWS\system32\Ati2evxx.exe
                                C:\WINDOWS\explorer.exe
                                C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                C:\WINDOWS\SOUNDMAN.EXE
                                C:\WINDOWS\ALCWZRD.EXE
                                C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                C:\Program Files\Microsoft IntelliType Pro\itype.exe
                                C:\Program Files\Winamp\winampa.exe
                                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                                C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Messenger\msmsgs.exe
                                C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
                                C:\WINDOWS\system32\IoctlSvc.exe
                                C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                C:\WINDOWS\system32\HPZipm12.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\SearchIndexer.exe
                                C:\PROGRA~1\AVG\AVG8\avgam.exe
                                C:\PROGRA~1\AVG\AVG8\avgrsx.exe
                                C:\PROGRA~1\AVG\AVG8\avgnsx.exe
                                C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                C:\PROGRA~1\AVG\AVG8\aAvgApi.exe
                                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                C:\Documents and Settings\Propriétaire\Bureau\RSIT.exe
                                C:\Program Files\Trend Micro\HijackThis\Propriétaire.exe

                                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                F2 - REG:system.ini: Shell=explorer.exe
                                O2 - BHO: D - {1109C88B-2081-30A9-8C6D-9BF211755EA7} - C:\WINDOWS\system32\mmx89564.dll (file missing)
                                O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                O2 - BHO: {167b5bf0-3527-734b-d824-9df3867b0c1c} - {c1c0b768-3fd9-428d-b437-72530fb5b761} - C:\WINDOWS\system32\snmgfr.dll
                                O2 - BHO: (no name) - {FC5417E1-122F-451C-B0F1-F7E748BE955A} - C:\WINDOWS\system32\qoMeBTnn.dll (file missing)
                                O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
                                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
                                O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
                                O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                                O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
                                O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
                                O4 - HKLM\..\Run: [\YUR442.exe] C:\Windows\system32\YUR442.exe
                                O4 - HKLM\..\Run: [\YUR443.exe] C:\Windows\system32\YUR443.exe
                                O4 - HKLM\..\Run: [\YUR444.exe] C:\Windows\system32\YUR444.exe
                                O4 - HKLM\..\Run: [\YUR445.exe] C:\Windows\system32\YUR445.exe
                                O4 - HKLM\..\Run: [\YUR446.exe] C:\Windows\system32\YUR446.exe
                                O4 - HKLM\..\Run: [20cf04bc] rundll32.exe "C:\WINDOWS\system32\kejiwxib.dll",b
                                O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
                                O4 - HKLM\..\Run: [\YUR16.exe] C:\Windows\system32\YUR16.exe
                                O4 - HKLM\..\Run: [\YUR29.exe] C:\Windows\system32\YUR29.exe
                                O4 - HKLM\..\Run: [\YUR2A.exe] C:\Windows\system32\YUR2A.exe
                                O4 - HKLM\..\Run: [\YUR2B.exe] C:\Windows\system32\YUR2B.exe
                                O4 - HKLM\..\Run: [\YUR2C.exe] C:\Windows\system32\YUR2C.exe
                                O4 - HKLM\..\Run: [\YUR52.exe] C:\Windows\system32\YUR52.exe
                                O4 - HKLM\..\Run: [\YUR53.exe] C:\Windows\system32\YUR53.exe
                                O4 - HKLM\..\Run: [\YUR54.exe] C:\Windows\system32\YUR54.exe
                                O4 - HKLM\..\Run: [\YUR55.exe] C:\Windows\system32\YUR55.exe
                                O4 - HKLM\..\Run: [\YUR58.exe] C:\Windows\system32\YUR58.exe
                                O4 - HKLM\..\Run: [\YUR91.exe] C:\Windows\system32\YUR91.exe
                                O4 - HKLM\..\Run: [\YUR97.exe] C:\Windows\system32\YUR97.exe
                                O4 - HKLM\..\Run: [\YUR98.exe] C:\Windows\system32\YUR98.exe
                                O4 - HKLM\..\Run: [\YURCB.exe] C:\Windows\system32\YURCB.exe
                                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
                                O4 - HKCU\..\Run: [\YUR442.exe] C:\Windows\system32\YUR442.exe
                                O4 - HKCU\..\Run: [\YUR443.exe] C:\Windows\system32\YUR443.exe
                                O4 - HKCU\..\Run: [\YUR444.exe] C:\Windows\system32\YUR444.exe
                                O4 - HKCU\..\Run: [\YUR445.exe] C:\Windows\system32\YUR445.exe
                                O4 - HKCU\..\Run: [\YUR446.exe] C:\Windows\system32\YUR446.exe
                                O4 - HKCU\..\Run: [\YUR16.exe] C:\Windows\system32\YUR16.exe
                                O4 - HKCU\..\Run: [\YUR29.exe] C:\Windows\system32\YUR29.exe
                                O4 - HKCU\..\Run: [\YUR2A.exe] C:\Windows\system32\YUR2A.exe
                                O4 - HKCU\..\Run: [\YUR2B.exe] C:\Windows\system32\YUR2B.exe
                                O4 - HKCU\..\Run: [\YUR2C.exe] C:\Windows\system32\YUR2C.exe
                                O4 - HKCU\..\Run: [\YUR52.exe] C:\Windows\system32\YUR52.exe
                                O4 - HKCU\..\Run: [\YUR53.exe] C:\Windows\system32\YUR53.exe
                                O4 - HKCU\..\Run: [\YUR54.exe] C:\Windows\system32\YUR54.exe
                                O4 - HKCU\..\Run: [\YUR55.exe] C:\Windows\system32\YUR55.exe
                                O4 - HKCU\..\Run: [\YUR58.exe] C:\Windows\system32\YUR58.exe
                                O4 - HKCU\..\Run: [\YUR91.exe] C:\Windows\system32\YUR91.exe
                                O4 - HKCU\..\Run: [\YUR97.exe] C:\Windows\system32\YUR97.exe
                                O4 - HKCU\..\Run: [\YUR98.exe] C:\Windows\system32\YUR98.exe
                                O4 - HKCU\..\Run: [\YURCB.exe] C:\Windows\system32\YURCB.exe
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
                                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
                                O20 - AppInit_DLLs: snmgfr.dll,avgrsstx.dll
                                O20 - Winlogon Notify: byXOhHYp - byXOhHYp.dll (file missing)
                                O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                                O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
                                O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                                O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
                                O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe
                                O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                -1
                                1. Contributeur sécurité
                                  ok ... la suite :

                                  1- Télécharges : - CCleaner
                                  https://www.pcastuces.com/logitheque/ccleaner.htm
                                  Ce logiciel va permettre de supprimer tous les fichiers temporaires et de corrigé ton registre .Lors de l'installation, avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires" sauf les 2 première.
                                  Une fois le prg instalé et lancé, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures"( Par la suite, laisse-le avec ses réglages par défaut. C'est tout ).

                                  Un tuto ( aide ):
                                  http://perso.orange.fr/jesses/Docs/Logiciels/CCleaner.htm

                                  ---> Utilisation:
                                  ! déconnectes toi et fermes toutes applications en cours !
                                  * vas dans "nettoyeur" : fait analyse puis nettoyage
                                  * vas dans "registre" : fait chercher les erreurs et réparer ( plusieurs fois jusqu'à ce qu'il n'y est plus d'erreur ) .

                                  ( CCleaner : soft à garder sur son PC , super utile pour de bons nettoyages ... )

                                  2- Télécharges VirtumundoBegone sur ton bureau:
                                  http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

                                  !! Ce déconnecter et fermer toute ces applications le temps de la manipe !!

                                  Double cliquer sur VirtumundoBeGone.exe et suivre les instructions.
                                  Une fois terminé, redémarrer le PC, le rapport VBG.TXT sera crée sur le bureau .
                                  (Si un message Ecran bleu "Erreur fatale" apparaît, pas d’inquiétude car c'est normal et attendu).

                                  Postes le rapport VBG accompagné d'un nouveau rapport RSIT pour analyse ...
                                  -1
                              2. Contributeur sécurité
                                Bon ... la suite :

                                Télécharges MalwareByte's :
                                ici ftp://ftp.commentcamarche.com/download/mbam-setup.exe
                                ou ici : http://www.malwarebytes.org/mbam.php

                                Installes le ( choisis bien "francais" ; ne modifies pas les paramètres d'installe ) et mets le à jour .

                                (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharges le ici : https://www.malekal.com/tutorial-aboutbuster/ )

                                Potasses le tuto pour te familiariser avec le prg : https://forum.pcastuces.com/sujet.asp?f=31&s=3
                                ( cela dis, il est très simple d'utilisation ).

                                Impératif : redémarres en mode sans échec :
                                Comment aller en Mode sans échec
                                1) Redémarres ton ordi
                                2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                                3) Tu verras un écran avec options de démarrage apparaître
                                4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                                5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
                                (attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...)

                                Lances Malwarebyte's .

                                Fais un scan dit "complet" ( sélectionnes bien tous tes disks avant le scan ! ) et supprimes tout ce qu'il peut trouver, c'est à dire :
                                -->Laisses le scan se terminer,puis à la fin tu cliques sur "résultat" .
                                -->Vérifies que tous les objets infectés soient validés, puis cliques sur " suppression " .

                                Redémarres ton PC ( mode normal ).

                                Postes le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date) accompagné d'un nouvel hijackthis ( fait en mode normal ) ...
                                -1
                                1. Contributeur sécurité
                                  Salut,

                                  On continue dans l'ordre :

                                  1- Supprimes tout ce qui ce trouve dans la quarantaine de Malwarebytes ( via celle-ci bien sûr ) .

                                  2- Refais un coup de CCleaner ( registre compris ) .

                                  3- Fais exactement ce qui suit :

                                  Télécharges ComboFix (par sUBs) sur ton Bureau (et pas ailleurs !):
                                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe <--- clik droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix et valide .

                                  --------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
                                  !! Déconnectes toi,fermes tes applications en cours et DESACTIVES TOUTES TES DEFENSES (anti-virus, guardes anti spy-ware, pare-feu) le temps de la manipe :
                                  en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!
                                  --->Important : si tu rencontres des difficultés à ce niveau là, fais m'en part avant de poursuivre ...
                                  Tuto ( aide ) ici : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                                  ---------------------------------------------------------------------------------------------------------------------------------

                                  Ensuite :
                                  double-cliques C-Fix.exe ( = combofix.exe ) .

                                  Appuyes sur la touche Y (Yes) pour démarrer le scan .

                                  Attention :
                                  --> n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi .
                                  --> Il se peut que le PC redémarre de lui même ( pour finaliser le nettoyage ) , laisses le faire .
                                  --> si un message d'erreur windows apparait à un momment : clik sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

                                  Le rapport sera crée dans: C:\Combofix.txt

                                  Postes le rapport Combofix accompagné d'un nouveau rapport RSIT pour analyse ...
                                  -1
                                  1. Contributeur sécurité
                                    la suite:

                                    1-Crées un doc texte sur ton bureau :
                                    pointes ta souris sur ton bureau , cliques droit : vas dans "nouveau" et choisis "document texte" .

                                    Ensuite copie/colle le texte ci-dessous ( et rien d'autre!) dans le fichier texte que tu viens de créer :

                                    Registry::
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                                    "AppInit_DLLs"=-

                                    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byXOhHYp]

                                    File::
                                    C:\WINDOWS\system32\bixwijek.ini
                                    C:\WINDOWS\system32\2becc0c2-.txt
                                    C:\WINDOWS\system32\nnTBeMoq.ini2
                                    C:\WINDOWS\system32\nnTBeMoq.ini


                                    Puis vas dans "fichier" et choisis "enregistrer sous ..." et tu le nommes exactement ainsi :
                                    CFScript puis valides ...

                                    2-Nettoyage :

                                    !! Déconnectes toi, fermes toutes tes applications et désactives TOUTES TES DEFENSES ( tu les réactiveras après ) !!

                                    --->Sur ton bureau, fais un glissé avec ta souris le fichier CFScript sur l'icône de ComboFix.exe .

                                    (Regarde ici : http://i261.photobucket.com/albums/ii49/Malekal_morte/CFScript.gif )

                                    Cette manipulation va relancer combofix .
                                    --> Une fenêtre bleue va apparaître: au message qui apparaît "Type 1 to continue, or 2 to abort" : tapes 1 puis valide.

                                    Puis patientes le temps du scan.( Le Bureau va disparaître à plusieurs reprises : c'est normal!)

                                    !! Ne touches à rien tant que le scan n'est pas terminé !!

                                    Note : en fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisses-le faire.

                                    Une fois le scan achevé, un rapport va s'afficher : Postes le accompagné dans une autre réponse d' un nouveau rapport RSIT pour analyse ...

                                    ( Attention : cette manipe a été fait pour ce PC . Toute réutilisation peut endommager sévèrement le système d'exploitation )
                                    -1
                                    • 1
                                    • 2