Farandole de virus et malwares

Résolu
Bonjour,

Vendredi dernier, j'ai été attaqué par le malware Antivirus XP 2008. Depuis j'ai installé Avast, ce qui me semble être une erreur avec le recul parce qu'il n'arrête pas de me trouver des virus, notamment rookit-gen et Win 32: Trojan-gen, mais qu'il ne les supprime jamais complètement. A chaque redémarrage, je les retrouve.

Je crois que je me suis débarrassé d'antivirus XP, mais il y a toujours des séquelles : j'ai toujours le fond d'écran inamovible avec la fenêtre m'invitant à acheter antivirus XP. Impossible de l'enlever ou de restaurer les onglets des propriétés du fond d'écran.

Mais le plus grave, c'est que mon Outlook est complètement hijacké. Dès que je me connecte, badaboum, Avast me signale des tombereaux de mails inconnus qui partent de mon compte pour vendre des assurances ou des développeurs de pénis, vous voyez le genre.

Avast proposait un scan au redémarrage, et j'ai coché la case : il m'a scanné les disques durs au démarrage, sur l'écran en fond bleu, avant que l'ordi ne me demande mon mdp. Ca n'a rien arrangé.

Dernière surprise : ce matin, le démarrage foire et j'ai un message de windows qui me dit que "le système s'est remis d'une erreur grave" et qu'il faut faire un signalement d'erreurs. Ca m'a conduit vers un site intitulé "wer.microsoft.com" et j'ai peur de m'être fait avoir.

Enfin, je suis sur XP, sur un Acer que j'ai acheté "tout installé". J'ai essayé carrément de formater le disque dur, mais je n'y arrive pas (j'aurais utilisé le CD d'install d'XP que j'utilisais sur mon ordinateur précédent.

Donc, là je ne sais pas trop quoi faire ni par où commencer. Télécharger malewarebytes ? Hijackthis ? Comme vous l'aurez constaté, je suis une brelle en informatique... Si quelqu'un peut me porter secours, ce serait formidable.
Configuration: Windows XP
Internet Explorer 7.0

19 réponses

  1. Bon, voilà le rapport de Hijackthis (que j'ai renommé en HJT) :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:44:13, on 22/09/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
    C:\Acer\Empowering Technology\eRecovery\Monitor.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-

    B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\WINDOWS\system32\PSIService.exe
    C:\Program Files\Acer\Acer eMode Management\AspireService.exe
    C:\Program Files\Acer\Acer eConsole\MediaSync.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-

    B58F-2F227FCA9A08}\PIFSvc.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\WINDOWS\system32\lphclj6j0erdj.exe
    C:\WINDOWS\system32\rtm.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Trend Micro\HijackThis\HJT.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

    https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

    https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

    https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =

    https://www.acer.com/worldwide/selection.html
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet

    Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,userinit.exe
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-

    784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer -

    {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program

    Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -

    C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -

    c:\program files\google\googletoolbar4.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

    files\google\googletoolbar4.dll
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-

    Maker 7\ntiMUI.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07

    \bin\jusched.exe"
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program

    Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil

    /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe

    /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32

    \IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

    /IMEName
    O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering

    Technology\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode

    Management\AspireService.exe
    O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer

    eConsole\MediaSync.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program

    Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software

    Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop

    Album Starter Edition\3.0\Apps\apdproxy.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -

    atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers

    communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe"

    /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-

    4c61-B58F-2F227FCA9A08}\AlertEng.dll"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers

    communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [lphclj6j0erdj] C:\WINDOWS\system32\lphclj6j0erdj.exe
    O4 - HKLM\..\Run: [inrhcgj6j0erdj] C:\Documents and Settings\JayWicky\Local

    Settings\Temp\.tt63.tmp.exe

    /CR=5F8C0875B49BA02BB503A8EC828A17BC23B10321BDF21BB1F8AD889BF06E9C2A49DE13EBC4

    84CF0342D937C907953F32B0A974C1649723F0C0F149B8BD36C2092476569ADD79758CE1B3FCF2

    4785858397
    O4 - HKLM\..\Run: [rtm] C:\WINDOWS\system32\rtm.exe \u
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program

    Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
    O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0

    \Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User

    'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User

    'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User

    'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User

    'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program

    Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk =

    C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program

    Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel -

    res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

    C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-

    00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -

    C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -

    C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-

    f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

    C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-

    00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} -

    https://support.norton.com/sp/en/us/home/current/info
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -

    http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} -

    http://download.divx.com/player/DivXBrowserPlugin.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager)

    - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

    http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_

    site.cab?1156030872718
    O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de

    DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm

    -activex-2.2.1.6.cab
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program

    Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer

    eConsole\MediaServerService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software -

    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. -

    C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil

    Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil

    Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil

    Software\Avast4\ashWebSv.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown

    owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file

    missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program

    Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision

    Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel

    32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program

    Files\iPod\bin\iPodService.exe
    O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown

    owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file

    missing)
    O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program

    Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-

    2F227FCA9A08}\PIFSvc.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32

    \PSIService.exe
    0
    1. OK... Mais comment je fais pour désactiver les protections? Merci.
      0
      1. Non, c'est bon, il y a un lien pour désactiver les protections sur la page du tutorial combofix, désolé, j'avais pas vu.
        0
        1. Euh, désolé d'être lourd, mais je préfère être prudent : quand je fais glisser l'icone du fichier d'installation de la console de récupération Windows sur Combofix, Combofix démarre directement. C'est normal ?

          Encore une fois, désolé, mais vu que Combofix a l'air d'être un truc assez puissant, je préfère prendre un max de précautions.
          0
          1. Alors voilà le log de combofix. Mon nom apparaissant dans mon nom d'utilisateur, je l'ai remplacé par *****.

            ComboFix 08-09-20.05 - **** 2008-09-23 14:35:56.1 - NTFSx86
            Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.375 [GMT 2:00]
            Lancé depuis: C:\Documents and Settings\****\Bureau\ComboFix.exe
            Commutateurs utilisés :: C:\Documents and Settings\****\Bureau\WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
            * Un nouveau point de restauration a été créé
            .

            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
            .

            C:\WINDOWS\Downloaded Program Files\setup.inf
            C:\WINDOWS\system32\lphclj6j0erdj.exe
            C:\WINDOWS\system32\phclj6j0erdj.bmp

            .
            ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
            .

            -------\Service_TDSSserv

            ((((((((((((((((((((((((((((( Fichiers créés du 2008-08-23 au 2008-09-23 ))))))))))))))))))))))))))))))))))))
            .

            2008-09-22 10:43 . 2008-09-22 10:43 <REP> d-------- C:\Program Files\Trend Micro
            2008-09-22 09:11 . 2008-09-22 09:11 104,944 --a------ C:\WINDOWS\system32\drivers\b2847a37.sys
            2008-09-19 18:51 . 2008-09-19 18:51 <REP> d-------- C:\Program Files\Alwil Software
            2008-09-19 14:06 . 2008-09-19 14:06 33,280 --a------ C:\WINDOWS\system32\rtm.exe
            2008-09-19 14:06 . 2008-09-19 14:06 33,280 ---h----- C:\Documents and Settings\****\kji.exe
            2008-08-27 14:47 . 2008-08-27 14:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WinZip

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2008-09-19 16:48 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
            2008-09-19 16:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
            2008-09-19 16:44 --------- d-----w C:\Program Files\Norton 360
            2008-08-18 15:15 --------- d-----w C:\Program Files\Lavasoft
            2008-08-18 15:14 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
            2008-08-18 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
            2008-07-30 15:42 23,888 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
            2008-07-30 15:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
            2008-07-30 15:28 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
            2008-07-24 17:57 --------- d-----w C:\Program Files\Java
            2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
            2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
            2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
            2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
            2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
            2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
            2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
            2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
            2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
            2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
            2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
            2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
            2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
            2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
            2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
            2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
            2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
            2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
            2008-07-07 20:28 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
            2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
            2008-06-24 16:44 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
            2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
            2008-06-24 08:28 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
            2008-06-23 09:21 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
            2008-06-23 09:21 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
            2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
            2005-05-13 15:12 217,073 -csha-r C:\WINDOWS\meta4.exe
            2005-10-24 09:13 66,560 --sha-r C:\WINDOWS\MOTA113.exe
            2005-07-14 10:31 27,648 --sha-r C:\WINDOWS\system32\AVSredirect.dll
            2008-02-08 10:50 88 --sh--r C:\WINDOWS\system32\CD27353510.sys
            2005-06-26 13:32 616,448 -csha-r C:\WINDOWS\system32\cygwin1.dll
            2005-06-21 20:37 45,568 --sha-r C:\WINDOWS\system32\cygz.dll
            2004-01-24 22:00 70,656 --sha-r C:\WINDOWS\system32\i420vfw.dll
            2008-02-08 10:50 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
            2005-02-28 11:16 240,128 --sha-r C:\WINDOWS\system32\x.264.exe
            2004-01-24 22:00 70,656 --sha-r C:\WINDOWS\system32\yv12vfw.dll
            .

            ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
            "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]
            "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "LaunchApp"="Alaunch" [X]
            "ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]
            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
            "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
            "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
            "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
            "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
            "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
            "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 397312]
            "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-09-29 114688]
            "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-09-21 425984]
            "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
            "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
            "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
            "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 282624]
            "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-05-26 257088]
            "Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
            "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-04-18 185896]
            "rtm"="C:\WINDOWS\system32\rtm.exe" [2008-09-19 33280]
            "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 C:\WINDOWS\system32\HdAShCut.exe]
            "RTHDCPL"="RTHDCPL.EXE" [2005-09-22 C:\WINDOWS\RTHDCPL.exe]

            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
            "vidc.I420"= i420vfw.dll
            "vidc.yv12"= yv12vfw.dll
            "VIDC.ACDV"= ACDV.dll

            [HKEY_LOCAL_MACHINE\software\microsoft\security center]
            "AntiVirusDisableNotify"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
            "DisableMonitoring"=dword:00000001

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
            "EnableFirewall"= 0 (0x0)

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
            "C:\\Program Files\\iTunes\\iTunes.exe"=
            "C:\\Documents and Settings\\****\\kji.exe"=
            "C:\\WINDOWS\\system32\\rtm.exe"=

            R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-02-05 85888]
            R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
            R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
            R2 BCMNTIO;BCMNTIO;C:\PROGRA~1\CheckIt\DIAGNO~1\BCMNTIO.sys [2004-03-18 3744]
            R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 69632]
            R2 MAPMEM;MAPMEM;C:\PROGRA~1\CheckIt\DIAGNO~1\MAPMEM.sys [2004-03-18 3904]
            .
            - - - - ORPHELINS SUPPRIMES - - - -

            HKCU-Run-swg - C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
            HKCU-Run-WhenUSave - C:\Program Files\Save\Save.exe
            HKLM-Run-lphclj6j0erdj - C:\WINDOWS\system32\lphclj6j0erdj.exe
            HKLM-Run-inrhcgj6j0erdj - C:\Documents and Settings\****\Local Settings\Temp\.tt63.tmp.exe

            .
            ------- Examen supplémentaire -------
            .
            R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
            R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
            R1 -: HKCU-Internet Connection Wizard,ShellNext = hxxp://global.acer.com/
            R1 -: HKCU-Internet Settings,ProxyOverride = *.local
            R1 -: HKCU-SearchURL,(Default) = hxxp://www.google.com/search?q=%s
            O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            .

            **************************************************************************

            catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2008-09-23 14:40:09
            Windows 5.1.2600 Service Pack 3 NTFS

            Recherche de processus cachés ...

            Recherche d'éléments en démarrage automatique cachés ...

            Recherche de fichiers cachés ...

            Scan terminé avec succès
            Fichiers cachés: 0

            **************************************************************************
            .
            ------------------------ Autres processus actifs ------------------------
            .
            C:\WINDOWS\system32\ati2evxx.exe
            C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\ati2evxx.exe
            C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
            C:\WINDOWS\system32\PSIService.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
            C:\ComboFix\pv.cfexe
            .
            **************************************************************************
            .
            Heure de fin: 2008-09-23 14:47:12 - La machine a redémarré [****]
            ComboFix-quarantined-files.txt 2008-09-23 12:47:07

            Avant-CF: 66ÿ387ÿ709ÿ952 octets libres
            Après-CF: 66,401,628,160 octets libres

            WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
            [boot loader]
            timeout=2
            default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
            [operating systems]
            C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
            multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

            189 --- E O F --- 2008-09-10 12:21:21

            Et voilà le log d'hijackthis :

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 14:56:27, on 23/09/2008
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v7.00 (7.00.6000.16705)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\Ati2evxx.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\Acer\Empowering Technology\eRecovery\Monitor.exe
            C:\Program Files\Acer\Acer eMode Management\AspireService.exe
            C:\Program Files\Acer\Acer eConsole\MediaSync.exe
            C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\WINDOWS\system32\PSIService.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\HJT.exe

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
            O4 - HKLM\..\Run: [LaunchApp] Alaunch
            O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
            O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
            O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
            O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
            O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - https://support.norton.com/sp/en/us/home/current/info
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
            O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
            O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
            O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
            O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
            O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
            O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
            0
            1. Voilà le combofix :

              ComboFix 08-09-20.05 - **** 2008-09-23 16:58:08.2 - NTFSx86
              Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.411 [GMT 2:00]
              Lancé depuis: C:\Documents and Settings\****\Bureau\ComboFix.exe
              Commutateurs utilisés :: C:\Documents and Settings\****\Bureau\CFScript.txt
              * Un nouveau point de restauration a été créé

              FILE ::
              c:\documents and settings\****\local settings\temp\.tt63.tmp.exe
              c:\program files\save\save.exe
              .

              ((((((((((((((((((((((((((((( Fichiers créés du 2008-08-23 au 2008-09-23 ))))))))))))))))))))))))))))))))))))
              .

              2008-09-22 10:43 . 2008-09-22 10:43 <REP> d-------- C:\Program Files\Trend Micro
              2008-09-22 09:11 . 2008-09-22 09:11 104,944 --a------ C:\WINDOWS\system32\drivers\b2847a37.sys
              2008-09-19 18:51 . 2008-09-19 18:51 <REP> d-------- C:\Program Files\Alwil Software
              2008-09-19 14:06 . 2008-09-19 14:06 33,280 ---h----- C:\Documents and Settings\****\kji.exe
              2008-08-27 14:47 . 2008-08-27 14:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WinZip

              .
              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
              .
              2008-09-19 16:48 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
              2008-09-19 16:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
              2008-09-19 16:44 --------- d-----w C:\Program Files\Norton 360
              2008-08-18 15:15 --------- d-----w C:\Program Files\Lavasoft
              2008-08-18 15:14 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
              2008-08-18 15:13 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
              2008-07-30 15:42 23,888 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
              2008-07-30 15:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
              2008-07-30 15:28 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
              2008-07-24 17:57 --------- d-----w C:\Program Files\Java
              2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
              2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
              2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
              2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
              2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
              2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
              2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
              2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
              2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
              2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
              2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
              2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
              2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
              2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
              2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
              2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
              2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
              2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
              2008-07-07 20:28 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
              2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
              2008-06-24 16:44 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
              2008-06-24 16:12 295,936 ------w C:\WINDOWS\system32\wmpeffects.dll
              2008-06-24 08:28 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
              2008-06-23 09:21 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
              2008-06-23 09:21 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
              2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
              2005-05-13 15:12 217,073 -csha-r C:\WINDOWS\meta4.exe
              2005-10-24 09:13 66,560 --sha-r C:\WINDOWS\MOTA113.exe
              2005-07-14 10:31 27,648 --sha-r C:\WINDOWS\system32\AVSredirect.dll
              2008-02-08 10:50 88 --sh--r C:\WINDOWS\system32\CD27353510.sys
              2005-06-26 13:32 616,448 -csha-r C:\WINDOWS\system32\cygwin1.dll
              2005-06-21 20:37 45,568 --sha-r C:\WINDOWS\system32\cygz.dll
              2004-01-24 22:00 70,656 --sha-r C:\WINDOWS\system32\i420vfw.dll
              2008-02-08 10:50 848 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
              2005-02-28 11:16 240,128 --sha-r C:\WINDOWS\system32\x.264.exe
              2004-01-24 22:00 70,656 --sha-r C:\WINDOWS\system32\yv12vfw.dll
              .

              ((((((((((((((((((((((((((((( snapshot@2008-09-23_14.46.47.89 )))))))))))))))))))))))))))))))))))))))))
              .
              + 2008-09-23 14:48:50 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_5b0.dat
              .
              ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
              .
              .
              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
              REGEDIT4

              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
              "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2008-04-14 1695232]
              "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "LaunchApp"="Alaunch" [X]
              "ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 45056]
              "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
              "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 32768]
              "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 208952]
              "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 59392]
              "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
              "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
              "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 397312]
              "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-09-29 114688]
              "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-09-21 425984]
              "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 241664]
              "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 49152]
              "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
              "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-04-27 282624]
              "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-05-26 257088]
              "Symantec PIF AlertEng"="C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
              "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-04-18 185896]
              "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 C:\WINDOWS\system32\HdAShCut.exe]
              "RTHDCPL"="RTHDCPL.EXE" [2005-09-22 C:\WINDOWS\RTHDCPL.exe]

              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
              "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-14 15360]

              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
              "vidc.I420"= i420vfw.dll
              "vidc.yv12"= yv12vfw.dll
              "VIDC.ACDV"= ACDV.dll

              [HKEY_LOCAL_MACHINE\software\microsoft\security center]
              "AntiVirusDisableNotify"=dword:00000001

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
              "DisableMonitoring"=dword:00000001

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
              "DisableMonitoring"=dword:00000001

              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
              "DisableMonitoring"=dword:00000001

              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
              "%windir%\\system32\\sessmgr.exe"=
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
              "C:\\Program Files\\iTunes\\iTunes.exe"=
              "C:\\Documents and Settings\\****\\kji.exe"=

              R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-02-05 85888]
              R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
              R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
              R2 BCMNTIO;BCMNTIO;C:\PROGRA~1\CheckIt\DIAGNO~1\BCMNTIO.sys [2004-03-18 3744]
              R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 69632]
              R2 MAPMEM;MAPMEM;C:\PROGRA~1\CheckIt\DIAGNO~1\MAPMEM.sys [2004-03-18 3904]

              *Newly Created Service* - INT15.SYS
              .

              **************************************************************************

              catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-09-23 17:00:11
              Windows 5.1.2600 Service Pack 3 NTFS

              Recherche de processus cachés ...

              Recherche d'éléments en démarrage automatique cachés ...

              Recherche de fichiers cachés ...

              Scan terminé avec succès
              Fichiers cachés: 0

              **************************************************************************
              .
              Heure de fin: 2008-09-23 17:01:43
              ComboFix-quarantined-files.txt 2008-09-23 15:01:35
              ComboFix2.txt 2008-09-23 12:47:13

              Avant-CF: 66ÿ487ÿ275ÿ520 octets libres
              Après-CF: 66,478,243,840 octets libres

              143 --- E O F --- 2008-09-10 12:21:21

              Et voilà le Hijackthis :

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 17:03:24, on 23/09/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16705)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
              C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
              C:\Acer\Empowering Technology\eRecovery\Monitor.exe
              C:\Program Files\Acer\Acer eMode Management\AspireService.exe
              C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
              C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
              C:\WINDOWS\system32\PSIService.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\iPod\bin\iPodService.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\HPZipm12.exe
              C:\WINDOWS\explorer.exe
              C:\Program Files\Trend Micro\HijackThis\HJT.exe

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.acer.com/worldwide/selection.html
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
              O4 - HKLM\..\Run: [LaunchApp] Alaunch
              O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
              O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
              O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
              O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
              O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
              O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
              O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
              O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
              O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
              O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
              O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
              O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - https://support.norton.com/sp/en/us/home/current/info
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
              O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
              O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
              O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
              O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe (file missing)
              O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
              O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
              0
              1. Ah, je précise qu'il n'y a pas eu de redémarrage.
                0
                1. Un autre truc que je tiens à préciser : Maintenant, Windows m'envoie des fenêtres d'avertissement chaque fois que j'essaie de me connecter sur hotmail ou gmail, comme quoi la connexion n'est pas sécurisée.

                  En fait, il m'envoie d'abord une fenêtre qui dit les données vont être encryptées pour plus de sûreté, et ensuite une fenêtre qui me dit que non, en fait, la page ne sera pas sécurisée et que les informations pourront être lues par des tiers.

                  Pas bon pour ma parano, ça !
                  0
                  1. OK, J'ai tout fait comme tu as dit.

                    Le positif :

                    - l'Outlook semble marcher normalement, je n'ai plus de messages d'erreur comme quoi mon adresse a envoyé 600 spams cette nuit.

                    - Comme je le disais précédemment, mon fond d'écran et ses fonctionnalités sont redevenus normaux.

                    Les problèmes qui restent :

                    - ces fenêtres de Windows qui s'ouvrent chaque fois que je vais sur hotmail ou gmail. D'abord une fenêtre qui me dit que les informations vont être encryptées (ou "chiffrées"), puis une autre (après que j'aie tapé mon pseudo et mon mdp) qui me dit que la page n'est pas sécurisée et que tout ce que j'y poste est visible par tout un chacun.

                    - mon pourvoyeur habituel de mail, Orange pour ne pas le nommer, m'a envoyé un mail suite aux envois de spams depuis mon adresse. Ils me demandent d'aller sur une adresse qui commence par http://r.orange.fr/ pour s'assurer que je ne suis pas un vilain voyou infesté de spams.

                    Je ne demande qu'à les rassurer, mais bon... Vu toutes les saletés que j'ai récupéré dans mes mails ces jours-ci...

                    C'était envoyé par "abuse@orange.fr", mais ce "r.orange" m'inquiète. Je me suis demandé si c'était pas du phishing. J'ai appellé Orange cette après-midi pour être sûr que c'était du vrai de vrai, mais bon, ils m'ont renvoyé sur un répondeur où j'ai laissé un message qui ne recevra probablement pas de réponse avant un bail.

                    Mais bon, l'histoire d'Orange, c'est pas le plus important. C'est davantage l'histoire des fenêtres de Windows qui s'ouvrent quand je vais sur hotmail ou gmail qui m'inquiètent.

                    Ca va beaucoup mieux, mais je préfère être débarassé de tous ces petits problèmes avant de cocher la case "résolu".

                    Ah, j'oubliais, vu qu'Avast m'a plutôt déçu sur ce coup-là, j'aimerais bien savoir s'il se désinstalle facilement. Dois-je créer un nouveau sujet pour ça, ou bien peut-on continuer sur ce fil de discussion ? Je pense à me payer tout simplement un BitDefender, je l'avais pris il y a un an ou deux et j'en ai de bons souvenirs... Bien meilleurs que de cette enflure de Norton qui ralentit le bouzin comme c'est pas possible.
                    0
                    1. Ah j'oubliais, oui, le pare est activé.
                      0
                      1. Désolé de ne pas avoir répondu plus tôt, j'ai eu à faire ailleurs, comme dit Max.

                        J'ai désinstallé avast, supprimé les bouts qui restaient, exécuté plusieurs fois CCleaner, puis j'ai installé BitDefender.

                        Je crois que je n'ai plus de problèmes viraux, même si certaines choses me paraissent bizarres : ma souris double-clique parfois alors que j'ai juste cliqué, lorsque j'utilise la molette de la souris sur des textes (dans Word, par exemple), l'affichage des textes est perturbé (la même ligne apparaît dix fois de suite à l'écran)...

                        C'est peut-être les effets secondaires de BitDefender ?

                        JW
                        0
                        1. Contributeur sécurité
                          Salut !!

                          Fais un rapport hijackthis pour que je puisse vérifier les infections de ton pc stp

                          ▶ Télécharge hijackthis à cette adresse, tout est expliqué pour bien l installer et pour savoir s'en servir :

                          https://www.androidworld.fr/

                          Comment copier/coller le rapport :

                          Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

                          ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.

                          Une explication des raccourcis clavier sont illustrés sur mon site web à cette adresse :

                          https://www.androidworld.fr/
                          -1
                          1. Contributeur sécurité
                            Bonjour

                            Télécharge le fichier d’installation d’Hijackthis en cliquant sur ce lien

                            http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

                            Enregistre HJTInstall.exe sur ton bureau.

                            Double-clique sur HJTInstall.exe pour lancer le programme

                            Tuto : https://www.malekal.com/tutoriel-hijackthis/
                            http://pageperso.aol.fr/balltrap34/Hijenr.gif

                            Accepte la license en cliquant sur le bouton "I Accept"
                            Choisis l'option "Do a system scan and save a log file"
                            Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
                            Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

                            Colle le rapport que tu viens de copier sur ce forum
                            -1
                            1. Contributeur sécurité
                              ok...commence par faire ceci stp :

                              ▶ Télécharge combofix (par sUBs) à cette adresse :

                              (c est le numéro 5 en bas de la page) : https://www.androidworld.fr/

                              ▶ et enregistre le sur le Bureau.

                              ▶ désactive tes protections et ferme toutes tes applications(antivirus, parefeu, garde en temps réel de l'antispyware)

                              Voici le tutoriel officiel de Bleeping Computer pour savoir l utiliser :

                              https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                              ensuite envois le rapport et refais un nouveau rapport hijackthis stp
                              -1
                              1. Contributeur sécurité
                                Oui c est normal ;-)

                                J attends ton rapport
                                -1
                                1. Contributeur sécurité
                                  lol ok pas grave.

                                  ▶ Copie le texte ci-dessous :

                                  File::
                                  c:\program files\save\save.exe
                                  c:\documents and settings\****\local settings\temp\.tt63.tmp.exe

                                  Folder::

                                  Registry::


                                  ▶ Ouvre le Bloc-Notes puis colle le texte copié.
                                  (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
                                  ▶ Sauvegarde ce fichier sous le nom de CFScript.txt.

                                  ▶ Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

                                  http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

                                  ▶ Cela va relancer Combofix,

                                  ▶ Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                                  ▶ Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                                  Ne touche à rien tant que le scan n'est pas terminé.

                                  ▶ Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

                                  ▶ S'il n'y a pas de rédémarrage, poste quand même les rapports.

                                  ensuite refais un nouveau rapport hijackthis stp
                                  -1
                                  1. Contributeur sécurité
                                    relance hijackthis en cliquant sur scan only et coches ces lignes stp :

                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab

                                    puis tu cliques sur fix checked.

                                    il reste des traces de norton dans ton pc...exécute ce logiciel pour les éliminer stp :

                                    norton removal tools : http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

                                    est ce que ton pare est activé ??

                                    et est ce que tu as encore des problemes ??
                                    -1
                                    1. Contributeur sécurité
                                      pour tes messages d erreur je ne vois vraiment pas ce que ca pourrait etre...

                                      Si il t as donné un lien orange tu n as pas à te tracasser, ce n est pas un employé de chez orange qui va infecter ton PC...

                                      Si tu veux changer d antivirus, je te propose de désinstaller avast proprement dans ajout/suppression de programmes.

                                      ensuite fais une recherche de ton pc en tapant avast et supprime tout ce qu il trouvera.

                                      vide ta corbeille, redémarre ton PC et ensuite tu peux télécharger Antivir qui est très performant..

                                      Un tutoriel sera à ta disposition sur le site.

                                      est ce que tu as d autres problèmes viraux ??
                                      -1
                                      1. Contributeur sécurité
                                        Salut !!

                                        pour le double-clic de ta souris, c est peut etre elle qui a un problème..

                                        et pour ton problème d affichage des textes, peut etre que tu veux descendre trop vite d un coup, je ne sais pas...

                                        Bitdefender est en effet très gourmand en ressource...je l ai testé avant d acheter kaspersky 2009 et j ai vite désinstallé. Je parie que tu as aussi un problème au démarrage avec un écran bleu et des petits points qui s affichent lentement..lol

                                        si tu n as plus de problemes tu peux faire ceci pour terminer stp :

                                        Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

                                        ▶ Télécharge Toolscleaner sur ton Bureau :

                                        (c est le numéro 15 en bas de la page)

                                        ▶ Double-clique sur ToolsCleaner2.exe et laisse le travailler
                                        ▶ Clique sur Recherche et laisse le scan se terminer.
                                        ▶ Clique sur Suppression pour finaliser.
                                        ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
                                        ▶ Clique sur Quitter, pour que le rapport puisse se créer.
                                        ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

                                        Désactive et réactive la Restauration du système :

                                        1 Dans la barre des tâches de Windows, clique sur Démarrer.

                                        2 Clique avec le bouton droit de la souris sur Poste de travail puis clique sur Propriétés.

                                        3 Dans l'onglet Restauration du système, coche "Désactiver la Restauration du système"

                                        4 Clique sur Appliquer.

                                        5 Ensuite décoche "Désactiver la restauration du systeme"

                                        6 clique sur appliquer puis ok

                                        7 vas créer un point de restauration en cliquant sur démarrer => tous les programmes => accessoires =>

                                        outils systeme => restauration du systeme => créer un point de restauration => tu mets un nom

                                        (exemple : après désinfection sur CCM) puis tu valides.

                                        PS : les liens de toolscleaner, etc... C est mon site web si ca peut t aider ;-)
                                        -1