Infection hldrrr.exe et srosa.sys

Bonjour,
Suite à l'ouverture d'un fichier téléchargé sur un logiciel pair-à-pair mon ordinateur s'est trouvé infecté à la fois par srosa.sys et hldrrr.exe. D'après ce que j'ai pu voir dans mes recherches, il y aurait au moins du B(e)agle dans le coin...
Je n'ai pas l'habitude de traiter ce genre de problème voilà pourquoi je sollicite votre aide.
Mon antivirus est avast, c'est lui qui m'a alerté, mais malgré plusieurs scans au démarrage, et tentative de suppression et/ou de mise en quarantaine, mon ordinateur est toujours infecté, et donc je retombe sur les mêmes alertes d'avast.
Je constate comme d'autres qui sont passé par là avant moi que le processus hldrrr.exe monopolise le processeur. Alors parfois j'arrive à le supprimer du gestionnaire des tâches, mais des fois non :/
Bref, je tourne en rond, et comme je n'ai pas trouvé de sujet traitant de mes deux infections simultanément, je préfère exposer ma propre situation.
Dois-je également utiliser Eliblaga et Hijack this?
Je vous laisse, je dois aller en cours....
Donc à cet après-midi!

Merci d'avance.
tikkhai.
Configuration: Windows XP
Firefox 3.0.3
Dell optiplex GX 280

25 réponses

Résumé de la discussion

Un signalement décrit une infection concomitante par srosa.sys et hldrrr.exe après l’ouverture d’un fichier téléchargé via un logiciel pair-à-pair, avec une utilisation élevée du processeur et des alertes Avast. Plusieurs réponses proposent des outils et méthodes, notamment ToolsCleaner et HijackThis, pour nettoyer les traces, générer des rapports et identifier des éléments à éliminer. Des rapports de sécurité évoquent des menaces telles que Trojan/Bagle et des éléments récalcitrants, tandis que des tests avec BitDefender Online Scanner et HijackThis alimentent le diagnostic. En cas de mise à jour manquante et de configuration navigateur variée, la discussion suggère des rapports à remettre et des nettoyages successifs, sans conclure sur une résolution immédiate.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    tant que tu n'auras pas résolu ton problème de mise à jour, tu seras plus vulnérable que la moyenne.

    Nettoyage des outils.

    * Télécharge ToolsCleaner par A.Rothstein & dj QUIOU sur ton Bureau.

    http://pc-system.fr/
    hxxp://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
    hxxp://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe

    * Clique sur Recherche et laisse le scan se terminer.

    * Clique, sur Suppression pour finaliser.

    * Tu peux, si tu le souhaites, te servir des Options facultatives.

    * Clique sur Quitter, pour que le rapport puisse se créer.

    * Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).
    1
    1. Contributeur sécurité
      Bonjour,

      supprime d'abord ton crack, sinon il réinfectera l'ordi.

      Ensuite :

      avec Internet explorer

      télécharge combofix (par sUBs) ici :

      http://download.bleepingcomputer.com/sUBs/ComboFix.exe

      et enregistre le sur le Bureau sous le nom Réparer.exe (change le nom avant qu'il soit enregistré, d'où l'utilisation de IE) .

      déconnecte toi d'internet et ferme toutes tes applications.

      désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

      double-clique sur combofix.exe (en fait Réparer
      .exe) et suis les instructions

      à la fin, il va produire un rapport C:\ComboFix.txt

      réactive ton parefeu, ton antivirus, la garde de ton antispyware

      copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

      Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

      Tu as un tutoriel complet ici :

      https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
      0
      1. ok, je m'y colle,
        merci de ta réponse Lyonnais92.
        0
        1. Voici ComboFix.txt

          ComboFix 08-10-01.02 - TK 2008-10-02 15:48:58.1 - NTFSx86
          Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.233 [GMT 2:00]

          [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
          .

          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
          .

          C:\InfoSat.txt
          C:\WINDOWS\system32\drivers\downld
          C:\WINDOWS\system32\drivers\downld\116000.exe
          C:\WINDOWS\system32\drivers\downld\117343.exe
          C:\WINDOWS\system32\drivers\downld\138390.exe
          C:\WINDOWS\system32\drivers\downld\140031.exe
          C:\WINDOWS\system32\drivers\downld\16557562.exe
          C:\WINDOWS\system32\drivers\downld\16558875.exe
          C:\WINDOWS\system32\drivers\downld\180359.exe
          C:\WINDOWS\system32\drivers\downld\191093.exe
          C:\WINDOWS\system32\drivers\downld\192312.exe
          C:\WINDOWS\system32\drivers\downld\193062.exe
          C:\WINDOWS\system32\drivers\downld\195078.exe
          C:\WINDOWS\system32\drivers\downld\232468.exe
          C:\WINDOWS\system32\drivers\downld\249562.exe
          C:\WINDOWS\system32\drivers\downld\256984.exe
          C:\WINDOWS\system32\drivers\downld\321890.exe
          C:\WINDOWS\system32\drivers\downld\325125.exe
          C:\WINDOWS\system32\drivers\downld\343593.exe
          C:\WINDOWS\system32\drivers\downld\367187.exe
          C:\WINDOWS\system32\drivers\downld\4353000.exe
          C:\WINDOWS\system32\drivers\downld\4354484.exe
          C:\WINDOWS\system32\drivers\downld\4368875.exe
          C:\WINDOWS\system32\drivers\downld\4404312.exe
          C:\WINDOWS\system32\drivers\downld\4407031.exe
          C:\WINDOWS\system32\drivers\downld\445937.exe
          C:\WINDOWS\system32\drivers\downld\448062.exe
          C:\WINDOWS\system32\drivers\downld\95203.exe
          C:\WINDOWS\system32\drivers\downld\97484.exe
          C:\WINDOWS\system32\drivers\downld\98671.exe
          C:\WINDOWS\system32\drivers\hldrrr.exe
          C:\WINDOWS\system32\drivers\srosa.sys
          C:\WINDOWS\system32\nvs2.inf

          .
          ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-02 au 2008-10-02 ))))))))))))))))))))))))))))))))))))
          .

          2008-10-02 01:07 . 2008-10-02 01:07 <REP> d-------- C:\Program Files\Trend Micro
          2008-10-02 00:27 . 2008-10-02 00:27 <REP> d-------- C:\Muestras
          2008-10-01 22:26 . 2008-10-02 00:08 <REP> d-------- C:\!KillBox
          2008-10-01 19:21 . 2008-10-01 19:21 <REP> d-------- C:\WINDOWS\PrimoPDF4
          2008-10-01 19:21 . 2006-12-11 22:12 176,235 --a------ C:\WINDOWS\system32\Primomonnt.dll
          2008-09-21 21:56 . 2008-09-21 21:56 <REP> d-------- C:\Program Files\AlexSoft
          2008-09-12 23:31 . 2008-09-13 22:26 <REP> d-------- C:\Documents and Settings\TK\iWizz

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-10-02 13:30 --------- d-----w C:\Program Files\FlashGet
          2008-10-01 17:57 --------- d-----w C:\Program Files\eMule
          2008-09-25 16:53 --------- d-----w C:\Documents and Settings\TK\Application Data\LimeWire
          2008-09-09 14:55 --------- d-----w C:\Program Files\Winamp
          2008-09-01 11:00 --------- d-----w C:\Documents and Settings\TK\Application Data\DataCast
          2008-09-01 10:59 --------- d-----w C:\Program Files\Samsung
          2008-09-01 10:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
          2008-09-01 10:30 65,024 ----a-w C:\WINDOWS\IFinst26.exe
          2008-09-01 10:30 --------- d-----w C:\Program Files\Xvid
          2008-09-01 10:30 --------- d-----w C:\Program Files\Lame MP3 Codec
          2008-09-01 10:28 --------- d-----w C:\Program Files\MarkAny
          2008-08-29 18:00 --------- d-----w C:\Program Files\Zylom Games
          2008-08-20 18:16 --------- d-----w C:\Program Files\EyeToyPC
          2008-08-20 18:13 1,118,064 ----a-w C:\Program Files\EyeToyPC.zip
          2008-08-19 22:10 --------- d-----w C:\Program Files\LimeWire
          2008-08-19 22:06 4,898,520 ----a-w C:\Program Files\LimeWireWin.exe
          2008-08-19 20:43 --------- d-----w C:\Program Files\CCleaner
          2008-08-13 10:13 --------- d-----w C:\Program Files\RegCleaner
          2008-08-12 23:20 --------- d-----w C:\Documents and Settings\TK\Application Data\Skype
          2008-08-12 23:17 --------- d-----w C:\Documents and Settings\TK\Application Data\skypePM
          2008-08-09 21:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\Zylom
          2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
          2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
          2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
          2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
          2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
          2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
          2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
          2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
          2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
          2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
          2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
          2008-04-14 15:49 318,904 -c--a-w C:\Program Files\wmpfirefoxplugin.exe
          2008-04-11 14:46 27,994 ----a-w C:\Documents and Settings\TK\XMLA-TD8.zip
          2008-01-12 18:03 38,672 -c--a-w C:\Documents and Settings\TK\Application Data\GDIPFONTCACHEV1.DAT
          2007-09-01 01:18 2,523,342 -c--a-w C:\Program Files\inkredist(www.mess.be).zip
          2007-08-30 21:11 20 -c-h--w C:\Documents and Settings\All Users\Application Data\PKP_DLec.DAT
          2007-02-08 21:20 113,455 -c--a-w C:\Program Files\INSTALL.LOG
          2006-05-03 10:06 163,328 --sh--r C:\WINDOWS\system32\flvDX.dll
          2007-02-21 11:47 31,232 -csh--r C:\WINDOWS\system32\msfDX.dll
          2007-12-17 13:43 27,648 -csh--w C:\WINDOWS\system32\Smab0.dll
          .

          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 15360]
          "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-10-02 851976]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
          "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-19 160768]
          "igfxpers"="C:\WINDOWS\System32\igfxpers.exe" [2005-09-20 114688]
          "igfxhkcmd"="C:\WINDOWS\System32\hkcmd.exe" [2005-09-20 77824]
          "igfxtray"="C:\WINDOWS\System32\igfxtray.exe" [2005-09-20 94208]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 15360]
          "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-11-09 1634304]

          [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
          "{88485281-8b4b-4f8d-9ede-82e29a064277}"= "C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL" [2004-11-23 192512]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
          "VIDC.I420"= i420vfw.dll
          "VIDC.VP40"= vp4vfw.dll
          "vidc.yv12"= yv12vfw.dll

          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
          path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
          backup=C:\WINDOWS\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
          path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
          backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
          --a------ 2005-09-25 20:11 94208 C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
          --a------ 2004-08-19 17:09 15360 C:\WINDOWS\system32\ctfmon.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
          --a------ 2004-08-03 23:32 208952 C:\WINDOWS\ime\imjp8_1\imjpmig.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
          --a------ 2008-01-15 04:22 267048 C:\Program Files\iTunes\iTunesHelper.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSPY2002]
          --a------ 2002-08-28 23:39 59392 C:\WINDOWS\system32\IME\PINTLGNT\IMSCINST.EXE

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
          --a--c--- 2005-09-25 20:11 155648 C:\WINDOWS\system32\NeroCheck.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCSuiteTrayApplication]
          --a--c--- 2006-11-08 14:27 222208 C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
          --a------ 2002-08-28 23:39 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
          --a------ 2002-08-28 23:39 455168 C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
          --a------ 2008-01-10 16:27 385024 C:\Program Files\QuickTime\QTTask.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
          --a------ 2008-02-22 05:25 144784 C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
          --a------ 2006-11-01 16:40 185896 C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "C:\\Program Files\\LimeWire\\LimeWire.exe"=
          "C:\\Program Files\\iTunes\\iTunes.exe"=
          "C:\\Program Files\\eMule\\emule.exe"=
          "C:\\Program Files\\BitLord\\BitLord.exe"=
          "C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
          "C:\\Program Files\\Xming\\Xming.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
          "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
          "C:\\Program Files\\SFR\\SFR Connexion\\SFR Connexion.exe"=
          "C:\\Program Files\\Messenger\\msmsgs.exe"=
          "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
          "C:\\WINDOWS\\system32\\muzapp.exe"=

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
          "3389:TCP"= 3389:TCP:196.254.236.21/255.255.255.255:Disabled:@xpsp2res.dll,-22009

          R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416]
          R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560]
          R3 sfr0901;SFR Connexion Adapter V9;C:\WINDOWS\system32\DRIVERS\sfr0901.sys [2007-08-08 26496]
          S3 libusb0;LibUsb-Win32 - Kernel Driver 11/20/2005, 20051120;C:\WINDOWS\system32\DRIVERS\libusb0.sys [2006-05-31 29184]

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
          \Shell\AutoRun\command - G:\LaunchU3.exe -a
          .
          Contenu du dossier 'Tâches planifiées'
          .
          - - - - ORPHELINS SUPPRIMES - - - -

          MSConfigStartUp-drvsyskit - C:\WINDOWS\system32\drivers\hldrrr.exe
          MSConfigStartUp-Steam - D:\Documents TK\_MAI-LINH\CS\Valve\Steam.exe
          MSConfigStartUp-Veoh - C:\Program Files\Veoh Networks\Veoh\VeohClient.exe

          .
          ------- Examen supplémentaire -------
          .
          FireFox -: Profile - C:\Documents and Settings\TK\Application Data\Mozilla\Firefox\Profiles\o8kxt6q6.default\
          FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.google.fr/
          FF -: plugin - C:\Documents and Settings\All Users\Application Data\Zylom\ZylomGamesPlayer\npzylomgamesplayer.dll
          FF -: plugin - C:\Documents and Settings\TK\Application Data\VideoEgg\Loader\4665\npvideoegg-loader.dll
          FF -: plugin - C:\Program Files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
          FF -: plugin - C:\Program Files\DivX\DivX Content Uploader\npUpload.dll
          FF -: plugin - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
          .

          **************************************************************************

          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-10-02 15:51:10
          Windows 5.1.2600 Service Pack 2 NTFS

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          Recherche de fichiers cachés ...

          Scan terminé avec succès
          Fichiers cachés: 0

          **************************************************************************

          [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\srosa]

          .
          Heure de fin: 2008-10-02 15:55:09
          ComboFix-quarantined-files.txt 2008-10-02 13:55:05

          Avant-CF: 320,212,992 octets libres
          Après-CF: 253,116,416 octets libres

          203 --- E O F --- 2008-09-11 11:06:46
          0
          1. Contributeur sécurité
            Re,

            réinstalle ton antivirus.

            Clique sur ce lien
            http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
            pour télécharger le fichier d'installation d'HijackThis.

            Enregistre HJTInstall.exe sur ton bureau.

            Double-clique sur HJTInstall.exe pour lancer le programme

            Par défaut, il s'installera là :
            C:\Program Files\Trend Micro\HijackThis

            Accepte la license en cliquant sur le bouton "I Accept"

            Choisis l'option "Do a system scan and save a log file"

            Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

            Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

            Colle le rapport que tu viens de copier sur ce forum

            Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

            Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
            http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm
            0
            1. Contributeur sécurité
              Re,

              réinstalle ton antivirus.

              Clique sur ce lien
              http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe
              pour télécharger le fichier d'installation d'HijackThis.

              Enregistre HJTInstall.exe sur ton bureau.

              Double-clique sur HJTInstall.exe pour lancer le programme

              Par défaut, il s'installera là :
              C:\Program Files\Trend Micro\HijackThis

              Accepte la license en cliquant sur le bouton "I Accept"

              Choisis l'option "Do a system scan and save a log file"

              Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note

              Clique sur "Edition -> Sélectionner tout", puis sur "Edition -> Copier" pour copier tout le contenu du rapport

              Colle le rapport que tu viens de copier sur ce forum

              Ne fixe encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement

              Tutoriaux : http://pageperso.aol.fr/balltrap34/demohijack.htm (ne fixe rien pour le moment !!)
              http://cybersecurite.xooit.com/t138-HijackThis-2-0-2.htm
              0
              1. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 18:28:29, on 02/10/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\System32\igfxpers.exe
                C:\WINDOWS\System32\hkcmd.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                C:\Program Files\Mozilla Firefox\firefox.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/offres-numericable.html
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: Flashget Catch Url Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
                O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
                O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
                O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
                O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
                O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
                O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
                O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
                O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
                O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
                O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-18989689f1e8de06.spaces.live.com/PhotoUpload/MsnPUpld.cab
                O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
                0
                1. Contributeur sécurité
                  Re,

                  on a bien progressé. L'infection bagle semble jugulée.

                  Par contre, il y a d'autres infections.

                  Télécharge Toolbar-S&D (Team IDN) sur ton Bureau :

                  https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                  * Lance l'installation du programme en exécutant le fichier téléchargé.
                  * Double-clique maintenant sur le raccourci de Toolbar-S&D.
                  * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                  * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                  * Poste le rapport généré. (C:\TB.txt)
                  0
                  1. -----------\\ ToolBar S&D 1.2.1 XP/Vista

                    Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
                    X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.80GHz )
                    BIOS : Phoenix ROM BIOS PLUS Version 1.10 A03
                    USER : TK ( Administrator )
                    BOOT : Normal boot
                    Antivirus : avast! antivirus 4.8.1229 [VPS 081002-0] 4.8.1229 (Activated)
                    A:\ (USB)
                    C:\ (Local Disk) - NTFS - Total : 9 Go Free : 0 Go
                    D:\ (Local Disk) - NTFS - Total : 32 Go Free : 0 Go
                    E:\ (Local Disk) - NTFS - Total : 32 Go Free : 0 Go
                    F:\ (CD or DVD) - CDFS - Total : 0 Go Free : 0 Go

                    "C:\ToolBar SD" ( MAJ : 24-09-2008|21:50 )
                    Option : [1] ( 02/10/2008|19:16 )

                    -----------\\ Recherche de Fichiers / Dossiers ...

                    C:\Program Files\BitLord
                    C:\Program Files\BitLord\BitLord.exe
                    C:\Program Files\BitLord\BitLord.url
                    C:\Program Files\BitLord\BitLord.xml
                    C:\Program Files\BitLord\Downloads
                    C:\Program Files\BitLord\Downloads.xml
                    C:\Program Files\BitLord\lang
                    C:\Program Files\BitLord\License.txt
                    C:\Program Files\BitLord\rules
                    C:\Program Files\BitLord\Torrents
                    C:\Program Files\BitLord\uninst.exe
                    C:\DOCUME~1\TK\Bureau\BitLord.lnk
                    C:\DOCUME~1\TK\MENUDM~1\PROGRA~1\BitLord

                    -----------\\ Extensions

                    (TK) - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} => flashgot
                    (TK) - {71328583-3CA7-4809-B4BA-570A85818FBB} => cacheviewer
                    (TK) - {c45c406e-ab73-11d8-be73-000a95be3b12} => webdeveloper

                    -----------\\ [..\Internet Explorer\Main]

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    "Start Page"="https://www.sfr.fr/offres-numericable.html"
                    "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                    "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

                    --------------------\\ Recherche d'autres infections

                    C:\DOCUME~1\TK\LOCALS~1\APPLIC~1\cufbggrs_navfx.dat
                    C:\DOCUME~1\TK\LOCALS~1\APPLIC~1\kufilj_navfx.dat
                    C:\DOCUME~1\TK\LOCALS~1\APPLIC~1\mqyao.dat
                    C:\DOCUME~1\TK\LOCALS~1\APPLIC~1\mqyao_nav.dat
                    C:\DOCUME~1\TK\LOCALS~1\APPLIC~1\mqyao_navps.dat
                    [b]==> EGDACCESS <==/b

                    1 - "C:\ToolBar SD\TB_1.txt" - 02/10/2008|19:17 - Option : [1]

                    -----------\\ Fin du rapport a 19:17:24,71
                    0
                    1. Contributeur sécurité
                      Re,

                      Ouvre Spybot search and destroy.

                      clique sur mode, choisis advanced mode;

                      dans la colonne de gauche clique sur le + devant tools.

                      clique sur résident (colonne de gauche)

                      dans la fenêtre de droite décoche la case devant "resident tea-timer"
                      __________

                      Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
                      ! Ne ferme pas la fenêtre lors de la suppression !
                      Un rapport sera généré, poste son contenu ici.

                      ___________
                      http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
                      pour télécharger navilog1.exe.

                      Choisis Enregistrer

                      et enregistre-le sur ton bureau.

                      Ensuite double clique sur navilog1.exe pour lancer l'installation.
                      Une fois l'installation terminée, le fix s'exécutera automatiquement.
                      (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

                      Laisse-toi guider. Au menu principal, choisis 1 et valides.
                      (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

                      Patiente jusqu'au message :
                      *** Analyse Termine le ..... ***
                      Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
                      Copie-colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
                      Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
                      0
                      1. TB.txt:
                        -----------\\ ToolBar S&D 1.2.1 XP/Vista

                        Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
                        X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) 4 CPU 2.80GHz )
                        BIOS : Phoenix ROM BIOS PLUS Version 1.10 A03
                        USER : TK ( Administrator )
                        BOOT : Normal boot
                        Antivirus : avast! antivirus 4.8.1229 [VPS 081002-0] 4.8.1229 (Activated)
                        A:\ (USB)
                        C:\ (Local Disk) - NTFS - Total : 9 Go Free : 0 Go
                        D:\ (Local Disk) - NTFS - Total : 32 Go Free : 0 Go
                        E:\ (Local Disk) - NTFS - Total : 32 Go Free : 0 Go
                        F:\ (CD or DVD) - CDFS - Total : 0 Go Free : 0 Go

                        "C:\ToolBar SD" ( MAJ : 24-09-2008|21:50 )
                        Option : [2] ( 02/10/2008|20:37 )

                        -----------\\ SUPPRESSION

                        Supprime! - C:\Program Files\BitLord\BitLord.exe
                        Supprime! - C:\Program Files\BitLord\BitLord.url
                        Supprime! - C:\Program Files\BitLord\BitLord.xml
                        Supprime! - C:\Program Files\BitLord\Downloads
                        Supprime! - C:\Program Files\BitLord\Downloads.xml
                        Supprime! - C:\Program Files\BitLord\lang
                        Supprime! - C:\Program Files\BitLord\License.txt
                        Supprime! - C:\Program Files\BitLord\rules
                        Supprime! - C:\Program Files\BitLord\Torrents
                        Supprime! - C:\Program Files\BitLord\uninst.exe
                        Supprime! - C:\DOCUME~1\TK\Bureau\BitLord.lnk
                        Supprime! - C:\DOCUME~1\TK\MENUDM~1\PROGRA~1\BitLord
                        Supprime! - C:\Program Files\BitLord

                        -----------\\ Recherche de Fichiers / Dossiers ...

                        -----------\\ Extensions

                        (TK) - {19503e42-ca3c-4c27-b1e2-9cdb2170ee34} => flashgot
                        (TK) - {71328583-3CA7-4809-B4BA-570A85818FBB} => cacheviewer
                        (TK) - {c45c406e-ab73-11d8-be73-000a95be3b12} => webdeveloper

                        -----------\\ [..\Internet Explorer\Main]

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                        "Start Page"="https://www.sfr.fr/offres-numericable.html"
                        "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                        "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                        "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                        "Start Page"="https://www.msn.com/fr-fr/"

                        --------------------\\ Recherche d'autres infections

                        C:\DOCUME~1\TK\LOCALS~1\APPLIC~1\cufbggrs_navfx.dat
                        C:\DOCUME~1\TK\LOCALS~1\APPLIC~1\kufilj_navfx.dat
                        C:\DOCUME~1\TK\LOCALS~1\APPLIC~1\mqyao.dat
                        C:\DOCUME~1\TK\LOCALS~1\APPLIC~1\mqyao_nav.dat
                        C:\DOCUME~1\TK\LOCALS~1\APPLIC~1\mqyao_navps.dat
                        [b]==> EGDACCESS <==/b

                        1 - "C:\ToolBar SD\TB_1.txt" - 02/10/2008|19:17 - Option : [1]
                        2 - "C:\ToolBar SD\TB_2.txt" - 02/10/2008|20:39 - Option : [2]

                        -----------\\ Fin du rapport a 20:39:14,51
                        0
                      2. @tikkhaiSearch Navipromo version 3.6.6 commencé le 02/10/2008 à 20:45:43,79

                        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                        !!! Postez ce rapport sur le forum pour le faire analyser !!!
                        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                        Outil exécuté depuis C:\Program Files\navilog1
                        Session actuelle : "TK"

                        Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

                        Microsoft Windows XP [version 5.1.2600]
                        Internet Explorer : 6.0.2900.2180
                        Système de fichiers : NTFS

                        Recherche executé en mode normal

                        *** Recherche Programmes installés ***

                        *** Recherche dossiers dans "C:\WINDOWS" ***

                        *** Recherche dossiers dans "C:\Program Files" ***

                        *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                        *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                        *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                        *** Recherche dossiers dans "C:\Documents and Settings\TK\applic~1" ***

                        *** Recherche dossiers dans "C:\Documents and Settings\TK\locals~1\applic~1" ***

                        *** Recherche dossiers dans "C:\Documents and Settings\TK\menudm~1\progra~1" ***

                        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                        pour + d'infos : http://www.gmer.net

                        *** Recherche avec GenericNaviSearch ***
                        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                        !!! A vérifier impérativement avant toute suppression manuelle !!!

                        * Recherche dans "C:\WINDOWS\system32" *

                        * Recherche dans "C:\Documents and Settings\TK\locals~1\applic~1" *

                        Fichiers suspects :

                        gcess.exe trouvé !

                        *** Recherche fichiers ***

                        *** Recherche clés spécifiques dans le Registre ***

                        *** Module de Recherche complémentaire ***
                        (Recherche fichiers spécifiques)

                        1)Recherche nouveaux fichiers Instant Access :

                        2)Recherche Heuristique :

                        * Dans "C:\WINDOWS\system32" :

                        * Dans "C:\Documents and Settings\TK\locals~1\applic~1" :

                        cufbggrs_navfx.dat trouvé !
                        kufilj_navfx.dat trouvé !
                        mqyao.dat trouvé !
                        mqyao_nav.dat trouvé !
                        mqyao_navps.dat trouvé !

                        3)Recherche Certificats :

                        Certificat Egroup absent !
                        Certificat Electronic-Group trouvé !
                        Certificat Montorgueil absent !
                        Certificat OOO-Favorit trouvé !
                        Certificat Sunny-Day-Design-Ltd absent !

                        4)Recherche fichiers connus :

                        *** Analyse terminée le 02/10/2008 à 20:49:47,26 ***
                        0
                    2. Re re,
                      (lol)
                      en fait, de Spybot je n'ai que TeaTimer.exe comme exécutable, et le dossier "Help". Il est possible qu'il s'agisse des restes d'une mauvaise désinstallation de ma part... je t'avoue ne plus m'en rappeler :/

                      Dans ce cas, dois-je sauter l'étape Spybot et suivre tes instructions suivantes?

                      Merci.
                      0
                      1. Parce qu'en fait TeaTimer.exe n'est jamais lancé (ou alors il n'apparaît pas parmi les processus affichés dans le gestionnaire des tâches).
                        Voilà, c'est tout.
                        0
                        1. Ah oui, et si je veux le lancer, ben j'ai le message d'erreur disant que TeaTimer.exe n'est pas une application win32 valide. Donc, je crois que je dois laisser tomber cette étape...? J'attends ta confirmation... merci.
                          0
                          1. Contributeur sécurité
                            Tr,

                            tu fais ça :

                            Relance HijackThis.

                            Choisis Do a scan only

                            Coche la case devant les lignes suivantes

                            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

                            Ferme toutes les fenêtres (hormis HijackThis), y compris ton navigateur.

                            Clique sur fix checked.

                            Ferme Hijackthis

                            Ensuite tu reprends en sautant l'étape du tea-timer
                            0
                            1. Contributeur sécurité
                              Re,

                              OK, on avance.

                              Le rapport de navilog maintenant.
                              0
                              1. Contributeur sécurité
                                Re,

                                Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
                                Au menu principal, choisis 2 et valide.

                                Le fix va t'informer qu'il va alors redémarrer ton PC
                                Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
                                Appuie sur une touche comme demandé.
                                (si ton Pc ne redémarre pas automatiquement, fais le toi même)
                                Au redémarrage de ton PC, choisis ta session habituelle.

                                Patiente jusqu'au message :
                                *** Nettoyage Termine le ..... ***
                                Le blocnote va s'ouvrir.
                                Sauvegarde le rapport de manière à le retrouver
                                Referme le blocnote. Ton bureau va réapparaitre

                                PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
                                Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
                                Tape explorer et valide. Celà te fera apparaitre ton bureau.

                                Fais redémarrer l'ordi.

                                Remets un rapport Hijackthis.
                                0
                                1. Voici donc mon (dernier?) rapport HijackThis:

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 22:42:23, on 02/10/2008
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\WINDOWS\System32\igfxpers.exe
                                  C:\WINDOWS\System32\hkcmd.exe
                                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                                  C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\Program Files\Mozilla Firefox\firefox.exe
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.sfr.fr/offres-numericable.html
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.searchgateway.net/search/%s
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: Flashget Catch Url Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
                                  O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
                                  O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
                                  O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
                                  O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
                                  O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                                  O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
                                  O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                  O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
                                  O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
                                  O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
                                  O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
                                  O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
                                  O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                  O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-18989689f1e8de06.spaces.live.com/PhotoUpload/MsnPUpld.cab
                                  O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
                                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                  O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                                  O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
                                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                  O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                  O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                  O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                                  O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
                                  0
                                2. @tikkhaiEt désolée du retard.
                                  0
                                3. Le raport Navilog:

                                  Clean Navipromo version 3.6.6 commencé le 02/10/2008 à 22:24:29,56

                                  Outil exécuté depuis C:\Program Files\navilog1
                                  Session actuelle : "TK"

                                  Mise à jour le 29.09.2008 à 17h30 par IL-MAFIOSO

                                  Microsoft Windows XP [version 5.1.2600]
                                  Internet Explorer : 6.0.2900.2180
                                  Système de fichiers : NTFS

                                  Mode suppression automatique
                                  avec prise en charge résultats Catchme et GNS

                                  Nettoyage exécuté au redémarrage de l'ordinateur

                                  *** fsbl1.txt non trouvé ***
                                  (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                                  *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                                  * Suppression dans "C:\WINDOWS\System32" *

                                  * Suppression dans "C:\Documents and Settings\TK\locals~1\applic~1" *

                                  *** Suppression dossiers dans "C:\WINDOWS" ***

                                  *** Suppression dossiers dans "C:\Program Files" ***

                                  *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                                  *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                                  *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                                  *** Suppression dossiers dans "C:\Documents and Settings\TK\applic~1" ***

                                  *** Suppression dossiers dans "C:\Documents and Settings\TK\locals~1\applic~1" ***

                                  *** Suppression dossiers dans "C:\Documents and Settings\TK\menudm~1\progra~1" ***

                                  *** Suppression fichiers ***

                                  *** Suppression fichiers temporaires ***

                                  Nettoyage contenu C:\WINDOWS\Temp effectué !
                                  Nettoyage contenu C:\Documents and Settings\TK\locals~1\Temp effectué !

                                  *** Traitement Recherche complémentaire ***
                                  (Recherche fichiers spécifiques)

                                  1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                                  2)Recherche, création sauvegardes et suppression Heuristique :

                                  * Dans "C:\WINDOWS\system32" *

                                  * Dans "C:\Documents and Settings\TK\locals~1\applic~1" *

                                  mqyao.dat trouvé !
                                  Copie mqyao.dat réalisée avec succès !
                                  mqyao.dat supprimé !

                                  mqyao_nav.dat trouvé !
                                  Copie mqyao_nav.dat réalisée avec succès !
                                  mqyao_nav.dat supprimé !

                                  mqyao_navps.dat trouvé !
                                  Copie mqyao_navps.dat réalisée avec succès !
                                  mqyao_navps.dat supprimé !

                                  cufbggrs_navfx.dat trouvé !
                                  Copie cufbggrs_navfx.dat réalisée avec succès !
                                  cufbggrs_navfx.dat supprimé !

                                  kufilj_navfx.dat trouvé !
                                  Copie kufilj_navfx.dat réalisée avec succès !
                                  kufilj_navfx.dat supprimé !

                                  *** Sauvegarde du Registre vers dossier Safebackup ***

                                  sauvegarde du Registre réalisée avec succès !

                                  *** Nettoyage Registre ***

                                  Nettoyage Registre Ok

                                  *** Certificats ***

                                  Certificat Egroup absent !
                                  Certificat Electronic-Group supprimé !
                                  Certificat Montorgueil absent !
                                  Certificat OOO-Favorit supprimé !
                                  Certificat Sunny-Day-Design-Ltdt absent !

                                  *** Fichiers suspects non supprimés par Navilog1 ***
                                  !! Fichiers légitimes possibles, à contrôler avant suppression !!

                                  Fichiers suspects dans "C:\Documents and Settings\TK\locals~1\applic~1" :

                                  gcess.exe trouvé !

                                  *** Nettoyage terminé le 02/10/2008 à 22:28:42,29 ***
                                  0
                              2. Contributeur sécurité
                                Re,

                                pas de problème pour le retard.

                                mais je voudrais le rapport Navilog (cleannavi.txt)
                                0
                                1. Contributeur sécurité
                                  Re,

                                  un fichier à contrôler :

                                  Rends toi sur ce site :

                                  https://www.virustotal.com/gui/

                                  Clique sur parcourir et cherche ce fichier C:\Documents and Settings\TK\local settings\application Data\gcess.exe

                                  Clique sur Send File.

                                  Un rapport va s'élaborer ligne à ligne.

                                  Attends la fin. Il doit comprendre la taille du fichier envoyé.

                                  Sauvegarde le rapport avec le bloc-note.

                                  Copie le dans ta réponse.

                                  Si VirusTotal indique que le fichier a déjà été analysé, cliquer sur le bouton Reanalyse le fichier maintenant
                                  0
                                  1. Fichier gcess.exe reçu le 2008.10.02 23:22:00 (CET)
                                    Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
                                    Résultat: 1/36 (2.78%)

                                    Antivirus Version Dernière mise à jour Résultat
                                    AhnLab-V3 2008.10.3.0 2008.10.02 -
                                    AntiVir 7.8.1.34 2008.10.02 -
                                    Authentium 5.1.0.4 2008.10.02 -
                                    Avast 4.8.1248.0 2008.10.02 -
                                    AVG 8.0.0.161 2008.10.02 -
                                    BitDefender 7.2 2008.10.02 -
                                    CAT-QuickHeal 9.50 2008.10.01 -
                                    ClamAV 0.93.1 2008.10.02 -
                                    DrWeb 4.44.0.09170 2008.10.02 -
                                    eSafe 7.0.17.0 2008.10.02 -
                                    eTrust-Vet 31.6.6121 2008.10.02 -
                                    Ewido 4.0 2008.10.02 -
                                    F-Prot 4.4.4.56 2008.09.30 -
                                    F-Secure 8.0.14332.0 2008.10.02 -
                                    Fortinet 3.113.0.0 2008.10.02 -
                                    GData 19 2008.10.02 -
                                    Ikarus T3.1.1.34.0 2008.10.02 -
                                    K7AntiVirus 7.10.481 2008.10.02 -
                                    Kaspersky 7.0.0.125 2008.10.02 -
                                    McAfee 5397 2008.10.02 -
                                    Microsoft 1.4005 2008.10.02 -
                                    NOD32 3490 2008.10.02 -
                                    Norman 5.80.02 2008.10.02 -
                                    Panda 9.0.0.4 2008.10.02 -
                                    PCTools 4.4.2.0 2008.10.02 -
                                    Prevx1 V2 2008.10.02 -
                                    Rising 20.63.62.00 2008.09.28 -
                                    SecureWeb-Gateway 6.7.6 2008.10.02 Win32.Malware.dam (suspicious)
                                    Sophos 4.34.0 2008.10.02 -
                                    Sunbelt 3.1.1668.1 2008.09.24 -
                                    Symantec 10 2008.10.02 -
                                    TheHacker 6.3.1.0.098 2008.10.02 -
                                    TrendMicro 8.700.0.1004 2008.10.02 -
                                    VBA32 3.12.8.6 2008.10.02 -
                                    ViRobot 2008.10.2.1403 2008.10.02 -
                                    VirusBuster 4.5.11.0 2008.10.02 -

                                    Information additionnelle
                                    File size: 24628 bytes
                                    MD5...: 843938dd7504762c0f0455478ba84b31
                                    SHA1..: fe2bc7123b28277df9bc1d53854175f4245664d7
                                    SHA256: c21547f6e3fca2ac19fcb1b241fc88d0e429ea298e6adce46d8ffa7e70d09219
                                    SHA512: 8f4ba743d4bd3697ad47540cd20834b36b2f35c3e91167ef9f44e0003c696219
                                    792516fd47e777161b7551d1b688b67735d681cb6904cc4b787d511d387fa7dc
                                    PEiD..: -
                                    TrID..: File type identification
                                    Generic Win/DOS Executable (49.9%)
                                    DOS Executable Generic (49.8%)
                                    Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
                                    PEInfo: PE Structure information

                                    ( base data )
                                    entrypointaddress.: 0x401000
                                    timedatestamp.....: 0x41785046 (Fri Oct 22 00:11:50 2004)
                                    machinetype.......: 0x14c (I386)

                                    ( 3 sections )
                                    name viradd virsiz rawdsiz ntrpy md5
                                    .text 0x1000 0x3a471 0x3b000 6.76 27c1890403ded841b58881bfbca1f19a
                                    .rdata 0x3c000 0xbdc 0x1000 0.00 d41d8cd98f00b204e9800998ecf8427e
                                    .data 0x3d000 0x6f9c 0x7000 0.00 d41d8cd98f00b204e9800998ecf8427e

                                    ( 0 imports )

                                    ( 0 exports )
                                    packers (Kaspersky): PE_Patch
                                    0
                                2. Contributeur sécurité
                                  Re,

                                  mets à jour Internet explorer (Démarrer, Aide et support, Maintenir son ordi ...) et Adobe Acrobat reader (cherche Adobe reader dans les téléchargements de CCM).

                                  Désinstalle l'ancienne version de adobe reader.

                                  on nettoye :

                                  Lis bien et exécute cette manip dans l’ordre.

                                  #Télécharge et installe ces logiciels (si tu ne les as pas) pour les 3 premiers
                                  mets les à jour, comme indiqué dans les démos ou tutos.

                                  Ne les utilise pas tout de suite.

                                  Antispywares et autres :

                                  Télécharge Malwarebytes' Anti-Malware (MBAM) et enregistre le sur ton bureau à partir de ce lien :

                                  https://www.malwarebytes.com/

                                  A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.

                                  Double-clique sur l'icône Download_mbam-setup.exe sur ton bureau pour démarrer le programme d'installation.

                                  Pendant l'installation, suis les indications (en particulier le choix de la langue et l'autorisation d'accession à Internet). N'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.

                                  MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue.

                                  Nettoyeurs (de fichiers inutiles) et autres :

                                  *Ccleaner (gratuit)
                                  Téléchargement :
                                  https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
                                  Tuto :
                                  https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php

                                  Lors de l’installation, [décoche] l’option qui t’installerait la barre Yahoo !

                                  ========================================
                                  ->Affiche tous les fichiers et dossiers :
                                  clique sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage

                                  [Coche] « afficher les dossiers et fichiers cachés »

                                  [Décoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »

                                  [Décoche] « masquer les extensions dont le type est connu »

                                  Puis fais [appliquer] pour valider les changements.

                                  Et [Ok]
                                  .

                                  =======================================

                                  ->Démarre en mode sans échec :
                                  Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                                  Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec
                                  puis tape « entrée ».
                                  Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                                  (Si F8 ne marche pas utilise la touche F5).

                                  ========================================
                                  ->Lance CCleaner.

                                  Suppression des fichiers temporaires

                                  Va dans la section "Options" situé dans la marge gauche.
                                  Décoche "Avancé"
                                  Retourne ensuite dans la section "Nettoyeur"
                                  Fais bien attention de cocher toutes ces cases dans la marge gauche (Internet Explorer/Windows Explorer/Système)
                                  • Clique sur [Analyse]
                                  • Patiente le temps du scan, qui peut prendre un peu de temps si c'est la première fois.
                                  • Une fois le scan terminé, clique sur [Lancer le Nettoyage]

                                  ========================================
                                  Lance Malwarebytes AntiMalware

                                  Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.

                                  MBAM analyse ton ordinateur. L'analyse peut prendre un certain teps. Il suffit de vérifier de temps en temps son avancement.

                                  A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.

                                  Si des malwares ont été détectés, leur liste s'affiche.
                                  En cliquant sur Suppression (?) , MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                                  MBAM va ouvrir le bloc-notes et y copier le rapport d'analyse. Ferme le bloc-note. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)

                                  Ferme MBAM en cliquant sur Quitter.
                                  ========================================

                                  ->Relance CCleaner.
                                  Suppression des incohérences du registre

                                  • Clique sur l'icône [Registre] situés dans la marge à gauche
                                  • Puis clique sur [Analyser les erreurs]
                                  • Patiente pendant que CCleaner scan ton registre.
                                  • Une fois le scan terminé, coche toutes les entrèes qu'il t'aura trouvée.
                                  • Tu peux cliquer ensuite sur [Corriger les erreurs].

                                  Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement.
                                  ========================================
                                  ->Vide ta Corbeille.
                                  ========================================
                                  ->Redémarre en mode normal,

                                  - > Ouvre ce lien pour scanner ton PC avec un BitDefender en ligne (uniquement sous Internet Explorer) :

                                  https://www.bitdefender.com/toolbox/

                                  Utilisation :
                                  Cliquer sur "J'accepte" puis accepter également l'ActiveX bloqué par la barre anti-popup du SP2 qui clignotera en haut et l'installer.
                                  Ensuite, cliquer sur "Cliquez ici pour scanner".
                                  Patienter jusqu'à la fin du scan qui peut durer assez longtemps...

                                  Copier/coller le rapport entier sur le forum.

                                  Tutoriel en images ici : http://pageperso.aol.fr/rginformatique/mapage/defender.htm (merci à Balltrap34 pour cette réalisation)
                                  [Recoche] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »
                                  0
                                  1. Enfin! C'était long! entre cete nuit et aujourd'hui, je n'ai pas pu finir plus tôt!
                                    Voici le scan de bitdefender:

                                    BitDefender Online Scanner
                                    Scan report generated at: Fri, Oct 03, 2008 - 14:42:50

                                    Scan path: A:\;C:\;D:\;E:\;F:\;

                                    Statistics
                                    ----------
                                    Time 03:11:58
                                    Files 1034005
                                    Folders 17065
                                    Boot Sectors 0
                                    Archives 21810
                                    Packed Files 51270

                                    Results
                                    -------
                                    Identified Viruses 2
                                    Infected Files 3
                                    Suspect Files 0
                                    Warnings 0
                                    Disinfected 0
                                    Deleted Files 3

                                    Engines Info
                                    ------------
                                    Virus Definitions 1833022
                                    Engine build AVCORE v1.7 (build 8314.19) (i386) (Sep 10 2008 19:37:42)
                                    Scan plugins 16
                                    Archive plugins 43
                                    Unpack plugins 7
                                    E-mail plugins 6
                                    System plugins 4

                                    Scan Settings
                                    -------------
                                    First Action Disinfect
                                    Second Action Delete
                                    Heuristics Yes
                                    Enable Warnings Yes
                                    Scanned Extensions *;
                                    Exclude Extensions
                                    Scan Emails Yes
                                    Scan Archives Yes
                                    Scan Packed Yes
                                    Scan Files Yes
                                    Scan Boot Yes

                                    Scanned File | Status
                                    ------------ ------
                                    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe |
                                    Infected with: Win32.Worm.Bagle.ZMO

                                    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe |
                                    Deleted

                                    C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\hldrrr.exe.vir |
                                    Infected with: Win32.Worm.Bagle.ZMO

                                    C:\QooBox\Quarantine\C\WINDOWS\system32\drivers\hldrrr.exe.vir |
                                    Deleted

                                    D:\Documents TK\[...]\SOAD - Atwa.mp3 |
                                    Infected with: Trojan.Downloader.WMA.Wimad.N

                                    D:\Documents TK\[...]\SOAD - Atwa.mp3 |
                                    Deleted
                                    0
                                  2. @tikkhaiet celui-ci, le très résumé pour leurs stats:

                                    BitDefender Online Scanner - Real Time Virus Report
                                    Generated at: Fri, Oct 03, 2008 - 18:52:23

                                    Scan Info
                                    -------------
                                    Scanned Files 1051114
                                    Infected Files 3

                                    Virus Detected
                                    ---------------------
                                    Trojan.Downloader.WMA.Wimad.N 1
                                    Win32.Worm.Bagle.ZMO 2
                                    0
                                  3. Malwarebytes' Anti-Malware 1.28
                                    Version de la base de données: 1226
                                    Windows 5.1.2600 Service Pack 2

                                    03/10/2008 10:07:52
                                    mbam-log-2008-10-03 (10-07-52).txt

                                    Type de recherche: Examen complet (C:\|D:\|E:\|)
                                    Eléments examinés: 202206
                                    Temps écoulé: 2 hour(s), 48 minute(s), 47 second(s)

                                    Processus mémoire infecté(s): 0
                                    Module(s) mémoire infecté(s): 0
                                    Clé(s) du Registre infectée(s): 27
                                    Valeur(s) du Registre infectée(s): 0
                                    Elément(s) de données du Registre infecté(s): 0
                                    Dossier(s) infecté(s): 13
                                    Fichier(s) infecté(s): 155

                                    Processus mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Module(s) mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Clé(s) du Registre infectée(s):
                                    HKEY_CLASSES_ROOT\videoegg.activexloader (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{168dc258-1455-4e61-8590-9dac2f27b675} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{1a8642f1-dc80-4edc-a39d-0fb62a58b455} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{3f91eb90-ef62-44ee-a685-fac29af111cd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{5c29c7e4-5321-4cad-be2e-877666bed5df} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{83dfb6ee-ab18-41b5-86d4-b544a141d67e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{88d6cf0e-cf70-4c24-bf6e-e4e414bc649c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{8f6a82a2-d7b1-443e-bb9f-f7dc887dd618} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{9856e2d8-ffb2-4fe5-8cad-d5ad6a35a804} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{a3d06987-c35e-49e4-8fe2-ac67b9fbfb4c} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{a58c497b-3ee2-45e7-9594-daca6be2a0d0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{ad0a3058-fd49-4f98-a514-fd055201835e} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{ad5915ea-b61a-4dba-b5c8-ef4b2df0a3c7} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{bb187c0d-6f53-4f3e-9590-98fd3a7364a2} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{d17726cc-d4dd-4c4a-9671-471d56e413b5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{db8cce99-59c6-4552-8bfc-058feb38d6ce} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{dc3a04ee-cdd7-4407-915c-a5502f97eecd} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{e1a63484-a022-4d42-830a-fbd411514440} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\CLSID\{e282c728-189d-419e-8ee2-1601f4b39ba5} (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\videoegg (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_LOCAL_MACHINE\SOFTWARE\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@videoegg.com/publisher,version=1.5 (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CURRENT_USER\SOFTWARE\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    HKEY_CURRENT_USER\SOFTWARE\MozillaPlugins\@videoegg.com/publisher,version=1.5 (Adware.VideoEgg) -> Quarantined and deleted successfully.

                                    Valeur(s) du Registre infectée(s):
                                    (Aucun élément nuisible détecté)

                                    Elément(s) de données du Registre infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Dossier(s) infecté(s):
                                    C:\Documents and Settings\TK\Application Data\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Data (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Loader (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Loader\4665 (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520 (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\messages (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4665 (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Updater (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Updater\4665 (Adware.VideoEgg) -> Quarantined and deleted successfully.

                                    Fichier(s) infecté(s):
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Loader\4665\npvideoegg-loader.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Updater\updater.exe (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Updater\VideoEggBroker.exe (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Updater\VideoEggBroker.exe.old (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    D:\Documents TK\UTILS\VideoEggPublisher.exe (Malware.Tool) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\DataLOCKED (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Uninstall.exe (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Data\report.log (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Loader\loader.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\publisher.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\avcodec.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\crashRpt.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\FLVEncoder.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\lame_enc.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\LevelMeter.ax (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\libcurlve.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\libpng.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\npvideoegg-publisher.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\VideoEgg_FLVWriter.ax (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\zlib.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\aol_watermark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\audio_combo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\audio_source.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\big_gray_logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\big_logo_cropped.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\blank_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\button_browse_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\button_browse_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\button_browse_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\camcorders_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\camcorder_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\camcorder_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\corners_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\corners_bottom_left_curve.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\corners_bottom_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\corners_top_right.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\done_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dropshadow_bottom_left.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dropshadow_horiz.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dropshadow_vertical.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dropzone.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dv_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dv_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dv_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dv_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\dv_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\email_instructions.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\email_sent.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\email_sent_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\email_sent_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\eraser.CUR (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\eraser_cursor.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\file_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\file_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\help.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_camcorder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_camcorders.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_camcorder_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_camcorder_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_ff.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_file_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_file_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_phone_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_phone_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_stop.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_webcam.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_webcams.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_webcam_dark.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\icon_webcam_light.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\loading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\loading_movie.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\locating.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\logo.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\logo_bottom.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\logo_middle.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\logo_top.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\mobile_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\mobile_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\mobile_slide_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\movie_placeholder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\ok.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\ok_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\ok_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_fast_forward.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_fast_forward_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_pause.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_play.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_rewind.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_rewind_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\player_rewind_to_start.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\playhead.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\powered_by.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\progress.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\refresh_list_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\refresh_list_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\refresh_list_up.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\restart.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\restart_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_over_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\start_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\stop_capture.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\stop_capture_disabled.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\stop_capture_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\stop_capture_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\stop_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\tab_slide_deselected.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\tape_control.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_camcorder.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_camcorder_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_file.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_file_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_phone.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_phone_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_webcam.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\text_webcam_highlight.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\upload.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading_fill.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading_high.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading_low.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading_medium.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\uploading_thumbnail.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\upload_down.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\upload_from.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\upload_over.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_gray.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_green.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_high.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_low.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_orange.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_red.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\volume_slider.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\waiting_for_email.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\webcams_title.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\webcam_btn_highlighted.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\images\webcam_slide.png (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Publisher\4520\resources\VideoEgg\messages\messages.en-US.bundle (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Updater\updater.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Updater\4665\libcurlve.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\TK\Application Data\VideoEgg\Updater\4665\updater.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
                                    0
                                3. Contributeur sécurité
                                  Bonjour,

                                  je peux avoir le rapport de MBAM.

                                  réinstalle Spybot S&D (mais pas le Tea-timer).

                                  Par contre, tu vaccines .
                                  0
                                  1. Merci, qu'est-ce que tu veux dire par vacciner?
                                    0
                                • 1
                                • 2