Pc infecté

00sebounet00 Messages postés 22 Statut Membre -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour,

suite a un scan gratuit avec panda j'ai vu que mon pc etait infecté
voici le logfile hijackthis : quelqu'un peut il m'aider merci

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:32:35, on 23/10/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
K:\Windows\system32\taskeng.exe
K:\Windows\system32\Dwm.exe
K:\Windows\system32\taskeng.exe
K:\Windows\Explorer.EXE
K:\Program Files\Yamicsoft\Vista Manager\WallpaperChanger.exe
K:\Program Files\Windows Defender\MSASCui.exe
K:\Program Files\Windows Live\Contrôle parental\fssui.exe
K:\Windows\SOUNDMAN.EXE
F:\Avira\AntiVir PersonalEdition Classic\avgnt.exe
K:\Windows\WindowsMobile\wmdSync.exe
K:\Windows\System32\rundll32.exe
F:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
F:\Program Files\DAEMON Tools Lite\daemon.exe
K:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
K:\Program Files\Windows Live\Messenger\msnmsgr.exe
F:\Program Files\eMule\emule.exe
K:\Windows\System32\mobsync.exe
K:\Program Files\Windows Media Player\wmpnscfg.exe
K:\Windows\system32\wbem\unsecapp.exe
K:\Program Files\Internet Explorer\iexplore.exe
K:\Program Files\Internet Explorer\iexplore.exe
K:\Program Files\Internet Explorer\iexplore.exe
K:\Users\seb\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - K:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - K:\Windows\system32\BhoECart.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - K:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Windows Live OneCare Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - K:\Program Files\Windows Live\Contrôle parental\fssbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - f:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - K:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - K:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - K:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - K:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - K:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [fssui] "K:\Program Files\Windows Live\Contrôle parental\fssui.exe" -autorun
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "K:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE K:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE K:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE K:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "F:\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] f:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "F:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [swg] K:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "K:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [eMuleAutoStart] F:\Program Files\eMule\emule.exe -AutoStart
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - K:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - K:\Windows\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - f:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - f:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - F:\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - F:\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - f:\Program Files\Ares\chatServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - K:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - F:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - K:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - K:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - K:\Windows\system32\IoctlSvc.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - K:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - K:\Windows\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - K:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - K:\Windows\system32\vmnat.exe
O23 - Service: [webwiz] - webcam via ftp - [RUELEPIC] (webwiz) - [ruelepic] - K:\PROGRA~1\_WEBWI~1\Webwizsvc.exe

--
End of file - 7926 bytes
Configuration: Windows Vista
Internet Explorer 8.0

15 réponses

  1. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    slt tu as le rapport panda???

    colle le nous
    0
  2. 00sebounet00 Messages postés 22 Statut Membre
     
    slt jlpjlp,

    je n'ai pas sauvegarder le rapport panda je refais un scan et je le poste
    -1
  3. 00sebounet00 Messages postés 22 Statut Membre
     
    rebj,

    voici le rapport panda, merci pour vos reponse :

    ;***********************************************************************************************************************************************************************************
    ANALYSIS: 2008-10-23 15:10:58
    PROTECTIONS: 1
    MALWARE: 13
    SUSPECTS: 0
    ;***********************************************************************************************************************************************************************************
    PROTECTIONS
    Description Version Active Updated
    ;===================================================================================================================================================================================
    Windows Defender 1.1.4005.0 No No
    ;===================================================================================================================================================================================
    MALWARE
    Id Description Type Active Severity Disinfectable Disinfected Location
    ;===================================================================================================================================================================================
    00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@doubleclick[1].txt
    00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@atdmt[2].txt
    00145393 Cookie/Tradedoubler TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@tradedoubler[2].txt
    00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@mediaplex[1].txt
    00167704 Cookie/Xiti TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@xiti[1].txt
    00168061 Cookie/Apmebf TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@apmebf[1].txt
    00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@serving-sys[2].txt
    00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@bs.serving-sys[2].txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@advertising[2].txt
    00172449 Cookie/MetriWeb TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@metriweb[1].txt
    00173520 Cookie/Bluestreak TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@bluestreak[1].txt
    00273339 Cookie/Smartadserver TrackingCookie No 0 Yes No K:\Users\seb\AppData\Roaming\Microsoft\Windows\Cookies\seb@smartadserver[1].txt
    03738686 Generic Malware Virus/Trojan No 0 Yes No K:\Program Files\Navilog1\catchme.exe
    ;===================================================================================================================================================================================
    SUSPECTS
    Sent Location �K����s5
    ;===================================================================================================================================================================================
    ;===================================================================================================================================================================================
    VULNERABILITIES
    Id Severity Description �K����s5
    ;===================================================================================================================================================================================
    ;===================================================================================================================================================================================
    -1
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    slt il n' y a aucune infection :)

    que des cookies que l'on a des que l'on va sur le net: utilise ccleaner pour les virer regulierement ou supprime les via les options de ton navigateur internet

    https://www.malekal.com/tutoriel-ccleaner/

    ensuite il y a ceci:
    03738686 Generic Malware Virus/Trojan No 0 Yes No K:\Program Files\Navilog1\catchme.exe

    c'est le logiciel navilog que tu as dû utiliser , tu peux le deinstaller via ton panneau de configuration comme tu le ferait avec d'autres logiciels
    -1
  6. 00sebounet00 Messages postés 22 Statut Membre
     
    ok

    merci pour ta reponse

    mais je ne comprend pas pourquoi, alors j'ai des probleme d'affichage (grande police, grande icone, image pas a leur place, internet explorer ne peux afficher cette page web, etc...) seulement par moment.
    -1
  7. 00sebounet00 Messages postés 22 Statut Membre
     
    bonjour,

    voici le rapport malwarebyte's comme demander mais je ne comprend pas il ne troouve rien.
    mais la j'ai fais tout ce que vous m'avez dis et ca a l'air d'etre ok alors merci pour vos conseil

    Malwarebytes' Anti-Malware 1.30
    Version de la base de données: 1306
    Windows 6.0.6001 Service Pack 1

    24/10/2008 01:31:10
    mbam-log-2008-10-24 (01-31-10).txt

    Type de recherche: Examen complet (C:\|F:\|K:\|)
    Eléments examinés: 179604
    Temps écoulé: 1 hour(s), 13 minute(s), 15 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    -1
  8. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    télécharge combofix (par sUBs) ici :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    et enregistre le sur le bureau.

    déconnecte toi d'internet et ferme toutes tes applications.

    désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

    double-clique sur combofix.exe et suis les instructions

    à la fin, il va produire un rapport C:\ComboFix.txt

    réactive ton parefeu, ton antivirus, la garde de ton antispyware

    copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

    Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

    Tu as un tutoriel complet ici :

    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
    -1
  9. 00sebounet00 Messages postés 22 Statut Membre
     
    voici le rapport combofix:

    ComboFix 08-10-24.02 - seb 2008-10-25 1:10:27.1 - NTFSx86
    Microsoft® Windows Vista™ Professionnel 6.0.6001.1.1252.1.1036.18.1345 [GMT 2:00]
    Lancé depuis: K:\Users\seb\Desktop\ComboFix.exe
    * Un nouveau point de restauration a été créé
    .

    ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-24 au 2008-10-24 ))))))))))))))))))))))))))))))))))))
    .

    2008-10-25 01:05 . 2008-10-25 01:05 233,269,684 --a------ K:\Windows\MEMORY.DMP
    2008-10-23 18:41 . 2008-10-23 18:41 <REP> d-------- K:\Users\seb\AppData\Roaming\Malwarebytes
    2008-10-23 18:41 . 2008-10-23 18:41 <REP> d-------- K:\Users\All Users\Malwarebytes
    2008-10-23 18:41 . 2008-10-23 18:41 <REP> d-------- K:\Program Files\Malwarebytes' Anti-Malware
    2008-10-23 18:41 . 2008-10-23 18:41 <REP> d-------- K:\PROGRA~2\Malwarebytes
    2008-10-23 18:41 . 2008-10-22 16:10 38,496 --a------ K:\Windows\System32\drivers\mbamswissarmy.sys
    2008-10-23 18:41 . 2008-10-22 16:10 15,504 --a------ K:\Windows\System32\drivers\mbam.sys
    2008-10-23 17:35 . 2008-10-23 17:35 2,560 --a------ K:\Windows\_MSRSTRT.EXE
    2008-10-23 02:28 . 2008-10-23 02:28 <REP> d-------- K:\Program Files\Panda Security
    2008-10-23 02:28 . 2008-06-19 17:24 28,544 --a------ K:\Windows\System32\drivers\pavboot.sys
    2008-10-22 10:52 . 2008-10-22 10:52 0 --ah----- K:\Windows\System32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
    2008-10-20 22:25 . 2008-10-20 22:26 <REP> d-------- K:\Program Files\Satsuki Decoder Pack
    2008-10-18 22:18 . 2008-10-18 22:18 25 --a------ K:\Windows\cdplayer.ini
    2008-10-18 22:16 . 2008-10-18 22:16 <REP> d-------- K:\Program Files\Common Files\xing shared
    2008-10-18 22:09 . 2008-10-18 22:16 <REP> d-------- K:\Program Files\Common Files\Real
    2008-10-18 22:00 . 2008-10-18 22:02 <REP> d-------- K:\Users\seb\AppData\Roaming\vlc
    2008-10-18 21:58 . 2008-10-18 21:58 <REP> d-------- K:\Program Files\VideoLAN
    2008-10-18 21:51 . 2008-10-18 21:51 <REP> d-------- K:\Program Files\CCleaner
    2008-10-18 21:43 . 2008-10-18 21:43 <REP> d-------- K:\Program Files\Haali
    2008-10-18 21:15 . 2008-10-18 21:15 <REP> d-------- K:\Program Files\Matroska Playback Pack
    2008-10-15 16:55 . 2008-10-15 16:55 <REP> d-------- K:\Program Files\Virtualis
    2008-10-15 03:06 . 2008-09-18 07:09 3,601,464 --a------ K:\Windows\System32\ntkrnlpa.exe
    2008-10-15 03:06 . 2008-09-18 07:09 3,549,240 --a------ K:\Windows\System32\ntoskrnl.exe
    2008-10-15 02:30 . 2008-09-18 04:16 2,032,640 --a------ K:\Windows\System32\win32k.sys
    2008-10-15 02:28 . 2008-08-27 03:06 288,768 --a------ K:\Windows\System32\drivers\srv.sys
    2008-10-15 02:19 . 2008-10-15 02:19 <REP> d-------- K:\Users\All Users\NVIDIA
    2008-10-15 02:19 . 2008-10-15 02:19 <REP> d-------- K:\PROGRA~2\NVIDIA
    2008-10-13 21:45 . 2008-10-13 21:45 <REP> d-------- K:\Program Files\VideoCap
    2008-10-13 21:18 . 2008-10-23 17:35 <REP> d-------- K:\Program Files\[webwiz]
    2008-10-13 21:18 . 2008-10-13 21:18 209 --a------ K:\Windows\ODBCINST.INI
    2008-10-13 21:18 . 2008-10-13 21:31 130 --a------ K:\Windows\ODBC.INI
    2008-10-13 20:54 . 2006-07-24 17:47 129,304 --a------ K:\Windows\System32\drivers\cam1210.sys
    2008-10-13 20:54 . 2006-06-29 16:35 36,864 --a------ K:\Windows\System32\cam1210.ax
    2008-10-13 20:54 . 2006-07-24 16:46 31,232 --a------ K:\Windows\System32\cam1210.dll
    2008-10-13 20:16 . 2008-10-13 20:16 <REP> d-------- K:\Users\All Users\PC Drivers HeadQuarters
    2008-10-13 20:16 . 2008-10-13 20:16 <REP> d-------- K:\PROGRA~2\PC Drivers HeadQuarters
    2008-10-13 19:46 . 2004-08-09 17:43 94,208 --a------ K:\Windows\amcap.exe
    2008-10-13 18:54 . 2008-10-13 18:54 <REP> d-------- K:\Program Files\Lavalys
    2008-10-13 15:14 . 2008-10-13 15:14 <REP> d-------- K:\Windows\Sun
    2008-10-10 18:58 . 2008-10-23 18:43 <REP> d-------- K:\Program Files\Navilog1
    2008-10-10 16:22 . 2008-10-10 16:22 <REP> d-------- K:\Users\All Users\Avira
    2008-10-10 16:22 . 2008-10-10 16:22 <REP> d-------- K:\PROGRA~2\Avira
    2008-10-08 19:55 . 2008-10-08 19:55 <REP> d-------- K:\Users\seb\AppData\Roaming\gtk-2.0
    2008-10-08 19:55 . 2008-10-08 19:55 <REP> d-------- K:\Users\seb\.thumbnails
    2008-10-08 19:46 . 2008-10-08 20:01 <REP> d-------- K:\Users\seb\.gimp-2.6
    2008-10-08 19:46 . 2008-10-08 19:46 <REP> d-------- K:\Users\seb\.gegl-0.0
    2008-10-08 19:39 . 2008-10-08 19:40 <REP> d-------- K:\Program Files\Gimp-2.0
    2008-09-30 13:41 . 2008-09-30 13:41 0 --ah----- K:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
    2008-09-26 16:39 . 2008-10-24 22:36 <REP> d-------- K:\Users\All Users\Google Updater
    2008-09-26 16:39 . 2008-10-24 22:36 <REP> d-------- K:\PROGRA~2\Google Updater
    2008-09-26 12:26 . 2008-09-27 17:03 <REP> d-------- K:\Users\seb\AppData\Roaming\Command and Conquer 3 Tiberium Wars
    2008-09-26 11:02 . 2008-09-26 11:02 <REP> d-------- K:\Users\seb\AppData\Roaming\ESTsoft
    2008-09-26 11:02 . 2008-09-26 11:02 <REP> d-------- K:\Program Files\ESTsoft
    2008-09-25 17:50 . 2007-10-12 15:14 3,734,536 --a------ K:\Windows\System32\d3dx9_36.dll
    2008-09-25 17:50 . 2007-10-12 15:14 1,374,232 --a------ K:\Windows\System32\D3DCompiler_36.dll
    2008-09-25 17:50 . 2007-10-02 09:56 444,776 --a------ K:\Windows\System32\d3dx10_36.dll
    2008-09-25 17:50 . 2007-10-22 03:39 267,272 --a------ K:\Windows\System32\xactengine2_10.dll
    2008-09-25 17:50 . 2007-10-22 03:37 17,928 --a------ K:\Windows\System32\X3DAudio1_2.dll
    2008-09-25 16:49 . 2008-09-25 16:49 <REP> dr-h----- K:\Users\seb\AppData\Roaming\SecuROM
    2008-09-25 16:49 . 2008-09-25 16:49 98,304 --a------ K:\Windows\system32CmdLineExt.dll
    2008-09-25 16:47 . 2006-11-29 13:06 3,426,072 --a------ K:\Windows\System32\d3dx9_32.dll
    2008-09-25 16:26 . 2008-10-14 12:20 <REP> d-------- K:\Program Files\Electronic Arts

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-10-24 23:05 --------- d-----w K:\PROGRA~2\VMware
    2008-10-22 13:29 --------- d-----w K:\Program Files\Google
    2008-10-18 19:54 --------- d-----w K:\PROGRA~2\Spybot - Search & Destroy
    2008-10-15 09:59 --------- d-----w K:\Program Files\Windows Mail
    2008-10-13 18:26 --------- d--h--w K:\Program Files\InstallShield Installation Information
    2008-10-13 16:05 --------- d-----w K:\Program Files\Windows Live Safety Center
    2008-10-10 12:20 --------- d-----w K:\Program Files\Windows Live
    2008-09-25 14:19 --------- d-----w K:\Users\seb\AppData\Roaming\Azureus
    2008-09-25 13:42 --------- d-----w K:\Program Files\Common Files\InstallShield
    2008-09-25 10:29 --------- d-----w K:\PROGRA~2\WLInstaller
    2008-09-23 13:37 --------- d-----w K:\PROGRA~2\avg8
    2008-09-23 09:13 --------- d-----w K:\Users\seb\AppData\Roaming\Media Player Classic
    2008-09-22 17:47 --------- d-----w K:\Program Files\Creative Zone
    2008-09-21 01:00 --------- d-----w K:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-09-20 21:52 --------- d-----w K:\Program Files\Yamicsoft
    2008-09-20 21:40 --------- d-----w K:\Program Files\MagicISO
    2008-09-20 18:36 --------- d-----w K:\Users\seb\AppData\Roaming\Nero
    2008-09-20 18:34 --------- d-----w K:\Program Files\Common Files\Nero
    2008-09-20 18:32 --------- d-----w K:\Program Files\Nero
    2008-09-20 18:32 --------- d-----w K:\PROGRA~2\Nero
    2008-09-20 09:47 --------- d-----w K:\PROGRA~2\IM
    2008-09-20 09:39 --------- d-----w K:\PROGRA~2\IncrediMail
    2008-09-20 01:32 174 --sha-w K:\Program Files\desktop.ini
    2008-09-20 01:22 --------- d-----w K:\Program Files\Windows Sidebar
    2008-09-20 01:22 --------- d-----w K:\Program Files\Windows Calendar
    2008-09-20 01:21 --------- d-----w K:\Program Files\Windows Photo Gallery
    2008-09-20 01:21 --------- d-----w K:\Program Files\Windows Journal
    2008-09-20 01:21 --------- d-----w K:\Program Files\Windows Defender
    2008-09-20 01:21 --------- d-----w K:\Program Files\Windows Collaboration
    2008-09-19 22:38 82,432 ----a-w K:\Windows\System32\axaltocm.dll
    2008-09-19 22:38 101,888 ----a-w K:\Windows\System32\ifxcardm.dll
    2008-09-18 15:00 --------- d-----w K:\Program Files\Java
    2008-09-18 14:51 --------- d-----w K:\Program Files\Common Files\Java
    2008-09-18 13:54 --------- d-----w K:\Program Files\Sun
    2008-09-18 13:53 410,976 ----a-w K:\Windows\System32\deploytk.dll
    2008-09-18 09:30 1,524,736 ----a-w K:\Windows\System32\wucltux.dll
    2008-09-18 09:29 83,456 ----a-w K:\Windows\System32\wudriver.dll
    2008-09-18 09:29 563,912 ----a-w K:\Windows\System32\wuapi.dll
    2008-09-18 09:29 53,448 ----a-w K:\Windows\System32\wuauclt.exe
    2008-09-18 09:29 45,768 ----a-w K:\Windows\System32\wups2.dll
    2008-09-18 09:29 36,552 ----a-w K:\Windows\System32\wups.dll
    2008-09-18 09:29 1,811,656 ----a-w K:\Windows\System32\wuaueng.dll
    2008-09-18 09:28 31,232 ----a-w K:\Windows\System32\wuapp.exe
    2008-09-18 09:28 163,904 ----a-w K:\Windows\System32\wuwebv.dll
    2008-09-18 01:02 269,312 ----a-w K:\Windows\System32\es.dll
    2008-09-17 15:42 --------- d-----r K:\Users\seb\AppData\Roaming\Brother
    2008-09-16 20:37 --------- d-----w K:\Program Files\DAEMON Tools Toolbar
    2008-09-16 20:29 717,296 ----a-w K:\Windows\system32\drivers\sptd.sys
    2008-09-16 20:27 --------- d-----w K:\Users\seb\AppData\Roaming\DAEMON Tools
    2008-09-16 18:10 61,440 ----a-w K:\Windows\System32\winipsec.dll
    2008-09-16 18:10 361,984 ----a-w K:\Windows\System32\IPSECSVC.DLL
    2008-09-16 18:10 28,672 ----a-w K:\Windows\System32\FwRemoteSvr.dll
    2008-09-16 18:10 272,896 ----a-w K:\Windows\System32\polstore.dll
    2008-09-16 18:07 4,240,384 ----a-w K:\Windows\System32\GameUXLegacyGDFs.dll
    2008-09-16 18:07 28,160 ----a-w K:\Windows\System32\Apphlpdm.dll
    2008-09-16 18:07 2,560 ----a-w K:\Windows\AppPatch\AcRes.dll
    2008-09-16 18:07 1,695,744 ----a-w K:\Windows\System32\gameux.dll
    2008-09-16 17:55 2,048 ----a-w K:\Windows\System32\tzres.dll
    2008-09-16 17:53 303,616 ----a-w K:\Windows\System32\wmpeffects.dll
    2008-09-16 17:38 9,892,864 ----a-w K:\Windows\System32\NlsLexicons000a.dll
    2008-09-16 17:26 988,216 ----a-w K:\Windows\System32\winload.exe
    2008-09-16 17:26 927,288 ----a-w K:\Windows\System32\winresume.exe
    2008-09-16 17:26 615,992 ----a-w K:\Windows\System32\ci.dll
    2008-09-16 17:26 6,656 ----a-w K:\Windows\System32\kbd106n.dll
    2008-09-16 17:26 46,592 ----a-w K:\Windows\System32\setbcdlocale.dll
    2008-09-16 17:26 40,960 ----a-w K:\Windows\System32\srclient.dll
    2008-09-16 17:26 378,368 ----a-w K:\Windows\System32\srcore.dll
    2008-09-16 17:26 318,464 ----a-w K:\Windows\System32\rstrui.exe
    2008-09-16 17:26 19,000 ----a-w K:\Windows\System32\kd1394.dll
    2008-09-16 17:26 14,848 ----a-w K:\Windows\System32\srdelayed.exe
    2008-09-16 17:21 295,936 ----a-w K:\Windows\System32\gdi32.dll
    2008-09-16 17:17 14,848 ----a-w K:\Windows\System32\wshrm.dll
    2008-09-16 17:17 113,664 ----a-w K:\Windows\system32\drivers\rmcast.sys
    2008-09-16 17:15 84,480 ----a-w K:\Windows\System32\INETRES.dll
    2008-09-16 17:15 738,304 ----a-w K:\Windows\System32\inetcomm.dll
    2008-09-16 17:14 1,314,816 ----a-w K:\Windows\System32\quartz.dll
    2008-09-16 15:56 --------- d-----w K:\Users\seb\AppData\Roaming\VMware
    2008-09-16 14:37 --------- d-----w K:\Program Files\VMware
    2008-09-16 14:37 --------- d-----w K:\Program Files\Common Files\VMware
    2008-09-16 11:08 --------- d-----w K:\PROGRA~2\NOS
    2008-09-15 21:42 --------- d-----w K:\Program Files\Common Files\Adobe
    2008-09-15 21:00 --------- d-----w K:\Program Files\Realtek AC97
    2008-09-15 20:59 319,488 ----a-w K:\Windows\HideWin.exe
    2008-09-15 20:58 691,200 ----a-w K:\Windows\System32\RtkPgExt.dll
    2008-09-15 20:58 598,016 ----a-w K:\Windows\SOUNDMAN.EXE
    2008-09-15 20:58 4,137,312 ----a-w K:\Windows\system32\drivers\RTKVAC.SYS
    2008-09-15 20:58 2,159,104 ----a-w K:\Windows\System32\RtkAPO.dll
    2008-09-15 20:58 147,456 ----a-w K:\Windows\System32\RTLCPAPI.dll
    2008-09-15 20:58 10,968,576 ----a-w K:\Windows\System32\RTLCPL.EXE
    2008-09-15 20:57 524,288 ----a-w K:\Windows\RtlExUpd.dll
    2008-09-15 20:57 315,392 ----a-w K:\Windows\alcupd.exe
    2008-09-15 20:57 217,088 ----a-w K:\Windows\alcrmv.exe
    2008-09-15 20:41 --------- dcsh--w K:\Program Files\Common Files\WindowsLiveInstaller
    2008-09-15 19:43 --------- d-----w K:\Users\seb\AppData\Roaming\InstallShield
    2008-09-15 19:43 --------- d-----w K:\Program Files\Realtek
    2008-09-15 19:42 9,728 ----a-w K:\Windows\System32\RtNicProp32.dll
    2008-09-15 19:42 51,200 ----a-w K:\Windows\system32\drivers\Rtnicxp.sys
    2008-09-15 19:41 --------- d-----w K:\Program Files\Intel
    2008-09-15 19:33 --------- d-----w K:\PROGRA~2\ma-config.com
    2008-09-15 19:13 --------- d-----w K:\PROGRA~2\Azureus
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SpybotSD TeaTimer"="f:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
    "DAEMON Tools Lite"="F:\Program Files\DAEMON Tools Lite\daemon.exe" [2008-07-24 490952]
    "swg"="K:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-09-26 39408]
    "msnmsgr"="K:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
    "eMuleAutoStart"="F:\Program Files\eMule\emule.exe" [2008-08-01 5480448]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "fssui"="K:\Program Files\Windows Live\Contrôle parental\fssui.exe" [2007-12-17 243240]
    "Adobe Reader Speed Launcher"="K:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "NvSvc"="K:\Windows\system32\nvsvc.dll" [2006-10-09 90191]
    "NvCplDaemon"="K:\Windows\system32\NvCpl.dll" [2006-10-09 7741440]
    "NvMediaCenter"="K:\Windows\system32\NvMcTray.dll" [2006-10-09 81920]
    "avgnt"="F:\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
    "Windows Mobile-based device management"="K:\Windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
    "SoundMan"="SOUNDMAN.EXE" [2008-09-15 K:\Windows\SOUNDMAN.EXE]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-404885146-768755033-4060301274-1000]
    "EnableNotifications"=dword:00000001
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{24D375CF-1DB8-480B-9F55-7610DB08B893}"= K:\Program Files\AVG\AVG8\avgemc.exe:avgemc.exe
    "{ACC92C44-A6B6-4636-A50F-F030C8163BE7}"= K:\Program Files\AVG\AVG8\avgupd.exe:avgupd.exe
    "TCP Query User{9276932F-49E0-428C-86DA-328ABF4AD774}F:\\emule\\emule.exe"= UDP:F:\emule\emule.exe:eMule
    "UDP Query User{B8A72D2E-E3B9-48EF-BF89-8036BC5AD4F8}F:\\emule\\emule.exe"= TCP:F:\emule\emule.exe:eMule
    "TCP Query User{7AC2BE80-5C7B-42C5-924F-108D32D50211}F:\\program files\\emule\\emule.exe"= UDP:F:\program files\emule\emule.exe:eMule
    "UDP Query User{848D36EA-D547-4961-806A-88FFD0ECF5FA}F:\\program files\\emule\\emule.exe"= TCP:F:\program files\emule\emule.exe:eMule
    "{3BDC1DF9-05A4-4022-A4C9-1C78E78AB649}"= UDP:4661:emule_TCP
    "{A874E6DB-F5C2-4191-8CFA-6B6720EAED50}"= TCP:4761:emule_UDP
    "TCP Query User{9114FE6F-AF3D-4FB3-BA08-48A2D9A8FC74}F:\\program files\\vuze\\azureus.exe"= UDP:F:\program files\vuze\azureus.exe:Azureus
    "UDP Query User{3124C08A-EB8B-4788-9624-605EC29BF737}F:\\program files\\vuze\\azureus.exe"= TCP:F:\program files\vuze\azureus.exe:Azureus
    "{0EC2F927-A45B-4967-A9D3-30B67290891D}"= UDP:48113:LocalSubnet:LocalSubnet:maconfig_tcp
    "{9A12862D-5363-4D65-81A7-ED232C0E649C}"= TCP:48113:LocalSubnet:LocalSubnet:maconfig_udp
    "{B0EF9E4F-8ECB-4111-A3E4-331F1233C9F5}"= UDP:F:\Program Files\ma-config.com\maconfservice.exe:maconfservice
    "{4078D484-ED04-4CFB-B75D-71AA8BCDD4C6}"= TCP:F:\Program Files\ma-config.com\maconfservice.exe:maconfservice
    "TCP Query User{ECC819B1-8D7B-4383-8FA4-A090317A7298}F:\\program files\\emule\\emule.exe"= UDP:F:\program files\emule\emule.exe:eMule
    "UDP Query User{8FC6056C-3310-4068-8C0E-D29921E11F04}F:\\program files\\emule\\emule.exe"= TCP:F:\program files\emule\emule.exe:eMule
    "TCP Query User{1AA4B9B4-7EC4-40C2-871D-50CF8355E5E5}F:\\program files\\vuze\\azureus.exe"= UDP:F:\program files\vuze\azureus.exe:Azureus
    "UDP Query User{F8C43591-D18C-4847-ACB3-11EA1F6081FE}F:\\program files\\vuze\\azureus.exe"= TCP:F:\program files\vuze\azureus.exe:Azureus
    "{4DB69E9D-5E4E-4134-B83E-70E916820CDA}"= K:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
    "{FC56501B-6AF3-4860-AB84-A25016420319}"= K:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
    "TCP Query User{18E10C7C-4240-46EF-8A9D-792F6C2EECB5}K:\\program files\\internet explorer\\iexplore.exe"= UDP:K:\program files\internet explorer\iexplore.exe:Internet Explorer
    "UDP Query User{B3491FCF-45C7-48CB-9D1C-9CA768F45D99}K:\\program files\\internet explorer\\iexplore.exe"= TCP:K:\program files\internet explorer\iexplore.exe:Internet Explorer
    "TCP Query User{53B7A173-2836-48F2-969F-FA06E4620EA6}F:\\program files\\ares\\ares.exe"= UDP:F:\program files\ares\ares.exe:Ares p2p for windows
    "UDP Query User{E7496438-B0CD-4CE3-86A4-BB31FE228181}F:\\program files\\ares\\ares.exe"= TCP:F:\program files\ares\ares.exe:Ares p2p for windows
    "{F2320926-10FE-4B23-9D32-0D3D98953406}"= UDP:F:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
    "{CAB5C6F1-AE10-4147-8510-F280E012AC4B}"= TCP:F:\Program Files\IncrediMail\bin\ImpCnt.exe:IncrediMail
    "{633869D1-6882-4101-B7D1-33C62532F48A}"= UDP:F:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
    "{2EB036FF-7100-4FE4-9D1C-B65603C8DEA4}"= TCP:F:\Program Files\IncrediMail\bin\IncMail.exe:IncrediMail
    "{3313FBEC-073D-4777-8456-27F5001B5C4D}"= UDP:F:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
    "{AD128C7D-9A7C-4E6B-8980-281FF5308F6D}"= TCP:F:\Program Files\IncrediMail\bin\ImApp.exe:IncrediMail
    "{54C65B6B-52C3-46F8-BAFA-2FFDA4E1DA0E}"= UDP:F:\Program Files\IncrediMail\bin\ImNotfy.exe:ImNotfy
    "{F71D415A-9AB5-4962-9506-966E3886FDA3}"= TCP:F:\Program Files\IncrediMail\bin\ImNotfy.exe:ImNotfy
    "{93191F2D-8976-4C6A-BE56-F7611A48832A}"= K:\Program Files\Electronic Arts\Command & Conquer 3\RetailExe\1.0\cnc3game.dat:Command & Conquer 3 Les guerres du Tiberium™
    "TCP Query User{611ABA12-C4BF-4230-9FB9-E3964752C07E}K:\\program files\\live-player\\live-player.exe"= UDP:K:\program files\live-player\live-player.exe:Live-Player
    "UDP Query User{AF6D2213-2FF0-47AA-BD21-3B04802BBB89}K:\\program files\\live-player\\live-player.exe"= TCP:K:\program files\live-player\live-player.exe:Live-Player

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
    "EnableFirewall"= 0 (0x0)

    R0 pavboot;pavboot;K:\Windows\system32\drivers\pavboot.sys [2008-06-19 28544]
    R2 fssfltr;FssFltr;K:\Windows\system32\DRIVERS\fssfltr.sys [2007-10-17 43816]
    R2 fsssvc;Windows Live OneCare Contrôle parental;K:\Program Files\Windows Live\Contrôle parental\fsssvc.exe [2007-12-17 523816]
    R3 CAM1210;SM0121 USB 2.0 Video Camera;K:\Windows\system32\Drivers\cam1210.sys [2006-07-24 129304]
    R3 PRISM_A00;Wireless PCI 802.11b/g adapter WN4201B Driver;K:\Windows\system32\DRIVERS\PCTELSAP.SYS [2004-11-30 306560]
    R3 VST_DPV;VST_DPV;K:\Windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
    R3 VSTHWBS2;VSTHWBS2;K:\Windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
    S3 maconfservice;Ma-Config Service;F:\Program Files\ma-config.com\maconfservice.exe [2008-09-02 191656]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d40b9bac-842e-11dd-8afc-005056c00008}]
    \shell\AutoRun\command - G:\autorun.exe

    *Newly Created Service* - CATCHME
    .
    .
    ------- Examen supplémentaire -------
    .
    R0 -: HKCU-Main,Start Page = hxxp://google.fr/

    O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
    K:\Windows\Downloaded Program Files\CONFLICT.1\oscan8.inf
    K:\Windows\bdoscandel.exe
    K:\Windows\bdoscandellang.ini
    K:\Windows\Downloaded Program Files\CONFLICT.1\live.ini
    K:\Windows\Downloaded Program Files\CONFLICT.1\scanoptions.tsi
    K:\Windows\Downloaded Program Files\CONFLICT.1\lang.ini
    K:\Windows\Downloaded Program Files\CONFLICT.1\ipsupd.dll
    K:\Windows\Downloaded Program Files\CONFLICT.1\bdupd.dll
    K:\Windows\Downloaded Program Files\CONFLICT.1\libfn.dll
    K:\Windows\Downloaded Program Files\CONFLICT.1\bdcore.dll
    K:\Windows\Downloaded Program Files\CONFLICT.1\oscan8.ocx

    O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_1.cab
    K:\Windows\Downloaded Program Files\hardwaredetection.inf
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-10-25 01:17:55
    Windows 6.0.6001 Service Pack 1 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    Heure de fin: 2008-10-25 1:19:53
    ComboFix-quarantined-files.txt 2008-10-24 23:19:46
    ComboFix2.txt 2008-10-24 22:38:36

    Avant-CF: 23 834 234 880 octets libres
    Après-CF: 22,964,039,680 octets libres

    285 --- E O F --- 2008-10-24 10:55:35
    -1
  10. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    tes soucis c'est pas depuis la mise de internet explorer 8?

    __________

    Telecharge UsbFix sur ton bureau
    http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

    --> Lance l installation avec les parametres par default

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    --> Double clic sur le raccourci UsbFix sur ton bureau

    --> Le pc va redémarer

    -->Apres redémarrage post le rapport UsbFix.txt

    Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
    Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides
    -1
  11. 00sebounet00 Messages postés 22 Statut Membre
     
    voici le rapport usbfix et non le probleme etait la avant ie8

    -------------- UsbFix V2.395 ---------------

    * User : seb - PC-DE-SEB
    * Outils mis a jours le 20/10/2008 par Chiquitine29 et Chimay8
    * Recherche effectuée à 18:45:16 le 25/10/2008
    * Windows Vista - Internet Explorer 8.0.6001.18241

    --------------- [ Processus actifs ] ----------------

    K:\Windows\System32\smss.exe
    K:\Windows\system32\csrss.exe
    K:\Windows\system32\wininit.exe
    K:\Windows\system32\csrss.exe
    K:\Windows\system32\services.exe
    K:\Windows\system32\lsass.exe
    K:\Windows\system32\lsm.exe
    K:\Windows\system32\winlogon.exe
    K:\Windows\system32\svchost.exe
    K:\Windows\system32\svchost.exe
    K:\Windows\System32\svchost.exe
    K:\Windows\System32\svchost.exe
    K:\Windows\System32\svchost.exe
    K:\Windows\system32\svchost.exe
    K:\Windows\system32\svchost.exe
    K:\Windows\system32\SLsvc.exe
    K:\Windows\system32\svchost.exe
    K:\Windows\system32\svchost.exe
    K:\Windows\system32\Dwm.exe
    K:\Windows\System32\spoolsv.exe
    K:\Windows\system32\taskeng.exe
    F:\Avira\AntiVir PersonalEdition Classic\sched.exe
    K:\Windows\system32\svchost.exe
    K:\Program Files\Yamicsoft\Vista Manager\WallpaperChanger.exe
    K:\Windows\system32\taskeng.exe
    K:\Windows\system32\taskeng.exe
    F:\Avira\AntiVir PersonalEdition Classic\avguard.exe
    K:\Program Files\Windows Live\Contrôle parental\fsssvc.exe
    K:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    K:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
    K:\Windows\system32\IoctlSvc.exe
    K:\Windows\system32\svchost.exe
    K:\Windows\system32\svchost.exe
    K:\Program Files\VMware\VMware Player\vmware-authd.exe
    K:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
    K:\Windows\System32\svchost.exe
    K:\Windows\system32\SearchIndexer.exe
    K:\Windows\system32\vmnetdhcp.exe
    K:\Windows\system32\WUDFHost.exe
    K:\Windows\system32\DllHost.exe
    K:\Users\seb\AppData\Local\Temp\25D2.tmp\b2e.exe
    K:\Windows\system32\conime.exe

    --------------- [ Informations lecteurs ] ----------------

    C: - Lecteur fixe
    F: - Lecteur fixe
    H: - Lecteur amovible
    J: - Lecteur amovible
    K: - Lecteur fixe
    N: - Lecteur amovible

    --------------- [ Registre / Startup ] ----------------

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
    fssui REG_SZ "K:\Program Files\Windows Live\Contr“le parental\fssui.exe" -autorun
    Adobe Reader Speed Launcher REG_SZ "K:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    SoundMan REG_SZ SOUNDMAN.EXE
    NvSvc REG_SZ RUNDLL32.EXE K:\Windows\system32\nvsvc.dll,nvsvcStart
    NvCplDaemon REG_SZ RUNDLL32.EXE K:\Windows\system32\NvCpl.dll,NvStartup
    NvMediaCenter REG_SZ RUNDLL32.EXE K:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    avgnt REG_SZ "F:\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    Windows Mobile-based device management REG_EXPAND_SZ %windir%\WindowsMobile\wmdSync.exe

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents

    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    SpybotSD TeaTimer REG_SZ f:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    DAEMON Tools Lite REG_SZ "F:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
    swg REG_SZ K:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    msnmsgr REG_SZ "K:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    eMuleAutoStart REG_SZ F:\Program Files\eMule\emule.exe -AutoStart

    --------------- [ Registre / Mountpoint2 ] ----------------

    Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d40b9bac-842e-11dd-8afc-005056c00008}\Shell\AutoRun\command
    Supprimé ! - HKEY_USERS\S-1-5-21-404885146-768755033-4060301274-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d40b9bac-842e-11dd-8afc-005056c00008}\Shell\AutoRun\command

    --------------- [ Nettoyage des disques ] ----------------

    --------------- ! Fin du rapport ! ----------------
    -1
  12. 00sebounet00 Messages postés 22 Statut Membre
     
    j'ai desinstaller la maj ie8 et c'est pareil
    -1
  13. 00sebounet00 Messages postés 22 Statut Membre
     
    salut,

    j'ai restaurer le systeme comme tu me l'as demander mais le probleme perciste j'ai donc annuler la restauration puis j'ai essayer firefox et c'est toujours pareil
    -1