Virus Sumom.A - Help !

Bonjour,

Depuis lundi soir je suis contaminé par un virus qui se nomme, selon Spybot, Sumom.A ! En fait, à la suite de l'aparition du virus j'ai successivement installé Spybot (qui m'a viré une trentaine de cookies et autre espions, sauf celui-là qui n'arrive pas à éliminer, puis une version payante de Trend Micro ! Là encore, il m'a découvert une douzaine de choses malsaines, dont un cheval de troie... Mais mon virus est toujours présent ! J'ai essayé de faire tourner Trend Micros en mode sans échec, mais ça ne fonctionne pas...

J'ai vu qu'une façon de demander de l'aide était de coller le rapport Hijackthis... ce que j'ai fait ! Je remercie d'avance la personne qui saurait me sortir de là... MERCI !!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:28:06, on 20.11.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\bgsvcgen.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\Motive\McciCMService.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\RealVNC\VNC4\WinVNC4.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\WebMediaViewer\qttask.exe
C:\Program Files\WebMediaViewer\hpmon.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\WebMediaViewer\qttaskm.exe
C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\QuickHelp2\QuickHelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WebMediaViewer\hpmom.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
F:\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Microsoft Office\Office\WINWORD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: VirusTriggerBinWarningBHO Class - {096CBA44-4A4C-49f7-8903-1E75550ABCB7} - C:\Program Files\VirusTriggerBin\VirusTriggerBinWarning.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {64466B8E-20A7-4A4A-AFF4-AAD9CA68B52C} - C:\Program Files\WebMediaViewer\hpmun.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (file missing)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (file missing)
O3 - Toolbar: Browser Toolbar - {2EEF94DF-75F6-42E9-B7FB-AF5A170A6E2E} - C:\Program Files\WebMediaViewer\browseul.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
O3 - Toolbar: (no name) - {53E0B6E8-A51D-448B-B692-40B67B285543} - (no file)
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [QuickHelp2_McciTrayApp] C:\Program Files\QuickHelp2\QuickHelp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ANTIVIRUS] C:\Program Files\AAV\AAV.ExE
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA2323] command /c del "C:\Program Files\Everest Poker\gvmain.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingC6925] cmd /c del "C:\Program Files\Everest Poker\gvmain.exe"
O4 - HKLM\..\RunOnce: [SpybotDeletingA3394] command /c del "C:\Program Files\Everest Poker\udhglstl.tmp"
O4 - HKLM\..\RunOnce: [SpybotDeletingC8878] cmd /c del "C:\Program Files\Everest Poker\udhglstl.tmp"
O4 - HKLM\..\RunOnce: [SpybotSnD] "F:\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [VirusTriggerBin] "C:\Program Files\VirusTriggerBin\VirusTriggerBin.exe"
O4 - HKCU\..\Run: [ANTIVIRUS] C:\Program Files\AAV\AAV.ExE
O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKLM\..\Policies\Explorer\Run: [QuickTime Task] C:\Program Files\WebMediaViewer\qttask.exe
O4 - HKLM\..\Policies\Explorer\Run: [VMware hptray] C:\Program Files\WebMediaViewer\hpmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quick Help.lnk = C:\Program Files\Bluewin\Quick Help\bin\matcli.exe
O9 - Extra button: (no name) - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.ietoolexpress.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IExplorer Security - {3B8FB116-D358-48A3-A5C7-DB84F15CBB04} - http://www.ietoolexpress.com/redirect.php (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://my.tcs.ch/my.logout.php3?errorcode=19#version=6020,2008,0717,1603
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://my.tcs.ch/my.logout.php3?errorcode=19$$/iNotes6W.cab
O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://my.tcs.ch/my.logout.php3?errorcode=19#version=6020,2008,0717,1611
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O22 - SharedTaskScheduler: behaves - {1f3dd9bf-1472-4a8b-b295-b596a597149b} - C:\WINDOWS\system32\gowqug.dll (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Fichiers communs\Motive\McciCMService.exe
O23 - Service: Composant de commande centrale Trend Micro (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe

--
End of file - 11698 bytes
Configuration: Windows XP
Internet Explorer 7.0

24 réponses

Résumé de la discussion

Une infection par Sumom.A sur Windows XP SP3 persiste malgré Spybot puis Trend Micro, et l'auteur recherche de l'aide via un rapport HijackThis. Le log HijackThis répertorie de multiples processus et entrées de démarrage, avec des BHO, des barres d'outils Google et des composants tierce partie, dont certains fichiers manquants. Des éléments du rapport correspondent à des services légitimes détournés ou à des programmes parfois indésirables, ce qui rend le tri des composants compromis complexe. En cas de persistance, la solution pourrait impliquer une désinfection plus approfondie et potentiellement une réinstallation du système pour éviter une réinfection durable.

Bobot (l’IA à votre service)
  1. bonsoir

    Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31) :
    http://siri.urz.free.fr/Fix/SmitfraudFix.exe ou http://www.geekstogo.com/forum/files/file/6-smitfraudfix/

    - Enregistre-le sur le bureau

    - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée

    - Un rapport sera généré, poste-le dans ta prochaine réponse.

    [*] process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus.[*]

    ** Ne fais l'étape 2 que si on te le demande, on doit d'abord examiner le premier rapport de
    a+
    1. Ok, merci Archet9, voici le rapport :

      SmitFraudFix v2.376

      Rapport fait à 19:52:42.81, 20.11.2008
      Executé à partir de C:\Documents and Settings\Yves Kaltenrieder\Bureau\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Le type du système de fichiers est NTFS
      Fix executé en mode normal

      »»»»»»»»»»»»»»»»»»»»»»»» Process

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\WINDOWS\system32\bgsvcgen.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Fichiers communs\Motive\McciCMService.exe
      C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\RealVNC\VNC4\WinVNC4.exe
      C:\Program Files\Trend Micro\BM\TMBMSRV.exe
      C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
      C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
      C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
      C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
      C:\WINDOWS\system32\devldr32.exe
      C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\Winamp\winampa.exe
      C:\Program Files\QuickHelp2\QuickHelp.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
      F:\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Logitech\SetPoint\SetPoint.exe
      C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
      C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
      C:\Program Files\Microsoft Office\Office\WINWORD.EXE
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\cmd.exe

      »»»»»»»»»»»»»»»»»»»»»»»» hosts

      Fichier hosts corrompu !

      127.0.0.1 www.legal-at-spybot.info
      127.0.0.1 legal-at-spybot.info

      »»»»»»»»»»»»»»»»»»»»»»»» C:\

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

      »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

      C:\WINDOWS\system32\aav.cpl PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Yves Kaltenrieder

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\YVESKA~1\LOCALS~1\Temp

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Yves Kaltenrieder\Application Data

      C:\Documents and Settings\Yves Kaltenrieder\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusTrigger 2.1.lnk PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

      C:\DOCUME~1\YVESKA~1\MENUDM~1\VirusTrigger 2.1.lnk PRESENT !
      C:\DOCUME~1\ALLUSE~1\MENUDM~1\Antivirus Scan.url PRESENT !

      »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\YVESKA~1\Favoris

      »»»»»»»»»»»»»»»»»»»»»»»» Bureau

      »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

      »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

      »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
      "Source"="About:Home"
      "SubscribedURL"="About:Home"
      "FriendlyName"="Ma page d'accueil"

      »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      o4Patch
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      IEDFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» VACFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      VACFix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      404Fix
      Credits: Malware Analysis & Diagnostic
      Code: S!Ri

      »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
      "{1f3dd9bf-1472-4a8b-b295-b596a597149b}"="behaves"

      [HKEY_CLASSES_ROOT\CLSID\{1f3dd9bf-1472-4a8b-b295-b596a597149b}\InProcServer32]
      @="C:\WINDOWS\system32\gowqug.dll"

      [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1f3dd9bf-1472-4a8b-b295-b596a597149b}\InProcServer32]
      @="C:\WINDOWS\system32\gowqug.dll"

      »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLs"=""

      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
      "System"=""

      »»»»»»»»»»»»»»»»»»»»»»»» RK

      »»»»»»»»»»»»»»»»»»»»»»»» DNS

      Description: Netopia 3300 Series USB Network Adapter - Miniport d'ordonnancement de paquets
      DNS Server Search Order: 192.168.1.1

      HKLM\SYSTEM\CCS\Services\Tcpip\..\{FD781830-46AC-414F-8161-51F40AB0CF86}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\..\{FD781830-46AC-414F-8161-51F40AB0CF86}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS3\Services\Tcpip\..\{FD781830-46AC-414F-8161-51F40AB0CF86}: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
      HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

      »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      1. ok fait ceci ds l ordre:
        Télécharge cet outil de SiRi:

        http://siri.urz.free.fr/RHosts.php

        Double-clique dessus pour l'exécuter

        et clique sur "Restore original Hosts"

        ps : Tu auras l’impression que rien ne s’est passé, c’est normal.

        ensuite:

        Suite de la manipe ( nettoyage ), fais exactement ce qui suit :

        * Impératif : Redémarrer l'ordinateur en mode sans échec .
        Comment aller en Mode sans échec
        1) Redémarre ton ordi
        2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
        3) Tu verras un écran avec options de démarrage apparaître
        4) Choisis la première option : Sans Échec, et valide avec "Entrée"
        5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
        ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copies ou imprimes bien les info ci-dessous ...)

        *Double click sur SmitfraudFix.exe

        * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

        -> Si besion :
        * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presser Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

        ( Le correctif déterminera si le fichier wininet.dll est infecté.)

        * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
        pour remplacer le fichier corrompu.

        * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

        Le rapport se trouve à la racine de C\:
        (dans le fichier "rapport.txt")

        Postes moi ce dernier rapport ...

        a+
        1. Voilà, c'est fait... voici le rapport :

          SmitFraudFix v2.376

          Rapport fait à 20:26:54.49, 20.11.2008
          Executé à partir de C:\Documents and Settings\Yves Kaltenrieder\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Le type du système de fichiers est NTFS
          Fix executé en mode sans echec

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
          "{1f3dd9bf-1472-4a8b-b295-b596a597149b}"="behaves"

          [HKEY_CLASSES_ROOT\CLSID\{1f3dd9bf-1472-4a8b-b295-b596a597149b}\InProcServer32]
          @="C:\WINDOWS\system32\gowqug.dll"

          [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{1f3dd9bf-1472-4a8b-b295-b596a597149b}\InProcServer32]
          @="C:\WINDOWS\system32\gowqug.dll"

          »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          127.0.0.1 localhost

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

          S!Ri's WS2Fix: LSP not Found.

          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

          GenericRenosFix by S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

          C:\WINDOWS\system32\aav.cpl supprimé
          C:\Documents and Settings\Yves Kaltenrieder\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusTrigger 2.1.lnk supprimé
          C:\DOCUME~1\YVESKA~1\MENUDM~1\VirusTrigger 2.1.lnk supprimé
          C:\DOCUME~1\ALLUSE~1\MENUDM~1\Antivirus Scan.url supprimé

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{FD781830-46AC-414F-8161-51F40AB0CF86}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{FD781830-46AC-414F-8161-51F40AB0CF86}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\..\{FD781830-46AC-414F-8161-51F40AB0CF86}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

          »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

          Nettoyage terminé.

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin
          1. ok ....tres bien....

            la suite:

            1: je suis hyper fatigué ('boulot demain)
            donc fais ce qui suit.... ca dure + ou - 1 heure voir bien +...
            poste le rapport je verrai ca demain soir....
            2:
            --Fais un scan avec cet antispyware :

            Telecharge malwarebytes + tutoriel :

            -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

            Tu l´installes; le programme va se mettre automatiquement a jour.

            Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

            Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

            Puis click sur "rechercher".

            Laisse le scanner le pc...

            Si des elements on ete trouvés > click sur supprimer la selection.

            si il t´es demandé de redemarrer > click sur "yes".

            A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

            Copie et colle le rapport stp.

            a+

            Antonio Giacomo Stradivari, souvent appelé Stradivarius (Crémone, 1644 - Crémone, 18 décembre 1737 
            Le Soil (1714), considéré par beaucoup comme le meilleur instrument du monde.
            peu de temps avant sa mort il cherchait encore... 
        2. Toujours un grand merci... effectivement ça pris son temps ! Mais j'ai l'impréssion que c'est pas trop mal nettoyé tout ça... Voici le rapport :

          Excellente journée pour demain !

          Malwarebytes' Anti-Malware 1.30
          Version de la base de données: 1414
          Windows 5.1.2600 Service Pack 3

          20.11.2008 23:38:42
          mbam-log-2008-11-20 (23-38-42).txt

          Type de recherche: Examen complet (C:\|F:\|)
          Eléments examinés: 178993
          Temps écoulé: 2 hour(s), 14 minute(s), 57 second(s)

          Processus mémoire infecté(s): 4
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 15
          Valeur(s) du Registre infectée(s): 7
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 1
          Fichier(s) infecté(s): 16

          Processus mémoire infecté(s):
          C:\Program Files\WebMediaViewer\hpmon.exe (Trojan.Zlob) -> Unloaded process successfully.
          C:\Program Files\WebMediaViewer\hpmom.exe (Trojan.Zlob) -> Unloaded process successfully.
          C:\Program Files\WebMediaViewer\qttask.exe (Trojan.Zlob) -> Unloaded process successfully.
          C:\Program Files\WebMediaViewer\qttaskm.exe (Trojan.Zlob) -> Unloaded process successfully.

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          HKEY_CLASSES_ROOT\CLSID\{2eef94df-75f6-42e9-b7fb-af5a170a6e2e} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2eef94df-75f6-42e9-b7fb-af5a170a6e2e} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\CLSID\{64466b8e-20a7-4a4a-aff4-aad9ca68b52c} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64466b8e-20a7-4a4a-aff4-aad9ca68b52c} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64466b8e-20a7-4a4a-aff4-aad9ca68b52c} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{3b8fb116-d358-48a3-a5c7-db84f15cbb04} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{096cba44-4a4c-49f7-8903-1e75550abcb7} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929cd6e-2062-44a4-b2c5-2c7e78fbab38} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{53e0b6e8-a51d-448b-b692-40b67b285543} (Adware.180Solutions) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0b385ee3-ee18-4c69-bf55-6b6b406ef591} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{3b8fb116-d358-48a3-a5c7-db84f15cbb04} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\webmedia.chl (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Online Alert Manager (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IExplorer add-on (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Browser Toolbar (Trojan.Zlob) -> Quarantined and deleted successfully.

          Valeur(s) du Registre infectée(s):
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\vmware hptray (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{2eef94df-75f6-42e9-b7fb-af5a170a6e2e} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2eef94df-75f6-42e9-b7fb-af5a170a6e2e} (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{53e0b6e8-a51d-448b-b692-40b67b285543} (Adware.180Solutions) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\quicktime task (Trojan.Zlob) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus (Rogue.Antivirus) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\p2p networking (Backdoor.Bot) -> Quarantined and deleted successfully.

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          C:\Program Files\WebMediaViewer (Trojan.Zlob) -> Quarantined and deleted successfully.

          Fichier(s) infecté(s):
          C:\Program Files\WebMediaViewer\hpmon.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\hpmom.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\browseul.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\hpmun.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\browseu.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\hpmun.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\myd.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\mym.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\myp.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\myv.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\ot.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\qttask.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\qttaskm.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\qttasku.exe (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Program Files\WebMediaViewer\ts.ico (Trojan.Zlob) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Menu Démarrer\Online Antispyware Test.url (Trojan.Zlob) -> Quarantined and deleted successfully.
          1. super....
            ton virus A (aav en fait ) avait ete supprimé par smitfraud...
            mail restait pas mal de choses....

            refais 1 scan hijack stp...et colle le rapport....

            a+
            1. Hello ! Je rentre de week-end... voici le rapport Hijack :

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 20:16:28, on 23.11.2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16735)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\WINDOWS\system32\bgsvcgen.exe
              C:\Program Files\Bonjour\mDNSResponder.exe
              C:\Program Files\Fichiers communs\Motive\McciCMService.exe
              C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\RealVNC\VNC4\WinVNC4.exe
              C:\Program Files\Trend Micro\BM\TMBMSRV.exe
              C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
              C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
              C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
              C:\WINDOWS\system32\devldr32.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Program Files\Winamp\winampa.exe
              C:\Program Files\QuickHelp2\QuickHelp.exe
              C:\Program Files\iTunes\iTunesHelper.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
              F:\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
              C:\Program Files\Logitech\SetPoint\SetPoint.exe
              C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
              C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
              C:\Program Files\iPod\bin\iPodService.exe
              C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
              C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - F:\SPYBOT~1\SDHelper.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (file missing)
              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (file missing)
              O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
              O3 - Toolbar: (no name) - {2EEF94DF-75F6-42E9-B7FB-AF5A170A6E2E} - (no file)
              O3 - Toolbar: (no name) - {53E0B6E8-A51D-448B-B692-40B67B285543} - (no file)
              O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
              O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
              O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
              O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
              O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
              O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
              O4 - HKLM\..\Run: [QuickHelp2_McciTrayApp] C:\Program Files\QuickHelp2\QuickHelp.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
              O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
              O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART
              O4 - HKLM\..\Run: [ANTIVIRUS] C:\Program Files\AAV\AAV.ExE
              O4 - HKLM\..\RunOnce: [SpybotDeletingA2323] command /c del "C:\Program Files\Everest Poker\gvmain.exe"
              O4 - HKLM\..\RunOnce: [SpybotDeletingC6925] cmd /c del "C:\Program Files\Everest Poker\gvmain.exe"
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] F:\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
              O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
              O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
              O4 - Global Startup: Quick Help.lnk = C:\Program Files\Bluewin\Quick Help\bin\matcli.exe
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - F:\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://my.tcs.ch/my.logout.php3?errorcode=19#version=6020,2008,0717,1603
              O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://my.tcs.ch/my.logout.php3?errorcode=19$$/iNotes6W.cab
              O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://my.tcs.ch/my.logout.php3?errorcode=19#version=6020,2008,0717,1611
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
              O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
              O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Fichiers communs\Motive\McciCMService.exe
              O23 - Service: Composant de commande centrale Trend Micro (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
              O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
              O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
              O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
              O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
              1. greeeee....
                toujours la
                fais ceci:

                -Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
                http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
                Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                • Redémarre ton ordinateur
                • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                • Choisis ton compte.
                Déroule la liste des instructions ci-dessous :
                • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                • Appuie sur Y pour commencer le processus de nettoyage.
                • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                • Appuie sur une touche pour redémarrer le PC.
                • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum
                -a+
                Antonio Giacomo Stradivari, souvent appelé Stradivarius (Crémone, 1644 - Crémone, 18 décembre 1737 
                Le Soil (1714), considéré par beaucoup comme le meilleur instrument du monde.
                peu de temps avant sa mort il cherchait encore... 
            2. Voilà c'est fait...

              Rootkit scan 2008-11-23 21:16:35
              Windows 5.1.2600 Service Pack 3 NTFS

              scanning hidden processes ...

              scanning hidden services & system hive ...

              scanning hidden registry entries ...

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
              "TracesProcessed"=dword:0000013b

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              [b]Remaining Services [/b]:

              Authorized Application Key Export:

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
              "C:\\WINDOWS\\system32\\P2P Networking\\P2P Networking.exe"="C:\\WINDOWS\\system32\\P2P Networking\\P2P Networking.exe:*:Enabled:P2P Networking"
              "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
              "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
              "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"="C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe:*:Enabled:Logitech Desktop Messenger"
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

              [b]Remaining Files [/b]:

              [b]Files with Hidden Attributes [/b]:

              Thu 5 Aug 2004 24,448 A.SHR --- "C:\NTBOOTDD.SYS"
              Mon 14 Apr 2008 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
              Tue 11 Jul 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
              Sat 13 Nov 2004 37,376 ...H. --- "C:\Program Files\Fichiers communs\Adobe\ESD\DLMCleanup.exe"
              Sat 28 Jan 2006 484,592 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2d3de94317cec27c0fd13671114be92a\BIT21.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\63b905df19815a870a89ce42f8c36cbc\BIT1D.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\652df4481e78cf8db95f337e5e6fd06c\BIT1B.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\6b5f484130e76f990053cd368ea0c649\BIT1E.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\92187aedab601bb25548bba6adc50cc9\BIT22.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\a42f4d4aec80f787c077283561db7334\BIT1A.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\a9e93f8b9968640870c66d6cd37b81d2\BIT1F.tmp"
              Sat 28 Jan 2006 497,904 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\bec6ccdc2e87326a059fbc24a1ba98c2\BIT19.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\d34105cbc07cfc82a840c12d5e028679\BIT1C.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\1059f9fa18db5c659dd880c6bde1acd8\download\BIT2A.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\20b3cabb260cb882b3d8b497abda1f71\download\BIT2E.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\2ffcd6f975143621cd7ba191a25e7dee\download\BIT33.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\4042804c2a776995a3f497dfcca87fe6\download\BIT29.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\5d517eaaa9133b0aeaba239b1f097b26\download\BIT28.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\6070200d7a7ca14424fd0e4f019a7293\download\BIT35.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\6f2b5559e414363c0d050fcdeff24588\download\BIT38.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\7551d9aad32dabb2ef3aa5108dd69f4c\download\BIT3A.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\8f21a6fc8706e4a58a3abcb6b73de26c\download\BIT39.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\925c7afc2ba478434e358c78673b4a12\download\BIT36.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\97e754582377d850e2164a4adca20caa\download\BIT2D.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\98091b7e393d32343cd6ee6419786bb1\download\BIT2F.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\a1a09926ba55692e4bb839d62c2c1e21\download\BIT2B.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\a784624f51e504c24fcaaa117668f3b6\download\BIT25.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\aa5e30c9c629be6e595c0c04f3e98649\download\BIT31.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\c27bd89901ef6b60dcbba81071f79f35\download\BIT34.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\caba68ba086fd3fb31100e13b6c192ae\download\BIT37.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\ce8dd34f24716c36effd4f314c91c35b\download\BIT2C.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\d4a37460d445a728eedf3490051e8fa1\download\BIT27.tmp"
              Sat 28 Jan 2006 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\S-1-5-18\fda4a07ab7a56c6d4616537d15334ad6\download\BIT30.tmp"

              [b]Finished![/b]
              1. yep, voici :

                SmitFraudFix v2.376

                Rapport fait à 22:04:15.69, 23.11.2008
                Executé à partir de C:\Documents and Settings\Yves Kaltenrieder\Bureau\SmitfraudFix
                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                Le type du système de fichiers est NTFS
                Fix executé en mode normal

                »»»»»»»»»»»»»»»»»»»»»»»» Process

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\system32\bgsvcgen.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Fichiers communs\Motive\McciCMService.exe
                C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\RealVNC\VNC4\WinVNC4.exe
                C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
                C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\Winamp\winampa.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\devldr32.exe
                C:\Program Files\QuickHelp2\QuickHelp.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
                F:\Spybot - Search & Destroy\TeaTimer.exe
                C:\Program Files\Logitech\SetPoint\SetPoint.exe
                C:\Program Files\Microsoft Office\Office\WINWORD.EXE
                C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
                C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\WINDOWS\system32\cmd.exe

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Yves Kaltenrieder

                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\YVESKA~1\LOCALS~1\Temp

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Yves Kaltenrieder\Application Data

                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\YVESKA~1\Favoris

                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                o4Patch
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                IEDFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                VACFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                404Fix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"=""

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                "System"=""

                »»»»»»»»»»»»»»»»»»»»»»»» RK

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                Description: Netopia 3300 Series USB Network Adapter - Miniport d'ordonnancement de paquets
                DNS Server Search Order: 192.168.1.1

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{FD781830-46AC-414F-8161-51F40AB0CF86}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{FD781830-46AC-414F-8161-51F40AB0CF86}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS3\Services\Tcpip\..\{FD781830-46AC-414F-8161-51F40AB0CF86}: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                »»»»»»»»»»»»»»»»»»»»»»»» Fin
                1. ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                  /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

                  ---> Double-clique sur Combofix.exe
                  Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
                  Accepte en cliquant sur "Oui"

                  ---> Mets-le en langue française F
                  Tape sur la touche 1 (Yes) pour démarrer le scan.

                  /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

                  En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                  Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                  /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                  Note : Le rapport se trouve également là : C:\ComboFix.txt
              2. yep !

                ComboFix 08-11-22.02 - Yves Kaltenrieder 2008-11-23 22:42:02.1 - NTFSx86
                Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.353 [GMT 1:00]
                Lancé depuis: c:\documents and settings\Yves Kaltenrieder\Bureau\ComboFix.exe
                * Un nouveau point de restauration a été créé

                [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
                .

                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                .

                c:\documents and settings\Yves Kaltenrieder\Menu Démarrer\Programmes\VirusTrigger 2.1
                c:\documents and settings\Yves Kaltenrieder\Menu Démarrer\Programmes\VirusTrigger 2.1\VirusTrigger 2.1.lnk
                c:\program files\Seekmo Programs
                c:\windows\system32\mdm.exe
                c:\windows\system32\P2P Networking
                f:\mes documents\My Documents.url

                .
                ((((((((((((((((((((((((((((( Fichiers créés du 2008-10-23 au 2008-11-23 ))))))))))))))))))))))))))))))))))))
                .

                2008-11-23 21:03 . 2008-11-23 21:03 579,584 --a--c--- c:\windows\system32\dllcache\user32.dll
                2008-11-23 20:59 . 2008-11-23 20:59 <REP> d-------- c:\windows\ERUNT
                2008-11-23 20:53 . 2008-11-23 21:28 <REP> d-------- C:\SDFix
                2008-11-20 21:12 . 2008-11-20 21:12 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                2008-11-20 21:12 . 2008-11-20 21:12 <REP> d-------- c:\documents and settings\Yves Kaltenrieder\Application Data\Malwarebytes
                2008-11-20 21:12 . 2008-11-20 21:12 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                2008-11-20 21:12 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                2008-11-20 21:12 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                2008-11-20 19:53 . 2008-11-23 22:04 3,474 --a------ c:\windows\system32\tmp.reg
                2008-11-20 19:52 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
                2008-11-20 19:52 . 2006-04-27 16:49 288,417 --a------ c:\windows\system32\SrchSTS.exe
                2008-11-20 19:52 . 2008-10-01 14:51 87,552 --a------ c:\windows\system32\VACFix.exe
                2008-11-20 19:52 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\o4Patch.exe
                2008-11-20 19:52 . 2008-05-18 20:40 82,944 --a------ c:\windows\system32\IEDFix.exe
                2008-11-20 19:52 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\IEDFix.C.exe
                2008-11-20 19:52 . 2008-08-18 11:19 82,432 --a------ c:\windows\system32\404Fix.exe
                2008-11-20 19:52 . 2003-06-05 20:13 53,248 --a------ c:\windows\system32\Process.exe
                2008-11-20 19:52 . 2004-07-31 17:50 51,200 --a------ c:\windows\system32\dumphive.exe
                2008-11-20 19:52 . 2007-10-03 23:36 25,600 --a------ c:\windows\system32\WS2Fix.exe
                2008-11-19 18:26 . 2008-11-23 22:30 <REP> d-------- c:\documents and settings\All Users\Application Data\Trend Micro
                2008-11-19 18:26 . 2007-12-24 17:37 138,384 --a------ c:\windows\system32\drivers\tmcomm.sys
                2008-11-19 18:26 . 2007-12-24 17:37 52,496 --a------ c:\windows\system32\drivers\tmactmon.sys
                2008-11-19 18:26 . 2007-12-24 17:37 52,240 --a------ c:\windows\system32\drivers\tmevtmgr.sys
                2008-11-19 18:25 . 2008-11-20 19:25 <REP> d-------- c:\program files\Trend Micro
                2008-11-18 19:24 . 2008-11-18 19:24 423 --a------ c:\windows\wininit.ini
                2008-11-18 18:34 . 2008-11-18 19:25 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                2008-11-17 23:51 . 2008-11-18 01:22 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
                2008-11-12 18:44 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
                2008-11-12 18:43 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
                2008-10-26 12:18 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-11-23 19:56 65,536 ----a-w c:\windows\system32\drivers\CnxE2FS.bin
                2008-11-19 19:12 --------- d-----w c:\documents and settings\Yves Kaltenrieder\Application Data\Apple Computer
                2008-11-19 17:53 --------- d-----w c:\program files\Yahoo!
                2008-10-26 11:50 --------- d-----w c:\program files\eMule
                2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
                2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
                2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
                2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
                2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
                2008-08-29 08:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
                2008-08-29 07:53 61,440 ----a-w c:\windows\system32\dnssd.dll
                2008-08-26 08:11 826,368 ----a-w c:\windows\system32\wininet.dll
                2006-08-29 21:58 6,121,488 -c--a-w c:\program files\winamp524_full.exe
                .

                ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                REGEDIT4

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
                "LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-27 67128]
                "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                "OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
                "SpybotSD TeaTimer"="f:\spybot - search & destroy\TeaTimer.exe" [2008-07-07 2156368]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
                "Motive SmartBridge"="c:\progra~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe" [2005-07-29 397312]
                "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-05-29 180269]
                "WinampAgent"="c:\program files\Winamp\winampa.exe" [2006-06-21 35328]
                "OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 40960]
                "QuickHelp2_McciTrayApp"="c:\program files\QuickHelp2\QuickHelp.exe" [2007-11-02 1474048]
                "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
                "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
                "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
                "UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
                "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 c:\windows\KHALMNPR.Exe]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                "SpybotDeletingA2323"="command" [X]
                "SpybotDeletingC6925"="del" [X]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2006-01-28 110592]
                Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-27 67128]
                Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-05-21 450560]
                Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]
                Quick Help.lnk - c:\program files\Bluewin\Quick Help\bin\matcli.exe [2006-03-22 217088]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                "aux"= ctwdm32.dll
                "VIDC.MJPG"= pvmjpg21.dll

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
                "DisableMonitoring"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
                "DisableMonitoring"=dword:00000001

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                "EnableFirewall"= 0 (0x0)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                "%windir%\\system32\\sessmgr.exe"=
                "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
                "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                "c:\\Program Files\\iTunes\\iTunes.exe"=
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

                R2 McciCMService;McciCMService;"c:\program files\Fichiers communs\Motive\McciCMService.exe" [2008-05-20 303104]
                S3 MREMP50;MREMP50 NDIS Protocol Driver;\??\c:\progra~1\FICHIE~1\Motive\MREMP50.SYS [2008-05-20 19712]
                S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;\??\c:\progra~1\FICHIE~1\Motive\MREMP50a64.SYS []
                S3 MRESP50;MRESP50 NDIS Protocol Driver;\??\c:\progra~1\FICHIE~1\Motive\MRESP50.SYS [2008-05-20 18304]
                S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;\??\c:\progra~1\FICHIE~1\Motive\MRESP50a64.SYS []
                S3 ZD1211U(ZyXEL);ZyAIR G-220 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyXEL);c:\windows\system32\DRIVERS\zd1211u.sys [2006-01-28 237568]

                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c4a183e3-1c61-11dd-9890-000fcc46e749}]
                \Shell\AutoRun\command - TISSOT.exe

                *Newly Created Service* - PROCEXP90
                .
                Contenu du dossier 'Tâches planifiées'

                2008-11-18 c:\windows\Tasks\AppleSoftwareUpdate.job
                - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
                .
                - - - - ORPHELINS SUPPRIMES - - - -

                HKCU-Run-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                HKLM-Run-MMTray - c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
                HKLM-Run-mmtask - c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe
                HKLM-Run-P2P Networking - c:\windows\system32\P2P Networking\P2P Networking.exe
                HKLM-Run-ANTIVIRUS - c:\program files\AAV\AAV.ExE
                HKLM-RunOnce-<NO NAME> - (no file)

                .
                ------- Examen supplémentaire -------
                .
                uStart Page = hxxp://www.google.ch/
                uInternet Settings,ProxyOverride = 127.0.0.1;*.local
                Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

                O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
                c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
                .

                **************************************************************************

                catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-11-23 22:48:24
                Windows 5.1.2600 Service Pack 3 NTFS

                Recherche de processus cachés ...

                Recherche d'éléments en démarrage automatique cachés ...

                Recherche de fichiers cachés ...

                **************************************************************************
                .
                --------------------- DLLs chargées dans les processus actifs ---------------------

                - - - - - - - > 'winlogon.exe'(1092)
                c:\windows\system32\WgaLogon.dll
                .
                Heure de fin: 2008-11-23 22:51:54
                ComboFix-quarantined-files.txt 2008-11-23 21:50:33

                Avant-CF: 7'450'808'320 octets libres
                Après-CF: 8,186,761,216 octets libres

                161 --- E O F --- 2008-11-12 23:51:36
                1. la suite demain...
                  boulot...demain a 6heures....

                  a demain
              3. Ok bonne nuit & merci !

                A demain
                1. refais 1 scan hijack stp...

                  a+--
                  Antonio Giacomo Stradivari, souvent appelé Stradivarius (Crémone, 1644 - Crémone, 18 décembre 1737 
                  Le Soil (1714), considéré par beaucoup comme le meilleur instrument du monde.
                  peu de temps avant sa mort il cherchait encore... 
              4. Me voici de retour....

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 22:37:59, on 24.11.2008
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16735)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\system32\bgsvcgen.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Fichiers communs\Motive\McciCMService.exe
                C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\RealVNC\VNC4\WinVNC4.exe
                C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
                C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\Winamp\winampa.exe
                C:\WINDOWS\system32\devldr32.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
                C:\Program Files\Logitech\SetPoint\SetPoint.exe
                C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
                C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
                C:\Program Files\iPod\bin\iPodService.exe
                C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                C:\WINDOWS\explorer.exe
                C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (file missing)
                O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (file missing)
                O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
                O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
                O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
                O4 - HKLM\..\Run: [QuickHelp2_McciTrayApp] C:\Program Files\QuickHelp2\QuickHelp.exe
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
                O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
                O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
                O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART
                O4 - HKLM\..\Run: [ANTIVIRUS] C:\Program Files\AAV\AAV.ExE
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
                O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O4 - Global Startup: Quick Help.lnk = C:\Program Files\Bluewin\Quick Help\bin\matcli.exe
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://my.tcs.ch/my.logout.php3?errorcode=19#version=6020,2008,0717,1603
                O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://my.tcs.ch/my.logout.php3?errorcode=19$$/iNotes6W.cab
                O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://my.tcs.ch/my.logout.php3?errorcode=19#version=6020,2008,0717,1611
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Fichiers communs\Motive\McciCMService.exe
                O23 - Service: Composant de commande centrale Trend Micro (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
                1. re...
                  Fais un scan avec cet antispyware :

                  Telecharge malwarebytes + tutoriel :

                  -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                  Tu l´installes; le programme va se mettre automatiquement a jour.

                  Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

                  Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

                  Puis click sur "rechercher".

                  Laisse le scanner le pc...

                  Si des elements on ete trouvés > click sur supprimer la selection.

                  si il t´es demandé de redemarrer > click sur "yes".

                  A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

                  Copie et colle le rapport stp.

                  a+
              5. salut ! Voilà... il en a trouvé 2....

                Malwarebytes' Anti-Malware 1.30
                Version de la base de données: 1423
                Windows 5.1.2600 Service Pack 3

                25.11.2008 22:06:03
                mbam-log-2008-11-25 (22-06-03).txt

                Type de recherche: Examen complet (A:\|C:\|D:\|E:\|F:\|G:\|)
                Eléments examinés: 163995
                Temps écoulé: 1 hour(s), 52 minute(s), 8 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 0
                Valeur(s) du Registre infectée(s): 2
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 0

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Valeur(s) du Registre infectée(s):
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus (Rogue.Antivirus) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\p2p networking (Backdoor.Bot) -> Quarantined and deleted successfully.

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                (Aucun élément nuisible détecté)
                1. scan hijack stp...

                  a+--
                  Antonio Giacomo Stradivari, souvent appelé Stradivarius (Crémone, 1644 - Crémone, 18 décembre 1737 
                  Le Soil (1714), considéré par beaucoup comme le meilleur instrument du monde.
                  peu de temps avant sa mort il cherchait encore... 
              6. yep !

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 22:35:52, on 25.11.2008
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16735)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\system32\bgsvcgen.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Fichiers communs\Motive\McciCMService.exe
                C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\RealVNC\VNC4\WinVNC4.exe
                C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
                C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\Winamp\winampa.exe
                C:\Program Files\QuickHelp2\QuickHelp.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
                C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
                C:\WINDOWS\system32\devldr32.exe
                C:\Program Files\Logitech\SetPoint\SetPoint.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
                C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
                C:\Program Files\iPod\bin\iPodService.exe
                C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                C:\Program Files\Microsoft Office\Office\WINWORD.EXE
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll (file missing)
                O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll (file missing)
                O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll (file missing)
                O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
                O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
                O4 - HKLM\..\Run: [QuickHelp2_McciTrayApp] C:\Program Files\QuickHelp2\QuickHelp.exe
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
                O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
                O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
                O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
                O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                O4 - Global Startup: Quick Help.lnk = C:\Program Files\Bluewin\Quick Help\bin\matcli.exe
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://my.tcs.ch/my.logout.php3?errorcode=19#version=6020,2008,0717,1603
                O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://my.tcs.ch/my.logout.php3?errorcode=19$$/iNotes6W.cab
                O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://my.tcs.ch/my.logout.php3?errorcode=19#version=6020,2008,0717,1611
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: Google Updater Service (gusvc) - Unknown owner - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (file missing)
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Fichiers communs\Motive\McciCMService.exe
                O23 - Service: Composant de commande centrale Trend Micro (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
                1. des nouvelles de spybot et du pc stp?

                  -A+

                  -
                  Antonio Giacomo Stradivari, souvent appelé Stradivarius (Crémone, 1644 - Crémone, 18 décembre 1737 
                  Le Soil (1714), considéré par beaucoup comme le meilleur instrument du monde.
                  peu de temps avant sa mort il cherchait encore... 
              7. A vrai dire, je ne constate plus de problème depuis le passage de Combofixe. Je n'ai plus de messages d'erreur et la "security bar google" a enfin disparue... Bon la vraie Google toolbar aussi, mais c'est moi qui ai détuit le fichier dans la foulée... :-)

                A ton avis, c'est propre non ?
                1. on va voir

                  Télécharge UsbFix sur ton bureau

                  http://sd-1.archive-host.com/membres/up/116615172019703188/U­sbFix.exe

                  --> Lance l installation avec les paramètres par default

                  Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                  --> Double clic sur le raccourci UsbFix sur ton bureau

                  --> Le PC va redémarrer

                  -->Après redémarrage poste le rapport UsbFix.txt

                  Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
                  Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes

                  attendre le rapport et ensuite...

                  --------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
                  !! déconnecte toi, ferme toutes tes applications en cours et DESACTIVE TOUTES TES DEFENCES (anti-virus, antispyware, pare-feu) le temps de la manipulation : en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!

                  ---> Surtout, si tu rencontres des difficultés à ce niveau là, dis le moi avant de poursuivre...

                  Tuto ici : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                  ---------------------------------------------------------------------------------------------------------------------------------

                  Ensuite :

                  Double-clique sur C-Fix.exe (= combofix.exe ) .

                  Appuie sur une touche pour démarrer le scan .

                  Attention : n'utilise pas ta souris ni ton clavier pendant que le programme tourne. Cela pourrait figer l'ordi ---> si un message d'erreur windows apparait à un moment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer

                  Le rapport sera crée dans: C:\Combofix.txt , poste le ici stp
              8. de retour aux affaires...

                voici déjà le rappor USBfix

                -------------- UsbFix V2.413.1 ---------------

                * User : Yves Kaltenrieder - KALTOX
                * Outils mis a jours le 24/11/2008 par Chiquitine29 et Chimay8
                * Recherche effectuée à 1:34:14 le 28.11.2008
                * Windows Xp - Internet Explorer 7.0.5730.11

                --------------- [ Processus actifs ] ----------------

                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                C:\WINDOWS\system32\bgsvcgen.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Fichiers communs\Motive\McciCMService.exe
                C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\wdfmgr.exe
                C:\Program Files\RealVNC\VNC4\WinVNC4.exe
                C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
                C:\DOCUME~1\YVESKA~1\LOCALS~1\Temp\4.tmp\b2e.exe
                C:\WINDOWS\System32\alg.exe
                C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\Winamp\winampa.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\QuickHelp2\QuickHelp.exe
                C:\Program Files\iTunes\iTunesHelper.exe
                C:\Program Files\Messenger\msmsgs.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe
                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                C:\Program Files\QuickHelp2\QuickHelpBrowser.exe
                C:\Program Files\QuickHelp2\QuickHelpBrowser.exe
                C:\WINDOWS\system32\devldr32.exe
                C:\Program Files\QuickHelp2\QuickHelpBrowser.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
                C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
                C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\iPod\bin\iPodService.exe
                C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                C:\Program Files\Trend Micro\Internet Security\TmProxy.exe

                --------------- [ Informations lecteurs ] ----------------

                C: - Lecteur fixe

                F: - Lecteur fixe

                --------------- [ Lecteur C ] ----------------

                C: - Lecteur fixe

                +- Listing des fichiers présents :

                [28.01.2006 14:35][--a------] C:\AUTOEXEC.BAT
                [05.08.2004 13:00][-rahs----] C:\NTDETECT.COM
                [24.05.2001 11:59][--a------] C:\UNWISE.EXE
                [28.01.2006 14:28][---hs----] C:\boot.ini
                [24.11.2008 22:34][--a------] C:\ComboFix.txt
                [24.11.2008 22:34][--a------] C:\rapport.txt
                [24.11.2008 22:34][--a------] C:\UsbFix.txt
                [28.01.2006 14:35][--a------] C:\CONFIG.SYS
                [28.01.2006 14:35][--a------] C:\hiberfil.sys
                [28.01.2006 14:35][--a------] C:\IO.SYS
                [28.01.2006 14:35][--a------] C:\MSDOS.SYS
                [28.01.2006 14:35][--a------] C:\NTBOOTDD.SYS
                [28.01.2006 14:35][--a------] C:\pagefile.sys

                --------------- [ Lecteur F ] ----------------

                F: - Lecteur fixe

                +- Listing des fichiers présents :

                [01.03.1999 14:11][--a------] F:\pngsetup.exe
                [01.03.1999 14:11][--a------] F:\eMule0.49b-Installer1.exe

                --------------- [ Registre / Startup ] ----------------

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

                [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
                LDM=C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
                OM_Monitor=C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
                OE="C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
                swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
                Adobe Photo Downloader="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                Motive SmartBridge=C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
                Logitech Hardware Abstraction Layer=KHALMNPR.EXE
                TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                WinampAgent=C:\Program Files\Winamp\winampa.exe
                OM_Monitor=C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
                QuickHelp2_McciTrayApp=C:\Program Files\QuickHelp2\QuickHelp.exe
                QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
                AppleSyncNotifier=C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
                UfSeAgnt.exe="C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
                MMTray="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
                mmtask="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
                HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
                Installed=1
                HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
                NoChange=1
                Installed=1
                HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
                Installed=1

                --------------- [ Registre / Mountpoint2 ] ----------------

                Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c4a183e3-1c61-11dd-9890-000fcc46e749}\Shell\AutoRun\command

                --------------- [ Nettoyage des disques ] ----------------

                Supprimé ! - [23.11.2008 22:04][--a------] C:\WINDOWS\system32\tmp.reg
                Supprimé ! - [23.11.2008 22:04][--a------] C:\WINDOWS\system32\tmp.txt

                --------------- [ Resumé ] ----------------

                -> /!\ Le resultat doit etre interprété par un spécialiste /!\

                [28.01.2006 14:35][--a------] C:\AUTOEXEC.BAT
                [05.08.2004 13:00][-rahs----] C:\NTDETECT.COM
                [24.05.2001 11:59][--a------] C:\UNWISE.EXE
                [28.01.2006 14:28][---hs----] C:\boot.ini
                [01.03.1999 14:11][--a------] F:\pngsetup.exe
                [01.03.1999 14:11][--a------] F:\eMule0.49b-Installer1.exe

                --------------- ! Fin du rapport ! ----------------
                1. et le combofix

                  ComboFix 08-11-22.02 - Yves Kaltenrieder 2008-11-28 1:47:08.3 - NTFSx86
                  Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.390 [GMT 1:00]
                  Lancé depuis: c:\documents and settings\Yves Kaltenrieder\Bureau\ComboFix.exe

                  [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
                  .

                  ((((((((((((((((((((((((((((( Fichiers créés du 2008-10-28 au 2008-11-28 ))))))))))))))))))))))))))))))))))))
                  .

                  2008-11-28 01:29 . 2008-11-28 01:37 <REP> d-------- c:\program files\UsbFix
                  2008-11-25 22:56 . 2008-11-25 22:56 <REP> d-------- c:\program files\Google
                  2008-11-23 21:03 . 2008-11-23 21:03 579,584 --a--c--- c:\windows\system32\dllcache\user32.dll
                  2008-11-23 20:59 . 2008-11-23 20:59 <REP> d-------- c:\windows\ERUNT
                  2008-11-23 20:53 . 2008-11-23 21:28 <REP> d-------- C:\SDFix
                  2008-11-20 21:12 . 2008-11-25 20:11 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                  2008-11-20 21:12 . 2008-11-20 21:12 <REP> d-------- c:\documents and settings\Yves Kaltenrieder\Application Data\Malwarebytes
                  2008-11-20 21:12 . 2008-11-20 21:12 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                  2008-11-20 21:12 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                  2008-11-20 21:12 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                  2008-11-20 19:52 . 2007-09-05 23:22 289,144 --a------ c:\windows\system32\VCCLSID.exe
                  2008-11-20 19:52 . 2006-04-27 16:49 288,417 --a------ c:\windows\system32\SrchSTS.exe
                  2008-11-20 19:52 . 2008-10-01 14:51 87,552 --a------ c:\windows\system32\VACFix.exe
                  2008-11-20 19:52 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\o4Patch.exe
                  2008-11-20 19:52 . 2008-05-18 20:40 82,944 --a------ c:\windows\system32\IEDFix.exe
                  2008-11-20 19:52 . 2008-10-10 07:58 82,944 --a------ c:\windows\system32\IEDFix.C.exe
                  2008-11-20 19:52 . 2008-08-18 11:19 82,432 --a------ c:\windows\system32\404Fix.exe
                  2008-11-20 19:52 . 2003-06-05 20:13 53,248 --a------ c:\windows\system32\Process.exe
                  2008-11-20 19:52 . 2004-07-31 17:50 51,200 --a------ c:\windows\system32\dumphive.exe
                  2008-11-20 19:52 . 2007-10-03 23:36 25,600 --a------ c:\windows\system32\WS2Fix.exe
                  2008-11-19 18:26 . 2008-11-23 22:30 <REP> d-------- c:\documents and settings\All Users\Application Data\Trend Micro
                  2008-11-19 18:26 . 2007-12-24 17:37 138,384 --a------ c:\windows\system32\drivers\tmcomm.sys
                  2008-11-19 18:26 . 2007-12-24 17:37 52,496 --a------ c:\windows\system32\drivers\tmactmon.sys
                  2008-11-19 18:26 . 2007-12-24 17:37 52,240 --a------ c:\windows\system32\drivers\tmevtmgr.sys
                  2008-11-19 18:25 . 2008-11-20 19:25 <REP> d-------- c:\program files\Trend Micro
                  2008-11-18 19:24 . 2008-11-18 19:24 423 --a------ c:\windows\wininit.ini
                  2008-11-18 18:34 . 2008-11-24 00:34 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                  2008-11-17 23:51 . 2008-11-18 01:22 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
                  2008-11-12 18:44 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
                  2008-11-12 18:43 . 2008-09-04 18:16 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2008-11-28 00:34 65,536 ----a-w c:\windows\system32\drivers\CnxE2FS.bin
                  2008-11-19 19:12 --------- d-----w c:\documents and settings\Yves Kaltenrieder\Application Data\Apple Computer
                  2008-11-19 17:53 --------- d-----w c:\program files\Yahoo!
                  2008-10-26 11:50 --------- d-----w c:\program files\eMule
                  2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
                  2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
                  2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
                  2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
                  2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
                  2008-08-29 08:18 87,336 ----a-w c:\windows\system32\dns-sd.exe
                  2008-08-29 07:53 61,440 ----a-w c:\windows\system32\dnssd.dll
                  2006-08-29 21:58 6,121,488 -c--a-w c:\program files\winamp524_full.exe
                  .

                  ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                  REGEDIT4

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
                  "LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-03-27 67128]
                  "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                  "OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2006-05-16 57344]
                  "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-25 39408]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
                  "Motive SmartBridge"="c:\progra~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe" [2005-07-29 397312]
                  "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-05-29 180269]
                  "WinampAgent"="c:\program files\Winamp\winampa.exe" [2006-06-21 35328]
                  "OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2006-05-16 40960]
                  "QuickHelp2_McciTrayApp"="c:\program files\QuickHelp2\QuickHelp.exe" [2007-11-02 1474048]
                  "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
                  "AppleSyncNotifier"="c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
                  "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
                  "UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2008-07-29 1398024]
                  "MMTray"="c:\program files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [BU]
                  "mmtask"="c:\program files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [BU]
                  "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-05-20 c:\windows\KHALMNPR.Exe]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                  c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                  Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2006-01-28 110592]
                  Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2007-03-27 67128]
                  Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-05-21 450560]
                  Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2000-01-21 65588]
                  Quick Help.lnk - c:\program files\Bluewin\Quick Help\bin\matcli.exe [2006-03-22 217088]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                  "aux"= ctwdm32.dll
                  "VIDC.MJPG"= pvmjpg21.dll

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendAntiVirus]
                  "DisableMonitoring"=dword:00000001

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\TrendFirewall]
                  "DisableMonitoring"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                  "c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
                  "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                  "c:\\Program Files\\iTunes\\iTunes.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

                  R2 McciCMService;McciCMService;"c:\program files\Fichiers communs\Motive\McciCMService.exe" [2008-05-20 303104]
                  S3 MREMP50;MREMP50 NDIS Protocol Driver;\??\c:\progra~1\FICHIE~1\Motive\MREMP50.SYS [2008-05-20 19712]
                  S3 MREMP50a64;MREMP50a64 NDIS Protocol Driver;\??\c:\progra~1\FICHIE~1\Motive\MREMP50a64.SYS []
                  S3 MRESP50;MRESP50 NDIS Protocol Driver;\??\c:\progra~1\FICHIE~1\Motive\MRESP50.SYS [2008-05-20 18304]
                  S3 MRESP50a64;MRESP50a64 NDIS Protocol Driver;\??\c:\progra~1\FICHIE~1\Motive\MRESP50a64.SYS []
                  S3 ZD1211U(ZyXEL);ZyAIR G-220 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyXEL);c:\windows\system32\DRIVERS\zd1211u.sys [2006-01-28 237568]
                  .
                  Contenu du dossier 'Tâches planifiées'

                  2008-11-25 c:\windows\Tasks\AppleSoftwareUpdate.job
                  - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
                  .
                  .
                  ------- Examen supplémentaire -------
                  .
                  uInternet Settings,ProxyOverride = 127.0.0.1;*.local
                  Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll

                  O16 -: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
                  c:\windows\Downloaded Program Files\Microsoft XML Parser for Java.osd
                  .

                  **************************************************************************

                  catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2008-11-28 01:51:44
                  Windows 5.1.2600 Service Pack 3 NTFS

                  Recherche de processus cachés ...

                  Recherche d'éléments en démarrage automatique cachés ...

                  Recherche de fichiers cachés ...

                  **************************************************************************
                  .
                  --------------------- DLLs chargées dans les processus actifs ---------------------

                  - - - - - - - > 'winlogon.exe'(1092)
                  c:\windows\system32\WgaLogon.dll
                  .
                  Heure de fin: 2008-11-28 1:55:17
                  ComboFix-quarantined-files.txt 2008-11-28 00:53:54
                  ComboFix2.txt 2008-11-24 21:34:31
                  ComboFix3.txt 2008-11-23 21:51:58

                  Avant-CF: 7'652'155'392 octets libres
                  Après-CF: 7,647,158,272 octets libres

                  140 --- E O F --- 2008-11-12 23:51:36
                  1. hijack stp?

                    a+
                2. voici :

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 10:55:59, on 28.11.2008
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16735)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\WINDOWS\system32\bgsvcgen.exe
                  C:\Program Files\Bonjour\mDNSResponder.exe
                  C:\Program Files\Fichiers communs\Motive\McciCMService.exe
                  C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\RealVNC\VNC4\WinVNC4.exe
                  C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                  C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
                  C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                  C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\Program Files\Winamp\winampa.exe
                  C:\Program Files\QuickHelp2\QuickHelp.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
                  C:\WINDOWS\system32\devldr32.exe
                  C:\Program Files\Logitech\SetPoint\SetPoint.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
                  C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                  C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                  C:\Program Files\internet explorer\iexplore.exe
                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                  O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                  O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                  O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\MotiveSB.exe
                  O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
                  O4 - HKLM\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\FirstStart.exe
                  O4 - HKLM\..\Run: [QuickHelp2_McciTrayApp] C:\Program Files\QuickHelp2\QuickHelp.exe
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
                  O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
                  O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
                  O4 - HKLM\..\Run: [MsgCenterExe] "C:\Program Files\Fichiers communs\Real\Update_OB\RealOneMessageCenter.exe" -osboot
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [OM_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master\Monitor.exe
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                  O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                  O4 - Global Startup: Quick Help.lnk = C:\Program Files\Bluewin\Quick Help\bin\matcli.exe
                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                  O16 - DPF: {2A0B9B82-D5C8-4D3D-8338-AD55B23662B1} (F5 Networks CacheCleaner) - https://my.tcs.ch/my.logout.php3?errorcode=19#version=6020,2008,0717,1603
                  O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://my.tcs.ch/my.logout.php3?errorcode=19$$/iNotes6W.cab
                  O16 - DPF: {45B69029-F3AB-4204-92DE-D5140C3E8E74} (F5 Networks Auto Update) - https://my.tcs.ch/my.logout.php3?errorcode=19#version=6020,2008,0717,1611
                  O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                  O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\WINDOWS\system32\bgsvcgen.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Fichiers communs\Motive\McciCMService.exe
                  O23 - Service: Composant de commande centrale Trend Micro (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
                  O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
                  O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
                  O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
                  O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4.exe
                  1. c est bon
                    mais fait ca pour voir

                    Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
                    https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                    * Lance l'installation du programme en exécutant le fichier téléchargé.
                    * Double-clique maintenant sur le raccourci de Toolbar-S&D.
                    * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                    * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                    * Poste le rapport généré. (C:\TB.txt)
                    a+
                3. yep !

                  -----------\\ ToolBar S&D 1.2.5 XP/Vista

                  Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                  X86-based PC ( Uniprocessor Free : AMD Athlon(tm) Processor )
                  BIOS : Award Medallion BIOS v6.0
                  USER : Yves Kaltenrieder ( Administrator )
                  BOOT : Normal boot
                  Antivirus : Trend Micro Internet Security 16.10.1183 (Activated)
                  Firewall : Pare-feu personnel de Trend Micro 5.2 (Activated)
                  A:\ (USB)
                  C:\ (Local Disk) - NTFS - Total:28 Go (Free:7 Go)
                  D:\ (CD or DVD)
                  E:\ (CD or DVD)
                  F:\ (Local Disk) - FAT32 - Total:298 Go (Free:276 Go)

                  "C:\ToolBar SD" ( MAJ : 20-11-2008|20:25 )
                  Option : [1] ( 28.11.2008|11:42 )

                  -----------\\ Recherche de Fichiers / Dossiers ...

                  -----------\\ [..\Internet Explorer\Main]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                  "Local Page"="C:\\windows\\system32\\blank.htm"
                  "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                  "Start Page"="https://www.google.ch/?gws_rd=ssl"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                  "Local Page"="C:\\windows\\system32\\blank.htm"
                  "Start Page"="https://www.msn.com/fr-fr"

                  --------------------\\ Recherche d'autres infections

                  Aucune autre infection trouvée !

                  1 - "C:\ToolBar SD\TB_1.txt" - 28.11.2008|11:46 - Option : [1]

                  -----------\\ Fin du rapport a 11:46:32.68
                  1. ok c est bon....

                    plus de problèmes ?

                    A+--
                    Antonio Giacomo Stradivari, souvent appelé Stradivarius (Crémone, 1644 - Crémone, 18 décembre 1737 
                    Le Soil (1714), considéré par beaucoup comme le meilleur instrument du monde.
                    peu de temps avant sa mort il cherchait encore... 
                • 1
                • 2