Svchost.exe+defragsys.exe infectés par un TRJ

servillee -  
serville Messages postés 102 Statut Membre -
Bonjour,

Après avoir désinfecté un portable de plus de 20000 fichiers infectés (si si! +20 000...!!!), Avast détecte encore dans Windows et System32 des chevaux de troie dans C:\WINDOWS\pss\svchost.exeCommon Startup et c:\windows\system32\defragsys.exe.
Dois-je les supprimer ou les mettre en quarantaine?
Sinon, que puis-je faire?
Merci à tous.
Configuration: Windows XP
Internet Explorer 6.0

17 réponses

Résumé de la discussion

Le fil décrit une infection présumée sur Windows XP où Avast signale des trojans dans le dossier System32 et dans un chemin Common Startup, notamment svchost.exeCommon Startup et defragsys.exe. Plusieurs réponses recommandent de mettre à jour les définitions, de redémarrer en mode sans échec et de relancer un balayage avec Malwarebytes, puis d’analyser les résultats via HijackThis et les rapports de suppression. Outils complémentaires comme HijackThis et ComboFix ont été utilisés pour identifier et nettoyer des éléments malveillants, avec des notes sur les entrées de registre et des programmes de démarrage douteux et sur des restes rootkits.

Bobot (l'IA à votre service)
  1. totobetourne Messages postés 5677 Statut Membre 65
     
    bonjour

    telecharge cela:util pour voir ce que peut etre l infection et agir ensuite.

    http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

    installe le normallement comme tout autre programme dans c/programme/...............
    clique sur do a scan and save a logfile, tu obtiens un rapport que tu colles.
    parfois alerte comme quoi, sans la fonction administrateur le rapport ne peut pas etre complet .
    a ce moment relance hijack avec un clique droit sur le raccourci et executer en tant qu administrateur.
    0
    1. servillee
       
      bonjour,

      Voici le rapport HIjacktis.

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 13:04:51, on 23/11/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
      C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://fr.yahoo.com/fsc/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S85.tmp" /EF "HKLM"
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
      O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrôle d'AcDcToday) - file://C:\Program Files\AutoCAD LT 2002 Fra\AcDcToday.ocx
      O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
      O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
      0
  2. totobetourne Messages postés 5677 Statut Membre 65
     
    a priori rien sur ton hijack.

    on va passer cet antimlaware , garde le et passe un scan de temp en temps.
    passe cet antimalware, fait comme indique
    Telecharges malwaresbytes antimalwares(MBAM) : egalement tres util sur pb de pub mais pas tous malheureusement

    Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
    fais comme indique,mise a jour , scan complet en mode sans echec et les rapports.

    garde le et lance un scan tout les mois comme indique.

    si tu as ad aware tu peux desinstalle car il ne reconnait plus grand chose.
    0
  3. serville Messages postés 102 Statut Membre 12
     
    merci,

    j'ai executé malware, et il annonce que b.exe (dans windows) est infecté. sois je le supp? Concernant les fichiers que Avast reconnait comme virus dans windows ou system32, est ce des vrais virus ou dois-je les supp?

    voici les fichiers : c:\windows\pss\svchost.execommon startup
    c:\windows\system32\defragsys.exe
    c:\windows\system32\hldrrr.exe
    c:\windows\system32\??sembly\msconfig.exe

    En attendant merci b<cp pour tes conseils. Concernant ad aware, je ne l'utilise plus non plus car je trouve wqu'il prend bcp de mémoire pour fonctionner.

    En tout cas, je vais de tps en tps lancé malware... ça ne lui fera pas de mal...lol. Et comme j'ai installé avast car malheureusmt, ce pc n'avait pas d'antivirus, je pense que les utilisateurs serons moins embêtés.

    Merci enciore
    0
  4. totobetourne Messages postés 5677 Statut Membre 65
     
    as tu bien regarde le tuto de malwarebyte tout est indique comment bien l utiliser.
    ici il faut nous coller les rapports.

    on fera apres malwarebyte car tu as une infection bagle a priori a elimine en premier.

    vire les cracks de ton pc si tu en as.

    et ensuite passe cela:
    Télécharges FindyKill de Chiquitine29

    Fais un clique droit sur le lien et choisis "enregistrer la cible sous ...." , destination le bureau .

    http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

    Note importante : si tu as le prg Elibagla sur ton PC , supprimes le ( risque de conflit entre les deux outils ) .

    --> Entre dans le dossier " FindyKill "

    Double clic sur " FindyKill.bat " (et pas sur autre chose!) pour lancer l'outil .

    ->choisis l'option 1 . Puis laisses travailler ...

    Une fois terminé, postes le rapport FindyKill.txt qui est généré ...

    ( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )
    0
    1. serville Messages postés 102 Statut Membre 12
       
      dsl totobetourne,

      Effectivement, j'avais pas compris tout le didacticiel.

      Je vais donc revoir tout ça... mais malheureusement pas ce soir. Le pc ne m'appartenant pas, je vais devoir le rendre et je ne sais pas quand je le récupèrerai pour terminer les^procédures de désinfection du pc.

      Ne cloture pas le topic... j'y reviendrai sans faute et je te posterai les résultats.

      Merci d'avance.Et bonne continuation dans l'attente de tes conseils.

      A bientôt et surtout ne cloture pas la discussion.

      Mer<i encore.
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. totobetourne Messages postés 5677 Statut Membre 65
     
    tres bien ecris moi je ne peux pas fermer le topic de toute manniere.
    colle le rapport de findykill en option 1.
    0
  7. serville Messages postés 102 Statut Membre 12
     
    Bonjour,

    Me revoilà de retour avec le protable infecté. J'ai repris la procédure et j'ai lancé findykill comme préconisé. Voici le rapport comme convenu.

    ----------------- FindyKill V4.706 ------------------

    * User : fuji - NOM-87CE7A529A6
    * Emplacement : C:\Program Files\FindyKill
    * Outils Mis a jours le 27/11/08 par Chiquitine29
    * Recherche effectuée à 11:19:46 le 02/12/2008
    * Windows XP - Internet Explorer 6.0.2900.2180

    ((((((((((((((((( *** Recherche *** ))))))))))))))))))

    --------------- [ Processus actifs ] ----------------

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\System32\alg.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE

    --------------- [ Fichiers/Dossiers infectieux ] ----------------

    »»»» Presence des fichiers dans C:

    »»»» Presence des fichiers dans C:\WINDOWS

    »»»» Presence des fichiers dans C:\WINDOWS\Prefetch

    »»»» Presence des fichiers dans C:\WINDOWS\system32

    Found ! [21/11/2008 15:19] - C:\WINDOWS\system32\ban_list.txt

    »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

    »»»» Presence des fichiers dans C:\Documents and Settings\fuji\Application Data

    »»»» Presence des fichiers dans C:\DOCUME~1\fuji\LOCALS~1\Temp

    »»»» Presence des fichiers dans C:\Documents and Settings\fuji\Local Settings\Temporary Internet Files\Content.IE5

    --------------- [ Registre / Startup ] ----------------

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

    ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
    EPSON Stylus DX7400 Series=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S8B.tmp" /EF "HKCU"

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

    EPSON Stylus DX4000 Series=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S85.tmp" /EF "HKLM"
    KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
    avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    RealTray=C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
    Installed=1
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
    Installed=1
    NoChange=1
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
    Installed=1

    --------------- [ Registre / Clés infectieuses ] ----------------

    Found ! - HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_HOOK

    --------------- [ Etat / Services ] ----------------

    Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

    - sans echec non fonctionnel !!

    Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

    - sans echec non fonctionnel !!

    +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

    /!\ Ndisuio - Type de démarrage = 4

    /!\ Ip6Fw - Type de démarrage = 4

    SharedAccess - Type de démarrage = 2

    wuauserv - Type de démarrage = 2

    wscsvc - Type de démarrage = 2

    --------------- [ Recherche dans supports amovibles] ----------------

    +- Informations :

    C: - Lecteur fixe

    F: - Lecteur fixe

    +- Contenu de l'autorun : F:\autorun.inf

    [autorun]
    icon = .\mxoicon6.ico

    +- presence des fichiers :

    Found ! [10/05/2007 08:48][--a------] - F:\autorun.inf

    --------------- [ Registre / Mountpoint2 ] ----------------

    Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{03093472-7587-11db-a656-0014a540b5ff}\Shell\AutoRun\command
    Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3a1a5154-78fe-11dd-a8a8-0014a540b5ff}\Shell\AutoRun\command
    Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{688b1948-fa0a-11db-a733-0014a540b5ff}\Shell\AutoRun\command
    Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{99cfaa2a-def6-11db-a71c-0014a540b5ff}\Shell\AutoRun\command
    Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ce4e6e84-a6e4-11db-a6d7-0014a540b5ff}\Shell\AutoRun\command
    Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ce7dfa14-7d4f-11db-a667-0014a540b5ff}\Shell\AutoRun\command
    Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cf42bc45-fdfb-11db-a736-0014a540b5ff}\Shell\AutoRun\command
    Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d1c59ecc-e1d0-11da-a5e9-0014a540b5ff}\Shell\AutoRun\command

    ------------------- ! Fin du rapport ! --------------------

    J'attends la suite de la procédure.
    Merci d'avance et à tt' à l'heure.
    0
  8. totobetourne Messages postés 5677 Statut Membre 65
     
    de retour

    Réouvre FindyKill , choisi cette fois ci l option 2 (Suppression)

    /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage terminé"

    -------> ensuite post le rapport FindyKill.txt

    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
    0
  9. serville Messages postés 102 Statut Membre 12
     
    Hello,

    Voici le rapport findykill après execution de l'option 2.

    Merci d'avance pour la suite.

    Petites précisions peut être utiles : l'ordi ne veut plus démarrer en mode sans echec et il ne m'est plus possible de réactiver la restauration du système. (on ne sait jamais)

    ----------------- FindyKill V4.706 ------------------

    * User : fuji - NOM-87CE7A529A6
    * executed from : C:\Program Files\FindyKill
    * Update on 27/11/08 par Chiquitine29
    * Start at 11:06:11 the 05/12/2008
    * Windows XP - Internet Explorer 7.0.5730.13

    ((((((((((((((( *** deleting *** ))))))))))))))))))

    --------------- [ Active Processes ] ----------------

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\logonui.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\userinit.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\WINDOWS\system32\fxssvc.exe

    --------------- [ Infected files / folders ] ----------------

    »»»» Supression files in C:

    Deleted ! - C:\InfoSat.txt

    »»»» Supression files in C:\WINDOWS

    »»»» Supression files in C:\WINDOWS\Prefetch

    »»»» Supression files in C:\WINDOWS\system32

    »»»» Supression files in C:\WINDOWS\system32\drivers

    »»»» Supression files in C:\Documents and Settings\fuji\Application Data

    »»»» Supression files in C:\DOCUME~1\fuji\LOCALS~1\Temp

    »»»» Supression files in C:\Documents and Settings\fuji\Local Settings\Temporary Internet Files\Content.IE5

    --------------- [ Registry / Infected keys ] ----------------

    Deleted ! - HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_HOOK

    --------------- [ States / Restarting of services ] ----------------

    +- Services : [ Auto=2 / Request=3 / Disable=4 ]

    Ndisuio - Type of startup = 3

    EapHost - Type of startup = 2

    Ip6Fw - Type of startup = 2

    SharedAccess - Type of startup = 2

    wuauserv - Type of startup = 2

    wscsvc - Type of startup = 2

    --------------- [ Cleaning removable drives ] ----------------

    +- Informations :

    C: - Lecteur fixe

    +- deleting files :

    --------------- [ Registry / Mountpoint2 ] ----------------

    Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{03093472-7587-11db-a656-0014a540b5ff}\Shell\AutoRun\command
    Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3a1a5154-78fe-11dd-a8a8-0014a540b5ff}\Shell\AutoRun\command
    Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{688b1948-fa0a-11db-a733-0014a540b5ff}\Shell\AutoRun\command
    Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{99cfaa2a-def6-11db-a71c-0014a540b5ff}\Shell\AutoRun\command
    Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ce4e6e84-a6e4-11db-a6d7-0014a540b5ff}\Shell\AutoRun\command
    Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ce7dfa14-7d4f-11db-a667-0014a540b5ff}\Shell\AutoRun\command
    Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cf42bc45-fdfb-11db-a736-0014a540b5ff}\Shell\AutoRun\command
    Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{d1c59ecc-e1d0-11da-a5e9-0014a540b5ff}\Shell\AutoRun\command

    --------------- [ Searching Cracks / Keygen ] ----------------

    ---------------- ! End of report ! ------------------
    0
    1. serville Messages postés 102 Statut Membre 12
       
      Jed me suis aperçu que Elibagla était installé sur l'ordi. J'ai supprimé l'"application et relancé l'option 2 de findykill. Voici le nouveau rapport.

      ----------------- FindyKill V4.706 ------------------

      * User : fuji - NOM-87CE7A529A6
      * executed from : C:\Program Files\FindyKill
      * Update on 27/11/08 par Chiquitine29
      * Start at 11:49:29 the 05/12/2008
      * Windows XP - Internet Explorer 7.0.5730.13


      ((((((((((((((( *** deleting *** ))))))))))))))))))


      --------------- [ Active Processes ] ----------------


      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\logonui.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\userinit.exe

      --------------- [ Infected files / folders ] ----------------


      »»»» Supression files in C:

      Deleted ! - C:\InfoSat.txt

      »»»» Supression files in C:\WINDOWS


      »»»» Supression files in C:\WINDOWS\Prefetch


      »»»» Supression files in C:\WINDOWS\system32


      »»»» Supression files in C:\WINDOWS\system32\drivers


      »»»» Supression files in C:\Documents and Settings\fuji\Application Data


      »»»» Supression files in C:\DOCUME~1\fuji\LOCALS~1\Temp


      »»»» Supression files in C:\Documents and Settings\fuji\Local Settings\Temporary Internet Files\Content.IE5


      --------------- [ Registry / Infected keys ] ----------------


      --------------- [ States / Restarting of services ] ----------------



      +- Services : [ Auto=2 / Request=3 / Disable=4 ]

      Ndisuio - Type of startup = 3

      EapHost - Type of startup = 2

      Ip6Fw - Type of startup = 2

      SharedAccess - Type of startup = 2

      wuauserv - Type of startup = 2

      wscsvc - Type of startup = 2


      --------------- [ Cleaning removable drives ] ----------------

      +- Informations :

      C: - Lecteur fixe


      +- deleting files :


      --------------- [ Registry / Mountpoint2 ] ----------------


      -> Not found !


      --------------- [ Searching Cracks / Keygen ] ----------------



      ---------------- ! End of report ! ------------------
      0
      1. serville Messages postés 102 Statut Membre 12 > serville Messages postés 102 Statut Membre
         
        J'ai repassé uin h



        ijackthis, voici le rapport :

        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S85.tmp" /EF "HKLM"
        O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
        O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S8B.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Auto EPSON Stylus DX7400 Series sur SERVILLE] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S33.tmp" /EF "HKCU"
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
        O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
        O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrôle d'AcDcToday) - file://C:\Program Files\AutoCAD LT 2002 Fra\AcDcToday.ocx
        0
      2. serville Messages postés 102 Statut Membre 12 > serville Messages postés 102 Statut Membre
         
        dsl, mauvaise manip.
        Voici le rapport :
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 16:19:30, on 05/12/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16735)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S85.tmp" /EF "HKLM"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S8B.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Auto EPSON Stylus DX7400 Series sur SERVILLE] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S33.tmp" /EF "HKCU"
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
        O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
        O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrôle d'AcDcToday) - file://C:\Program Files\AutoCAD LT 2002 Fra\AcDcToday.ocx
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        0
      3. serville Messages postés 102 Statut Membre 12 > serville Messages postés 102 Statut Membre
         
        Voici le rapport mAntimalware après suppression d'un rootkit:

        alwarebytes' Anti-Malware 1.31
        Version de la base de données: 1463
        Windows 5.1.2600 Service Pack 3

        05/12/2008 18:19:19
        mbam-log-2008-12-05 (18-19-19).txt

        Type de recherche: Examen complet (C:\|)
        Eléments examinés: 107413
        Temps écoulé: 45 minute(s), 19 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 1
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 0

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\poof (Rootkit.Agent) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Voici également le rapport hijtkis après cette suppression :

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:25:51, on 05/12/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16735)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
        O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S85.tmp" /EF "HKLM"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S8B.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [Auto EPSON Stylus DX7400 Series sur SERVILLE] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S33.tmp" /EF "HKCU"
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
        O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
        O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrôle d'AcDcToday) - file://C:\Program Files\AutoCAD LT 2002 Fra\AcDcToday.ocx
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        0
  10. totobetourne Messages postés 5677 Statut Membre 65
     
    passe maintenant malwarebyte comme indique, lis bien le tuto.colle le rapport apres suppression.
    0
    1. serville Messages postés 102 Statut Membre 12
       
      Merci,

      Malheureusement, l'ordi ne veut pas démarrer en mode sans échec. Il met très rapidement un message du genre "un problème s'est...." sur écran bleu. Mais là non plus, je n'ai pas le temps de le lire et il reboote tout seul. Du coup, je suis bloqué pour suivre la procédure malwarebytes.
      Par contre j'ai récupéré la possibilité de desactiver ou d'activer la restauration du systeme. Maintenant, je l'ai desactivé.
      Et j'ai installé Avast.
      Que puis-je faire maintenant?

      Voici le nouveau log d'Hijackthis :
      0
  11. totobetourne Messages postés 5677 Statut Membre 65
     
    lance le alors en mode normal fait comme indique.
    0
    1. serville Messages postés 102 Statut Membre 12
       
      Voici le rapport mAntimalware après suppression d'un rootkit:

      alwarebytes' Anti-Malware 1.31
      Version de la base de données: 1463
      Windows 5.1.2600 Service Pack 3

      05/12/2008 18:19:19
      mbam-log-2008-12-05 (18-19-19).txt

      Type de recherche: Examen complet (C:\|)
      Eléments examinés: 107413
      Temps écoulé: 45 minute(s), 19 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 1
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 0

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\poof (Rootkit.Agent) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Voici également le rapport hijtkis après cette suppression :

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 18:25:51, on 05/12/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16735)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S85.tmp" /EF "HKLM"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S8B.tmp" /EF "HKCU"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Auto EPSON Stylus DX7400 Series sur SERVILLE] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S33.tmp" /EF "HKCU"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
      O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrôle d'AcDcToday) - file://C:\Program Files\AutoCAD LT 2002 Fra\AcDcToday.ocx
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      End of file - 4936 bytes

      Faut il à ton avis faire d'autres manip?

      Merci d'avance
      0
  12. totobetourne Messages postés 5677 Statut Membre 65
     
    le mode sans echec toujours impossible ou pas?si tu peux y passer relance un scan de malwarebyte mais avant tout cela refais bien une mise a jour.
    0
  13. serville Messages postés 102 Statut Membre 12
     
    Le mode sans echec est toujours impossible.... malheureusement.
    0
  14. totobetourne Messages postés 5677 Statut Membre 65
     
    c est etrange car l infection bagle enlever avec findykill doit te remettre le mode sans echec fonctionnel.
    il doit en rester une partie qu on n arrive pas a cerner.

    passe cet outil, il reconnait egalement bagle on va voir ce que donne le rapport.fait bien comme indique

    pour voir télécharge combofix (par sUBs) ici :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    et enregistre le sur le bureau.

    déconnecte toi d'internet et ferme toutes tes applications.

    désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

    double-clique sur combofix.exe et suis les instructions

    à la fin, il va produire un rapport C:\ComboFix.txt

    réactive ton parefeu, ton antivirus, la garde de ton antispyware

    copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

    Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

    Tu as un tutoriel complet ici :

    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
    0
    1. serville Messages postés 102 Statut Membre 12
       
      bonjour,

      voilà le log après passage de combofix

      ComboFix 08-12-09.02 - fuji 2008-12-10 9:38:17.1 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.674 [GMT 1:00]
      Lancé depuis: c:\documents and settings\fuji\Bureau\ComboFix.exe
      * Un nouveau point de restauration a été créé
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\fuji\ravmonlog
      c:\program files\curity~1
      c:\program files\Fichiers communs\{342CC~1
      c:\program files\Fichiers communs\{342CC~1\Uninst.exe
      c:\program files\Fichiers communs\{B42CC~1
      c:\program files\Internet Explorer\iekey.dll
      c:\program files\printview
      c:\windows\b.exe
      c:\windows\system32\plugin1.dat
      c:\windows\system32\rnaph.dll
      c:\windows\system32\sembly~1
      c:\windows\system32\sembly~1\??sembly\
      c:\windows\system32\sembly~1\msconfig.exe
      c:\windows\system32\taskkill.exe
      c:\windows\system32\wnsintsv.exe

      .
      ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Legacy_BOONTY_GAMES
      -------\Service_Boonty Games


      ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-10 au 2008-12-10 ))))))))))))))))))))))))))))))))))))
      .

      2008-12-09 15:41 . 2008-12-09 15:41 <REP> d-------- c:\windows\system32\LogFiles
      2008-12-05 10:08 . 2008-12-05 10:08 10,108,116 --a------ C:\upload_moi_NOM-87CE7A529A6.tar.gz
      2008-12-04 15:04 . 2008-12-04 15:04 <REP> d-------- c:\windows\system32\fr
      2008-12-04 15:04 . 2008-12-04 15:04 <REP> d-------- c:\windows\system32\bits
      2008-12-04 15:04 . 2008-12-04 15:04 <REP> d-------- c:\windows\l2schemas
      2008-12-04 15:03 . 2008-12-04 15:05 <REP> d-------- c:\windows\ServicePackFiles
      2008-12-04 14:56 . 2008-12-04 14:56 <REP> d-------- c:\windows\EHome
      2008-12-04 14:10 . 2008-12-05 10:29 1,374 --a------ c:\windows\imsins.BAK
      2008-12-02 11:15 . 2008-12-05 11:50 <REP> d-------- c:\program files\FindyKill
      2008-12-02 10:24 . 2008-12-02 10:24 <REP> d-------- c:\documents and settings\All Users\Application Data\EPSON
      2008-12-02 10:24 . 2006-12-08 11:04 76,800 --a------ c:\windows\system32\E_FLBCDE.DLL
      2008-12-02 10:24 . 2006-04-19 11:00 62,976 --a------ c:\windows\system32\E_FD4BCDE.DLL
      2008-11-23 16:06 . 2008-12-05 11:59 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
      2008-11-23 16:06 . 2008-11-23 16:06 <REP> d-------- c:\documents and settings\fuji\Application Data\Malwarebytes
      2008-11-23 16:06 . 2008-11-23 16:06 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
      2008-11-23 16:06 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
      2008-11-23 16:06 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
      2008-11-23 13:04 . 2008-11-23 13:04 <REP> d-------- c:\program files\Trend Micro
      2008-11-23 11:56 . 2004-08-03 22:41 1,041,536 --------- c:\windows\system32\drivers\hsfdpsp2.sys
      2008-11-23 11:56 . 2004-08-03 22:41 685,056 --------- c:\windows\system32\drivers\hsfcxts2.sys
      2008-11-23 11:56 . 2004-08-03 22:41 220,032 --------- c:\windows\system32\drivers\hsfbs2s2.sys
      2008-11-23 11:56 . 2004-07-17 22:55 129,045 --------- c:\windows\system32\drivers\cxthsfs2.cty
      2008-11-23 11:56 . 2004-08-03 22:41 11,868 --------- c:\windows\system32\drivers\mdmxsdk.sys
      2008-11-23 11:08 . 2008-06-14 18:33 272,768 --------- c:\windows\system32\drivers\bthport.sys
      2008-11-23 11:08 . 2008-06-14 18:33 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
      2008-11-23 11:07 . 2008-09-15 16:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
      2008-11-23 11:07 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
      2008-11-23 11:07 . 2008-08-14 11:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
      2008-11-23 11:06 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
      2008-11-23 11:06 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
      2008-11-23 11:06 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
      2008-11-23 11:06 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
      2008-11-23 11:04 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
      2008-11-23 11:04 . 2008-05-08 15:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
      2008-11-23 11:03 . 2008-04-11 20:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
      2008-11-23 11:03 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
      2008-11-21 21:38 . 2008-11-21 21:38 123 --a------ c:\windows\wininit.ini
      2008-11-21 21:04 . 2008-11-21 21:16 72,389 --a------ c:\windows\system32\defragsys.exe
      2008-11-21 20:54 . 2008-11-21 20:54 <REP> d-------- c:\documents and settings\fuji\Application Data\MSNInstaller
      2008-11-21 20:42 . 2008-11-21 20:42 <REP> d-------- c:\program files\CCleaner
      2008-11-21 18:54 . 2008-12-04 20:35 <REP> d-------- c:\program files\Spybot - Search & Destroy
      2008-11-21 18:54 . 2008-12-04 20:35 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
      2008-11-21 15:18 . 2008-11-21 15:18 <REP> d-------- c:\program files\Neuf

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-12-04 18:29 --------- d--h--w c:\program files\InstallShield Installation Information
      2008-12-04 18:29 --------- d-----w c:\program files\CyberLink
      2008-11-22 21:01 --------- d-----w c:\program files\EBP
      2008-11-21 19:57 --------- d-----w c:\program files\Google
      2008-11-21 18:03 98,545 ----a-w c:\windows\svd.exe
      2008-11-07 13:05 --------- d-----w c:\documents and settings\fuji\Application Data\EBP
      2008-11-07 13:05 --------- d-----w c:\documents and settings\fuji\Application Data\Comptabilité
      2008-11-04 15:16 --------- d-----w c:\program files\SAGEM WiFi manager
      2008-11-04 15:15 --------- d-----w c:\program files\SAGEM
      2008-11-04 15:15 --------- d-----w c:\documents and settings\fuji\Application Data\InstallShield
      2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
      2007-02-01 15:11 643,129 ----a-w c:\program files\unins000.exe
      2007-02-01 15:11 2,229 ----a-w c:\program files\unins000.dat
      2006-05-12 06:09 0 -c--a-w c:\documents and settings\fuji\Application Data\wklnhst.dat
      .

      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "EPSON Stylus DX7400 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE" [2007-04-12 182272]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
      "Auto EPSON Stylus DX7400 Series sur SERVILLE"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE" [2007-04-12 182272]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
      path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
      backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Loadout Manager.lnk]
      path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Loadout Manager.lnk
      backup=c:\windows\pss\Loadout Manager.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
      path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
      backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^svchost.exe]
      path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\svchost.exe
      backup=c:\windows\pss\svchost.exeCommon Startup

      [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk]
      path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk
      backup=c:\windows\pss\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnkCommon Startup

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
      --a------ 2005-10-13 21:05 344064 c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
      --a------ 2005-08-23 14:47 450560 c:\program files\VIAudioi\SBADeck\ADeck.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
      --a------ 2008-04-14 03:33 15360 c:\windows\system32\ctfmon.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\defragsystem]
      --a------ 2008-11-21 21:16 72389 c:\windows\system32\defragsys.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fsc-reminder.exe]
      --------- 2005-01-19 17:10 28672 c:\windows\reminder\fsc-reminder.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
      --a------ 2006-07-19 12:03 94208 c:\program files\Fichiers communs\Logitech\khalshared\KHALMNPR.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
      --------- 2008-04-14 03:34 1695232 c:\program files\Messenger\msmsgs.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
      --a------ 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
      --a--c--- 2006-07-03 19:13 26112 c:\program files\Real\RealPlayer\realplay.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
      --a------ 2005-04-15 16:13 45056 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
      --a------ 2005-03-18 14:34 688217 c:\program files\Synaptics\SynTP\SynTPEnh.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
      --a------ 2005-03-18 14:35 98393 c:\program files\Synaptics\SynTP\SynTPLpr.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
      --a------ 2006-07-19 12:03 94208 c:\windows\KHALMNPR.Exe

      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
      "MDM"=2 (0x2)
      "ose"=3 (0x3)
      "Boonty Games"=3 (0x3)
      "avast! Web Scanner"=3 (0x3)
      "avast! Mail Scanner"=3 (0x3)
      "aspnet_state"=3 (0x3)
      "C-DillaCdaC11BA"=2 (0x2)
      "avast! Antivirus"=2 (0x2)
      "aswUpdSv"=2 (0x2)

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusDisableNotify"=dword:00000001
      "UpdatesDisableNotify"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "c:\\WINDOWS\\system32\\sessmgr.exe"=
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "%windir%\\system32\\sessmgr.exe"=

      R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-05 111184]
      R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-05 20560]
      R2 LBeepKE;LBeepKE;c:\windows\system32\Drivers\LBeepKE.sys [2007-01-21 3712]
      S3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys []
      S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;c:\windows\system32\DRIVERS\WlanBZXP.sys [2008-11-04 450560]
      S3 ZDCndis5;ZDCndis5 Protocol Driver;\??\c:\windows\system32\ZDCndis5.SYS []

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd17d210-f94d-11db-a731-0014a540b5ff}]
      \Shell\AutoRun\command - E:\ie.exe
      \Shell\explore\Command - E:\ie.exe
      \Shell\open\Command - E:\ie.exe

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8207e8a-0195-11dc-a73c-0014a540b5ff}]
      \Shell\AutoRun\command - setup.exe
      .
      Contenu du dossier 'Tâches planifiées'

      2008-12-05 c:\windows\Tasks\Norton AntiVirus - Analyser mon ordinateur - fuji.job
      - c:\progra~1\NORTON~1\NORTON~1\Navw32.exe []

      2008-12-10 c:\windows\Tasks\Symantec NetDetect.job
      - c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-01-27 15:59]
      .
      - - - - ORPHELINS SUPPRIMES - - - -

      MSConfigStartUp-EPSON Product Rappel concernant l'enregistrement - c:\windows\Temp\RegModule.exe
      MSConfigStartUp-MessagerStarter Wanadoo - c:\progra~1\MESSAG~1\StartMessager.exe
      MSConfigStartUp-msnmsgr - c:\program files\MSN Messenger\msnmsgr.exe
      MSConfigStartUp-PCMService - c:\program files\CyberLink\PowerCinema\PCMService.exe
      MSConfigStartUp-PinnacleDriverCheck - c:\windows\system32\PSDrvCheck.exe
      MSConfigStartUp-RavAV - c:\windows\AdobeR.exe
      MSConfigStartUp-SpybotSD TeaTimer - c:\program files\Spybot - Search & Destroy\TeaTimer.exe
      MSConfigStartUp-Steam - c:\program files\steam\steam.exe
      MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe



      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-12-10 09:43:22
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'winlogon.exe'(1000)
      c:\windows\system32\Ati2evxx.dll
      .
      ------------------------ Autres processus actifs ------------------------
      .
      c:\program files\Alwil Software\Avast4\aswUpdSv.exe
      c:\program files\Alwil Software\Avast4\ashServ.exe
      c:\windows\system32\wdfmgr.exe
      c:\program files\Alwil Software\Avast4\ashMaiSv.exe
      c:\program files\Alwil Software\Avast4\ashWebSv.exe
      c:\windows\system32\wscntfy.exe
      c:\program files\Alwil Software\Avast4\ashDisp.exe
      .
      **************************************************************************
      .
      Heure de fin: 2008-12-10 9:46:30 - La machine a redémarré [fuji]
      ComboFix-quarantined-files.txt 2008-12-10 08:46:27

      Avant-CF: 88 344 428 544 octets libres
      Après-CF: 88,310,272,000 octets libres

      WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

      230 --- E O F --- 2008-12-05 09:29:45


      merci encore pour ton aide
      0
    2. serville Messages postés 102 Statut Membre 12
       
      re,
      J'ai pu redémarrer enfin en mode sans échec.
      J'ai passé malware en suivant la procédure
      voici le rapport

      Malwarebytes' Anti-Malware 1.31
      Version de la base de données: 1463
      Windows 5.1.2600 Service Pack 3

      10/12/2008 16:09:09
      mbam-log-2008-12-10 (16-09-09).txt

      Type de recherche: Examen complet (C:\|)
      Eléments examinés: 108525
      Temps écoulé: 53 minute(s), 30 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 1

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\WINDOWS\pss\svchost.exeCommon Startup (Trojan.Dropper) -> Quarantined and deleted successfully.


      Et dans la foulée le rapport Hijackthis (scan réalisé en mode sans echec) :
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 16:10:28, on 10/12/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16735)
      Boot mode: Safe mode

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\WINDOWS\system32\NOTEPAD.EXE

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S8B.tmp" /EF "HKCU"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Auto EPSON Stylus DX7400 Series sur SERVILLE] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S33.tmp" /EF "HKCU"
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
      O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrôle d'AcDcToday) - file://C:\Program Files\AutoCAD LT 2002 Fra\AcDcToday.ocx
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      0
    3. serville Messages postés 102 Statut Membre 12
       
      voici le dernier log findykill après execution option 1

      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\wdfmgr.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\alg.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe

      --------------- [ Fichiers/Dossiers infectieux ] ----------------


      »»»» Presence des fichiers dans C:


      »»»» Presence des fichiers dans C:\WINDOWS


      »»»» Presence des fichiers dans C:\WINDOWS\Prefetch


      »»»» Presence des fichiers dans C:\WINDOWS\system32


      »»»» Presence des fichiers dans C:\WINDOWS\system32\drivers


      »»»» Presence des fichiers dans C:\Documents and Settings\fuji\Application Data


      »»»» Presence des fichiers dans C:\DOCUME~1\fuji\LOCALS~1\Temp


      »»»» Presence des fichiers dans C:\Documents and Settings\fuji\Local Settings\Temporary Internet Files\Content.IE5


      --------------- [ Registre / Startup ] ----------------

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

      EPSON Stylus DX7400 Series=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S8B.tmp" /EF "HKCU"
      ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
      Auto EPSON Stylus DX7400 Series sur SERVILLE=C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S33.tmp" /EF "HKCU"

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

      avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
      Installed=1
      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
      Installed=1
      NoChange=1
      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
      Installed=1


      --------------- [ Registre / Clés infectieuses ] ----------------



      --------------- [ Etat / Services ] ----------------



      +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

      Ndisuio - Type de démarrage = 3

      EapHost - Type de démarrage = 2

      Ip6Fw - Type de démarrage = 2

      SharedAccess - Type de démarrage = 2

      wuauserv - Type de démarrage = 2

      wscsvc - Type de démarrage = 2



      --------------- [ Recherche dans supports amovibles] ----------------


      +- Informations :

      C: - Lecteur fixe


      +- presence des fichiers :



      --------------- [ Registre / Mountpoint2 ] ----------------


      -> Not found !


      ------------------- ! Fin du rapport ! --------------------
      0
  15. totobetourne Messages postés 5677 Statut Membre 65
     
    1)le rapport hijack a l air correct plus d infection a priori, dis moi comment se comporte ton pc?

    2)on peut passer au stade de securisation et on peut enlever des lignes inutiles sur le hijack.
    dis moi ou tu en es, il faut faire deja cela.cela a peut etre l air un peu long mais c est du temps de gagner sur une prochaine possible infection.

    a)• Télécharger CCLeaner et l'installer sur le bureau en refusant l'installation de la barre Yahoo.
    http://www.commentcamarche.net/telecharger/telecharger 168 ccleaner

    • Fermer toutes les applications
    • Lancer CCLeaner
    S'il n'est pas en Français cliquer sur Options, Setting, Language
    et sélectionner Français
    • cocher dans le menu Nettoyeur - onglet Windows :
    Internet Explorer: Fichiers Internet Temporaires, Cookies
    • Système: Vider la Poubelle, Fichiers Temporaires, Presse-papiers
    • Avancé: Vieilles données du Prefetch
    • Décocher dans le menu Options - sous-menu Avancé :
    Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures
    • Cocher dans le menu Nettoyeur - onglet Applications : Internet: Sun Java
    • Cocher , si cela est possible, dans le menu Nettoyeur - onglet Applications :
    Firefox/Mozilla: Cache Internet, Cookies
    • Click sur Analyse
    • Click sur le bouton Lancer le nettoyage dans le menu Nettoyeur.
    • Click sur Registre
    • Sélectionner tout
    • Click sur Chercher des erreurs (En bas)

    Une fois le scan terminé sélectionner tout
    • Click sur Réparer les erreurs sélectionnées

    b)Relance hijack et clique sur "Do a system scan only"
    Ensuite recherche ces lignes et coches les cases

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe (file missing)

    Ensuite clique sur "Fix checked"

    c)pare-feu gratuits:regle un seul pare feu sur un ordi.telecharge un des suivants ensuite deconnecte toi.
    puis desactive le pare feu windows(aller dans le centre de securite puis pare feu windows et la desactive le)
    puis installe celui de ton choix.

    je te conseille un des 2(en anglais mais simple avec le tuto qui est donne)

    Comodo pro Firewall
    http://www.commentcamarche.net/telecharger/telecharger 34055041 comodo firewall pro
    Tuto pour la 3.0
    https://infomars.fr/forum/index.php?showtopic=1225

    ou

    OnlineArmor :
    téléchargement:https://www.commentcamarche.net/telecharger/ 34055356 online armor personal firewall

    tutoriels:https://forum.pcastuces.com/sujet.asp?f=25&s=35606
    :http://www.malekal.com/tutorial_Online_Armor.ph

    il y en a d autres mais d apres les test de matousec en gratuit il n y en a pas bcp d autre.
    http://www.matousec.com/index.html

    d)passe a mozilla 3 au lieu d internet explorer car c est bien plus sur.

    http://www.commentcamarche.net/telecharger/telecharger 111 firefox

    fait ce qui est indique sur ce lien pour mieux securise firefox.
    https://www.malekal.com/securiser-le-navigateur-web-firefox-2/

    e)Télécharge ToolsCleaner sur ton bureau.(pour enlever ce que je t ai fait telecharger comme fix)
    -->
    http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner

    # Clique sur Recherche et laisse le scan agir ...
    # Clique sur Suppression pour finaliser.
    # Tu peux, si tu le souhaites, te servir des Options facultatives.
    # Clique sur Quitter pour obtenir le rapport.
    # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

    ensuite :

    Clic sur "démarrer", cliques droit sur "poste de travail", "propriétés", onglet "restauration du système"

    ¤ coche la case "désactiver la Restauration du systéme sur tous les lecteurs", puis clic sur "appliquer"
    ¤ décoche la case et clic sur "appliquer" puis "ok".

    Maintenant, que l'ont à effacés les point infectés, nous allons créer un point propre:

    Clic sur "démarrer", "tous les programmes", "accessoires", "outils système", "restauration du système", choisis "créer un point de restauration" nommes le " ccm" par exemple, cliques sur "créer" puis "ok".
    Voilà, maintenant le point de restauration est créé. Si un jour tu décides tu pourras revenir en arrière à la date créée.

    Tuto : http://www.libellules.ch/desactiver_restauration.php
    0
    1. serville Messages postés 102 Statut Membre 12
       
      bonjour,
      concernant le pc, pas de soucis. Je pense avoir récupéré ,toutes les fonctions (son et démarrage en mode sans echec).
      Avant la dernière procédure j'ai repassé un scan de Avast. Il avait encore un trojan(bifrose) dans un fichier nommé defragsys.exe dans windows/system32/pss. Après mise en quarantaine, il ne semble plus y avoir de virus.

      je te porte le log de toolscleaner.
      [ Rapport ToolsCleaner version 2.2.7 (par A.Rothstein & dj QUIOU) ]

      -->- Recherche:

      C:\Combofix.txt: trouvé !
      C:\FindyKill.txt: trouvé !
      C:\Qoobox: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
      C:\Documents and Settings\fuji\Bureau\HijackThis.lnk: trouvé !
      C:\Documents and Settings\fuji\Bureau\ComboFix.exe: trouvé !
      C:\Documents and Settings\fuji\Bureau\hijackthis.log: trouvé !
      C:\Documents and Settings\fuji\Menu Démarrer\Programmes\FindyKill: trouvé !
      C:\Documents and Settings\fuji\Recent\HijackThis.lnk: trouvé !
      C:\Program Files\FindyKill: trouvé !
      C:\Program Files\Trend Micro\HijackThis: trouvé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
      C:\WINDOWS\NIRCMD.exe: trouvé !

      ---------------------------------
      -->- Suppression:

      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
      C:\Documents and Settings\fuji\Bureau\HijackThis.lnk: supprimé !
      C:\Documents and Settings\fuji\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
      C:\Documents and Settings\fuji\Recent\HijackThis.lnk: supprimé !
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
      C:\Combofix.txt: supprimé !
      C:\FindyKill.txt: supprimé !
      C:\Documents and Settings\fuji\Bureau\hijackthis.log: supprimé !
      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
      C:\WINDOWS\NIRCMD.exe: supprimé !
      C:\Qoobox: supprimé !
      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
      C:\Documents and Settings\fuji\Menu Démarrer\Programmes\FindyKill: supprimé !
      C:\Program Files\FindyKill: supprimé !
      C:\Program Files\Trend Micro\HijackThis: supprimé !

      Fichiers temporaires nettoyés !
      Corbeille vidée!

      Merci encore pour ton aide.
      Je peux te dire que la personne qui a téléchargé des cracks et jouer en ligne sans aucune protection pour le portable n'est pas près de le réutiliser d'"autant qu'il est réservé uniquement à un usage professionnel. Les conséquences aurait pu être dramatique.

      Bonne continuation
      0
  16. totobetourne Messages postés 5677 Statut Membre 65
     
    POUR CE QUE T A REPERE AVAST.
    je te conseille si cela n a pas modifier ton pc.sors le de la quarantaine.

    et fait cela
    Ensuite,
    *Rends toi sur ce site :

    https://www.virustotal.com/gui/

    *Clique sur "Parcourir" et cherche ce fichier : le fichier incrimine
    *Un rapport va s'élaborer ligne à ligne.
    *Attends la fin. Il doit comprendre la taille du fichier envoyé.
    *Sauvegarde le rapport avec le bloc-note.
    *Copie le dans ta réponse.
    *Si VirusTotal indique que le fichier a déjà été analysé, clique sur le bouton "Reanalyse" le fichier maintenant

    colle le rapport obtenu.

    bientot la fin.
    0
    1. serville Messages postés 102 Statut Membre 12
       
      D'autant qu'un scan des archives au démarrage à encore détecté le bifrose sur une archive winrar placée sur la racine du disque.
      Je fais le nécessaire et je te poste les rapports.
      0
    2. serville Messages postés 102 Statut Membre 12
       
      bob, impossible de scanner defragsys.exe avec virustotal. Il ne le reçoit pas (et je ne comprends pas pourquoi!) et donc, pas de rapport, mais bon, sa suppression n'affecte en rien le portable.
      Est ce que j'en ai vu le bout cette fois?... Sacré virus cet hiver...lol
      A bientot et merci encore.
      0
  17. totobetourne Messages postés 5677 Statut Membre 65
     
    une derniere chose , il reste a faire cela je crois bien.

    /!\ Manip crée spécialement pour cet utilisateur , ne pas reproduire chez soi ... /!\

    Ouvre le Bloc-Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)

    Copie ce texte ( en gras )d'une traite ( CTRL+C pour copier ) puis colle-le ( CTRL+V dans le bloc-note )

    Files::
    c:\program files\internet explorer\iekey.dll
    c:\windows\system32\plugin1.dat
    e:\ie.exe
    c:\windows\adober.exe

    Sauvegarde ce fichier sur ton bureau sous le nom de CFScript.txt.

    Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    Cela va relancer Combofix,

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

    S'il n'y a pas de rédémarrage, poste quand même les rapports.

    Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt
    0
    1. serville Messages postés 102 Statut Membre 12
       
      je te joins aussi le log d'Avast

      * Rapport avast!
      * Ce fichier est généré automatiquement
      *
      * Tâche utilisée 'Interface utilisateur simplifiée'
      * Débuté le vendredi 12 décembre 2008 19:24:38
      * VPS : 081212-0, 12/12/2008
      *

      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MaxFiles.zip\Program Files\ipwins\ipwins.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MaxFiles.zip\Program Files\ipwins\Services.dll [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MaxFiles.zip\Program Files\ipwins\Uninst.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MaxFiles.zip\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterdisabled.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityCenterdisabled.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityInternetExplorer.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MicrosoftWindowsSecurityInternetExplorer.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\StudA.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\StudA.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\1023875.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\10509890.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\1085609.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\10893046.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\1112656.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\1114843.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\1202828.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\12715156.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\12739546.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\132546.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\145765.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14665375.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14684781.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14739203.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14815859.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14816468.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14818609.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14846640.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14857187.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14935343.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14971406.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14982406.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\14983859.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15011203.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15067046.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15076359.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\151187.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15169250.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15201937.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15251187.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15284765.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15350890.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15351375.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15456875.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15544296.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15680125.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15732093.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15815656.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15838078.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\15853062.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\1619578.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\16266937.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\16304500.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\16445031.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\164500.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\16782328.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\16785281.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\16806125.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\16835234.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\177093.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\1817328.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\18211046.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\18456000.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\1862234.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\1901828.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\190390.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\193328.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\1989531.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\199718.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\201515.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\202812.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\210796.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\219625.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\221500.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\224921.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\2252640.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\226125.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\226390.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\2309468.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\24570562.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\249234.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\250031.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\25112015.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\253125.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\25445296.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\25830234.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\260031.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\262500.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\263234.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\263296.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\263328.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\268734.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\276859.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\285765.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\288781.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\289093.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\289203.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\292859.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\295265.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\29933875.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\29934640.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\300921.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\301031.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\30127671.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\30131296.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\302468.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\302515.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\30264359.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\30743968.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\308875.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\309968.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\31048406.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\310812.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\3150562.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\3150578.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\315796.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\31589250.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\316765.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\320812.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\323906.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\323921.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\33153843.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\33162921.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\33175359.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\33464500.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\337656.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\339453.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\346890.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\349078.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\355359.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\363828.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\3641296.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\3642890.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\372843.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\37515171.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\375656.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\391859.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\393062.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\408015.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\414640.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\431531.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\440156.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\45627125.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\45802593.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\460390.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\46252046.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\463703.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\473890.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\475140.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\508421.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\5251250.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\535500.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\536218.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\561390.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\572093.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\586625.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\590875.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\592187.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\600171.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\600687.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\602859.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\652953.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\653781.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\694937.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\700796.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\706406.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\708343.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\711984.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\781828.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\823812.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\8916875.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\8948421.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\9210187.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\995921.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\a.bat [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\WINDOWS\exefld\d.bat [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy.zip\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy1.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinAgentbgy1.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBagleAV.zip\m_hook.sys [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBagleAV.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBagleAV1.zip\Documents and Settings\fuji\Application Data\hidires\hidr.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBagleAV1.zip\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBagleE.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBagleE.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBaglehi.zip\sbRecovery.reg [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBaglehi.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinVBlu.zip\svchost.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinVBlu.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip\Yazzle1122OinAdmin.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip\Yazzle1122OinUninstaller.exe [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Yazzle1.zip\sbRecovery.ini [E] L'archive est protégée par mot de passe. (42056)
      C:\Documents and Settings\fuji\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\fuji\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\fuji\ntuser.dat [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\fuji\ntuser.dat.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\LocalService\NTUSER.DAT [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\LocalService\ntuser.dat.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\NetworkService\NTUSER.DAT [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Documents and Settings\NetworkService\ntuser.dat.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\EBP\Dossiers\Demo\Compta.0\Cpta.dic\Cpta [E] archive GZIP corrompue. (42129)
      C:\EBP\Dossiers\planeteenfants\Compta.0\Cpta.dic\Cpta [E] archive GZIP corrompue. (42129)
      C:\EBP\Dossiers\planeteenfants\Compta.0\Schimmos.dic\Schimmos [E] archive GZIP corrompue. (42129)
      C:\pagefile.sys [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\Program Files\EBP\Compta\BaseVide\Cpta.dic\Cpta [E] archive GZIP corrompue. (42129)
      C:\Program Files\EBP\Compta\BaseVide\Schimmos.dic\Schimmos [E] archive GZIP corrompue. (42129)
      C:\WINDOWS\system32\CatRoot2\edb.log [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\CatRoot2\tmp.edb [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\config\default [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\config\default.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\config\SAM [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\config\SAM.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\config\SECURITY [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\config\SECURITY.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\config\software [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\config\software.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\config\system [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\system32\config\system.LOG [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\Temp\Perflib_Perfdata_84.dat [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      C:\WINDOWS\Temp\_avast4_\Webshlock.txt [E] Le processus ne peut pas accéder au fichier car ce fichier est utilisé par un autre processus (32)
      Fichiers infectés : 0
      Total des fichiers : 358311
      Total des dossiers : 4270
      Taille totale : 15,4 GB

      *
      * Tâche terminée : vendredi 12 décembre 2008 20:10:10
      * Programme était en exécution 45 minute(s), 32 seconde(s)
      *

      Peux tu m'expliquer pourquoi tu m'as fait faire la manip tout à l'heure? Tu penses qu'il y a encore des infections quelque part? A bientot.
      0
  18. serville Messages postés 102 Statut Membre 12
     
    Voici les 2 rapports,

    ComboFix 08-12-11.05 - fuji 2008-12-12 15:00:53.2 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.681 [GMT 1:00]
    Lancé depuis: c:\documents and settings\fuji\Bureau\ComboFix.exe
    Commutateurs utilisés :: c:\documents and settings\fuji\Bureau\CFScript.txt
    * Un nouveau point de restauration a été créé
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\cfx32.ocx

    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-12 au 2008-12-12 ))))))))))))))))))))))))))))))))))))
    .

    2008-12-12 14:50 . 2008-12-12 14:50 <REP> d-------- c:\windows\LastGood
    2008-12-11 15:17 . 2008-12-11 15:39 2,560 --a------ C:\MKDEWE.TRN
    2008-12-11 15:12 . 2008-12-11 15:12 <REP> d-------- c:\program files\EBP
    2008-12-11 15:12 . 2008-12-11 15:12 <REP> d-------- C:\EBP
    2008-12-11 15:12 . 1998-02-03 12:48 818,688 --a------ c:\windows\system32\VCF132.OCX
    2008-12-11 15:12 . 1996-10-07 19:22 320,512 --a------ c:\windows\system32\W32MKDE.EXE
    2008-12-11 15:12 . 1996-09-24 16:40 110,080 --a------ c:\windows\system32\W32MKRC.DLL
    2008-12-11 15:12 . 1998-03-13 17:02 68,096 --a------ c:\windows\system32\Wbtrv32.dll
    2008-12-11 15:12 . 1998-02-10 21:59 43,008 --a------ c:\windows\system32\W32BTICM.DLL
    2008-12-09 15:41 . 2008-12-10 18:12 <REP> d-------- c:\windows\system32\LogFiles
    2008-12-04 15:04 . 2008-12-04 15:04 <REP> d-------- c:\windows\system32\fr
    2008-12-04 15:04 . 2008-12-04 15:04 <REP> d-------- c:\windows\system32\bits
    2008-12-04 15:04 . 2008-12-04 15:04 <REP> d-------- c:\windows\l2schemas
    2008-12-04 15:03 . 2008-12-04 15:05 <REP> d-------- c:\windows\ServicePackFiles
    2008-12-04 14:56 . 2008-12-04 14:56 <REP> d-------- c:\windows\EHome
    2008-12-04 14:26 . 2008-12-04 15:04 <REP> d-------- c:\windows\system32\fr-fr
    2008-12-04 14:26 . 2008-10-03 18:12 6,066,176 -----c--- c:\windows\system32\dllcache\ieframe.dll
    2008-12-04 14:26 . 2007-04-17 10:32 2,455,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dat
    2008-12-04 14:26 . 2007-03-08 06:10 1,048,576 -----c--- c:\windows\system32\dllcache\ieframe.dll.mui
    2008-12-04 14:26 . 2008-08-26 09:11 459,264 -----c--- c:\windows\system32\dllcache\msfeeds.dll
    2008-12-04 14:26 . 2008-08-26 09:11 383,488 -----c--- c:\windows\system32\dllcache\ieapfltr.dll
    2008-12-04 14:26 . 2008-08-26 09:11 267,776 -----c--- c:\windows\system32\dllcache\iertutil.dll
    2008-12-04 14:26 . 2008-08-26 09:11 63,488 -----c--- c:\windows\system32\dllcache\icardie.dll
    2008-12-04 14:26 . 2008-08-26 09:11 52,224 -----c--- c:\windows\system32\dllcache\msfeedsbs.dll
    2008-12-04 14:26 . 2008-08-25 09:38 13,824 -----c--- c:\windows\system32\dllcache\ieudinit.exe
    2008-12-04 14:10 . 2008-12-05 10:29 1,374 --a------ c:\windows\imsins.BAK
    2008-12-02 10:24 . 2008-12-02 10:24 <REP> d-------- c:\documents and settings\All Users\Application Data\EPSON
    2008-12-02 10:24 . 2006-12-08 11:04 76,800 --a------ c:\windows\system32\E_FLBCDE.DLL
    2008-12-02 10:24 . 2006-04-19 11:00 62,976 --a------ c:\windows\system32\E_FD4BCDE.DLL
    2008-11-23 16:06 . 2008-12-05 11:59 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
    2008-11-23 16:06 . 2008-11-23 16:06 <REP> d-------- c:\documents and settings\fuji\Application Data\Malwarebytes
    2008-11-23 16:06 . 2008-11-23 16:06 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-11-23 16:06 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
    2008-11-23 16:06 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
    2008-11-23 13:04 . 2008-12-11 10:33 <REP> d-------- c:\program files\Trend Micro
    2008-11-23 11:56 . 2004-08-03 22:41 1,041,536 --------- c:\windows\system32\drivers\hsfdpsp2.sys
    2008-11-23 11:56 . 2004-08-03 22:41 685,056 --------- c:\windows\system32\drivers\hsfcxts2.sys
    2008-11-23 11:56 . 2004-08-03 22:41 220,032 --------- c:\windows\system32\drivers\hsfbs2s2.sys
    2008-11-23 11:56 . 2004-07-17 22:55 129,045 --------- c:\windows\system32\drivers\cxthsfs2.cty
    2008-11-23 11:56 . 2004-08-03 22:41 11,868 --------- c:\windows\system32\drivers\mdmxsdk.sys
    2008-11-23 11:08 . 2008-06-14 18:33 272,768 --------- c:\windows\system32\drivers\bthport.sys
    2008-11-23 11:08 . 2008-06-14 18:33 272,768 -----c--- c:\windows\system32\dllcache\bthport.sys
    2008-11-23 11:07 . 2008-09-15 16:26 1,846,528 -----c--- c:\windows\system32\dllcache\win32k.sys
    2008-11-23 11:07 . 2008-09-08 11:41 333,824 -----c--- c:\windows\system32\dllcache\srv.sys
    2008-11-23 11:07 . 2008-08-14 11:04 138,496 -----c--- c:\windows\system32\dllcache\afd.sys
    2008-11-23 11:06 . 2008-08-14 14:23 2,191,232 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
    2008-11-23 11:06 . 2008-08-14 14:23 2,147,328 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
    2008-11-23 11:06 . 2008-08-14 14:23 2,068,096 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
    2008-11-23 11:06 . 2008-08-14 14:23 2,025,984 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
    2008-11-23 11:04 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
    2008-11-23 11:04 . 2008-05-08 15:02 203,136 -----c--- c:\windows\system32\dllcache\rmcast.sys
    2008-11-23 11:03 . 2008-04-11 20:05 691,712 -----c--- c:\windows\system32\dllcache\inetcomm.dll
    2008-11-23 11:03 . 2008-10-15 17:35 337,408 -----c--- c:\windows\system32\dllcache\netapi32.dll
    2008-11-21 21:38 . 2008-11-21 21:38 123 --a------ c:\windows\wininit.ini
    2008-11-21 20:54 . 2008-11-21 20:54 <REP> d-------- c:\documents and settings\fuji\Application Data\MSNInstaller
    2008-11-21 20:42 . 2008-11-21 20:42 <REP> d-------- c:\program files\CCleaner
    2008-11-21 18:54 . 2008-12-04 20:35 <REP> d-------- c:\program files\Spybot - Search & Destroy
    2008-11-21 18:54 . 2008-12-04 20:35 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2008-11-21 15:18 . 2008-11-21 15:18 <REP> d-------- c:\program files\Neuf

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-11 14:38 --------- d-----w c:\documents and settings\fuji\Application Data\Comptabilité
    2008-12-04 18:29 --------- d--h--w c:\program files\InstallShield Installation Information
    2008-12-04 18:29 --------- d-----w c:\program files\CyberLink
    2008-11-21 20:16 2,864 -c--a-w c:\windows\system32\winsock.dll
    2008-11-21 19:57 --------- d-----w c:\program files\Google
    2008-11-21 18:03 98,545 ----a-w c:\windows\svd.exe
    2008-11-07 13:05 --------- d-----w c:\documents and settings\fuji\Application Data\EBP
    2008-11-04 15:16 --------- d-----w c:\program files\SAGEM WiFi manager
    2008-11-04 15:15 --------- d-----w c:\program files\SAGEM
    2008-11-04 15:15 --------- d-----w c:\documents and settings\fuji\Application Data\InstallShield
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
    2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
    2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
    2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
    2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
    2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
    2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
    2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
    2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
    2007-02-01 15:11 643,129 ----a-w c:\program files\unins000.exe
    2007-02-01 15:11 2,229 ----a-w c:\program files\unins000.dat
    2006-05-12 06:09 0 -c--a-w c:\documents and settings\fuji\Application Data\wklnhst.dat
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "EPSON Stylus DX7400 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE" [2007-04-12 182272]
    "Auto EPSON Stylus DX7400 Series sur SERVILLE"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE" [2007-04-12 182272]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Lancement rapide d'Adobe Reader.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Lancement rapide d'Adobe Reader.lnk
    backup=c:\windows\pss\Lancement rapide d'Adobe Reader.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Loadout Manager.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Loadout Manager.lnk
    backup=c:\windows\pss\Loadout Manager.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Logitech SetPoint.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Logitech SetPoint.lnk
    backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^svchost.exe]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\svchost.exe
    backup=c:\windows\pss\svchost.exeCommon Startup

    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk]
    path=c:\documents and settings\All Users\Menu Démarrer\Programmes\Démarrage\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk
    backup=c:\windows\pss\Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnkCommon Startup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
    --a------ 2005-10-13 21:05 344064 c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioDeck]
    --a------ 2005-08-23 14:47 450560 c:\program files\VIAudioi\SBADeck\ADeck.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
    --a------ 2008-04-14 03:33 15360 c:\windows\system32\ctfmon.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fsc-reminder.exe]
    --------- 2005-01-19 17:10 28672 c:\windows\reminder\fsc-reminder.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
    --a------ 2006-07-19 12:03 94208 c:\program files\Fichiers communs\Logitech\khalshared\KHALMNPR.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --------- 2008-04-14 03:34 1695232 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    --a------ 2001-07-09 09:50 155648 c:\windows\system32\NeroCheck.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
    --a--c--- 2006-07-03 19:13 26112 c:\program files\Real\RealPlayer\realplay.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
    --a------ 2005-04-15 16:13 45056 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
    --a------ 2005-03-18 14:34 688217 c:\program files\Synaptics\SynTP\SynTPEnh.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
    --a------ 2005-03-18 14:35 98393 c:\program files\Synaptics\SynTP\SynTPLpr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
    --a------ 2006-07-19 12:03 94208 c:\windows\KHALMNPR.Exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "MDM"=2 (0x2)
    "ose"=3 (0x3)
    "Boonty Games"=3 (0x3)
    "avast! Web Scanner"=3 (0x3)
    "avast! Mail Scanner"=3 (0x3)
    "aspnet_state"=3 (0x3)
    "C-DillaCdaC11BA"=2 (0x2)
    "avast! Antivirus"=2 (0x2)
    "aswUpdSv"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "c:\\WINDOWS\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=

    R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-05 111184]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-05 20560]
    R2 LBeepKE;LBeepKE;c:\windows\system32\Drivers\LBeepKE.sys [2007-01-21 3712]
    S3 bcgame;Nostromo HID Device Minidriver;c:\windows\system32\drivers\bcgame.sys []
    S3 SG762_XP;SAGEM 802.11g XG762 1211B Driver;c:\windows\system32\DRIVERS\WlanBZXP.sys [2008-11-04 450560]
    S3 ZDCndis5;ZDCndis5 Protocol Driver;\??\c:\windows\system32\ZDCndis5.SYS []

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd17d210-f94d-11db-a731-0014a540b5ff}]
    \Shell\AutoRun\command - E:\ie.exe
    \Shell\explore\Command - E:\ie.exe
    \Shell\open\Command - E:\ie.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f8207e8a-0195-11dc-a73c-0014a540b5ff}]
    \Shell\AutoRun\command - setup.exe
    .
    Contenu du dossier 'Tâches planifiées'

    2008-12-05 c:\windows\Tasks\Norton AntiVirus - Analyser mon ordinateur - fuji.job
    - c:\progra~1\NORTON~1\NORTON~1\Navw32.exe []

    2008-12-12 c:\windows\Tasks\Symantec NetDetect.job
    - c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-01-27 15:59]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    MSConfigStartUp-defragsystem - c:\windows\system32\defragsys.exe

    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.googled.fr/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Connection Wizard,ShellNext = iexplore
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-12 15:02:47
    Windows 5.1.2600 Service Pack 3 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------

    - - - - - - - > 'winlogon.exe'(988)
    c:\windows\system32\Ati2evxx.dll
    .
    Heure de fin: 2008-12-12 15:03:46
    ComboFix-quarantined-files.txt 2008-12-12 14:03:22

    Avant-CF: 88 256 729 088 octets libres
    Après-CF: 88,255,180,800 octets libres

    214 --- E O F --- 2008-12-05 09:29:45

    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\notepad.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S8B.tmp" /EF "HKCU"
    O4 - HKCU\..\Run: [Auto EPSON Stylus DX7400 Series sur SERVILLE] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE /FU "C:\WINDOWS\TEMP\E_S33.tmp" /EF "HKCU"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (Contrôle d'AcDcToday) - file://C:\Program Files\AutoCAD LT 2002 Fra\AcDcToday.ocx
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    0