Diagnostique d'un LOG HIJACKTHIS - Help !

Résolu
Bonjour à tous !

Qui peut m'aider à analyser le log de Hijackthis ?

J'ai fait quelques manip hier pour enlever des virus mais je ne suis pas sûr d'avoir fait ce qu'il fallait.

Merci pour votre aide.

cdt.

Lor_enzo

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 10:14, on 2008-12-07
Platform: Windows XP SP3 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PVSW\Bin\WGE_SRV.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PVSW\BIN\W3dbsmgr.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Wireless Console 2\wcourier.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\ASUS\PowerForPhone\PowerForPhone.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\ATK0100\ATKOSD.EXE
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\LFR\Bureau\HiJackThis_v2.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.akeoportail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IEToolbarBHO Class - {1A1DAC8C-074D-440F-8707-7009A672D7D1} - C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\LinkedinIEToolbar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: LinkedIn Toolbar - {BB670D0B-5C46-40C7-B38B-40DD26987723} - C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\LinkedinIEToolbar.dll
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\ASUS\PowerForPhone\PowerForPhone.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\RunOnce: [SpybotDeletingA670] command /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKLM\..\RunOnce: [SpybotDeletingC9508] cmd /c del "C:\WINDOWS\SchedLgU.Txt"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: MultiFrame.lnk = ?
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} -
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: APSHook.dll uzhvse.dll
O20 - Winlogon Notify: OneCard - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: EBP Pervasive.SQL - Unknown owner - C:\PVSW\Bin\WGE_SRV.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe

--
End of file - 16255 bytes
Configuration: Windows XP Pack 3
Firefox 3.0.4 
IE 7

13 réponses

  1. Merci.

    Voici le résultat.

    KASPERSKY ON-LINE SCANNER REPORT
    Sunday, December 07, 2008 2:40:13 PM
    Système d'exploitation : Microsoft Windows XP Professional, Service Pack 3 (Build 2600)
    Kaspersky On-line Scanner version : 5.0.84.2
    Dernière mise à jour de la base antivirus Kaspersky : 7/12/2008
    Enregistrements dans la base antivirus Kaspersky : 1441542
    Paramètres d'analyse
    Analyser avec la base antivirus suivante étendue
    Analyser les archives vrai
    Analyser les bases de messagerie vrai
    Cible de l'analyse Poste de travail
    C:\
    D:\
    E:\
    Statistiques de l'analyse
    Total d'objets analysés 138481
    Nombre de virus trouvés 1
    Nombre d'objets infectés 1 / 0
    Nombre d'objets suspects 0
    Durée de l'analyse 01:58:34

    Nom de l'objet infecté Nom du virus Dernière action
    C:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\Media Ce.evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\ASUS Sec.evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\Antivirus.Evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\OSession.evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\ODiag.evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\Canal+.evt L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SOFTWARE L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SYSTEM L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\DEFAULT L'objet est verrouillé ignoré
    C:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
    C:\WINDOWS\system32\5B8U7uQM.exe Infecté : Trojan-Downloader.Win32.Agent.atfv ignoré
    C:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
    C:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
    C:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
    C:\WINDOWS\temp\_avast4_\Webshlock.txt L'objet est verrouillé ignoré
    C:\WINDOWS\temp\Perflib_Perfdata_7bc.dat L'objet est verrouillé ignoré
    C:\WINDOWS\temp\Perflib_Perfdata_300.dat L'objet est verrouillé ignoré
    C:\WINDOWS\temp\Fichiers Internet temporaires\Content.IE5\index.dat L'objet est verrouillé ignoré
    C:\WINDOWS\temp\Cookies\index.dat L'objet est verrouillé ignoré
    C:\WINDOWS\temp\History\History.IE5\index.dat L'objet est verrouillé ignoré
    C:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
    C:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
    C:\WINDOWS\Sti_Trace.log L'objet est verrouillé ignoré
    C:\WINDOWS\wiaservc.log L'objet est verrouillé ignoré
    C:\WINDOWS\wiadebug.log L'objet est verrouillé ignoré
    C:\WINDOWS\ModemLog_Motorola SM56 Speakerphone Modem.txt L'objet est verrouillé ignoré
    C:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
    C:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf1.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Ntf2.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Temp\usgthrsvc\Perflib_Perfdata_924.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy98.gthr L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.ci L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wsb L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010008.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000B.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000C.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000D.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000E.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010011.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010015.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010016.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010019.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001A.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001001B.wid L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.339.gthr L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.339.Crwl L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\tmp.edb L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSStmp.log L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\Windows.edb L'objet est verrouillé ignoré
    C:\Documents and Settings\All Users\Application Data\Microsoft\Search\Data\Applications\Windows\MSS.log L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\NTUSER.DAT L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\ntuser.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Temporary Internet Files\Content.IE5\Q86P4P8Y\1[1].flv L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\ApplicationHistory\hpqimzone.exe.3204510e.ini.inuse L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\CB_Server_Errors.txt L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\administrativeInfo.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\pathnameTable.cdx L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.cdx L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\albumTable.cdx L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\albumImagesTable.cdx L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\keywordTable.cdx L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\keywordImagesTable.cdx L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\managedFolderTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\EXIFTable.cdx L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\ROFTable.cdx L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\ROFImagesTable.cdx L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.dbf L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\propertiesTable.cdx L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\HP\Digital Imaging\db\imageTable.fpt L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\Cache\_CACHE_MAP_ L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\Cache\_CACHE_001_ L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\Cache\_CACHE_002_ L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\Cache\_CACHE_003_ L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\urlclassifier3.sqlite L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\temp\~DFA60B.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\temp\~DFA619.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\temp\~DFB2D8.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Local Settings\temp\~DFB487.tmp L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Cookies\index.dat L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\parent.lock L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\places.sqlite-journal L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\cert8.db L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\key3.db L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\permissions.sqlite L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\places.sqlite L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\downloads.sqlite L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\cookies.sqlite L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\formhistory.sqlite L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\content-prefs.sqlite L'objet est verrouillé ignoré
    C:\Documents and Settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\search.sqlite L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\log\selfdef.log L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat L'objet est verrouillé ignoré
    C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db L'objet est verrouillé ignoré
    C:\System Volume Information\_restore{E34B35B4-6996-48FC-B915-EC3106927D5E}\RP1\change.log L'objet est verrouillé ignoré
    D:\System Volume Information\_restore{E34B35B4-6996-48FC-B915-EC3106927D5E}\RP1\change.log L'objet est verrouillé ignoré
    Analyse terminée.
    0
    1. Contributeur sécurité
      télécharge OTMoveIt
      http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

      double-clique sur OTMoveIt.exe pour le lancer.
      copie la liste qui se trouve en citation ci-dessous,
      et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
      (attention mettre :files )

      :files
      C:\WINDOWS\system32\5B8U7uQM.exe

      clique sur MoveIt! pour lancer la suppression.
      le résultat apparaitra dans le cadre "Results".
      clique sur Exit pour fermer.
      poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

      il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
      0
      1. Je viens de faire la manip :

        Résultat :

        ========== FILES ==========
        C:\WINDOWS\system32\5B8U7uQM.exe moved successfully.

        OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12072008_161017
        0
        1. Voilà le résultat :

          Il y a un fichier qui n'a pas été "deleté" et me demande de rebooté ??? qui dois je faire ?

          Malwarebytes' Anti-Malware 1.31
          Version de la base de données: 1471
          Windows 5.1.2600 Service Pack 3

          2008-12-07 18:02:09
          mbam-log-2008-12-07 (18-02-09).txt

          Type de recherche: Examen complet (C:\|D:\|)
          Eléments examinés: 183126
          Temps écoulé: 38 minute(s), 42 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 3
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 7

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6d794cb4-c7cd-4c6f-bfdc-9b77afbdc02c} (Trojan.Vundo) -> Quarantined and deleted successfully.
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winzzd32 (Dialer) -> Quarantined and deleted successfully.

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          C:\System Volume Information\_restore{E34B35B4-6996-48FC-B915-EC3106927D5E}\RP1\A0000652.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\System Volume Information\_restore{E34B35B4-6996-48FC-B915-EC3106927D5E}\RP1\A0000653.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\System Volume Information\_restore{E34B35B4-6996-48FC-B915-EC3106927D5E}\RP1\A0000654.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Qoobox\Quarantine\C\WINDOWS\system32\orhifkwd.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Qoobox\Quarantine\C\WINDOWS\system32\tuvWqRLe.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Qoobox\Quarantine\C\WINDOWS\system32\uzhvse.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\WINDOWS\system32\ (Dialer) -> Delete on reboot.
          0
          1. J'oubliais le dernier log e HIJACKTHIS

            Logfile of Trend Micro HijackThis v2.0.0 (BETA)
            Scan saved at 18:30, on 2008-12-07
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\PVSW\Bin\WGE_SRV.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\PVSW\BIN\W3dbsmgr.EXE
            C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\SearchIndexer.exe
            c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsGHost.exe
            C:\WINDOWS\Explorer.EXE
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\Wireless Console 2\wcourier.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\system32\wbem\wmiapsrv.exe
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
            C:\Program Files\ASUS\PowerForPhone\PowerForPhone.exe
            C:\WINDOWS\ATK0100\HControl.exe
            C:\WINDOWS\ehome\ehtray.exe
            C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
            C:\WINDOWS\system32\rundll32.exe
            C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\DNA\btdna.exe
            C:\WINDOWS\ATK0100\ATKOSD.exe
            C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
            C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Documents and Settings\LFR\Bureau\HiJackThis_v2.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.akeoportail.com/
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: IEToolbarBHO Class - {1A1DAC8C-074D-440F-8707-7009A672D7D1} - C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\LinkedinIEToolbar.dll
            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
            O2 - BHO: (no name) - {44B3A33C-556A-4CF1-8222-15384F55F22F} - (no file)
            O2 - BHO: (no name) - {73027AC2-C7F4-4F14-AC47-4EC34F369EC1} - (no file)
            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
            O2 - BHO: (no name) - {CBEA270A-78C2-43C2-A95E-2835A74A8B22} - (no file)
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: ASUS Security Protect Manager - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItIEAddIn.dll
            O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
            O3 - Toolbar: LinkedIn Toolbar - {BB670D0B-5C46-40C7-B38B-40DD26987723} - C:\Program Files\LinkedIn\IE Toolbar\3.0.3.1100\LinkedinIEToolbar.dll
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
            O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
            O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
            O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\ASUS\PowerForPhone\PowerForPhone.exe
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
            O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
            O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll,RegisterModule
            O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
            O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
            O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
            O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
            O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
            O4 - Global Startup: MultiFrame.lnk = ?
            O4 - Global Startup: Bluetooth Manager.lnk = ?
            O4 - Global Startup: Démarrage rapide de HP Photosmart Premier.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
            O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
            O8 - Extra context menu item: Ajouter au fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
            O8 - Extra context menu item: Convertir en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
            O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
            O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
            O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
            O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
            O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
            O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
            O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab
            O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
            O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
            O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O20 - AppInit_DLLs: APSHook.dll uzhvse.dll
            O20 - Winlogon Notify: hgGvuSml - C:\WINDOWS\
            O20 - Winlogon Notify: OneCard - c:\Program Files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
            O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
            O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
            O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
            O23 - Service: EBP Pervasive.SQL - Unknown owner - C:\PVSW\Bin\WGE_SRV.exe
            O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
            O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
            O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\system32\imapi.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\system32\mnmsrvc.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
            O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
            O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
            O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
            O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
            O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
            O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
            O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
            O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
            O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\system32\wbem\wmiapsrv.exe
            O23 - Service: Service Partage réseau du Lecteur Windows Media (WMPNetworkSvc) - Unknown owner - C:\Program Files\Windows Media Player\WMPNetwk.exe
            0
            1. Contributeur sécurité
              tu redemarre pour finir le nettoyage de malwarebyte

              puis

              télécharge combofix (par sUBs) ici :

              http://download.bleepingcomputer.com/sUBs/ComboFix.exe

              et enregistre le sur le bureau.

              déconnecte toi d'internet et ferme toutes tes applications.

              désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

              double-clique sur combofix.exe et suis les instructions

              à la fin, il va produire un rapport C:\ComboFix.txt

              réactive ton parefeu, ton antivirus, la garde de ton antispyware

              copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

              Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

              Tu as un tutoriel complet ici :

              https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
              0
              1. Et voila :

                ComboFix 08-12-06.04 - LFR 2008-12-07 20:29:07.3 - [color=red][b]FAT32[/b][/color]x86
                Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.1375 [GMT 1:00]
                Lancé depuis: c:\documents and settings\LFR\Bureau\ComboFix.exe
                .

                ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-07 au 2008-12-07 ))))))))))))))))))))))))))))))))))))
                .

                2008-12-07 19:07 . 2008-12-07 19:08 210 --a------ c:\windows\system32\spupdsvc.inf
                2008-12-07 19:06 . 2008-12-07 19:06 <REP> d-------- c:\windows\SxsCaPendDel
                2008-12-07 19:06 . 2008-12-07 19:06 <REP> d-------- C:\c8ad0ae3ccdf2468d6
                2008-12-07 17:21 . 2008-12-07 17:21 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                2008-12-07 17:21 . 2008-12-07 17:21 <REP> d-------- c:\documents and settings\LFR\Application Data\Malwarebytes
                2008-12-07 17:21 . 2008-12-07 17:21 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                2008-12-07 17:21 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                2008-12-07 17:21 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                2008-12-07 16:10 . 2008-12-07 16:10 <REP> d-------- C:\_OTMoveIt
                2008-12-07 12:51 . 2008-12-07 12:51 <REP> d-------- c:\program files\RegCleaner
                2008-12-07 02:16 . 2008-12-07 02:16 <REP> d-------- c:\program files\Yahoo!
                2008-12-06 21:24 . 2008-12-06 21:57 127 --a------ c:\windows\wininit.ini
                2008-12-06 21:01 . 2008-12-06 21:01 <REP> dr------- c:\documents and settings\NetworkService\Favoris
                2008-12-06 21:01 . 2008-12-06 21:01 <REP> d-------- c:\documents and settings\NetworkService\Application Data\LinkedIn
                2008-12-06 20:37 . 2008-12-06 20:37 <REP> d-------- c:\windows\HDTVXviD Codec
                2008-11-28 13:12 . 2008-11-28 13:12 410,976 --a------ c:\windows\system32\deploytk.dll
                2008-11-26 16:03 . 2008-11-26 16:03 <REP> d-------- c:\program files\Virtual Earth 3D
                2008-11-26 13:52 . 2008-11-26 13:52 <REP> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
                2008-11-16 12:55 . 2008-11-16 12:55 <REP> d--h----- c:\documents and settings\All Users\Application Data\{B9701F15-283E-476B-9DF5-EEC72005FA5F}
                2008-11-16 12:55 . 2008-05-01 10:58 3,715,072 --a------ c:\windows\system32\cdintf300.dll
                2008-11-12 11:25 . 2008-09-04 18:16 1,106,944 --------- c:\windows\system32\dllcache\msxml3.dll
                2008-11-12 11:25 . 2008-10-24 12:21 455,296 --------- c:\windows\system32\dllcache\mrxsmb.sys
                2008-11-09 18:46 . 2008-11-09 18:46 <REP> d-------- c:\program files\Fichiers communs\xing shared

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-11-09 18:06 3,532 ----a-w C:\drmHeader.bin
                2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx0c.dll
                2008-10-28 22:36 823,296 ----a-w c:\windows\system32\divx_xx07.dll
                2008-10-28 22:35 815,104 ----a-w c:\windows\system32\divx_xx0a.dll
                2008-10-28 22:35 802,816 ----a-w c:\windows\system32\divx_xx11.dll
                2008-10-28 22:35 684,032 ----a-w c:\windows\system32\DivX.dll
                2008-10-26 16:33 --------- d-----w c:\documents and settings\INDIGO_GS\Application Data\Toshiba
                2008-10-25 16:45 --------- d-----w c:\program files\Neuf
                2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
                2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
                2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
                2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
                2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
                2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
                2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
                2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
                2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
                2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
                2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
                2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
                2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
                2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
                2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
                2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
                2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
                2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
                2008-10-15 17:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
                2008-10-14 13:24 --------- d-----w c:\program files\BurnAware Free
                2008-10-13 19:39 --------- d-----w c:\program files\SystemRequirementsLab
                2008-10-13 19:39 --------- d-----w c:\documents and settings\LFR\Application Data\SystemRequirementsLab
                2008-10-13 15:39 --------- d-----w c:\documents and settings\INDIGO_GS\Application Data\DivX
                2008-10-12 18:29 --------- d--h--r c:\documents and settings\LFR\Application Data\Asus MiVo Messenger
                2008-10-12 17:45 --------- d-----w c:\program files\ma-config.com
                2008-10-12 17:45 --------- d-----w c:\documents and settings\All Users\Application Data\ma-config.com
                2008-10-12 17:12 --------- d-----w c:\program files\Reference Assemblies
                2008-10-03 18:12 6,066,176 ------w c:\windows\system32\dllcache\ieframe.dll
                2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
                2008-09-25 08:03 81,920 ----a-w c:\windows\system32\dpl100.dll
                2008-09-25 08:03 593,920 ----a-w c:\windows\system32\dpuGUI11.dll
                2008-09-25 08:03 57,344 ----a-w c:\windows\system32\dpv11.dll
                2008-09-25 08:03 53,248 ----a-w c:\windows\system32\dpuGUI10.dll
                2008-09-25 08:03 524,288 ----a-w c:\windows\system32\DivXsm.exe
                2008-09-25 08:03 344,064 ----a-w c:\windows\system32\dpus11.dll
                2008-09-25 08:03 294,912 ----a-w c:\windows\system32\dpu11.dll
                2008-09-25 08:03 294,912 ----a-w c:\windows\system32\dpu10.dll
                2008-09-25 08:03 196,608 ----a-w c:\windows\system32\dtu100.dll
                2008-09-25 08:03 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
                2008-09-19 21:57 3,596,288 ----a-w c:\windows\system32\qt-dx331.dll
                2008-09-19 21:55 200,704 ----a-w c:\windows\system32\ssldivx.dll
                2008-09-19 21:55 1,044,480 ----a-w c:\windows\system32\libdivx.dll
                2008-09-19 21:54 12,288 ----a-w c:\windows\system32\DivXWMPExtType.dll
                2008-09-15 16:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
                2008-09-15 16:26 1,846,528 ------w c:\windows\system32\dllcache\win32k.sys
                2008-09-10 01:15 1,307,648 ------w c:\windows\system32\msxml6.dll
                2008-09-10 01:15 1,307,648 ------w c:\windows\system32\dllcache\msxml6.dll
                2008-09-08 11:41 333,824 ------w c:\windows\system32\dllcache\srv.sys
                2008-04-02 08:48 32 ----a-w c:\documents and settings\All Users\Application Data\ezsid.dat
                2006-11-17 18:27 2,532,922 ----a-w c:\windows\inf\SET44D.tmp
                2006-03-24 19:00 1,568,358 ----a-w c:\windows\inf\SET4C0.tmp
                2005-11-04 16:15 1,228,800 ----a-w c:\program files\Fichiers communs\vfp9rfra.dll
                2005-11-04 16:13 4,722,688 ----a-w c:\program files\Fichiers communs\vfp9r.dll
                2005-11-04 16:13 3,891,200 ----a-w c:\program files\Fichiers communs\vfp9t.dll
                2005-11-04 15:44 1,187,840 ----a-w c:\program files\Fichiers communs\VFP9RENU.DLL
                2001-09-06 05:00 1,700,352 ----a-w c:\program files\Fichiers communs\gdiplus.dll
                .

                ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                REGEDIT4

                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Secure Disks]
                @="{666C7836-A9B6-4AB4-94ED-DC238C81E925}"
                [HKEY_CLASSES_ROOT\CLSID\{666C7836-A9B6-4AB4-94ED-DC238C81E925}]
                2006-04-02 17:08 381952 -ra------ c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\SFSShell.dll

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-11-12 342336]
                "H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "!AVG Anti-Spyware"="c:\program files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 6731312]
                "Wireless Console 2"="c:\program files\Wireless Console 2\wcourier.exe" [2005-10-17 987136]
                "TomTomHOME.exe"="c:\program files\TomTom HOME 2\HOMERunner.exe" [2007-08-15 374688]
                "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-05-25 786521]
                "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-28 136600]
                "SMSERIAL"="c:\program files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-08-06 573440]
                "Power_Gear"="c:\program files\ASUS\Power4 Gear\BatteryLife.exe" [2006-03-14 90112]
                "PowerForPhone"="c:\program files\ASUS\PowerForPhone\PowerForPhone.exe" [2006-06-29 774144]
                "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-09-06 86016]
                "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-09-06 7585792]
                "HControl"="c:\windows\ATK0100\HControl.exe" [2006-04-17 110592]
                "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
                "CognizanceTS"="c:\progra~1\ASUSSE~1\ASUSSE~1\Bin\ASTSVCC.dll" [2003-12-22 17920]
                "ATKMEDIA"="c:\program files\ASUS\ATK Media\DMEDIA.EXE" [2006-06-08 53248]
                "ABLKSR"="c:\windows\ABLKSR\ABLKSR.exe" [2006-01-02 61440]
                "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
                "IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-08-02 802816]
                "IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-08-02 696320]
                "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]
                "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-01-09 282624]
                "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-11-09 185872]
                "SkyTel"="SkyTel.EXE" [2006-05-16 c:\windows\SkyTel.exe]
                "RTHDCPL"="RTHDCPL.EXE" [2006-07-21 c:\windows\RTHDCPL.exe]
                "nwiz"="nwiz.exe" [2006-09-06 c:\windows\system32\nwiz.exe]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                c:\documents and settings\LFR\Menu D‚marrer\Programmes\D‚marrage\
                Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 113664]

                c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                MultiFrame.lnk - c:\program files\ASUS\Asus MultiFrame\MultiFrame.exe [2006-12-16 491520]
                Bluetooth Manager.lnk - c:\program files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe [2006-05-16 1777664]
                D‚marrage rapide de HP Photosmart Premier.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 73728]
                Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]

                [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OneCard]
                2006-05-02 22:23 40448 c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hgGvuSml]
                [BU]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                "AppInit_DLLs"=APSHook.dll uzhvse.dll

                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ati2bhxx.sys]
                @="Driver"

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                "DisableMonitoring"=dword:00000001

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                "EnableFirewall"= 0 (0x0)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                "c:\\Program Files\\BitTorrent\\bittorrent.exe"=
                "c:\\Program Files\\Messenger\\msmsgs.exe"=
                "c:\\Program Files\\Real\\RealPlayer\\RealPlay.exe"=
                "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                "c:\\Program Files\\DNA\\btdna.exe"=
                "c:\\PVSW\\Bin\\W3DBSMGR.EXE"=
                "c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
                "c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
                "c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                "%windir%\\system32\\sessmgr.exe"=
                "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                "c:\\Program Files\\EBP\\TPE13.0\\TPE.exe"=

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

                R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-03-31 111184]
                R1 ItSDisk;ItSDisk;c:\windows\system32\Drivers\ItSDisk.sys [2006-05-16 17840]
                R2 ASChannel;Canal de communication local;c:\windows\System32\svchost.exe -k Cognizance [2006-09-15 14336]
                R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-03-31 20560]
                R2 EBP Pervasive.SQL;EBP Pervasive.SQL;c:\pvsw\Bin\WGE_SRV.exe [2006-12-07 32768]
                R3 SynMini;USB2.0 1.3M WebCam;c:\windows\system32\Drivers\SynMini.sys [2006-12-16 1116544]
                R3 SynScan;USB2.0 1.3M WebCam Still Image;c:\windows\system32\Drivers\SynScan.sys [2006-12-16 7808]
                S0 ati2bhxx;ati2bhxx;c:\windows\system32\Drivers\ati2bhxx.sys []
                S3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys [2006-12-16 34944]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                Cognizance REG_MULTI_SZ ASChannel
                HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0f6ce808-9814-11db-8ca4-0018f38d619b}]
                \Shell\AutoRun\command - F:\Autorun.exe

                *Newly Created Service* - CATCHME

                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7E391C66-844C-D2A9-EC12-95EC44BF8228}]
                c:\windows\system32\updating\update.exe s
                .
                Contenu du dossier 'Tâches planifiées'

                2008-12-06 c:\windows\Tasks\At1.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-07 c:\windows\Tasks\At2.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At3.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At4.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At5.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At6.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At7.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At8.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At9.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At10.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At11.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-07 c:\windows\Tasks\At12.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-07 c:\windows\Tasks\At13.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-07 c:\windows\Tasks\At14.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-07 c:\windows\Tasks\At15.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-07 c:\windows\Tasks\At16.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-07 c:\windows\Tasks\At17.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-07 c:\windows\Tasks\At18.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-07 c:\windows\Tasks\At19.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-07 c:\windows\Tasks\At20.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At21.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At22.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At23.job
                - c:\windows\system32\5B8U7uQM.exe []

                2008-12-06 c:\windows\Tasks\At24.job
                - c:\windows\system32\5B8U7uQM.exe []
                .
                - - - - ORPHELINS SUPPRIMES - - - -

                BHO-{44B3A33C-556A-4CF1-8222-15384F55F22F} - (no file)
                BHO-{73027AC2-C7F4-4F14-AC47-4EC34F369EC1} - (no file)
                BHO-{CBEA270A-78C2-43C2-A95E-2835A74A8B22} - (no file)

                .
                ------- Examen supplémentaire -------
                .
                uStart Page = hxxp://www.akeoportail.com/
                uInternet Settings,ProxyOverride = <local>
                IE: Ajouter au fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                IE: Convertir en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                IE: Convertir la cible du lien en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                IE: Convertir la cible du lien en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                IE: Convertir la sélection en Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
                IE: Convertir la sélection en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
                IE: Convertir les liens sélectionnés en fichier Adobe PDF - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                IE: Convertir les liens sélectionnés en un fichier PDF existant - c:\program files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
                IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000

                c:\windows\bdoscandellang.ini - c:\windows\bdoscandel.exe
                c:\windows\Downloaded Program Files\live.ini
                c:\windows\Downloaded Program Files\scanoptions.tsi
                c:\windows\Downloaded Program Files\lang.ini
                c:\windows\Downloaded Program Files\ipsupd.dll
                c:\windows\Downloaded Program Files\bdupd.dll
                c:\windows\Downloaded Program Files\libfn.dll
                c:\windows\Downloaded Program Files\bdcore.dll
                c:\windows\Downloaded Program Files\oscan8.ocx
                O16 -: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
                hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                c:\windows\Downloaded Program Files\oscan8.inf
                FireFox -: Profile - c:\documents and settings\LFR\Application Data\Mozilla\Firefox\Profiles\l0gsu41x.default\
                FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.asus.com/
                FF -: plugin - c:\program files\Adobe\Acrobat 8.0\Acrobat\browser\nppdf32.dll
                FF -: plugin - c:\program files\DNA\plugins\npbtdna.dll
                FF -: plugin - c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
                FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll
                FF -: plugin - c:\program files\Java\jre6\bin\new_plugin\npjp2.dll
                FF -: plugin - c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
                FF -: plugin - c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
                FF -: plugin - c:\program files\Mozilla Firefox\plugins\npdeploytk.dll
                FF -: plugin - c:\program files\Virtual Earth 3D\npVE3D.dll
                FF -: plugin - c:\program files\Yahoo!\Common\npyaxmpb.dll
                FF -: plugin - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
                .

                **************************************************************************

                catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-12-07 20:30:11
                Windows 5.1.2600 Service Pack 3 FAT NTAPI

                Recherche de processus cachés ...

                Recherche d'éléments en démarrage automatique cachés ...

                Recherche de fichiers cachés ...

                Scan terminé avec succès
                Fichiers cachés: 0

                **************************************************************************
                .
                --------------------- DLLs chargées dans les processus actifs ---------------------

                - - - - - - - > 'winlogon.exe'(656)
                c:\windows\system32\APSHook.dll
                c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ASWLNPkg.dll
                c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\AsChnl.dll
                c:\program files\ASUS Security Center\ASUS Security Protect Manager\Bin\ItMsg.dll

                - - - - - - - > 'lsass.exe'(712)
                c:\windows\system32\APSHook.dll
                .
                Heure de fin: 2008-12-07 20:30:42
                ComboFix3.txt 2008-01-19 09:04:44
                ComboFix-quarantined-files.txt 2008-12-07 19:30:42
                ComboFix2.txt 2008-12-07 09:12:54

                Avant-CF: 38,320,340,992 octets libres
                Après-CF: 38,492,766,208 octets libres

                WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
                [boot loader]
                timeout=2
                default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
                [operating systems]
                c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect

                320 --- E O F --- 2008-11-12 11:08:12
                0
                1. Contributeur sécurité
                  vire toutes les taches planifiées sauf "creer une nouvelle tache"
                  en allant dans poste de travail puis

                  c:\windows\Tasks

                  ____________

                  utilise pour supprimer tes traces

                  CCLEANER: (lance un nettoyage et répare 3 fois le registre) sans installer la barre yahoo
                  (dans les options puis avancé :désactive la case: effacer les fichiers de plus de 48 heures)
                  https://www.malekal.com/tutoriel-ccleaner/
                  https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

                  _______________

                  encore des soucis? explique
                  0
                  1. Merci cela parrait mieux....

                    Mais j'ai un nouveau souci, j'au une message d'erreur de Microsoft .NET Framework : "une exception non gérée s'est produite dans un composant de votre application. Si vous ...... La référence d'objet n'est pas définie à une instance d'un objet"

                    Et impossible de la faire disparaitre en cliquant sur Continuer....:

                    Voila le détail :

                    Consultez la fin de ce message pour plus de détails sur l'appel du débogage
                    juste-à-temps (JIT) à la place de cette boîte de dialogue.

                    ************** Texte de l'exception **************
                    System.NullReferenceException: La référence d'objet n'est pas définie à une instance d'un objet.
                    at HP.CUE.Video.PlaybackControl.UpdateProgressBar()
                    at HP.CUE.Video.PlaybackControl._ProgressTimer_Tick(Object sender, EventArgs e)
                    at System.Windows.Forms.Timer.OnTick(EventArgs e)
                    at System.Windows.Forms.Timer.Callback(IntPtr hWnd, Int32 msg, IntPtr idEvent, IntPtr dwTime)

                    ************** Assemblys chargés **************
                    mscorlib
                    Version de l'assembly : 1.0.5000.0
                    Version Win32 : 1.1.4322.2407
                    CodeBase : file:///c:/windows/microsoft.net/framework/v1.1.4322/mscorlib.dll
                    ----------------------------------------
                    hpqimzone
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///C:/Program%20Files/HP/Digital%20Imaging/bin/hpqimzone.exe
                    ----------------------------------------
                    hpqiface
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqiface/4.0.0.0__a53cf5803f4c3827/hpqiface.dll
                    ----------------------------------------
                    System.Windows.Forms
                    Version de l'assembly : 1.0.5000.0
                    Version Win32 : 1.1.4322.2032
                    CodeBase : file:///c:/windows/assembly/gac/system.windows.forms/1.0.5000.0__b77a5c561934e089/system.windows.forms.dll
                    ----------------------------------------
                    System.Drawing
                    Version de l'assembly : 1.0.5000.0
                    Version Win32 : 1.1.4322.2032
                    CodeBase : file:///c:/windows/assembly/gac/system.drawing/1.0.5000.0__b03f5f7f11d50a3a/system.drawing.dll
                    ----------------------------------------
                    System
                    Version de l'assembly : 1.0.5000.0
                    Version Win32 : 1.1.4322.2407
                    CodeBase : file:///c:/windows/assembly/gac/system/1.0.5000.0__b77a5c561934e089/system.dll
                    ----------------------------------------
                    hpqcc2
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqcc2/3.0.0.0__a53cf5803f4c3827/hpqcc2.dll
                    ----------------------------------------
                    hpqutils
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqutils/4.0.0.0__a53cf5803f4c3827/hpqutils.dll
                    ----------------------------------------
                    hpqfmrsc
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqfmrsc/4.0.0.0__a53cf5803f4c3827/hpqfmrsc.dll
                    ----------------------------------------
                    hpqtray
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqtray/4.0.0.0__a53cf5803f4c3827/hpqtray.dll
                    ----------------------------------------
                    hpqovskn
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqovskn/3.0.0.0__a53cf5803f4c3827/hpqovskn.dll
                    ----------------------------------------
                    hpqthumb
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqthumb/3.0.0.0__a53cf5803f4c3827/hpqthumb.dll
                    ----------------------------------------
                    hpqimvlt
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqimvlt/3.0.0.0__a53cf5803f4c3827/hpqimvlt.dll
                    ----------------------------------------
                    hpqimgrc
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqimgrc/4.0.0.0__a53cf5803f4c3827/hpqimgrc.dll
                    ----------------------------------------
                    hpqimzone.resources
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.099.000
                    CodeBase : file:///C:/Program%20Files/HP/Digital%20Imaging/bin/fr/hpqimzone.resources.DLL
                    ----------------------------------------
                    hpqntrop
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqntrop/4.0.0.0__a53cf5803f4c3827/hpqntrop.dll
                    ----------------------------------------
                    Interop.hpqcxm08
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 70.0.170.000
                    CodeBase : file:///c:/windows/assembly/gac/interop.hpqcxm08/3.0.0.0__a53cf5803f4c3827/interop.hpqcxm08.dll
                    ----------------------------------------
                    System.Xml
                    Version de l'assembly : 1.0.5000.0
                    Version Win32 : 1.1.4322.2032
                    CodeBase : file:///c:/windows/assembly/gac/system.xml/1.0.5000.0__b77a5c561934e089/system.xml.dll
                    ----------------------------------------
                    LEAD
                    Version de l'assembly : 13.0.0.113
                    Version Win32 : 13.0.0.113
                    CodeBase : file:///c:/windows/assembly/gac/lead/13.0.0.113__9cf889f53ea9b907/lead.dll
                    ----------------------------------------
                    LEAD.Wrapper
                    Version de l'assembly : 13.0.0.113
                    Version Win32 : 13.0.0.113
                    CodeBase : file:///c:/windows/assembly/gac/lead.wrapper/13.0.0.113__9cf889f53ea9b907/lead.wrapper.dll
                    ----------------------------------------
                    hpqtray.resources
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.099.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqtray.resources/4.0.0.0_fr_a53cf5803f4c3827/hpqtray.resources.dll
                    ----------------------------------------
                    hpqfmrsc.resources
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.099.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqfmrsc.resources/4.0.0.0_fr_a53cf5803f4c3827/hpqfmrsc.resources.dll
                    ----------------------------------------
                    LEAD.Windows.Forms
                    Version de l'assembly : 13.0.0.113
                    Version Win32 : 13.0.0.113
                    CodeBase : file:///c:/windows/assembly/gac/lead.windows.forms/13.0.0.113__9cf889f53ea9b907/lead.windows.forms.dll
                    ----------------------------------------
                    LEAD.Drawing
                    Version de l'assembly : 13.0.0.113
                    Version Win32 : 13.0.0.113
                    CodeBase : file:///c:/windows/assembly/gac/lead.drawing/13.0.0.113__9cf889f53ea9b907/lead.drawing.dll
                    ----------------------------------------
                    interop.hpqimgr
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 4.0.0.0
                    CodeBase : file:///c:/windows/assembly/gac/interop.hpqimgr/4.0.0.0__a53cf5803f4c3827/interop.hpqimgr.dll
                    ----------------------------------------
                    hpqasset
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqasset/4.0.0.0__a53cf5803f4c3827/hpqasset.dll
                    ----------------------------------------
                    hpqmirsc
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///C:/Program%20Files/HP/Digital%20Imaging/bin/hpqmirsc.DLL
                    ----------------------------------------
                    hpqmirsc.resources
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.099.000
                    CodeBase : file:///C:/Program%20Files/HP/Digital%20Imaging/bin/fr/hpqmirsc.resources.DLL
                    ----------------------------------------
                    hpqedit
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqedit/3.0.0.0__a53cf5803f4c3827/hpqedit.dll
                    ----------------------------------------
                    hpqvideo
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqvideo/3.0.0.0__a53cf5803f4c3827/hpqvideo.dll
                    ----------------------------------------
                    LEAD.Windows.Forms.DrawingContainer
                    Version de l'assembly : 13.0.0.113
                    Version Win32 : 13.0.0.113
                    CodeBase : file:///c:/windows/assembly/gac/lead.windows.forms.drawingcontainer/13.0.0.113__9cf889f53ea9b907/lead.windows.forms.drawingcontainer.dll
                    ----------------------------------------
                    hpqmdmr
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqmdmr/4.0.0.0__a53cf5803f4c3827/hpqmdmr.dll
                    ----------------------------------------
                    LEAD.Drawing.Imaging.ImageProcessing
                    Version de l'assembly : 13.0.0.113
                    Version Win32 : 13.0.0.113
                    CodeBase : file:///c:/windows/assembly/gac/lead.drawing.imaging.imageprocessing/13.0.0.113__9cf889f53ea9b907/lead.drawing.imaging.imageprocessing.dll
                    ----------------------------------------
                    hpqimlib
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqimlib/3.0.0.0__a53cf5803f4c3827/hpqimlib.dll
                    ----------------------------------------
                    hpqedit.resources
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.099.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqedit.resources/3.0.0.0_fr_a53cf5803f4c3827/hpqedit.resources.dll
                    ----------------------------------------
                    hpqglutl
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 065.000.117.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqglutl/4.0.0.0__a53cf5803f4c3827/hpqglutl.dll
                    ----------------------------------------
                    hpqcc2.resources
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.099.000
                    CodeBase : file:///c:/windows/assembly/gac/hpqcc2.resources/3.0.0.0_fr_a53cf5803f4c3827/hpqcc2.resources.dll
                    ----------------------------------------
                    hpqvideo.resources
                    Version de l'assembly : 3.0.0.0
                    Version Win32 : 065.000.099.000
                    CodeBase : file:///C:/Program%20Files/HP/Digital%20Imaging/bin/fr/hpqvideo.resources.DLL
                    ----------------------------------------
                    Interop.hpqvideo
                    Version de l'assembly : 4.0.0.0
                    Version Win32 : 4.0.0.0
                    CodeBase : file:///c:/windows/assembly/gac/interop.hpqvideo/4.0.0.0__a53cf5803f4c3827/interop.hpqvideo.dll
                    ----------------------------------------
                    mscorlib.resources
                    Version de l'assembly : 1.0.5000.0
                    Version Win32 : 1.1.4322.573
                    CodeBase : file:///c:/windows/assembly/gac/mscorlib.resources/1.0.5000.0_fr_b77a5c561934e089/mscorlib.resources.dll
                    ----------------------------------------
                    SYSTEM.WINDOWS.FORMS.resources
                    Version de l'assembly : 1.0.5000.0
                    Version Win32 : 1.1.4322.573
                    CodeBase : file:///c:/windows/assembly/gac/system.windows.forms.resources/1.0.5000.0_fr_b77a5c561934e089/system.windows.forms.resources.dll
                    ----------------------------------------

                    ************** Débogage JIT **************
                    Pour activer le débogage juste-à-temps (JIT), le fichier de configuration pour cette
                    application ou cet ordinateur (machine.config) doit avoir la valeur
                    jitDebugging définie dans la section system.windows.forms.
                    L'application doit également être compilée avec le débogage
                    activé.

                    Par exemple :

                    <configuration>
                    <system.windows.forms jitDebugging="true" />
                    </configuration>

                    Lorsque le débogage juste-à-temps est activé, les exceptions non gérées
                    seront envoyées au débogueur JIT inscrit sur l'ordinateur
                    plutôt que d'être gérées par cette boîte de dialogue.
                    0
                    1. A priori tout est rentré dans l'ordre, j'ai réinstaller mon "centre de solution HP" qui posait pb avec .net Framework.

                      merci ton aide.

                      Lor_enzo
                      0