Pb malware bloque MAJ

Résolu
Bonjour,
mon ordinateur a contracter un spyware , et maintenant quand je clique sur un lien, je suis amener sur un autre site , je ne suis maintenant plus capable de mettre avast a jour , j'ai le message Imposible de se connecter au serveur et sa me fait la même chose quand j'essaie d'instaler "Spypot "
je pe envoyer un rapport hijackthis peut etre? je ss un peu bcp en galere !
Configuration: Windows XP
Internet Explorer 6.0

37 réponses

Résumé de la discussion

Une infection par spyware empêche les mises à jour d' Avast et redirige les clics de liens vers d'autres sites, sur un système Windows XP avec Internet Explorer 6. Des mesures recommandées incluent la mise à jour d'Internet Explorer et un scan en ligne via Kaspersky, puis l'utilisation de ToolsCleaner2 et CCleaner pour nettoyer le système et le registre. D'autres préconisations portent sur la désactivation puis réactivation de la restauration système, la création d'un point de restauration et le recours à Antivir avec MBAM, privilégiant Firefox et Noscript. En complément, il est suggéré de vérifier ou modifier le fichier hosts et d'envisager des extensions de sécurité comme NoScript pour Mozilla Firefox pour augmenter la vigilance lors de la navigation.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut,

    Ne te fais pas aider par plusieurs forums à la fois, risque de plantage :
    http://www.infos-du-net.com/forum/284161-11-discussion#t352676
    3
    1. colle le rapport hijack. merci.
      0
      1. je ne me rapel plus trop si il suffi de cliquer sur " do a system scan and save a logfile" :s
        j'envoi le rappor :

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 15:15:59, on 15/12/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\WINDOWS\system32\WgaTray.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\RTHDCPL.EXE
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\PowerArchiver\PASTARTER.EXE
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Hercules\WiFi Station\WifiStation.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\BitComet\BitComet.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] C:\Program Files\Uniblue\RegistryBooster\RegistryBooster.exe /S
        O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: WiFi Station.lnk = ?
        O8 - Extra context menu item: &T&élécharger &avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
        O8 - Extra context menu item: &T&élécharger tout avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
        O8 - Extra context menu item: &T&élécharger toute vidéo avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O10 - Unknown file in Winsock LSP: c:\windows\system32\gnbihsre.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\gnbihsre.dll
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
        O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.systemrequirementslab.com/cyri
        O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - https://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        0
        1. la je connais pas trop, passe smitfraud fix

          Télécharge SmitfraudFix
          Utilitaire de S!Ri: Moe et balltrap34
          http://siri.urz.free.fr/Fix/SmitfraudFix.php
          et télécharge SmitfraudFix.exe.

          Exécute le en choisissant l’option 1,
          il va générer un rapport
          Copie/colle le sur le poste stp.
          0
          1. ok je t'envoi le rapport de smitfraudfix:

            SmitFraudFix v2.385

            Rapport fait à 15:28:01,46, 15/12/2008
            Executé à partir de C:\Documents and Settings\VINCE\Bureau\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\WINDOWS\system32\WgaTray.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\PowerArchiver\PASTARTER.EXE
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\Program Files\Hercules\WiFi Station\WifiStation.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\wscntfy.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\BitComet\BitComet.exe
            C:\Documents and Settings\VINCE\Bureau\SmitfraudFix\Policies.exe
            C:\WINDOWS\system32\cmd.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

            C:\WINDOWS\system32\tdssservers.dat détecté, utilisez un scanner de Rootkit
            C:\WINDOWS\system32\tdssadw.dll détecté, utilisez un scanner de Rootkit
            C:\WINDOWS\system32\tdssinit.dll détecté, utilisez un scanner de Rootkit
            C:\WINDOWS\system32\tdssl.dll détecté, utilisez un scanner de Rootkit
            C:\WINDOWS\system32\tdsslog.dll détecté, utilisez un scanner de Rootkit
            C:\WINDOWS\system32\tdssmain.dll détecté, utilisez un scanner de Rootkit
            C:\WINDOWS\system32\drivers\tdssserv.sys détecté, utilisez un scanner de Rootkit

            »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\VINCE

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\VINCE\LOCALS~1\Temp

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\VINCE\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\VINCE\Favoris

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            C:\Program Files\Google\googletoolbar1.dll PRESENT !

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
            "Source"="About:Home"
            "SubscribedURL"="About:Home"
            "FriendlyName"="Ma page d'accueil"

            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            o4Patch
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            Agent.OMZ.Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"=""

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: Hercules Wireless G PCI - Miniport d'ordonnancement de paquets
            DNS Server Search Order: 192.168.1.254

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{39BEAC45-91A1-40D1-98CB-FB0FAE5B73F7}: DhcpNameServer=192.168.1.254
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{39BEAC45-91A1-40D1-98CB-FB0FAE5B73F7}: DhcpNameServer=192.168.1.254
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{39BEAC45-91A1-40D1-98CB-FB0FAE5B73F7}: DhcpNameServer=192.168.1.254
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin
            0
            1. OK , encore un p..... de rootkit.

              pour voir télécharge combofix (par sUBs) ici :

              http://download.bleepingcomputer.com/sUBs/ComboFix.exe

              et enregistre le sur le bureau.

              déconnecte toi d'internet et ferme toutes tes applications.

              désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

              double-clique sur combofix.exe et suis les instructions

              à la fin, il va produire un rapport C:\ComboFix.txt

              réactive ton parefeu, ton antivirus, la garde de ton antispyware

              copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

              Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

              Tu as un tutoriel complet ici :

              https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
              0
              1. le lien de combofix ne fonctione pas, je le telecharge moi meme?
                0
                1. je ne parvien pas a telecharger combofix :s
                  0
                  1. passe cet antimalware, fait comme indique
                    Telecharges malwaresbytes antimalwares(MBAM) : egalement tres util sur pb de pub mais pas tous malheureusement

                    Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                    Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
                    fais comme indique,mise a jour , scan complet en mode sans echec et les rapports.
                    COLLE LE RAPPORT APRES SUPPRESSION MERCI.

                    garde le et lance un scan tout les mois comme indique.

                    si tu as ad aware tu peux desinstalle car il ne reconnait plus grand chose.
                    0
                    1. le lien pour malware ne marche pas
                      j'avais essayer de l'installer avant mais il ne se lancé pas
                      0
                      1. Modérateur
                        http://sd-1.archive-host.com/membres/up/3288717712384394/ComboFix.exe

                        Si tu arrives à télécharger ComboFix, renomme-le en Combo-Fix s'il ne se lance pas.
                        0
                        1. voici le rapport combofix :

                          ComboFix 08-12-15.01 - VINCE 2008-12-15 22:52:48.1 - NTFSx86
                          Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1023.806 [GMT 1:00]
                          Lancé depuis: c:\downloads\ComboFix.exe

                          [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
                          .

                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          c:\windows\system32\404Fix.exe
                          c:\windows\system32\config\47733372.Evt
                          c:\windows\system32\drivers\TDSSserv.sys
                          c:\windows\system32\dumphive.exe
                          c:\windows\system32\IEDFix.C.exe
                          c:\windows\system32\IEDFix.exe
                          c:\windows\system32\o4Patch.exe
                          c:\windows\system32\Process.exe
                          c:\windows\system32\SrchSTS.exe
                          c:\windows\system32\TDSSadw.dll
                          c:\windows\system32\TDSSerrors.log
                          c:\windows\system32\tdssinit.dll
                          c:\windows\system32\tdssl.dll
                          c:\windows\system32\tdsslog.dll
                          c:\windows\system32\TDSSmain.dll
                          c:\windows\system32\TDSSserf.dll
                          c:\windows\system32\tdssservers.dat
                          c:\windows\system32\tmp.reg
                          c:\windows\system32\VACFix.exe
                          c:\windows\system32\VCCLSID.exe
                          c:\windows\system32\WS2Fix.exe

                          .
                          ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          -------\Service_TDSSSERV
                          -------\Legacy_TDSSSERV
                          -------\Service_asc3550p

                          ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-15 au 2008-12-15 ))))))))))))))))))))))))))))))))))))
                          .

                          2008-12-15 15:27 . 2008-12-12 00:57 78,336 --a------ c:\windows\system32\Agent.OMZ.Fix.exe
                          2008-12-15 15:15 . 2008-12-15 15:15 <REP> d-------- c:\program files\Trend Micro
                          2008-12-15 14:36 . 2008-12-15 16:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                          2008-12-14 20:27 . 2008-12-14 20:27 <REP> d-------- c:\documents and settings\All Users\Application Data\NVIDIA
                          2008-12-06 19:40 . 2008-12-06 19:40 <REP> d-------- c:\program files\OpenAL
                          2008-12-06 19:40 . 2008-12-06 19:50 413,696 --a------ c:\windows\system32\wrap_oal.dll
                          2008-12-06 19:40 . 2008-12-06 19:50 110,592 --a------ c:\windows\system32\OpenAL32.dll
                          2008-12-05 18:45 . 2008-12-15 14:02 <REP> d-------- c:\program files\PowerArchiver
                          2008-11-30 11:23 . 2008-11-30 11:23 573,473 --a------ c:\windows\system32\WBOCX.OCX
                          2008-11-30 11:23 . 2008-11-30 11:23 56,496 --a------ c:\windows\system32\WBHELP2.DLL
                          2008-11-29 00:33 . 2008-12-15 22:48 69 --a------ c:\windows\NeroDigital.ini
                          2008-11-29 00:31 . 2008-11-29 00:32 <REP> d-------- c:\program files\Fichiers communs\Ahead
                          2008-11-29 00:31 . 2008-11-29 00:31 <REP> d-------- c:\program files\Ahead
                          2008-11-29 00:31 . 2004-07-26 17:16 1,568,768 --------- c:\windows\system32\ImagX7.dll
                          2008-11-29 00:31 . 2004-07-26 17:16 476,320 --------- c:\windows\system32\ImagXpr7.dll
                          2008-11-29 00:31 . 2004-07-26 17:16 471,040 --------- c:\windows\system32\ImagXRA7.dll
                          2008-11-29 00:31 . 2004-07-26 17:16 262,144 --------- c:\windows\system32\ImagXR7.dll
                          2008-11-29 00:31 . 2001-07-09 11:50 155,648 --a------ c:\windows\system32\NeroCheck.exe
                          2008-11-29 00:31 . 2000-06-26 11:45 106,496 --a------ c:\windows\system32\TwnLib20.dll
                          2008-11-23 19:07 . 2008-11-23 19:07 86,016 --a------ c:\windows\system32\gnbihsre.dll
                          2008-11-19 19:33 . 2008-11-19 19:33 <REP> d-------- c:\documents and settings\VINCE\Application Data\Capcom

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2008-12-15 21:58 --------- d-----w c:\program files\eMule
                          2008-12-06 18:52 --------- d-----w c:\documents and settings\All Users\Application Data\TrackMania
                          2008-12-06 18:44 --------- d--h--w c:\program files\InstallShield Installation Information
                          2008-11-26 12:47 --------- d-----w c:\program files\BitComet
                          2008-11-17 22:38 --------- d-----w c:\program files\Fichiers communs\InstallShield
                          2008-11-04 15:37 --------- d-----w c:\program files\Electronic Arts
                          2008-10-31 13:40 --------- d-----w c:\program files\TmNationsForever
                          2008-09-17 18:19 74,752 ----a-w c:\windows\ST6UNST.EXE
                          2008-09-17 18:19 290,816 ------w c:\windows\Setup1.exe
                          .

                          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                          REGEDIT4

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
                          "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-19 1667584]
                          "PowerArchiver Tray"="c:\program files\PowerArchiver\PASTARTER.EXE" [2008-11-30 148800]
                          "eMuleAutoStart"="c:\program files\eMule\emule.exe" [2008-08-01 5480448]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
                          "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
                          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-05-11 6729728]
                          "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-05-11 86016]
                          "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-08-26 413696]
                          "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
                          "RTHDCPL"="RTHDCPL.EXE" [2008-07-03 c:\windows\RTHDCPL.exe]
                          "nwiz"="nwiz.exe" [2005-05-11 c:\windows\system32\nwiz.exe]

                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                          "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

                          c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                          Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
                          WiFi Station.lnk - c:\program files\Hercules\WiFi Station\WifiStation.exe [2008-07-19 650240]

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                          "EnableFirewall"= 0 (0x0)

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                          "%windir%\\system32\\sessmgr.exe"=
                          "c:\\Program Files\\Messenger\\msmsgs.exe"=
                          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                          "c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
                          "c:\\Program Files\\eMule\\emule.exe"=

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                          "24428:TCP"= 24428:TCP:BitComet 24428 TCP
                          "24428:UDP"= 24428:UDP:BitComet 24428 UDP
                          "25135:TCP"= 25135:TCP:BitComet 25135 TCP
                          "25135:UDP"= 25135:UDP:BitComet 25135 UDP
                          "23071:TCP"= 23071:TCP:BitComet 23071 TCP
                          "23071:UDP"= 23071:UDP:BitComet 23071 UDP

                          R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-08-25 78416]
                          R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-08-25 20560]
                          .
                          - - - - ORPHELINS SUPPRIMES - - - -

                          HKCU-Run-Uniblue RegistryBooster 2009 - c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe

                          .
                          ------- Examen supplémentaire -------
                          .
                          uStart Page = hxxp://www.google.fr/
                          uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
                          mStart Page = hxxp://www.ustart.org
                          uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
                          IE: &T&élécharger &avec BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
                          IE: &T&élécharger tout avec BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
                          IE: &T&élécharger toute vidéo avec BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm
                          LSP: c:\windows\system32\gnbihsre.dll

                          c:\windows\Downloaded Program Files\sysreqlab3.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
                          hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
                          c:\windows\Downloaded Program Files\SysReqLab3.osd

                          O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_2_0.cab
                          c:\windows\Downloaded Program Files\hardwaredetection.inf
                          .

                          **************************************************************************

                          catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2008-12-15 22:58:39
                          Windows 5.1.2600 Service Pack 2 NTFS

                          Recherche de processus cachés ...

                          Recherche d'éléments en démarrage automatique cachés ...

                          Recherche de fichiers cachés ...

                          Scan terminé avec succès
                          Fichiers cachés: 0

                          **************************************************************************
                          .
                          ------------------------ Autres processus actifs ------------------------
                          .
                          c:\program files\Alwil Software\Avast4\aswUpdSv.exe
                          c:\windows\system32\nvsvc32.exe
                          c:\windows\system32\wscntfy.exe
                          c:\windows\system32\WgaTray.exe
                          c:\windows\system32\rundll32.exe
                          .
                          **************************************************************************
                          .
                          Heure de fin: 2008-12-15 22:59:58 - La machine a redémarré
                          ComboFix-quarantined-files.txt 2008-12-15 21:59:49

                          Avant-CF: 132,635,000,832 octets libres
                          Après-CF: 132,957,786,112 octets libres

                          156 --- E O F --- 2008-08-18 01:00:59
                          0
                          1. Modérateur
                            - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

                            - Double-clique sur RSIT.exe afin de lancer le programme.

                            - Clique sur Continue à l'écran Disclaimer.

                            - Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

                            - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

                            Note : Les rapports sont sauvegardés dans le dossier C:\rsit.
                            0
                            1. voici le contenu du log :

                              Logfile of random's system information tool 1.04 (written by random/random)
                              Run by VINCE at 2008-12-16 09:36:05
                              Microsoft Windows XP Professionnel Service Pack 2
                              System drive C: has 127 GB (65%) free of 194 GB
                              Total RAM: 1023 MB (64% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 09:36:10, on 16/12/2008
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\WINDOWS\system32\WgaTray.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\RTHDCPL.EXE
                              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                              C:\WINDOWS\system32\RUNDLL32.EXE
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\PowerArchiver\PASTARTER.EXE
                              C:\Program Files\Hercules\WiFi Station\WifiStation.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\WINDOWS\system32\nvsvc32.exe
                              C:\WINDOWS\system32\wscntfy.exe
                              C:\Program Files\BitComet\BitComet.exe
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Downloads\RSIT.exe
                              C:\Program Files\Trend Micro\HijackThis\VINCE.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [PowerArchiver Tray] C:\Program Files\PowerArchiver\PASTARTER.EXE
                              O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                              O4 - Global Startup: WiFi Station.lnk = ?
                              O8 - Extra context menu item: &T&élécharger &avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
                              O8 - Extra context menu item: &T&élécharger tout avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
                              O8 - Extra context menu item: &T&élécharger toute vidéo avec BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                              O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                              O10 - Unknown file in Winsock LSP: c:\windows\system32\gnbihsre.dll
                              O10 - Unknown file in Winsock LSP: c:\windows\system32\gnbihsre.dll
                              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                              O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.systemrequirementslab.com/cyri
                              O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - https://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
                              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                              0
                              1. je ne sais pas trop si c'est vraiment lanalyse :s

                                Fichier gnbihsre.dll reçu le 2008.12.03 19:09:26 (CET)
                                Situation actuelle: terminé

                                Résultat: 1/37 (2.70%)
                                Formaté Impression des résultats
                                Antivirus Version Dernière mise à jour Résultat
                                AhnLab-V3 - - -
                                AntiVir - - -
                                Authentium - - -
                                Avast - - -
                                AVG - - -
                                BitDefender - - -
                                CAT-QuickHeal - - -
                                ClamAV - - -
                                DrWeb - - -
                                eSafe - - -
                                eTrust-Vet - - -
                                Ewido - - -
                                F-Prot - - -
                                F-Secure - - -
                                Fortinet - - -
                                GData - - -
                                Ikarus - - -
                                K7AntiVirus - - -
                                Kaspersky - - -
                                McAfee - - -
                                McAfee+Artemis - - -
                                Microsoft - - -
                                NOD32 - - -
                                Norman - - -
                                Panda - - -
                                PCTools - - -
                                Prevx1 - - Malware Downloader
                                Rising - - -
                                SecureWeb-Gateway - - -
                                Sophos - - -
                                Sunbelt - - -
                                Symantec - - -
                                TheHacker - - -
                                TrendMicro - - -
                                VBA32 - - -
                                ViRobot - - -
                                VirusBuster - - -
                                Information additionnelle
                                MD5: 4e250fbd84097dac8effb426374bfc7b
                                SHA1: 4e4b6ae7634a414ac7f2ec72c28f08036ec16b26
                                SHA256: afea2ab4e85d5f1e04e45384d52d85e7f7172a936981d85cfb45b3243af98cec
                                SHA512: 7d7d6c372c8a96bc0474d2d2b7368f9ec8881a84e47dbce34dd55058cfaae822c02cd9d60d18494c01878d08014503319541effaaf5d9ab2e381e85ca7f5a630
                                0
                                1. Modérateur
                                  Si, c'est OK.

                                  - Télécharge LSPFix et dézippe-le sur ton Bureau :
                                  http://www.cexx.org/lspfix.zip

                                  - Lance LSPfix et se mettre en plein écran pour voir tous les boutons et ascenseurs

                                  - Ferme Internet Explorer et arrête la connexion à Internet

                                  - Coche la case "I know what I'm doing" (je sais ce que je fais)

                                  - Dans la colonne de gauche, sélectionne gnbihsre.dll

                                  - Clique sur la flèche vers la droite pour l'ajouter (de la colonne KEEP) dans la colonne REMOVE

                                  - Scroll et clique sur Finish
                                  0
                                  1. j'ai fait ce que tu as demandé sans probleme
                                    ya t'il un rapport a envoyer?
                                    0
                                    1. Modérateur
                                      /!\ Seul victa peut suivre cette procédure /!\

                                      1/

                                      ---> Clique sur Démarrer, Exécuter, tape notepad clique sur OK.

                                      ---> Copie le texte ci-dessous par sélection puis Ctrl+C :

                                      KillAll::

                                      File::
                                      C:\WINDOWS\system32\Agent.OMZ.Fix.exe
                                      C:\WINDOWS\system32\gnbihsre.dll

                                      ---> Colle la sélection dans le bloc-notes

                                      ---> Enregistre ce fichier sur le bureau (Impératif)

                                      ---> Nom du fichier : CFScript
                                      ---> Type du fichier : tous les fichiers
                                      ---> Clique sur Enregistrer
                                      ---> Quitte le bloc-notes

                                      2/

                                      ---> Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :
                                      http://www.searchengines.pl/phpbb203/pliki/picasso/virus/programs/combofix/combofix_cfscript.gif

                                      [*] Une fenêtre bleue va apparaître : au message qui apparaît, tu acceptes.

                                      [*] Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
                                      Ne touche à rien tant que le scan n'est pas terminé.

                                      [*] Une fois le scan achevé, un rapport va s'afficher : poste-le

                                      [*] Si le fichier ne s'ouvre pas, il se trouve ici C:\ComboFix\Combofix.txt
                                      0
                                      1. voici le rapport de combofix :

                                        ComboFix 08-12-15.01 - VINCE 2008-12-16 18:19:38.2 - NTFSx86
                                        Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1023.637 [GMT 1:00]
                                        Lancé depuis: c:\downloads\ComboFix.exe
                                        Commutateurs utilisés :: c:\documents and settings\VINCE\Bureau\CFScript.txt
                                        * Un nouveau point de restauration a été créé

                                        [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]

                                        FILE ::
                                        c:\windows\system32\Agent.OMZ.Fix.exe
                                        c:\windows\system32\gnbihsre.dll
                                        .

                                        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                        .

                                        c:\windows\system32\Agent.OMZ.Fix.exe
                                        c:\windows\system32\gnbihsre.dll

                                        .
                                        ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-16 au 2008-12-16 ))))))))))))))))))))))))))))))))))))
                                        .

                                        2008-12-16 09:36 . 2008-12-16 09:36 <REP> d-------- C:\rsit
                                        2008-12-15 15:34 . 2008-08-14 14:44 2,182,400 -----c--- c:\windows\system32\dllcache\ntoskrnl.exe
                                        2008-12-15 15:34 . 2008-08-14 14:44 2,138,112 -----c--- c:\windows\system32\dllcache\ntkrnlmp.exe
                                        2008-12-15 15:34 . 2008-08-14 14:44 2,059,776 -----c--- c:\windows\system32\dllcache\ntkrnlpa.exe
                                        2008-12-15 15:34 . 2008-08-14 14:44 2,017,792 -----c--- c:\windows\system32\dllcache\ntkrpamp.exe
                                        2008-12-15 15:34 . 2008-09-04 17:45 1,106,944 -----c--- c:\windows\system32\dllcache\msxml3.dll
                                        2008-12-15 15:34 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
                                        2008-12-15 15:34 . 2008-10-15 17:59 332,800 -----c--- c:\windows\system32\dllcache\netapi32.dll
                                        2008-12-15 15:34 . 2008-10-03 11:17 247,326 -----c--- c:\windows\system32\dllcache\strmdll.dll
                                        2008-12-15 15:15 . 2008-12-15 15:15 <REP> d-------- c:\program files\Trend Micro
                                        2008-12-15 14:36 . 2008-12-15 16:32 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                                        2008-12-14 20:27 . 2008-12-14 20:27 <REP> d-------- c:\documents and settings\All Users\Application Data\NVIDIA
                                        2008-12-06 19:40 . 2008-12-06 19:40 <REP> d-------- c:\program files\OpenAL
                                        2008-12-06 19:40 . 2008-12-06 19:50 413,696 --a------ c:\windows\system32\wrap_oal.dll
                                        2008-12-06 19:40 . 2008-12-06 19:50 110,592 --a------ c:\windows\system32\OpenAL32.dll
                                        2008-12-05 18:45 . 2008-12-16 17:23 <REP> d-------- c:\program files\PowerArchiver
                                        2008-11-30 11:23 . 2008-11-30 11:23 573,473 --a------ c:\windows\system32\WBOCX.OCX
                                        2008-11-30 11:23 . 2008-11-30 11:23 56,496 --a------ c:\windows\system32\WBHELP2.DLL
                                        2008-11-29 00:33 . 2008-12-16 18:18 69 --a------ c:\windows\NeroDigital.ini
                                        2008-11-29 00:31 . 2008-11-29 00:32 <REP> d-------- c:\program files\Fichiers communs\Ahead
                                        2008-11-29 00:31 . 2008-11-29 00:31 <REP> d-------- c:\program files\Ahead
                                        2008-11-29 00:31 . 2004-07-26 17:16 1,568,768 --------- c:\windows\system32\ImagX7.dll
                                        2008-11-29 00:31 . 2004-07-26 17:16 476,320 --------- c:\windows\system32\ImagXpr7.dll
                                        2008-11-29 00:31 . 2004-07-26 17:16 471,040 --------- c:\windows\system32\ImagXRA7.dll
                                        2008-11-29 00:31 . 2004-07-26 17:16 262,144 --------- c:\windows\system32\ImagXR7.dll
                                        2008-11-29 00:31 . 2001-07-09 11:50 155,648 --a------ c:\windows\system32\NeroCheck.exe
                                        2008-11-29 00:31 . 2000-06-26 11:45 106,496 --a------ c:\windows\system32\TwnLib20.dll
                                        2008-11-19 19:33 . 2008-11-19 19:33 <REP> d-------- c:\documents and settings\VINCE\Application Data\Capcom

                                        .
                                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                        .
                                        2008-12-16 12:53 --------- d-----w c:\program files\eMule
                                        2008-12-06 18:52 --------- d-----w c:\documents and settings\All Users\Application Data\TrackMania
                                        2008-12-06 18:44 --------- d--h--w c:\program files\InstallShield Installation Information
                                        2008-11-26 12:47 --------- d-----w c:\program files\BitComet
                                        2008-11-17 22:38 --------- d-----w c:\program files\Fichiers communs\InstallShield
                                        2008-10-31 13:40 --------- d-----w c:\program files\TmNationsForever
                                        2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
                                        2008-09-17 18:19 74,752 ----a-w c:\windows\ST6UNST.EXE
                                        2008-09-17 18:19 290,816 ------w c:\windows\Setup1.exe
                                        .

                                        ((((((((((((((((((((((((((((( snapshot@2008-12-15_22.59.24.96 )))))))))))))))))))))))))))))))))))))))))
                                        .
                                        + 2008-10-24 11:10:42 453,632 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
                                        + 2008-08-14 13:44:35 2,138,112 ------w c:\windows\Driver Cache\i386\ntkrnlmp.exe
                                        + 2008-08-14 13:44:39 2,059,776 ------w c:\windows\Driver Cache\i386\ntkrnlpa.exe
                                        + 2008-08-14 13:44:33 2,017,792 ------w c:\windows\Driver Cache\i386\ntkrpamp.exe
                                        + 2008-08-14 13:44:37 2,182,400 ------w c:\windows\Driver Cache\i386\ntoskrnl.exe
                                        - 2008-06-23 15:39:58 1,024,000 ----a-w c:\windows\system32\browseui.dll
                                        + 2008-10-16 10:38:30 1,024,000 ----a-w c:\windows\system32\browseui.dll
                                        - 2008-06-23 15:39:58 152,064 ----a-w c:\windows\system32\cdfview.dll
                                        + 2008-10-16 10:38:27 152,064 ----a-w c:\windows\system32\cdfview.dll
                                        - 2008-06-23 15:39:59 1,056,768 ----a-w c:\windows\system32\danim.dll
                                        + 2008-10-16 10:38:27 1,056,768 ----a-w c:\windows\system32\danim.dll
                                        - 2008-06-20 10:44:38 138,368 -c--a-w c:\windows\system32\dllcache\afd.sys
                                        + 2008-08-14 09:51:43 138,368 -c--a-w c:\windows\system32\dllcache\afd.sys
                                        - 2008-06-23 15:39:58 1,024,000 -c--a-w c:\windows\system32\dllcache\browseui.dll
                                        + 2008-10-16 10:38:30 1,024,000 -c--a-w c:\windows\system32\dllcache\browseui.dll
                                        - 2008-06-23 15:39:58 152,064 -c--a-w c:\windows\system32\dllcache\cdfview.dll
                                        + 2008-10-16 10:38:27 152,064 -c--a-w c:\windows\system32\dllcache\cdfview.dll
                                        - 2008-06-23 15:39:59 1,056,768 -c--a-w c:\windows\system32\dllcache\danim.dll
                                        + 2008-10-16 10:38:27 1,056,768 -c--a-w c:\windows\system32\dllcache\danim.dll
                                        - 2008-06-23 15:40:00 357,888 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
                                        + 2008-10-16 10:38:27 357,888 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
                                        - 2008-06-23 15:40:00 205,312 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
                                        + 2008-10-16 10:38:28 205,312 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
                                        - 2008-06-23 15:40:00 55,808 -c--a-w c:\windows\system32\dllcache\extmgr.dll
                                        + 2008-10-16 10:38:28 55,808 -c--a-w c:\windows\system32\dllcache\extmgr.dll
                                        + 2008-10-23 13:00:15 283,648 -c----w c:\windows\system32\dllcache\gdi32.dll
                                        - 2008-06-23 09:49:29 18,432 -c--a-w c:\windows\system32\dllcache\iedw.exe
                                        + 2008-10-15 09:45:01 18,432 -c--a-w c:\windows\system32\dllcache\iedw.exe
                                        - 2008-06-23 15:40:00 251,392 -c--a-w c:\windows\system32\dllcache\iepeers.dll
                                        + 2008-10-16 10:38:28 251,392 -c--a-w c:\windows\system32\dllcache\iepeers.dll
                                        - 2008-06-23 15:40:00 96,768 -c--a-w c:\windows\system32\dllcache\inseng.dll
                                        + 2008-10-16 10:38:28 96,768 -c--a-w c:\windows\system32\dllcache\inseng.dll
                                        - 2008-06-23 15:40:00 16,384 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
                                        + 2008-10-16 10:38:29 16,384 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
                                        + 2008-06-10 00:31:06 103,936 -c----w c:\windows\system32\dllcache\logagent.exe
                                        - 2008-06-23 15:40:02 3,080,704 -c--a-w c:\windows\system32\dllcache\mshtml.dll
                                        + 2008-10-16 10:38:30 3,080,704 -c--a-w c:\windows\system32\dllcache\mshtml.dll
                                        - 2008-06-23 15:40:03 449,024 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
                                        + 2008-10-16 10:38:29 449,024 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
                                        - 2008-06-23 15:40:03 146,432 -c--a-w c:\windows\system32\dllcache\msrating.dll
                                        + 2008-10-16 10:38:28 146,432 -c--a-w c:\windows\system32\dllcache\msrating.dll
                                        - 2008-06-23 15:40:04 532,480 -c--a-w c:\windows\system32\dllcache\mstime.dll
                                        + 2008-10-16 10:38:28 532,480 -c--a-w c:\windows\system32\dllcache\mstime.dll
                                        - 2008-06-23 15:40:04 39,424 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
                                        + 2008-10-16 10:38:28 39,424 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
                                        - 2008-06-23 15:40:05 1,495,040 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
                                        + 2008-10-16 10:38:29 1,495,040 -c--a-w c:\windows\system32\dllcache\shdocvw.dll
                                        - 2008-06-23 15:40:06 474,624 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
                                        + 2008-10-16 10:38:29 474,624 -c--a-w c:\windows\system32\dllcache\shlwapi.dll
                                        - 2004-08-03 21:14:46 336,256 -c--a-w c:\windows\system32\dllcache\srv.sys
                                        + 2008-08-28 10:04:17 333,056 -c--a-w c:\windows\system32\dllcache\srv.sys
                                        - 2008-06-23 15:40:06 617,984 -c--a-w c:\windows\system32\dllcache\urlmon.dll
                                        + 2008-10-16 10:38:30 617,984 -c--a-w c:\windows\system32\dllcache\urlmon.dll
                                        - 2004-08-03 22:45:58 1,836,032 -c--a-w c:\windows\system32\dllcache\win32k.sys
                                        + 2008-09-15 15:39:16 1,846,144 -c--a-w c:\windows\system32\dllcache\win32k.sys
                                        - 2008-06-23 15:40:08 663,552 -c--a-w c:\windows\system32\dllcache\wininet.dll
                                        + 2008-10-16 10:38:29 663,552 -c--a-w c:\windows\system32\dllcache\wininet.dll
                                        + 2008-06-10 17:18:18 1,053,696 -c----w c:\windows\system32\dllcache\WMNetmgr.dll
                                        + 2008-11-07 17:32:20 2,109,440 -c----w c:\windows\system32\dllcache\WMVCore.dll
                                        - 2008-06-20 10:44:38 138,368 ----a-w c:\windows\system32\drivers\afd.sys
                                        + 2008-08-14 09:51:43 138,368 ----a-w c:\windows\system32\drivers\afd.sys
                                        - 2004-08-03 21:14:46 336,256 ----a-w c:\windows\system32\drivers\srv.sys
                                        + 2008-08-28 10:04:17 333,056 ----a-w c:\windows\system32\drivers\srv.sys
                                        - 2008-06-23 15:40:00 357,888 ----a-w c:\windows\system32\dxtmsft.dll
                                        + 2008-10-16 10:38:27 357,888 ----a-w c:\windows\system32\dxtmsft.dll
                                        - 2008-06-23 15:40:00 205,312 ----a-w c:\windows\system32\dxtrans.dll
                                        + 2008-10-16 10:38:28 205,312 ----a-w c:\windows\system32\dxtrans.dll
                                        - 2008-06-23 15:40:00 55,808 ----a-w c:\windows\system32\extmgr.dll
                                        + 2008-10-16 10:38:28 55,808 ----a-w c:\windows\system32\extmgr.dll
                                        - 2008-09-17 17:23:19 95,072 ----a-w c:\windows\system32\FNTCACHE.DAT
                                        + 2008-12-16 07:45:28 95,072 ----a-w c:\windows\system32\FNTCACHE.DAT
                                        - 2004-08-19 14:09:28 278,016 ----a-w c:\windows\system32\gdi32.dll
                                        + 2008-10-23 13:00:15 283,648 ----a-w c:\windows\system32\gdi32.dll
                                        - 2008-06-23 15:40:00 251,392 ----a-w c:\windows\system32\iepeers.dll
                                        + 2008-10-16 10:38:28 251,392 ----a-w c:\windows\system32\iepeers.dll
                                        - 2008-06-23 15:40:00 96,768 ----a-w c:\windows\system32\inseng.dll
                                        + 2008-10-16 10:38:28 96,768 ----a-w c:\windows\system32\inseng.dll
                                        - 2008-06-23 15:40:00 16,384 ----a-w c:\windows\system32\jsproxy.dll
                                        + 2008-10-16 10:38:29 16,384 ----a-w c:\windows\system32\jsproxy.dll
                                        - 2004-08-19 14:09:56 103,936 ----a-w c:\windows\system32\logagent.exe
                                        + 2008-06-10 00:31:06 103,936 ----a-w c:\windows\system32\logagent.exe
                                        - 2008-08-05 09:11:02 15,888,504 ----a-w c:\windows\system32\MRT.exe
                                        + 2008-12-09 14:24:38 17,593,280 ----a-w c:\windows\system32\MRT.exe
                                        - 2008-06-23 15:40:02 3,080,704 ----a-w c:\windows\system32\mshtml.dll
                                        + 2008-10-16 10:38:30 3,080,704 ----a-w c:\windows\system32\mshtml.dll
                                        - 2008-06-23 15:40:03 449,024 ----a-w c:\windows\system32\mshtmled.dll
                                        + 2008-10-16 10:38:29 449,024 ----a-w c:\windows\system32\mshtmled.dll
                                        - 2008-06-23 15:40:03 146,432 ----a-w c:\windows\system32\msrating.dll
                                        + 2008-10-16 10:38:28 146,432 ----a-w c:\windows\system32\msrating.dll
                                        - 2008-06-23 15:40:04 532,480 ----a-w c:\windows\system32\mstime.dll
                                        + 2008-10-16 10:38:28 532,480 ----a-w c:\windows\system32\mstime.dll
                                        - 2004-08-19 14:09:36 1,236,480 ----a-w c:\windows\system32\msxml3.dll
                                        + 2008-09-04 16:45:11 1,106,944 ----a-w c:\windows\system32\msxml3.dll
                                        - 2004-08-19 14:09:36 332,288 ----a-w c:\windows\system32\netapi32.dll
                                        + 2008-10-15 16:59:28 332,800 ----a-w c:\windows\system32\netapi32.dll
                                        - 2004-08-03 23:05:42 2,058,880 ----a-w c:\windows\system32\ntkrnlpa.exe
                                        + 2008-08-14 13:44:39 2,059,776 ----a-w c:\windows\system32\ntkrnlpa.exe
                                        - 2004-08-03 22:49:16 2,183,040 ----a-w c:\windows\system32\ntoskrnl.exe
                                        + 2008-08-14 13:44:37 2,182,400 ----a-w c:\windows\system32\ntoskrnl.exe
                                        - 2008-06-23 15:40:04 39,424 ----a-w c:\windows\system32\pngfilt.dll
                                        + 2008-10-16 10:38:28 39,424 ----a-w c:\windows\system32\pngfilt.dll
                                        - 2008-06-23 15:40:05 1,495,040 ----a-w c:\windows\system32\shdocvw.dll
                                        + 2008-10-16 10:38:29 1,495,040 ----a-w c:\windows\system32\shdocvw.dll
                                        - 2008-06-23 15:40:06 474,624 ----a-w c:\windows\system32\shlwapi.dll
                                        + 2008-10-16 10:38:29 474,624 ----a-w c:\windows\system32\shlwapi.dll
                                        - 2004-08-19 14:09:46 246,302 ----a-w c:\windows\system32\strmdll.dll
                                        + 2008-10-03 10:17:02 247,326 ----a-w c:\windows\system32\strmdll.dll
                                        - 2008-07-14 11:09:18 62,976 ------w c:\windows\system32\tzchange.exe
                                        + 2008-10-22 09:47:07 62,976 ------w c:\windows\system32\tzchange.exe
                                        - 2008-06-23 15:40:06 617,984 ----a-w c:\windows\system32\urlmon.dll
                                        + 2008-10-16 10:38:30 617,984 ----a-w c:\windows\system32\urlmon.dll
                                        - 2004-08-03 22:45:58 1,836,032 ----a-w c:\windows\system32\win32k.sys
                                        + 2008-09-15 15:39:16 1,846,144 ----a-w c:\windows\system32\win32k.sys
                                        - 2008-06-23 15:40:08 663,552 ----a-w c:\windows\system32\wininet.dll
                                        + 2008-10-16 10:38:29 663,552 ----a-w c:\windows\system32\wininet.dll
                                        - 2004-08-19 14:09:50 1,050,624 ----a-w c:\windows\system32\wmnetmgr.dll
                                        + 2008-06-10 17:18:18 1,053,696 ----a-w c:\windows\system32\WMNetmgr.dll
                                        - 2004-08-19 14:10:14 2,105,344 ----a-w c:\windows\system32\wmvcore.dll
                                        + 2008-11-07 17:32:20 2,109,440 ----a-w c:\windows\system32\WMVCore.dll
                                        - 2008-07-03 09:42:35 370,176 ----a-w c:\windows\system32\xpsp3res.dll
                                        + 2008-10-15 19:05:28 370,176 ----a-w c:\windows\system32\xpsp3res.dll
                                        + 2008-04-15 17:56:59 1,724,416 ----a-w c:\windows\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.2600.3352_x-ww_81af8e88\GdiPlus.dll
                                        .
                                        -- Instantané actualisé --
                                        .
                                        ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                        .
                                        .
                                        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                        REGEDIT4

                                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                        "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]
                                        "eMuleAutoStart"="c:\program files\eMule\emule.exe" [2008-08-01 5480448]

                                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                        "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
                                        "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 78008]
                                        "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-05-11 6729728]
                                        "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2005-05-11 86016]
                                        "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-08-26 413696]
                                        "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
                                        "RTHDCPL"="RTHDCPL.EXE" [2008-07-03 c:\windows\RTHDCPL.exe]
                                        "nwiz"="nwiz.exe" [2005-05-11 c:\windows\system32\nwiz.exe]

                                        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                        "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

                                        c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                                        Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 29696]
                                        WiFi Station.lnk - c:\program files\Hercules\WiFi Station\WifiStation.exe [2008-07-19 650240]

                                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                        "%windir%\\system32\\sessmgr.exe"=
                                        "c:\\Program Files\\Messenger\\msmsgs.exe"=
                                        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                        "c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
                                        "c:\\Program Files\\eMule\\emule.exe"=

                                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                                        "24428:TCP"= 24428:TCP:BitComet 24428 TCP
                                        "24428:UDP"= 24428:UDP:BitComet 24428 UDP
                                        "25135:TCP"= 25135:TCP:BitComet 25135 TCP
                                        "25135:UDP"= 25135:UDP:BitComet 25135 UDP
                                        "23071:TCP"= 23071:TCP:BitComet 23071 TCP
                                        "23071:UDP"= 23071:UDP:BitComet 23071 UDP

                                        R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-08-25 78416]
                                        R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-08-25 20560]
                                        .
                                        .
                                        ------- Examen supplémentaire -------
                                        .
                                        uStart Page = hxxp://www.google.fr/
                                        uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
                                        mStart Page = hxxp://www.ustart.org
                                        uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
                                        IE: &T&élécharger &avec BitComet - c:\program files\BitComet\BitComet.exe/AddLink.htm
                                        IE: &T&élécharger tout avec BitComet - c:\program files\BitComet\BitComet.exe/AddAllLink.htm
                                        IE: &T&élécharger toute vidéo avec BitComet - c:\program files\BitComet\BitComet.exe/AddVideo.htm

                                        c:\windows\Downloaded Program Files\sysreqlab3.dll - O16 -: {1E54D648-B804-468d-BC78-4AFFED8E262E}
                                        hxxp://www.srtest.com/srl_bin/sysreqlab3.cab
                                        c:\windows\Downloaded Program Files\SysReqLab3.osd

                                        O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_2_0.cab
                                        c:\windows\Downloaded Program Files\hardwaredetection.inf
                                        .

                                        **************************************************************************

                                        catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                        Rootkit scan 2008-12-16 18:21:56
                                        Windows 5.1.2600 Service Pack 2 NTFS

                                        Recherche de processus cachés ...

                                        Recherche d'éléments en démarrage automatique cachés ...

                                        Recherche de fichiers cachés ...

                                        Scan terminé avec succès
                                        Fichiers cachés: 0

                                        **************************************************************************
                                        .
                                        ------------------------ Autres processus actifs ------------------------
                                        .
                                        c:\program files\Alwil Software\Avast4\aswUpdSv.exe
                                        c:\windows\system32\WgaTray.exe
                                        c:\windows\system32\rundll32.exe
                                        c:\windows\system32\nvsvc32.exe
                                        c:\windows\system32\wscntfy.exe
                                        .
                                        **************************************************************************
                                        .
                                        Heure de fin: 2008-12-16 18:23:51 - La machine a redémarré
                                        ComboFix-quarantined-files.txt 2008-12-16 17:23:08
                                        ComboFix2.txt 2008-12-15 21:59:59

                                        Avant-CF: 142 797 623 296 octets libres
                                        Après-CF: 142,836,568,064 octets libres

                                        265 --- E O F --- 2008-12-15 22:23:49
                                        0
                                    2. Modérateur
                                      ---> Désinstalle Java 6 Update 7.

                                      ---> Mets à jour Java :
                                      https://www.java.com/fr/download/manual.jsp

                                      ---> Mets à jour Adobe Reader :
                                      https://get2.adobe.com/reader/otherversions/

                                      ---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
                                      ---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
                                      ---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
                                      ---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
                                      ---> Sélectionne Exécuter un examen rapide.
                                      ---> Clique sur Rechercher. L'analyse démarre.

                                      A la fin de l'analyse, un message s'affiche :

                                      L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

                                      ---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
                                      ---> Ferme tes navigateurs.
                                      Si des malwares ont été détectés, clique sur Afficher les résultats.
                                      ---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
                                      ---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
                                      0
                                      1. MBAM n'a rien trouvé
                                        voici son rapport:

                                        Malwarebytes' Anti-Malware 1.31
                                        Version de la base de données: 1507
                                        Windows 5.1.2600 Service Pack 2

                                        16/12/2008 19:58:46
                                        mbam-log-2008-12-16 (19-58-46).txt

                                        Type de recherche: Examen rapide
                                        Eléments examinés: 43447
                                        Temps écoulé: 3 minute(s), 1 second(s)

                                        Processus mémoire infecté(s): 0
                                        Module(s) mémoire infecté(s): 0
                                        Clé(s) du Registre infectée(s): 0
                                        Valeur(s) du Registre infectée(s): 0
                                        Elément(s) de données du Registre infecté(s): 0
                                        Dossier(s) infecté(s): 0
                                        Fichier(s) infecté(s): 0

                                        Processus mémoire infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Module(s) mémoire infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Clé(s) du Registre infectée(s):
                                        (Aucun élément nuisible détecté)

                                        Valeur(s) du Registre infectée(s):
                                        (Aucun élément nuisible détecté)

                                        Elément(s) de données du Registre infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Dossier(s) infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Fichier(s) infecté(s):
                                        (Aucun élément nuisible détecté)
                                        0
                                    • 1
                                    • 2