Virus nmdfgds0.dll

Bonjour,

Avast a détecté quelques virus sur mon ordinateur dont nmdfgds0.dll. Même après suppression ils réapparraissent au démarrage. Conséquences : ordinateur ralenti, impossible de lancer les applications quelques fois, ouverture des disques dur dans des nouvelles fenêtres, impossible d'afficher les fichiers cachés...

Merci de pouvoir m'aider car ça devient très gênant
Configuration: Windows XP

27 réponses

Résumé de la discussion

Des infections détectées par Avast, dont nmdfgds0.dll, réapparaissent au démarrage malgré suppression, provoquant ralentissements, impossibilité de lancer certaines applications, ouverture multiple des disques et affichage dégradé des fichiers cachés. Les éléments de réponse prioritaires incluent la suppression des cracks et keygens et l’arrêt de téléchargements douteux, puis l’utilisation de FindyKill (option4) avec disques amovibles afin d’obtenir un rapport et supprimer les éléments détectés. Des analyses complémentaires comme Kaspersky Online Scanner et RSIT ont été évoquées pour identifier et traiter les éléments infectieux, avec des conseils sur la prudence lors des téléchargements et la mise à jour des outils.

Bobot (l’IA à votre service)
  1. Je demandais à super poivron comment allait son pc,au cas ou il reapparaitrait sur le forum
    0
    1. Il va très bien.....depuis que je l'ai formaté!!

      Au moins je suis tranquille! J'ai pris mon temps sauvegardé tout ce qu'il fallait et hop on réinstalle.

      Merci quand même pour le temps passé!
      0
  2. Ok voila comment se debarrasser de ce cauchemard.
    1: vous devez déactiver votre ANTIVIRUS ( juste pour la durée de cette astuce ).
    2: vous téléchargez un logiciel de suppression (je vous conseille de télécharger tuneUp et d'utiliser shredder, le logiciel de suppresion)
    3: vous séléctionnez le chemin du fichier (c:\....\nmdfgds.dll) pour le supprimer avec tune up.
    4: cliquez sur suivant ( le logiciel vous dit que la suppression a echoué ).
    5: redemmarez votre PC et activez votre antivirus.

    ça marche e tous les coups ( si ça ne marche pas verifiez que vous avez bien suivi les instructions dans l'ordre

    Bonne chance.
    0
    1. Contributeur
      Je fonce droit vers virut? Je peux rien faire de plus ?

      - Si !! supprimé tes cracks et keygens et arreter de telecharger n'importe quoi... rien n'est gratuit sur le net, et un jour on finit toujours par payer et plus...

      - Un peu de lecture " réaliste " te fera reflechir peut-etre !

      https://forum.malekal.com/viewtopic.php?f=33&t=893

      https://forum.zebulon.fr/topic/93281-pr%C3%A9vention-le-crack-dans-toute-sa-splendeur/

      https://forum.malekal.com/viewtopic.php?f=33&t=3208

      - Maintenant, si tu es pret a les supprimer, je peux t'aider si tu n'y arrives vraiment pas.

      - Il te suffit de faire l'option4 de Findykill en branchant tes disques amovibles ( clé USB, disque dur externe,ipod etc) et patientes le temps du scan...

      - Si tu n'as plus Findykill, prends le ici :
      Télécharges FindyKill de Chiquitine29 :

      http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

      ->Enregistres le sur ton bureau et pas ailleurs !

      !! Déconnectes toi et fermes toute applications en cours !!

      ->double Cliques sur "FindyKill.exe" pour lancer l'installe de l'outil . Ne touche surtout pas aux paramètres d'installation.

      ---> Branches tes disques amovibles ( clé usb, disques dur externe, ipod etc..) sans les ouvrir
      --> Double cliques sur le raccourci " FindyKill " qui est sur ton bureau
      --> Au menu, choisis l'option4 et patientes le temps du scan
      --> Postes le rapport Findykill.txt qui sera généré

      ----------------------
      De là, on pourra les supprimer avec un outil spécifique
      .
      0
      1. Désolé pour le retard,

        Voilà le rapport, il trouve rien

        ################################### [ FindyKill V4.720 ]

        # User : Jeremy (Administrateurs) # JEREM
        # Update on 12/03/09 by Chiquitine29
        # Start at: 13:06:29 | 26/03/2009

        # AMD Athlon(tm) 64 Processor 3000+
        # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
        # Internet Explorer 7.0.5730.13
        # Windows Firewall Status : Disabled
        # AV : Avira AntiVir PersonalEdition Classic 8.0.1.30 [ Enabled | Updated ]
        # FW : ZoneAlarm Firewall[ Enabled ]8.0.065.000

        # A:\ # Lecteur de disquettes 3 ½ pouces
        # C:\ # Disque fixe local # 128,49 Go (84,5 Go free) # NTFS
        # D:\ # Disque CD-ROM
        # E:\ # Disque CD-ROM
        # F:\ # Disque fixe local # 19,53 Go (5,16 Go free) [Système] # NTFS
        # G:\ # Disque CD-ROM
        # H:\ # Disque CD-ROM
        # J:\ # Disque fixe local # 465,76 Go (34,31 Go free) # NTFS

        ################################### [ Cracks / Keygens ... ]

        ################## [ ! Fin du rapport # FindyKill V4.720 ! ]
        0
    2. T'inquietes pas super poivron,ced king va te donner la suite de la procedure (il doit etre occupé là),meme virut ,on en vient à bout si l'infection est pas trop avancé.Par contre,fait gaffe aux cracks car bagle est pas mal aussi comme infection destructrice.
      0
      1. Je fonce droit vers virut? Je peux rien faire de plus ?
        0
        1. Contributeur
          - Kaspersky ne desinfecte pas en ligne, donc ton pc est toujours infecté...

          - Mais si tu ne vires pas tout ça, cela ne sert à rien de continuer...

          et en plus des infections, personnellement je trouve ceci " douteux "

          F:\Documents and Settings\Jeremy\Local Settings\temp\etilqs_EYgV9FON37KFaUhUQIOD L'objet est verrouillé ignoré
          F:\Documents and Settings\Jeremy\Local Settings\temp\etilqs_EYgV9FON37KFaUhUQIOD-journal L'objet est verrouillé ignoré
          F:\Documents and Settings\Jeremy\Local Settings\temp\etilqs_QnQVdVlAqzkvPuGwrN7h L'objet est verrouillé ignoré

          - Tu fonces droit vers virut, tu n'as rien supprimé du tout car Kaspersky les trouves :

          D:\Adobe Encore DVD 2.0 Tryout\crack\keygen.exe L'objet est verrouillé ignoré
          D:\After Effect\Trapcode.Multikeygen.v1.3.exe Infecté : Trojan.Win32.Genome.pfu ignoré
          F:\Program Files\eMule\Incoming\Adobe.Premiere.Pro.CS4-NoPE_crack_multi­language_tested_ok.zip/Adobe.Premiere.Pro.CS4-NoPE_crack_mul­tilanguage_tested_ok/Adobe.Premiere.Pro.CS4-NoPE_CRACK.exe I­nfecté : Trojan-Downloader.Win32.Agent.bipq ignoré
          F:\Program Files\eMule\Incoming\Adobe.Premiere.Pro.CS4-NoPE_crack_multi­language_tested_ok.zip ZIP: infecté - 1 ignoré


          -----
          0
          1. Ah si une autre question :

            dans le rapport kaspersky, il a trouvé des virus dans le dossier caché System Volume information.
            Je peux le supprimer?
            0
            1. Contributeur
              Re,

              - Supprimes tes cracks et keygens ou les infections reviendront à chaque fois...
              0
              1. lol,

                ok ben j'ai supprimé tout ca.

                Merci pour le temps que tu m'as accordé.

                A+
                0
            2. Contributeur
              Salut $uper-Poivron,

              - Ne fais surtout pas ce qu'il te demandes de faire, je te donnes la suite...

              - Il a décidé de me pourrir mes topics aujourd'hui, c'est un Troll...

              et Troll, n'a jamais été une insulte, juste un qualificatif qui lui va bien!
              0
              1. Bonjour,

                voilà j'ai terminé l'analyse Kaspersky et JavaRa, voilà les rapports :

                JavaRa 1.13 Removal Log.

                Report follows after line.

                ------------------------------------

                The JavaRa removal process was started on Wed Mar 18 18:06:58 2009

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}

                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

                Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

                Found and removed: Software\JavaSoft\Java2D\1.6.0_06

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}

                Found and removed: Software\Classes\CLSID\{CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}

                ------------------------------------

                Finished reporting.

                -------------------------------------------------------------------------------
                KASPERSKY ON-LINE SCANNER REPORT
                Thursday, March 19, 2009 7:05:25 AM
                Système d'exploitation : Microsoft Windows XP Home Edition, Service Pack 3 (Build 2600)
                Kaspersky On-line Scanner version : 5.0.84.2
                Dernière mise à jour de la base antivirus Kaspersky : 18/03/2009
                Enregistrements dans la base antivirus Kaspersky : 1743127
                -------------------------------------------------------------------------------

                Paramètres d'analyse:
                Analyser avec la base antivirus suivante: standard
                Analyser les archives: vrai
                Analyser les bases de messagerie: vrai

                Cible de l'analyse - Poste de travail:
                A:\
                C:\
                D:\
                E:\
                F:\
                G:\
                H:\
                I:\
                J:\

                Statistiques de l'analyse:
                Total d'objets analysés: 199887
                Nombre de virus trouvés: 3
                Nombre d'objets infectés: 10 / 0
                Nombre d'objets suspects: 0
                Durée de l'analyse: 11:24:26

                Nom de l'objet infecté / Nom du virus / Dernière action
                C:\luk1ylq.com Infecté : Trojan.Win32.Agent.bvsq ignoré
                C:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
                C:\System Volume Information\_restore{70C6087A-59A5-4833-B6F7-5B15E72EDDE2}\RP100\change.log L'objet est verrouillé ignoré
                C:\System Volume Information\_restore{70C6087A-59A5-4833-B6F7-5B15E72EDDE2}\RP90\A0022589.com Infecté : Trojan.Win32.Agent.bvsq ignoré
                D:\Adobe Encore DVD 2.0 Tryout\crack\keygen.exe L'objet est verrouillé ignoré
                D:\After Effect\Trapcode.Multikeygen.v1.3.exe Infecté : Trojan.Win32.Genome.pfu ignoré
                F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\All Users\Application Data\Nero\Nero BackItUp 4\Cache\BIU1.txt L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\cert8.db L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\content-prefs.sqlite L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\cookies.sqlite L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\downloads.sqlite L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\formhistory.sqlite L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\key3.db L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\parent.lock L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\permissions.sqlite L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\places.sqlite L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\places.sqlite-journal L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\search.sqlite L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Skype\jerem.brunet\dc.db L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Skype\jerem.brunet\dc.lock L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Skype\jerem.brunet\main.db L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Application Data\Skype\jerem.brunet\main.lock L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Cookies\index.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Application Data\Adobe\Acrobat\9.0\Updater\updater.log L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Application Data\Adobe\Updater6\aumLib.log L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\Cache\_CACHE_001_ L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\Cache\_CACHE_002_ L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\Cache\_CACHE_003_ L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\Cache\_CACHE_MAP_ L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\urlclassifier3.sqlite L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Historique\History.IE5\MSHist012009031820090319\index.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\temp\etilqs_EYgV9FON37KFaUhUQIOD L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\temp\etilqs_EYgV9FON37KFaUhUQIOD-journal L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\temp\etilqs_QnQVdVlAqzkvPuGwrN7h L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\temp\~DF86C3.tmp L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\temp\~DFED5.tmp L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\NTUSER.DAT L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\ntuser.dat.LOG L'objet est verrouillé ignoré
                F:\Documents and Settings\Jeremy\Tracing\WindowsLiveMessenger-uccapi-0.uccapilog L'objet est verrouillé ignoré
                F:\Documents and Settings\LocalService\Cookies\index.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
                F:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\LocalService\Local Settings\Temp\Fichiers Internet temporaires\Content.IE5\index.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\LocalService\NTUSER.DAT L'objet est verrouillé ignoré
                F:\Documents and Settings\LocalService\ntuser.dat.LOG L'objet est verrouillé ignoré
                F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat L'objet est verrouillé ignoré
                F:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG L'objet est verrouillé ignoré
                F:\Documents and Settings\NetworkService\NTUSER.DAT L'objet est verrouillé ignoré
                F:\Documents and Settings\NetworkService\ntuser.dat.LOG L'objet est verrouillé ignoré
                F:\luk1ylq.com Infecté : Trojan.Win32.Agent.bvsq ignoré
                F:\Program Files\eMule\Incoming\Adobe.Premiere.Pro.CS4-NoPE_crack_multilanguage_tested_ok.zip/Adobe.Premiere.Pro.CS4-NoPE_crack_multilanguage_tested_ok/Adobe.Premiere.Pro.CS4-NoPE_CRACK.exe Infecté : Trojan-Downloader.Win32.Agent.bipq ignoré
                F:\Program Files\eMule\Incoming\Adobe.Premiere.Pro.CS4-NoPE_crack_multilanguage_tested_ok.zip ZIP: infecté - 1 ignoré
                F:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
                F:\System Volume Information\_restore{70C6087A-59A5-4833-B6F7-5B15E72EDDE2}\RP100\change.log L'objet est verrouillé ignoré
                F:\System Volume Information\_restore{70C6087A-59A5-4833-B6F7-5B15E72EDDE2}\RP90\A0022591.com Infecté : Trojan.Win32.Agent.bvsq ignoré
                F:\System Volume Information\_restore{70C6087A-59A5-4833-B6F7-5B15E72EDDE2}\RP90\A0022597.exe Infecté : Trojan.Win32.Agent.bvsq ignoré
                F:\WINDOWS\Debug\PASSWD.LOG L'objet est verrouillé ignoré
                F:\WINDOWS\Internet Logs\IAMDB.RDB L'objet est verrouillé ignoré
                F:\WINDOWS\Internet Logs\JEREM.ldb L'objet est verrouillé ignoré
                F:\WINDOWS\Internet Logs\tvDebug.log L'objet est verrouillé ignoré
                F:\WINDOWS\SchedLgU.Txt L'objet est verrouillé ignoré
                F:\WINDOWS\SoftwareDistribution\ReportingEvents.log L'objet est verrouillé ignoré
                F:\WINDOWS\system32\CatRoot2\edb.log L'objet est verrouillé ignoré
                F:\WINDOWS\system32\CatRoot2\tmp.edb L'objet est verrouillé ignoré
                F:\WINDOWS\system32\CatRoot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\AppEvent.Evt L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\Canal+.evt L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\default L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\default.LOG L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\Internet.evt L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\ODiag.evt L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\OSession.evt L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\SAM L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\SAM.LOG L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\SecEvent.Evt L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\SECURITY L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\SECURITY.LOG L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\software L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\software.LOG L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\SysEvent.Evt L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\system L'objet est verrouillé ignoré
                F:\WINDOWS\system32\config\system.LOG L'objet est verrouillé ignoré
                F:\WINDOWS\system32\drivers\sptd.sys L'objet est verrouillé ignoré
                F:\WINDOWS\system32\h323log.txt L'objet est verrouillé ignoré
                F:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl L'objet est verrouillé ignoré
                F:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR L'objet est verrouillé ignoré
                F:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP L'objet est verrouillé ignoré
                F:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER L'objet est verrouillé ignoré
                F:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP L'objet est verrouillé ignoré
                F:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP L'objet est verrouillé ignoré
                F:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA L'objet est verrouillé ignoré
                F:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP L'objet est verrouillé ignoré
                F:\WINDOWS\Temp\Perflib_Perfdata_498.dat L'objet est verrouillé ignoré
                F:\WINDOWS\Temp\ZLT00aff.TMP L'objet est verrouillé ignoré
                F:\WINDOWS\WindowsUpdate.log L'objet est verrouillé ignoré
                J:\luk1ylq.com Infecté : Trojan.Win32.Agent.bvsq ignoré
                J:\System Volume Information\MountPointManagerRemoteDatabase L'objet est verrouillé ignoré
                J:\System Volume Information\_restore{70C6087A-59A5-4833-B6F7-5B15E72EDDE2}\RP100\change.log L'objet est verrouillé ignoré
                J:\System Volume Information\_restore{70C6087A-59A5-4833-B6F7-5B15E72EDDE2}\RP90\A0022593.com Infecté : Trojan.Win32.Agent.bvsq ignoré

                Analyse terminée.
                0
                1. Contributeur
                  - Va à la racine du disque dur et supprimes c:\qobox

                  ----------------------
                  - * Mets Adobe à jour : ( n'installes pas la barre d'outil google, décoches la)
                  https://get2.adobe.com/reader/otherversions/

                  ---------------------
                  * Installes la dernière version de Java :
                  https://www.java.com/fr/download/manual.jsp

                  -------------------
                  * Une fois à jour, télécharges JavaRa.zip
                  http://raproducts.org/click/click.php?id=1
                  ---> Autorise le processus a se connecter si il te le demande
                  . Cliques sur Install et suis les instructions

                  - Quand l'installation est finie, reviens à l'écran JavaRa

                  -Clic sur " Remove Old Versions " ou " recherches d'anciennes versions " --> cliques sur " oui "

                  -l'outil va travailler, cliques ensuite sur " Ok " et à nouveau sur Ok

                  - Un rapport s'ouvrira, refermes l'application puis postes le

                  - Met un coup de ccleaner >> nettoyage

                  -------------------
                  * Afin de mettre à jour les applications de ton pc et de verifier leur vulnerabilité, Installes le PCI de secunia :

                  https://www.flexera.com/products/operations/software-vulnerability-management.html

                  aides toi du tuto :

                  https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/
                  .
                  --------------------

                  Avast n'est pas un bon antivirus, supprimes le et telecharge avira antivir

                  https://www.avast.com/fr-fr/uninstall-utility ( utilitaire de desinstallation Avast)

                  Avira antivir est beaucoup plus performant, c'est ce que l'on fait de mieux en gratuits

                  https://www.avira.com/ et un tuto : https://www.malekal.com/avira-free-security-antivirus-gratuit/

                  Note :( 1 seul antivirus et 1 pare-feu )

                  ------------------------------

                  Ensuite, Fais un scan en ligne ici https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr (Avec Internet Explorer)

                  - En bas à droite, clique sur Démarrer Online-scanner

                  - Dans la nouvelle fenêtre qui s'affiche, clique sur J'accepte

                  - Accepte les Contrôles ActiveX

                  - Choisis Poste de travail pour le scan.

                  - Celui-ci terminé, sauvegarde (Choisis fichier texte) et poste le rapport

                  - Pour t'aider à utiliser le scan en ligne :
                  https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId291566

                  NOTE : Si tu reçois le message "La licence de Kaspersky On-line Scanner est périmée", va dans Ajout/Suppression de programmes puis désinstalle On-Line Scanner, reconnecte-toi sur le site de Kaspersky pour retenter le scan en ligne.
                  ------------------------------

                  Avant de lancer le scan en ligne Kaspersky, fais ceci :
                  le scan Kaspersky, fais ceci : Afficher les dossiers et fichiers cachés du systeme

                  -Démarrer
                  -Poste de travail
                  -Outils
                  -Options des dossiers
                  -Onglet "Affichage"
                  -Sous "Fichiers et dossiers cachés", cocher "Afficher les fichiers et dossiers cachés"
                  -Désélectionner "Masquer les fichiers protégés du système d'exploitation (recommandé)"
                  -Désélectionner "Masquer les extensions des fichiers dont le type est connu"
                  -Cliquez sur Oui dans la boîte de dialogue qui vous demande confirmation de votre choix.
                  -Ok
                  ------------------------------
                  .
                  0
                  1. Voilà les 2 rapports :

                    ComboFix 09-03-15.01 - Jeremy 2009-03-18 16:49:33.2 - NTFSx86
                    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1023.627 [GMT 1:00]
                    Lancé depuis: f:\documents and settings\Jeremy\Bureau\ComboFix.exe
                    Commutateurs utilisés :: f:\documents and settings\Jeremy\Bureau\CFScript.txt
                    AV: avast! antivirus 4.8.1335 [VPS 090317-0] *On-access scanning disabled* (Updated)
                    FW: ZoneAlarm Firewall *disabled*
                    * Un nouveau point de restauration a été créé
                    .

                    ((((((((((((((((((((((((((((( Fichiers créés du 2009-02-18 au 2009-03-18 ))))))))))))))))))))))))))))))))))))
                    .

                    2009-03-18 13:03 . 2009-03-18 15:23 <REP> d-------- f:\program files\FindyKill
                    2009-03-18 12:54 . 2009-03-18 12:54 <REP> d-------- f:\program files\CCleaner
                    2009-03-18 12:41 . 2009-03-18 12:42 <REP> d-------- F:\rsit
                    2009-03-18 12:41 . 2009-03-18 12:42 <REP> d-------- f:\program files\trend micro
                    2009-03-16 20:59 . 2008-04-13 11:45 10,368 --a------ f:\windows\system32\drivers\hidusb.sys
                    2009-03-16 20:59 . 2008-04-13 11:45 10,368 --a--c--- f:\windows\system32\dllcache\hidusb.sys
                    2009-03-16 19:06 . 2009-03-16 19:06 <REP> d-------- f:\documents and settings\All Users\Application Data\KONAMI
                    2009-03-16 18:56 . 2009-03-17 12:17 111,435 -r-hs---- F:\luk1ylq.com
                    2009-03-15 22:30 . 2009-03-15 22:30 <REP> d-------- f:\documents and settings\Jeremy\Application Data\Malwarebytes
                    2009-03-15 22:30 . 2009-03-15 22:30 <REP> d-------- f:\documents and settings\All Users\Application Data\Malwarebytes
                    2009-03-15 22:09 . 2009-03-15 22:09 118 --a------ f:\windows\system32\MRT.INI
                    2009-02-27 13:54 . 2009-02-27 14:04 <REP> d-------- f:\documents and settings\Jeremy\Application Data\LimeWire
                    2009-02-19 12:09 . 2009-02-19 12:10 <REP> d-------- f:\windows\system32\ZoneLabs
                    2009-02-19 12:09 . 2008-11-13 15:18 1,221,008 --a------ f:\windows\system32\zpeng25.dll
                    2009-02-19 12:09 . 2009-03-18 16:53 348,371 --a------ f:\windows\system32\vsconfig.xml
                    2009-02-18 17:24 . 2009-02-18 17:24 <REP> d-------- f:\documents and settings\All Users\Application Data\ALM

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2009-03-18 15:54 --------- d-----w f:\documents and settings\Jeremy\Application Data\skypePM
                    2009-03-18 15:54 --------- d-----w f:\documents and settings\Jeremy\Application Data\Skype
                    2009-03-18 15:47 --------- d-----w f:\documents and settings\Jeremy\Application Data\Azureus
                    2009-03-17 19:43 --------- d-----w f:\documents and settings\Jeremy\Application Data\dvdcss
                    2009-03-11 11:09 --------- d-----w f:\documents and settings\All Users\Application Data\Microsoft Help
                    2009-03-10 23:43 --------- d-----w f:\documents and settings\Jeremy\Application Data\Sites
                    2009-03-10 23:43 --------- d-----w f:\documents and settings\Jeremy\Application Data\Classes de site
                    2009-03-07 17:47 --------- d-----w f:\program files\Vuze
                    2009-03-05 11:45 --------- d-----w f:\program files\Fichiers communs\Adobe AIR
                    2009-02-27 12:54 --------- d-----w f:\program files\eMule
                    2009-02-27 12:36 --------- d-----w f:\program files\Fichiers communs\Adobe
                    2009-02-27 11:32 --------- d-----w f:\documents and settings\Jeremy\Application Data\Download Manager
                    2009-02-19 16:50 --------- d-----w f:\documents and settings\Jeremy\Application Data\Hamachi
                    2009-02-18 14:17 --------- d-----w f:\documents and settings\Jeremy\Application Data\Apple Computer
                    2009-02-15 16:08 25,280 ----a-w f:\windows\system32\drivers\hamachi.sys
                    2009-02-14 23:16 --------- d-----w f:\program files\WorldOfGoo
                    2009-02-12 22:10 --------- d-----w f:\documents and settings\All Users\Application Data\2DBoy
                    2009-02-12 13:19 --------- d--h--w f:\program files\InstallShield Installation Information
                    2009-02-11 13:13 --------- d-----w f:\program files\Xvid
                    2009-02-10 18:03 --------- d-----w f:\program files\Fichiers communs\Skype
                    2009-02-10 18:03 --------- d-----w f:\documents and settings\All Users\Application Data\Skype
                    2009-02-10 18:03 --------- d-----r f:\program files\Skype
                    2009-02-01 22:47 --------- d-----w f:\program files\Java
                    2009-01-30 16:04 --------- d-----w f:\program files\QuickTime
                    2009-01-30 16:04 --------- d-----w f:\program files\iTunes
                    2009-01-30 16:04 --------- d-----w f:\program files\iPod
                    2009-01-30 16:04 --------- d-----w f:\program files\Fichiers communs\Apple
                    2009-01-30 16:04 --------- d-----w f:\documents and settings\All Users\Application Data\Apple Computer
                    2009-01-30 16:04 --------- d-----w f:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
                    2009-01-30 16:03 --------- d-----w f:\program files\Apple Software Update
                    2009-01-30 16:03 --------- d-----w f:\documents and settings\All Users\Application Data\Apple
                    2009-01-30 15:58 --------- d-----w f:\program files\Research In Motion
                    2009-01-30 15:58 --------- d-----w f:\documents and settings\Jeremy\Application Data\Research In Motion
                    2009-01-27 16:39 --------- d--h--r f:\documents and settings\Jeremy\Application Data\SecuROM
                    2009-01-27 16:08 22,328 ----a-w f:\documents and settings\Jeremy\Application Data\PnkBstrK.sys
                    2009-01-26 16:43 --------- d-----w f:\documents and settings\Jeremy\Application Data\Roxio
                    2009-01-26 16:43 --------- d-----w f:\documents and settings\All Users\Application Data\Roxio
                    2009-01-26 15:58 --------- d-----w f:\documents and settings\LocalService\Application Data\Roxio
                    2009-01-26 15:52 --------- d-----w f:\documents and settings\Jeremy\Application Data\vlc
                    2009-01-26 15:48 --------- d-----w f:\documents and settings\Jeremy\Application Data\InstallShield
                    2009-01-26 15:47 --------- d-----w f:\program files\Fichiers communs\Roxio Shared
                    2009-01-26 15:45 --------- d-----w f:\program files\Roxio
                    2009-01-26 15:44 --------- d-----w f:\program files\Fichiers communs\Sonic Shared
                    2009-01-26 15:27 --------- d-----w f:\program files\Fichiers communs\Research In Motion
                    2009-01-26 13:29 --------- d-----w f:\program files\VideoLAN
                    2009-01-23 22:10 --------- d-----w f:\documents and settings\All Users\Application Data\Sonic
                    2009-01-23 22:10 --------- d-----w f:\documents and settings\All Users\Application Data\InstallShield
                    2009-01-23 22:06 --------- d-----w f:\program files\Fichiers communs\InstallShield
                    2009-01-20 19:09 --------- d-----w f:\documents and settings\Jeremy\Application Data\Partouche
                    2009-01-19 11:07 --------- d-----w f:\program files\NOS
                    2009-01-19 11:07 --------- d-----w f:\documents and settings\All Users\Application Data\NOS
                    2009-01-18 16:35 --------- d-----w f:\documents and settings\Jeremy\Application Data\Dynamique
                    2009-01-18 16:34 --------- d-----w f:\program files\Visicom Media
                    .

                    ((((((((((((((((((((((((((((( SnapShot@2009-03-18_14.22.27.17 )))))))))))))))))))))))))))))))))))))))))
                    .
                    + 2009-03-18 15:56:07 16,384 ----atw f:\windows\Temp\Perflib_Perfdata_250.dat
                    + 2009-03-18 15:53:51 16,384 ----atw f:\windows\Temp\Perflib_Perfdata_6b4.dat
                    - 2009-03-18 13:17:24 16,384 ----atw f:\windows\Temp\Perflib_Perfdata_72c.dat
                    + 2009-03-18 15:53:18 16,384 ----atw f:\windows\Temp\Perflib_Perfdata_72c.dat
                    .
                    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                    REGEDIT4

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "CTFMON.EXE"="f:\windows\system32\ctfmon.exe" [2008-04-13 15360]
                    "msnmsgr"="f:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
                    "DAEMON Tools Lite"="f:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
                    "ISUSPM"="f:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
                    "Skype"="f:\program files\Skype\Phone\Skype.exe" [2009-02-04 23975720]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "ALi5289"="f:\program files\ULI5289\ALi5289.exe" [2005-03-10 405504]
                    "RemoteControl"="f:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
                    "NvCplDaemon"="f:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
                    "avast!"="f:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
                    "Canal Widget"="f:\program files\Canal\Canal Widget\Launcher.exe" [2009-02-04 106040]
                    "NvMediaCenter"="f:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
                    "Adobe Reader Speed Launcher"="f:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
                    "AdobeCS4ServiceManager"="f:\program files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
                    "BlackBerryAutoUpdate"="f:\program files\Fichiers communs\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696]
                    "RoxWatchTray"="f:\program files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-09-19 236016]
                    "QuickTime Task"="f:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
                    "iTunesHelper"="f:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
                    "SunJavaUpdateSched"="f:\program files\Java\jre6\bin\jusched.exe" [2009-02-01 136600]
                    "ZoneAlarm Client"="f:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-11-13 981904]
                    "SoundMan"="SOUNDMAN.EXE" [2004-07-27 f:\windows\SOUNDMAN.EXE]
                    "nwiz"="nwiz.exe" [2008-09-17 f:\windows\system32\nwiz.exe]
                    "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 f:\windows\system32\bthprops.cpl]

                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                    "CTFMON.EXE"="f:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

                    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
                    "DisableMonitoring"=dword:00000001

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                    "EnableFirewall"= 0 (0x0)

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                    "%windir%\\system32\\sessmgr.exe"=
                    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                    "f:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                    "f:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
                    "f:\\Program Files\\Vuze\\Azureus.exe"=
                    "j:\\Jeux\\LEFT 4 DEAD\\hl2.exe"=
                    "f:\\Program Files\\iTunes\\iTunes.exe"=
                    "f:\\Program Files\\eMule\\emule.exe"=
                    "j:\\Jeux\\LEFT 4 DEAD\\left4dead.exe"=
                    "f:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                    "f:\\Program Files\\Skype\\Phone\\Skype.exe"=
                    "c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                    "5353:TCP"= 5353:TCP:Adobe CSI CS4

                    R0 m5289;m5289;f:\windows\system32\drivers\m5289.sys [2005-07-08 51840]
                    R0 uliagpkx;ULi AGP Bus Filter Driver;f:\windows\system32\drivers\AGPKX.SYS [2009-01-15 45056]
                    R1 aswSP;avast! Self Protection;f:\windows\system32\drivers\aswSP.sys [2009-01-15 114768]
                    R2 aswFsBlk;aswFsBlk;f:\windows\system32\drivers\aswFsBlk.sys [2009-01-15 20560]
                    R2 CanalPlus.VOD;CanalPlus.VOD;f:\program files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe [2008-12-10 61440]
                    R3 ULI5261XP;ULi M526X Ethernet NT Driver;f:\windows\system32\drivers\ULILAN51.SYS [2009-01-15 28672]
                    .
                    .
                    ------- Examen supplémentaire -------
                    .
                    uStart Page = hxxp://www.google.fr/ig?hl=fr&source=iglk
                    IE: E&xporter vers Microsoft Excel - f:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
                    TCP: {0CF64F40-DD0D-49A2-AE9B-949F5636FE48} = 192.168.1.240
                    FF - ProfilePath - f:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\
                    FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/ig?hl=fr&source=iglk
                    FF - component: f:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
                    FF - plugin: f:\program files\Canal\Canal Widget\VOD\npCpVod.dll
                    .

                    **************************************************************************

                    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2009-03-18 16:56:03
                    Windows 5.1.2600 Service Pack 3 NTFS

                    Recherche de processus cachés ...

                    Recherche d'éléments en démarrage automatique cachés ...

                    Recherche de fichiers cachés ...

                    Scan terminé avec succès
                    Fichiers cachés: 0

                    **************************************************************************
                    "ServiceDll"="f:\windows\system32\es.dll"

                    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FAH@F:+DOCUME~1+Jeremy+LOCALS~1+Temp+Rar$EX06.718+[RAZOR1911][WEB SEED] FAR CRY 2 CRACK - REAL 100% FULLY WORKING+FAH.exe]
                    0
                    1. Contributeur
                      > Télécharge ATF Cleaner par Atribune sur ton bureau : http://www.atribune.org/ccount/click.php?id=1
                      - Démarre ATF-Cleaner et coche toutes les cases.
                      - Clique sur <Empty Selected> et au message "Done Cleaning" sur <Ok>
                      NB : Si tu utilises Firefox ou Opera :
                      - Clique sur Firefox ou Opera en haut puis choisis <Select All>.
                      - Clique sur le bouton <Empty Selected> (NB : Si tu veux conserver tes mots de passe sauvegardés alors clique sur <No> à l'invite).
                      - Clique sur <Main> pour revenir à menu principal
                      - Clique sur <Exit>, du menu prinicipal, pour quitter ATFcleaner.
                      NB : Si le prefetch est nettoyé le redémarrage du PC sera plus lent.

                      -----------------------------

                      > Avec Combofix :
                      - Crée un nouveau document texte : clic droit de souris sur le bureau => Nouveau => Document Texte, et copie/colle dedans les lignes suivantes :



                      KILLALL::

                      Registry::
                      [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1e74740-fb53-11dd-b2a9-00138f381fe2}]

                      Files::
                      F:\luk1ylq.com
                      F:\WINDOWS\system32\nmdfgds1.dll
                      I:\cb.exe



                      - Enregistre ce fichier sous le nom CFScript (Type du fichier : tous les fichiers)
                      - Ferme tous tes navigateurs web (donc copie ou imprime les instructions suivantes avant si besoin est).
                      - Désactive ton antivirus et tes autres protections résidentes (ex : Spybot) si tu en as (c'est important).
                      - Fait un glisser/déposer de ce fichier CFScript sur le programme ComboFix.exe comme sur le lien :
                      http://img517.imageshack.us/img517/8662/cfscript10uc2.gif

                      ( Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relâche alors le bouton de la souris).
                      - Combofix va démarrer puis une fenêtre bleue va apparaître. Au message qui s'affiche (Type 1 to continue, or 2 to abort) : tape 1 puis valide.
                      - Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal !
                      - Ne touche à rien tant que le scan n'est pas terminé sinon le PC peut planter !
                      - Une fois le scan achevé, un rapport va s'afficher: poste le stp.

                      . -----------------------------

                      - Telecharges Malwarebytes' Anti-Malware :

                      http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                      - Installe le > double-clic sur Mbam-setup.exe, à la fin de l'installation, il se mettra automatiquement à jour
                      - Une fois installé, fermes toutes les applications en cours et lances Malwarebytes
                      - Executes un examen rapide du pc ( tu n'auras pas accés à internet pendant l'analyse)
                      - A la fin du scan clic sur " Afficher les resultats ", si Malwarebytes a trouvé des infections >> clic sur " Supprimer la selection "
                      - Si il a besoin de redemarrer le pc pour finir la desinfection, acceptes
                      - Un rapport s'etablira, postes son contenu.
                      ----------------------------------
                      0
                      1. Nan c'est bon apparemment y a plus rien

                        ################################### [ FindyKill V4.720 ]

                        # User : Jeremy (Administrateurs) # JEREM
                        # Update on 12/03/09 by Chiquitine29
                        # Start at: 15:23:55 | 18/03/2009

                        # AMD Athlon(tm) 64 Processor 3000+
                        # Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                        # Internet Explorer 7.0.5730.13
                        # Windows Firewall Status : Disabled
                        # AV : avast! antivirus 4.8.1335 [VPS 090317-0] 4.8.1335 [ Enabled | Updated ]
                        # FW : ZoneAlarm Firewall[ Enabled ]8.0.065.000

                        # A:\ # Lecteur de disquettes 3 ½ pouces
                        # C:\ # Disque fixe local # 128,49 Go (90,23 Go free) # NTFS
                        # D:\ # Disque CD-ROM # 2,56 Go (0 Mo free) [Logiciels] # CDFS
                        # E:\ # Disque CD-ROM # 3,77 Go (0 Mo free) [Kaamelott - L.4] # CDFS
                        # F:\ # Disque fixe local # 19,53 Go (5,01 Go free) [Système] # NTFS
                        # G:\ # Disque CD-ROM
                        # H:\ # Disque CD-ROM
                        # I:\ # Disque amovible # 3,84 Go (3,09 Go free) # FAT32
                        # J:\ # Disque fixe local # 465,76 Go (34,24 Go free) # NTFS

                        ################################### [ Cracks / Keygens ... ]

                        ################## [ ! Fin du rapport # FindyKill V4.720 ! ]
                        0
                        1. Contributeur
                          Branches tes disues amovibles sans les ouvrir et fais l'option 4 de Findykill

                          - Postes le rapport généré...
                          0
                          1. J'ai l'impression qu'il y a encore des traces du crack far cry...

                            ComboFix 09-03-15.01 - Jeremy 2009-03-18 14:14:44.1 - NTFSx86
                            Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.602 [GMT 1:00]
                            Lancé depuis: f:\documents and settings\Jeremy\Bureau\ComboFix.exe
                            AV: avast! antivirus 4.8.1335 [VPS 090317-0] *On-access scanning disabled* (Updated)
                            FW: ZoneAlarm Firewall *enabled*
                            * Un nouveau point de restauration a été créé
                            .

                            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                            .

                            C:\Autorun.inf
                            C:\uxkl0apt.bat
                            C:\yh.cmd
                            F:\autorun.inf
                            F:\uxkl0apt.bat
                            f:\windows\system32\nmdfgds0.dll
                            f:\windows\system32\olhrwef.exe
                            F:\yh.cmd
                            I:\autorun.inf
                            I:\uxkl0apt.bat
                            I:\yh.cmd
                            J:\Autorun.inf
                            J:\uxkl0apt.bat
                            J:\yh.cmd

                            .
                            ((((((((((((((((((((((((((((( Fichiers créés du 2009-02-18 au 2009-03-18 ))))))))))))))))))))))))))))))))))))
                            .

                            2009-03-18 13:03 . 2009-03-18 13:58 <REP> d-------- f:\program files\FindyKill
                            2009-03-18 12:54 . 2009-03-18 12:54 <REP> d-------- f:\program files\CCleaner
                            2009-03-18 12:41 . 2009-03-18 12:42 <REP> d-------- F:\rsit
                            2009-03-18 12:41 . 2009-03-18 12:42 <REP> d-------- f:\program files\trend micro
                            2009-03-16 20:59 . 2008-04-13 11:45 10,368 --a------ f:\windows\system32\drivers\hidusb.sys
                            2009-03-16 20:59 . 2008-04-13 11:45 10,368 --a--c--- f:\windows\system32\dllcache\hidusb.sys
                            2009-03-16 19:06 . 2009-03-16 19:06 <REP> d-------- f:\documents and settings\All Users\Application Data\KONAMI
                            2009-03-16 18:56 . 2009-03-17 12:17 111,435 -r-hs---- F:\luk1ylq.com
                            2009-03-15 22:30 . 2009-03-15 22:30 <REP> d-------- f:\documents and settings\Jeremy\Application Data\Malwarebytes
                            2009-03-15 22:30 . 2009-03-15 22:30 <REP> d-------- f:\documents and settings\All Users\Application Data\Malwarebytes
                            2009-03-15 22:09 . 2009-03-15 22:09 118 --a------ f:\windows\system32\MRT.INI
                            2009-02-27 13:54 . 2009-02-27 14:04 <REP> d-------- f:\documents and settings\Jeremy\Application Data\LimeWire
                            2009-02-19 12:09 . 2009-02-19 12:10 <REP> d-------- f:\windows\system32\ZoneLabs
                            2009-02-19 12:09 . 2008-11-13 15:18 1,221,008 --a------ f:\windows\system32\zpeng25.dll
                            2009-02-19 12:09 . 2009-03-18 14:17 348,371 --a------ f:\windows\system32\vsconfig.xml
                            2009-02-18 17:24 . 2009-02-18 17:24 <REP> d-------- f:\documents and settings\All Users\Application Data\ALM

                            .
                            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            2009-03-18 13:18 --------- d-----w f:\documents and settings\Jeremy\Application Data\Skype
                            2009-03-18 13:06 --------- d-----w f:\documents and settings\Jeremy\Application Data\Azureus
                            2009-03-18 11:14 --------- d-----w f:\documents and settings\Jeremy\Application Data\skypePM
                            2009-03-17 19:43 --------- d-----w f:\documents and settings\Jeremy\Application Data\dvdcss
                            2009-03-11 11:09 --------- d-----w f:\documents and settings\All Users\Application Data\Microsoft Help
                            2009-03-10 23:43 --------- d-----w f:\documents and settings\Jeremy\Application Data\Sites
                            2009-03-10 23:43 --------- d-----w f:\documents and settings\Jeremy\Application Data\Classes de site
                            2009-03-07 17:47 --------- d-----w f:\program files\Vuze
                            2009-03-05 11:45 --------- d-----w f:\program files\Fichiers communs\Adobe AIR
                            2009-03-02 11:11 83,558 ----a-w f:\windows\Internet Logs\zlclient_2nd_2009_03_01_22_16_02_small.dmp.zip
                            2009-02-27 13:05 1,427,968 ----a-w f:\windows\Internet Logs\xDB1.tmp
                            2009-02-27 12:54 --------- d-----w f:\program files\eMule
                            2009-02-27 12:36 --------- d-----w f:\program files\Fichiers communs\Adobe
                            2009-02-27 11:32 --------- d-----w f:\documents and settings\Jeremy\Application Data\Download Manager
                            2009-02-26 11:07 924,991 ----a-w f:\windows\Internet Logs\tvDebug.Zip
                            2009-02-19 16:50 --------- d-----w f:\documents and settings\Jeremy\Application Data\Hamachi
                            2009-02-18 14:17 --------- d-----w f:\documents and settings\Jeremy\Application Data\Apple Computer
                            2009-02-15 16:08 25,280 ----a-w f:\windows\system32\drivers\hamachi.sys
                            2009-02-14 23:16 --------- d-----w f:\program files\WorldOfGoo
                            2009-02-12 22:10 --------- d-----w f:\documents and settings\All Users\Application Data\2DBoy
                            2009-02-12 13:19 --------- d--h--w f:\program files\InstallShield Installation Information
                            2009-02-11 13:13 --------- d-----w f:\program files\Xvid
                            2009-02-10 18:03 --------- d-----w f:\program files\Fichiers communs\Skype
                            2009-02-10 18:03 --------- d-----w f:\documents and settings\All Users\Application Data\Skype
                            2009-02-10 18:03 --------- d-----r f:\program files\Skype
                            2009-02-01 22:47 --------- d-----w f:\program files\Java
                            2009-01-30 16:04 --------- d-----w f:\program files\QuickTime
                            2009-01-30 16:04 --------- d-----w f:\program files\iTunes
                            2009-01-30 16:04 --------- d-----w f:\program files\iPod
                            2009-01-30 16:04 --------- d-----w f:\program files\Fichiers communs\Apple
                            2009-01-30 16:04 --------- d-----w f:\documents and settings\All Users\Application Data\Apple Computer
                            2009-01-30 16:04 --------- d-----w f:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
                            2009-01-30 16:03 --------- d-----w f:\program files\Apple Software Update
                            2009-01-30 16:03 --------- d-----w f:\documents and settings\All Users\Application Data\Apple
                            2009-01-30 15:58 --------- d-----w f:\program files\Research In Motion
                            2009-01-30 15:58 --------- d-----w f:\documents and settings\Jeremy\Application Data\Research In Motion
                            2009-01-27 16:39 --------- d--h--r f:\documents and settings\Jeremy\Application Data\SecuROM
                            2009-01-27 16:08 22,328 ----a-w f:\documents and settings\Jeremy\Application Data\PnkBstrK.sys
                            2009-01-26 16:43 --------- d-----w f:\documents and settings\Jeremy\Application Data\Roxio
                            2009-01-26 16:43 --------- d-----w f:\documents and settings\All Users\Application Data\Roxio
                            2009-01-26 15:58 --------- d-----w f:\documents and settings\LocalService\Application Data\Roxio
                            2009-01-26 15:52 --------- d-----w f:\documents and settings\Jeremy\Application Data\vlc
                            2009-01-26 15:48 --------- d-----w f:\documents and settings\Jeremy\Application Data\InstallShield
                            2009-01-26 15:47 --------- d-----w f:\program files\Fichiers communs\Roxio Shared
                            2009-01-26 15:45 --------- d-----w f:\program files\Roxio
                            2009-01-26 15:44 --------- d-----w f:\program files\Fichiers communs\Sonic Shared
                            2009-01-26 15:27 --------- d-----w f:\program files\Fichiers communs\Research In Motion
                            2009-01-26 13:29 --------- d-----w f:\program files\VideoLAN
                            2009-01-23 22:10 --------- d-----w f:\documents and settings\All Users\Application Data\Sonic
                            2009-01-23 22:10 --------- d-----w f:\documents and settings\All Users\Application Data\InstallShield
                            2009-01-23 22:06 --------- d-----w f:\program files\Fichiers communs\InstallShield
                            2009-01-20 19:09 --------- d-----w f:\documents and settings\Jeremy\Application Data\Partouche
                            2009-01-19 11:07 --------- d-----w f:\program files\NOS
                            2009-01-19 11:07 --------- d-----w f:\documents and settings\All Users\Application Data\NOS
                            2009-01-18 16:35 --------- d-----w f:\documents and settings\Jeremy\Application Data\Dynamique
                            2009-01-18 16:34 --------- d-----w f:\program files\Visicom Media
                            .

                            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                            .
                            .
                            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                            REGEDIT4

                            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "CTFMON.EXE"="f:\windows\system32\ctfmon.exe" [2008-04-13 15360]
                            "msnmsgr"="f:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
                            "DAEMON Tools Lite"="f:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
                            "ISUSPM"="f:\program files\Fichiers communs\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
                            "Skype"="f:\program files\Skype\Phone\Skype.exe" [2009-02-04 23975720]

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                            "ALi5289"="f:\program files\ULI5289\ALi5289.exe" [2005-03-10 405504]
                            "RemoteControl"="f:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-10-31 32768]
                            "NvCplDaemon"="f:\windows\system32\NvCpl.dll" [2008-09-17 13574144]
                            "avast!"="f:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
                            "Canal Widget"="f:\program files\Canal\Canal Widget\Launcher.exe" [2009-02-04 106040]
                            "NvMediaCenter"="f:\windows\system32\NvMcTray.dll" [2008-09-17 86016]
                            "Adobe Reader Speed Launcher"="f:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
                            "AdobeCS4ServiceManager"="f:\program files\Fichiers communs\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
                            "BlackBerryAutoUpdate"="f:\program files\Fichiers communs\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2008-11-04 615696]
                            "RoxWatchTray"="f:\program files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-09-19 236016]
                            "QuickTime Task"="f:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
                            "iTunesHelper"="f:\program files\iTunes\iTunesHelper.exe" [2009-01-06 290088]
                            "SunJavaUpdateSched"="f:\program files\Java\jre6\bin\jusched.exe" [2009-02-01 136600]
                            "ZoneAlarm Client"="f:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-11-13 981904]
                            "SoundMan"="SOUNDMAN.EXE" [2004-07-27 f:\windows\SOUNDMAN.EXE]
                            "nwiz"="nwiz.exe" [2008-09-17 f:\windows\system32\nwiz.exe]
                            "BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-13 f:\windows\system32\bthprops.cpl]

                            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                            "CTFMON.EXE"="f:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

                            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
                            "DisableMonitoring"=dword:00000001

                            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                            "EnableFirewall"= 0 (0x0)

                            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                            "%windir%\\system32\\sessmgr.exe"=
                            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                            "f:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                            "f:\\Program Files\\Fichiers communs\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
                            "f:\\Program Files\\Vuze\\Azureus.exe"=
                            "j:\\Jeux\\LEFT 4 DEAD\\hl2.exe"=
                            "f:\\Program Files\\iTunes\\iTunes.exe"=
                            "f:\\Program Files\\eMule\\emule.exe"=
                            "j:\\Jeux\\LEFT 4 DEAD\\left4dead.exe"=
                            "f:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                            "f:\\Program Files\\Skype\\Phone\\Skype.exe"=
                            "c:\\Program Files\\KONAMI\\Pro Evolution Soccer 2009\\pes2009.exe"=

                            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                            "5353:TCP"= 5353:TCP:Adobe CSI CS4

                            R0 m5289;m5289;f:\windows\system32\drivers\m5289.sys [2005-07-08 51840]
                            R0 uliagpkx;ULi AGP Bus Filter Driver;f:\windows\system32\drivers\AGPKX.SYS [2009-01-15 45056]
                            R1 aswSP;avast! Self Protection;f:\windows\system32\drivers\aswSP.sys [2009-01-15 114768]
                            R2 aswFsBlk;aswFsBlk;f:\windows\system32\drivers\aswFsBlk.sys [2009-01-15 20560]
                            R2 CanalPlus.VOD;CanalPlus.VOD;f:\program files\Canal\Canal Widget\VOD\CanalPlus.VOD.exe [2008-12-10 61440]
                            R3 ULI5261XP;ULi M526X Ethernet NT Driver;f:\windows\system32\drivers\ULILAN51.SYS [2009-01-15 28672]

                            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c1e74740-fb53-11dd-b2a9-00138f381fe2}]
                            \Shell\AutoRun\command - WDSetup.exe
                            .
                            - - - - ORPHELINS SUPPRIMES - - - -

                            HKCU-Run-cdoosoft - f:\windows\system32\olhrwef.exe

                            .
                            ------- Examen supplémentaire -------
                            .
                            uStart Page = hxxp://www.google.fr/ig?hl=fr&source=iglk
                            IE: E&xporter vers Microsoft Excel - f:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
                            TCP: {0CF64F40-DD0D-49A2-AE9B-949F5636FE48} = 192.168.1.240
                            FF - ProfilePath - f:\documents and settings\Jeremy\Application Data\Mozilla\Firefox\Profiles\2f8z26tt.default\
                            FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/ig?hl=fr&source=iglk
                            FF - component: f:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
                            FF - plugin: f:\program files\Canal\Canal Widget\VOD\npCpVod.dll
                            .

                            **************************************************************************

                            catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2009-03-18 14:20:09
                            Windows 5.1.2600 Service Pack 3 NTFS

                            Recherche de processus cachés ...

                            Recherche d'éléments en démarrage automatique cachés ...

                            Recherche de fichiers cachés ...

                            Scan terminé avec succès
                            Fichiers cachés: 0

                            **************************************************************************
                            "ServiceDll"="f:\windows\system32\es.dll"

                            [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\FAH@F:+DOCUME~1+Jeremy+LOCALS~1+Temp+Rar$EX06.718+[RAZOR1911][WEB SEED] FAR CRY 2 CRACK - REAL 100% FULLY WORKING+FAH.exe]
                            0
                            1. Contributeur
                              Telecharges Combofix et enregistres le sur ton bureau

                              http://download.bleepingcomputer.com/sUBs/ComboFix.exe -

                              /!\ Desactives ton antivirus et la garde de ton antispyware ( si tu en as un) /!\

                              - Deconnectes toi et fermes toutes les applications en cours
                              - Double clic sur Combofix.exe >> un message apparait > réponds " oui "
                              - ( Il est conseillé d'installer la console de recuperations)
                              - Selectionnes la langue et presse la touche 1 ( yes) pour lancer le scan

                              /!\ Ne touche ni à la souris, ni au clavier durant le scan, cela pourrait figer l'ordi /!\

                              - A la fin du scan, Combofix aura besoin de redemarrer pour finir la desinfection, laisses le faire
                              - Une fois terminé, un rapport s'affiche, poste son contenu que tu peux aussi trouver à c:\combofix.txt
                              0
                              • 1
                              • 2