Malware très embêtant, du style Baggle

Résolu
Bonjour,
J'ai eu un gros problème jeudi soir, après avoir accidentellement rencontrer le chemin d'un faux crack, Windows c'est eteind et il rédemarrait sans cesse. Le lendemain un ami m'a prêter son CD d'installation de Windows XP (c'est mon OS) puis j'ai réparer mon Windows.

J'ai réussi a chasser le trojan "RelevantKnowledge" mais j'ai toujours des problèmes, je ne peux pas accéder a tout les dossiers et périphériques en double-cliquant, il faut que j'aille sur explorer sinon j'ai des erreurs "RECYCLER/...".

Autrement mon ordinateur est lent, mon navigateur bug pas mal, j'ai des tâches suspectes genre "364215.exe" (le numero change tout le temps) et je n'ai pas de mode sans échec, ça ne fonctionne pas.

J'ai voulu installer un anti-virus: Application win32 non valide.

J'ai déjà essayer Combofix et 2 autres mais je ne peux pas les lancer même en les renommant avant le download..

Je ne souhaite pas vraiment formater, donc si vous avez une autre solution,

Merci à vous, Amicalement.
Configuration: Windows XP
Firefox 3.0.7

45 réponses

Résumé de la discussion

Problème majeur: après une infection par un faux crack, Windows XP se réinitialise sans cesse et un malware Trojan nommé RelevantKnowledge circule, rendant l’accès aux dossiers et périphériques via l’Explorateur difficile. Plusieurs solutions de nettoyage et de décontamination ont été proposées, notamment SmitfraudFix, SDFix et ToolsCleaner, avec des redémarrages et l’exécution en mode sans échec puis la restitution des rapports. En cas d’échec des outils, la réinstallation de Windows a été recommandée comme solution durable, avec vigilance accrue et recours à un antivirus fiable et des pratiques de sécurité renforcées. Une nuance utile indique que les outils seuls ne suffisent pas et qu’un rétablissement stable passe par une réinstallation, une utilisation prudente des téléchargements et une surveillance continue.

Bobot (l’IA à votre service)
  1. Je sais que c'est très embêtant pour toi, mais, il faut formater tout. Car c'est le seul moyen le plus sûr, sans risque, et facile.
    Car ça m'est déjà arrivé la même chose, sauf que le vilain cheval de Troie qui s'est installé dans mon ordinateur, m'a désinstallé avast!, google Chrome, a bloqué mon parefeu, et supprimé toutes les mises à jour.

    Information : Le cheval de Troie = Win32MalwareGen
    0
    1. Après avoir bien réfléchis, je me suis décider à réinstaller windows.
      Et plus aucuns problèmes, ils sont tous résolus !

      Je vous remercie de votre aide, surtout Chiquitine29 !

      Cordialement,
      -1
      1. Contributeur sécurité
        je me suis décider à réinstaller windows

        Ca fait pas de mal de temps en temps ^^

        Bonne continuation et sois vigilant.

        https://sebsauvage.net/safehex.html

        Bye.
        0
    2. D'accord,

      Voila,

      info.txt logfile of random's system information tool 1.06 2009-04-05 12:29:48

      ======Uninstall list======

      -->MsiExec.exe /X{E9F81423-211E-46B6-9AE0-38568BC5CF6F}
      -->C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
      -->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      µTorrent 1.6.1 (Build 490)-->C:\Program Files\utorrent\Uninstal.exe
      7-Zip 4.57-->"C:\Program Files\7-Zip\Uninstall.exe"
      Adobe Flash Player ActiveX-->C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
      Adobe Flash Player Plugin-->C:\WINDOWS\System32\Macromed\Flash\uninstall_plugin.exe
      Adobe Reader 8.1.0 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A81000000003}
      Adobe Shockwave Player-->C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Avanquest update-->C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe -runfromtemp -l0x0009 -removeonly
      CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
      CLEO v3.0.950-->"C:\Program Files\Rockstar Games\GTA San Andreas\unins000.exe"
      Codeur Windows Media Série 9-->msiexec.exe /I {E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
      Codeur Windows Media Série 9-->MsiExec.exe /I{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}
      Counter-Strike: Source-->MsiExec.exe /I{9580813D-94B1-4C28-9426-A441E2BB29A5}
      CSO-DAX Compressor V0.38-->C:\Program Files\CSO-DAX Compressor\Uninstal.exe
      DAEMON Tools-->MsiExec.exe /I{3DED3A72-61A8-4B87-98A5-EF0BC8038AA0}
      DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
      DivX Converter-->C:\Program Files\DivX\ConverterUninstall.exe /CONVERTER
      DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
      DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
      DkZ Studio-->MsiExec.exe /I{F656DC79-013A-4683-8692-B938FC00B941}
      Easy2Sync for Files-->C:\PROGRA~1\EASY2S~1\UNWISE.EXE C:\PROGRA~1\EASY2S~1\INSTALL.LOG
      eMule-->"C:\Program Files\eMule\Uninstall.exe"
      Far Manager v1.70-->C:\Program Files\Far\uninstall.exe
      FreeUndelete-->C:\Program Files\FreeUndelete\GLF7B0.exe /handle:fru
      FTP Expert 3-->"C:\Program Files\Visicom Media\FTP Expert 3\uninst-ftp.exe"
      Game Graphic Studio-->MsiExec.exe /I{0A36AAD3-461C-4F21-B695-0754AEEC0B1B}
      GameSpy Arcade-->C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
      Ghost Navigator-->MsiExec.exe /I{93439603-0E8D-434C-B90C-013EDE863ABF}
      GIMP 2.6.4-->"C:\Program Files\GIMP-2.0\setup\unins000.exe"
      Google Earth Pro-->MsiExec.exe /X{9578C0CD-8108-4379-9026-4601F59859A0}
      Google Earth-->MsiExec.exe /I{1E04F83B-2AB9-4301-9EF7-E86307F79C72}
      Google Toolbar for Firefox-->MsiExec.exe /X{2CCBABCB-6427-4A55-B091-49864623C43F}
      GTA San Andreas-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\setup.exe" -l0x40c -removeonly
      GTAIII-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{92B94569-6683-4617-8C54-EB27A1B51B30}\Setup.exe" -l0x40c
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      Hijackthis Version Française 1.99.0.1-->"C:\Program Files\Hijackthis Version Française\unins000.exe"
      ImageMagick 6.4.9-2 Q16 (2009-02-01)-->"C:\Program Files\ImageMagick-6.4.9-Q16\unins000.exe"
      Indeo® Software-->C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Ligos\Indeo\Uninst.isu" -c"C:\Program Files\Ligos\Indeo\Indeo System Files\indounin.dll"
      J2SE Runtime Environment 5.0 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150030}
      JAP-->C:\Program Files\JAP\uninstall.exe
      Java(TM) 6 Update 12-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF}
      Java(TM) 6 Update 3-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030}
      Java(TM) 6 Update 5-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050}
      Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
      Kamzy FTP 2.6.0-->"C:\Program Files\Kamzy FTP\unins000.exe"
      Kaspersky Internet Security 2009-->MsiExec.exe /I{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}
      Kaspersky Internet Security 2009-->MsiExec.exe /I{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}
      KC Softwares VideoInspector-->"C:\Program Files\KC Softwares\VideoInspector\unins000.exe"
      K-Lite Codec Pack 4.4.5 (Full)-->"C:\Program Files\K-Lite Codec Pack\unins001.exe"
      Lecteur Windows Media 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      Lexmark 2200 Series-->C:\WINDOWS\System32\spool\drivers\w32x86\3\LXBVUN5C.EXE -dLexmark 2200 Series
      LimeWire PRO 4.12.6-->"C:\Program Files\LimeWire\uninstall.exe"
      Logiciel QuickCam de Logitech-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C43048A9-742C-4DAD-90D2-E3B53C9DB825}\setup.exe" -l0x40c
      Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
      Microsoft Office PowerPoint Viewer 2003-->MsiExec.exe /X{90AF040C-6000-11D3-8CFE-0150048383C9}
      Microsoft Windows Media Video 9 VCM-->RunDll32 advpack.dll,LaunchINFSection C:\windows\INF\wmv9vcm.inf, Uninstall
      Microsoft Xbox 360 Accessories 1.1-->MsiExec.exe /X{7ACDE995-61E8-41C6-86AD-86579F26A200}
      MIDI Tracker-->C:\Program Files\MIDITracker\MIDITracker.exe /uninstall
      MIKSOFT Mobile 3GP converter-->"C:\Program Files\MIKSOFT\Mobile 3GP converter\unins000.exe"
      mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
      Monopoly-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{D7E7EC5E-4349-4E40-B37C-4342188B86EC}\setup.exe" -l0x40c
      MotoGP URT 3-->"C:\Program Files\THQ\MotoGP URT 3\unins000.exe"
      Mozilla Firefox (3.0.8)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      MP3 Player Utilities 3.79-->MsiExec.exe /I{7784A172-61F1-445E-8368-601607E0DD22}
      MTA:SA DM Developer Preview 2.3-->C:\Program Files\MTA San Andreas\Uninstall.exe
      MTA:SA Race 1.1.2-->C:\Program Files\MTA San Andreas\Uninstall.exe
      Multimediafeed 3GP Mobile Video Converter 1.0-->"C:\Program Files\Multimediafeed 3GP Mobile Video Converter\unins000.exe"
      My Pictures And Sounds 8.01-->C:\Program Files\SAGEM\My Pictures And Sounds\Uninstall.exe
      My Sagem Video Encoder 1.01-->C:\Program Files\SAGEM\My Sagem Video Encoder\Uninstall.exe
      MyPhoneExplorer-->C:\Program Files\MyPhoneExplorer\uninstall.exe
      NeoTrace Express 3.25-->C:\PROGRA~1\NEOTRA~1\UNWISE.EXE C:\PROGRA~1\NEOTRA~1\INSTALL.LOG
      Nokia Connectivity Cable Driver-->RUNDLL32.EXE nsesetup.dll,DoNTUninst
      NVIDIA Drivers-->C:\WINDOWS\System32\nvudisp.exe UninstallGUI
      PC Inspector File Recovery-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0DD140D3-9563-481E-AA75-BA457CBDAEF2}\Setup.exe" -l0x40c
      PhotoFiltre-->"C:\Program Files\PhotoFiltre\Uninst.exe"
      Programme de gestion Camera de Logitech®-->"C:\Program Files\Fichiers communs\Logitech\QCDRV\BIN\SETUP.EXE" UNINSTALL REMOVEPROMPT
      QQ Live Player-->"C:\Program Files\Tencent\QQLivePlayer\uninst.exe"
      Qtracker-->C:\PROGRA~1\Qtracker\UNWISE.EXE C:\PROGRA~1\Qtracker\INSTALL.LOG
      Quake III Arena Point Release 1.32-->C:\WINDOWS\unvise32.exe C:\Program Files\Quake III Arena\uninstal5.log
      RealPlayer-->C:\Program Files\Fichiers communs\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0
      Realtek AC'97 Audio-->Alcrmv.exe -r -m
      SAGEM Full USB v3.5.3.0 (WHQL)-->"C:\Program Files\SAGEM\FullUSB\Drivers\uninstall.exe" /ID=FullUSB_x86
      San Andreas Mod Installer-->"C:\WINDOWS\San Andreas Mod Installer\uninstall.exe" "/U:C:\Program Files\San Andreas Mod Installer\Uninstall\uninstall.xml"
      SFR - Kit de connexion-->C:\Program Files\SFR\Kit\uninstall.exe
      Simulateur de conduite 3D-->"C:\program files\Simulateur de conduite 3D\uninstall.exe"
      SIW version 2008-12-16-->"C:\Program Files\SIW\unins000.exe"
      Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
      SmartBarre version 1.2.0.2 AntiPop v1.2-->"C:\Program Files\BarreDeSurf\unins000.exe"
      SoftPepper Video Converter 2.0-->C:\Program Files\SoftPepper Video Converter 2.0\uninst.exe
      Sony Ericsson PC Suite 3.209.00-->C:\Program Files\InstallShield Installation Information\{2FFE93F0-BB72-4E52-8761-354D1AAA9387}\Setup.exe -runfromtemp -l0x040c -removeonly
      SopCast 2.0.4-->C:\Program Files\SopCast\uninst.exe
      StarOffice 8-->MsiExec.exe /I{4BC1CB2B-FDCE-4DB4-A557-BA8127569B0D}
      Steam(TM)-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
      TeamSpeak 2 RC2-->"C:\Program Files\Teamspeak2_RC2\unins000.exe"
      Todae - Live Media-->C:\Program Files\Windows Media Player\Plugins\Todae\RMP\uninstall_fr.exe
      TVAnts 1.0-->C:\PROGRA~1\TvAnts\UNWISE.EXE C:\PROGRA~1\TvAnts\INSTALL.LOG
      UltraISO 8.0 Premium Edition-->"C:\Program Files\UltraISO\unins000.exe"
      VDownloader 0.77-->"C:\Program Files\VDOWNLOADER\unins000.exe"
      VirtualDub 1.6.9 Fr-->C:\Program Files\VirtualDub\UnInstall_VirtualDub.exe
      VLC media player 0.9.8a-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      WinAVI FLV Converter-->"C:\Program Files\WinAVI FLV Converter\unins000.exe"
      WinAVI Video Converter 8.0-->"C:\Program Files\WinAVI Video Converter\unins000.exe"
      Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
      Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Player 9 Series Power Toy - Ratings Migration-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\powertoy.inf,Uninstall
      Windows Media Player 9 Series TweakMP PowerToy-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\tweakmp.inf,DefaultUninstall
      WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall

      ======Hosts File======

      127.0.0.1 localhost

      ======Security center information======

      AV: Kaspersky Internet Security
      AV: ESET NOD32 antivirus system 2.70 (outdated)
      FW: Kaspersky Internet Security

      ======System event log======

      Computer Name: LUZET
      Event Code: 10
      Message: Ce lecteur ne semble pas prendre en charge la lecture audio numérique.

      Record Number: 5
      Source Name: redbook
      Time Written: 20090320194937.000000+060
      Event Type: Informations
      User:

      Computer Name: LUZET
      Event Code: 10
      Message: Ce lecteur ne semble pas prendre en charge la lecture audio numérique.

      Record Number: 4
      Source Name: redbook
      Time Written: 20090320194937.000000+060
      Event Type: Informations
      User:

      Computer Name: LUZET
      Event Code: 1006
      Message: Votre ordinateur n'a pas pu configurer automatiquement les paramètres IP pour
      la carte avec l'adresse réseau 00110941980B. Il s'est produit l'erreur suivante
      pendant la configuration : Paramètre incorrect.
      .

      Record Number: 3
      Source Name: Dhcp
      Time Written: 20090320194936.000000+060
      Event Type: Avertissement
      User:

      Computer Name: LUZET
      Event Code: 6005
      Message: Le service d'Enregistrement d'événement a démarré.

      Record Number: 2
      Source Name: EventLog
      Time Written: 20090320194930.000000+060
      Event Type: Informations
      User:

      Computer Name: LUZET
      Event Code: 6009
      Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 1 Uniprocessor Free.

      Record Number: 1
      Source Name: EventLog
      Time Written: 20090320194930.000000+060
      Event Type: Informations
      User:

      =====Application event log=====

      Computer Name: LUZET
      Event Code: 11931
      Message: Product: Ghost Navigator -- Info 1931. Le service Windows Installer ne peut pas mettre à jour le fichier système C:\WINDOWS\System32\shlwapi.dll car le fichier est protégé par Windows. Vous devrez peut-être mettre à jour votre système d'exploitation pour que le programme fonctionne correctement. Version : 6.0.2900.2180, Version protégée du système d'exploitation : 6.0.2800.1106

      Record Number: 10746
      Source Name: MsiInstaller
      Time Written: 20090226215748.000000+060
      Event Type: erreur
      User: LUZET\Thomas

      Computer Name: LUZET
      Event Code: 11931
      Message: Product: Ghost Navigator -- Error 1931. Le service Windows Installer ne peut pas mettre à jour le fichier système C:\WINDOWS\System32\mshtml.tlb car le fichier est protégé par Windows. Vous devrez peut-être mettre à jour votre système d'exploitation pour que le programme fonctionne correctement. Version : 6.0.2900.2180, Version protégée du système d'exploitation : 6.0.2800.1106

      Record Number: 10745
      Source Name: MsiInstaller
      Time Written: 20090226215748.000000+060
      Event Type: erreur
      User: LUZET\Thomas

      Computer Name: LUZET
      Event Code: 11708
      Message: Product: Ghost Navigator -- Installation operation failed.

      Record Number: 10744
      Source Name: MsiInstaller
      Time Written: 20090226215633.000000+060
      Event Type: Informations
      User: LUZET\Thomas

      Computer Name: LUZET
      Event Code: 11305
      Message: Product: Ghost Navigator -- Error 1305. Error reading from file: C:\DOCUME~1\THOMAS\LOCALS~1\TEMP\RAR$EX00.172\GHOST.MSI. Verify that the file exists and that you can access it.

      Record Number: 10743
      Source Name: MsiInstaller
      Time Written: 20090226215633.000000+060
      Event Type: erreur
      User: LUZET\Thomas

      Computer Name: LUZET
      Event Code: 1000
      Message: Application défaillante gta_sa.exe, version 0.0.0.0, module défaillant gta_sa.exe, version 0.0.0.0, adresse de défaillance 0x003f0bf7.

      Record Number: 10742
      Source Name: Application Error
      Time Written: 20090226215250.000000+060
      Event Type: erreur
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\system32\WBEM;c:\program files\imagemagick-6.4.9-q16;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
      "windir"=%SystemRoot%
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 10 Stepping 0, AuthenticAMD
      "PROCESSOR_REVISION"=0a00
      "NUMBER_OF_PROCESSORS"=1
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "FP_NO_HOST_CHECK"=NO

      -----------------EOF-----------------

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Thomas at 2009-04-05 12:29:27
      Microsoft Windows XP Édition familiale Service Pack 2
      System drive C: has 31 GB (27%) free of 114 GB
      Total RAM: 767 MB (43% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:29:42, on 05/04/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\netdde.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\MSN Messenger\msnmsgr.exe
      C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\WINDOWS\system32\slserv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      C:\Program Files\Sun\StarOffice 8\program\soffice.exe
      C:\Program Files\Sun\StarOffice 8\program\soffice.BIN
      C:\Program Files\MSN Messenger\livecall.exe
      C:\Program Files\MSN Messenger\usnsvc.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\Thomas\Mes documents\RSIT.exe
      C:\Program Files\trend micro\Thomas.exe

      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:8088
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: WinAVI FLVSense - {E8DF67A1-B618-4F3F-9E7C-CBE175ADEF5B} - C:\Program Files\WinAVI FLV Converter\FLVTune.dll
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
      O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" /systray /nologon
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
      O4 - Startup: StarOffice 8.lnk = C:\Program Files\Sun\StarOffice 8\program\quickstart.exe
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O8 - Extra context menu item: &Download FLV by WinAVI... - C:\Program Files\WinAVI FLV Converter\flv_link.htm
      O8 - Extra context menu item: &NeoTrace It! - C:\PROGRA~1\NEOTRA~1\NTXcontext.htm
      O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 3.79\AMVConverter\grab.html
      O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
      O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 3.79\MediaManager\grab.html
      O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\SCIEPlgn.dll
      O9 - Extra button: WinAVI FLV Manager - {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - C:\Program Files\WinAVI FLV Converter\FLVTune.dll
      O9 - Extra 'Tools' menuitem: WinAVI FLV Manager - {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - C:\Program Files\WinAVI FLV Converter\FLVTune.dll
      O9 - Extra button: Ghost Navigator - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Ghost Navigator\Ghost (file missing)
      O9 - Extra 'Tools' menuitem: Ghost Navigator - {ECC5777A-6E88-BFCE-13CE-81F134789E7B} - C:\Program Files\Ghost Navigator\Ghost (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra button: NeoTrace It! - {9885224C-1217-4c5f-83C2-00002E6CEF2B} - C:\PROGRA~1\NEOTRA~1\NTXtoolbar.htm (HKCU)
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~2\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~2\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~2\kloehk.dll
      O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
      O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
      O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Smart Link - (no file)
      -1
      1. Non, je n'ai pas de messages d'erreur, juste le son, rien ne s'ouvre.

        RSIT, oui j'ai reussi pas de probleme.
        -1
        1. Contributeur sécurité
          RSIT, oui j'ai reussi pas de probleme.

          Et bien, poste les 2 rapports.

          (Je ne suis pas certain de pouvoir te conseiller par la suite, donc sois patient avant de faire un "up", merci)

          @+
          0
      2. Merci,

        system.ini:

        File size: 326 bytes
        MD5...: c91f93744826bdf8945c887b16371308
        SHA1..: 6d8ab55150ee579af30483f1ffcd537dfd5af7bb
        SHA256: 5a1b4337e6645ad33dc94b3a354d22d88cea7545dd2ab80eeb8c6ad1da50e999
        SHA512: 44aeea6639c76deb845880745a9641a2bac3566d1b2e14021c804296029fe5f3
        854eaee8e6efee835f5c5781af0f79e36fe6fb4e16944ccdfb3ffe8a60b26453
        ssdeep: 6:aQ44VvYbie0xTHFlMsqQPMK+H5/hqQS2gV4voVnOfH9YfxCmfjN:F4YvYwHLMZ
        u+H6QS2g+j/CkC
        PEiD..: -
        TrID..: File type identification
        Unknown!
        PEInfo: -
        RDS...: NSRL Reference Data Set

        Pour le CD de Windows oui je l'ai.

        En ce moment je ne peux pas executer tout les fichiers installeur.

        Je ne peux pas accéder à la configuration par défaut des programmes ni ajouter/supprimer des programmes, il y a un son d'erreur.

        Dans connexion réseau, je ne peux pas accéder aux propriétés de ma connexion au réseau local.
        L'icone connexion internet n'apparait plus. Ma connexion s'en trouve limitée (j'ai vérifié ça avec les low ID avec la mule, ou meme µtorrent).

        J'ai remarqué aussi que le dernier numero de mon adresse IP change souvent, pas les 3 premiers.
        J'avais pourtant supprimé un certain detournement de DNS avec Smitfraudfix mais je crois qu'il y a encore un problème avec ça.
        -1
        1. Contributeur sécurité
          A défaut d'aide concrète, je te passe un peu de lecture.


          Je ne peux pas accéder à la configuration par défaut des programmes ni ajouter/supprimer des programmes, il y a un son d'erreur.


          Pas de messages Windows?

          Tu peux exécuter Rsit?
          0
      3. Contributeur sécurité
        Hello,

        Chiquitine est pas mal occupé, (si je ne m'abuse).

        Eventuellement pour lui faire gagner du temps:

        - Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

        - Double-clique sur RSIT.exe afin de lancer le programme.

        - Clique sur Continue à l'écran Disclaimer.

        - Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

        NB : Les rapports sont sauvegardés dans le dossier C:\rsit.

        Refais ce qu'il te demande dans le message N° 31.


        Pour info: As tu ton cd original de Windows?

        Décris avec le maximum de précision tes "symptômes" actuels.

        Il faut savoir que chaque bénévole du forum a une vie privée...
        Essaye de ne pas faire de "up" trop fréquemment (environ toutes les 48h c'est bien suffisant).

        @+
        -1
        1. J'ai vraiment besoin d'aide svp.
          -1
          1. Bonjour,

            J'ai de nouveaux des problèmes,
            Désormais je ne peux pas gérer ma connection, je m'explique
            Ma connection Reseau Local dans Connexions Reseau s'affiche mais je ne peux rien faire ...
            Je ne peux ni utiliser Ajouter/Supprimer des Programmes et Configurer les programmes par defaut non plus.
            Merci.
            -1
            1. Contributeur sécurité
              Up.
              0
          2. Bonjour,

            Est-ce qu'il reste a faire quelque chose pour finaliser le travail déjà entamé ?
            -1
            1. J'ai pas pu lancer malwarebytes tout a l'heure, tu m'as dit on va faire autrement.
              En tout cas mon PC a l'air d'etre bien,plu de pubs, plu de ralentissements...
              Vu l'heure, je pense que si ça te dérange pas on met ça de coter, tu m'as déjà très bien aider, je sais pas ce que j'aurai fait sans toi je te remercie beaucoup !
              -1
              1. désolé , ton rapport est complet ,

                tu veux bien réinstaller malewarebytes et scanner , puis poster le rapport stp
                -1
                1. g besoin du rapport complet ..
                  -1
                  1. Antivirus Version Dernière mise à jour Résultat

                    a-squared 4.0.0.101 2009.03.25 -
                    AhnLab-V3 5.0.0.2 2009.03.25 -
                    AntiVir 7.9.0.126 2009.03.25 -
                    Antiy-AVL 2.0.3.1 2009.03.25 -
                    Authentium 5.1.2.4 2009.03.25 -
                    Avast 4.8.1335.0 2009.03.25 -
                    AVG 8.5.0.283 2009.03.25 -
                    BitDefender 7.2 2009.03.25 -
                    CAT-QuickHeal 10.00 2009.03.25 -
                    ClamAV 0.94.1 2009.03.25 -
                    Comodo 1084 2009.03.25 -
                    DrWeb 4.44.0.09170 2009.03.25 -
                    eSafe 7.0.17.0 2009.03.25 -
                    eTrust-Vet 31.6.6417 2009.03.25 -
                    F-Prot 4.4.4.56 2009.03.25 -
                    F-Secure 8.0.14470.0 2009.03.25 -
                    Fortinet 3.117.0.0 2009.03.25 -
                    GData 19 2009.03.25 -
                    Ikarus T3.1.1.48.0 2009.03.25 -
                    K7AntiVirus 7.10.680 2009.03.24 -
                    Kaspersky 7.0.0.125 2009.03.25 -
                    McAfee 5564 2009.03.25 -
                    McAfee+Artemis 5564 2009.03.25 -
                    McAfee-GW-Edition 6.7.6 2009.03.25 -
                    Microsoft 1.4502 2009.03.25 -
                    NOD32 3963 2009.03.25 -
                    Norman 6.00.06 2009.03.25 -
                    nProtect 2009.1.8.0 2009.03.25 -
                    Panda 10.0.0.10 2009.03.25 -
                    PCTools 4.4.2.0 2009.03.25 -
                    Prevx1 V2 2009.03.25 -
                    Rising 21.22.21.00 2009.03.25 -
                    Sophos 4.39.0 2009.03.25 -
                    Sunbelt 3.2.1858.2 2009.03.25 -
                    Symantec 1.4.4.12 2009.03.25 -
                    TheHacker 6.3.3.6.291 2009.03.25 -
                    TrendMicro 8.700.0.1004 2009.03.25 -
                    VBA32 3.12.10.1 2009.03.24 -
                    ViRobot 2009.3.25.1663 2009.03.25 -
                    VirusBuster 4.6.5.0 2009.03.25 -

                    Information additionnelle

                    File size: 326 bytes
                    MD5...: c91f93744826bdf8945c887b16371308
                    SHA1..: 6d8ab55150ee579af30483f1ffcd537dfd5af7bb
                    SHA256: 5a1b4337e6645ad33dc94b3a354d22d88cea7545dd2ab80eeb8c6ad1da50e999
                    SHA512: 44aeea6639c76deb845880745a9641a2bac3566d1b2e14021c804296029fe5f3
                    854eaee8e6efee835f5c5781af0f79e36fe6fb4e16944ccdfb3ffe8a60b26453
                    ssdeep: 6:aQ44VvYbie0xTHFlMsqQPMK+H5/hqQS2gV4voVnOfH9YfxCmfjN:F4YvYwHLMZ
                    u+H6QS2g+j/CkC
                    PEiD..: -
                    TrID..: File type identification
                    Unknown!
                    PEInfo: -
                    RDS...: NSRL Reference Data Set
                    -
                    -1
                    1. Rends toi sur ce site :

                      https://www.virustotal.com/gui/

                      Clique sur parcourir et cherche ce fichier : c:\windows\system.ini

                      Clique sur Send File.

                      Un rapport va s'élaborer ligne à ligne.

                      Attends la fin. Il doit comprendre la taille du fichier envoyé.

                      Sauvegarde le rapport avec le bloc-note.

                      Copie le dans ta réponse.
                      -1
                      1. Voila,

                        ComboFix 09-03-23.01 - Thomas 2009-03-25 22:35:08.1 - NTFSx86
                        Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.767.578 [GMT 1:00]
                        Lancé depuis: c:\documents and settings\Thomas\Mes documents\ComboFix.exe
                        .

                        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                        .

                        c:\documents and settings\Thomas\Thomas.exe
                        c:\recycler\S-4-3-29-100032439-100013389-100006072-6216.com
                        c:\windows\system32\404Fix.exe
                        c:\windows\system32\Agent.OMZ.Fix.exe
                        c:\windows\system32\drivers\gaopdxbfalkrviqxumexmkpyvibnetirsbpfmq.sys
                        c:\windows\system32\drivers\gaopdxcbvxvkosiecuhlnnlsbsiemurwbfpdfq.sys
                        c:\windows\system32\drivers\gaopdxfibtsufvjnaakrmfxeoommfqlsqaavos.sys
                        c:\windows\system32\drivers\gaopdxkntlvvrjnckndmkjfgpsdmmbbufwbmil.sys
                        c:\windows\system32\drivers\gaopdxsmbivamrqhesiswbeavxepxurubwxlvd.sys
                        c:\windows\system32\drivers\gaopdxxujruyfqadpakcxbitqlvfbwuiqxfmvv.sys
                        c:\windows\system32\dumphive.exe
                        c:\windows\system32\gaopdxcounter
                        c:\windows\system32\gaopdxfwkvebwlwoikprrmthyqxqquyiyvgovx.dll
                        c:\windows\system32\gaopdxxnqxheycpyrevfassyarioexnqwmqppt.dll
                        c:\windows\system32\IEDFix.C.exe
                        c:\windows\system32\IEDFix.exe
                        c:\windows\system32\o4Patch.exe
                        c:\windows\system32\Process.exe
                        c:\windows\system32\SrchSTS.exe
                        c:\windows\system32\tmp.reg
                        c:\windows\system32\VACFix.exe
                        c:\windows\system32\VCCLSID.exe
                        c:\windows\system32\WS2Fix.exe

                        .
                        ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                        .

                        -------\Service_gaopdxserv.sys

                        ((((((((((((((((((((((((((((( Fichiers créés du 2009-02-25 au 2009-03-25 ))))))))))))))))))))))))))))))))))))
                        .

                        2009-03-25 21:44 . 2009-03-25 22:12 <REP> d-------- C:\SDFix
                        2009-03-25 20:49 . 2009-03-25 20:49 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                        2009-03-25 20:49 . 2009-03-25 20:49 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                        2009-03-25 20:49 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                        2009-03-25 20:49 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                        2009-03-25 20:48 . 2009-03-25 20:49 2,876,720 --a------ C:\mbam-setup.exe
                        2009-03-25 19:51 . 2009-03-25 21:42 <REP> d-------- c:\program files\trend micro
                        2009-03-24 18:27 . 2009-03-24 18:27 <REP> d-------- c:\documents and settings\Thomas\Application Data\ImTOO Software Studio
                        2009-03-22 12:35 . 2009-03-22 12:35 157 --a------ c:\windows\system32\temp_0000_85-19.aok
                        2009-03-22 11:43 . 2009-03-22 20:08 200 --a------ c:\windows\system32\test.aok
                        2009-03-22 11:40 . 2009-03-22 11:41 <REP> d-------- c:\program files\Ultra Mobile 3GP Video Converter
                        2009-03-22 11:40 . 2002-10-05 07:04 921,600 --a------ c:\windows\system32\vorbisenc.dll
                        2009-03-22 11:40 . 2004-01-11 08:02 258,048 --a------ c:\windows\system32\GplMpgDec.ax
                        2009-03-22 11:40 . 2002-10-07 02:42 237,568 --a------ c:\windows\system32\OggDS.dll
                        2009-03-22 11:40 . 2002-10-05 07:04 188,416 --a------ c:\windows\system32\vorbis.dll
                        2009-03-22 11:40 . 2007-04-12 14:19 129,024 --a------ c:\windows\system32\AVERM.dll
                        2009-03-22 11:40 . 2002-10-05 07:04 45,056 --a------ c:\windows\system32\ogg.dll
                        2009-03-22 11:40 . 2006-09-26 13:57 28,672 --a------ c:\windows\system32\AVEQT.dll
                        2009-03-20 23:01 . 2009-03-20 23:03 1,896 --a------ c:\windows\BricoPackFoldersDelete.cmd
                        2009-03-20 20:34 . 2004-08-05 13:00 131,584 --a--c--- c:\windows\system32\dllcache\pmxviceo.dll
                        2009-03-20 20:33 . 2004-08-05 13:00 563,712 --a--c--- c:\windows\system32\dllcache\fxsst.dll
                        2009-03-20 20:32 . 2004-05-13 00:39 876,653 --a--c--- c:\windows\system32\dllcache\fp4awel.dll
                        2009-03-20 20:28 . 2009-03-20 20:28 488 -rah----- c:\windows\system32\logonui.exe.manifest
                        2009-03-20 20:27 . 2009-03-20 20:27 749 -rah----- c:\windows\WindowsShell.Manifest
                        2009-03-20 20:27 . 2009-03-20 20:27 749 -rah----- c:\windows\system32\wuaucpl.cpl.manifest
                        2009-03-20 20:27 . 2009-03-20 20:27 749 -rah----- c:\windows\system32\sapi.cpl.manifest
                        2009-03-20 20:27 . 2009-03-20 20:27 749 -rah----- c:\windows\system32\ncpa.cpl.manifest
                        2009-03-20 20:18 . 2001-08-17 20:13 27,165 --a------ c:\windows\system32\drivers\fetnd5.sys
                        2009-03-20 20:07 . 2004-08-05 13:00 1,897,552 --a--c--- c:\windows\system32\dllcache\NT5.CAT
                        2009-03-20 19:32 . 2009-03-20 19:32 <REP> d-------- c:\windows\Provisioning
                        2009-03-20 19:32 . 2009-03-20 21:04 <REP> d-------- c:\windows\PeerNet
                        2009-03-20 18:55 . 2001-08-17 21:57 16,128 --a------ c:\windows\system32\drivers\MODEMCSA.sys
                        2009-03-20 18:53 . 2004-08-03 22:41 1,309,184 --a------ c:\windows\system32\drivers\mtlstrm.sys
                        2009-03-20 18:53 . 2004-08-03 22:41 404,990 --a------ c:\windows\system32\drivers\slntamr.sys
                        2009-03-20 18:53 . 2004-08-04 00:54 286,792 --a------ c:\windows\system32\slextspk.dll
                        2009-03-20 18:53 . 2004-08-04 00:54 188,508 --a------ c:\windows\system32\SLGen.dll
                        2009-03-20 18:53 . 2004-08-03 22:41 180,360 --a------ c:\windows\system32\drivers\ntmtlfax.sys
                        2009-03-20 18:53 . 2004-08-03 22:41 126,686 --a------ c:\windows\system32\drivers\mtlmnt5.sys
                        2009-03-20 18:53 . 2004-08-03 22:41 95,424 --a------ c:\windows\system32\drivers\slnthal.sys
                        2009-03-20 18:53 . 2004-08-04 00:54 73,832 --a------ c:\windows\system32\slcoinst.dll
                        2009-03-20 18:53 . 2004-08-04 00:55 73,796 --a------ c:\windows\system32\slserv.exe
                        2009-03-20 18:53 . 2004-08-04 00:55 32,866 --a------ c:\windows\system32\slrundll.exe
                        2009-03-20 18:53 . 2004-08-03 22:41 13,776 --a------ c:\windows\system32\drivers\RecAgent.sys
                        2009-03-20 18:53 . 2004-08-03 22:41 13,240 --a------ c:\windows\system32\drivers\slwdmsup.sys
                        2009-03-20 18:43 . 2004-08-05 13:00 79,360 --a------ c:\windows\system32\winar30.ime
                        2009-03-20 18:43 . 2004-08-05 13:00 79,360 --a--c--- c:\windows\system32\dllcache\winar30.ime
                        2009-03-20 18:43 . 2004-08-05 13:00 77,824 --a------ c:\windows\system32\quick.ime
                        2009-03-20 18:43 . 2004-08-05 13:00 77,824 --a--c--- c:\windows\system32\dllcache\quick.ime
                        2009-03-20 18:43 . 2004-08-05 13:00 65,536 --a------ c:\windows\system32\winime.ime
                        2009-03-20 18:43 . 2004-08-05 13:00 65,536 --a--c--- c:\windows\system32\dllcache\winime.ime
                        2009-03-20 18:43 . 2004-08-05 13:00 65,024 --a------ c:\windows\system32\unicdime.ime
                        2009-03-20 18:43 . 2004-08-05 13:00 65,024 --a--c--- c:\windows\system32\dllcache\unicdime.ime
                        2009-03-20 18:43 . 2004-08-05 13:00 15,872 --a--c--- c:\windows\system32\dllcache\padrs404.dll
                        2009-03-20 18:43 . 2004-08-05 13:00 11,776 --a------ c:\windows\system32\miniime.tpl
                        2009-03-20 18:41 . 2004-08-05 13:00 1,086,058 -ra------ c:\windows\SETB4.tmp
                        2009-03-20 18:41 . 2004-08-05 13:00 1,014,836 -ra------ c:\windows\SETB3.tmp
                        2009-03-20 18:41 . 2004-08-05 13:00 14,043 -ra------ c:\windows\SETC0.tmp
                        2009-03-20 18:41 . 2004-08-05 13:00 7,334 --a--c--- c:\windows\system32\dllcache\wmerrenu.cat
                        2009-03-19 19:24 . 2009-03-19 19:24 <REP> d-------- c:\program files\PlayMe
                        2009-03-19 19:24 . 2009-03-19 19:24 163,840 --a------ c:\windows\system32\nvtpm32.dll
                        2009-03-19 19:24 . 2009-03-19 19:24 97,280 --a------ c:\windows\system32\azton.mt
                        2009-03-19 19:24 . 2009-03-19 19:24 64,512 --a------ c:\windows\system32\ewf3.pxf
                        2009-03-19 19:24 . 2009-03-19 19:24 32,768 --a------ c:\windows\system32\fe3.wa
                        2009-03-19 18:41 . 2009-03-19 18:41 <REP> d-------- c:\program files\MIKSOFT
                        2009-03-18 14:02 . 2009-03-18 14:02 <REP> d-------- c:\program files\MIDITracker
                        2009-03-17 22:07 . 2009-03-17 22:07 <REP> d-------- c:\program files\Common Files
                        2009-03-17 22:01 . 2009-03-17 22:02 <REP> d-------- c:\program files\XeroBank
                        2009-03-17 21:12 . 2009-03-17 21:12 <REP> d-------- c:\documents and settings\Thomas\Application Data\Sites prédéfinis
                        2009-03-17 21:11 . 2009-03-17 21:11 <REP> d-------- c:\program files\Visicom Media
                        2009-03-17 21:11 . 2009-03-17 21:12 <REP> d-------- c:\documents and settings\Thomas\Application Data\Dynamique
                        2009-03-17 21:05 . 2009-03-17 21:06 <REP> d-------- c:\program files\Kamzy FTP
                        2009-03-17 21:05 . 2005-04-05 06:51 24,576 --a------ c:\windows\system32\KzLib.dll
                        2009-03-15 11:38 . 2009-03-20 19:15 325,405 --a------ c:\windows\setupapi.old
                        2009-03-13 23:11 . 2009-03-13 23:11 <REP> d-------- c:\program files\KC Softwares
                        2009-03-07 19:38 . 2009-03-07 19:38 0 --ah----- c:\windows\system32\drivers\Msft_Kernel_ggsemc_01005.Wdf
                        2009-03-07 12:24 . 2009-03-07 12:26 <REP> d-------- c:\program files\Simulateur de conduite 3D
                        2009-03-06 20:39 . 2009-03-06 20:44 <REP> d-------- c:\program files\SystemRequirementsLab
                        2009-03-06 20:39 . 2009-03-06 20:39 <REP> d-------- c:\documents and settings\Thomas\Application Data\SystemRequirementsLab
                        2009-03-05 13:27 . 2009-03-05 13:27 <REP> d-------- c:\program files\Teamspeak2_RC2
                        2009-03-01 21:36 . 2009-03-02 00:45 <REP> d-------- c:\program files\Privoxy
                        2009-03-01 21:00 . 2009-03-01 21:02 <REP> d-------- c:\program files\JAP
                        2009-03-01 21:00 . 2007-07-19 18:14 3,727,720 --a------ c:\windows\system32\d3dx9_35.dll
                        2009-03-01 21:00 . 2007-05-16 16:45 3,497,832 --a------ c:\windows\system32\d3dx9_34.dll
                        2009-03-01 21:00 . 2007-03-12 16:42 3,495,784 --a------ c:\windows\system32\d3dx9_33.dll
                        2009-03-01 21:00 . 2007-05-16 16:45 1,124,720 --a------ c:\windows\system32\D3DCompiler_34.dll
                        2009-03-01 21:00 . 2007-03-12 16:42 1,123,696 --a------ c:\windows\system32\D3DCompiler_33.dll
                        2009-03-01 21:00 . 2007-05-16 16:45 443,752 --a------ c:\windows\system32\d3dx10_34.dll
                        2009-03-01 21:00 . 2007-03-15 16:57 443,752 --a------ c:\windows\system32\d3dx10_33.dll
                        2009-03-01 21:00 . 2007-06-20 20:46 266,088 --a------ c:\windows\system32\xactengine2_8.dll
                        2009-03-01 21:00 . 2007-04-04 18:55 261,480 --a------ c:\windows\system32\xactengine2_7.dll
                        2009-03-01 21:00 . 2007-01-24 15:27 255,848 --a------ c:\windows\system32\xactengine2_6.dll
                        2009-03-01 21:00 . 2007-04-04 18:53 81,768 --a------ c:\windows\system32\xinput1_3.dll
                        2009-03-01 21:00 . 2007-10-22 03:37 17,928 --a------ c:\windows\system32\X3DAudio1_2.dll
                        2009-03-01 21:00 . 2007-03-05 12:42 15,128 --a------ c:\windows\system32\x3daudio1_1.dll
                        2009-03-01 20:02 . 2009-03-01 20:02 <REP> d-------- c:\windows\Logs
                        2009-02-26 21:57 . 2009-02-26 21:57 <REP> d-------- c:\program files\Ghost Navigator

                        .
                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2009-03-25 21:18 --------- d-----w c:\documents and settings\Thomas\Application Data\Skype
                        2009-03-25 20:50 --------- d-----w c:\program files\ESET
                        2009-03-25 15:35 --------- d-----w c:\documents and settings\Thomas\Application Data\skypePM
                        2009-03-24 18:16 --------- d-----w c:\documents and settings\Thomas\Application Data\uTorrent
                        2009-03-23 17:24 --------- d-----w c:\documents and settings\Thomas\Application Data\dvdcss
                        2009-03-22 10:05 --------- d-----w c:\program files\eMule
                        2009-03-21 14:37 --------- d-----w c:\program files\RACE 07 Offline
                        2009-03-21 07:36 --------- d-----w c:\program files\Hijackthis Version Française
                        2009-03-20 22:03 47,661 ----a-w c:\windows\BricoPackUninst.cmd
                        2009-03-20 22:03 219,648 ----a-w c:\windows\system32\uxtheme.dll
                        2009-03-20 20:02 410,984 ----a-w c:\windows\system32\deploytk.dll
                        2009-03-20 20:02 --------- d-----w c:\program files\Java
                        2009-03-17 17:54 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
                        2009-03-15 17:15 --------- d-----w c:\program files\TvAnts
                        2009-03-08 16:47 --------- d-----w c:\program files\Rockstar Games
                        2009-03-07 21:52 --------- d-----w c:\documents and settings\Thomas\Application Data\teamspeak2
                        2009-03-06 18:38 --------- d-----w c:\program files\MTA San Andreas
                        2009-03-06 17:20 --------- d--h--w c:\program files\InstallShield Installation Information
                        2009-03-05 12:26 --------- d-----w c:\program files\mIRC
                        2009-03-05 12:26 --------- d-----w c:\documents and settings\Thomas\Application Data\mIRC
                        2009-03-05 08:49 --------- d-----w c:\program files\Electronic Arts
                        2009-02-24 09:15 --------- d-----w c:\program files\Codemasters
                        2009-02-22 23:15 --------- d-----w c:\program files\SIW
                        2009-02-21 19:34 --------- d-----w c:\program files\utorrent
                        2009-02-19 22:34 --------- d-----w c:\program files\CCleaner
                        2009-02-16 16:45 --------- d-----w c:\documents and settings\Thomas\Application Data\Desktopicon
                        2009-02-14 23:50 --------- d-----w c:\documents and settings\Thomas\Application Data\StarOffice8
                        2009-02-09 20:56 --------- d-----w c:\program files\GIMP-2.0
                        2009-02-09 20:51 --------- d-----w c:\documents and settings\Thomas\Application Data\gtk-2.0
                        2009-02-09 20:44 --------- d-----w c:\program files\ImageMagick-6.4.9-Q16
                        2009-02-09 20:38 --------- d-----w c:\program files\PhotoFiltre
                        2009-02-08 18:33 --------- d-----w c:\program files\VDOWNLOADER
                        2009-02-08 15:20 --------- d-----w c:\program files\Avanquest update
                        2009-02-06 06:22 --------- d-----w c:\documents and settings\All Users\Application Data\BVRP Software
                        2009-02-06 06:10 --------- d-----w c:\program files\MSN Messenger
                        2009-02-06 06:10 --------- d-----w c:\program files\Messenger Plus! Live
                        2009-02-05 19:46 --------- d-----w c:\program files\Tencent
                        2009-01-31 23:40 --------- d-----w c:\program files\Globe7
                        2009-01-31 22:14 --------- d-----w c:\documents and settings\Thomas\Application Data\Globe7
                        2009-01-31 21:27 --------- d-----w c:\program files\Skype
                        2009-01-31 21:27 --------- d-----w c:\program files\Fichiers communs\Skype
                        2009-01-31 21:27 --------- d-----w c:\documents and settings\All Users\Application Data\Skype
                        2009-01-27 04:02 481,367 ----a-w C:\JabbaDDOS.exe
                        2007-07-07 13:57 278,528 ----a-w c:\program files\Fichiers communs\FDEUnInstaller.exe
                        1996-07-29 10:11 733,296 ----a-w c:\documents and settings\Thomas\OPENGL32.DLL
                        1996-07-29 10:09 139,712 ----a-w c:\documents and settings\Thomas\GLU32.DLL
                        .

                        ------- Sigcheck -------

                        2004-08-05 13:00 1220096 de43b7f2d8b37ca03f7794bb7f3275f7 c:\windows\system32\wininet.dll
                        2004-08-05 13:00 1220096 de43b7f2d8b37ca03f7794bb7f3275f7 c:\windows\system32\dllcache\wininet.dll

                        2004-08-05 13:00 1884672 90e794c5d2d368686fe71b4a0354462c c:\windows\explorer.exe
                        2004-08-05 13:00 1884672 90e794c5d2d368686fe71b4a0354462c c:\windows\system32\dllcache\explorer.exe
                        .
                        ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                        REGEDIT4

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "msnmsgr"="c:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
                        "Sony Ericsson PC Suite"="c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SEPCSuite.exe" [2008-02-20 360448]
                        "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-07 21633320]
                        "LogitechSoftwareUpdate"="c:\program files\Logitech\Video\ManifestEngine.exe" [2005-06-08 196608]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-05-24 185896]
                        "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-20 148888]
                        "SoundMan"="SOUNDMAN.EXE" [2007-04-16 c:\windows\soundman.exe]

                        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                        "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-05 15360]

                        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                        "tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-05 44544]

                        c:\documents and settings\Thomas\Menu D‚marrer\Programmes\D‚marrage\
                        StarOffice 8.lnk - c:\program files\Sun\StarOffice 8\program\quickstart.exe [2005-06-21 122880]

                        c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                        WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2007-08-29 118784]

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                        "enablefirewall"= 0 (0x0)

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                        "%windir%\\system32\\sessmgr.exe"=
                        "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                        "c:\\Program Files\\MSN Messenger\\livecall.exe"=

                        R0 jklvd;jklvd;c:\windows\system32\drivers\jklvd.sys [2008-12-28 155136]
                        R0 jklvd1;jklvd1;c:\windows\system32\drivers\jklvd1.sys [2008-12-28 5248]
                        R0 sfsync03;StarForce Protection Synchronization Driver (version 3.x);c:\windows\system32\drivers\sfsync03.sys [2005-12-06 35328]
                        R3 Tetris;Tetris driver;c:\windows\system32\drivers\Tetris.sys [2007-07-30 48928]
                        S1 aswSP;avast! Self Protection; [x]
                        S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys --> c:\windows\system32\DRIVERS\aswFsBlk.sys [?]
                        S2 SPF4;Sunbelt Personal Firewall 4; [x]
                        S3 cpuz131;cpuz131;\??\c:\docume~1\Thomas\LOCALS~1\Temp\cpuz131\cpuz_x32.sys --> c:\docume~1\Thomas\LOCALS~1\Temp\cpuz131\cpuz_x32.sys [?]
                        S3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\drivers\ggflt.sys [2008-12-14 13352]
                        S3 PID_0920;Logitech QuickCam Express(PID_0920);c:\windows\system32\drivers\LV532AV.SYS [2007-07-21 163328]
                        S3 UsbSagCom;Mobile Device Full USB Driver;c:\windows\system32\drivers\UsbSagCom.sys [2007-06-29 51712]
                        .
                        - - - - ORPHELINS SUPPRIMES - - - -

                        WebBrowser-{ECDEE021-0D17-467F-A1FF-C7A115230949} - (no file)
                        WebBrowser-{90B8B761-DF2B-48AC-BBE0-BCC03A819B3B} - (no file)

                        .
                        ------- Examen supplémentaire -------
                        .
                        uStart Page = hxxp://www.sfr.fr/kit/adsl/
                        mWindow Title =
                        uInternet Settings,ProxyServer = 127.0.0.1:8088
                        uInternet Settings,ProxyOverride = <local>
                        IE: &Download FLV by WinAVI... - c:\program files\WinAVI FLV Converter\flv_link.htm
                        IE: &NeoTrace It! - c:\progra~1\NEOTRA~1\NTXcontext.htm
                        IE: Add to AMV Convert Tool... - c:\program files\MP3 Player Utilities 3.79\AMVConverter\grab.html
                        IE: MediaManager tool grab multimedia file - c:\program files\MP3 Player Utilities 3.79\MediaManager\grab.html
                        IE: {{ECC5777A-6E88-BFCE-13CE-81F134789E7B} - c:\program files\Ghost Navigator\Ghost
                        IE: {{DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - {EC83A912-7EF4-410D-9CC7-3BDAA709CA71} - c:\program files\WinAVI FLV Converter\FLVTune.dll
                        Trusted Zone: pogo.fr\www
                        Trusted Zone: slutload.com\www
                        FF - ProfilePath - c:\documents and settings\Thomas\Application Data\Mozilla\Firefox\Profiles\orajj9by.default\
                        FF - prefs.js: browser.search.selectedEngine - Live Search
                        FF - prefs.js: browser.startup.homepage - hxxp://google.fr
                        FF - prefs.js: keyword.URL - hxxp://search.live.com/results.aspx?mkt=fr-FR&FORM=MIMWA5&q=
                        FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll

                        ---- PARAMETRES FIREFOX ----
                        FF - user.js: yahoo.homepage.dontask - true.

                        **************************************************************************

                        catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2009-03-25 22:40:13
                        Windows 5.1.2600 Service Pack 2 NTFS

                        Recherche de processus cachés ...

                        Recherche d'éléments en démarrage automatique cachés ...

                        Recherche de fichiers cachés ...

                        c:\windows\system.ini 326 bytes

                        Scan terminé avec succès
                        Fichiers cachés: 1

                        **************************************************************************
                        .
                        --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                        [HKEY_USERS\S-1-5-21-484763869-854245398-725345543-1004\Software\Microsoft\SystemCertificates\AddressBook*]
                        @Allowed: (Read) (RestrictedCode)
                        @Allowed: (Read) (RestrictedCode)

                        [HKEY_USERS\S-1-5-21-484763869-854245398-725345543-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
                        "??"=hex:70,e5,f3,3b,f0,b2,f6,e7,c0,a5,d7,51,78,ef,27,10,27,ae,43,50,56,b1,02,
                        d1,ce,56,13,85,92,0d,09,0c,f3,fe,f2,cf,bb,a5,04,bc,ce,6f,42,8f,e9,da,70,3f,\
                        "??"=hex:d1,57,84,6b,5e,be,68,ba,c4,d6,80,90,25,4b,9b,14

                        [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\WPAEvents]
                        @Denied: (Full) (LocalSystem)
                        "OOBETimer"=hex:ff,d5,71,d6,8b,6a,8d,6f,d5,33,93,fd
                        .
                        Heure de fin: 2009-03-25 22:44:57
                        ComboFix-quarantined-files.txt 2009-03-25 21:44:56

                        Avant-CF: 27,249,377,280 octets libres
                        Après-CF: 27,539,496,960 octets libres

                        WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                        [boot loader]
                        timeout=2
                        default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                        [operating systems]
                        c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                        multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /fastdetect

                        287 --- E O F --- 2007-07-27 15:12:31
                        -1
                        1. Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                          -> Double clique sur combofix.exe.
                          -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                          -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                          NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                          Avant d'utiliser ComboFix :

                          -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                          -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

                          Une fois fait, sur ton bureau double-clic sur Combofix.exe.

                          - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                          /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                          - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                          - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                          -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                          -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
                          -1
                          1. Voila,

                            Toolscleaner:

                            [ Rapport ToolsCleaner version 2.3.2 (par A.Rothstein & dj QUIOU) ]

                            -->- Recherche:

                            C:\SmitFraudFix.exe: trouvé !
                            C:\VundoFix.txt: trouvé !
                            C:\egd.txt: trouvé !
                            C:\Navipromo.txt: trouvé !
                            C:\TB.txt: trouvé !
                            C:\OTMoveIt3.exe: trouvé !
                            C:\SDFIX: trouvé !
                            C:\Vundofix backups: trouvé !
                            C:\_OtMoveIt: trouvé !
                            C:\Toolbar SD: trouvé !
                            C:\Rsit: trouvé !
                            C:\BFU\EGDACCESS.bfu: trouvé !
                            C:\Documents and Settings\Thomas\Bureau\SmitFraudFix.exe: trouvé !
                            C:\Documents and Settings\Thomas\Bureau\ToolBarSD.exe: trouvé !
                            C:\Documents and Settings\Thomas\Bureau\SmitFraudfix: trouvé !
                            C:\Documents and Settings\Thomas\Mes documents\FindyKill: trouvé !
                            C:\Documents and Settings\Thomas\Mes documents\AUTRE\EGDACCESS.bfu: trouvé !
                            C:\Documents and Settings\Thomas\Mes documents\AUTRE\Gmer.zip: trouvé !
                            C:\Documents and Settings\Thomas\Mes documents\AUTRE\Bfu.exe: trouvé !
                            C:\Documents and Settings\Thomas\Mes documents\AUTRE\vundoFix.exe: trouvé !
                            C:\Program Files\Hijackthis Version Française\hijackthis.log: trouvé !
                            C:\Program Files\Mozilla Firefox\SmitFraudfix: trouvé !
                            C:\Program Files\trend micro\HijackThis.exe: trouvé !
                            C:\Program Files\trend micro\hijackthis.log: trouvé !

                            ---------------------------------
                            -->- Suppression:

                            C:\SmitFraudFix.exe: supprimé !
                            C:\BFU\EGDACCESS.bfu: supprimé !
                            C:\Documents and Settings\Thomas\Bureau\SmitFraudFix.exe: supprimé !
                            C:\Documents and Settings\Thomas\Bureau\ToolBarSD.exe: supprimé !
                            C:\Documents and Settings\Thomas\Mes documents\AUTRE\EGDACCESS.bfu: supprimé !
                            C:\Documents and Settings\Thomas\Mes documents\AUTRE\Gmer.zip: supprimé !
                            C:\Documents and Settings\Thomas\Mes documents\AUTRE\Bfu.exe: supprimé !
                            C:\Documents and Settings\Thomas\Mes documents\AUTRE\vundoFix.exe: supprimé !
                            C:\Program Files\trend micro\HijackThis.exe: supprimé !
                            C:\VundoFix.txt: supprimé !
                            C:\egd.txt: supprimé !
                            C:\Navipromo.txt: supprimé !
                            C:\TB.txt: supprimé !
                            C:\OTMoveIt3.exe: supprimé !
                            C:\Program Files\Hijackthis Version Française\hijackthis.log: supprimé !
                            C:\Program Files\trend micro\hijackthis.log: supprimé !
                            C:\SDFIX: supprimé !
                            C:\Vundofix backups: supprimé !
                            C:\_OtMoveIt: supprimé !
                            C:\Toolbar SD: supprimé !
                            C:\Rsit: supprimé !
                            C:\Documents and Settings\Thomas\Bureau\SmitFraudfix: supprimé !
                            C:\Documents and Settings\Thomas\Mes documents\FindyKill: supprimé !
                            C:\Program Files\Mozilla Firefox\SmitFraudfix: supprimé !

                            SDfix:

                            [b]SDFix: Version 1.240 /b
                            Run by Thomas on 25/03/2009 at 22:00

                            Microsoft Windows XP [version 5.1.2600]
                            Running From: C:\SDFix

                            [b]Checking Services /b:

                            Restoring Default Security Values
                            Restoring Default Hosts File

                            Rebooting

                            [b]Checking Files /b:

                            Trojan Files Found:

                            C:\WINDOWS\SYSTEM32\EWLH.DLL - Deleted
                            C:\WINDOWS\Config\csrss.exe - Deleted
                            C:\WINDOWS\system32\kr_done1 - Deleted

                            Removing Temp Files

                            [b]ADS Check /b:

                            [b]Final Check /b:

                            catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2009-03-25 22:12:01
                            Windows 5.1.2600 Service Pack 2 NTFS

                            scanning hidden processes ...

                            scanning hidden services & system hive ...

                            disk error: C:\WINDOWS\system32\config\system, 0
                            scanning hidden registry entries ...

                            disk error: C:\WINDOWS\system32\config\software, 0
                            disk error: C:\Documents and Settings\Thomas\ntuser.dat, 0
                            scanning hidden files ...

                            disk error: C:\WINDOWS\

                            please note that you need administrator rights to perform deep scan

                            [b]Remaining Services /b:

                            Authorized Application Key Export:

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                            "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Messenger"
                            "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Call"
                            "c:\\program files\\relevantknowledge\\rlvknlg.exe"="c:\\program files\\relevantknowledge\\rlvknlg.exe:*:Enabled:rlvknlg.exe"

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

                            [b]Remaining Files /b:

                            File Backups: - C:\SDFix\backups\backups.zip

                            [b]Files with Hidden Attributes /b:

                            [b]Finished!/b
                            -1
                            • 1
                            • 2
                            • 3