Pub cid

Bonjour,

Des pubs CID s'affichent sans arrêt quand j'ouvre une page internet. Il y a quelques jours, elles s'ouvraient en rafale.. J'ai regardé sur des forums pour résoudre le problème mais j'ai pas vraiment compris comment il fallait s'y prendre. Pouvez vous m'aider? Merci d'avance.
Configuration: Windows XP
Internet Explorer 7.0

47 réponses

Résumé de la discussion

Des publicités CID s'affichent de manière répétée lors de l'ouverture de pages et apparaissent en rafale, indiquant une infection potentielle ou une configuration publicitaire indésirable. Plusieurs solutions ont été proposées, notamment l’utilisation d’outils de diagnostic et de nettoyage tels que HijackThis, SDFix et des scans avec ComboFix ou Malwarebytes, pour identifier et supprimer les éléments indésirables. Les échanges précisent des détails pratiques: exécuter les outils, enregistrer et partager les rapports, puis déconnecter d’internet et désactiver temporairement l’antivirus lors de l’utilisation de ComboFix. En dernier élément, un test avec Malwarebytes a donné des résultats négatifs sur les éléments malveillants détectables, signalant que l’infection n’était pas nécessairement présente dans le système à ce moment-là.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    salut

    Attention aux cracks, c'est un important vecteur d'infection (télécharger un crack ou même visiter un site de crack a de grandes chances d'infecter l'ordinateur) : plus de 40%des infections
    1-IMPORTANT :
    je rappelle que bagle est amené par un crack et qu'il se relance dès que tu te sers de celui ci; même si tu ne sers pas, il peut se relancer de lui même au démarrage de ton PC . En claire :
    Essayes surtout de te rappeler si récemment tu n' as pas clicker sur un "patch" ou un "keygen" pour installer un logiciel, un jeu cracké ou avoir une version complète d'un soft , et qu'il ne se soit rien passé de particulier ... C'est la que les bagles s'infiltrent ! Si tu retrouves ce crack en particulier ,scratch tout ( le crack, le soft ou encore les zip concernés). Si tu ne te rappelles plus trop , je te conseille fortement de supprimer tous les cracks qui sont sur ton PC ... ;)

    https://forum.malekal.com/viewtopic.php?f=33&t=893
    Si tu en as, il faut les supprimer, ou il vont réinfecter continuellement ton pc...

    fait un scan antivirus en ligne içi

    https://www.trendmicro.com/en_us/forHome/products/housecall.html

    et içi pour finir

    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    1. voila le 2eme rappor

      "C:\Documents and Settings\HP_Administrateur\Bureau\ToolBar SD\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
      Option : [2] ( 16/04/2009|12:12 )

      -----------\\ Recherche de Fichiers / Dossiers ...

      -----------\\ [..\Internet Explorer\Main]

      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
      "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
      "Start Page"="https://www.msn.com/fr-fr"
      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
      "Default_Search_URL"="http://ie.redirect.hp.com/..."

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
      "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
      "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
      "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
      "Start Page"="https://www.msn.com/fr-fr/"
      "Search Bar"="http://ie.redirect.hp.com/..."

      --------------------\\ Recherche d'autres infections

      --------------------\\ Cracks & Keygens ..

      C:\DOCUME~1\HP_ADM~1\Mes documents\Ma musique\Rockin' Squat - Too Hot For TV-2007-BY POPOF\05 Crack game.mp3

      1 - "C:\Documents and Settings\HP_Administrateur\Bureau\ToolBar SD\ToolBar SD\TB_1.txt" - 15/04/2009| 7:19 - Option : [1]
      2 - "C:\Documents and Settings\HP_Administrateur\Bureau\ToolBar SD\ToolBar SD\TB_2.txt" - 15/04/2009| 7:21 - Option : [2]
      3 - "C:\Documents and Settings\HP_Administrateur\Bureau\ToolBar SD\ToolBar SD\TB_3.txt" - 16/04/2009|12:12 - Option : [2]

      -----------\\ Fin du rapport a 12:12:51,14
      1. salut, voici le rapport

        -----------\\ ToolBar S&D 1.2.8 XP/Vista

        Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
        X86-based PC ( Uniprocessor Free : AMD Athlon(tm) 64 Processor 3500+ )
        BIOS : Phoenix - AwardBIOS v6.00PG
        USER : HP_Administrateur ( Administrator )
        BOOT : Normal boot
        Antivirus : Bitdefender Antivirus 8.0 (Activated)
        Firewall : Bitdefender Firewall 8.0 (Activated)
        C:\ (Local Disk) - NTFS - Total:142 Go (Free:76 Go)
        D:\ (Local Disk) - FAT32 - Total:6 Go (Free:1 Go)
        E:\ (CD or DVD)
        G:\ (USB)
        H:\ (USB)
        I:\ (USB)
        J:\ (USB)

        "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
        Option : [1] ( 16/04/2009|12:09 )

        -----------\\ Recherche de Fichiers / Dossiers ...

        -----------\\ [..\Internet Explorer\Main]

        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
        "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
        "Start Page"="https://www.msn.com/fr-fr"
        "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
        "Default_Search_URL"="https://fr.search.yahoo.com/?fr=cb-hp06"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
        "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
        "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
        "Start Page"="https://www.msn.com/fr-fr/"
        "Search Bar"="https://fr.search.yahoo.com/?fr=cb-hp06"

        --------------------\\ Recherche d'autres infections

        --------------------\\ Cracks & Keygens ..

        C:\DOCUME~1\HP_ADM~1\Bureau\ToolBar SD\ToolBar SD\Crack.txt
        C:\DOCUME~1\HP_ADM~1\Mes documents\Ma musique\Rockin' Squat - Too Hot For TV-2007-BY POPOF\05 Crack game.mp3

        1 - "C:\ToolBar SD\TB_1.txt" - 16/04/2009|12:10 - Option : [1]

        -----------\\ Fin du rapport a 12:10:22,56
        1. Contributeur sécurité
          OK y'a du mieux on s'occupe du reste après

          Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
          https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

          * Lance l'installation du programme en exécutant le fichier téléchargé.
          * Double-clique maintenant sur le raccourci de Toolbar-S&D.
          * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
          * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
          * Poste le rapport généré. (C:\TB.txt)

          * Relance Toolbar-S&D en double-cliquant sur son raccourci situé sur le Bureau. Tape sur "2" puis valide en appuyant sur "Entrée". Ne ferme pas la fenêtre lors de la suppression. Un rapport sera généré, sauvegarde-le.
          1. salut, voici le rapport Combofix

            ComboFix 09-04-14.09 - HP_Administrateur 14/04/2009 19:43.3 - NTFSx86
            Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.958.642 [GMT 2:00]
            Lancé depuis: c:\documents and settings\HP_Administrateur\Bureau\ComboFix.exe
            Commutateurs utilisés :: c:\documents and settings\HP_Administrateur\Bureau\CFScript.txt..txt
            AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
            FW: Bitdefender Firewall *enabled*
            * Un nouveau point de restauration a été créé

            FILE ::
            c:\program files\Uninstall Ask Toolbar.dll
            c:\temp\atmp8
            c:\windows\QTFont.for
            c:\windows\QTFont.qfn
            c:\windows\system32\biruwuta.dll
            c:\windows\system32\bitipote.dll
            c:\windows\system32\bowafefi.dll
            c:\windows\system32\dadopuga.dll
            c:\windows\system32\delopeha.dll
            c:\windows\system32\dewozuzi.dll
            c:\windows\system32\firotapa.dll
            c:\windows\system32\fizipime.dll
            c:\windows\system32\gakewake.dll
            c:\windows\system32\gukevewi.dll
            c:\windows\system32\honimava.dll
            c:\windows\system32\jedepona.dll
            c:\windows\system32\jezosudo.dll
            c:\windows\system32\jobavito.dll
            c:\windows\system32\jojesira.dll
            c:\windows\system32\juyimebo.dll
            c:\windows\system32\kidapita.dll
            c:\windows\system32\lasobemo.dll
            c:\windows\system32\lowopami.dll
            c:\windows\system32\malufige.dll
            c:\windows\system32\minutara.dll
            c:\windows\system32\nevibuni.dll
            c:\windows\system32\nilejonu.dll
            c:\windows\system32\notabage.exe
            c:\windows\system32\nuwiyidi.dll
            c:\windows\system32\pelozeho.dll
            c:\windows\system32\pemivubu.dll
            c:\windows\system32\perfc00C.dat
            c:\windows\system32\perfh00C.dat
            c:\windows\system32\powipogi.exe
            c:\windows\system32\pulemebo.dll
            c:\windows\system32\razoriti.dll
            c:\windows\system32\rojideze.exe
            c:\windows\system32\rupibemo.dll
            c:\windows\system32\rusahene.exe
            c:\windows\system32\ruyebana.dll
            c:\windows\system32\sayoroso.dll
            c:\windows\system32\seratewa.dll
            c:\windows\system32\serubifa.exe
            c:\windows\system32\sikezovo.dll
            c:\windows\system32\tayufazu.dll
            c:\windows\system32\tisawipu.dll
            c:\windows\system32\vezeyege.dll
            c:\windows\system32\vodarowo.dll
            c:\windows\system32\vosubupa.dll
            c:\windows\system32\yabuvasu.dll
            c:\windows\system32\yapigifa.dll
            c:\windows\system32\yuvukina.dll
            c:\windows\system32\yuwegiju.dll
            c:\windows\system32\zafugiho.dll
            c:\windows\system32\zitajalu.dll
            c:\windows\system32\zubadira.dll
            c:\windows\system32\zulelolo.dll
            .

            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
            .

            c:\program files\Uninstall Ask Toolbar.dll
            c:\temp\atmp8
            c:\temp\atmp8\ead.log
            c:\windows\system32\biruwuta.dll
            c:\windows\system32\bitipote.dll
            c:\windows\system32\bowafefi.dll
            c:\windows\system32\dadopuga.dll
            c:\windows\system32\delopeha.dll
            c:\windows\system32\dewozuzi.dll
            c:\windows\system32\firotapa.dll
            c:\windows\system32\fizipime.dll
            c:\windows\system32\gakewake.dll
            c:\windows\system32\gukevewi.dll
            c:\windows\system32\jedepona.dll
            c:\windows\system32\jezosudo.dll
            c:\windows\system32\jobavito.dll
            c:\windows\system32\jojesira.dll
            c:\windows\system32\juyimebo.dll
            c:\windows\system32\kidapita.dll
            c:\windows\system32\lasobemo.dll
            c:\windows\system32\lowopami.dll
            c:\windows\system32\malufige.dll
            c:\windows\system32\minutara.dll
            c:\windows\system32\nevibuni.dll
            c:\windows\system32\nilejonu.dll
            c:\windows\system32\notabage.exe
            c:\windows\system32\pelozeho.dll
            c:\windows\system32\perfc00C.dat
            c:\windows\system32\perfh00C.dat
            c:\windows\system32\powipogi.exe
            c:\windows\system32\pulemebo.dll
            c:\windows\system32\razoriti.dll
            c:\windows\system32\rojideze.exe
            c:\windows\system32\rupibemo.dll
            c:\windows\system32\rusahene.exe
            c:\windows\system32\ruyebana.dll
            c:\windows\system32\sayoroso.dll
            c:\windows\system32\seratewa.dll
            c:\windows\system32\serubifa.exe
            c:\windows\system32\sikezovo.dll
            c:\windows\system32\tayufazu.dll
            c:\windows\system32\vezeyege.dll
            c:\windows\system32\vodarowo.dll
            c:\windows\system32\vosubupa.dll
            c:\windows\system32\yabuvasu.dll
            c:\windows\system32\yapigifa.dll
            c:\windows\system32\yuvukina.dll
            c:\windows\system32\zafugiho.dll
            c:\windows\system32\zitajalu.dll

            .
            ((((((((((((((((((((((((((((( Fichiers créés du 2009-03-14 au 2009-04-14 ))))))))))))))))))))))))))))))))))))
            .

            2009-04-10 11:50 . 2009-04-10 11:50 579584 ----a-w c:\windows\system32\dllcache\user32.dll
            2009-04-10 11:47 . 2009-04-11 14:33 -------- d-----w C:\SDFix
            2009-04-10 11:37 . 2009-04-10 11:37 -------- d-----w c:\windows\ERUNT
            2009-04-02 08:06 . 2009-03-26 14:49 15504 ----a-w c:\windows\system32\drivers\mbam.sys
            2009-04-02 08:06 . 2009-03-26 14:49 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
            2009-03-30 07:18 . 2009-03-30 07:18 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Malwarebytes
            2009-03-30 07:18 . 2009-04-11 14:33 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
            2009-03-30 07:18 . 2009-03-30 07:18 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
            2009-03-29 08:26 . 2009-03-30 07:33 -------- d-----w c:\program files\Lopxp
            2009-03-28 13:48 . 2009-03-30 07:47 -------- d-----w C:\Lop SD
            2009-03-27 17:34 . 2009-03-28 12:26 -------- d-----w c:\program files\Navilog1
            2009-03-27 12:48 . 2009-03-27 12:48 -------- d-----w c:\program files\Trend Micro
            2009-03-27 11:10 . 2009-03-27 11:10 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
            2009-03-27 11:08 . 2009-03-27 11:08 -------- d-sh--w c:\documents and settings\HP_Administrateur\IECompatCache
            2009-03-27 11:07 . 2009-03-27 11:07 -------- d-sh--w c:\documents and settings\HP_Administrateur\PrivacIE
            2009-03-27 11:03 . 2009-03-27 11:03 -------- d-sh--w c:\documents and settings\HP_Administrateur\IETldCache
            2009-03-27 10:38 . 2009-03-27 10:42 -------- dc-h--w c:\windows\ie8

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2009-04-13 09:00 . 2009-02-17 14:12 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
            2009-03-30 07:49 . 2009-03-28 13:49 17097 ----a-w C:\lopR.txt
            2009-03-29 12:35 . 2008-10-04 10:11 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\OpenOffice.org2
            2009-03-28 12:17 . 2009-03-28 12:01 2763 ----a-w C:\cleannavi.txt
            2009-03-28 12:01 . 2009-03-27 17:36 2689 ----a-w C:\fixnavi.txt
            2009-03-28 09:30 . 2007-06-22 08:23 81984 ----a-w c:\windows\system32\bdod.bin
            2009-03-24 06:00 . 2007-02-01 22:54 -------- d-----w c:\program files\AskTBar
            2009-03-22 12:50 . 2006-08-14 14:25 -------- d-----w c:\program files\Google
            2009-03-22 12:35 . 2007-08-03 09:47 -------- d-----w c:\program files\Windows Live
            2009-03-22 12:31 . 2006-08-14 14:05 -------- d--h--w c:\program files\InstallShield Installation Information
            2009-03-22 12:31 . 2006-08-14 14:07 -------- d-----w c:\program files\Fichiers communs\muvee Technologies
            2009-03-22 12:30 . 2008-12-20 19:01 -------- d-----w c:\program files\Veetle
            2009-03-22 12:28 . 2008-11-28 12:51 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Samsung
            2009-03-21 12:25 . 2007-06-22 18:45 -------- d-----w c:\program files\Windows Live Safety Center
            2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\vulabiro.dll
            2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\sogoruro.dll
            2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\pokefige.dll
            2009-03-20 08:24 . 2006-12-04 16:10 24758 ----a-w c:\documents and settings\HP_Administrateur\Application Data\wklnhst.dat
            2009-03-14 08:11 . 2009-03-14 08:11 -------- d-----w c:\program files\Microsoft
            2009-03-14 08:10 . 2009-03-14 08:10 -------- d-----w c:\program files\Windows Live SkyDrive
            2009-03-08 13:09 . 2004-08-10 11:00 638816 ----a-w c:\windows\system32\dllcache\iexplore.exe
            2009-03-08 13:09 . 2004-08-10 11:00 391536 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
            2009-03-08 03:41 . 2004-08-10 11:00 5937152 ----a-w c:\windows\system32\dllcache\mshtml.dll
            2009-03-08 03:39 . 2007-04-25 07:39 11063808 ----a-w c:\windows\system32\dllcache\ieframe.dll
            2009-03-08 03:34 . 2004-08-10 11:00 914944 ----a-w c:\windows\system32\wininet.dll
            2009-03-08 03:34 . 2004-08-10 11:00 914944 ----a-w c:\windows\system32\dllcache\wininet.dll
            2009-03-08 03:34 . 2004-08-10 11:00 1206784 ----a-w c:\windows\system32\dllcache\urlmon.dll
            2009-03-08 03:34 . 2004-08-10 11:00 236544 ----a-w c:\windows\system32\dllcache\webcheck.dll
            2009-03-08 03:34 . 2004-08-10 11:00 43008 ----a-w c:\windows\system32\licmgr10.dll
            2009-03-08 03:34 . 2004-08-10 11:00 43008 ----a-w c:\windows\system32\dllcache\licmgr10.dll
            2009-03-08 03:34 . 2004-08-10 11:00 105984 ----a-w c:\windows\system32\dllcache\url.dll
            2009-03-08 03:34 . 2004-08-10 11:00 193536 ----a-w c:\windows\system32\dllcache\msrating.dll
            2009-03-08 03:34 . 2004-08-10 11:00 109568 ----a-w c:\windows\system32\dllcache\occache.dll
            2009-03-08 03:33 . 2004-08-10 11:00 759296 ----a-w c:\windows\system32\dllcache\VGX.dll
            2009-03-08 03:33 . 2009-03-08 03:33 18944 ------w c:\windows\system32\dllcache\corpol.dll
            2009-03-08 03:33 . 2004-08-10 11:00 18944 ----a-w c:\windows\system32\corpol.dll
            2009-03-08 03:33 . 2004-08-10 11:00 25600 ----a-w c:\windows\system32\dllcache\jsproxy.dll
            2009-03-08 03:33 . 2008-05-09 10:55 726528 ----a-w c:\windows\system32\dllcache\jscript.dll
            2009-03-08 03:33 . 2004-08-10 11:00 229376 ----a-w c:\windows\system32\dllcache\ieaksie.dll
            2009-03-08 03:33 . 2008-05-09 10:55 420352 ----a-w c:\windows\system32\dllcache\vbscript.dll
            2009-03-08 03:33 . 2004-08-10 11:00 420352 ----a-w c:\windows\system32\vbscript.dll
            2009-03-08 03:33 . 2004-08-10 11:00 125952 ----a-w c:\windows\system32\dllcache\ieakeng.dll
            2009-03-08 03:32 . 2004-08-10 11:00 72704 ----a-w c:\windows\system32\dllcache\admparse.dll
            2009-03-08 03:32 . 2004-08-10 11:00 72704 ----a-w c:\windows\system32\admparse.dll
            2009-03-08 03:32 . 2004-08-10 11:00 173056 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
            2009-03-08 03:32 . 2004-08-10 04:00 163840 ----a-w c:\windows\system32\dllcache\ieakui.dll
            2009-03-08 03:32 . 2004-08-10 11:00 71680 ----a-w c:\windows\system32\iesetup.dll
            2009-03-08 03:32 . 2004-08-10 11:00 71680 ----a-w c:\windows\system32\dllcache\iesetup.dll
            2009-03-08 03:32 . 2004-08-10 11:00 55808 ----a-w c:\windows\system32\dllcache\iernonce.dll
            2009-03-08 03:32 . 2004-08-10 11:00 128512 ----a-w c:\windows\system32\dllcache\advpack.dll
            2009-03-08 03:32 . 2004-08-10 11:00 94720 ----a-w c:\windows\system32\dllcache\inseng.dll
            2009-03-08 03:32 . 2007-04-25 07:39 594432 ----a-w c:\windows\system32\dllcache\msfeeds.dll
            2009-03-08 03:32 . 2007-04-25 07:39 1985024 ----a-w c:\windows\system32\dllcache\iertutil.dll
            2009-03-08 03:32 . 2004-08-10 11:00 611840 ----a-w c:\windows\system32\dllcache\mstime.dll
            2009-03-08 03:24 . 2004-08-10 11:00 68608 ----a-w c:\windows\system32\dllcache\hmmapi.dll
            2009-03-08 03:22 . 2004-08-10 04:00 156160 ----a-w c:\windows\system32\msls31.dll
            2009-03-08 03:22 . 2004-08-10 04:00 156160 ----a-w c:\windows\system32\dllcache\msls31.dll
            2009-03-08 03:11 . 2007-04-25 07:38 445952 ----a-w c:\windows\system32\dllcache\ieapfltr.dll
            2009-02-28 09:31 . 2008-11-22 16:13 -------- d-----w c:\program files\Microsoft Silverlight
            2009-02-26 15:54 . 2007-05-16 17:40 -------- d-----w c:\program files\eMule
            2009-02-09 14:05 . 2008-10-15 06:58 1846912 ------w c:\windows\system32\dllcache\win32k.sys
            2009-02-09 14:05 . 2004-08-10 11:00 1846912 ----a-w c:\windows\system32\win32k.sys
            2009-02-06 20:07 . 2007-04-17 09:32 3698584 ----a-w c:\windows\system32\dllcache\ieapfltr.dat
            2009-02-06 17:52 . 2009-02-06 17:52 49504 ----a-w c:\windows\system32\sirenacm.dll
            2008-11-22 16:21 . 2006-11-15 17:08 63872 ----a-w c:\documents and settings\HP_Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
            2008-09-14 10:45 . 2008-08-09 09:53 47360 ----a-w c:\documents and settings\HP_Administrateur\Application Data\pcouffin.sys
            2006-11-15 21:14 . 2007-06-22 07:22 140 ----a-w c:\documents and settings\HP_Administrateur\Local Settings\Application Data\fusioncache.dat
            2006-08-14 13:32 . 2006-08-14 13:32 137 ----a-w c:\documents and settings\Administrateur\Local Settings\Application Data\fusioncache.dat
            .

            (((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
            .

            ---- Directory of c:\temp\atmp8 ----

            2009-03-16 08:06 . 2009-03-16 08:06 1858 ----a-w c:\temp\atmp8\ead.log

            ((((((((((((((((((((((((((((( SnapShot@2009-04-13_10.50.41.60 )))))))))))))))))))))))))))))))))))))))))
            .
            + 2009-04-14 17:47 . 2009-04-14 17:47 16384 c:\windows\Temp\Perflib_Perfdata_7d4.dat
            + 2009-04-14 17:45 . 2005-10-20 18:02 163328 c:\windows\ERDNT\subs\ERDNT.EXE
            - 2009-04-13 08:46 . 2005-10-20 18:02 163328 c:\windows\ERDNT\subs\ERDNT.EXE
            .
            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [BU]
            "Configuration de la neuf Box"="c:\program files\neuf telecom\neuf Box\Wizard\QuickAccess.exe" [BU]
            "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 68856]
            "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [BU]
            "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
            "BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
            "BDOESRV"="c:\program files\Softwin\BitDefender9\bdoesrv.exe" [2005-03-11 90112]
            "BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
            "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
            "DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
            "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
            "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
            "HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
            "NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [BU]
            "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
            "PCDrProfiler"="c:\program files\PC-Doctor 5 for Windows\RunProfiler.exe" [BU]
            "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
            "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
            "Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
            "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
            "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-08-14 180269]
            "AlwaysReady Power Message APP"="ARPWRMSG.EXE" - c:\windows\arpwrmsg.exe [2005-08-03 77312]
            "ftutil2"="ftutil2.dll" - c:\windows\system32\ftutil2.dll [2004-06-07 106496]
            "nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-05-09 1519616]
            "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2006-06-14 16239616]

            c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
            HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
            TrayMin210.exe.lnk - c:\program files\Philips\Philips SPC210NC Webcam\TrayMin210.exe [2007-6-6 278528]
            Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-2-5 118784]

            [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
            "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
            Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
            "DisableMonitoring"=dword:00000001

            [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
            "DisableMonitoring"=dword:00000001

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
            "EnableFirewall"= 0 (0x0)

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
            "c:\\Program Files\\eMule\\emule.exe"=
            "c:\\Program Files\\Messenger\\msmsgs.exe"=
            "c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
            "c:\\Program Files\\TVAnts\\Tvants.exe"=
            "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
            "c:\\Program Files\\SopCast\\SopCast.exe"=
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
            "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
            "c:\\Program Files\\Fichiers communs\\BitDefender\\BitDefender Update Service\\livesrv.exe"=

            R2 FILESpy;FILESpy; [x]
            R2 gupdate1c99109e78fbed3;Service Google Update (gupdate1c99109e78fbed3);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 133104]
            R3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;c:\windows\system32\DRIVERS\WlanUZXP.sys [2005-07-13 260608]
            S3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2008-06-24 86792]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
            bdx REG_MULTI_SZ scan
            .
            Contenu du dossier 'Tâches planifiées'

            2009-03-25 c:\windows\Tasks\AppleSoftwareUpdate.job
            - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 13:42]

            2009-04-14 c:\windows\Tasks\Google Software Updater.job
            - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-27 19:01]

            2009-03-28 c:\windows\Tasks\GoogleUpdateTaskMachine.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 14:13]
            .
            .
            ------- Examen supplémentaire -------
            .
            uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
            mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
            uInternet Connection Wizard,ShellNext = hxxp://www.google.com/support/chrome/bin/request.py?hl=en-US&contact_type=uninstall&crversion=1.0.154.48&os=5.1.2600
            uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
            IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
            .

            **************************************************************************

            catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2009-04-14 19:52
            Windows 5.1.2600 Service Pack 3 NTFS

            Recherche de processus cachés ...

            Recherche d'éléments en démarrage automatique cachés ...

            Recherche de fichiers cachés ...

            Scan terminé avec succès
            Fichiers cachés: 0

            **************************************************************************
            .
            --------------------- DLLs chargées dans les processus actifs ---------------------

            - - - - - - - > 'explorer.exe'(384)
            c:\program files\Softwin\BitDefender9\bdoe.dll
            c:\windows\system32\XCOMM.dll
            c:\windows\system32\ieframe.dll
            c:\windows\system32\eappprxy.dll
            c:\windows\system32\webcheck.dll
            c:\windows\system32\WPDShServiceObj.dll
            c:\windows\system32\PortableDeviceTypes.dll
            c:\windows\system32\PortableDeviceApi.dll
            .
            ------------------------ Autres processus actifs ------------------------
            .
            c:\program files\Java\jre6\bin\jqs.exe
            c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
            c:\program files\HP\Digital Imaging\bin\hpqste08.exe
            .
            **************************************************************************
            .
            Heure de fin: ~,10time:~,-3machine was rebootedCombobatch-by
            ComboFix-quarantined-files.txt 2009-04-14 17:56
            ComboFix2.txt 2009-04-13 09:11
            ComboFix3.txt 2009-04-13 08:51
            ComboFix4.txt 2009-04-11 13:41

            Avant-CF: 82 424 365 056 octets libres
            Après-CF: 82 481 786 880 octets libres

            354 --- E O F --- 2009-03-15 09:30

            Et le rapport Hijackthis

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 20:13:46, on 14/04/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v8.00 (8.00.6001.18702)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            C:\Program Files\Google\Update\GoogleUpdate.exe
            C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
            C:\Program Files\Softwin\BitDefender9\bdoesrv.exe
            C:\WINDOWS\VM_STI.EXE
            C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
            C:\WINDOWS\ehome\ehtray.exe
            C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            C:\Program Files\Windows Desktop Search\WindowsSearch.exe
            C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
            C:\WINDOWS\explorer.exe
            c:\windows\system\hpsysdrv.exe
            C:\Program Files\internet explorer\iexplore.exe
            C:\Program Files\internet explorer\iexplore.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
            O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
            O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
            O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
            O4 - HKLM\..\Run: [BDOESRV] "C:\Program Files\Softwin\BitDefender9\bdoesrv.exe"
            O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC210NC Webcam
            O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
            O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
            O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
            O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
            O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
            O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
            O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [PCDrProfiler] "C:\Program Files\PC-Doctor 5 for Windows\RunProfiler.exe" -r
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
            O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [Configuration de la neuf Box] C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
            O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
            O4 - Global Startup: TrayMin210.exe.lnk = C:\Program Files\Philips\Philips SPC210NC Webcam\TrayMin210.exe
            O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
            O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
            O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
            O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
            O23 - Service: Service Google Update (gupdate1c99109e78fbed3) (gupdate1c99109e78fbed3) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
            O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
            O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
            1. Contributeur sécurité
              /!\ Manip crée spécialement pour cet utilisateur , ne pas reproduire chez soi ... /!\

              Ouvre le Bloc-Notes (Démarrer\Tous les programmes\Accessoires\Bloc notes.)

              Copie ce texte ( en gras )d'une traite ( CTRL+C pour copier ) puis colle-le ( CTRL+V dans le bloc-note )


              File::
              c:\windows\system32\honimava.dll
              c:\windows\system32\zulelolo.dll
              c:\windows\system32\tisawipu.dll
              c:\windows\system32\nuwiyidi.dll
              c:\program files\Uninstall Ask Toolbar.dll
              c:\windows\system32\zubadira.dll
              c:\windows\system32\yuwegiju.dll
              c:\windows\system32\pemivubu.dll
              c:\windows\QTFont.qfn
              c:\windows\QTFont.for
              c:\temp\atmp8
              c:\windows\system32\perfc00C.dat
              c:\windows\system32\perfh00C.dat
              c:\windows\system32\serubifa.exe
              c:\windows\system32\serubifa.exe
              c:\windows\system32\notabage.exe
              c:\windows\system32\notabage.exe
              c:\windows\system32\rojideze.exe
              c:\windows\system32\rojideze.exe
              c:\windows\system32\powipogi.exe
              c:\windows\system32\powipogi.exe
              c:\windows\system32\rusahene.exe
              c:\windows\system32\rusahene.exe
              c:\windows\system32\kidapita.dll
              c:\windows\system32\bowafefi.dll
              c:\windows\system32\vodarowo.dll
              c:\windows\system32\ruyebana.dll
              c:\windows\system32\jedepona.dll
              c:\windows\system32\yabuvasu.dll
              c:\windows\system32\lowopami.dll
              c:\windows\system32\seratewa.dll
              c:\windows\system32\nilejonu.dll
              c:\windows\system32\lasobemo.dll
              c:\windows\system32\nevibuni.dll
              c:\windows\system32\malufige.dll
              c:\windows\system32\gakewake.dll
              c:\windows\system32\sikezovo.dll
              c:\windows\system32\vosubupa.dll
              c:\windows\system32\dewozuzi.dll
              c:\windows\system32\razoriti.dll
              c:\windows\system32\sayoroso.dll
              c:\windows\system32\bitipote.dll
              c:\windows\system32\yuvukina.dll
              c:\windows\system32\rupibemo.dll
              c:\windows\system32\delopeha.dll
              c:\windows\system32\vezeyege.dll
              c:\windows\system32\jojesira.dll
              c:\windows\system32\firotapa.dll
              c:\windows\system32\fizipime.dll
              c:\windows\system32\biruwuta.dll
              c:\windows\system32\pelozeho.dll
              c:\windows\system32\minutara.dll
              c:\windows\system32\zafugiho.dll
              c:\windows\system32\tayufazu.dll
              c:\windows\system32\jobavito.dll
              c:\windows\system32\jezosudo.dll
              c:\windows\system32\dadopuga.dll
              c:\windows\system32\pulemebo.dll
              c:\windows\system32\gukevewi.dll
              c:\windows\system32\yapigifa.dll
              c:\windows\system32\juyimebo.dll
              c:\windows\system32\zitajalu.dll

              Folder::
              c:\temp\atmp8

              DirLook::
              c:\temp\atmp8


              Sauvegarde ce fichier sur ton bureau sous le nom de CFScript.txt.

              Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

              http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

              Cela va relancer Combofix,

              Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

              Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

              Ne touche à rien tant que le scan n'est pas terminé.

              Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

              S'il n'y a pas de rédémarrage, poste quand même les rapports.

              Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
              Mais C.. de penser que ­tu es libre...Merci a australe13
              1. Contributeur sécurité
                salut

                c'est pas possible c'est un concours a qui pourrit son pc le premier tu va entrer dans le guiness record

                c'est un gag la ?

                LOL
                1. salut, voila le rapport

                  ComboFix 09-04-13.A0 - HP_Administrateur 2009-04-13 10:41.1 - NTFSx86
                  Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.958.649 [GMT 2:00]
                  Lancé depuis: c:\documents and settings\HP_Administrateur\Bureau\ComboFix.exe
                  Commutateurs utilisés :: c:\documents and settings\HP_Administrateur\Bureau\CFScript.txt
                  AV: Bitdefender Antivirus *On-access scanning enabled* (Updated)
                  FW: Bitdefender Firewall *enabled*
                  * Un nouveau point de restauration a été créé
                  .

                  (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  c:\documents and settings\HP_Administrateur\Application Data\inst.exe
                  c:\program files\outlook
                  c:\windows\system32\avohirew.ini
                  c:\windows\system32\bszip.dll
                  c:\windows\system32\emezetef.ini
                  c:\windows\system32\eyujazot.ini
                  c:\windows\system32\gotiyewi.dll
                  c:\windows\system32\hekewufu.dll
                  c:\windows\system32\hujepaka.dll
                  c:\windows\system32\huzitala.dll
                  c:\windows\system32\jonefede.dll
                  c:\windows\system32\rugakeju.dll
                  c:\windows\system32\udokalul.ini
                  c:\windows\system32\yegegeyo.dll
                  c:\windows\winhelp.ini
                  D:\Autorun.inf

                  .
                  ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  -------\Legacy_DHLP

                  ((((((((((((((((((((((((((((( Fichiers créés du 2009-03-13 au 2009-04-13 ))))))))))))))))))))))))))))))))))))
                  .

                  2009-04-10 11:50 . 2009-04-10 11:50 579584 ----a-w c:\windows\system32\dllcache\user32.dll
                  2009-04-10 11:47 . 2009-04-11 14:33 -------- d-----w C:\SDFix
                  2009-04-10 11:37 . 2009-04-10 11:37 -------- d-----w c:\windows\ERUNT
                  2009-04-02 08:06 . 2009-03-26 14:49 15504 ----a-w c:\windows\system32\drivers\mbam.sys
                  2009-04-02 08:06 . 2009-03-26 14:49 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
                  2009-03-30 07:18 . 2009-03-30 07:18 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Malwarebytes
                  2009-03-30 07:18 . 2009-04-11 14:33 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
                  2009-03-30 07:18 . 2009-03-30 07:18 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
                  2009-03-29 08:26 . 2009-03-30 07:33 -------- d-----w c:\program files\Lopxp
                  2009-03-28 13:48 . 2009-03-30 07:47 -------- d-----w C:\Lop SD
                  2009-03-27 17:34 . 2009-03-28 12:26 -------- d-----w c:\program files\Navilog1
                  2009-03-27 12:48 . 2009-03-27 12:48 -------- d-----w c:\program files\Trend Micro
                  2009-03-27 11:10 . 2009-03-27 11:10 -------- d-sh--w c:\documents and settings\LocalService\IETldCache
                  2009-03-27 11:08 . 2009-03-27 11:08 -------- d-sh--w c:\documents and settings\HP_Administrateur\IECompatCache
                  2009-03-27 11:07 . 2009-03-27 11:07 -------- d-sh--w c:\documents and settings\HP_Administrateur\PrivacIE
                  2009-03-27 11:03 . 2009-03-27 11:03 -------- d-sh--w c:\documents and settings\HP_Administrateur\IETldCache
                  2009-03-27 10:38 . 2009-03-27 10:42 -------- dc-h--w c:\windows\ie8
                  2009-03-24 19:28 . 2009-03-24 19:28 5297 --sh--w c:\windows\system32\honimava.dll
                  2009-03-23 19:32 . 2009-03-23 19:32 912 --sh--w c:\windows\system32\zulelolo.dll
                  2009-03-23 19:32 . 2009-03-23 19:32 912 --sh--w c:\windows\system32\tisawipu.dll
                  2009-03-23 19:32 . 2009-03-23 19:37 912 ----a-w c:\windows\system32\nuwiyidi.dll
                  2009-03-23 07:38 . 2008-03-08 09:42 245760 ----a-w c:\program files\Uninstall Ask Toolbar.dll
                  2009-03-23 07:36 . 2009-03-23 08:36 912 ----a-w c:\windows\system32\zubadira.dll
                  2009-03-23 07:36 . 2009-03-23 07:36 912 --sh--w c:\windows\system32\yuwegiju.dll
                  2009-03-23 07:36 . 2009-03-23 08:36 912 ----a-w c:\windows\system32\pemivubu.dll
                  2009-03-22 12:51 . 2009-03-22 12:51 54156 ---ha-w c:\windows\QTFont.qfn
                  2009-03-22 12:51 . 2009-03-22 12:51 1409 ----a-w c:\windows\QTFont.for
                  2009-03-16 08:05 . 2009-03-16 08:06 -------- d-----w c:\temp\atmp8

                  .
                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2009-04-11 14:40 . 2005-10-10 11:39 85258 ----a-w c:\windows\system32\perfc00C.dat
                  2009-04-11 14:40 . 2005-10-10 11:39 492556 ----a-w c:\windows\system32\perfh00C.dat
                  2009-03-30 07:49 . 2009-03-28 13:49 17097 ----a-w C:\lopR.txt
                  2009-03-29 12:35 . 2008-10-04 10:11 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\OpenOffice.org2
                  2009-03-29 07:30 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\serubifa.exe
                  2009-03-29 07:30 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\serubifa.exe
                  2009-03-28 19:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\notabage.exe
                  2009-03-28 19:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\notabage.exe
                  2009-03-28 12:17 . 2009-03-28 12:01 2763 ----a-w C:\cleannavi.txt
                  2009-03-28 12:01 . 2009-03-27 17:36 2689 ----a-w C:\fixnavi.txt
                  2009-03-28 09:30 . 2007-06-22 08:23 81984 ----a-w c:\windows\system32\bdod.bin
                  2009-03-28 07:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\rojideze.exe
                  2009-03-28 07:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\rojideze.exe
                  2009-03-27 19:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\powipogi.exe
                  2009-03-27 19:29 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\powipogi.exe
                  2009-03-27 09:17 . 2009-02-17 14:12 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
                  2009-03-27 07:28 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\rusahene.exe
                  2009-03-27 07:28 . 1601-01-01 00:12 61440 --sha-w c:\windows\system32\rusahene.exe
                  2009-03-26 19:28 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\kidapita.dll
                  2009-03-26 07:28 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\bowafefi.dll
                  2009-03-25 07:27 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\vodarowo.dll
                  2009-03-25 07:27 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\ruyebana.dll
                  2009-03-25 07:27 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\jedepona.dll
                  2009-03-24 07:27 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\yabuvasu.dll
                  2009-03-24 07:27 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\lowopami.dll
                  2009-03-24 06:00 . 2007-02-01 22:54 -------- d-----w c:\program files\AskTBar
                  2009-03-22 12:50 . 2006-08-14 14:25 -------- d-----w c:\program files\Google
                  2009-03-22 12:35 . 2007-08-03 09:47 -------- d-----w c:\program files\Windows Live
                  2009-03-22 12:31 . 2006-08-14 14:05 -------- d--h--w c:\program files\InstallShield Installation Information
                  2009-03-22 12:31 . 2006-08-14 14:07 -------- d-----w c:\program files\Fichiers communs\muvee Technologies
                  2009-03-22 12:30 . 2008-12-20 19:01 -------- d-----w c:\program files\Veetle
                  2009-03-22 12:28 . 2008-11-28 12:51 -------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Samsung
                  2009-03-22 12:26 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\seratewa.dll
                  2009-03-22 12:26 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\nilejonu.dll
                  2009-03-22 12:26 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\lasobemo.dll
                  2009-03-21 22:40 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\nevibuni.dll
                  2009-03-21 22:40 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\malufige.dll
                  2009-03-21 22:40 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\gakewake.dll
                  2009-03-21 12:25 . 2007-06-22 18:45 -------- d-----w c:\program files\Windows Live Safety Center
                  2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\vulabiro.dll
                  2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\sogoruro.dll
                  2009-03-20 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\pokefige.dll
                  2009-03-20 08:24 . 2006-12-04 16:10 24758 ----a-w c:\documents and settings\HP_Administrateur\Application Data\wklnhst.dat
                  2009-03-20 08:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\sikezovo.dll
                  2009-03-20 08:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\vosubupa.dll
                  2009-03-20 08:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\dewozuzi.dll
                  2009-03-19 20:13 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\razoriti.dll
                  2009-03-19 20:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\sayoroso.dll
                  2009-03-19 20:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\bitipote.dll
                  2009-03-19 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\yuvukina.dll
                  2009-03-19 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\rupibemo.dll
                  2009-03-19 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\delopeha.dll
                  2009-03-18 20:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\vezeyege.dll
                  2009-03-18 20:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\jojesira.dll
                  2009-03-18 20:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\firotapa.dll
                  2009-03-18 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\fizipime.dll
                  2009-03-18 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\biruwuta.dll
                  2009-03-18 08:12 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\pelozeho.dll
                  2009-03-17 20:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\minutara.dll
                  2009-03-17 20:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\zafugiho.dll
                  2009-03-17 08:15 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\tayufazu.dll
                  2009-03-17 08:15 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\jobavito.dll
                  2009-03-17 08:15 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\jezosudo.dll
                  2009-03-16 20:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\dadopuga.dll
                  2009-03-16 20:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\pulemebo.dll
                  2009-03-16 20:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\gukevewi.dll
                  2009-03-16 08:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\yapigifa.dll
                  2009-03-16 08:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\juyimebo.dll
                  2009-03-16 08:11 . 1601-01-01 00:12 912 --sha-w c:\windows\system32\zitajalu.dll
                  2009-03-14 08:11 . 2009-03-14 08:11 -------- d-----w c:\program files\Microsoft
                  2009-03-14 08:10 . 2009-03-14 08:10 -------- d-----w c:\program files\Windows Live SkyDrive
                  2009-03-08 13:09 . 2004-08-10 11:00 638816 ----a-w c:\windows\system32\dllcache\iexplore.exe
                  2009-03-08 13:09 . 2004-08-10 11:00 391536 ----a-w c:\windows\system32\dllcache\iedkcs32.dll
                  2009-03-08 03:41 . 2004-08-10 11:00 5937152 ----a-w c:\windows\system32\dllcache\mshtml.dll
                  2009-03-08 03:39 . 2007-04-25 07:39 11063808 ----a-w c:\windows\system32\dllcache\ieframe.dll
                  2009-03-08 03:34 . 2004-08-10 11:00 914944 ----a-w c:\windows\system32\wininet.dll
                  2009-03-08 03:34 . 2004-08-10 11:00 914944 ----a-w c:\windows\system32\dllcache\wininet.dll
                  2009-03-08 03:34 . 2004-08-10 11:00 1206784 ----a-w c:\windows\system32\dllcache\urlmon.dll
                  2009-03-08 03:34 . 2004-08-10 11:00 236544 ----a-w c:\windows\system32\dllcache\webcheck.dll
                  2009-03-08 03:34 . 2004-08-10 11:00 43008 ----a-w c:\windows\system32\licmgr10.dll
                  2009-03-08 03:34 . 2004-08-10 11:00 43008 ----a-w c:\windows\system32\dllcache\licmgr10.dll
                  2009-03-08 03:34 . 2004-08-10 11:00 105984 ----a-w c:\windows\system32\dllcache\url.dll
                  2009-03-08 03:34 . 2004-08-10 11:00 193536 ----a-w c:\windows\system32\dllcache\msrating.dll
                  2009-03-08 03:34 . 2004-08-10 11:00 109568 ----a-w c:\windows\system32\dllcache\occache.dll
                  2009-03-08 03:33 . 2004-08-10 11:00 759296 ----a-w c:\windows\system32\dllcache\VGX.dll
                  2009-03-08 03:33 . 2009-03-08 03:33 18944 ------w c:\windows\system32\dllcache\corpol.dll
                  2009-03-08 03:33 . 2004-08-10 11:00 18944 ----a-w c:\windows\system32\corpol.dll
                  2009-03-08 03:33 . 2004-08-10 11:00 25600 ----a-w c:\windows\system32\dllcache\jsproxy.dll
                  2009-03-08 03:33 . 2008-05-09 10:55 726528 ----a-w c:\windows\system32\dllcache\jscript.dll
                  2009-03-08 03:33 . 2004-08-10 11:00 229376 ----a-w c:\windows\system32\dllcache\ieaksie.dll
                  2009-03-08 03:33 . 2008-05-09 10:55 420352 ----a-w c:\windows\system32\dllcache\vbscript.dll
                  2009-03-08 03:33 . 2004-08-10 11:00 420352 ----a-w c:\windows\system32\vbscript.dll
                  2009-03-08 03:33 . 2004-08-10 11:00 125952 ----a-w c:\windows\system32\dllcache\ieakeng.dll
                  2009-03-08 03:32 . 2004-08-10 11:00 72704 ----a-w c:\windows\system32\dllcache\admparse.dll
                  2009-03-08 03:32 . 2004-08-10 11:00 72704 ----a-w c:\windows\system32\admparse.dll
                  2009-03-08 03:32 . 2004-08-10 11:00 173056 ----a-w c:\windows\system32\dllcache\ie4uinit.exe
                  2009-03-08 03:32 . 2004-08-10 04:00 163840 ----a-w c:\windows\system32\dllcache\ieakui.dll
                  2009-03-08 03:32 . 2004-08-10 11:00 71680 ----a-w c:\windows\system32\iesetup.dll
                  2009-03-08 03:32 . 2004-08-10 11:00 71680 ----a-w c:\windows\system32\dllcache\iesetup.dll
                  2009-03-08 03:32 . 2004-08-10 11:00 55808 ----a-w c:\windows\system32\dllcache\iernonce.dll
                  .

                  ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                  REGEDIT4

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                  "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 68856]
                  "Configuration de la neuf Box"="c:\program files\neuf telecom\neuf Box\Wizard\QuickAccess.exe" [BU]
                  "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [BU]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-08-14 180269]
                  "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
                  "Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
                  "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
                  "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
                  "PCDrProfiler"="c:\program files\PC-Doctor 5 for Windows\RunProfiler.exe" [BU]
                  "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-10 7311360]
                  "NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [BU]
                  "HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
                  "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
                  "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
                  "DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
                  "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
                  "BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
                  "BDOESRV"="c:\program files\Softwin\BitDefender9\bdoesrv.exe" [2005-03-11 90112]
                  "BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
                  "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
                  "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [BU]
                  "RTHDCPL"="RTHDCPL.EXE" [2006-06-14 c:\windows\RTHDCPL.EXE]
                  "nwiz"="nwiz.exe" [2006-05-10 c:\windows\system32\nwiz.exe]
                  "ftutil2"="ftutil2.dll" [2004-06-07 c:\windows\system32\ftutil2.dll]
                  "AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]

                  c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                  HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
                  TrayMin210.exe.lnk - c:\program files\Philips\Philips SPC210NC Webcam\TrayMin210.exe [2007-06-06 278528]
                  Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]

                  [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                  "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                  Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                  "DisableMonitoring"=dword:00000001

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                  "DisableMonitoring"=dword:00000001

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                  "DisableMonitoring"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                  "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
                  "c:\\Program Files\\eMule\\emule.exe"=
                  "c:\\Program Files\\Messenger\\msmsgs.exe"=
                  "c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
                  "c:\\Program Files\\TVAnts\\Tvants.exe"=
                  "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
                  "c:\\Program Files\\SopCast\\SopCast.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                  "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                  "c:\\Program Files\\Fichiers communs\\BitDefender\\BitDefender Update Service\\livesrv.exe"=

                  R2 FILESpy;FILESpy; [x]
                  R2 gupdate1c99109e78fbed3;Service Google Update (gupdate1c99109e78fbed3);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 133104]
                  R3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;c:\windows\system32\DRIVERS\WlanUZXP.sys [2005-07-13 260608]
                  S3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\DRIVERS\bdfndisf.sys [2008-06-24 86792]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                  bdx REG_MULTI_SZ scan

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{381a841a-d73f-11dd-bee7-0018f36f024d}]
                  \Shell\AutoRun\command - f:\wd_windows_tools\Setup.exe

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c64e4e58-114f-11de-bf36-0018f36f024d}]
                  \Shell\Auto\command - F:\Start.exe
                  \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
                  .
                  Contenu du dossier 'Tâches planifiées'

                  2009-03-25 c:\windows\Tasks\AppleSoftwareUpdate.job
                  - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

                  2009-04-13 c:\windows\Tasks\Google Software Updater.job
                  - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-22 21:01]

                  2009-03-28 c:\windows\Tasks\GoogleUpdateTaskMachine.job
                  - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 16:13]
                  .
                  - - - - ORPHELINS SUPPRIMES - - - -

                  WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)

                  .
                  ------- Examen supplémentaire -------
                  .
                  uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
                  mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
                  uInternet Connection Wizard,ShellNext = hxxp://www.google.com/support/chrome/bin/request.py?hl=en-US&contact_type=uninstall&crversion=1.0.154.48&os=5.1.2600
                  uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                  IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
                  .

                  **************************************************************************

                  catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2009-04-13 10:47
                  Windows 5.1.2600 Service Pack 3 NTFS

                  Recherche de processus cachés ...

                  Recherche d'éléments en démarrage automatique cachés ...

                  Recherche de fichiers cachés ...

                  Scan terminé avec succès
                  Fichiers cachés: 0

                  **************************************************************************
                  .
                  --------------------- DLLs chargées dans les processus actifs ---------------------

                  - - - - - - - > 'explorer.exe'(2888)
                  c:\program files\Softwin\BitDefender9\bdoe.dll
                  c:\windows\system32\XCOMM.dll
                  c:\windows\system32\ieframe.dll
                  c:\windows\system32\eappprxy.dll
                  c:\windows\system32\webcheck.dll
                  c:\windows\system32\WPDShServiceObj.dll
                  c:\windows\system32\PortableDeviceTypes.dll
                  c:\windows\system32\PortableDeviceApi.dll
                  .
                  ------------------------ Autres processus actifs ------------------------
                  .
                  c:\program files\Java\jre6\bin\jqs.exe
                  c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
                  c:\program files\HP\Digital Imaging\bin\hpqste08.exe
                  .
                  **************************************************************************
                  .
                  Heure de fin: 2009-04-13 10:51 - La machine a redémarré [HP_Administrateur]
                  ComboFix-quarantined-files.txt 2009-04-13 08:51
                  ComboFix2.txt 2009-04-11 13:41

                  Avant-CF: 82 506 194 944 octets libres
                  Après-CF: 82,569,945,088 octets libres

                  304 --- E O F --- 2009-03-15 09:30
                  1. Contributeur sécurité
                    > Avec Combofix :
                    - Crée un nouveau document texte : clic droit de souris sur le bureau => Nouveau => Document Texte, et copie/colle dedans les lignes suivantes :

                    Registry::
                    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{381a841a-d73f-11dd-bee7-0018f36f024d}]
                    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c64e4e58-114f-11de-bf36-0018f36f024d}]

                    File::
                    c:\windows\system32\honimava.dll
                    c:\windows\system32\zulelolo.dll
                    c:\windows\system32\tisawipu.dll
                    c:\windows\system32\nuwiyidi.dll
                    c:\windows\system32\zubadira.dll
                    c:\windows\system32\yuwegiju.dll
                    c:\windows\system32\pemivubu.dll
                    c:\windows\QTFont.qfn
                    c:\windows\QTFont.for


                    - Enregistre ce fichier sous le nom CFScript (Type du fichier : tous les fichiers)
                    - Ferme tous tes navigateurs web (donc copie ou imprime les instructions suivantes avant si besoin est).
                    - Désactive ton antivirus et tes autres protections résidentes (ex : Spybot) si tu en as (c'est important).
                    - Fait un glisser/déposer de ce fichier CFScript sur le programme ComboFix.exe
                    (Explications du glisser/coller : Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relâche alors le bouton de la souris).
                    - Combofix va démarrer puis une fenêtre bleue va apparaître. Au message qui s'affiche (Type 1 to continue, or 2 to abort) : tape 1 puis valide.
                    - Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal !
                    - Ne touche à rien tant que le scan n'est pas terminé sinon le PC peut planter !
                    - Une fois le scan achevé, un rapport va s'afficher: poste le stp.
                    PS : Si le fichier ne s'ouvre pas, il se trouve ici => C:\ComboFix.txt

                    Par Manque De Curiosité On Risque De Mourir Ignorant;Tu es libre de penser que tu es C..,
                    Mais C.. de penser que ­tu es libre...Merci a australe13
                    1. salut voila le rapport

                      ComboFix 09-04-04.01 - HP_Administrateur 2009-04-11 15:31:22.1 - NTFSx86
                      Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.958.606 [GMT 2:00]
                      Lancé depuis: c:\documents and settings\HP_Administrateur\Bureau\ComboFix.exe
                      * Un nouveau point de restauration a été créé
                      .

                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      c:\documents and settings\HP_Administrateur\Application Data\inst.exe
                      c:\program files\INSTALL.LOG
                      c:\program files\outlook
                      c:\windows\system32\avohirew.ini
                      c:\windows\system32\bszip.dll
                      c:\windows\system32\emezetef.ini
                      c:\windows\system32\eyujazot.ini
                      c:\windows\system32\gotiyewi.dll
                      c:\windows\system32\hekewufu.dll
                      c:\windows\system32\hujepaka.dll
                      c:\windows\system32\huzitala.dll
                      c:\windows\system32\jonefede.dll
                      c:\windows\system32\rugakeju.dll
                      c:\windows\system32\udokalul.ini
                      c:\windows\system32\yegegeyo.dll
                      c:\windows\winhelp.ini
                      D:\Autorun.inf

                      .
                      ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      -------\Legacy_DHLP

                      ((((((((((((((((((((((((((((( Fichiers créés du 2009-03-11 au 2009-04-11 ))))))))))))))))))))))))))))))))))))
                      .

                      2009-04-10 13:50 . 2009-04-10 13:50 579,584 --a------ c:\windows\system32\dllcache\user32.dll
                      2009-04-10 13:47 . 2009-04-11 13:16 <REP> d-------- C:\SDFix
                      2009-04-10 13:37 . 2009-04-10 13:37 <REP> d-------- c:\windows\ERUNT
                      2009-04-02 10:06 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                      2009-04-02 10:06 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                      2009-03-30 09:18 . 2009-04-11 13:15 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                      2009-03-30 09:18 . 2009-03-30 09:18 <REP> d-------- c:\documents and settings\HP_Administrateur\Application Data\Malwarebytes
                      2009-03-30 09:18 . 2009-03-30 09:18 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                      2009-03-29 10:26 . 2009-03-30 09:33 <REP> d-------- c:\program files\Lopxp
                      2009-03-28 15:48 . 2009-03-30 09:47 <REP> d-------- C:\Lop SD
                      2009-03-27 19:34 . 2009-03-28 14:26 <REP> d-------- c:\program files\Navilog1
                      2009-03-27 14:48 . 2009-03-27 14:48 <REP> d-------- c:\program files\Trend Micro
                      2009-03-27 13:10 . 2009-03-27 13:10 <REP> d--hs---- c:\documents and settings\LocalService\IETldCache
                      2009-03-27 13:08 . 2009-03-27 13:08 <REP> d--hs---- c:\documents and settings\HP_Administrateur\IECompatCache
                      2009-03-27 13:07 . 2009-03-27 13:07 <REP> d--hs---- c:\documents and settings\HP_Administrateur\PrivacIE
                      2009-03-27 13:03 . 2009-03-27 13:03 <REP> d--hs---- c:\documents and settings\HP_Administrateur\IETldCache
                      2009-03-27 12:38 . 2009-03-27 12:42 <REP> d--h-c--- c:\windows\ie8
                      2009-03-24 21:28 . 2009-03-24 21:28 5,297 ---hs---- c:\windows\system32\honimava.dll
                      2009-03-23 21:32 . 2009-03-23 21:32 912 ---hs---- c:\windows\system32\zulelolo.dll
                      2009-03-23 21:32 . 2009-03-23 21:32 912 ---hs---- c:\windows\system32\tisawipu.dll
                      2009-03-23 21:32 . 2009-03-23 21:37 912 --a------ c:\windows\system32\nuwiyidi.dll
                      2009-03-23 09:38 . 2008-03-08 11:42 245,760 --a------ c:\program files\Uninstall Ask Toolbar.dll
                      2009-03-23 09:36 . 2009-03-23 10:36 912 --a------ c:\windows\system32\zubadira.dll
                      2009-03-23 09:36 . 2009-03-23 09:36 912 ---hs---- c:\windows\system32\yuwegiju.dll
                      2009-03-23 09:36 . 2009-03-23 10:36 912 --a------ c:\windows\system32\pemivubu.dll
                      2009-03-22 14:51 . 2009-03-22 14:51 54,156 --ah----- c:\windows\QTFont.qfn
                      2009-03-22 14:51 . 2009-03-22 14:51 1,409 --a------ c:\windows\QTFont.for
                      2009-03-16 10:05 . 2009-03-16 10:06 <REP> d-------- c:\temp\atmp8
                      2009-03-14 10:36 . 2009-04-11 09:05 <REP> d-------- c:\documents and settings\HP_Administrateur\Tracing
                      2009-03-14 10:11 . 2009-03-14 10:11 <REP> d-------- c:\program files\Microsoft
                      2009-03-14 10:10 . 2009-03-14 10:10 <REP> d-------- c:\program files\Windows Live SkyDrive

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2009-03-29 12:35 --------- d-----w c:\documents and settings\HP_Administrateur\Application Data\OpenOffice.org2
                      2009-03-27 09:17 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
                      2009-03-24 06:00 --------- d-----w c:\program files\AskTBar
                      2009-03-22 12:50 --------- d-----w c:\program files\Google
                      2009-03-22 12:35 --------- d-----w c:\program files\Windows Live
                      2009-03-22 12:31 --------- d--h--w c:\program files\InstallShield Installation Information
                      2009-03-22 12:31 --------- d-----w c:\program files\Fichiers communs\muvee Technologies
                      2009-03-22 12:30 --------- d-----w c:\program files\Veetle
                      2009-03-22 12:28 --------- d-----w c:\documents and settings\HP_Administrateur\Application Data\Samsung
                      2009-03-21 12:25 --------- d-----w c:\program files\Windows Live Safety Center
                      2009-03-20 08:24 24,758 ----a-w c:\documents and settings\HP_Administrateur\Application Data\wklnhst.dat
                      2009-02-28 09:31 --------- d-----w c:\program files\Microsoft Silverlight
                      2009-02-26 15:54 --------- d-----w c:\program files\eMule
                      2008-09-14 10:45 47,360 ----a-w c:\documents and settings\HP_Administrateur\Application Data\pcouffin.sys
                      2008-09-05 18:02 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\Historique\History.IE5\MSHist012008090520080906\index.dat
                      .

                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                      REGEDIT4

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-14 68856]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-08-14 180269]
                      "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
                      "Reminder"="c:\windows\Creator\Remind_XP.exe" [2004-12-14 663552]
                      "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2005-07-22 237568]
                      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-04-27 282624]
                      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-10 7311360]
                      "HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 249856]
                      "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
                      "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
                      "DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
                      "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
                      "BigDogPath"="c:\windows\VM_STI.EXE" [2004-06-09 40960]
                      "BDOESRV"="c:\program files\Softwin\BitDefender9\bdoesrv.exe" [2005-03-11 90112]
                      "BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-09-16 368640]
                      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
                      "RTHDCPL"="RTHDCPL.EXE" [2006-06-14 c:\windows\RTHDCPL.EXE]
                      "nwiz"="nwiz.exe" [2006-05-10 c:\windows\system32\nwiz.exe]
                      "ftutil2"="ftutil2.dll" [2004-06-07 c:\windows\system32\ftutil2.dll]
                      "AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 c:\windows\arpwrmsg.exe]

                      c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                      HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 288472]
                      TrayMin210.exe.lnk - c:\program files\Philips\Philips SPC210NC Webcam\TrayMin210.exe [2007-06-06 278528]
                      Windows Desktop Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2007-02-05 118784]

                      [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
                      "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                      Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

                      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                      "DisableMonitoring"=dword:00000001

                      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                      "DisableMonitoring"=dword:00000001

                      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                      "DisableMonitoring"=dword:00000001

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                      "EnableFirewall"= 0 (0x0)

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                      "%windir%\\system32\\sessmgr.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
                      "c:\\Program Files\\eMule\\emule.exe"=
                      "c:\\Program Files\\Messenger\\msmsgs.exe"=
                      "c:\\Program Files\\TVUPlayer\\TVUPlayer.exe"=
                      "c:\\Program Files\\TVAnts\\Tvants.exe"=
                      "c:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
                      "c:\\Program Files\\SopCast\\SopCast.exe"=
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                      "c:\\Program Files\\Fichiers communs\\BitDefender\\BitDefender Update Service\\livesrv.exe"=

                      R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-01-25 86792]
                      S2 FILESpy;FILESpy;\??\c:\program files\Softwin\BitDefender9\filespy.sys --> c:\program files\Softwin\BitDefender9\filespy.sys [?]
                      S2 gupdate1c99109e78fbed3;Service Google Update (gupdate1c99109e78fbed3);c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 133104]
                      S3 SG760_XP;SAGEM 802.11g XG760 1211 Driver;c:\windows\system32\drivers\WlanUZXP.sys [2008-12-20 260608]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                      bdx REG_MULTI_SZ scan

                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{381a841a-d73f-11dd-bee7-0018f36f024d}]
                      \Shell\AutoRun\command - f:\wd_windows_tools\Setup.exe

                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c64e4e58-114f-11de-bf36-0018f36f024d}]
                      \Shell\Auto\command - F:\Start.exe
                      \Shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe
                      .
                      Contenu du dossier 'Tâches planifiées'

                      2009-03-25 c:\windows\Tasks\AppleSoftwareUpdate.job
                      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42]

                      2009-04-11 c:\windows\Tasks\Google Software Updater.job
                      - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-22 21:01]

                      2009-03-28 c:\windows\Tasks\GoogleUpdateTaskMachine.job
                      - c:\program files\Google\Update\GoogleUpdate.exe [2009-02-17 16:13]
                      .
                      - - - - ORPHELINS SUPPRIMES - - - -

                      WebBrowser-{A057A204-BACC-4D26-C39E-35F1D2A32EC8} - (no file)
                      HKCU-Run-Configuration de la neuf Box - c:\program files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
                      HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                      HKLM-Run-PCDrProfiler - c:\program files\PC-Doctor 5 for Windows\RunProfiler.exe
                      HKLM-Run-NBKeyScan - c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
                      HKLM-Run-Adobe Photo Downloader - c:\program files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe

                      .
                      ------- Examen supplémentaire -------
                      .
                      uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
                      mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=64&bd=PAVILION&pf=desktop
                      uInternet Connection Wizard,ShellNext = hxxp://www.google.com/support/chrome/bin/request.py?hl=en-US&contact_type=uninstall&crversion=1.0.154.48&os=5.1.2600
                      uSearchURL,(Default) = hxxp://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
                      IE: Liens de téléchargement avec Mega Manager... - c:\program files\Megaupload\Mega Manager\mm_file.htm
                      .

                      **************************************************************************

                      catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2009-04-11 15:37:00
                      Windows 5.1.2600 Service Pack 3 NTFS

                      Recherche de processus cachés ...

                      Recherche d'éléments en démarrage automatique cachés ...

                      Recherche de fichiers cachés ...

                      Scan terminé avec succès
                      Fichiers cachés: 0

                      **************************************************************************
                      .
                      ------------------------ Autres processus actifs ------------------------
                      .
                      c:\program files\Java\jre6\bin\jqs.exe
                      c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
                      c:\windows\system\hpsysdrv.exe
                      .
                      **************************************************************************
                      .
                      Heure de fin: 2009-04-11 15:41:02 - La machine a redémarré
                      ComboFix-quarantined-files.txt 2009-04-11 13:40:40

                      Avant-CF: 81 252 315 136 octets libres
                      Après-CF: 82,951,286,784 octets libres

                      208 --- E O F --- 2009-03-15 09:30:58
                      1. Salut, vu que mon pc est en mode diagnostic l'antivirus ne marche pas. J'ai BitDefender 2008
                        1. Contributeur sécurité
                          salut

                          suit bien les instruction qui vont suivre car la les infections tu les collectionnes

                          Telecharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                          -> Double clique combofix.exe.
                          -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                          -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                          NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                          Avant d'utiliser ComboFix :

                          -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                          -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

                          Une fois fait, sur ton bureau double-clic sur Combofix.exe.

                          - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                          -Attention Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes. risque de figer l'ordi

                          - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                          - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                          -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                          -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

                          !\ Ne touche à rien tant que le scan n'est pas terminé. /!\ : risque de figer l'ordi (plantage complet)

                          ::Si combofix demande a faire mise a jour tu refuse
                          ::Si combofix detecte quelque chose et de demande a redemarer tu accepte
                          1. Salut, voila le rapport

                            [b]SDFix: Version 1.240 [/b]
                            Run by HP_Administrateur on 10/04/2009 at 13:50

                            Microsoft Windows XP [version 5.1.2600]
                            Running From: C:\SDFix

                            [b]Checking Services [/b]:

                            Restoring Default Security Values
                            Restoring Default Hosts File

                            Rebooting

                            [b]Checking Files [/b]:

                            Trojan Files Found:

                            C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\TMP1C.tmp - Deleted

                            Folder C:\VirusGarde - Removed

                            Removing Temp Files

                            [b]ADS Check [/b]:

                            [b]Final Check [/b]:

                            catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2009-04-10 13:58:47
                            Windows 5.1.2600 Service Pack 3 NTFS

                            scanning hidden processes ...

                            scanning hidden services & system hive ...

                            scanning hidden registry entries ...

                            scanning hidden files ...

                            scan completed successfully
                            hidden processes: 0
                            hidden services: 0
                            hidden files: 0

                            [b]Remaining Services [/b]:

                            Authorized Application Key Export:

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                            "C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL France"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
                            "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
                            "C:\\Documents and Settings\\HP_Administrateur\\Local Settings\\Temp\\Rar$EX00.578\\emule.exe"="C:\\Documents and Settings\\HP_Administrateur\\Local Settings\\Temp\\Rar$EX00.578\\emule.exe:*:Disabled:eMule"
                            "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
                            "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                            "C:\\Program Files\\TVUPlayer\\TVUPlayer.exe"="C:\\Program Files\\TVUPlayer\\TVUPlayer.exe:*:Enabled:TVUPlayer Component"
                            "C:\\Program Files\\TVAnts\\Tvants.exe"="C:\\Program Files\\TVAnts\\Tvants.exe:*:Enabled:TVAnts"
                            "C:\\Program Files\\SopCast\\adv\\SopAdver.exe"="C:\\Program Files\\SopCast\\adv\\SopAdver.exe:*:Enabled:SopCast Adver"
                            "C:\\Program Files\\SopCast\\SopCast.exe"="C:\\Program Files\\SopCast\\SopCast.exe:*:Enabled:SopCast Main Application"
                            "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                            "C:\\WINDOWS\\explorer.exe"="C:\\WINDOWS\\explorer.exe:*:Enabled:Explorer"
                            "C:\\Program Files\\Fichiers communs\\BitDefender\\BitDefender Update Service\\livesrv.exe"="C:\\Program Files\\Fichiers communs\\BitDefender\\BitDefender Update Service\\livesrv.exe:*:Enabled:livesrv"
                            "C:\\WINDOWS\\system32\\winlogon.exe"="C:\\WINDOWS\\system32\\winlogon.exe:*:Enabled:winlogon"

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                            "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                            [b]Remaining Files [/b]:

                            File Backups: - C:\SDFix\backups\backups.zip

                            [b]Files with Hidden Attributes [/b]:

                            Fri 22 Jun 2007 211 A.SHR --- "C:\BOOT.BAK"
                            Mon 14 Apr 2008 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
                            Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\biruwuta.dll"
                            Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\bitipote.dll"
                            Thu 26 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\bowafefi.dll"
                            Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\dadopuga.dll"
                            Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\delopeha.dll"
                            Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\dewozuzi.dll"
                            Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\firotapa.dll"
                            Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\fizipime.dll"
                            Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\gakewake.dll"
                            Thu 26 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\gotiyewi.dll"
                            Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\gukevewi.dll"
                            Fri 27 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\hekewufu.dll"
                            Tue 24 Mar 2009 5,297 ..SH. --- "C:\WINDOWS\system32\honimava.dll"
                            Wed 25 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\hujepaka.dll"
                            Thu 26 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\huzitala.dll"
                            Wed 25 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\jedepona.dll"
                            Tue 17 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\jezosudo.dll"
                            Tue 17 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\jobavito.dll"
                            Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\jojesira.dll"
                            Sat 28 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\jonefede.dll"
                            Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\juyimebo.dll"
                            Thu 26 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\kidapita.dll"
                            Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\lasobemo.dll"
                            Tue 24 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\lowopami.dll"
                            Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\malufige.dll"
                            Tue 17 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\minutara.dll"
                            Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\nevibuni.dll"
                            Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\nilejonu.dll"
                            Sat 28 Mar 2009 61,440 A.SH. --- "C:\WINDOWS\system32\notabage.exe"
                            Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\pelozeho.dll"
                            Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\pokefige.dll"
                            Fri 27 Mar 2009 61,440 A.SH. --- "C:\WINDOWS\system32\powipogi.exe"
                            Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\pulemebo.dll"
                            Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\razoriti.dll"
                            Sat 28 Mar 2009 61,440 A.SH. --- "C:\WINDOWS\system32\rojideze.exe"
                            Sat 28 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\rugakeju.dll"
                            Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\rupibemo.dll"
                            Fri 27 Mar 2009 61,440 A.SH. --- "C:\WINDOWS\system32\rusahene.exe"
                            Wed 25 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\ruyebana.dll"
                            Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\sayoroso.dll"
                            Sun 22 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\seratewa.dll"
                            Sun 29 Mar 2009 61,440 A.SH. --- "C:\WINDOWS\system32\serubifa.exe"
                            Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\sikezovo.dll"
                            Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\sogoruro.dll"
                            Tue 17 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\tayufazu.dll"
                            Mon 23 Mar 2009 912 ..SH. --- "C:\WINDOWS\system32\tisawipu.dll"
                            Wed 18 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\vezeyege.dll"
                            Wed 25 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\vodarowo.dll"
                            Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\vosubupa.dll"
                            Fri 20 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\vulabiro.dll"
                            Tue 24 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\yabuvasu.dll"
                            Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\yapigifa.dll"
                            Fri 27 Mar 2009 84,992 A.SH. --- "C:\WINDOWS\system32\yegegeyo.dll"
                            Thu 19 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\yuvukina.dll"
                            Mon 23 Mar 2009 912 ..SH. --- "C:\WINDOWS\system32\yuwegiju.dll"
                            Tue 17 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\zafugiho.dll"
                            Mon 16 Mar 2009 912 A.SH. --- "C:\WINDOWS\system32\zitajalu.dll"
                            Mon 23 Mar 2009 912 ..SH. --- "C:\WINDOWS\system32\zulelolo.dll"
                            Fri 22 Jun 2007 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                            Sun 23 Dec 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
                            Thu 7 Dec 2006 3,096,576 A..H. --- "C:\Documents and Settings\HP_Administrateur\Application Data\U3\temp\Launchpad Removal.exe"

                            [b]Finished![/b]
                            1. Contributeur sécurité
                              salut

                              1) Télécharge SDFix d' AndyManchesta

                              http://downloads.andymanchesta.com/RemovalTools/SDFix.exe sur ton Bureau.

                              Double clique sur SDFix.exe et choisis Install. L'outil sera extrait à la racine du lecteur système (généralement le C:\)

                              N y touche pas pour l instant.

                              2) Redémarre en mode sans échec pour cela (tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter)
                              3) SDFix
                              * Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                              * Appuie sur Y pour commencer le processus de nettoyage.
                              * Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                              * Appuie sur une touche pour redémarrer le PC.
                              * Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                              * Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                              * Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                              · Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                              --------------------------
                              Si SDfix ne se lance pas (ça arrive!)

                              * Démarrer->Exécuter
                              * Copie/colle ceci dans la fenêtre :

                              %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

                              * Clique sur ok, et valide.
                              * Redémarre et essaye de nouveau de lancer SDfix.

                              1. Salut,

                                ça ne fonctionne pas. Un message d'erreur s'affiche:

                                Script: C\DocumentsandSettings\HP_Administrateur\Bureau\GenProc\outils\message.vbs
                                Ligne: 2
                                Caract.: 1
                                Erreur: Le service ne peut être démarré parce qu'il est désactivé ou qu'aucun périphérique activé ne lui est associé
                                Code: 80070422
                                Source: (null)
                                1. Contributeur sécurité
                                  salut

                                  comment sa vide normalement tous ton pc est répertorier a cette endroit

                                  télécharge GenProc http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip sur ton bureau

                                  dézippe le dossier, double-clique sur GenProc.bat et poste le contenu du rapport qui s'ouvre

                                  Aide en images : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
                                  1. Salut

                                    Il n'y a rien qui s'affiche dans le gestionnaire des périphériques, c'est vide...
                                    1. Contributeur sécurité
                                      salut a toi

                                      clic droit sur le raccourcie du poste de travail puis tu clic sur propriété puis tu clic sur matériel et tu fini par gestionnaire de périphérique
                                      • 1
                                      • 2
                                      • 3