Virus

Bonjour,
j'ai un petit souci ou peut-être un gros, j'ai un trojan que je n'arrive pas à supprimer. Je suis sur windows xp. il s'appelle trojan-dropper:w32/vundo.ns. je vous en remercie par avance
Configuration: Windows XP
Firefox 3.0.7

23 réponses

Résumé de la discussion

Un Trojan-dropper signant trojan-dropper:w32/vundo.ns est signalé sur Windows XP avec Firefox 3.0.7, présentant des symptômes d'infection difficiles à éradiquer et nécessitant une approche multiple de suppression et de prévention. Plusieurs conseils techniques apparaissent, notamment l'exécution de MBAM en quarantaine puis suppression, le re-Scan avec RSIT et l'utilisation d'outils comme HijackThis ou GMER pour révéler les entrées cachées. D'autres méthodes évoquées comprennent le relevé et la suppression des clés de registre associées et la surveillance des processus, fichiers et services affectés, afin d'éviter une réinfestation. Des éléments critiques incluent des clés Run et des BHO infectés, et des DLL malicieuses désormais quarantinées ou supprimées pour réduire les risques de réinfection.

Bobot (l’IA à votre service)
  1. Modérateur
    --> Télécharge WinsockXPFix sur ton Bureau.

    --> Double-clique sur WinsockXPFix.exe.
    --> Tout d'abord, clique sur le boutton ReG-Backup. Cela sauvegardera ton registre par précaution.
    --> Clique sur OK, et encore une fois. Tu verras une fenêtre de sauvegarde de ton registre, tu cliqueras une nouvelle fois sur OK.

    --> Retourne à la fenêtre principale.
    --> Clique sur Fix.
    --> Clique sur Yes.
    --> Il se lancera pendant une minute ou deux et un bip se fera entendre et tu verras cette fenêtre.
    --> Finalement, clique sur OK et laisse ton PC redémarrer.
    1. Modérateur
      ---> Supprime les traces de McAfee avec ceci :
      http://download.mcafee.com/products/licensed/cust_support_patches/MCPR.exe

      ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

      ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.

      ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

      ---> Copie (Ctrl+C) le texte suivant ci-dessous :

      :processes
      explorer.exe

      :reg
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
      "AppInit_DLLS"=""
      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
      "Notification Packages"=hex(7):73,00,63,00,65,00,63,00,6c,00,69,00,00,00,00,00

      :commands
      [purity]
      [emptytemp]
      [reboot]

      ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

      ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

      Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
      Accepte en cliquant sur YES.

      ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
      Le nom du rapport correspond au moment de sa création : date_heure.log
      1. salut, je désolé pour hier, mais plus adresse IP et aujourd'hui pareil, je suis sur un autre pc, mais je te remerci pour ta patience, merci de ta compréhention
    2. Logfile of random's system information tool 1.06 (written by random/random)
      Run by oussin at 2009-03-27 18:37:47
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 119 GB (78%) free of 153 GB
      Total RAM: 1023 MB (35% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 18:38:07, on 27/03/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16791)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\WINDOWS\vVX1000.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Microsoft IntelliType Pro\itype.exe
      C:\Program Files\Microsoft IntelliPoint\ipoint.exe
      C:\Program Files\SFR\Pack Sécurité\Common\FSM32.EXE
      C:\Program Files\Windows Live\Family Safety\fsui.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      c:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
      C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
      C:\Program Files\SFR\Pack Sécurité\Anti-Virus\FSGK32.EXE
      C:\Program Files\Windows Live\Family Safety\fsssvc.exe
      C:\Program Files\SFR\Pack Sécurité\Common\FSMB32.EXE
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
      C:\Program Files\SFR\Pack Sécurité\Common\FCH32.EXE
      C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
      C:\Program Files\SFR\Pack Sécurité\Common\FAMEH32.EXE
      C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsqh.exe
      C:\Program Files\SFR\Pack Sécurité\FSPC\fspc.exe
      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      C:\Program Files\SFR\Pack Sécurité\FSGUI\fsguidll.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsaua.exe
      C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fssm32.exe
      C:\Program Files\SFR\Pack Sécurité\FWES\Program\fsdfwd.exe
      C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsav32.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsus.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Documents and Settings\oussin\Bureau\RSIT.exe
      C:\Program Files\trend micro\oussin.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.search.yahoo.com/search?fr=mcafee&p=%s
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
      O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
      O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
      O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S101.tmp" /EF "HKLM"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
      O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
      O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\SFR\Pack Sécurité\Common\FSM32.EXE" /splash
      O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\SFR\Pack Sécurité\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\SFR\Pack Sécurité\FSPC\fspcmsie.dll
      O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\SFR\Pack Sécurité\FSPC\fspcmsie.dll
      O9 - Extra 'Tools' menuitem: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\SFR\Pack Sécurité\FSPC\fspcmsie.dll
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
      O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
      O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - http://fichiers.touslesdrivers.com/...
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/...
      O20 - AppInit_DLLs: c:\windows\system32\divosimu.dll,C:\WINDOWS\system32\weyagiba.dll
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe
      O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
      O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsaua.exe
      O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\FWES\Program\fsdfwd.exe
      O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
      O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\ORSP Client\fsorsp.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Wireless Network Security Service (MWLSvc) - Unknown owner - C:\Program Files\Mcafee\MWL\MwlSvc.exe (file missing)
      1. Modérateur
        --> Double-clique sur RSIT.exe afin de lancer le programme.
        (Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)

        --> Clique sur Continue à l'écran Disclaimer.

        --> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

        --> Lorsque l'analyse sera terminée, poste le contenu de log.txt.

        Note : les rapports sont sauvegardés dans le dossier C:\rsit.
        1. catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
          http://www.gmer.net

          scanning hidden processes ...

          scanning hidden services ...

          scanning hidden autostart entries ...

          scanning hidden files ...

          scan completed successfully
          hidden processes: 0
          hidden services: 0
          hidden files: 0
          1. Malwarebytes' Anti-Malware 1.35
            Version de la base de données: 1905
            Windows 5.1.2600 Service Pack 3

            27/03/2009 18:29:13
            mbam-log-2009-03-27 (18-29-13).txt

            Type de recherche: Examen rapide
            Eléments examinés: 89716
            Temps écoulé: 12 minute(s), 19 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 0

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            (Aucun élément nuisible détecté)
            1. Modérateur
              ---> Relance MBAM, va dans Quarantaine et supprime tout.

              ---> Refais un scan RSIT et poste le rapport log.
              1. catchme 0.2 W2K/XP/Vista - userland rootkit detector by Gmer, 17 October 2006
                http://www.gmer.net

                scanning hidden processes ...

                scanning hidden services ...

                scanning hidden autostart entries ...

                scanning hidden files ...

                scan completed successfully
                hidden processes: 0
                hidden services: 0
                hidden files: 0
                1. Modérateur
                  --> Télécharge CatchMe (Przemyslaw Gmerek) sur ton Bureau.
                  --> Double-clique sur catchme.exe (le .exe n'est pas forcément visible) afin de le lancer.
                  --> Lorsque la recherche sera terminée, poste le rapport catchme.log dans ta prochaine réponse. (Ce rapport est sur ton Bureau.)
                  1. Malwarebytes' Anti-Malware 1.35
                    Version de la base de données: 1905
                    Windows 5.1.2600 Service Pack 3

                    27/03/2009 17:36:13
                    mbam-log-2009-03-27 (17-36-13).txt

                    Type de recherche: Examen rapide
                    Eléments examinés: 89425
                    Temps écoulé: 10 minute(s), 36 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 0
                    Valeur(s) du Registre infectée(s): 0
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 3

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Valeur(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    C:\WINDOWS\system32\drivers\ovfsth.sys (Trojan.Agent) -> Quarantined and deleted successfully.
                    C:\WINDOWS\system32\ovfsthvvseyihdgxjdwnobfqruxhyegspludkg.dat (Trojan.Agent) -> Quarantined and deleted successfully.
                    C:\WINDOWS\system32\ovfsthyypyhvypesbtevtalgrpgudjfgvoamgp.dat (Trojan.Agent) -> Quarantined and deleted successfully.
                    1. Malwarebytes' Anti-Malware 1.35
                      Version de la base de données: 1905
                      Windows 5.1.2600 Service Pack 3

                      27/03/2009 17:19:43
                      mbam-log-2009-03-27 (17-19-43).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 89876
                      Temps écoulé: 4 minute(s), 52 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 12
                      Valeur(s) du Registre infectée(s): 5
                      Elément(s) de données du Registre infecté(s): 1
                      Dossier(s) infecté(s): 1
                      Fichier(s) infecté(s): 9

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{66d7c1a0-8c9e-4cbc-851f-6d168ff2f2c2} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\CLSID\{66d7c1a0-8c9e-4cbc-851f-6d168ff2f2c2} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{6c51f7e9-8542-4f25-a30f-2060157752e1} (Trojan.Downloader) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Interface\{9d573d0e-663c-435f-bf31-2c4497373c41} (Trojan.Downloader) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\Typelib\{90a52f08-64ac-4dc6-9d7d-4516670275d3} (Trojan.Downloader) -> Quarantined and deleted successfully.
                      HKEY_CLASSES_ROOT\AppID\{90a52f08-64ac-4dc6-9d7d-4516670275d3} (Trojan.Downloader) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Trojan.Agent) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

                      Valeur(s) du Registre infectée(s):
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\c03a92b5 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpmc309a129 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yabavoworo (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.

                      Elément(s) de données du Registre infecté(s):
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                      Dossier(s) infecté(s):
                      C:\WINDOWS\system32\kazaabackupfiles (Worm.Archive) -> Quarantined and deleted successfully.

                      Fichier(s) infecté(s):
                      C:\WINDOWS\system32\joxdyleb.0xe (Backdoor.Bot) -> Quarantined and deleted successfully.
                      C:\WINDOWS\system32\nesavina.0ll (Trojan.Vundo) -> Quarantined and deleted successfully.
                      C:\WINDOWS\system32\habpqrmi.0xe (Backdoor.Bot) -> Quarantined and deleted successfully.
                      C:\WINDOWS\system32\mubodigi.0ll (Trojan.Vundo) -> Quarantined and deleted successfully.
                      C:\WINDOWS\system32\KazaaBackupFiles\shServ.0xe (Backdoor.Bot) -> Quarantined and deleted successfully.
                      C:\WINDOWS\system32\ovfsthddlpvyoxoxxiuxbjygexqohrmjsnfohh.dll (Trojan.Agent) -> Delete on reboot.
                      C:\WINDOWS\system32\ovfsthtowqbobetgyknigrnxmthpiitfehaijb.dll (Trojan.Agent) -> Delete on reboot.
                      C:\WINDOWS\system32\ovfsthxdxfeqomkixmbdpnkxldsxiduygclmon.dll (Trojan.Agent) -> Delete on reboot.
                      C:\WINDOWS\system32\drivers\ovfsthojpjemwuyfjteeqmrfkulwayvtkwrajg.sys (Trojan.Agent) -> Quarantined and deleted successfully.
                      1. Modérateur
                        ---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
                        ---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
                        ---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
                        ---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
                        ---> Sélectionne Exécuter un examen rapide.
                        ---> Clique sur Rechercher. L'analyse démarre.

                        A la fin de l'analyse, un message s'affiche :

                        L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

                        ---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
                        ---> Ferme tes navigateurs.
                        Si des malwares ont été détectés, clique sur Afficher les résultats.
                        ---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
                        ---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
                        1. excuse-moi j'ai été déconnecté voici le rapport
                          ========== PROCESSES ==========
                          Process explorer.exe killed successfully.
                          ========== FILES ==========
                          C:\WINDOWS\system32\ulolamub.ini moved successfully.
                          C:\WINDOWS\system32\vfhr.exe moved successfully.
                          C:\WINDOWS\IEXPOLES.exe moved successfully.
                          C:\syx23x.exe moved successfully.
                          C:\sysx.exe moved successfully.
                          C:\saxy.exe moved successfully.
                          C:\WINDOWS\system32\303369.exe moved successfully.
                          C:\dfssz.exe moved successfully.
                          C:\RESTORE\S-1-5-21-1482476501-1644491937-682003330-1013 moved successfully.
                          C:\RESTORE moved successfully.
                          DllUnregisterServer procedure not found in C:\WINDOWS\system32\lconqh.dll
                          C:\WINDOWS\system32\lconqh.dll NOT unregistered.
                          C:\WINDOWS\system32\lconqh.dll moved successfully.
                          C:\dfss.exe moved successfully.
                          C:\bmf.exe moved successfully.
                          C:\WINDOWS\system32\dowigemu.exe moved successfully.
                          DllUnregisterServer procedure not found in C:\WINDOWS\system32\divosimu.dll
                          C:\WINDOWS\system32\divosimu.dll NOT unregistered.
                          C:\WINDOWS\system32\divosimu.dll moved successfully.
                          DllUnregisterServer procedure not found in C:\WINDOWS\system32\bumalolu.dll
                          C:\WINDOWS\system32\bumalolu.dll NOT unregistered.
                          C:\WINDOWS\system32\bumalolu.dll moved successfully.
                          C:\WINDOWS\system32\nlzbxp.exe moved successfully.
                          DllUnregisterServer procedure not found in C:\WINDOWS\system32\lotuluba.dll
                          C:\WINDOWS\system32\lotuluba.dll NOT unregistered.
                          C:\WINDOWS\system32\lotuluba.dll moved successfully.
                          DllUnregisterServer procedure not found in C:\WINDOWS\system32\jumayiya.dll
                          C:\WINDOWS\system32\jumayiya.dll NOT unregistered.
                          C:\WINDOWS\system32\jumayiya.dll moved successfully.
                          File/Folder C:\WINDOWS\system32\nesavina.dll not found.
                          File/Folder c:\windows\system32\hariviza.dll not found.
                          DllUnregisterServer procedure not found in C:\WINDOWS\system32\weyagiba.dll
                          C:\WINDOWS\system32\weyagiba.dll NOT unregistered.
                          C:\WINDOWS\system32\weyagiba.dll moved successfully.
                          ========== REGISTRY ==========
                          Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\WINDOWS\system32\nlzbxp.exe deleted successfully.
                          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"Notification Packages"|hex(7):73,00,63,00,65,00,63,00,6c,00,69,00,00,00,00,00 /E : value set successfully!
                          ========== COMMANDS ==========
                          File delete failed. C:\DOCUME~1\oussin\LOCALS~1\Temp\etilqs_1Dpt47AdtD6Wd6Gm5xmD scheduled to be deleted on reboot.
                          File delete failed. C:\DOCUME~1\oussin\LOCALS~1\Temp\~DFD9D1.tmp scheduled to be deleted on reboot.
                          User's Temp folder emptied.
                          User's Temporary Internet Files folder emptied.
                          User's Internet Explorer cache folder emptied.
                          Local Service Temp folder emptied.
                          Local Service Temporary Internet Files folder emptied.
                          File delete failed. C:\WINDOWS\temp\nvcbin.def.76167175.TMP scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_14c.dat scheduled to be deleted on reboot.
                          Windows Temp folder emptied.
                          Java cache emptied.
                          File delete failed. C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                          File delete failed. C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\XUL.mfl scheduled to be deleted on reboot.
                          FireFox cache emptied.
                          Temp folders emptied.

                          OTMoveIt3 by OldTimer - Version 1.0.9.0 log created on 03272009_163517

                          Files moved on Reboot...
                          File C:\DOCUME~1\oussin\LOCALS~1\Temp\etilqs_1Dpt47AdtD6Wd6Gm5xmD not found!
                          C:\DOCUME~1\oussin\LOCALS~1\Temp\~DFD9D1.tmp moved successfully.
                          File move failed. C:\WINDOWS\temp\nvcbin.def.76167175.TMP scheduled to be moved on reboot.
                          File C:\WINDOWS\temp\Perflib_Perfdata_14c.dat not found!
                          C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\Cache\_CACHE_001_ moved successfully.
                          C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\Cache\_CACHE_002_ moved successfully.
                          C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\Cache\_CACHE_003_ moved successfully.
                          C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\Cache\_CACHE_MAP_ moved successfully.
                          C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\urlclassifier3.sqlite moved successfully.
                          C:\Documents and Settings\oussin\Local Settings\Application Data\Mozilla\Firefox\Profiles\6czq7cqo.default\XUL.mfl moved successfully.
                          1. Modérateur
                            1/

                            ---> Lance ce fichier : C:\Program Files\trend micro\oussin.exe

                            ---> Choisis Do a system scan only.

                            ---> Coche les cases qui sont devant les lignes suivantes :

                            O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

                            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

                            O2 - BHO: (no name) - {66d7c1a0-8c9e-4cbc-851f-6d168ff2f2c2} - C:\WINDOWS\system32\jumayiya.dll

                            O2 - BHO: {87853ce8-898e-1939-f2f4-29b6768e9796} - {6979e867-6b92-4f2f-9391-e8988ec35878} - C:\WINDOWS\system32\lconqh.dll

                            O4 - HKLM\..\Run: [Microsoft Update] SVCHOSTS.EXE

                            O4 - HKLM\..\Run: [System Restore] IEXPOLES.exe

                            O4 - HKLM\..\Run: [Windows Layer] nlzbxp.exe

                            O4 - HKLM\..\Run: [yabavoworo] Rundll32.exe "C:\WINDOWS\system32\lotuluba.dll",s

                            O4 - HKLM\..\Run: [c03a92b5] rundll32.exe "C:\WINDOWS\system32\bumalolu.dll",b

                            O4 - HKLM\..\Run: [CPMc309a129] Rundll32.exe "C:\WINDOWS\system32\divosimu.dll",a

                            O4 - HKLM\..\RunServices: [Windows Layer] nlzbxp.exe

                            O4 - HKCU\..\Run: [Windows Layer] nlzbxp.exe

                            O20 - AppInit_DLLs: c:\windows\system32\hariviza.dll C:\WINDOWS\system32\nesavina.dll C:\WINDOWS\system32\weyagiba.dll c:\windows\system32\divosimu.dll

                            O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\divosimu.dll

                            O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\divosimu.dll

                            ---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.

                            ---> Ferme HijackThis.

                            2/

                            ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

                            ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau.

                            ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                            ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                            :processes
                            explorer.exe

                            :files
                            C:\WINDOWS\system32\ulolamub.ini
                            C:\WINDOWS\system32\vfhr.exe
                            C:\WINDOWS\IEXPOLES.exe
                            C:\syx23x.exe
                            C:\sysx.exe
                            C:\saxy.exe
                            C:\WINDOWS\system32\303369.exe
                            C:\dfssz.exe
                            C:\RESTORE
                            C:\WINDOWS\system32\lconqh.dll
                            C:\dfss.exe
                            C:\bmf.exe
                            C:\WINDOWS\system32\dowigemu.exe
                            C:\WINDOWS\system32\divosimu.dll
                            C:\WINDOWS\system32\bumalolu.dll
                            C:\WINDOWS\system32\nlzbxp.exe
                            C:\WINDOWS\system32\lotuluba.dll
                            C:\WINDOWS\system32\jumayiya.dll
                            C:\WINDOWS\system32\nesavina.dll
                            c:\windows\system32\hariviza.dll
                            C:\WINDOWS\system32\weyagiba.dll

                            :reg
                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                            "C:\WINDOWS\system32\nlzbxp.exe"=-
                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
                            "Notification Packages"=hex(7):73,00,63,00,65,00,63,00,6c,00,69,00,00,00,00,00

                            :commands
                            [purity]
                            [emptytemp]
                            [reboot]

                            ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                            ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                            Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                            Accepte en cliquant sur YES.

                            ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                            Le nom du rapport correspond au moment de sa création : date_heure.log
                            1. Logfile of random's system information tool 1.06 (written by random/random)
                              Run by oussin at 2009-03-27 15:52:56
                              Microsoft Windows XP Édition familiale Service Pack 3
                              System drive C: has 119 GB (78%) free of 153 GB
                              Total RAM: 1023 MB (36% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 15:54:36, on 27/03/2009
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16791)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
                              C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
                              C:\Program Files\SFR\Pack Sécurité\Anti-Virus\FSGK32.EXE
                              C:\Program Files\Java\jre6\bin\jqs.exe
                              C:\Program Files\SFR\Pack Sécurité\Common\FSMB32.EXE
                              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                              C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
                              C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                              C:\Program Files\SFR\Pack Sécurité\Common\FCH32.EXE
                              c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
                              C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                              C:\Program Files\SFR\Pack Sécurité\Common\FAMEH32.EXE
                              C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsqh.exe
                              C:\Program Files\SFR\Pack Sécurité\FSPC\fspc.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsaua.exe
                              C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fssm32.exe
                              C:\Program Files\SFR\Pack Sécurité\FWES\Program\fsdfwd.exe
                              C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsus.exe
                              C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsav32.exe
                              C:\WINDOWS\system32\wbem\wmiapsrv.exe
                              C:\WINDOWS\AGRSMMSG.exe
                              C:\WINDOWS\SOUNDMAN.EXE
                              C:\WINDOWS\vVX1000.exe
                              C:\Program Files\Java\jre6\bin\jusched.exe
                              C:\Program Files\Microsoft IntelliType Pro\itype.exe
                              C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                              C:\Program Files\SFR\Pack Sécurité\Common\FSM32.EXE
                              C:\WINDOWS\IEXPOLES.exe
                              C:\WINDOWS\system32\nlzbxp.exe
                              C:\Program Files\SFR\Pack Sécurité\FSGUI\fsguidll.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\WINDOWS\System32\svchost.exe
                              c:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
                              C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Windows Live\Contacts\wlcomm.exe
                              C:\WINDOWS\system32\rundll32.exe
                              C:\Program Files\Windows Live\Toolbar\wltuser.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Documents and Settings\oussin\Bureau\RSIT.exe
                              C:\Program Files\trend micro\oussin.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.search.yahoo.com/search?fr=mcafee&p=%s
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: (no name) - {66d7c1a0-8c9e-4cbc-851f-6d168ff2f2c2} - C:\WINDOWS\system32\jumayiya.dll
                              O2 - BHO: {87853ce8-898e-1939-f2f4-29b6768e9796} - {6979e867-6b92-4f2f-9391-e8988ec35878} - C:\WINDOWS\system32\lconqh.dll
                              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                              O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptsn.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
                              O2 - BHO: McAfee Popup Blocker - {C68AE9C0-0909-4DDC-B661-C1AFB9F5AE53} - (no file)
                              O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                              O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                              O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                              O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
                              O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
                              O4 - HKLM\..\Run: [EPSON Stylus DX4000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBEE.EXE /FU "C:\WINDOWS\TEMP\E_S101.tmp" /EF "HKLM"
                              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [itype] "c:\Program Files\Microsoft IntelliType Pro\itype.exe"
                              O4 - HKLM\..\Run: [IntelliPoint] "c:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                              O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                              O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\SFR\Pack Sécurité\Common\FSM32.EXE" /splash
                              O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\SFR\Pack Sécurité\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [Microsoft Update] SVCHOSTS.EXE
                              O4 - HKLM\..\Run: [System Restore] IEXPOLES.exe
                              O4 - HKLM\..\Run: [Windows Layer] nlzbxp.exe
                              O4 - HKLM\..\Run: [yabavoworo] Rundll32.exe "C:\WINDOWS\system32\lotuluba.dll",s
                              O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                              O4 - HKLM\..\Run: [c03a92b5] rundll32.exe "C:\WINDOWS\system32\bumalolu.dll",b
                              O4 - HKLM\..\Run: [CPMc309a129] Rundll32.exe "C:\WINDOWS\system32\divosimu.dll",a
                              O4 - HKLM\..\RunServices: [Windows Layer] nlzbxp.exe
                              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [Windows Layer] nlzbxp.exe
                              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                              O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                              O9 - Extra button: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Program Files\SFR\Pack Sécurité\FSPC\fspcmsie.dll
                              O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\SFR\Pack Sécurité\FSPC\fspcmsie.dll
                              O9 - Extra 'Tools' menuitem: Parental... - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Program Files\SFR\Pack Sécurité\FSPC\fspcmsie.dll
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
                              O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
                              O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} (NVIDIA Smart Scan) - https://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab
                              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
                              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://sdlc-esd.sun.com/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?AuthParam=1232635260_bd98eec91bec693c1bc1cb5edd772320&GroupName=JSC&FilePath=/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab&File=jinstall-6u11-windows-i586-jc.cab&BHost=javadl.sun.com
                              O20 - AppInit_DLLs: c:\windows\system32\hariviza.dll C:\WINDOWS\system32\nesavina.dll C:\WINDOWS\system32\weyagiba.dll c:\windows\system32\divosimu.dll
                              O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\divosimu.dll
                              O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\divosimu.dll
                              O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                              O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe
                              O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
                              O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\FSAUA\program\fsaua.exe
                              O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\FWES\Program\fsdfwd.exe
                              O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
                              O23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\SFR\Pack Sécurité\ORSP Client\fsorsp.exe
                              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                              O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
                              O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                              O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
                              O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
                              O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                              O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                              O23 - Service: McAfee Wireless Network Security Service (MWLSvc) - Unknown owner - C:\Program Files\Mcafee\MWL\MwlSvc.exe (file missing)
                              • 1
                              • 2