Impossible de télécharger

Résolu
Bonjour,
Avast a détecté un cheval de troie, pendant plusieurs jours à chaque fois que j'alumais l'ordi il était détecté malgré les mise en quarantaine et supprimé. J'ai usé de programme comme hijackthis , toolscleanner et malwarebytes. maintenant je me retrouve avec 2 problèmes.
le premier est la perte de mon lecteur/graveur. Quand j'alume l'ordi windoos m'informe qu il y a un nouveau matériel derectéet demande un CD d'intalation mais comme le CD n'est pas lu...
Ensuite je ne peut plus télécharger des programmes; exemple je télécharge navilog, je lance navilog, je choisi la langue et plus rien ou alors hier j'ai essayé de télécharger fixcd j'ai eu que l'info de la configuration .
merci de votre aide
Configuration: Windows XP Internet Explorer 7.0

29 réponses

Résumé de la discussion

Le fil décrit une infection présumée par cheval de Troie détectée par Avast, associée à des dysfonctionnements matériels et à des messages d’installation de CD/DVD non reconnus. Les symptômes incluent la perte du lecteur/graveur, l’impossibilité de lire les CD, et l’impossibilité de télécharger ou d’installer des programmes sous Windows XP et Internet Explorer 7. Plusieurs répondants suggèrent des diagnostics et remèdes variés, notamment des scans en ligne, des manipulations du disque dur, des vérifications de connexions et l’emploi de Combofix et HijackThis. En cas de résultat contrasté, la suite proposée inclut une vérification matérielle et des analyses approfondies pour isoler les éléments indésirables et évaluer l’état du disque.

Bobot (l’IA à votre service)
  1. voilà tout est ok maintenant, encore merci pour ton aide
    0
    1. Contributeur
      Bonsoir,

      très bien si c'est ok :)

      Pas de soucis de compatibilité mais attention à la multiplication des logiciels de protection, cela paut engendrer plus de soucis qu'autres choses.

      Pour la pare-feu soit tu garde celui de Windows ou soit tu en utilise un gratuitement, regarde pour ZoneAlarm
      http://www.swl1f.net/viewtopic.php?f=14&t=178&sid=c3847d3bb0d9c9256e4926d49d2cdbf1

      @+
      0
      1. j'ai pu télécharger le diver JMICRON 36X RAID et cala marche. j'avais bien fait une mauvaise manip.

        Malwarebytes et Spyware Terminator sont ils comptibless avec AVAST?
        Je n'ai que le pare feu de windoos a moins que la livebox de orange ait un autre pare feu.

        Merci pour ton aide
        0
        1. oui, j'ai même branché un ancien dvd. je vais peut être faire contrôler la carte mère.
          0
          1. Contributeur
            je ne sais pas trop, as tu vérifié les connexions ?
            0
            1. Je n'ai pas de DVD/CD Rom driver qui apparait.
              J'ai un point d'exclamation sur controleur IDE
              0
              1. Contributeur
                il te faut vérifier tes drivers

                fait Clique droit sur le pose de travail > Gérer > Gestionnaire de périphériques > une fois que tu as cliqué sur Gestionnaire de périphériques regarde dans la colonne de droite et dit moi si tu as un point d'interrogation ou d'exclamation sur DVD/CD-Rom drivers.
                0
                1. bonsoir ep44
                  Après avoir lancer toolscleaner2 le bureau n'a pas disparu.

                  LE dernier soucis est le lecteur CD, le pc ne le reconnait toujours pas. Quand je redémare le PC, il reconnait un nouveau matériel, me demande d'inserer le CD mais dans le poste de travail il n'y a plus de lecteur reconnu. Par contre si je place une cle USB , elle est reconnue
                  0
                  1. Contributeur
                    Bonsoir,

                    Dommage pour bitdefender,

                    si plus de soucis

                    Télécharge ATF Cleaner par Atribune. <== Tu pourras garder ce logiciel pour une utilisation régulière.
                    http://www.atribune.org/ccount/click.php?id=1

                    Double-clique ATF-Cleaner.exe afin de lancer le programme.
                    Sous l'onglet Main, choisis : Select All
                    Clique sur le bouton Empty Selected

                    Si tu utilises le navigateur Firefox :

                    Clique Firefox au haut et choisis : Select All
                    Clique le bouton Empty Selected
                    NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

                    Si tu utilises le navigateur Opera :


                    Clique Opera au haut et choisis : Select All
                    Clique le bouton Empty Selected
                    NOTE : Si tu veux conserver tes mots de passe sauvegardés, clique No à l'invite.

                    Clique Exit, du menu principal, afin de fermer le programme.
                    Pour obtenir du Support technique, double-clique l'adresse électronique située au bas de chacun des menus.

                    ensuite ce logiciel va t'aider a supprimer les outils utiliser

                    Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.
                    http://pc-system.fr/

                    Double clique sur ToolsCleaner2.exe >
                    puis Recherche
                    et sur Suppression
                    Note : ton bureau va disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

                    CTRL+ALT+SUPP
                    pour ouvrir le Gestionnaire des tâches.
                    Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

                    Tape explorer.exe et valide. Cela fera re-apparaître le Bureau

                    ensuite fait ceci (IMPORTANT)

                    * Désactivation :

                    Cliquer droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > cocher la case "Désactiver la Restauration du système sur tous les lecteurs"
                    > Appliquer patiente jusqu a que cela soit marqué "désactivée" puis Ok.

                    * Activation :
                    Suivre le même chemin ; décocher la case "Désactiver la Restauration du système sur tous les lecteurs"
                    > Appliquer attends que cela soit a nouveau sur "surveillance" puis Ok. Redémarrer l'ordinateur..

                    Pense aussi à faire tes mises à jours régulièrement

                    Windows update : ==> ici =>http://www.update.microsoft.com/windowsupdate/v6/default.aspx
                    Java : ==> ici => https://www.java.com/fr/download/

                    Ces mises à jours sont très importantes pour la sécurité de ton PC.

                    N'installe qu'un seul parefeu !!
                    et bien sur qu'un antivirus

                    N'oublie pas de faire régulièrement les mises à jour de tes logiciels avant chaque scan.

                    * Tu peux aussi utiliser ces logiciels de sécurité

                    Malwarebytes => C'est un anti-malwares gratuit et en français, tu devras une fois installer le lancer périodiquement pour contrôler ton PC.
                    Un tuto pour le télécharger et son installation => Ici => http://www.swl1f.net/viewtopic.php?f=14&t=68

                    Spyware Terminator => C'est un anti-spyware gratuit et en français, Il travaillera automatiquement grâce à son module résident, tu pourras le programmer pour effectuer un scan journalier.
                    Un tuto pour le télécharger et son installation => Ici => http://www.swl1f.net/viewtopic.php?f=14&t=66

                    * Ensuite quelques conseils
                    L'infection de ton pc peut se faire de différente façon, voici en quelques lignes plusieurs points à éviter. ==> ici =>http://www.swl1f.net/viewtopic.php?f=14&t=67

                    * le navigateur

                    Essaye le navigateur Firefox plus sur/securisé qu IE
                    Firefox n'utilise pas le dangereux protocole ActiveX
                    * Téléchargement: ==> Firefox => http://www.mozilla-europe.org/fr/products/firefox/
                    * Tutorial pour le sécuriser: ==> ici =>https://forum.zebulon.fr/topic/69628-s%C3%A9curiser-un-peu-plus-firefox/

                    Important
                    Surfez avec les droits administrateurs sur le net te rend vulnérable, il faut donc utiliser un autre compte que celui de l'administrateur


                    * Pour que ton pc retrouve un peu de jeunesse
                    * Pense a lancer une petite défragmentation.
                    * Utilise CCleaner régulièrement.
                    * Gère tes services grâce a ces 2 liens
                    ==> ici => http://speedweb1.free.fr/frames2.php?page=service3 et ==> ici => http://speedweb1.free.fr/frames2.php?page=service4
                    * Utilise Zeb Utility
                    une application ne nécessitant pas d’installation, pour optimiser un poil ton pc. (merci a l ami Zebulon)
                    Téléchargement : ==> ici ==> https://www.zebulon.fr/telechargements/utilitaires/optimisation/zeb-utility.html
                    Tuto : ==> ici => https://www.zebulon.fr/dossiers/autres/58-zebutility.html

                    Et pour finir

                    Dénonce ton infection pour faire condamner les auteurs.

                    Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être les plus nombreux possibles, alors rends compte de ton infection

                    - Voir les règles du forum : ==> ici => https://malwarecomplaints.info/
                    - Après t'être enregistré à l'aide du bouton en haut se nommant "Register"
                    Si tu as plus de 13 ans, choisir : "I Agree to these terms and am over or exactly 13 years of age"
                    Si tu as moins, clique sur : "I Agree to these terms and am under 13 years of age"

                    Tu as alors sous forme de liste un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).

                    * malwarecomplaints => https://malwarecomplaints.info/

                    Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), crée un message dans le sujet Autres infections
                    conforme au règle du forum (age, ville, département etc..)

                    Indique aussi le nom du Forum qui t'a aidé

                    * Tuto => http://www.malekal.com/malwarecomplaints.html

                    @+

                    0
                    1. bonsoir,
                      Mon pc semble bien se comporter. je viens de télécharger une musique sur jamendo, c'est OK.

                      Je viens d'utiliser bitdefender mais je n'ai pas de rapport du scan, je dois mal l'utiliser.
                      0
                      1. bonsoir
                        voici le rapport de Navilog

                        Fix Navipromo version 4.0.1 commencé le 10/08/2009 23:21:42,12

                        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                        !!! Postez ce rapport sur le forum pour le faire analyser !!!

                        Outil exécuté depuis C:\Program Files\navilog1

                        Mise à jour le 18.07.2009 à 11h00 par IL-MAFIOSO

                        Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
                        X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU 6300 @ 1.86GHz )
                        BIOS : Phoenix - AwardBIOS v6.00PG
                        USER : Helen ( Administrator )
                        BOOT : Normal boot

                        Antivirus : avast! antivirus 4.8.1335 [VPS 090809-0] 4.8.1335 (Activated)

                        C:\ (Local Disk) - NTFS - Total:78 Go (Free:24 Go)
                        E:\ (Local Disk) - NTFS - Total:154 Go (Free:89 Go)

                        Recherche executée en mode normal

                        Nettoyage exécuté au redémarrage de l'ordinateur

                        C:\Documents and Settings\All Users\menudm~1\progra~1\Live-Player supprimé !
                        C:\Documents and Settings\Helen\locals~1\applic~1\Live-Player supprimé !

                        Nettoyage contenu C:\WINDOWS\Temp effectué !
                        Nettoyage contenu C:\Documents and Settings\Helen\locals~1\Temp effectué !

                        *** Sauvegarde du Registre vers dossier Safebackup ***

                        sauvegarde du Registre réalisée avec succès !

                        *** Nettoyage Registre ***

                        Nettoyage Registre Ok

                        *** Scan terminé 10/08/2009 23:30:15,07 ***
                        0
                        1. Contributeur
                          Bonsoir,

                          oui lance navilog et poste le rapport

                          @+
                          0
                          1. Navilog semble fonctionner.
                            Je vais jusqu'a la selection recherche/désinfection automatique.
                            faut-il que je le selectionne?
                            0
                            1. ComboFix 09-08-09.03 - Helen 09/08/2009 22:52.6.2 - NTFSx86
                              Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1022.499 [GMT 2:00]
                              Running from: c:\documents and settings\Helen\Bureau\combofix.exe
                              Command switches used :: c:\documents and settings\Helen\Bureau\CFScript.txt
                              AV: avast! antivirus 4.8.1335 [VPS 090807-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

                              WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

                              FILE ::
                              "c:\documents and settings\helen\local settings\application data\ucayy.exe"
                              .

                              ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              c:\program files\Live-Player
                              c:\program files\Live-Player\data\translation_file_live-player.xml
                              c:\program files\Live-Player\SkinCrafterDll.dll
                              c:\program files\Live-Player\skins\live-player.skf
                              c:\program files\Live-Player\sqlite3.dll
                              c:\program files\Live-Player\uninst.exe

                              .
                              ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              -------\Service_soqwx32

                              ((((((((((((((((((((((((( Files Created from 2009-07-09 to 2009-08-09 )))))))))))))))))))))))))))))))
                              .

                              2009-08-09 10:02 . 2009-08-09 10:02 -------- d-----w- c:\program files\Navilog1
                              2009-08-09 09:24 . 2009-08-09 09:24 -------- d-----w- C:\rsit
                              2009-08-03 16:22 . 2009-08-03 16:22 -------- d-sh--w- c:\documents and settings\Helen\IECompatCache
                              2009-07-26 07:52 . 2009-07-27 20:48 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

                              .
                              (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2009-08-09 21:00 . 2007-02-09 12:37 -------- d-----w- c:\program files\Wanadoo
                              2009-08-09 20:30 . 2006-03-02 12:00 89048 ----a-w- c:\windows\system32\perfc00C.dat
                              2009-08-09 20:30 . 2006-03-02 12:00 499492 ----a-w- c:\windows\system32\perfh00C.dat
                              2009-08-09 09:24 . 2009-01-02 01:27 -------- d-----w- c:\program files\trend micro
                              2009-08-07 09:31 . 2007-02-07 16:04 -------- d--h--w- c:\program files\InstallShield Installation Information
                              2009-08-07 09:30 . 2007-11-14 23:46 -------- d-----w- c:\program files\eMule
                              2009-08-07 07:14 . 2009-08-07 07:16 242298 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1036.dat
                              2009-07-30 08:15 . 2008-03-29 20:56 -------- d-----w- c:\program files\Azureus
                              2009-07-30 08:14 . 2008-03-29 20:56 -------- d-----w- c:\documents and settings\Helen\Application Data\Azureus
                              2009-07-03 16:57 . 2006-03-02 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
                              2009-06-16 14:40 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
                              2009-06-16 14:40 . 2006-03-02 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
                              2009-06-11 08:05 . 2008-10-09 18:10 -------- d-----w- c:\program files\e-Carte Bleue LCL
                              2009-06-03 19:10 . 2006-03-02 12:00 1297408 ----a-w- c:\windows\system32\quartz.dll
                              2009-05-17 09:44 . 2009-05-17 09:44 278728 ----a-w- c:\windows\system32\drivers\atksgt.sys
                              2009-05-17 09:44 . 2009-05-17 09:44 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys
                              .

                              ((((((((((((((((((((((((((((( SnapShot@2009-08-09_12.10.25 )))))))))))))))))))))))))))))))))))))))))
                              .
                              + 2009-08-09 20:57 . 2009-08-09 20:57 16384 c:\windows\Temp\Perflib_Perfdata_6b8.dat
                              + 2006-03-02 12:00 . 2009-08-09 20:30 72788 c:\windows\system32\perfc009.dat
                              - 2006-03-02 12:00 . 2009-08-09 09:25 72788 c:\windows\system32\perfc009.dat
                              + 2009-08-09 20:55 . 2009-08-09 20:55 8192 c:\windows\ERDNT\subs\Users\00000004\UsrClass.dat
                              + 2009-08-09 20:55 . 2009-08-09 20:55 8192 c:\windows\ERDNT\subs\Users\00000002\UsrClass.dat
                              - 2006-03-02 12:00 . 2009-08-09 09:25 428820 c:\windows\system32\perfh009.dat
                              + 2006-03-02 12:00 . 2009-08-09 20:30 428820 c:\windows\system32\perfh009.dat
                              + 2009-08-09 20:55 . 2009-08-09 20:55 180224 c:\windows\ERDNT\subs\Users\00000006\UsrClass.dat
                              + 2009-08-09 20:55 . 2009-08-09 20:55 229376 c:\windows\ERDNT\subs\Users\00000003\NTUSER.DAT
                              + 2009-08-09 20:55 . 2009-08-09 20:55 229376 c:\windows\ERDNT\subs\Users\00000001\NTUSER.DAT
                              + 2009-08-09 20:55 . 2009-08-09 20:55 6139904 c:\windows\ERDNT\subs\Users\00000005\NTUSER.DAT
                              .
                              ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              *Note* empty entries & legit default entries are not shown
                              REGEDIT4

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [2004-08-23 122880]
                              "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
                              "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
                              "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "JMB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-04-20 385024]
                              "WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-08-23 20480]
                              "WOOTASKBARICON"="c:\progra~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
                              "EPSON Stylus Photo RX420 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE" [2004-04-09 98304]
                              "USB2Check"="c:\windows\system32\PCLECoInst.dll" [2004-09-21 73728]
                              "USBToolTip"="c:\program files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2005-06-13 192512]
                              "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
                              "eCarteBleue-CLEO"="c:\program files\e-Carte Bleue\LCL\e-Carte Bleue VISA Cleo\ECB-CLEO.exe" [2006-02-07 200704]
                              "NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
                              "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-09-09 282624]
                              "PROMT Integrator"="c:\program files\PROMT5\INTEGRAL\PinStart.exe" [2001-09-03 49152]
                              "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
                              "ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
                              "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
                              "ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-08-09 221184]
                              "ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
                              "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-05-04 16206848]
                              "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-04-24 1448960]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                              "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                              c:\documents and settings\Helen\Menu D‚marrer\Programmes\D‚marrage\
                              Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                              "%windir%\\system32\\sessmgr.exe"=
                              "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                              "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                              "c:\\Program Files\\Vsk3\\Vsk3.exe"=
                              "c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
                              "c:\\Program Files\\Fichiers communs\\Ahead\\Nero Web\\SetupX.exe"=
                              "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
                              "c:\\WINDOWS\\system32\\dplaysvr.exe"=

                              R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [07/09/2008 18:08 114768]
                              R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [07/09/2008 18:08 20560]
                              R3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [22/07/2008 11:14 16384]
                              R3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [22/07/2008 11:14 9856]

                              [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                              "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
                              .
                              .
                              ------- Supplementary Scan -------
                              .
                              uStart Page = hxxp://www.digitalfan.com/start
                              mWindow Title =
                              uInternet Connection Wizard,ShellNext = iexplore
                              uSearchURL,(Default) = hxxp://www.searchgateway.net/search/%s
                              IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
                              IE: { - c:\program files\Messenger\msmsgs.exe
                              IE: {{7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - c:\program files\PROMT5\PROMTIE4\promtie5.htm
                              IE: {{7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - c:\program files\PROMT5\PROMTIE4\options.htm
                              DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} - hxxps://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
                              .

                              **************************************************************************

                              catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2009-08-09 22:57
                              Windows 5.1.2600 Service Pack 3 NTFS

                              scanning hidden processes ...

                              scanning hidden autostart entries ...

                              scanning hidden files ...

                              scan completed successfully
                              hidden files: 0

                              **************************************************************************
                              .
                              --------------------- LOCKED REGISTRY KEYS ---------------------

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,10,bc,8b,95,fc,
                              1b,05,96,c8,28,51,af,b0,29,a3,98,0c,96,fc,91,41,3c,1e,d0,e2,63,26,f1,3f,c8,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,38,0b,b8,5d,3b,
                              b8,06,c3,71,3b,04,66,8b,46,0d,96,38,79,34,a8,2f,e9,d7,ef,6a,9c,d6,61,af,45,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,d8,d4,1f,22,b5,
                              4c,51,87,25,da,ec,7e,55,20,c9,26,27,79,ab,f4,7b,87,f5,d9,ff,7c,85,e0,43,d4,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,d3,e0,5b,c4,21,
                              a2,02,c3,3e,1e,9e,e0,57,5a,93,61,60,e4,4f,20,f1,bb,9e,9d,86,8c,21,01,be,91,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,48,46,46,45,36,
                              22,fe,12,cd,44,cd,b9,a6,33,6c,cd,32,1f,8d,4f,3c,40,1f,ac,f5,1d,4d,73,a8,13,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,42,e3,25,9e,cd,
                              82,07,6d,b0,18,ed,a7,3f,8d,37,a4,a1,b4,2c,33,fd,f2,95,d6,df,20,58,62,78,6b,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "4d370831d2c43cd13623e232fed27b7b"=hex:97,20,4e,9a,c7,f1,35,ee,54,fc,8d,a0,c3,
                              1d,4e,4d,31,77,e1,ba,b1,f8,68,02,92,c3,91,cb,d1,44,1b,bf,fb,a7,78,e6,12,2f,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,d1,15,eb,24,8b,
                              4b,6a,1f,83,6c,56,8b,a0,85,96,ab,85,99,c7,55,9c,1e,a0,eb,01,3a,48,fc,e8,04,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,1e,64,88,4d,10,
                              2c,5e,83,51,fa,6e,91,28,9e,14,cc,69,1b,14,be,f1,b7,d5,a8,f6,0f,4e,58,98,5b,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,dd,20,ba,69,62,
                              f8,4e,11,b1,cd,45,5a,a8,c4,f8,b9,1e,03,24,04,15,d3,6c,5d,3d,ce,ea,26,2d,45,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,cc,91,d2,a3,dd,
                              bb,d0,32,e3,0e,66,d5,eb,bc,2f,6b,16,64,1d,3d,66,45,59,04,2a,b7,cc,b5,b9,7f,\

                              [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
                              "ThreadingModel"="Apartment"
                              @="c:\\WINDOWS\\system32\\OLE32.DLL"
                              "8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,f6,0f,4c,49,65,
                              d9,96,ef,fa,ea,66,7f,d4,3b,6b,70,22,41,fb,d6,e4,90,d4,3e,6c,43,2d,1e,aa,22,\
                              .
                              --------------------- DLLs Loaded Under Running Processes ---------------------

                              - - - - - - - > 'winlogon.exe'(744)
                              c:\windows\system32\Ati2evxx.dll

                              - - - - - - - > 'explorer.exe'(692)
                              c:\program files\Fichiers communs\Ahead\Lib\NeroSearchBar.dll
                              c:\program files\Fichiers communs\Ahead\Lib\MFC71U.DLL
                              c:\program files\Fichiers communs\Ahead\Lib\BCGCBPRO860un71.dll
                              c:\windows\system32\eappprxy.dll
                              c:\windows\system32\webcheck.dll
                              c:\windows\system32\WPDShServiceObj.dll
                              c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
                              c:\windows\system32\PortableDeviceTypes.dll
                              c:\windows\system32\PortableDeviceApi.dll
                              .
                              ------------------------ Other Running Processes ------------------------
                              .
                              c:\windows\system32\ati2evxx.exe
                              c:\windows\system32\ati2evxx.exe
                              c:\program files\Alwil Software\Avast4\aswUpdSv.exe
                              c:\program files\Alwil Software\Avast4\ashServ.exe
                              c:\windows\system32\drivers\CDAC11BA.EXE
                              c:\windows\system32\FTRTSVC.exe
                              c:\program files\Fichiers communs\LightScribe\LSSrvc.exe
                              c:\program files\Pinnacle\Shared Files\Programs\USBTip\USBTip.exe
                              c:\progra~1\Wanadoo\TaskBarIcon.exe
                              c:\program files\ATI Technologies\ATI.ACE\CLI.exe
                              c:\progra~1\Wanadoo\GestionnaireInternet.exe
                              c:\program files\PROMT5\INTEGRAL\pinmenu.exe
                              c:\progra~1\Wanadoo\ComComp.exe
                              c:\progra~1\Wanadoo\Toaster.exe
                              c:\progra~1\Wanadoo\Inactivity.exe
                              c:\progra~1\Wanadoo\PollingModule.exe
                              c:\program files\Alwil Software\Avast4\ashMaiSv.exe
                              c:\program files\Alwil Software\Avast4\ashWebSv.exe
                              c:\program files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                              c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                              c:\program files\ATI Technologies\ATI.ACE\CLI.exe
                              c:\program files\ATI Technologies\ATI.ACE\CLI.exe
                              c:\progra~1\Wanadoo\WOOBrowser\WOOBrowser.exe
                              c:\windows\system32\ALERTM~1\ALERTM~1.EXE
                              .
                              **************************************************************************
                              .
                              Completion time: 2009-08-09 23:01 - machine was rebooted
                              ComboFix-quarantined-files.txt 2009-08-09 21:01
                              ComboFix2.txt 2009-08-09 12:11

                              Pre-Run: 26 820 083 712 octets libres
                              Post-Run: 26 682 351 616 octets libres

                              244 --- E O F --- 2009-07-29 13:40
                              0
                              1. Contributeur
                                selectionne ceci

                                KillAll::

                                Driver::
                                soqwx32

                                Registry::
                                [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                                "ms18_word"=-

                                File::
                                c:\documents and settings\helen\local settings\application data\ucayy.exe

                                Folder::
                                c:\program files\Live-Player

                                * Copie le texte sélectionné (CTRL+C).
                                * Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
                                * Veille à ce que Retour à la ligne ne soit pas coché dans Format.
                                * Colle le texte copié dans ce bloc-notes (CTRL+V).
                                * Sauvegarde ce fichier sous le nom de CFScript.txt
                                * Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme ceci
                                http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
                                * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal!
                                Ne touche à rien tant que le scan n'est pas terminé.
                                * Une fois le scan achevé, un rapport va s'afficher : Poste son contenu.
                                * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                                Note: Le code ci-dessus a été intentionnellement rédigé pour CET utilisateur.
                                si vous n'êtes pas CET utilisateur, NE PAS appliquer ces directives : elles pourraient endommager votre système.

                                ensuite essaye de relancer naviolg
                                0
                                1. voici les résultats
                                  ComboFix 09-08-08.04 - Helen 09/08/2009 14:05.5.2 - NTFSx86
                                  Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1022.501 [GMT 2:00]
                                  Running from: c:\documents and settings\Helen\Bureau\combofix.exe
                                  AV: avast! antivirus 4.8.1335 [VPS 090807-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

                                  WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
                                  .

                                  ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
                                  .

                                  c:\documents and settings\Helen\Application Data\wiaserva.log
                                  c:\documents and settings\Helen\oashdihasidhasuidhiasdhiashdiuasdhasd
                                  C:\hijackthis test.exe
                                  c:\windows\Installer\2bc206.msi

                                  .
                                  ((((((((((((((((((((((((( Files Created from 2009-07-09 to 2009-08-09 )))))))))))))))))))))))))))))))
                                  .

                                  2009-08-03 16:22 . 2009-08-03 16:22 -------- d-sh--w- c:\documents and settings\Helen\IECompatCache
                                  2009-07-26 07:52 . 2009-07-27 20:48 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP

                                  .
                                  (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                                  .
                                  2009-08-09 10:02 . 2009-08-09 10:02 -------- d-----w- c:\program files\Navilog1
                                  2009-08-09 09:25 . 2006-03-02 12:00 89048 ----a-w- c:\windows\system32\perfc00C.dat
                                  2009-08-09 09:25 . 2006-03-02 12:00 499492 ----a-w- c:\windows\system32\perfh00C.dat
                                  2009-08-09 09:24 . 2009-01-02 01:27 -------- d-----w- c:\program files\trend micro
                                  2009-08-09 09:21 . 2007-02-09 12:37 -------- d-----w- c:\program files\Wanadoo
                                  2009-08-07 09:31 . 2007-02-07 16:04 -------- d--h--w- c:\program files\InstallShield Installation Information
                                  2009-08-07 09:30 . 2007-11-14 23:46 -------- d-----w- c:\program files\eMule
                                  2009-08-07 07:14 . 2009-08-07 07:16 242298 ----a-w- c:\windows\pchealth\helpctr\Config\Cache\Personal_32_1036.dat
                                  2009-08-01 08:12 . 2009-02-01 15:56 -------- d-----w- c:\program files\Live-Player
                                  2009-07-30 08:15 . 2008-03-29 20:56 -------- d-----w- c:\program files\Azureus
                                  2009-07-30 08:14 . 2008-03-29 20:56 -------- d-----w- c:\documents and settings\Helen\Application Data\Azureus
                                  2009-07-03 16:57 . 2006-03-02 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
                                  2009-06-16 14:40 . 2006-03-02 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
                                  2009-06-16 14:40 . 2006-03-02 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
                                  2009-06-11 08:05 . 2008-10-09 18:10 -------- d-----w- c:\program files\e-Carte Bleue LCL
                                  2009-06-03 19:10 . 2006-03-02 12:00 1297408 ----a-w- c:\windows\system32\quartz.dll
                                  2009-05-17 09:44 . 2009-05-17 09:44 278728 ----a-w- c:\windows\system32\drivers\atksgt.sys
                                  2009-05-17 09:44 . 2009-05-17 09:44 25416 ----a-w- c:\windows\system32\drivers\lirsgt.sys
                                  .

                                  ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                                  .
                                  .
                                  *Note* empty entries & legit default entries are not shown
                                  REGEDIT4

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "WOOKIT"="c:\progra~1\Wanadoo\Shell.exe" [2004-08-23 122880]
                                  "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 152872]
                                  "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "JMB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-04-20 385024]
                                  "WOOWATCH"="c:\progra~1\Wanadoo\Watch.exe" [2004-08-23 20480]
                                  "WOOTASKBARICON"="c:\progra~1\Wanadoo\GestMaj.exe" [2004-10-14 32768]
                                  "EPSON Stylus Photo RX420 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE" [2004-04-09 98304]
                                  "USB2Check"="c:\windows\system32\PCLECoInst.dll" [2004-09-21 73728]
                                  "USBToolTip"="c:\program files\Pinnacle\Shared Files\\Programs\USBTip\USBTip.exe" [2005-06-13 192512]
                                  "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-05-10 90112]
                                  "eCarteBleue-CLEO"="c:\program files\e-Carte Bleue\LCL\e-Carte Bleue VISA Cleo\ECB-CLEO.exe" [2006-02-07 200704]
                                  "NeroFilterCheck"="c:\program files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 153136]
                                  "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2007-09-09 282624]
                                  "PROMT Integrator"="c:\program files\PROMT5\INTEGRAL\PinStart.exe" [2001-09-03 49152]
                                  "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
                                  "ioCentre"="c:\genius\ioCentre\gTaskBar.exe" [2007-01-19 61440]
                                  "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
                                  "ISUSPM Startup"="c:\progra~1\FICHIE~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-08-09 221184]
                                  "ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-08-09 81920]
                                  "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-05-04 16206848]
                                  "SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-04-24 1448960]

                                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                                  c:\documents and settings\Helen\Menu D‚marrer\Programmes\D‚marrage\
                                  Adobe Gamma.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

                                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                  "%windir%\\system32\\sessmgr.exe"=
                                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                  "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                                  "c:\\Program Files\\Vsk3\\Vsk3.exe"=
                                  "c:\\Program Files\\Nero\\Nero 7\\Nero ShowTime\\ShowTime.exe"=
                                  "c:\\Program Files\\Fichiers communs\\Ahead\\Nero Web\\SetupX.exe"=
                                  "c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
                                  "c:\\WINDOWS\\system32\\dplaysvr.exe"=

                                  R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [07/09/2008 18:08 114768]
                                  R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [07/09/2008 18:08 20560]
                                  R3 gHidPnp;USB Device Enhanced Function Driver;c:\windows\system32\drivers\gHidPnp.sys [22/07/2008 11:14 16384]
                                  R3 gMouUsb;USB Mouse Device Drv;c:\windows\system32\drivers\gMouUsb.sys [22/07/2008 11:14 9856]
                                  S1 soqwx32;soqwx32;\??\c:\windows\system32\drivers\soqwx32.sys --> c:\windows\system32\drivers\soqwx32.sys [?]

                                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                                  "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
                                  .
                                  .
                                  ------- Supplementary Scan -------
                                  .
                                  uStart Page = hxxp://www.digitalfan.com/start
                                  mWindow Title =
                                  uInternet Connection Wizard,ShellNext = iexplore
                                  uSearchURL,(Default) = hxxp://www.searchgateway.net/search/%s
                                  IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
                                  IE: { - c:\program files\Messenger\msmsgs.exe
                                  IE: {{7A2EFD41-E6B3-11D2-89E3-00E0292EE574} - c:\program files\PROMT5\PROMTIE4\promtie5.htm
                                  IE: {{7A2EFD41-E6B3-11D2-89E3-00E0292EE575} - c:\program files\PROMT5\PROMTIE4\options.htm
                                  DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} - hxxps://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.0.cab
                                  .

                                  **************************************************************************

                                  catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                  Rootkit scan 2009-08-09 14:10
                                  Windows 5.1.2600 Service Pack 3 NTFS

                                  scanning hidden processes ...

                                  scanning hidden autostart entries ...

                                  scanning hidden files ...

                                  scan completed successfully
                                  hidden files: 0

                                  **************************************************************************
                                  .
                                  --------------------- LOCKED REGISTRY KEYS ---------------------

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{47629D4B-2AD3-4e50-B716-A66C15C63153}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "cd042efbbd7f7af1647644e76e06692b"=hex:c8,28,51,af,b0,29,a3,98,10,bc,8b,95,fc,
                                  1b,05,96,c8,28,51,af,b0,29,a3,98,0c,96,fc,91,41,3c,1e,d0,e2,63,26,f1,3f,c8,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{604BB98A-A94F-4a5c-A67C-D8D3582C741C}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "bca643cdc5c2726b20d2ecedcc62c59b"=hex:71,3b,04,66,8b,46,0d,96,38,0b,b8,5d,3b,
                                  b8,06,c3,71,3b,04,66,8b,46,0d,96,38,79,34,a8,2f,e9,d7,ef,6a,9c,d6,61,af,45,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{684373FB-9CD8-4e47-B990-5A4466C16034}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "2c81e34222e8052573023a60d06dd016"=hex:ff,7c,85,e0,43,d4,0e,fe,d8,d4,1f,22,b5,
                                  4c,51,87,25,da,ec,7e,55,20,c9,26,27,79,ab,f4,7b,87,f5,d9,ff,7c,85,e0,43,d4,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{74554CCD-F60F-4708-AD98-D0152D08C8B9}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "2582ae41fb52324423be06337561aa48"=hex:3e,1e,9e,e0,57,5a,93,61,d3,e0,5b,c4,21,
                                  a2,02,c3,3e,1e,9e,e0,57,5a,93,61,60,e4,4f,20,f1,bb,9e,9d,86,8c,21,01,be,91,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{7EB537F9-A916-4339-B91B-DED8E83632C0}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "caaeda5fd7a9ed7697d9686d4b818472"=hex:f5,1d,4d,73,a8,13,5c,05,48,46,46,45,36,
                                  22,fe,12,cd,44,cd,b9,a6,33,6c,cd,32,1f,8d,4f,3c,40,1f,ac,f5,1d,4d,73,a8,13,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{948395E8-7A56-4fb1-843B-3E52D94DB145}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "a4a1bcf2cc2b8bc3716b74b2b4522f5d"=hex:df,20,58,62,78,6b,cf,c8,42,e3,25,9e,cd,
                                  82,07,6d,b0,18,ed,a7,3f,8d,37,a4,a1,b4,2c,33,fd,f2,95,d6,df,20,58,62,78,6b,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{AC3ED30B-6F1A-4bfc-A4F6-2EBDCCD34C19}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "4d370831d2c43cd13623e232fed27b7b"=hex:97,20,4e,9a,c7,f1,35,ee,54,fc,8d,a0,c3,
                                  1d,4e,4d,31,77,e1,ba,b1,f8,68,02,92,c3,91,cb,d1,44,1b,bf,fb,a7,78,e6,12,2f,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{DE5654CA-EB84-4df9-915B-37E957082D6D}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "1d68fe701cdea33e477eb204b76f993d"=hex:01,3a,48,fc,e8,04,4a,f1,d1,15,eb,24,8b,
                                  4b,6a,1f,83,6c,56,8b,a0,85,96,ab,85,99,c7,55,9c,1e,a0,eb,01,3a,48,fc,e8,04,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{E39C35E8-7488-4926-92B2-2F94619AC1A5}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "1fac81b91d8e3c5aa4b0a51804d844a3"=hex:f6,0f,4e,58,98,5b,89,c9,1e,64,88,4d,10,
                                  2c,5e,83,51,fa,6e,91,28,9e,14,cc,69,1b,14,be,f1,b7,d5,a8,f6,0f,4e,58,98,5b,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{EACAFCE5-B0E2-4288-8073-C02FF9619B6F}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "f5f62a6129303efb32fbe080bb27835b"=hex:b1,cd,45,5a,a8,c4,f8,b9,dd,20,ba,69,62,
                                  f8,4e,11,b1,cd,45,5a,a8,c4,f8,b9,1e,03,24,04,15,d3,6c,5d,3d,ce,ea,26,2d,45,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{F8F02ADD-7366-4186-9488-C21CB8B3DCEC}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "fd4e2e1a3940b94dceb5a6a021f2e3c6"=hex:e3,0e,66,d5,eb,bc,2f,6b,cc,91,d2,a3,dd,
                                  bb,d0,32,e3,0e,66,d5,eb,bc,2f,6b,16,64,1d,3d,66,45,59,04,2a,b7,cc,b5,b9,7f,\

                                  [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{FEE45DE2-A467-4bf9-BF2D-1411304BCD84}\InprocServer32*]
                                  "ThreadingModel"="Apartment"
                                  @="c:\\WINDOWS\\system32\\OLE32.DLL"
                                  "8a8aec57dd6508a385616fbc86791ec2"=hex:6c,43,2d,1e,aa,22,2f,9c,f6,0f,4c,49,65,
                                  d9,96,ef,fa,ea,66,7f,d4,3b,6b,70,22,41,fb,d6,e4,90,d4,3e,6c,43,2d,1e,aa,22,\
                                  .
                                  --------------------- DLLs Loaded Under Running Processes ---------------------

                                  - - - - - - - > 'winlogon.exe'(748)
                                  c:\windows\system32\Ati2evxx.dll
                                  .
                                  Completion time: 2009-08-09 14:11
                                  ComboFix-quarantined-files.txt 2009-08-09 12:11

                                  Pre-Run: 26 699 948 032 octets libres
                                  Post-Run: 26 838 794 240 octets libres

                                  182 --- E O F --- 2009-07-29 13:40
                                  0
                                  1. Contributeur
                                    le mot image en devrait pas être la
                                    ignore le

                                    il ta faut le télécharger sur le Bureau
                                    0
                                    1. Avant de commencer la manip peux tu me préciser ce qu'est le bureauImage SVP?
                                      0
                                      • 1
                                      • 2