Infection virus heur trojan win32 generic

Résolu
Bonjour,
J'ai été infecté par virus heur trojan win32 generic. Je tente en vain des analyses avec dc web cureit mais l'examen echoue : mon pc reboot au milieu de l'analyse.
Aidez moi s'il vous plait.
J'attends impatiemment votre réponse
Merci d'avance
Configuration: Windows Vista Internet Explorer 7.0

58 réponses

Résumé de la discussion

Une infection par le cheval de Troie Win32 Generic provoque des redémarrages du système en cours d’analyse, rendant les outils d’éradication comme CureIt inopérants et nécessitant une approche de désinfection plus robuste. Des propositions de solution incluent l’utilisation d’outils alternatifs et des procédures en plusieurs étapes, notamment téléchargement sécurisé d’outils externes, exécution en mode administrateur, puis génération et analyse d’un rapport avant suppression. Plusieurs conseils ont été partagés, tels que sauvegarder les données personnelles avant toute intervention, éviter les formats de fuite et recueillir des rapports détaillés (HiJackThis, TCleaner) pour orienter le nettoyage. En dernier lieu, GMER a été utilisé pour repérer des éléments malveillants persistants et la discussion a évolué vers une approche collaborative et pédagogique.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Re,

    OK, tu as bien fait.

    On continue comme ça :

    * Télécharge ToolsCleaner par A.Rothstein & dj QUIOU sur ton Bureau.

    http://pc-system.fr/
    hxxp://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
    hxxp://pagesperso-orange.fr/AceRothstein/ToolsCleaner2.exe

    * Clique droit et exécuter en tant qu'administrateur.

    * Clique sur Recherche et laisse le scan se terminer.

    * Clique, sur Suppression pour finaliser.

    * Tu peux, si tu le souhaites, te servir des Options facultatives.

    * Clique sur Quitter, pour que le rapport puisse se créer.

    * Poste moi le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur( C:\).

    53
    1. Contributeur sécurité
      Re,

      de rien pour l'aide.

      C'est un plaisir.
      0
      1. Merci, je v essayer de suivre tes conseils même si je ne suis pas top en anglais. Je v télécharger firefox si tu me dis que c plus sûr. Merci, merci pour tout
        0
        1. Contributeur sécurité
          Re,

          de rien pour l'aide.

          ==

          Voici quelques conseils pour mieux protéger ton ordi des malwares :

          Mets à jour Windows en consultant régulièrement le site de mise à jour :
          http://www.update.microsoft.com/windowsupdate/v6/default.aspx

          - Sécurise Internet Explorer
          * Clique sur Démarrer puis Exécuter
          * Tape Inetcpl.cpl dans la zone de saisie puis OK
          * Clique sur l'onglet Sécurité
          * Clique sur "Rétablir toutes les zones au niveau par défaut"
          * Sélectionne Zone Internet et clique sur "Personaliser le niveau"
          * Dans la section sur les ActiveX, règle sur "Demander" les téléchargements des ActiveX sognés et non sognés et règle sur "Désactivé" "Contrôles d'initialisation et de script ActiveX non marqués comme sécurisés"

          - ATF Cleaner nettoye les fichiers temporaires d'Internet Explorer et Windows (et Firefox), vide la corbeille et effectue quelques autres actions de nettoyage. Il améliore la vitesse et élimine les fichiers malveillants logés dans les fichiers temporaires : https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html

          - Noscript est un "Addon" pour Firefox qui empêche l'exécution de scripts en provenance des sites Web. il stoppe l'installation de logiciels infectieux via flash, java, javascript et d'autres points d'entrée : http://www.geekstogo.com/forum/redirect.php?url=http%3A%2F%2Fwww.noscript.net

          - Conserve une sauvegarde des fichiers importants. Ceco devient de plus en plus important. Cet article, en anglais, est rempli d'informations sur les solutions possibles : http://www.geekstogo.com/559/options-for-home-computer-data-backup-part-1/

          - MVPS Hosts replace le fichier Hosts par un fichier contenantles sites de pub et autres sites dangereux. Fondamentalement, cela empêche l'ordi de se connecter à ces sites en redirigeant l'appel vers 127.0.0.1 qui correspond à ton ordi. Ceci rend plus difficile d'infecter l'ordi.

          https://winhelp2002.mvps.org/hosts.htm

          - Il vaut mieux utiliser un navigateur alternatif à Internet Explorer. Je recommande celui de Mozilla, Firefox, très agréable, mieux sécurisé et doté d'un très bon bloqueur de pop-ups. lien de téléchargement : https://www.commentcamarche.net/telecharger/web-internet/9879-securite-firefox-deux-failles-graves-corrigees-en-urgence/

          3) Si tu lis l'anglais, cet article de Tony Klein comporte d'excellentes suggestions : http://www.geekstogo.com/how-did-i-get-infected-in-the-first-place

          4)ERUNT (Emergency Recovery Utility NT) permet de prendre une sauvegarde de la base de registre et de la restaurer en cas de besoin. La copie de sauvegarde du registre effectuée par Windows n'est pas complète : https://www.commentcamarche.net/telecharger/utilitaires/9095-erunt/

          5)Console de récupération Face aux nouvelles menaces (attaque du secteur de boot par exemple), la Console de récupération peut être la seule solution. Un tutoriel ici : https://www.pcastuces.com/pratique/windows/xp/console_recuperation/page1.htm . N'hésite pas à poser des questions si nécessaire.

          ===

          Bon surf.
          0
          1. Voilà tout est fait..
            Je te remercie pour tout ce temps passé à résoudre mon problème.
            Merci encore
            0
            1. Contributeur sécurité
              Bonjour,

              je ne pense pas à une infection (sauf si cela se reproduit).

              Utilise ce lien pour purger ta Restauration système (inutile de garder des points infectés) :

              http://www.libellules.ch/restauration_system_vista.php

              ==

              Si tu ne l'as pas déjà,

              =>[/b] Télécharge ATF-Cleaner (Attribune) : http://www.atribune.org/ccount/click.php?id=1
              -- Met le sur ton bureau

              Le mode d'emploi (en gros une fois par jour)

              => Lance ATF-Cleaner :
              * Sous l'onglet Main, choisis : Select All
              * Clique sur le bouton Empty Selected

              * Sous l'onglet Firefox (si présent) : Clique sur select all
              -- Au message "are you sure you want to delete your firefox saved password" clique sur NON
              -- Clique sur Empty selected

              * Sous l'onglet Opéra (si présent) : Clique sur select all
              -- Au message "are you sure you want to delete your firefox saved password" clique sur NON
              -- Clique sur Empty selected

              * Quitte ATF-Cleaner
              ==

              A moins que tu ais encore des soucis, on devrait avoir fini.
              0
              1. Voilà c fait.. J'ai tout viré. Un petit soucis tout de même, hier soir, le bureau était figé, plus moyen d'accéder ni à internet ni aux dossiers. J'ai du éteindre le PC. Au redémarage, après lancement des programmes quand g voulu me connecter, il y avait mentionné "restaurer la dernière page" ou "page d'accueil". J'ai restauré la dernière page, c'est alors que 31 pages internet successives se sont ouvertes et après tout était figé à nouveau.
                J'ai alors refait la même manoeuvre mais j'ai tipé vers la page d'accueil et là çà a été.
                C'était quoi ? Encore un virus ?
                0
                1. Contributeur sécurité
                  Bonjour,

                  tu supprimes à la main :

                  C:\Program Files\ZHPDiag
                  C:\Program Files\trend micro\HijackThis.exe
                  C:\Program Files\trend micro\hijackthis.log

                  Si le répertoire C:\Program Files\trend micro est maintenant vide, tu le supprimes aussi.
                  0
                  1. Voilà j'ai fait mon analyse mais ne l'avais pas fait en tant qu'administrateur, alors j'ai fait un copié collé du premier scan. Ensuite j'ai refait une analyse en tant qu'administrateur et j'ai pu avoir ce fameux rapport. Alors çà donne çà :

                    -> Suppression:

                    C:\Program Files\trend micro\HijackThis.exe: ERREUR DE SUPPRESSION !!
                    C:\Users\MARC\Downloads\OTM.exe: supprimé !
                    C:\Combofix.txt: supprimé !
                    C:\Program Files\trend micro\hijackthis.log: ERREUR DE SUPPRESSION !!
                    C:\Users\MARC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content(13).IE5\5IPYV42B\hijackthis.log: supprimé !
                    C:\Users\MARC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content(13).IE5\KHSGS4Y0\hijackthis.log: supprimé !
                    C:\Users\MARC\Downloads\Rsit.exe: supprimé !
                    C:\_OTM: supprimé !
                    C:\Program Files\ZHPDiag: ERREUR DE SUPPRESSION !!
                    C:\Users\MARC\AppData\Local\VirtualStore\Program Files\ZHPDiag: supprimé !

                    [ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]

                    --> Recherche:

                    C:\Program Files\ZHPDiag: trouvé !
                    C:\Program Files\trend micro\HijackThis.exe: trouvé !
                    C:\Program Files\trend micro\hijackthis.log: trouvé !

                    J'attends ta réponse pour savoir si j'ai bien fait ou pas trop mal fait.
                    Merci
                    0
                    1. Bonjour,
                      J'ai bien effectué la manoeuvre mais j'ai eu un message d'erreur que je t'avais transmis. J'ai fait en revanche la manoeuvre en tant qu'adminsitrateur et çà a marché. J'espère que j'ai bien fait.
                      Merci
                      0
                      1. Contributeur sécurité
                        Bonjour,

                        on va faire autrement.

                        As tu fait la maneuvre de suppression de Combofix (via la commande éexécuter") ?

                        Elle doit être faite en premier.
                        0
                        1. Pardonne moi j avais mal lu.
                          Y a quand même un problème . Lorsque je mets nettoyer y a marqué :
                          Impossible de créer le fichier C:\program files\ZHPficQuarantine.txt. Acces refusé
                          0
                          1. Contributeur sécurité
                            Re,

                            la manip du post 120 vise à nettoyer les outils devenus inutiles (voire dangereux).

                            Il faut la faire.
                            0
                            1. je fais demarrer mais je trouve pas executer
                              0
                            2. @ULTIMATEFOURsuis sous vista
                              0
                          2. Contributeur sécurité
                            Re,

                            oui, il n'y a plus rien dans les rapports.

                            La seule chose qui restait est le dysfonctionnement de l'antivirus.

                            ===

                            Fais démarrer, puis Exécuter.

                            Dans la fenêtre de saisie qui s'ouvre tape :

                            combofix /u


                            puis clique sur OK.

                            (Si tu n'as pas la commande Exécuter, suis les instructions de ce lien :

                            https://www.generation-nt.com/windows-vista-commande-executer-activer-afficher-astuce-41574-1.html )


                            Clique sur ZHPFix sur ton Bureau puis sur le A rouge (Nettoyeur de tools).

                            Clique ensuite sur Nettoyer.
                            0
                            1. Re,
                              Ben écoutes finalement la mise à jour s'est faite normalement quelques heures après la desinfection. Dois je quand même faire ta dernière manip ?
                              Dois je faire un point de restauration du système ?
                              0
                          3. Contributeur sécurité
                            Bonjour,

                            j'ai eu les 2 rapports.

                            Kaspersky ne se met plus à jour même après un redémarrage ?

                            Tu as le nom du fichier manquant ?
                            0
                            1. bonsoir,
                              mon antivirus remarche, nickel. Merci
                              et les 2 rapports sont ils bons ?
                              0
                          4. Contributeur sécurité
                            Bonjour,

                            refais tourner Gmer et poste le nouveau rapport.
                            0
                            1. Voilà mon rapport GMER :

                              http://www.cijoint.fr/cjlink.php?file=cj200909/cijUrQMCON.txt
                              0
                            2. Re,
                              J'ai eu un message de mon antivirus qui n'arrive plus à se mettre à jour
                              Lors de la mise à jour, il me met "fichier introuvable"
                              Encore une résultante de mon infection on dirait
                              0
                            3. Coucou,
                              J'ai posté les deux rapports, les as tu eu ?
                              Merci de me rémpondre
                              0
                          5. Et voilà le hijackthis...

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 09:58:53, on 05/09/2009
                            Platform: Windows Vista SP1 (WinNT 6.00.1905)
                            MSIE: Internet Explorer v8.00 (8.00.6001.18813)
                            Boot mode: Normal

                            Running processes:
                            C:\Windows\system32\Dwm.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\Windows\RtHDVCpl.exe
                            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                            C:\Program Files\Launch Manager\LManager.exe
                            C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
                            C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
                            C:\Program Files\Windows Live\Family Safety\fsui.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Windows\ehome\ehtray.exe
                            C:\Windows\System32\p2phost.exe
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                            C:\Program Files\Windows Media Player\wmpnscfg.exe
                            C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
                            C:\Windows\ehome\ehmsas.exe
                            C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
                            C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
                            C:\Program Files\Windows Live\Contacts\wlcomm.exe
                            C:\Windows\Explorer.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Windows Live\Toolbar\wltuser.exe
                            C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
                            C:\Program Files\Internet Explorer\IEXPLORE.EXE
                            C:\Program Files\Internet Explorer\IEXPLORE.EXE
                            C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
                            C:\Program Files\Internet Explorer\IEXPLORE.EXE
                            C:\Users\MARC\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KHSGS4Y0\HiJackThis[1].exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://neufportail.fr/
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
                            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                            O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
                            O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                            O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                            O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
                            O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
                            O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                            O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                            O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                            O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
                            O4 - HKLM\..\Run: [WarReg_PopUp] C:\Acer\WR_PopUp\WarReg_PopUp.exe
                            O4 - HKLM\..\Run: [Acer Tour Reminder] C:\Acer\AcerTour\Reminder.exe
                            O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                            O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
                            O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                            O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                            O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
                            O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
                            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                            O4 - HKCU\..\Run: [CollaborationHost] C:\Windows\system32\p2phost.exe -s
                            O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup
                            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                            O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                            O4 - Startup: Outil de détection de support Picture Motion Browser.lnk = C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
                            O4 - Global Startup: Empowering Technology Launcher.lnk = C:\Acer\Empowering Technology\eAPLauncher.exe
                            O8 - Extra context menu item: Ajouter à l'Anti-bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
                            O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                            O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                            O9 - Extra button: Clavier &virtuel - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
                            O9 - Extra button: Analyse des &liens - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
                            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
                            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                            O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
                            O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
                            O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
                            O23 - Service: eDSService.exe (eDataSecurity Service) - HiTRSUT - C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe
                            O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
                            O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
                            O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
                            O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                            O23 - Service: Service Google Update (gupdate1ca0791a68fd045) (gupdate1ca0791a68fd045) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                            O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
                            O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
                            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                            O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Windows\System32\TuneUpDefragService.exe
                            O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
                            O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio.exe (file missing)
                            0
                            1. Contributeur sécurité
                              Re,

                              pas de changement.

                              Ce n'est pas une bonne nouvelle.

                              Copie ou imprime les instructions avant

                              Déconnecte toi d'internet et ferme toutes tes applications.

                              Désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

                              Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

                              KillAll::

                              Driver::
                              kbiwkmbricndgw
                              kbiwkmivsbhdco
                              kbiwkmymrycttv

                              File::
                              c:\windows\system32\drivers\kbiwkmiipferay.sys
                              c:\windows\system32\drivers\kbiwkmktnwfvpp.sys
                              c:\windows\system32\drivers\kbiwkmqveibqbx.sys
                              c:\windows\system32\kbiwkmcqamjrxg.dll
                              c:\windows\system32\kbiwkmwsjudvil.dat
                              c:\windows\system32\kbiwkmqyonqyaf.dat
                              c:\windows\system32\kbiwkmxpcxovew.dll
                              c:\windows\system32\kbiwkmptrwjcpo.dll
                              c:\windows\system32\kbiwkmqwururfy.dat
                              c:\windows\system32\kbiwkmydpakofp.dat
                              c:\windows\system32\kbiwkmtovmmqoi.dll
                              c:\windows\system32\kbiwkmrinstyqp.dll
                              c:\windows\system32\kbiwkmisxypxnw.dat
                              c:\windows\system32\kbiwkmflwjmxec.dll
                              c:\windows\system32\kbiwkmieadrtuy.dat
                              C:\tblafakj.sys

                              RegLock::
                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]


                              Enregistre ce fichier sous le nom CFscript

                              Fait un glisser/déposer de ce fichier CFscript sur le fichier ComboFix.exe

                              Clique sur le fichier CFscript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFscrïpt vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

                              Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                              Ne touche à rien tant que le scan n'est pas terminé.

                              Réactive ton parefeu, ton antivirus, la garde de ton antispyware

                              Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

                              Remets aussi un rapport Hijackthis

                              Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                              Attention : cette manip a été fait pour cet ordi. Tout réutilisation peut endommager sévèrement le système d'exploitation.
                              0
                              1. ComboFix 09-09-03.02 - MARC 05/09/2009 9:31.5.2 - NTFSx86
                                Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.2046.1166 [GMT 2:00]
                                Running from: c:\users\MARC\Desktop\antitibs.exe
                                Command switches used :: c:\users\MARC\Desktop\CFscript.txt
                                SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

                                FILE ::
                                "C:\tblafakj.sys"
                                "c:\windows\system32\drivers\kbiwkmiipferay.sys"
                                "c:\windows\system32\drivers\kbiwkmktnwfvpp.sys"
                                "c:\windows\system32\drivers\kbiwkmqveibqbx.sys"
                                "c:\windows\system32\kbiwkmcqamjrxg.dll"
                                "c:\windows\system32\kbiwkmflwjmxec.dll"
                                "c:\windows\system32\kbiwkmieadrtuy.dat"
                                "c:\windows\system32\kbiwkmisxypxnw.dat"
                                "c:\windows\system32\kbiwkmptrwjcpo.dll"
                                "c:\windows\system32\kbiwkmqwururfy.dat"
                                "c:\windows\system32\kbiwkmqyonqyaf.dat"
                                "c:\windows\system32\kbiwkmrinstyqp.dll"
                                "c:\windows\system32\kbiwkmtovmmqoi.dll"
                                "c:\windows\system32\kbiwkmwsjudvil.dat"
                                "c:\windows\system32\kbiwkmxpcxovew.dll"
                                "c:\windows\system32\kbiwkmydpakofp.dat"
                                .

                                ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                ---- Previous Run -------
                                .
                                C:\tblafakj.sys

                                .
                                ((((((((((((((((((((((((( Files Created from 2009-08-05 to 2009-09-05 )))))))))))))))))))))))))))))))
                                .

                                2009-09-05 07:38 . 2009-09-05 07:40 -------- d-----w- c:\users\MARC\AppData\Local\temp
                                2009-09-05 07:38 . 2009-09-05 07:38 -------- d-----w- c:\users\Public\AppData\Local\temp
                                2009-09-05 07:38 . 2009-09-05 07:38 -------- d-----w- c:\users\Default\AppData\Local\temp
                                2009-09-04 16:13 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                                2009-09-04 16:13 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
                                2009-09-04 09:40 . 2009-09-04 16:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                                2009-09-02 20:54 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
                                2009-09-02 20:54 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
                                2009-09-02 18:16 . 2009-09-02 18:16 -------- d-----w- c:\program files\ZHPDiag
                                2009-09-02 16:55 . 2009-09-02 16:55 -------- d-----w- C:\NVIDIA
                                2009-09-01 06:55 . 2009-09-01 07:05 -------- d-----w- C:\rsit
                                2009-08-31 10:19 . 2009-08-31 10:19 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
                                2009-08-31 10:19 . 2009-09-01 20:01 -------- d-----w- c:\users\MARC\AppData\Roaming\SUPERAntiSpyware.com
                                2009-08-31 10:19 . 2009-09-01 20:00 -------- d-----w- c:\program files\SUPERAntiSpyware
                                2009-08-30 21:34 . 2009-08-30 21:34 -------- d-----w- c:\users\MARC\AppData\Roaming\Malwarebytes
                                2009-08-30 21:34 . 2009-08-30 21:34 -------- d-----w- c:\programdata\Malwarebytes
                                2009-08-30 20:25 . 2009-08-30 20:25 -------- d-----w- C:\_OTM
                                2009-08-30 07:35 . 2009-08-30 07:36 -------- d-----w- c:\users\MARC\AppData\Roaming\dvdcss
                                2009-08-27 11:35 . 2009-09-01 06:55 -------- d-----w- c:\program files\trend micro
                                2009-08-27 01:56 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
                                2009-08-27 01:56 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
                                2009-08-27 01:56 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
                                2009-08-27 01:56 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
                                2009-08-27 01:56 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
                                2009-08-27 01:56 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
                                2009-08-27 01:56 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
                                2009-08-27 01:56 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
                                2009-08-27 01:04 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
                                2009-08-26 20:11 . 2009-08-26 22:10 -------- d-----w- C:\ToolBar SD
                                2009-08-26 09:37 . 2009-08-26 19:33 -------- d--h--w- C:\$AVG8.VAULT$
                                2009-08-26 09:24 . 2009-08-27 17:48 -------- d-----w- c:\programdata\avg8
                                2009-08-25 19:29 . 2009-08-25 19:29 -------- d-----w- c:\users\MARC\DoctorWeb
                                2009-08-19 07:36 . 2009-08-19 08:49 -------- d-----w- c:\program files\Corel
                                2009-08-16 21:30 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
                                2009-08-16 21:30 . 2009-06-10 12:12 160256 ----a-w- c:\windows\system32\wkssvc.dll
                                2009-08-16 21:30 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
                                2009-08-16 21:29 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
                                2009-08-16 21:29 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
                                2009-08-16 21:29 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
                                2009-08-16 21:29 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
                                2009-08-16 21:28 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL

                                .
                                (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2009-09-05 07:41 . 2009-05-19 13:33 -------- d-----w- c:\programdata\Kaspersky Lab
                                2009-09-05 05:27 . 2007-08-23 21:02 12978 ----a-w- c:\users\MARC\AppData\Roaming\nvModes.dat
                                2009-09-04 16:45 . 2009-03-29 09:28 -------- d-----w- c:\users\MARC\AppData\Roaming\uTorrent
                                2009-09-01 20:01 . 2008-03-03 09:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
                                2009-08-31 09:39 . 2006-12-10 19:02 672506 ----a-w- c:\windows\system32\perfh00C.dat
                                2009-08-31 09:39 . 2006-12-10 19:02 125110 ----a-w- c:\windows\system32\perfc00C.dat
                                2009-08-23 07:05 . 2009-05-19 13:22 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
                                2009-08-19 08:49 . 2008-08-18 08:23 -------- d-----w- c:\programdata\Ulead Systems
                                2009-08-19 07:56 . 2008-08-18 08:23 -------- d-----w- c:\users\MARC\AppData\Roaming\Ulead Systems
                                2009-08-19 07:47 . 2006-12-02 07:31 -------- d--h--w- c:\program files\InstallShield Installation Information
                                2009-08-19 07:10 . 2008-06-16 16:36 -------- d-----w- c:\program files\Sony
                                2009-08-17 01:13 . 2009-01-11 13:37 -------- d-----w- c:\program files\Microsoft Silverlight
                                2009-08-17 01:04 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
                                2009-08-11 10:35 . 2007-04-09 23:41 485920 ----a-w- c:\windows\system32\nvuninst.exe
                                2009-07-25 10:15 . 2007-11-07 19:14 -------- d-----w- c:\program files\Common Files\Nero
                                2009-07-25 09:41 . 2007-11-07 19:14 -------- d-----w- c:\programdata\Nero
                                2009-07-25 07:02 . 2007-11-07 19:03 -------- d-----w- c:\program files\Nero
                                2009-07-24 21:23 . 2007-11-07 19:03 -------- d-----w- c:\users\MARC\AppData\Roaming\Nero
                                2009-07-24 21:23 . 2007-11-07 19:03 -------- d-----w- c:\program files\Common Files\Simple Star Shared
                                2009-07-24 18:08 . 2009-06-14 16:34 -------- d-----w- c:\users\MARC\AppData\Roaming\vlc
                                2009-07-21 21:52 . 2009-07-28 19:43 915456 ----a-w- c:\windows\system32\wininet.dll
                                2009-07-21 21:47 . 2009-07-28 19:43 109056 ----a-w- c:\windows\system32\iesysprep.dll
                                2009-07-21 21:47 . 2009-07-28 19:43 71680 ----a-w- c:\windows\system32\iesetup.dll
                                2009-07-21 20:13 . 2009-07-28 19:43 133632 ----a-w- c:\windows\system32\ieUnatt.exe
                                2009-07-20 07:05 . 2009-07-20 07:05 356352 ----a-w- c:\windows\Araignée3DUninstaller.exe
                                2009-07-18 10:26 . 2009-07-18 10:19 -------- d-----w- c:\program files\Google
                                2009-07-18 10:20 . 2009-07-18 10:19 -------- d-----w- c:\programdata\Google Updater
                                2009-07-13 12:19 . 2009-05-24 13:30 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
                                2009-07-13 12:13 . 2009-07-13 12:13 604140 --sha-w- c:\windows\system32\drivers\ISwift3(62).dat
                                2009-07-13 12:13 . 2009-07-13 12:13 604140 ----a-w- c:\windows\system32\drivers\ISwift3(40).dat
                                2009-07-13 12:13 . 2009-07-13 12:13 604140 ------w- c:\windows\system32\drivers\ISwift3.dat
                                2009-07-13 12:09 . 2009-07-13 12:09 105395 ----a-w- c:\windows\system32\drivers\klin.dat
                                2009-07-13 12:09 . 2009-07-13 12:09 94643 ----a-w- c:\windows\system32\drivers\klick.dat
                                2009-07-13 12:07 . 2009-07-13 12:07 -------- d-----w- c:\program files\Kaspersky Lab
                                2009-07-13 10:22 . 2009-06-20 19:51 -------- d-----w- c:\users\MARC\AppData\Roaming\FMZilla
                                2009-07-12 19:07 . 2009-01-04 11:23 -------- d-----w- c:\programdata\f-secure
                                2009-07-11 15:23 . 2007-08-24 00:51 -------- d-----w- c:\program files\Messenger Plus! Live
                                2009-07-06 07:09 . 2009-05-19 13:33 8261152 --sha-w- c:\windows\system32\drivers\fidbox.dat
                                2009-07-06 07:09 . 2009-05-19 13:33 524320 --sha-w- c:\windows\system32\drivers\fidbox2.dat
                                2009-06-15 15:24 . 2009-07-15 07:07 156672 ----a-w- c:\windows\system32\t2embed.dll
                                2009-06-15 15:20 . 2009-07-15 07:07 72704 ----a-w- c:\windows\system32\fontsub.dll
                                2009-06-15 15:20 . 2009-07-15 07:07 10240 ----a-w- c:\windows\system32\dciman32.dll
                                2009-06-15 12:52 . 2009-07-15 07:07 289792 ----a-w- c:\windows\system32\atmfd.dll
                                .

                                ((((((((((((((((((((((((((((( SnapShot@2009-09-04_18.29.09 )))))))))))))))))))))))))))))))))))))))))
                                .
                                + 2006-12-10 10:07 . 2009-09-05 07:41 80442 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
                                + 2006-11-02 13:05 . 2009-09-05 07:41 83882 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
                                + 2007-08-23 12:07 . 2009-09-05 07:41 21840 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2230032509-3730063523-3314345870-1000_UserData.bin
                                - 2007-08-23 18:53 . 2009-09-04 15:53 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                                + 2007-08-23 18:53 . 2009-09-05 07:39 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                                + 2007-08-23 18:53 . 2009-09-05 07:39 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                                - 2007-08-23 18:53 . 2009-09-04 15:53 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                                + 2009-09-05 07:39 . 2009-09-05 07:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                                - 2009-09-04 18:26 . 2009-09-04 18:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                                + 2009-09-05 07:39 . 2009-09-05 07:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                                - 2009-09-04 18:26 . 2009-09-04 18:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                                + 2009-05-03 07:53 . 2009-09-05 07:39 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
                                - 2009-05-03 07:53 . 2009-09-04 15:54 245760 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat
                                - 2007-08-23 18:53 . 2009-09-04 15:53 655360 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                                + 2007-08-23 18:53 . 2009-09-05 07:39 655360 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                                .
                                ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                *Note* empty entries & legit default entries are not shown
                                REGEDIT4

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
                                "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
                                "CollaborationHost"="c:\windows\system32\p2phost.exe" [2008-01-19 192000]
                                "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
                                "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
                                "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
                                "Acer Tour Reminder"="" [BU]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
                                "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
                                "eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-01-02 464168]
                                "LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-12-21 659456]
                                "WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
                                "Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-01-14 151552]
                                "NvSvc"="c:\windows\system32\nvsvc.dll" [2006-12-20 90191]
                                "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-20 7766016]
                                "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-20 81920]
                                "NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 3100672]
                                "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
                                "fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
                                "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-05-25 303376]
                                "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-08-03 419088]
                                "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-09 3784704]

                                c:\users\MARC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                                Outil de d‚tection de support Picture Motion Browser.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-6-16 385024]

                                c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                                Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2006-12-10 528384]

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                "EnableUIADesktopToggle"= 0 (0x0)

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                                "AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
                                @="Service"

                                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
                                "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                                "QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
                                "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                                "DisableMonitoring"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
                                "DisableMonitoring"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                                "DisableMonitoring"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                                "DisableMonitoring"=dword:00000001

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
                                "EnableFirewall"= 0 (0x0)

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                                "{081659FE-5F03-42E3-B488-636242C7D835}"= UDP:c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
                                "{2A8BAAA4-1E02-4C0A-BC8A-3882CFC56A0D}"= TCP:c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
                                "{C75E6919-C22E-443B-B3E3-B01DEBC9683C}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
                                "{0CAB35C8-9849-421F-9007-CED2C685A676}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
                                "{9F3D756E-B5A2-477D-ADA6-6D6D5E3DBB9D}"= c:\program files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:Rosetta Stone Version 3 Application
                                "{C955C15A-2E5C-45DD-B671-F3CC5DCF83B6}"= c:\program files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:Rosetta Stone Ltd Services
                                "{006025CC-C37B-494B-BCFB-3B9F13C1A49E}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
                                "{6A079D00-5914-45C7-B16C-39CFCD8BC951}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
                                "{1C69DC1A-F1C3-4D71-9D68-E03B581466BC}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
                                "TCP Query User{F961E09A-CBBE-4343-A70B-FB1146C55086}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
                                "UDP Query User{CC4DEA9B-B97C-402D-B02C-017ECE06F833}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
                                "EnableFirewall"= 0 (0x0)

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
                                "EnableFirewall"= 0 (0x0)

                                R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [15/12/2008 20:41 33808]
                                R1 GRD;G DATA Rootkit Detector Driver;c:\windows\System32\drivers\GRD.sys [03/04/2009 14:56 29128]
                                R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [15/05/2009 18:50 21008]
                                R2 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [11/01/2009 15:36 55264]
                                R2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
                                R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [04/09/2009 18:13 232720]
                                R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\System32\drivers\klmouflt.sys [16/05/2009 20:59 19472]
                                R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [04/09/2009 18:13 19096]
                                S2 gupdate1ca0791a68fd045;Service Google Update (gupdate1ca0791a68fd045);c:\program files\Google\Update\GoogleUpdate.exe [18/07/2009 12:22 133104]
                                S3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\System32\drivers\WsAudioDevice_383.sys [18/06/2009 18:34 16640]

                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                                "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
                                .
                                Contents of the 'Scheduled Tasks' folder

                                2009-09-05 c:\windows\Tasks\Google Software Updater.job
                                - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-18 10:19]

                                2009-09-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                                - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-18 10:21]

                                2009-09-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                                - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-18 10:21]

                                2009-09-05 c:\windows\Tasks\Maintenance en 1 clic.job
                                - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-21 11:14]

                                2009-09-05 c:\windows\Tasks\User_Feed_Synchronization-{F9AA5A26-145C-4972-9770-63D1DA176BAC}.job
                                - c:\windows\system32\msfeedssync.exe [2009-07-28 20:13]
                                .
                                .
                                ------- Supplementary Scan -------
                                .
                                uStart Page = hxxp://www.neufportail.fr/
                                uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
                                mStart Page = hxxp://fr.fr.acer.yahoo.com
                                uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
                                IE: Ajouter à l'Anti-bannière - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
                                .

                                **************************************************************************

                                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2009-09-05 09:39
                                Windows 6.0.6001 Service Pack 1 NTFS

                                scanning hidden processes ...

                                scanning hidden autostart entries ...

                                scanning hidden files ...

                                scan completed successfully
                                hidden files: 0

                                **************************************************************************
                                .
                                --------------------- LOCKED REGISTRY KEYS ---------------------

                                [HKEY_USERS\S-1-5-21-2230032509-3730063523-3314345870-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
                                "??"=hex:e2,3c,ed,27,a9,f9,bf,ef,92,35,99,ed,6e,eb,c2,e9,83,b0,8c,d8,04,a5,f2,
                                f5,72,6e,5c,03,54,27,59,57,03,94,8f,83,b9,b9,af,d1,d9,78,c5,bd,8b,59,92,bd,\
                                "??"=hex:4e,1f,5a,92,5e,0c,80,9f,fb,2b,82,ba,8b,19,1b,fe
                                .
                                --------------------- DLLs Loaded Under Running Processes ---------------------

                                - - - - - - - > 'Explorer.exe'(1064)
                                c:\acer\Empowering Technology\EPOWER\SysHook.dll
                                .
                                ------------------------ Other Running Processes ------------------------
                                .
                                c:\windows\System32\audiodg.exe
                                c:\program files\Common Files\InterVideo\DeviceService\DevSvc.exe
                                c:\acer\Empowering Technology\eDataSecurity\eDSService.exe
                                c:\acer\Empowering Technology\eLock\Service\eLockServ.exe
                                c:\program files\Common Files\LightScribe\LSSrvc.exe
                                c:\acer\Mobility Center\MobilityService.exe
                                c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                                c:\program files\CyberLink\Shared Files\RichVideo.exe
                                c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                c:\acer\Empowering Technology\eRecovery\eRecoveryService.exe
                                c:\acer\Empowering Technology\eSettings\Service\capuserv.exe
                                c:\acer\Empowering Technology\ePower\ePowerSvc.exe
                                c:\windows\System32\wbem\unsecapp.exe
                                c:\program files\Launch Manager\LManager.exe
                                c:\windows\ehome\ehmsas.exe
                                c:\acer\Empowering Technology\ePower\ePower_DMC.exe
                                c:\program files\Windows Media Player\wmpnetwk.exe
                                c:\acer\Empowering Technology\Acer.Empowering.Framework.Supervisor.exe
                                c:\program files\Windows Live\Contacts\wlcomm.exe
                                c:\program files\PC Connectivity Solution\ServiceLayer.exe
                                c:\windows\servicing\TrustedInstaller.exe
                                .
                                **************************************************************************
                                .
                                Completion time: 2009-09-05 9:46 - machine was rebooted
                                ComboFix-quarantined-files.txt 2009-09-05 07:46
                                ComboFix2.txt 2009-09-04 21:27
                                ComboFix3.txt 2009-09-04 19:00
                                ComboFix4.txt 2009-09-04 18:37

                                Pre-Run: 3 092 029 440 octets libres
                                Post-Run: 3 259 920 384 octets libres

                                296 --- E O F --- 2009-09-04 08:36
                                0
                            2. Contributeur sécurité
                              Re,

                              et m... je travaille comme un débutant.

                              Supprime Combofix.exe.

                              Fais comme ça :

                              On va utiliser ComboFix.exe. Rends toi sur cette page web pour obtenir les liens de téléchargement, ainsi que des instructions pour exécuter l'outil:

                              https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                              * lorsque la fenêtre te demandant où et sous quel nom tu veux enregistrer le fichier, enregistre le sous antitibs.exe. Il faut le faire à ce moment là. Renommer le fichier après le téléchargement ne servirait à rien.

                              * Vérifie que tu as fermé/désactivé tous les programmes anti-virus, anti-malware ou anti-spyware afin qu'ils n'interfèrent pas avec le travail de ComboFix.

                              Envoie le contenu de C:\ComboFix.txt dans ta prochaine réponse afin que je l'examine.
                              0
                              1. Voilà ce que tu me demandes... (avec tous mes remerciements pour le temps que tu passes à m'aider) :

                                ComboFix 09-09-03.02 - MARC 04/09/2009 23:14.3.2 - NTFSx86
                                Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.33.1036.18.2046.1089 [GMT 2:00]
                                Running from: c:\users\MARC\Desktop\antitibs.exe
                                SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
                                .

                                ((((((((((((((((((((((((( Files Created from 2009-08-04 to 2009-09-04 )))))))))))))))))))))))))))))))
                                .

                                2009-09-04 21:23 . 2009-09-04 21:23 -------- d-----w- c:\users\MARC\AppData\Local\temp
                                2009-09-04 21:23 . 2009-09-04 21:23 -------- d-----w- c:\users\Public\AppData\Local\temp
                                2009-09-04 21:23 . 2009-09-04 21:23 -------- d-----w- c:\users\Default\AppData\Local\temp
                                2009-09-04 16:13 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                                2009-09-04 16:13 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
                                2009-09-04 09:40 . 2009-09-04 16:14 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                                2009-09-03 02:22 . 2009-09-03 02:22 84352 ----a-w- C:\tblafakj.sys
                                2009-09-02 20:54 . 2009-08-28 12:39 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
                                2009-09-02 20:54 . 2009-08-28 10:15 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
                                2009-09-02 18:16 . 2009-09-02 18:16 -------- d-----w- c:\program files\ZHPDiag
                                2009-09-02 16:55 . 2009-09-02 16:55 -------- d-----w- C:\NVIDIA
                                2009-09-01 06:55 . 2009-09-01 07:05 -------- d-----w- C:\rsit
                                2009-08-31 10:19 . 2009-08-31 10:19 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
                                2009-08-31 10:19 . 2009-09-01 20:01 -------- d-----w- c:\users\MARC\AppData\Roaming\SUPERAntiSpyware.com
                                2009-08-31 10:19 . 2009-09-01 20:00 -------- d-----w- c:\program files\SUPERAntiSpyware
                                2009-08-30 21:34 . 2009-08-30 21:34 -------- d-----w- c:\users\MARC\AppData\Roaming\Malwarebytes
                                2009-08-30 21:34 . 2009-08-30 21:34 -------- d-----w- c:\programdata\Malwarebytes
                                2009-08-30 20:25 . 2009-08-30 20:25 -------- d-----w- C:\_OTM
                                2009-08-30 07:35 . 2009-08-30 07:36 -------- d-----w- c:\users\MARC\AppData\Roaming\dvdcss
                                2009-08-27 11:35 . 2009-09-01 06:55 -------- d-----w- c:\program files\trend micro
                                2009-08-27 01:56 . 2009-06-15 15:21 499712 ----a-w- c:\windows\system32\kerberos.dll
                                2009-08-27 01:56 . 2009-06-15 15:24 175104 ----a-w- c:\windows\system32\wdigest.dll
                                2009-08-27 01:56 . 2009-06-15 15:24 270848 ----a-w- c:\windows\system32\schannel.dll
                                2009-08-27 01:56 . 2009-06-15 15:23 1256448 ----a-w- c:\windows\system32\lsasrv.dll
                                2009-08-27 01:56 . 2009-06-15 15:22 213504 ----a-w- c:\windows\system32\msv1_0.dll
                                2009-08-27 01:56 . 2009-06-15 18:20 439896 ----a-w- c:\windows\system32\drivers\ksecdd.sys
                                2009-08-27 01:56 . 2009-06-15 15:24 72704 ----a-w- c:\windows\system32\secur32.dll
                                2009-08-27 01:56 . 2009-06-15 12:57 9728 ----a-w- c:\windows\system32\lsass.exe
                                2009-08-27 01:04 . 2009-06-22 10:22 2048 ----a-w- c:\windows\system32\tzres.dll
                                2009-08-26 20:11 . 2009-08-26 22:10 -------- d-----w- C:\ToolBar SD
                                2009-08-26 09:37 . 2009-08-26 19:33 -------- d--h--w- C:\$AVG8.VAULT$
                                2009-08-26 09:24 . 2009-08-27 17:48 -------- d-----w- c:\programdata\avg8
                                2009-08-25 19:29 . 2009-08-25 19:29 -------- d-----w- c:\users\MARC\DoctorWeb
                                2009-08-19 07:36 . 2009-08-19 08:49 -------- d-----w- c:\program files\Corel
                                2009-08-16 21:30 . 2009-07-17 14:35 71680 ----a-w- c:\windows\system32\atl.dll
                                2009-08-16 21:30 . 2009-06-10 12:12 160256 ----a-w- c:\windows\system32\wkssvc.dll
                                2009-08-16 21:30 . 2009-06-04 12:34 2066432 ----a-w- c:\windows\system32\mstscax.dll
                                2009-08-16 21:29 . 2009-06-10 12:07 91136 ----a-w- c:\windows\system32\avifil32.dll
                                2009-08-16 21:29 . 2009-07-14 13:00 313344 ----a-w- c:\windows\system32\wmpdxm.dll
                                2009-08-16 21:29 . 2009-07-14 12:58 7680 ----a-w- c:\windows\system32\spwmp.dll
                                2009-08-16 21:29 . 2009-07-14 12:59 4096 ----a-w- c:\windows\system32\dxmasf.dll
                                2009-08-16 21:28 . 2009-07-14 10:59 8147456 ----a-w- c:\windows\system32\wmploc.DLL

                                .
                                (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2009-09-04 19:13 . 2009-05-19 13:33 -------- d-----w- c:\programdata\Kaspersky Lab
                                2009-09-04 16:45 . 2009-03-29 09:28 -------- d-----w- c:\users\MARC\AppData\Roaming\uTorrent
                                2009-09-03 20:42 . 2007-08-23 21:02 12978 ----a-w- c:\users\MARC\AppData\Roaming\nvModes.dat
                                2009-09-01 20:01 . 2008-03-03 09:05 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
                                2009-08-31 09:39 . 2006-12-10 19:02 672506 ----a-w- c:\windows\system32\perfh00C.dat
                                2009-08-31 09:39 . 2006-12-10 19:02 125110 ----a-w- c:\windows\system32\perfc00C.dat
                                2009-08-23 07:05 . 2009-05-19 13:22 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
                                2009-08-19 08:49 . 2008-08-18 08:23 -------- d-----w- c:\programdata\Ulead Systems
                                2009-08-19 07:56 . 2008-08-18 08:23 -------- d-----w- c:\users\MARC\AppData\Roaming\Ulead Systems
                                2009-08-19 07:47 . 2006-12-02 07:31 -------- d--h--w- c:\program files\InstallShield Installation Information
                                2009-08-19 07:10 . 2008-06-16 16:36 -------- d-----w- c:\program files\Sony
                                2009-08-17 01:13 . 2009-01-11 13:37 -------- d-----w- c:\program files\Microsoft Silverlight
                                2009-08-17 01:04 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
                                2009-08-11 10:35 . 2007-04-09 23:41 485920 ----a-w- c:\windows\system32\nvuninst.exe
                                2009-07-25 10:15 . 2007-11-07 19:14 -------- d-----w- c:\program files\Common Files\Nero
                                2009-07-25 09:41 . 2007-11-07 19:14 -------- d-----w- c:\programdata\Nero
                                2009-07-25 07:02 . 2007-11-07 19:03 -------- d-----w- c:\program files\Nero
                                2009-07-24 21:23 . 2007-11-07 19:03 -------- d-----w- c:\users\MARC\AppData\Roaming\Nero
                                2009-07-24 21:23 . 2007-11-07 19:03 -------- d-----w- c:\program files\Common Files\Simple Star Shared
                                2009-07-24 18:08 . 2009-06-14 16:34 -------- d-----w- c:\users\MARC\AppData\Roaming\vlc
                                2009-07-21 21:52 . 2009-07-28 19:43 915456 ----a-w- c:\windows\system32\wininet.dll
                                2009-07-21 21:47 . 2009-07-28 19:43 109056 ----a-w- c:\windows\system32\iesysprep.dll
                                2009-07-21 21:47 . 2009-07-28 19:43 71680 ----a-w- c:\windows\system32\iesetup.dll
                                2009-07-21 20:13 . 2009-07-28 19:43 133632 ----a-w- c:\windows\system32\ieUnatt.exe
                                2009-07-20 07:05 . 2009-07-20 07:05 356352 ----a-w- c:\windows\Araignée3DUninstaller.exe
                                2009-07-18 10:26 . 2009-07-18 10:19 -------- d-----w- c:\program files\Google
                                2009-07-18 10:20 . 2009-07-18 10:19 -------- d-----w- c:\programdata\Google Updater
                                2009-07-13 12:19 . 2009-05-24 13:30 128016 ----a-w- c:\windows\system32\drivers\kl1.sys
                                2009-07-13 12:13 . 2009-07-13 12:13 604140 --sha-w- c:\windows\system32\drivers\ISwift3(62).dat
                                2009-07-13 12:13 . 2009-07-13 12:13 604140 ----a-w- c:\windows\system32\drivers\ISwift3(40).dat
                                2009-07-13 12:13 . 2009-07-13 12:13 604140 ------w- c:\windows\system32\drivers\ISwift3.dat
                                2009-07-13 12:09 . 2009-07-13 12:09 105395 ----a-w- c:\windows\system32\drivers\klin.dat
                                2009-07-13 12:09 . 2009-07-13 12:09 94643 ----a-w- c:\windows\system32\drivers\klick.dat
                                2009-07-13 12:07 . 2009-07-13 12:07 -------- d-----w- c:\program files\Kaspersky Lab
                                2009-07-13 10:22 . 2009-06-20 19:51 -------- d-----w- c:\users\MARC\AppData\Roaming\FMZilla
                                2009-07-12 19:07 . 2009-01-04 11:23 -------- d-----w- c:\programdata\f-secure
                                2009-07-11 15:23 . 2007-08-24 00:51 -------- d-----w- c:\program files\Messenger Plus! Live
                                2009-07-06 07:09 . 2009-05-19 13:33 8261152 --sha-w- c:\windows\system32\drivers\fidbox.dat
                                2009-07-06 07:09 . 2009-05-19 13:33 524320 --sha-w- c:\windows\system32\drivers\fidbox2.dat
                                2009-06-15 15:24 . 2009-07-15 07:07 156672 ----a-w- c:\windows\system32\t2embed.dll
                                2009-06-15 15:20 . 2009-07-15 07:07 72704 ----a-w- c:\windows\system32\fontsub.dll
                                2009-06-15 15:20 . 2009-07-15 07:07 10240 ----a-w- c:\windows\system32\dciman32.dll
                                2009-06-15 12:52 . 2009-07-15 07:07 289792 ----a-w- c:\windows\system32\atmfd.dll
                                .

                                ((((((((((((((((((((((((((((( SnapShot@2009-09-04_18.29.09 )))))))))))))))))))))))))))))))))))))))))
                                .
                                + 2006-12-10 10:07 . 2009-09-04 19:13 80410 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
                                + 2006-11-02 13:05 . 2009-09-04 19:13 83866 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
                                - 2007-08-23 12:07 . 2009-09-04 18:28 21722 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2230032509-3730063523-3314345870-1000_UserData.bin
                                + 2007-08-23 12:07 . 2009-09-04 19:13 21722 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2230032509-3730063523-3314345870-1000_UserData.bin
                                - 2007-08-23 18:53 . 2009-09-04 15:53 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                                + 2007-08-23 18:53 . 2009-09-04 21:13 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                                - 2007-08-23 18:53 . 2009-09-04 15:53 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                                + 2007-08-23 18:53 . 2009-09-04 21:13 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                                - 2009-09-04 18:26 . 2009-09-04 18:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                                + 2009-09-04 19:11 . 2009-09-04 19:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
                                - 2009-09-04 18:26 . 2009-09-04 18:26 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                                + 2009-09-04 19:11 . 2009-09-04 19:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
                                + 2007-08-23 18:53 . 2009-09-04 21:13 655360 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                                - 2007-08-23 18:53 . 2009-09-04 15:53 655360 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                                .
                                ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                *Note* empty entries & legit default entries are not shown
                                REGEDIT4

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
                                "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
                                "CollaborationHost"="c:\windows\system32\p2phost.exe" [2008-01-19 192000]
                                "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2005-08-11 249856]
                                "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
                                "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
                                "Acer Tour Reminder"="" [BU]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
                                "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-23 815104]
                                "eDataSecurity Loader"="c:\acer\Empowering Technology\eDataSecurity\eDSloader.exe" [2007-01-02 464168]
                                "LManager"="c:\progra~1\LAUNCH~1\LManager.exe" [2006-12-21 659456]
                                "WarReg_PopUp"="c:\acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 57344]
                                "Acer Tour Reminder"="c:\acer\AcerTour\Reminder.exe" [2007-01-14 151552]
                                "NvSvc"="c:\windows\system32\nvsvc.dll" [2006-12-20 90191]
                                "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-20 7766016]
                                "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-20 81920]
                                "NSLauncher"="c:\program files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2007-09-07 3100672]
                                "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe" [2005-06-23 57344]
                                "fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
                                "AVP"="c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe" [2009-05-25 303376]
                                "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2009-08-03 419088]
                                "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2006-11-09 3784704]

                                c:\users\MARC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                                Outil de d‚tection de support Picture Motion Browser.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-6-16 385024]

                                c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
                                Empowering Technology Launcher.lnk - c:\acer\Empowering Technology\eAPLauncher.exe [2006-12-10 528384]

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                "EnableUIADesktopToggle"= 0 (0x0)

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                                "AppInit_DLLs"=c:\progra~1\KASPER~1\KASPER~1\mzvkbd3.dll c:\progra~1\KASPER~1\KASPER~1\kloehk.dll

                                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
                                @="Service"

                                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
                                "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                                "QuickTime Task"="c:\program files\QuickTime\qttask.exe" -atboottime
                                "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" -start

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                                "DisableMonitoring"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
                                "DisableMonitoring"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                                "DisableMonitoring"=dword:00000001

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                                "DisableMonitoring"=dword:00000001

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
                                "EnableFirewall"= 0 (0x0)

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                                "{081659FE-5F03-42E3-B488-636242C7D835}"= UDP:c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
                                "{2A8BAAA4-1E02-4C0A-BC8A-3882CFC56A0D}"= TCP:c:\program files\Acer Arcade Deluxe\Acer Arcade Deluxe\MCE Deluxe Suite.exe:CyberLink MCE Deluxe Suite
                                "{C75E6919-C22E-443B-B3E3-B01DEBC9683C}"= UDP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
                                "{0CAB35C8-9849-421F-9007-CED2C685A676}"= TCP:c:\program files\MSN Messenger\msnmsgr.exe:MSN Messenger 7.0
                                "{9F3D756E-B5A2-477D-ADA6-6D6D5E3DBB9D}"= c:\program files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:Rosetta Stone Version 3 Application
                                "{C955C15A-2E5C-45DD-B671-F3CC5DCF83B6}"= c:\program files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:Rosetta Stone Ltd Services
                                "{006025CC-C37B-494B-BCFB-3B9F13C1A49E}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
                                "{6A079D00-5914-45C7-B16C-39CFCD8BC951}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
                                "{1C69DC1A-F1C3-4D71-9D68-E03B581466BC}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
                                "TCP Query User{F961E09A-CBBE-4343-A70B-FB1146C55086}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
                                "UDP Query User{CC4DEA9B-B97C-402D-B02C-017ECE06F833}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
                                "EnableFirewall"= 0 (0x0)

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
                                "EnableFirewall"= 0 (0x0)

                                R0 klbg;Kaspersky Lab Boot Guard Driver;c:\windows\System32\drivers\klbg.sys [15/12/2008 20:41 33808]
                                R1 GRD;G DATA Rootkit Detector Driver;c:\windows\System32\drivers\GRD.sys [03/04/2009 14:56 29128]
                                R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\System32\drivers\klim6.sys [15/05/2009 18:50 21008]
                                R2 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [11/01/2009 15:36 55264]
                                R2 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
                                R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [04/09/2009 18:13 232720]
                                R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\System32\drivers\klmouflt.sys [16/05/2009 20:59 19472]
                                R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [04/09/2009 18:13 19096]
                                S2 gupdate1ca0791a68fd045;Service Google Update (gupdate1ca0791a68fd045);c:\program files\Google\Update\GoogleUpdate.exe [18/07/2009 12:22 133104]
                                S3 WsAudioDevice_383;WsAudioDevice_383;c:\windows\System32\drivers\WsAudioDevice_383.sys [18/06/2009 18:34 16640]

                                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                                "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
                                .
                                Contents of the 'Scheduled Tasks' folder

                                2009-09-04 c:\windows\Tasks\Google Software Updater.job
                                - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-07-18 10:19]

                                2009-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                                - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-18 10:21]

                                2009-09-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                                - c:\program files\Google\Update\GoogleUpdate.exe [2009-07-18 10:21]

                                2009-09-04 c:\windows\Tasks\Maintenance en 1 clic.job
                                - c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2008-11-21 11:14]

                                2009-09-04 c:\windows\Tasks\User_Feed_Synchronization-{F9AA5A26-145C-4972-9770-63D1DA176BAC}.job
                                - c:\windows\system32\msfeedssync.exe [2009-07-28 20:13]
                                .
                                .
                                ------- Supplementary Scan -------
                                .
                                uStart Page = hxxp://www.neufportail.fr/
                                uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
                                mStart Page = hxxp://fr.fr.acer.yahoo.com
                                uSearchURL,(Default) = hxxp://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
                                IE: Ajouter à l'Anti-bannière - c:\program files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
                                .

                                **************************************************************************

                                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2009-09-04 23:23
                                Windows 6.0.6001 Service Pack 1 NTFS

                                scanning hidden processes ...

                                scanning hidden autostart entries ...

                                scanning hidden files ...

                                scan completed successfully
                                hidden files: 0

                                **************************************************************************
                                .
                                --------------------- LOCKED REGISTRY KEYS ---------------------

                                [HKEY_USERS\S-1-5-21-2230032509-3730063523-3314345870-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
                                "??"=hex:e2,3c,ed,27,a9,f9,bf,ef,92,35,99,ed,6e,eb,c2,e9,83,b0,8c,d8,04,a5,f2,
                                f5,72,6e,5c,03,54,27,59,57,03,94,8f,83,b9,b9,af,d1,d9,78,c5,bd,8b,59,92,bd,\
                                "??"=hex:4e,1f,5a,92,5e,0c,80,9f,fb,2b,82,ba,8b,19,1b,fe

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
                                @Denied: (A) (Users)
                                @Denied: (A) (Everyone)
                                @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                                "BlindDial"=dword:00000000

                                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
                                @Denied: (A) (Users)
                                @Denied: (A) (Everyone)
                                @Allowed: (B 1 2 3 4 5) (S-1-5-20)
                                "BlindDial"=dword:00000000
                                .
                                --------------------- DLLs Loaded Under Running Processes ---------------------

                                - - - - - - - > 'Explorer.exe'(4832)
                                c:\acer\Empowering Technology\EPOWER\SysHook.dll
                                .
                                Completion time: 2009-09-04 23:27
                                ComboFix-quarantined-files.txt 2009-09-04 21:27
                                ComboFix2.txt 2009-09-04 19:00
                                ComboFix3.txt 2009-09-04 18:37

                                Pre-Run: 3 771 363 328 octets libres
                                Post-Run: 3 631 632 384 octets libres

                                254 --- E O F --- 2009-09-04 08:36
                                0
                            • 1
                            • 2
                            • 3