Problème virus DeepScan

Résolu
Bonjour, je viens ici car depuis 4 jours Bit Defender a trouvé quand je fais une analyse approfondie de mon PC deux virus mais impossible de les supprimer ou de les mettre en quarantaine. Je passe mes soirée à essayer de résoudre le problème mais rien n'y fais.
Voilà le message que l'anti-virus me donne:
DeepScan:Generic.PWStealer.D6ACDBA8
<System>==>C:\Windows\system32\svchost.exe [3504] (full dump)
Generic.PWStealer.0E96BF1A
<System>==>C:\Windows\system32\svchost.exe [3504] (memory dump)

Que dois-je faire pour régler le problème, s'il vous plait. Merci d'avance.
Configuration: Windows XP
Firefox 2.0.0.6

28 réponses

Résumé de la discussion

Plusieurs jours après une détection par BitDefender de deux infections sur un PC Windows XP, l'utilisateur ne parvient pas à les supprimer ni à les mettre en quarantaine. L'échange cite Windows XP Édition familiale Service Pack 2, et des éléments comme DeepScan: Generic.PWStealer et des entrées système liées à svchost.exe apparaissent dans les rapports. Des réponses évoquent notamment la difficulté à supprimer le fichier soqwx32.sys et fournissent des rapports système et analyses (RSIT, HijackThis) pour aider au diagnostic. D'autres éléments mentionnent la cohabitation éventuelle avec d'autres outils de sécurité et des entrées de démarrage potentiellement malveillantes, sans conclusion ni état du fil.

Bobot (l’IA à votre service)
  1. j'ai donc relancé le scan sur la totalité et rien trouvé, par contre il y a des éléments ignorés dans le scan, est-ce que c'est normal car sur bit defender 2008 il n'y avait pas cette ligne "élément ignorés", merci d'avance.
    1. Alors j'ai désinstallé bit defender 2008 et impossible de le réinstaller, en allant voir mon fournisseur informatique, il m'a dit que le 2008 avait eu de gros probléme mais que la société ne l'aurait pas trop ébruité pour raisons commerciales, j'ai donc acheté le 2010 et je l'installe ce soir.
      1. impossible de faire le scan en ligne chez Kaspersky 'ERROR: licence périmée'
        1. re,

          Commencez par le Mises à jours de ces :
          Java : https://www.java.com/fr/download/manual.jsp
          Adobe : https://get2.adobe.com/reader/otherversions/

          ► À utiliser/vérifier aux 30jours.

          Important pour prévenir les failles de sécurités des logiciels ayant un accès à Internet.
          ____________________________________________________________________

          Ensute..
          Allez faire un scan en ligne chez Kaspersky : https://www.kaspersky.fr/downloads
          • Appuyer sur Online scanner Cliquer-ici !
          • désactiver votre antivrus,
          • Installer le plugin (si requis)
          • Appuyer sur acceptez (en bas)
          >> Les mises à jours vont avoir lieu (plusieurs minutes)
          • Lancer le scanne du C:\... au complet
          • Lorsque le scan sera complété -> Sauvegarderez le rapport
          >>>>>>> Postez le rapport
          1. Alors, je suis allé sur un de mes jeux en lignes et j'ai relancé ,aprés avoir fermé internet avec Firefox, Bit defender sur mes archives et de nouveau les deux fichires avec DeepScanStealer sont réapparus, je vais relancé Malwarebyte pour voir.
            1. Hier j'ai eu une fenêtre d'un logiciel que je ne connaissais pas "Total security 2009" avec une détection de 30 spywares, trojans, worms et j'en passe, j'ai relancé Malwarebytes qui a tout supprimé et j'ai supprimé aussi "Total security 2009" que je ne conaissais pas et qui été sur C:ProgramFiles. Ai-je bien fait?
              De plus je me demande si Bit Defender Total Security 2008 est bien "installé" tout est "vert" mais je me pose des questions car il n'avais rien trouvé comme worms, trojans et compagnie.
              1. Logfile of random's system information tool 1.06 (written by random/random)
                Run by Stéphane at 2009-09-05 14:23:19
                Microsoft Windows XP Édition familiale Service Pack 2
                System drive C: has 58 GB (24%) free of 238 GB
                Total RAM: 3070 MB (87% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 14:23:24, on 05/09/2009
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Bonjour\mDNSResponder.exe
                C:\Program Files\Java\jre6\bin\jqs.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
                C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Documents and Settings\Stéphane\Bureau\RSIT.exe
                C:\Program Files\trend micro\Stéphane.exe

                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
                O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
                1. Le volume dans le lecteur C s'appelle 447907
                  Le num‚ro de s‚rie du volume est 844D-5D94

                  R‚pertoire de C:\WINDOWS\Minidump

                  31/08/2009 22:36 <REP> .
                  31/08/2009 22:36 <REP> ..
                  0 fichier(s) 0 octets

                  Total des fichiers list‚sÿ:
                  0 fichier(s) 0 octets
                  2 R‚p(s) 60ÿ446ÿ789ÿ632 octets libres
                  1. Malwarebytes' Anti-Malware 1.40
                    Version de la base de données: 2744
                    Windows 5.1.2600 Service Pack 2

                    05/09/2009 14:05:15
                    mbam-log-2009-09-05 (14-05-15).txt

                    Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|)
                    Eléments examinés: 297767
                    Temps écoulé: 1 hour(s), 43 minute(s), 55 second(s)

                    Processus mémoire infecté(s): 0
                    Module(s) mémoire infecté(s): 0
                    Clé(s) du Registre infectée(s): 0
                    Valeur(s) du Registre infectée(s): 0
                    Elément(s) de données du Registre infecté(s): 0
                    Dossier(s) infecté(s): 0
                    Fichier(s) infecté(s): 1

                    Processus mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Module(s) mémoire infecté(s):
                    (Aucun élément nuisible détecté)

                    Clé(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Valeur(s) du Registre infectée(s):
                    (Aucun élément nuisible détecté)

                    Elément(s) de données du Registre infecté(s):
                    (Aucun élément nuisible détecté)

                    Dossier(s) infecté(s):
                    (Aucun élément nuisible détecté)

                    Fichier(s) infecté(s):
                    C:\Documents and Settings\Stéphane\Application Data\wiaserva.log (Malware.Trace) -> Quarantined and deleted successfully.
                    1. soqwx32.sys not deleting
                      soqwx32.sys IS deleting
                      ikowin32.exe IS deleting

                      et je continue avec MAlwarebytes
                      1. Et continuer avec les procédures du message #7 pour lesquels ces rapports sont à postez :
                        - Malwarebytes. (<--IMPORTANT)
                        - RapDump.txt" du fichier de commande
                        - Log.txt refait avec Rsit
                        1. Si vous avez pas fait la procédure de la Citation au message précédent.

                          Utilisez plutôt le contenu de cette Citation :

                          if exist C:\Rap_Sup.txt del C:\Rap_Sup.txt
                          Attrib -s -h -r C:\Windows\system32\drivers\soqwx32.sys
                          del C:\Windows\system32\drivers\soqwx32.sys
                          if exist "C:\Windows\system32\drivers\soqwx32.sys" (echo soqwx32.sys not deleting >> C:\Rap_Sup.txt) else echo soqwx32.sys IS deleting >> C:\Rap_Sup.txt
                          Attrib -s -h -r "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe"
                          del "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe"
                          if exist "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe" (echo ikowin32.exe not deleting >> C:\Rap_Sup.txt) else echo ikowin32.exe IS deleting >> C:\Rap_Sup.txt
                          Start notepad C:\Rap_Sup.txt  
                          1. re,

                            Oui supprimer Combofix avec selon la procédure.

                            Ensuite..

                            • Ouvrer le Bloc-note dans le Menu Démarrer --> Tout les programmes --> Accessoire,
                            • Copier/ coller le contenu de la Citation suivante dans le Bloc-Note,
                            • Dans le bloc-note sélectionner -> Fichier -> Enregistrer sous..
                            • Sauvegarder le Bloc-Note sous Sup_Fic.Bat (sur le bureau)
                            • Double-cliquer sur le fichier Sup_Fic.Bat

                            Citation
                            Attrib -s -h -r C:\Windows\system32\drivers\soqwx32.sys
                            if exist "C:\Windows\system32\drivers\soqwx32.sys" (del "C:\Windows\system32\drivers\soqwx32.sys") else echo soqwx32.sys not deleting > C:\Rap_Sup.txt
                            Attrib -s -h -r "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe"
                            if exist "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe" (del "C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe") else echo ikowin32.exe not deleting >> C:\Rap_Sup.txt
                            Start notepad C:\Rap_Sup.txt 


                            ► Postez le fichier "Rap_Sup.txt" qui s'ouvrira à l'écran.

                            _________________________________________________________________

                            ► Et continuer avec les procédures qui suivent au message #7, en postant leurs rapports.
                            1. Pour être vraiment sur voici le contenu que j'ai pris, dites moi si c'est bien celui-ci et si je dois continuer la procédureplus haut "supprimer ComboFix" ou je me suis planter en quelque part?
                              1. vous entendez quoi par "si'ils y sonr"? sur le contenu? si c'est cela oui j'ai refait u cas où je me sois trompé de contenu quand même et je repost donc le nouveau rapport mais là encore je n'ai pas eu à taper 1 ou 2

                                ComboFix 09-09-03.02 - Stéphane 05/09/2009 0:54.5.1 - NTFSx86
                                Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.3070.2569 [GMT 2:00]
                                Running from: c:\documents and settings\Stéphane\Bureau\CB-F.exe
                                Command switches used :: c:\documents and settings\Stéphane\Bureau\CFScript.txt
                                AV: Bitdefender Antivirus *On-access scanning disabled* (Updated) {6C4BB89C-B0ED-4F41-A29C-4373888923BB}
                                FW: Bitdefender Firewall *disabled* {4055920F-2E99-48A8-A270-4243D2B8F242}

                                WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
                                .

                                ((((((((((((((((((((((((( Files Created from 2009-08-04 to 2009-09-04 )))))))))))))))))))))))))))))))
                                .

                                2009-09-04 16:18 . 2009-09-04 16:18 -------- d-----w- c:\program files\trend micro
                                2009-09-03 17:32 . 2009-09-03 17:32 -------- d-----w- C:\GenProc
                                2009-09-03 16:28 . 2009-09-03 16:28 -------- d-----w- C:\rsit
                                2009-08-31 20:29 . 2009-08-31 20:29 -------- d-----w- c:\program files\CCleaner
                                2009-08-28 23:57 . 2009-08-28 23:57 -------- d-----w- c:\program files\MSXML 6.0
                                2009-08-28 23:50 . 2009-08-28 23:50 -------- d-----w- c:\windows\ServicePackFiles
                                2009-08-06 12:48 . 2009-08-06 12:48 -------- d-----w- c:\program files\Paradox Interactive

                                .
                                (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2009-09-04 22:57 . 2006-06-06 12:38 81984 ----a-w- c:\windows\system32\bdod.bin
                                2009-09-01 20:04 . 2008-01-25 13:40 86792 ----a-w- c:\windows\system32\drivers\bdfndisf.sys
                                2009-09-01 19:22 . 2008-04-02 17:03 -------- d-----w- c:\program files\Fichiers communs\BitDefender
                                2009-08-29 00:03 . 2006-02-24 04:13 86538 ----a-w- c:\windows\system32\perfc00C.dat
                                2009-08-29 00:03 . 2006-02-24 04:13 513818 ----a-w- c:\windows\system32\perfh00C.dat
                                2009-08-29 00:00 . 2009-08-29 00:00 -------- d-----w- c:\program files\MSBuild
                                2009-08-29 00:00 . 2009-08-29 00:00 -------- d-----w- c:\program files\Reference Assemblies
                                2009-08-21 11:09 . 2008-10-20 11:10 -------- d-----w- c:\program files\ATI
                                2009-08-05 17:21 . 2008-04-12 09:18 -------- d-----w- c:\program files\Safari
                                2009-08-05 17:18 . 2009-08-05 17:18 -------- d-----w- c:\program files\iPod
                                2009-08-05 17:18 . 2009-08-05 17:18 -------- d-----w- c:\program files\iTunes
                                2009-08-05 17:18 . 2007-07-05 11:39 -------- d-----w- c:\program files\Fichiers communs\Apple
                                2009-08-05 17:15 . 2007-05-10 11:38 -------- d-----w- c:\program files\QuickTime
                                2009-08-05 09:06 . 2004-08-05 12:00 205312 ----a-w- c:\windows\system32\mswebdvd.dll
                                2009-07-29 04:53 . 2004-08-05 12:00 82432 ----a-w- c:\windows\system32\fontsub.dll
                                2009-07-29 04:53 . 2004-08-05 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
                                2009-07-27 05:29 . 2008-09-06 18:04 -------- d-----w- c:\program files\BitComet
                                2009-07-23 12:35 . 2006-11-12 13:46 -------- d-----w- c:\program files\ArtMoney
                                2009-07-17 18:56 . 2004-08-05 12:00 58880 ----a-w- c:\windows\system32\atl.dll
                                2009-07-13 21:43 . 2004-08-05 12:00 286208 ----a-w- c:\windows\system32\wmpdxm.dll
                                2009-06-27 14:31 . 2007-09-27 19:36 281760 ----a-w- c:\windows\system32\drivers\atksgt.sys
                                2009-06-27 14:31 . 2007-09-27 19:36 25888 ----a-w- c:\windows\system32\drivers\lirsgt.sys
                                2009-06-26 16:18 . 2004-08-05 12:00 663552 ------w- c:\windows\system32\wininet.dll
                                2009-06-26 16:18 . 2004-08-05 12:00 81920 ----a-w- c:\windows\system32\ieencode.dll
                                2009-06-25 08:44 . 2004-08-05 12:00 731136 ----a-w- c:\windows\system32\lsasrv.dll
                                2009-06-25 08:44 . 2004-08-05 12:00 59392 ----a-w- c:\windows\system32\wdigest.dll
                                2009-06-25 08:44 . 2004-08-05 12:00 56320 ----a-w- c:\windows\system32\secur32.dll
                                2009-06-25 08:44 . 2004-08-05 12:00 168448 ----a-w- c:\windows\system32\schannel.dll
                                2009-06-25 08:44 . 2004-08-05 12:00 133632 ----a-w- c:\windows\system32\msv1_0.dll
                                2009-06-25 08:44 . 2004-08-05 12:00 298496 ----a-w- c:\windows\system32\kerberos.dll
                                2009-06-22 11:34 . 2004-08-05 12:00 92544 ----a-w- c:\windows\system32\drivers\ksecdd.sys
                                2009-06-15 11:33 . 2004-08-05 12:00 78848 ----a-w- c:\windows\system32\telnet.exe
                                2009-06-10 14:23 . 2004-08-05 12:00 85504 ----a-w- c:\windows\system32\avifil32.dll
                                2009-06-10 06:30 . 2004-08-05 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
                                .

                                ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                *Note* empty entries & legit default entries are not shown
                                REGEDIT4

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
                                "BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2009-09-01 368640]

                                c:\documents and settings\St‚phane\Menu D‚marrer\Programmes\D‚marrage\
                                ikowin32.exe [2004-8-5 26112]

                                c:\documents and settings\St‚phane\Menu D‚marrer\Programmes\D‚marrage\
                                ikowin32.exe [2004-8-5 26112]

                                c:\documents and settings\St‚phane\Menu D‚marrer\Programmes\D‚marrage\
                                ikowin32.exe [2004-8-5 26112]

                                c:\documents and settings\St‚phane\Menu D‚marrer\Programmes\D‚marrage\
                                ikowin32.exe [2004-8-5 26112]

                                [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                "FirewallOverride"=dword:00000001

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                "EnableFirewall"= 0 (0x0)

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                "%windir%\\system32\\sessmgr.exe"=
                                "c:\\Program Files\\Messenger\\Msmsgs.exe"=
                                "c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
                                "c:\\WINDOWS\\system32\\dpnsvr.exe"=
                                "c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords.exe"=
                                "c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Warlords\\Civ4Warlords_PitBoss.exe"=
                                "c:\\Program Files\\Ubisoft\\Funatics\\The Settlers II - 10th Anniversary\\bin\\S2DNG.exe"=
                                "c:\\StubInstaller.exe"=
                                "c:\\Program Files\\LimeWire\\LimeWire.exe"=
                                "c:\\Documents and Settings\\Stéphane\\Mes documents\\internet\\abandonware\\warhammer\\wardark\\ENGREL.EXE"=
                                "c:\\Program Files\\eMule\\emule.exe"=
                                "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                                "c:\\Program Files\\MSN Messenger\\livecall.exe"=
                                "c:\\Program Files\\Ubisoft\\THE SETTLERS - Bâtisseurs d'Empire\\base\\bin\\Settlers6.exe"=
                                "c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
                                "c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
                                "c:\\Program Files\\2K Games\\Firaxis Games\\Sid Meier's Civilization IV Colonization\\Colonization.exe"=
                                "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                                "c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404\\Anno4.exe"=
                                "c:\\Program Files\\Ubisoft\\Related Designs\\ANNO 1404\\tools\\Anno4Web.exe"=
                                "c:\\Program Files\\iTunes\\iTunes.exe"=
                                "c:\\Program Files\\Paradox Interactive\\East India Company Demo\\eastindia.exe"=

                                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                                "20817:TCP"= 20817:TCP:BitComet 20817 TCP
                                "20817:UDP"= 20817:UDP:BitComet 20817 UDP

                                R2 acedrv11;acedrv11;c:\windows\system32\drivers\ACEDRV11.sys [23/01/2008 10:19 501560]
                                R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [25/01/2008 15:40 86792]
                                S1 soqwx32;soqwx32;\??\c:\windows\system32\drivers\soqwx32.sys --> c:\windows\system32\drivers\soqwx32.sys [?]
                                S2 FILESpy;FILESpy;\??\c:\program files\Softwin\BitDefender9\filespy.sys --> c:\program files\Softwin\BitDefender9\filespy.sys [?]
                                S3 FXDRV;FXDRV;\??\d:\fxdrv.sys --> d:\Fxdrv.sys [?]

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                                bdx REG_MULTI_SZ scan
                                .
                                Contents of the 'Scheduled Tasks' folder

                                2009-09-02 c:\windows\Tasks\AppleSoftwareUpdate.job
                                - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

                                2009-09-04 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
                                - c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 10:20]
                                .
                                .
                                ------- Supplementary Scan -------
                                .
                                uSearchMigratedDefaultURL = hxxp://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
                                uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
                                DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
                                .

                                **************************************************************************

                                catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2009-09-05 00:57
                                Windows 5.1.2600 Service Pack 2 NTFS

                                scanning hidden processes ...

                                scanning hidden autostart entries ...

                                scanning hidden files ...

                                scan completed successfully
                                hidden files: 0

                                **************************************************************************

                                [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
                                "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\

                                [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
                                "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
                                .
                                --------------------- LOCKED REGISTRY KEYS ---------------------

                                [HKEY_USERS\S-1-5-21-1929738347-3376605301-1782770845-1007\Software\Microsoft\SystemCertificates\AddressBook*]
                                @Allowed: (Read) (RestrictedCode)
                                @Allowed: (Read) (RestrictedCode)

                                [HKEY_USERS\S-1-5-21-1929738347-3376605301-1782770845-1007\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
                                "??"=hex:d2,ec,92,73,00,b0,e6,51,0a,14,4a,a9,6a,c3,a1,17,07,f0,ca,d8,7c,dd,be,
                                e1,88,52,b8,8d,61,29,e7,dc,cb,32,2d,3a,b4,ac,73,30,40,34,6d,76,2b,12,ce,84,\
                                "??"=hex:b6,67,2b,cd,ca,15,9f,32,97,f9,4f,4b,0d,95,c6,4b

                                [HKEY_USERS\S-1-5-21-1929738347-3376605301-1782770845-1007\Software\SecuROM\License information*]
                                "datasecu"=hex:3d,d1,0b,a4,7f,d4,83,a3,d1,59,ac,1e,3a,f9,ed,48,34,a9,53,90,7a,
                                13,05,df,06,c2,db,94,09,0d,67,49,f7,24,4f,97,19,9e,7f,e2,a0,64,46,8a,3f,49,\
                                "rkeysecu"=hex:bd,8f,c9,3d,e7,84,cf,b5,1d,4b,81,c8,ac,8b,3c,6e

                                [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\Ø•€|ÿÿÿÿ•€|ù•9~*]
                                "C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"

                                [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\ð•€|ÿÿÿÿ.•€|ù•9~*]
                                "C040211900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                                .
                                --------------------- DLLs Loaded Under Running Processes ---------------------

                                - - - - - - - > 'winlogon.exe'(956)
                                c:\windows\system32\Ati2evxx.dll

                                - - - - - - - > 'explorer.exe'(7860)
                                c:\progra~1\FICHIE~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
                                c:\program files\Fichiers communs\Microsoft Shared\Web Components\11\1036\OWCI11.DLL
                                c:\windows\system32\shdoclc.dll
                                c:\windows\system32\WPDShServiceObj.dll
                                c:\windows\system32\PortableDeviceTypes.dll
                                c:\windows\system32\PortableDeviceApi.dll
                                .
                                Completion time: 2009-09-04 0:59
                                ComboFix-quarantined-files.txt 2009-09-04 22:59
                                ComboFix2.txt 2009-09-04 22:43
                                ComboFix3.txt 2009-09-04 19:07

                                Pre-Run: 57 839 398 912 octets libres
                                Post-Run: 57 827 897 344 octets libres

                                171 --- E O F --- 2009-08-29 00:06
                                1. re,

                                  Vous vérifierez, s'ils y sont, pour suppirmer ces fichiers :
                                  C:\Documents and Settings\Stéphane\Menu Démarrer\Programmes\Démarrage\ikowin32.exe
                                  Et
                                  C:\Windows\system32\drivers\soqwx32.sys ?

                                  Donnez en des nouvelles..
                                  1. par contre je n'ai pas eu la phrase "à vos risque" ni taper 1 ou 2, je n'aurais pas fais une erreur?
                                    • 1
                                    • 2