Virus

Bonjour,
J'ai besoin d'aide. Mon ordinateur est infecté par un virus: Total Security. Je n'arrive pas à m'en débarrasser. Est ce que quelqu'un peut me guider pour le supprimer ? C'est un virus "à la mode" en ce moment parait-il! :-( et je me suis fais avoir!!

Merci pour vos réponse
Configuration: Windows Vista Internet Explorer 7.0

35 réponses

Résumé de la discussion

Un ordinateur sous Windows Vista est infecté par le malware Total Security et l'utilisateur recherche des étapes fiables pour s’en débarrasser face à une menace persistante. Les réponses techniques évoquent des outils comme UsbFix et HijackThis, avec l’examen des processus actifs, des fichiers et des éléments de registre associés à l’infection. Des rapports montrent des modifications visibles comme des paramètres navigateur modifiés et des éléments d’exécution automatique, tandis que les résultats citent Avast et d’autres composants système légitimes. En l’absence d’une solution unique, la discussion propose des pistes d’analyse et de nettoyage via des scans approfondis et une remise à zéro des paramètres, sans conclure sur l’issue.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    c'est pas cela !

    scan ton ordi avec antivir et colle un rapport avec
    0
    1. Ha! C'était pas le rapport d'antivir dans le message juste avant?
      Il faut que tu me dises comment faire si c'était pas ça
      Merki!
      0
      1. Contributeur sécurité
        non le rapport d'un scan de ton ordi avec antivir
        0
        1. Je l'avais oublié!
          Le voilà

          Avira AntiVir Personal - Free Antivirus Updater

          Heure de création : Wed Sep 23 18:35:10 2009

          Système d'exploitation:
          Windows Vista (Service Pack 2) [6.0.6002]

          Informations produit :
          Version produit : 9.0.0.67
          Updater : C:\Program Files\Avira\AntiVir Desktop\update.exe 9.0.0.52
          Plug-in : C:\Program Files\Avira\AntiVir Desktop\updext.dll 9.0.0.6

          Répertoire temporaire : C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\
          Répertoire de sauvegarde : C:\ProgramData\Avira\AntiVir Desktop\BACKUP\
          Répertoire dapos;installation : C:\Program Files\Avira\AntiVir Desktop\
          Répertoire de l'Updater : C:\Program Files\Avira\AntiVir Desktop\
          Répertoire AppData : C:\ProgramData\Avira\AntiVir Desktop\

          [UPD] [INFO] Contrôle en cours pour savoir si des fichiers plus récents sont disponibles.
          [UPD] [INFO] Sélection en cours du serveur de mise à jour 'http://[2a01:138:a001:201::22]/update'.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::22]/update/idx/master.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::22]/update/idx/master.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::22]/update/idx/master.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Sélection en cours du serveur de mise à jour 'http://[2a01:138:a001:201::24]/update'.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::24]/update/idx/master.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::24]/update/idx/master.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::24]/update/idx/master.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Sélection en cours du serveur de mise à jour 'http://[2a01:138:a001:201::21]/update'.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::21]/update/idx/master.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::21]/update/idx/master.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::21]/update/idx/master.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Sélection en cours du serveur de mise à jour 'http://[2a01:138:a001:201::23]/update'.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::23]/update/idx/master.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\master.idx'.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::23]/update/idx/wks_avira-win32-fr-pecl.idx' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-fr-pecl.idx'.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::23]/update/idx/wks_avira-win32-fr-pecl.info.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-fr-pecl.info.gz'.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::23]/update/idx/vdf.info.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\vdf.info.gz'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::23]/update/idx/vdf.info.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\vdf.info.gz'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Téléchargement de 'http://[2a01:138:a001:201::23]/update/idx/vdf.info.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\vdf.info.gz'.
          [UPDLIB] [ERROR] Gestionnaire de téléchargements : une erreur s'est produite dans la bibliothèque WinINet.
          [UPD] [INFO] Sélection en cours du serveur de mise à jour 'http://80.190.143.227/update'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/idx/vdf.info.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\vdf.info.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/idx/ave2-win32-int.info.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\ave2-win32-int.info.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/idx/specvir-win32-int.info.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\specvir-win32-int.info.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/idx/wks_avira-win32-fr-pecl-info.info.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\idx\wks_avira-win32-fr-pecl-info.info.gz'.
          [UPD] [INFO] Comparaison en cours des fichiers locaux avec la version disponible sur le serveur de mise à jour.
          [UPD] [INFO] Contrôle en cours du module SELFUPDATE :
          [UPD] [INFO] Contrôle en cours du module VDF :
          [UPD] [INFO] Fichier 'vdf/antivir2.vdf' (local, serveur) : 7.1.4.253 < 7.1.6.1
          [UPD] [INFO] Fichier 'vdf/antivir3.vdf' (local, serveur) : 7.1.5.19 < 7.1.6.29
          [UPD] [INFO] Contrôle en cours du module AVE2 :
          [UPD] [INFO] Fichier 'ave2/win32/int/aecore.dll' (local, serveur) : 8.1.7.6 < 8.1.8.1
          [UPD] [INFO] Fichier 'ave2/win32/int/aegen.dll' (local, serveur) : 8.1.1.50 < 8.1.1.63
          [UPD] [INFO] Fichier 'ave2/win32/int/aehelp.dll' (local, serveur) : 8.1.5.3 < 8.1.7.0
          [UPD] [INFO] Fichier 'ave2/win32/int/aeheur.dll' (local, serveur) : 8.1.0.143 < 8.1.0.155
          [UPD] [INFO] Fichier 'ave2/win32/int/aepack.dll' (local, serveur) : 8.1.3.18 < 8.2.0.0
          [UPD] [INFO] Fichier 'ave2/win32/int/aescn.dll' (local, serveur) : 8.1.2.4 < 8.1.2.5
          [UPD] [INFO] Fichier 'ave2/win32/int/aescript.dll' (local, serveur) : 8.1.2.18 < 8.1.2.33
          [UPD] [INFO] Fichier 'ave2/win32/int/aeset.dat' (local, serveur) : 8.2.0.228 < 8.2.1.23
          [UPD] [INFO] Fichier 'ave2/win32/int/aevdf.dll' (local, serveur) : 8.1.1.1 < 8.1.1.2
          [UPD] [INFO] Contrôle en cours du module MAIN :
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/basic-nt/avupgsvc.exe' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/basic-nt/presetup.exe' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/basic-nt/vcredist_x86.exe' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/filelist.ini' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/oembleft.bmp' n'existe pas et est en cours d'installation.
          [UPD] [INFO] Fichier 'wks_avira/win32/fr/classic-nt/oembleft.bmp' non pris en compte du fait du mode de mise à jour produit.
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/product.ini' a défini le drapeau IGNORE et n'est de ce fait pas pris en compte.
          [UPD] [INFO] Contrôle en cours du module AVREP_NT :
          [UPD] [INFO] Contrôle en cours du module COMMAPPDATA_AV :
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/basic-nt/addr_file.html' est déjà installé et ne sera pas actualisé.
          [UPD] [INFO] Contrôle en cours du module COMMAPP :
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/produpd.avj' est déjà installé et ne sera pas actualisé.
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/scanjob.avj' est déjà installé et ne sera pas actualisé.
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/startupd.avj' est déjà installé et ne sera pas actualisé.
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/updjob.avj' est déjà installé et ne sera pas actualisé.
          [UPD] [INFO] Contrôle en cours du module COMMAPDATA_AV_PROFILES :
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/folder.avp' est déjà installé et ne sera pas actualisé.
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/rootkit.avp' est déjà installé et ne sera pas actualisé.
          [UPD] [INFO] Contrôle en cours du module TEXT :
          [UPD] [INFO] Le fichier 'wks_avira/win32/fr/classic-nt/eula.txt' est déjà installé et ne sera pas actualisé.
          [UPD] [INFO] Contrôle en cours du module DRV :
          [UPD] [INFO] Contrôle en cours du module PRODINFO :
          [UPD] [INFO] Contrôle en cours des dépendances pour le mode de mise à jour produit.
          [UPD] [INFO] Les dépendances sont remplies.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\BACKUP\' requiert 5635107 octets d'espace mémoire libre.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\' requiert 16125990 octets d'espace mémoire libre.
          [UPD] [INFO] 'C:\Program Files\Avira\AntiVir Desktop\' requiert 8062995 octets d'espace mémoire libre.
          [UPD] [INFO] Espace mémoire OK.
          [UPD] [INFO] Lecteur : C:\, capacité disponible : 2362421248 octets.
          [UPD] [INFO] Téléchargement en cours de nouveaux fichiers...
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/vdf/antivir2.vdf.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\vdf\antivir2.vdf.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/vdf/antivir3.vdf.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\vdf\antivir3.vdf.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/ave2/win32/int/aecore.dll.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aecore.dll.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/ave2/win32/int/aegen.dll.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aegen.dll.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/ave2/win32/int/aehelp.dll.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aehelp.dll.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/ave2/win32/int/aeheur.dll.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aeheur.dll.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/ave2/win32/int/aepack.dll.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aepack.dll.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/ave2/win32/int/aescn.dll.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aescn.dll.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/ave2/win32/int/aescript.dll.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aescript.dll.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/ave2/win32/int/aeset.dat.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aeset.dat.gz'.
          [UPD] [INFO] Téléchargement de 'http://80.190.143.227/update/ave2/win32/int/aevdf.dll.gz' vers'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\ave2\win32\int\aevdf.dll.gz'.
          [UPD] [INFO] Fichier de licence : version intégrale
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\vdf\antivir2.vdf' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\antivir2.vdf'.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\vdf\antivir3.vdf' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\antivir3.vdf'.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aecore.dll' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aecore.dll'.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aegen.dll' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aegen.dll'.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aehelp.dll' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aehelp.dll'.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aeheur.dll' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aeheur.dll'.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aepack.dll' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aepack.dll'.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aescn.dll' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aescn.dll'.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aescript.dll' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aescript.dll'.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aeset.dat' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aeset.dat'.
          [UPD] [INFO] 'C:\ProgramData\Avira\AntiVir Desktop\TEMP\UPDATE\.\ave2\win32\int\aevdf.dll' a été copié vers 'C:\Program Files\Avira\AntiVir Desktop\aevdf.dll'.
          [UPD] [INFO] Réinitialisation du Avira AntiVir Guard réussie.

          Résumé :
          ********
          11 fichiers téléchargés
          11 fichiers installés
          Fichier(s) téléchargé(s) : antivir2.vdf 7.1.6.1; antivir3.vdf 7.1.6.29; aecore.dll 8.1.8.1; aegen.dll 8.1.1.63; aehelp.dll 8.1.7.0; aeheur.dll 8.1.0.155; aepack.dll 8.2.0.0;
          aescn.dll 8.1.2.5; aescript.dll 8.1.2.33; aeset.dat 8.2.1.23; aevdf.dll 8.1.1.2;

          18:41:09 La mise à jour a été effectuée avec succès !
          0
          1. Contributeur sécurité
            oui car il n'y en a plus besoin et il faut télécharger a chaque fois la dernière version

            colle un rapport antivir
            0
            1. Comment ca je vire tout? Ca va enlever usbfix, combofix, rsit et tout et tout???
              0
              1. Contributeur sécurité
                ok vire tout avec tool clenaer (il sert a virer ce qui a été utilisé et les infections mises en quarantaine )
                0
                1. Et voila le rapport de toolscleaner: (ca sert a quoi celui là??)

                  [ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]

                  --> Recherche:

                  C:\Combofix.txt: trouvé !
                  C:\UsbFix.txt: trouvé !
                  C:\Qoobox: trouvé !
                  C:\UsbFix: trouvé !
                  C:\Rsit: trouvé !
                  C:\Program Files\trend micro\HijackThis.exe: trouvé !
                  C:\Program Files\trend micro\hijackthis.log: trouvé !
                  C:\Qoobox\Quarantine\catchme.log: trouvé !
                  C:\Users\Vaness\Documents\En cas de virus\ComboFix.exe: trouvé !
                  C:\Users\Vaness\Documents\En cas de virus\UsbFix.exe: trouvé !
                  C:\Users\Vaness\Documents\En cas de virus\Rsit.exe: trouvé !
                  0
                  1. Ok, je vais faire tout ça!
                    En tout cas, merci bcp d'avoir été aussi disponible pour régler mon problème!
                    Et chapeau!! :-)
                    0
                    1. Contributeur sécurité
                      ok parfait

                      lance tool cleaner et colle le rapport de suppression
                      https://www.commentcamarche.net/telecharger/

                      _________________

                      avast est moyen
                      mets plutôt antivir et colle un rapport avec
                      https://www.malekal.com/avira-free-security-antivirus-gratuit/

                      pour protéger gratos ton ordi
                      https://www.commentcamarche.net/telecharger/

                      mettre un antivirus

                      ANTIVIR
                      https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
                      -------------
                      des anti-espions :
                      MALWAREBYTE ANTIMALWARE + SPYBOT
                      +
                      SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

                      --------
                      un pare feu :
                      (celui de Windows) ou mieux COMODO ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

                      http://www.clubic.com/telecharger-fiche11071-sunbelt-persona­l-firewall-e(...)
                      https://manuelsdaide.com/contact/
                      http://www.open-files.com/forum/index.php?showtopic=29277
                      https://www.commentcamarche.net/telecharger/ 157 zonealarm

                      -----------

                      CCLEANER pour effacer les traces de surf
                      0
                      1. Non, avast, je le paye pas et voici le deuxième rapport

                        ############################## | UsbFix V6.036 |

                        User : Vaness (Administrateurs) # PC-DE-VANESS
                        Update on 21/09/2009 by Chiquitine29, C_XX & Chimay8
                        Start at: 17:09:31 | 23/09/2009
                        Website : http://pagesperso-orange.fr/NosTools/index.html

                        Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                        Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                        Internet Explorer 8.0.6001.18813
                        Windows Firewall Status : Enabled

                        C:\ -> Disque fixe local # 455,34 Go (78,68 Go free) [HP] # NTFS
                        D:\ -> Disque fixe local # 10,42 Go (1,42 Go free) [FACTORY_IMAGE] # NTFS
                        E:\ -> Disque fixe local # 465,76 Go (465,66 Go free) [NEW_VOLUME] # NTFS
                        F:\ -> Disque CD-ROM
                        G:\ -> Disque CD-ROM
                        H:\ -> Disque amovible
                        I:\ -> Disque amovible
                        J:\ -> Disque amovible
                        K:\ -> Disque amovible # 1,86 Go (1,85 Go free) # FAT
                        L:\ -> Disque amovible # 488,84 Mo (456,61 Mo free) # FAT

                        ############################## | Processus actifs |

                        C:\Windows\System32\smss.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\wininit.exe
                        C:\Windows\system32\csrss.exe
                        C:\Windows\system32\services.exe
                        C:\Windows\system32\lsass.exe
                        C:\Windows\system32\lsm.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\winlogon.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\SLsvc.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\spoolsv.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                        C:\Program Files\Bonjour\mDNSResponder.exe
                        c:\hp\HPEZBTN\HPBtnSrv.exe
                        C:\Windows\system32\LogonUI.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                        C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                        C:\Program Files\CDBurnerXP\NMSAccessU.exe
                        C:\Windows\system32\svchost.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\Windows\system32\svchost.exe
                        C:\Windows\System32\svchost.exe
                        C:\Windows\system32\SearchIndexer.exe
                        C:\Windows\system32\userinit.exe
                        C:\Windows\system32\Dwm.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\Explorer.EXE
                        C:\Windows\system32\WUDFHost.exe
                        C:\Windows\system32\taskeng.exe
                        C:\Windows\system32\runonce.exe
                        C:\Windows\system32\conime.exe
                        C:\Windows\system32\wbem\wmiprvse.exe
                        C:\Windows\system32\taskeng.exe

                        ################## | Fichiers # Dossiers infectieux |

                        Supprimé ! D:\desktop.ini
                        Supprimé ! L:\.\RECYCLER\RECYCLER

                        ################## | Registre # Clés Run infectieuses |

                        Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
                        Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                        ################## | Registre # Mountpoints2 |

                        ################## | Listing des fichiers présent |

                        [02/01/2007 18:30|--a------|74] C:\autoexec.bat
                        [11/04/2009 08:36|-rahs----|333257] C:\bootmgr
                        [03/01/2007 02:26|-ra-s----|8192] C:\BOOTSECT.BAK
                        [23/09/2009 15:11|--a------|19565] C:\ComboFix.txt
                        [18/09/2006 23:43|--a------|10] C:\config.sys
                        [09/11/2008 14:03|-rahs----|0] C:\IO.SYS
                        [09/11/2008 14:03|-rahs----|0] C:\MSDOS.SYS
                        [?|?|?] C:\pagefile.sys
                        [28/07/2008 21:50|--a------|477] C:\RHDSetup.log
                        [23/09/2009 17:13|--a------|3409] C:\UsbFix.txt
                        [22/06/2007 18:44|---hs----|438328] D:\boo.mgr
                        [02/11/2006 02:53|---hs----|438840] D:\bootmgr
                        [03/01/2007 04:33|---hs----|111] D:\MASTER.LOG
                        [27/02/2008 19:23|---hs----|429] D:\pcdr.ini
                        [19/06/2007 17:22|---hs----|181616] D:\Protect.ed
                        [03/01/2007 04:33|---hs----|44] D:\RESTORE.INI
                        [18/07/2007 10:42|---hs----|34] D:\SystemRecovery.txt
                        [01/01/1601 02:00|-r-h-----|0] K:\MEMSTICK.IND
                        [01/01/1601 02:00|-r-h-----|0] K:\MSTK_PRO.IND
                        [18/07/2009 15:37|--ah-----|128] K:\.SonyVID
                        [04/09/2009 15:26|--a------|64000] L:\Carte de visite r‚a.pub
                        [04/09/2009 15:25|--a------|17883] L:\Carte de visite r‚a.jpg
                        [14/07/2009 16:51|--a------|442898] L:\Chlo‚ 14 juillet 2009 (2).jpg
                        [14/07/2009 16:52|--a------|387833] L:\Chlo‚ 14 juillet 2009 (3).jpg
                        [14/07/2009 18:16|--a------|270933] L:\Chlo‚ 14 juillet 2009 (4).jpg
                        [14/07/2009 18:17|--a------|390407] L:\Chlo‚ 14 juillet 2009 (5).jpg
                        [14/07/2009 16:50|--a------|403630] L:\Chlo‚ 14 juillet 2009 (6).jpg
                        [14/07/2009 16:51|--a------|474272] L:\Chlo‚ 14 juillet 2009 (7).jpg
                        [14/07/2009 16:51|--a------|460644] L:\Chlo‚ 14 juillet 2009.jpg
                        [23/07/2009 16:02|--a------|1347877] L:\DSC01885.JPG
                        [23/07/2009 16:02|--a------|1311382] L:\DSC01887.JPG
                        [23/07/2009 16:02|--a------|1303982] L:\DSC01888.JPG
                        [24/07/2009 11:46|--a------|621416] L:\DSC01891.JPG
                        [24/07/2009 11:46|--a------|1364388] L:\DSC01892.JPG
                        [23/07/2009 16:09|--a------|1359897] L:\DSC01893.JPG
                        [24/07/2009 11:46|--a------|1375917] L:\DSC01894.JPG
                        [23/07/2009 16:09|--a------|1274171] L:\DSC01895.JPG
                        [24/07/2009 11:46|--a------|617474] L:\DSC01897.JPG
                        [24/07/2009 11:42|--a------|1166681] L:\DSC01898.JPG
                        [23/07/2009 17:19|--a------|1258613] L:\DSC01899.JPG
                        [23/07/2009 18:10|--a------|1276670] L:\DSC01900.JPG
                        [23/07/2009 18:11|--a------|1283338] L:\DSC01904.JPG
                        [23/07/2009 18:12|--a------|1350366] L:\DSC01905.JPG
                        [23/07/2009 18:37|--a------|1357517] L:\DSC01906.JPG
                        [23/07/2009 18:45|--a------|1297444] L:\DSC01907.JPG
                        [23/07/2009 18:45|--a------|1310549] L:\DSC01908.JPG
                        [23/07/2009 18:45|--a------|1348001] L:\DSC01909.JPG
                        [23/07/2009 18:46|--a------|1381099] L:\DSC01910.JPG
                        [23/07/2009 18:47|--a------|1229462] L:\DSC01912.JPG
                        [23/07/2009 18:49|--a------|1345051] L:\DSC01914.JPG
                        [24/07/2009 11:45|--a------|1376180] L:\DSC01915.JPG
                        [23/07/2009 19:02|--a------|1413536] L:\DSC01916.JPG
                        [23/07/2009 19:02|--a------|1427800] L:\DSC01917.JPG

                        ################## | Vaccination |

                        # C:\autorun.inf -> Folder created by UsbFix.
                        # D:\autorun.inf -> Folder created by UsbFix.
                        # E:\autorun.inf -> Folder created by UsbFix.
                        # K:\autorun.inf -> Folder created by UsbFix.
                        # L:\autorun.inf -> Folder created by UsbFix.

                        ################## | Upload |

                        Veuillez envoyer le fichier : C:\Users\Vaness\Desktop\UsbFix_Upload_Me_PC-de-Vaness.zip : https://www.androidworld.fr/
                        Merci pour votre contribution .

                        ################## | ! Fin du rapport # UsbFix V6.036 ! |
                        0
                        1. Contributeur sécurité
                          ok fais usbfix option 2 et colle le rapport

                          pour avast tu le paye ou pas?
                          0
                          1. Mon PC va très bien, il est guéri!!! :-)))

                            Voici le rapport d'USBfix:

                            ############################## | UsbFix V6.036 |

                            User : Vaness (Administrateurs) # PC-DE-VANESS
                            Update on 21/09/2009 by Chiquitine29, C_XX & Chimay8
                            Start at: 16:09:16 | 23/09/2009
                            Website : http://pagesperso-orange.fr/NosTools/index.html

                            Intel(R) Core(TM)2 Quad CPU Q6600 @ 2.40GHz
                            Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                            Internet Explorer 8.0.6001.18813
                            Windows Firewall Status : Enabled

                            C:\ -> Disque fixe local # 455,34 Go (83,5 Go free) [HP] # NTFS
                            D:\ -> Disque fixe local # 10,42 Go (1,42 Go free) [FACTORY_IMAGE] # NTFS
                            E:\ -> Disque fixe local # 465,76 Go (465,66 Go free) [NEW_VOLUME] # NTFS
                            F:\ -> Disque CD-ROM
                            G:\ -> Disque CD-ROM
                            H:\ -> Disque amovible
                            I:\ -> Disque amovible
                            J:\ -> Disque amovible
                            K:\ -> Disque amovible # 1,86 Go (1,85 Go free) # FAT
                            L:\ -> Disque amovible # 488,84 Mo (456,61 Mo free) # FAT

                            ############################## | Processus actifs |

                            C:\Windows\System32\smss.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\wininit.exe
                            C:\Windows\system32\csrss.exe
                            C:\Windows\system32\services.exe
                            C:\Windows\system32\lsass.exe
                            C:\Windows\system32\lsm.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\winlogon.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\SLsvc.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\spoolsv.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            c:\hp\HPEZBTN\HPBtnSrv.exe
                            C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                            C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                            C:\Windows\system32\Dwm.exe
                            C:\Program Files\CDBurnerXP\NMSAccessU.exe
                            C:\Windows\system32\svchost.exe
                            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\Explorer.EXE
                            C:\Windows\system32\taskeng.exe
                            C:\Windows\System32\svchost.exe
                            C:\Windows\system32\SearchIndexer.exe
                            C:\Windows\system32\WUDFHost.exe
                            C:\Windows\system32\taskeng.exe
                            C:\Program Files\Windows Defender\MSASCui.exe
                            C:\hp\support\hpsysdrv.exe
                            C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                            C:\Windows\RtHDVCpl.exe
                            C:\Windows\System32\mobsync.exe
                            C:\Windows\system32\schtasks.exe
                            C:\Windows\system32\svchost.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Windows\System32\rundll32.exe
                            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                            C:\Windows\WindowsMobile\wmdc.exe
                            C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                            C:\Windows\system32\jusched.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\Windows Sidebar\sidebar.exe
                            C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
                            C:\Windows\ehome\ehtray.exe
                            C:\Windows\ehome\ehmsas.exe
                            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                            C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe
                            C:\Program Files\SFR\Media Center\MediaCenter.exe
                            C:\Program Files\Electronic Arts\EADM\Core.exe
                            C:\Program Files\Nosibay\VPbubble\Launcher.exe
                            C:\Program Files\Windows Media Player\wmpnscfg.exe
                            C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
                            C:\Program Files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe
                            C:\Program Files\Windows Media Player\wmpnetwk.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\Program Files\SFR\Media Center\httpd\httpd.exe
                            C:\Program Files\SFR\Media Center\httpd\httpd.exe
                            C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
                            C:\Program Files\Nosibay\VPbubble\VPbubble.exe
                            C:\Program Files\Windows Live\Messenger\usnsvc.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\hp\kbd\kbd.exe
                            c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
                            C:\PROGRA~1\MICROS~3\Office12\OUTLOOK.EXE
                            C:\Program Files\Internet Explorer\IEXPLORE.EXE
                            C:\Program Files\Internet Explorer\IEXPLORE.EXE
                            C:\Program Files\Windows Live\Toolbar\wltuser.exe
                            C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
                            C:\Program Files\Internet Explorer\IEXPLORE.EXE
                            C:\Program Files\Windows Media Player\wmplayer.exe
                            C:\Windows\system32\SearchProtocolHost.exe
                            C:\Windows\system32\SearchFilterHost.exe
                            C:\Windows\system32\wbem\wmiprvse.exe
                            C:\Windows\system32\conime.exe

                            ################## | Fichiers # Dossiers infectieux |

                            D:\desktop.ini
                            L:\.\RECYCLER\RECYCLER
                            L:\RECYCLER\RECYCLER

                            ################## | Registre # Clés Run infectieuses |

                            [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
                            [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
                            [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                            ################## | Registre # Mountpoints2 |

                            ################## | ! Fin du rapport # UsbFix V6.036 ! |
                            0
                            1. Bon, j'ai désinstaller avast et utilisé combofix, voici le rapport:

                              ComboFix 09-09-22.03 - Vaness 23/09/2009 14:58.1.4 - NTFSx86
                              Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6002.2.1252.33.1036.18.3326.2201 [GMT 2:00]
                              Lancé depuis: c:\users\Vaness\Desktop\ComboFix.exe
                              SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
                              .

                              (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
                              c:\$recycle.bin\S-1-5-21-2573755492-1421172810-2144186710-500
                              c:\$recycle.bin\S-1-5-21-404924975-3073534081-1105552264-500
                              c:\$recycle.bin\S-1-5-21-909821549-444324555-4134441507-1000
                              c:\program files\TS\tsc.exe
                              c:\users\Vaness\AppData\Roaming\Microsoft\Clip Organizer\mstore10.mgc
                              c:\users\Vaness\AppData\Roaming\Microsoft\Clip Organizer\Offic10.MGC
                              c:\windows\Installer\14c79d.msp
                              c:\windows\Installer\1a01c74.msi
                              c:\windows\system32\ealregsnapshot1.reg

                              .
                              ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                              .

                              -------\Service_Boonty Games

                              ((((((((((((((((((((((((((((( Fichiers créés du 2009-08-23 au 2009-09-23 ))))))))))))))))))))))))))))))))))))
                              .

                              2009-09-23 13:04 . 2009-09-23 13:04 -------- d-----w- c:\users\Default\AppData\Local\temp
                              2009-09-21 19:36 . 2009-09-21 19:43 -------- d-----w- c:\program files\trend micro
                              2009-09-21 19:36 . 2009-09-21 19:36 -------- d-----w- C:\rsit
                              2009-09-21 18:25 . 2009-09-21 18:25 -------- d-----w- c:\program files\CCleaner
                              2009-09-21 18:18 . 2009-09-10 12:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                              2009-09-21 18:18 . 2009-09-21 18:18 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                              2009-09-21 18:18 . 2009-09-10 12:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
                              2009-09-21 17:21 . 2009-09-21 17:21 -------- d-----w- c:\users\Vaness\AppData\Roaming\Malwarebytes
                              2009-09-21 17:20 . 2009-09-21 17:20 -------- d-----w- c:\programdata\Malwarebytes
                              2009-09-21 16:07 . 2009-09-21 16:07 -------- d-----w- c:\program files\Enigma Software Group
                              2009-09-21 15:34 . 2009-09-23 13:03 -------- d-----w- c:\program files\TS
                              2009-09-16 18:48 . 2009-09-16 18:48 -------- d-----w- c:\program files\MixMeister BPM Analyzer
                              2009-09-14 16:22 . 2009-05-18 12:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
                              2009-09-14 16:22 . 2008-04-17 11:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
                              2009-09-14 16:22 . 2009-09-14 16:22 -------- d-----w- c:\program files\iPod
                              2009-09-14 16:22 . 2009-09-14 16:22 -------- d-----w- c:\programdata\{755AC846-7372-4AC8-8550-C52491DAA8BD}
                              2009-09-14 16:10 . 2009-09-14 16:11 -------- d-----w- c:\program files\QuickTime
                              2009-09-11 16:02 . 2009-09-11 16:02 -------- d-----w- c:\users\Vaness\AppData\Local\Windows Live Writer
                              2009-09-11 16:02 . 2009-09-11 16:02 -------- d-----w- c:\users\Vaness\AppData\Roaming\Windows Live Writer
                              2009-09-06 09:34 . 2009-09-06 09:34 -------- d-----w- C:\tmp
                              2009-09-06 09:34 . 2009-09-06 09:34 -------- d-----w- c:\users\Vaness\AppData\Roaming\Nosibay
                              2009-09-06 09:34 . 2009-09-06 09:34 -------- d-----w- c:\program files\Nosibay
                              2009-09-04 14:41 . 2009-09-04 15:19 -------- d-----w- c:\users\Vaness\AppData\Roaming\Desktopicon
                              2009-09-04 14:08 . 2009-09-04 14:08 -------- d-----w- c:\program files\Pvm
                              2009-09-04 13:34 . 2009-09-04 13:35 -------- d-----w- c:\users\Vaness\AppData\Roaming\ACAMPREF
                              2009-09-03 17:13 . 2009-08-29 00:14 28672 ----a-w- c:\windows\system32\Apphlpdm.dll
                              2009-09-03 17:13 . 2009-08-29 00:27 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll
                              2009-08-30 16:34 . 2009-08-30 16:33 411368 ----a-w- c:\windows\system32\deploytk.dll
                              2009-08-28 17:42 . 2009-08-28 17:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
                              2009-08-28 17:42 . 2009-08-28 17:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
                              2009-08-26 13:11 . 2009-06-22 10:09 2048 ----a-w- c:\windows\system32\tzres.dll

                              .
                              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2009-09-22 15:30 . 2008-02-29 07:48 -------- d-----w- c:\programdata\Microsoft Help
                              2009-09-21 19:58 . 2008-02-27 17:26 112920 ----a-w- c:\users\Vaness\AppData\Local\GDIPFONTCACHEV1.DAT
                              2009-09-21 16:08 . 2009-08-01 08:51 2119680 ----a-w- c:\users\Vaness\AppData\Local\cooliris-win-ie-release-1.11.2.27471.en-US.msi
                              2009-09-21 12:12 . 2007-01-03 00:26 716060 ----a-w- c:\windows\system32\perfh00C.dat
                              2009-09-21 12:12 . 2007-01-03 00:26 144214 ----a-w- c:\windows\system32\perfc00C.dat
                              2009-09-14 16:41 . 2008-03-25 14:53 -------- d-----w- c:\users\Vaness\AppData\Roaming\Apple Computer
                              2009-09-14 16:22 . 2009-07-15 19:43 -------- d-----w- c:\program files\iTunes
                              2009-09-14 16:22 . 2008-03-25 14:50 -------- d-----w- c:\program files\Common Files\Apple
                              2009-09-09 21:09 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
                              2009-09-09 21:09 . 2008-12-24 11:29 -------- d-----w- c:\program files\Microsoft Silverlight
                              2009-09-04 14:41 . 2009-03-04 18:03 -------- d-----w- c:\program files\FormatFactory
                              2009-08-30 16:33 . 2007-01-02 16:31 -------- d-----w- c:\program files\Java
                              2009-08-24 14:10 . 2008-07-01 17:22 -------- d-----w- c:\program files\Electronic Arts
                              2009-08-22 13:48 . 2009-08-22 13:48 -------- d-----w- c:\program files\Microsoft Office Outlook Connector
                              2009-08-22 13:47 . 2009-01-02 09:38 -------- d-----w- c:\program files\MSECACHE
                              2009-08-20 16:11 . 2008-04-23 05:14 -------- d-----w- c:\program files\Common Files\Adobe
                              2009-08-14 16:27 . 2009-09-09 07:32 904776 ----a-w- c:\windows\system32\drivers\tcpip.sys
                              2009-08-14 15:53 . 2009-09-09 07:32 17920 ----a-w- c:\windows\system32\netevent.dll
                              2009-08-14 13:49 . 2009-09-09 07:32 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE
                              2009-08-14 13:49 . 2009-09-09 07:32 17920 ----a-w- c:\windows\system32\ROUTE.EXE
                              2009-08-14 13:49 . 2009-09-09 07:32 11264 ----a-w- c:\windows\system32\MRINFO.EXE
                              2009-08-14 13:49 . 2009-09-09 07:32 27136 ----a-w- c:\windows\system32\NETSTAT.EXE
                              2009-08-14 13:49 . 2009-09-09 07:32 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE
                              2009-08-14 13:49 . 2009-09-09 07:32 19968 ----a-w- c:\windows\system32\ARP.EXE
                              2009-08-14 13:49 . 2009-09-09 07:32 10240 ----a-w- c:\windows\system32\finger.exe
                              2009-08-14 13:48 . 2009-09-09 07:32 30720 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
                              2009-08-14 13:48 . 2009-09-09 07:32 105984 ----a-w- c:\windows\system32\netiohlp.dll
                              2009-08-04 09:38 . 2007-01-02 16:29 -------- d---a-w- c:\program files\Common Files\LightScribe
                              2009-07-27 07:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Sidebar
                              2009-07-27 07:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Photo Gallery
                              2009-07-27 07:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Journal
                              2009-07-27 07:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Collaboration
                              2009-07-27 07:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Calendar
                              2009-07-27 07:00 . 2006-11-02 12:37 -------- d-----w- c:\program files\Windows Defender
                              2009-07-21 21:52 . 2009-07-29 08:53 915456 ----a-w- c:\windows\system32\wininet.dll
                              2009-07-21 21:47 . 2009-07-29 08:53 109056 ----a-w- c:\windows\system32\iesysprep.dll
                              2009-07-21 21:47 . 2009-07-29 08:53 71680 ----a-w- c:\windows\system32\iesetup.dll
                              2009-07-21 20:13 . 2009-07-29 08:53 133632 ----a-w- c:\windows\system32\ieUnatt.exe
                              2009-07-17 13:54 . 2009-08-12 07:26 71680 ----a-w- c:\windows\system32\atl.dll
                              2009-07-15 12:40 . 2009-08-12 07:25 8147456 ----a-w- c:\windows\system32\wmploc.DLL
                              2009-07-15 12:39 . 2009-08-12 07:25 313344 ----a-w- c:\windows\system32\wmpdxm.dll
                              2009-07-15 12:39 . 2009-08-12 07:25 4096 ----a-w- c:\windows\system32\dxmasf.dll
                              2009-07-15 12:39 . 2009-08-12 07:25 7680 ----a-w- c:\windows\system32\spwmp.dll
                              2009-07-11 19:01 . 2009-09-09 07:32 513536 ----a-w- c:\windows\system32\wlansvc.dll
                              2009-07-11 19:01 . 2009-09-09 07:32 302592 ----a-w- c:\windows\system32\wlansec.dll
                              2009-07-11 19:01 . 2009-09-09 07:32 293376 ----a-w- c:\windows\system32\wlanmsm.dll
                              2009-07-11 19:01 . 2009-09-09 07:32 65024 ----a-w- c:\windows\system32\wlanapi.dll
                              2009-07-11 17:03 . 2009-09-09 07:32 127488 ----a-w- c:\windows\system32\L2SecHC.dll
                              2007-01-03 00:41 . 2007-01-03 00:28 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
                              .

                              ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                              REGEDIT4

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
                              "HPAdvisor"="c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-10-03 1783136]
                              "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
                              "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
                              "msnlivesearch"="c:\program files\Windows Live\MessengerSearchAddon\msgrsrch.exe" [2008-10-09 49152]
                              "Neuf Media Center"="c:\program files\SFR\Media Center\MediaCenter.exe" [2008-10-10 726336]
                              "EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]
                              "VPbubble"="c:\program files\Nosibay\VPbubble\launcher.exe" [2009-08-24 239120]
                              "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
                              "hpsysdrv"="c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
                              "KBD"="c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
                              "OsdMaestro"="c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
                              "SunJavaUpdateReg"="c:\windows\system32\jureg.exe" [2007-04-07 54936]
                              "NvSvc"="c:\windows\system32\nvsvc.dll" [2008-01-10 92704]
                              "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-01-10 8530464]
                              "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-01-10 88608]
                              "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
                              "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
                              "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
                              "Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
                              "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2008-06-02 178712]
                              "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-08-30 149280]
                              "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-09-04 417792]
                              "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-08 305440]
                              "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-01-15 4874240]

                              c:\users\Vaness\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                              OneNote 2007 - Capture d'‚cran et lancement.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
                              Outil de d‚tection de support Picture Motion Browser.lnk - c:\program files\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe [2008-12-25 385024]

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                              "EnableUIADesktopToggle"= 0 (0x0)

                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
                              @="Service"

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                              "AntiVirusOverride"=""
                              "FirewallOverride"=""
                              "UpdatesDisableNotify"=""

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                              "DisableMonitoring"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                              "DisableMonitoring"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                              "DisableMonitoring"=dword:00000001

                              [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
                              "VistaSp2"=hex(b):9a,e5,e5,0f,89,0e,ca,01

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                              "{5849F780-6F5C-478F-8E98-71C9A4F32FF0}"= c:\program files\Cyberlink\PowerDirector\PDR.EXE:CyberLink PowerDirector
                              "{FE3E9D01-7FD5-46B3-9996-039F6A97C89C}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
                              "{497775D5-12F6-4DBC-89AC-BE960C18CFB6}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
                              "TCP Query User{38B812F5-67DD-405E-AA1D-569F216116C2}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
                              "UDP Query User{05DBC9DD-81EC-4AD2-A6DB-A3E503ED32CF}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
                              "TCP Query User{2C6CA55C-8B8B-46B3-92F5-B3817FAAA54E}c:\\program files\\emule\\emule.exe"= UDP:c:\program files\emule\emule.exe:eMule
                              "UDP Query User{7D6816F2-3DC2-43B8-9119-A103EA123E3F}c:\\program files\\emule\\emule.exe"= TCP:c:\program files\emule\emule.exe:eMule
                              "TCP Query User{753990D5-6D2E-4E09-91EB-4C81B35521A1}c:\\program files\\electronic arts\\eadm\\core.exe"= UDP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
                              "UDP Query User{8136D1E7-A382-4A8D-8DC4-B3B4DE210322}c:\\program files\\electronic arts\\eadm\\core.exe"= TCP:c:\program files\electronic arts\eadm\core.exe:EA Download Manager
                              "{D2904B8A-EFFD-4758-AD44-72DF12F50F46}"= c:\program files\HP\DVDPlay\DVDPlay.exe:DVD Play
                              "{44A79FF8-F398-40D5-96C8-C432C0BEB08A}"= c:\program files\HP\DVDPlay\DPService.exe:DVD Play Resident Program
                              "{F0D32B4A-EBBB-4899-9AF2-13BEAD87619E}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
                              "{772EFFC9-925B-41D3-94C2-4E7C993D2F45}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
                              "{EA5975D9-6314-478A-B41D-28A2EF5C550F}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                              "TCP Query User{5F05A79A-DF00-4365-A2EE-4F3E97569A0D}c:\\program files\\sfr\\media center\\httpd\\httpd.exe"= UDP:c:\program files\sfr\media center\httpd\httpd.exe:Apache HTTP Server
                              "UDP Query User{90BA0F9B-DCEE-49A6-A177-DB0246DE4733}c:\\program files\\sfr\\media center\\httpd\\httpd.exe"= TCP:c:\program files\sfr\media center\httpd\httpd.exe:Apache HTTP Server
                              "{E121E1A0-48E1-491F-9178-979C0A3A4507}"= UDP:c:\program files\SFR\Media Center\httpd\httpd.exe:Serveur de partage Media Center (Player SFR)
                              "{9F7C2D05-F941-4CF7-925E-4F200DFFCCCC}"= TCP:c:\program files\SFR\Media Center\httpd\httpd.exe:Serveur de partage Media Center (Player SFR)
                              "TCP Query User{B7AF5DD8-7B7C-4DAA-9B1C-7B6BE1A7F5D7}c:\\users\\vaness\\appdata\\local\\temp\\qztemp\\emule.exe"= UDP:c:\users\vaness\appdata\local\temp\qztemp\emule.exe:emule.exe
                              "UDP Query User{A74095FE-845C-4908-86E9-C99F1B8DFC8A}c:\\users\\vaness\\appdata\\local\\temp\\qztemp\\emule.exe"= TCP:c:\users\vaness\appdata\local\temp\qztemp\emule.exe:emule.exe
                              "{079EB4CB-F47B-4CC1-B942-952BB1B7CCD3}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
                              "{4E79F7A6-1620-468D-8DAA-8ED8B8405CDE}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
                              "{2ED30084-47C5-42F2-8643-9ED59A782C5C}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
                              "{736CF841-4679-472C-A681-E7A64C385C07}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 7.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server
                              "{AEE354F7-5D0D-484A-A08F-DB41E3ECF52E}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
                              "{35989A8C-D345-4956-9E4B-5BF37D37E853}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes

                              [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
                              "EnableFirewall"= 0 (0x0)

                              R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263};c:\program files\HP\DVDPlay\000.fcl [02/01/2007 18:24 39408]
                              R2 HPBtnSrv;HP Chasis Button Service;c:\hp\HPEZBTN\HPBtnSrv.exe [02/01/2007 18:31 198240]
                              R3 netr73;USB Wireless 802.11 b/g Adaptor Driver for Vista;c:\windows\System32\drivers\netr73.sys [26/02/2008 09:17 493568]
                              S3 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [24/12/2008 13:28 55264]
                              S3 fsssvc;Windows Live Contrôle parental;c:\program files\Windows Live\Family Safety\fsssvc.exe [08/12/2008 18:01 533344]

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                              WindowsMobile REG_MULTI_SZ wcescomm rapimgr
                              LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
                              .
                              Contenu du dossier 'Tâches planifiées'

                              2009-09-22 c:\windows\Tasks\User_Feed_Synchronization-{22E7A771-D69F-491E-98DB-F97A59AF9AAD}.job
                              - c:\windows\system32\msfeedssync.exe [2009-07-29 20:13]
                              .
                              .
                              ------- Examen supplémentaire -------
                              .
                              uStart Page = www.google.fr/
                              mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=81&bd=Pavilion&pf=desktop
                              uInternet Settings,ProxyOverride = *.local
                              IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
                              IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
                              DPF: {C1FDEE68-98D5-4F42-A4DD-D0BECF5077EB} - hxxp://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-27-0.cab
                              .
                              - - - - ORPHELINS SUPPRIMES - - - -

                              HKLM-Run-HP Health Check Scheduler - [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
                              AddRemove-TS - c:\program files\TS\tsc.exe

                              **************************************************************************
                              Recherche de processus cachés ...

                              Recherche d'éléments en démarrage automatique cachés ...

                              Recherche de fichiers cachés ...

                              Scan terminé avec succès
                              Fichiers cachés:

                              **************************************************************************

                              [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{22D78859-9CE9-4B77-BF18-AC83E81A9263}]
                              "ImagePath"="\??\c:\program files\HP\DVDPlay\000.fcl"
                              .
                              --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                              [HKEY_USERS\S-1-5-21-2573755492-1421172810-2144186710-1000\Software\SecuROM\License information*]
                              "datasecu"=hex:af,e3,8f,4a,a3,76,28,8e,c0,89,7a,7a,1c,61,53,d4,75,3a,58,b8,6f,
                              33,78,b6,22,83,d7,51,dc,59,20,54,54,53,c2,74,dd,ee,2d,fd,23,00,95,d2,bf,4d,\
                              "rkeysecu"=hex:cd,9f,2b,72,0b,61,ac,d6,6a,ec,57,2d,99,fe,85,bf
                              .
                              --------------------- DLLs chargées dans les processus actifs ---------------------

                              - - - - - - - > 'Explorer.exe'(1752)
                              c:\program files\Hewlett-Packard\HP Advisor\Pillars\Market\MLDeskBand.dll
                              .
                              ------------------------ Autres processus actifs ------------------------
                              .
                              c:\windows\System32\audiodg.exe
                              c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              c:\program files\Bonjour\mDNSResponder.exe
                              c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
                              c:\program files\Common Files\LightScribe\LSSrvc.exe
                              c:\program files\CDBurnerXP\NMSAccessU.exe
                              c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                              c:\windows\System32\WUDFHost.exe
                              c:\program files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
                              c:\program files\Windows Media Player\wmpnetwk.exe
                              .
                              **************************************************************************
                              .
                              Heure de fin: 2009-09-23 15:11 - La machine a redémarré
                              ComboFix-quarantined-files.txt 2009-09-23 13:11

                              Avant-CF: 90 129 260 544 octets libres
                              Après-CF: 89 649 893 376 octets libres

                              253 --- E O F --- 2009-09-22 15:32
                              0
                              1. Contributeur sécurité
                                oui on le remettra après si tu n'arrive pas a le désactiver
                                0
                                1. Je dois désinstaller completement avast??
                                  0
                                  1. Je n'arrive pas a désactiver avast antivirus. J'ai pourtant cliquer sur désactiver la protection résidente mais combofix me dit qu'avast antivirus et avast antispyware est toujours actif! Je suis bloqué pour continuer!
                                    Comment puis je completement desactiver avast??
                                    0
                                    1. Contributeur sécurité
                                      désactive le le temps de faire combofix
                                      0
                                      • 1
                                      • 2