Virus protector

Bonjour,
quand je demarre le pc(Vista),le bureau ne s'affiche pas,mais c'est Virus protector.
Quand je cherche un peu,je trouve que le processus s'appelle "aadmvrqas.exe".
Evidement,j'ai au prealable cherche sur le forum et les solutions avec rogue remover et SmitFraudFix non plus.
Je viens de faire un scan avec MBAM et toujours rien.

Merci d'avance
Configuration: Windows Vista / Internet Explorer 7.0

26 réponses

Résumé de la discussion

Une infection survient sous Windows Vista où le bureau reste caché et un processus nuisible aadmvrqas.exe est détecté, avec Virus Protector actif et des tentatives de détournement infructueuses. Plusieurs solutions sont évoquées, allant de Rogue Remover et SmitFraudFix à ComboFix et UsbFix, avec MBAM en dernier recours et vérifications avant reconnection à Internet. Des rapports antivirus varient entre Trojan.Win32.SuspectCRC et Win32:Trojan, et des éléments comme keymaker.exe ou des entrées de registre sont signalés comme supprimés ou mis en quarantaine. En parallèle, des échanges demandent des logs RSIT pour finaliser l’analyse et orienter les actions à venir, sans annonce de résolution, mais avec un suivi nécessaire.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    ok

    la suppression s'est bien passée

    le pc va t il toujour bien ?

    relances RSIT et postes le rapport log stp que l'on finalise ton affaire
    1. Contributeur sécurité
      oups...avec la nouvelle version CCM, je t'ai un peu zappé
      désolé

      donc

      /!\ ATTENTION /!\ Le script qui suit a été écrit spécialement pour Marvolo, il n'est pas transposable sur un autre ordinateur !

      crées un sur ton bureau un nouveau fichier bloc note que tu nommeras CFScrip.txt
      Copies y ce texte dedans et enregistres le

      KillAll::

      File::
      C:\Windows\system32\aiXDKcoJh.dll
      C:\Windows\system32\aadmvrqas.exe


      * Désactive tes logiciels de protection
      * Fais un glisser/déposer de ce fichier CFScript.txt sur le fichier Combofix.exe (comme le lien suivant)
      http://apu.mabul.org/up/apu/2008/09/06/img-2258535my8h.gif

      * Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
      * Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
      * Si le fichier ne s'ouvre pas, il se trouve ici ? C:\ComboFix.txt


      Je cherche beaucoup...et maintenant je trouve !
      (sourire)
      1. Contributeur sécurité
        ok

        je demande une validation de script de suppression de ces deux fichiers infectés et je te poste ca
        1. Rapport aiXDKcoJh.dll

          Fichier aiXDKcoJh.dll reçu le 2010.03.18 02:33:52 (UTC)
          Antivirus Version Dernière mise à jour Résultat

          a-squared 4.5.0.50 2010.03.18 Trojan.Win32.SuspectCRC!IK
          AhnLab-V3 5.0.0.2 2010.03.18 -
          AntiVir 8.2.1.194 2010.03.17 TR/FakeMagic.A.5
          Antiy-AVL 2.0.3.7 2010.03.17 -
          Authentium 5.2.0.5 2010.03.18 -
          Avast 4.8.1351.0 2010.03.17 Win32:Trojan-gen
          Avast5 5.0.332.0 2010.03.17 Win32:Trojan-gen
          AVG 9.0.0.787 2010.03.17 SHeur3.CTH
          BitDefender 7.2 2010.03.18 -
          CAT-QuickHeal 10.00 2010.03.17 -
          ClamAV 0.96.0.0-git 2010.03.18 -
          Comodo 4301 2010.03.18 -
          DrWeb 5.0.1.12222 2010.03.18 Trojan.Fakealert.13764
          eSafe 7.0.17.0 2010.03.17 -
          eTrust-Vet 35.2.7371 2010.03.17 -
          F-Prot 4.5.1.85 2010.03.17 -
          F-Secure 9.0.15370.0 2010.03.18 -
          Fortinet 4.0.14.0 2010.03.15 -
          GData 19 2010.03.18 Win32:Trojan-gen
          Ikarus T3.1.1.80.0 2010.03.18 Trojan.Win32.SuspectCRC
          Jiangmin 13.0.900 2010.03.17 -
          K7AntiVirus 7.10.1000 2010.03.17 -
          Kaspersky 7.0.0.125 2010.03.17 -
          McAfee 5923 2010.03.17 -
          McAfee+Artemis 5923 2010.03.17 -
          McAfee-GW-Edition 6.8.5 2010.03.17 Trojan.FakeMagic.A.5
          Microsoft 1.5605 2010.03.17 Trojan:Win32/FakeMagic
          NOD32 4953 2010.03.17 a variant of Win32/Kryptik.CYZ
          Norman 6.04.08 2010.03.17 -
          nProtect 2009.1.8.0 2010.03.17 -
          Panda 10.0.2.2 2010.03.17 -
          PCTools 7.0.3.5 2010.03.18 -
          Prevx 3.0 2010.03.18 -
          Rising 22.39.03.01 2010.03.18 -
          Sophos 4.51.0 2010.03.18 -
          Sunbelt 5945 2010.03.18 Trojan.Win32.Generic!SB.0
          Symantec 20091.2.0.41 2010.03.18 Suspicious.Insight
          TheHacker 6.5.2.0.236 2010.03.17 Trojan/Kryptik.cyz
          TrendMicro 9.120.0.1004 2010.03.18 -
          VBA32 3.12.12.2 2010.03.17 -
          ViRobot 2010.3.17.2232 2010.03.17 -
          VirusBuster 5.0.27.0 2010.03.17 -

          Information additionnelle
          File size: 1471488 bytes
          MD5...: 2551f1e47e06584eec0b28e3598dc02f
          SHA1..: 9fbf72c45ee941a0f3ca6325553193d41790aa43
          SHA256: 2a04255b600b394bfbc82afd01935344244348e5be414b5570a6a981d2d2aacf
          ssdeep: 24576:rx8bEsE+HMbLAPZ1wQftekVSHKksU2w9c/K7uxvkF9TIlien0qr:rmVLc0<BR>h1BFzAKXw9+xS9TIH7r<BR>
          PEiD..: -
          PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x1000<BR>timedatestamp.....: 0x42316426 (Fri Mar 11 09:25:58 2005)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 5 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x155000 0x154600 8.00 48c3a670e88726301645809204ab1c5d<BR>.rdata 0x156000 0xc000 0xbc00 7.61 adb6b04c1859327dfd38853f33c181f3<BR>.data 0x162000 0xea000 0x2600 7.93 61266ef390ca5ba1c0b47493745682b7<BR>.idata 0x24c000 0x1000 0xa00 4.63 824e95152f6c5aa347e58aa700766f8f<BR>.rsrc 0x24d000 0x4000 0x3e00 4.38 e020776af0ebb38bf05387d846c21eec<BR><BR>( 6 imports ) <BR>> KERNEL32.dll: CloseHandle, CreateDirectoryA, EnumResourceNamesA, ExitProcess, GetCommandLineA, GetFileSize, GetModuleHandleA, GetStartupInfoA, HeapAlloc, LoadResource, MultiByteToWideChar, QueryPerformanceCounter, RemoveDirectoryA, RtlUnwind, SetLastError, SetUnhandledExceptionFilter, SleepEx, VirtualAlloc<BR>> user32.dll: EndPaint, EmptyClipboard, GetDlgItem, CharUpperBuffA, CharToOemBuffA, GetWindowTextA, MessageBoxA, SetFocus, SetMenuInfo, ShowCaret, DrawMenuBar<BR>> advapi32.dll: RegOpenKeyExA, RegLoadKeyA, RegEnumKeyA, RegCloseKey, RegQueryValueA<BR>> ole32.dll: OleInitialize, OleGetClipboard, OleUninitialize, CreateILockBytesOnHGlobal, CoUninitialize, CoRegisterClassObject, RegisterDragDrop, ReleaseStgMedium, StringFromGUID2, WriteClassStg, DoDragDrop, CLSIDFromString, CoCreateInstance, CoGetClassObject, CoInitialize<BR>> wininet.dll: InternetGetCookieA, InternetGetLastResponseInfoA, InternetQueryDataAvailable, InternetSetFilePointer, InternetSetOptionExA, InternetSetStatusCallbackA, InternetCrackUrlA, InternetConnectA, HttpSendRequestA, HttpQueryInfoA, HttpOpenRequestA, HttpAddRequestHeadersA, InternetCloseHandle<BR>> shell32.dll: SHGetFileInfoA, SHGetMalloc, SHGetPathFromIDListA, ShellExecuteA, ShellExecuteExW, SHGetDesktopFolder<BR><BR>( 0 exports ) <BR>
          RDS...: NSRL Reference Data Set<BR>-
          pdfid.: -sigcheck:<BR>publisher....: Westwood Studios<BR>copyright....: Copyright (c) 2000 Westwood Studios<BR>product......: Command _ Conquer : Tiberian Sun<BR>description..: Main executable for Tiberian Sun<BR>original name: Sun.exe<BR>internal name: Sun<BR>file version.: 2.03<BR>comments.....: <BR>signers......: -<BR>signing date.: -<BR>verified.....: Unsigned<BR>
          trid..: Generic Win/DOS Executable (49.9%)<BR>DOS Executable Generic (49.8%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
          1. RAPPORT aadmvrqas.exe

            Fichier aadmvrqas.exe reçu le 2010.03.18 02:28:38 (UTC)
            Antivirus Version Dernière mise à jour Résultat

            a-squared 4.5.0.50 2010.03.18 Trojan.Win32.SuspectCRC!IK
            AhnLab-V3 5.0.0.2 2010.03.17 -
            AntiVir 8.2.1.194 2010.03.17 TR/FakeMagic.A.5
            Antiy-AVL 2.0.3.7 2010.03.17 -
            Authentium 5.2.0.5 2010.03.18 -
            Avast 4.8.1351.0 2010.03.17 -
            Avast5 5.0.332.0 2010.03.17 -
            AVG 9.0.0.787 2010.03.17 SHeur3.CTH
            BitDefender 7.2 2010.03.18 -
            CAT-QuickHeal 10.00 2010.03.17 -
            ClamAV 0.96.0.0-git 2010.03.18 -
            Comodo 4301 2010.03.18 -
            DrWeb 5.0.1.12222 2010.03.18 Trojan.Fakealert.13764
            eSafe 7.0.17.0 2010.03.17 -
            eTrust-Vet 35.2.7371 2010.03.17 -
            F-Prot 4.5.1.85 2010.03.17 -
            F-Secure 9.0.15370.0 2010.03.18 -
            Fortinet 4.0.14.0 2010.03.15 -
            GData 19 2010.03.18 -
            Ikarus T3.1.1.80.0 2010.03.18 Trojan.Win32.SuspectCRC
            Jiangmin 13.0.900 2010.03.17 -
            K7AntiVirus 7.10.1000 2010.03.17 -
            Kaspersky 7.0.0.125 2010.03.17 -
            McAfee 5923 2010.03.17 -
            McAfee+Artemis 5923 2010.03.17 -
            McAfee-GW-Edition 6.8.5 2010.03.17 Trojan.FakeMagic.A.5
            Microsoft 1.5605 2010.03.17 Trojan:Win32/FakeMagic
            NOD32 4953 2010.03.17 a variant of Win32/Kryptik.CYZ
            Norman 6.04.08 2010.03.17 -
            nProtect 2009.1.8.0 2010.03.17 -
            Panda 10.0.2.2 2010.03.17 -
            PCTools 7.0.3.5 2010.03.18 -
            Prevx 3.0 2010.03.18 -
            Rising 22.39.03.01 2010.03.18 -
            Sophos 4.51.0 2010.03.18 -
            Sunbelt 5945 2010.03.18 Trojan.Win32.Generic!SB.0
            Symantec 20091.2.0.41 2010.03.18 Suspicious.Insight
            TheHacker 6.5.2.0.236 2010.03.17 Trojan/Kryptik.cyz
            TrendMicro 9.120.0.1004 2010.03.18 -
            VBA32 3.12.12.2 2010.03.17 -
            ViRobot 2010.3.17.2232 2010.03.17 -
            VirusBuster 5.0.27.0 2010.03.17 -

            Information additionnelle
            File size: 1471488 bytes
            MD5...: 2de28b05c1d8196f0aeca63de43a8667
            SHA1..: 79609d65d3ce66d5cef2656f7856c7deee55fe09
            SHA256: dc4ce80bfc64196b508f6a813fac8cec8052bcb12eee4a4af4c08016f1f3ec9e
            ssdeep: 24576:Lx8bEsE+HMbLAPZ1wQftekVSHKksU2w9c/K7uxvkF9TIlien0qr:LmVLc0<BR>h1BFzAKXw9+xS9TIH7r<BR>
            PEiD..: -
            PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x1000<BR>timedatestamp.....: 0x42316426 (Fri Mar 11 09:25:58 2005)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 5 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x155000 0x154600 8.00 48c3a670e88726301645809204ab1c5d<BR>.rdata 0x156000 0xc000 0xbc00 7.61 adb6b04c1859327dfd38853f33c181f3<BR>.data 0x162000 0xea000 0x2600 7.93 61266ef390ca5ba1c0b47493745682b7<BR>.idata 0x24c000 0x1000 0xa00 4.63 824e95152f6c5aa347e58aa700766f8f<BR>.rsrc 0x24d000 0x4000 0x3e00 4.38 e020776af0ebb38bf05387d846c21eec<BR><BR>( 6 imports ) <BR>> KERNEL32.dll: CloseHandle, CreateDirectoryA, EnumResourceNamesA, ExitProcess, GetCommandLineA, GetFileSize, GetModuleHandleA, GetStartupInfoA, HeapAlloc, LoadResource, MultiByteToWideChar, QueryPerformanceCounter, RemoveDirectoryA, RtlUnwind, SetLastError, SetUnhandledExceptionFilter, SleepEx, VirtualAlloc<BR>> user32.dll: EndPaint, EmptyClipboard, GetDlgItem, CharUpperBuffA, CharToOemBuffA, GetWindowTextA, MessageBoxA, SetFocus, SetMenuInfo, ShowCaret, DrawMenuBar<BR>> advapi32.dll: RegOpenKeyExA, RegLoadKeyA, RegEnumKeyA, RegCloseKey, RegQueryValueA<BR>> ole32.dll: OleInitialize, OleGetClipboard, OleUninitialize, CreateILockBytesOnHGlobal, CoUninitialize, CoRegisterClassObject, RegisterDragDrop, ReleaseStgMedium, StringFromGUID2, WriteClassStg, DoDragDrop, CLSIDFromString, CoCreateInstance, CoGetClassObject, CoInitialize<BR>> wininet.dll: InternetGetCookieA, InternetGetLastResponseInfoA, InternetQueryDataAvailable, InternetSetFilePointer, InternetSetOptionExA, InternetSetStatusCallbackA, InternetCrackUrlA, InternetConnectA, HttpSendRequestA, HttpQueryInfoA, HttpOpenRequestA, HttpAddRequestHeadersA, InternetCloseHandle<BR>> shell32.dll: SHGetFileInfoA, SHGetMalloc, SHGetPathFromIDListA, ShellExecuteA, ShellExecuteExW, SHGetDesktopFolder<BR><BR>( 0 exports ) <BR>
            RDS...: NSRL Reference Data Set<BR>-
            pdfid.: -
            trid..: Generic Win/DOS Executable (49.9%)<BR>DOS Executable Generic (49.8%)<BR>Autodesk FLIC Image File (extensions: flc, fli, cel) (0.1%)
            sigcheck:<BR>publisher....: Westwood Studios<BR>copyright....: Copyright (c) 2000 Westwood Studios<BR>product......: Command _ Conquer : Tiberian Sun<BR>description..: Main executable for Tiberian Sun<BR>original name: Sun.exe<BR>internal name: Sun<BR>file version.: 2.03<BR>comments.....: <BR>signers......: -<BR>signing date.: -<BR>verified.....: Unsigned<BR>
            1. ===== Rapport WareOut Removal Tool =====

              version 3.6.2

              analyse effectuée le 18/03/2010 à 2:21:48,70

              Résultats de l'analyse :
              ========================

              ~~~~ Recherche d'infections dans C:\ ~~~~

              C:\autorun.inf trouvé!
              C:\autorun.inf suppression impossible

              ~~~~ Recherche d'infections dans C:\Program Files\ ~~~~

              ~~~~ Recherche d'infections dans C:\Windows\system\ ~~~~

              ~~~~ Recherche d'infections dans C:\Windows\system32\ ~~~~

              ~~~~ Recherche d'infections dans C:\Windows\system32\drivers\ ~~~~

              ~~~~ Recherche d'infections dans C:\Users\Schizoprenic\AppData\Roaming\ ~~~~

              ~~~~ Recherche d'infections dans C:\Users\Schizoprenic\Bureau\ ~~~~

              ~~~~ Recherche de détournement de DNS ~~~~

              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{1DCF4499-04F7-4B72-A782-DB77FA010C94}]
              NameServer REG_SZ 85.255.112.189;85.255.112.113
              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{722C9BED-6214-4B55-8533-104D7BFC01B1}]
              NameServer REG_SZ 85.255.112.189;85.255.112.113
              [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{C4FF0844-4CEF-4130-BC06-070FEE20DF66}]
              NameServer REG_SZ 85.255.112.189;85.255.112.113

              ~~~~ Recherche de Rootkits ~~~~

              _______________________________________________________________________

              catchme 0.3.1398.3 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2010-03-18 02:21:54
              Windows 6.0.6002 Service Pack 2 NTFS

              scanning hidden files ...

              scan completed successfully
              hidden files: 0

              _______________________________________________________________________

              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
              System REG_SZ

              ~~~~ Recherche d'infections dans C:\Users\SCHIZO~1\AppData\Local\Temp\ ~~~~

              ~~~~ Recherche d'infections dans C:\Users\Schizoprenic\Start Menu\Programs\ ~~~~

              ~~~~ Nettoyage du registre ~~~~

              ~~~~ Tentative de réparation des entrées suivantes: ~~~~

              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] = "System"

              [HKLM\SYSTEM\CurrentControlSet\Services\Windows Tribute Service]
              [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_Windows Tribute Service]

              ~~~~ Vérification: ~~~~

              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
              System REG_SZ

              _________________________________

              développé par http://pc-system.fr
              _________________________________
              1. Contributeur sécurité
                ok

                encore plusieurs choses...

                1)

                Télécharge WareOut Removal Tool (par dj QUIOU & la team sécurité MH) ici :

                http://pc-system.fr/

                Lance le fichier WareOut_Removal_Tool.bat et choisis l'option n°1
                Patiente (une à deux minutes maximum) pendant que le programme sauvegarde le registre
                Lis bien attentivement les instructions qui te seront données
                A la fin de l'analyse, un rapport va s'ouvrir, poste le dans ta prochaine réponse.

                ...................

                2)

                Rends toi sur ce site :

                https://www.virustotal.com/gui/

                Clique sur parcourir et cherche ce fichier :

                C:\Windows\system32\aiXDKcoJh.dll
                C:\Windows\system32\aadmvrqas.exe

                Clique sur Send File.

                Un rapport va s'élaborer ligne à ligne.

                Attends la fin. Il doit comprendre la taille du fichier envoyé.

                Sauvegarde le rapport avec le bloc-note.

                Copie le dans ta réponse.

                Si tu ne trouves pas le fichier alors

                Affiche tous les fichiers et dossiers :

                Pour cela :
                Clique sur démarrer/panneau de configuration/option des dossiers/affichage

                Cocher afficher les dossiers cachés

                Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                Décocher masquer les extensions dont le type est connu

                Puis fais «appliquer» pour valider les changements.

                Et OK

                1. Logfile of random's system information tool 1.06 (written by random/random)
                  Run by Schizoprenic at 2010-03-17 03:45:02
                  Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
                  System drive C: has 28 GB (17%) free of 163 GB
                  Total RAM: 3070 MB (43% free)

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 03:45:10, on 17/03/2010
                  Platform: Windows Vista SP2 (WinNT 6.00.1906)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18882)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\system32\taskeng.exe
                  C:\Windows\Explorer.EXE
                  C:\Program Files\Sony\VAIO Update 5\VAIOUpdt.exe
                  C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                  C:\Program Files\Apoint\Apoint.exe
                  C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                  C:\Program Files\Apoint\ApMsgFwd.exe
                  C:\Program Files\Apoint\Apntex.exe
                  C:\Program Files\Java\jre6\bin\jusched.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                  C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
                  C:\Program Files\Logitech\SetPoint\SetPoint.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Lexmark 2600 Series\lxdnMsdMon.exe
                  C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                  C:\Windows\system32\wbem\unsecapp.exe
                  C:\Program Files\Steam\Steam.exe
                  C:\Program Files\Megaupload\Mega Manager\MegaManager.exe
                  c:\program files\steam\steamapps\common\football manager 2010\fm.exe
                  C:\Program Files\Steam\GameOverlayUI.exe
                  C:\Program Files\Winamp\winamp.exe
                  C:\Users\Schizoprenic\Desktop\RSIT.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Program Files\Trend Micro\HijackThis\Schizoprenic.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.yahoo.com/
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://fr.msn.com/
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: NetXfer - {83B80A9C-D91A-4F22-8DCF-EA7204039F79} - C:\Program Files\Xi\NetXfer\NXIEHelper.dll
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                  O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe"
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                  O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                  O4 - HKLM\..\Run: [lxdnmon.exe] "C:\Program Files\Lexmark 2600 Series\lxdnmon.exe"
                  O4 - HKLM\..\Run: [lxdnamon] "C:\Program Files\Lexmark 2600 Series\lxdnamon.exe"
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
                  O4 - Global Startup: BTTray.lnk = ?
                  O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                  O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
                  O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
                  O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                  O9 - Extra button: ºÜ¿ìÊÓÆµËÑË÷ - {998A88A0-A355-809B-831C-B83A80000991} - http://www.henkuai.com/?from=iebannel (file missing)
                  O9 - Extra 'Tools' menuitem: ºÜ¿ìÊÓÆµËÑË÷ - {998A88A0-A355-809B-831C-B83A80000991} - http://www.henkuai.com/?from=iebannel (file missing)
                  O9 - Extra button: Æô¶¯UUSee ÍøÂçµçÊÓ - {998A88A0-A355-809B-831C-B83A80000992} - C:\Program Files\uusee\UUSeePlayer.exe
                  O9 - Extra 'Tools' menuitem: Æô¶¯UUSee ÍøÂçµçÊÓ - {998A88A0-A355-809B-831C-B83A80000992} - C:\Program Files\uusee\UUSeePlayer.exe
                  O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
                  O15 - Trusted Zone: http://*.www.m6.fr
                  O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
                  O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
                  O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
                  O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} - http://srtest-cdn.systemrequirementslab.com.s3.amazonaws.com/bin/sysreqlabdetect.cab
                  O16 - DPF: {61FA0CB0-0806-46EA-B784-0F843285BA23} (TuentiFotoUploader Control) - http://estaticosak1.tuenti.com/client_apps/TuentiPhotoUploader.24936.cab
                  O16 - DPF: {78ABDC59-D8E7-44D3-9A76-9A0918C52B4A} (DLoader Class) - http://dl.uc.sina.com/cab/downloader.cab
                  O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
                  O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                  O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/VistaMSNPUpldfr-fr.cab
                  O17 - HKLM\System\CS1\Services\Tcpip\..\{1DCF4499-04F7-4B72-A782-DB77FA010C94}: NameServer = 85.255.112.189;85.255.112.113
                  O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
                  O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                  O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                  O23 - Service: Service Google Update (gupdate1ca2cd22c28197e) (gupdate1ca2cd22c28197e) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
                  O23 - Service: lxdnCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdnserv.exe
                  O23 - Service: lxdn_device - - C:\Windows\system32\lxdncoms.exe
                  O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
                  O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
                  O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
                  O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
                  O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
                  O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\stacsv.exe
                  O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                  O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                  O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                  O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                  O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                  O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                  O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                  O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
                  O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                  O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                  O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
                  O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
                  O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                  O23 - Service: VUAgent - Sony Corporation - C:\Program Files\Sony\VAIO Update 5\VUAgent.exe
                  O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                  O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                  O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                  1. Contributeur sécurité
                    bien

                    relances RSIT et postes le rapport log stp
                    1. Ouais,depuis combofix,plus de soucis et pas de lignes rouges dans le rapport
                      1. Contributeur sécurité
                        ok

                        comment va le pc ?

                        je postes pour toi le rapport

                        GMER 1.0.15.15281 - http://www.gmer.net
                        Rootkit scan 2010-03-16 11:57:57
                        Windows 6.0.6002 Service Pack 2
                        Running: 7rf1gwo0.exe; Driver: C:\Users\SCHIZO~1\AppData\Local\Temp\kwroiaog.sys

                        ---- System - GMER 1.0.15 ----

                        INT 0x51 ? 87B48F00
                        INT 0x62 ? 87B48F00
                        INT 0x72 ? 86324BF8
                        INT 0x82 ? 85590BF8
                        INT 0x92 ? 85590BF8
                        INT 0xA2 ? 87B48F00
                        INT 0xA2 ? 87B48F00
                        INT 0xA2 ? 87B48F00
                        INT 0xB3 ? 87B48F00

                        ---- Kernel code sections - GMER 1.0.15 ----

                        ? System32\Drivers\spnc.sys Le chemin d'accès spécifié est introuvable. !
                        .text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8FC03340, 0x3441C7, 0xE8000020]
                        .text USBPORT.SYS!DllUnload 903B541B 5 Bytes JMP 87B484E0
                        .text am81opkz.SYS 8B37A000 22 Bytes [82, A3, A1, 82, 6C, A2, A1, ...]
                        .text am81opkz.SYS 8B37A017 181 Bytes [00, 32, 07, DA, 8A, 3D, 05, ...]
                        .text am81opkz.SYS 8B37A0CE 10 Bytes [00, 00, 00, 00, 00, 00, 02, ...]
                        .text am81opkz.SYS 8B37A0DA 12 Bytes [00, 00, 02, 00, 00, 00, 24, ...]
                        .text am81opkz.SYS 8B37A0E7 714 Bytes [00, F0, 0E, 00, 00, 00, 00, ...]
                        .text ...
                        .text C:\Windows\system32\DRIVERS\atksgt.sys section is writeable [0xA14DF300, 0x3B6D8, 0xE8000020]
                        .text C:\Windows\system32\DRIVERS\lirsgt.sys section is writeable [0xA1522300, 0x1BEE, 0xE8000020]

                        ---- User code sections - GMER 1.0.15 ----

                        .text C:\Program Files\Internet Explorer\iexplore.exe[2216] USER32.dll!CreateWindowExW 76141305 5 Bytes JMP 7108D9BC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[2216] USER32.dll!DialogBoxParamW 761610B0 5 Bytes JMP 70FB5689 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[2216] USER32.dll!DialogBoxIndirectParamW 76162EF5 5 Bytes JMP 711843F7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[2216] USER32.dll!DialogBoxParamA 76178152 5 Bytes JMP 71184394 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[2216] USER32.dll!DialogBoxIndirectParamA 7617847D 5 Bytes JMP 7118445A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[2216] USER32.dll!MessageBoxIndirectA 7618D4D9 5 Bytes JMP 71184329 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[2216] USER32.dll!MessageBoxIndirectW 7618D5D3 5 Bytes JMP 711842BE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[2216] USER32.dll!MessageBoxExA 7618D639 5 Bytes JMP 7118425C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[2216] USER32.dll!MessageBoxExW 7618D65D 5 Bytes JMP 711841FA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!SetWindowsHookExW 761387AD 5 Bytes JMP 71089B29 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!CallNextHookEx 76138E3B 5 Bytes JMP 7107D171 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!UnhookWindowsHookEx 761398DB 5 Bytes JMP 70FF486E C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!CreateWindowExW 76141305 5 Bytes JMP 7108D9BC C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!DialogBoxParamW 761610B0 5 Bytes JMP 70FB5689 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!DialogBoxIndirectParamW 76162EF5 5 Bytes JMP 711843F7 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!DialogBoxParamA 76178152 5 Bytes JMP 71184394 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!DialogBoxIndirectParamA 7617847D 5 Bytes JMP 7118445A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!MessageBoxIndirectA 7618D4D9 5 Bytes JMP 71184329 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!MessageBoxIndirectW 7618D5D3 5 Bytes JMP 711842BE C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!MessageBoxExA 7618D639 5 Bytes JMP 7118425C C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] USER32.dll!MessageBoxExW 7618D65D 5 Bytes JMP 711841FA C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] ole32.dll!OleLoadFromStream 76981E12 5 Bytes JMP 71184778 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Internet Explorer\iexplore.exe[4280] ole32.dll!CoCreateInstance 769B9EA6 5 Bytes JMP 7108DA18 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] kernel32.dll!FindResourceExA 76C72575 7 Bytes JMP 28001D80 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] kernel32.dll!FindResourceA 76C72653 5 Bytes JMP 28001CF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] kernel32.dll!CreateEventA 76C944C0 5 Bytes JMP 28001840 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] kernel32.dll!LockResource 76C968DF 5 Bytes JMP 28001F50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] kernel32.dll!FindResourceExW 76C969FD 7 Bytes JMP 28001C60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] kernel32.dll!LoadResource 76C96ADB 7 Bytes JMP 28001E20 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] kernel32.dll!FindResourceW 76C97FA1 5 Bytes JMP 28001BE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] kernel32.dll!SizeofResource 76C97FBF 7 Bytes JMP 28001EE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] ADVAPI32.dll!CryptDeriveKey 77B6FCAE 7 Bytes JMP 28001000 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] ADVAPI32.dll!CryptDecrypt 77B6FE91 7 Bytes JMP 28001060 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] USER32.dll!CreateDialogParamW 761372A2 5 Bytes JMP 28006090 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] USER32.dll!SetWindowPlacement 76137963 5 Bytes JMP 28005E10 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] USER32.dll!SetWindowRgn 7613A221 7 Bytes JMP 28005F50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] USER32.dll!LoadImageW 7613C9E5 5 Bytes JMP 280066E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] USER32.dll!LoadIconW 7613DA9F 5 Bytes JMP 280068D0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] USER32.dll!CreateWindowExW 76141305 5 Bytes JMP 28003C60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] USER32.dll!GetWindowLongW 7614F8BF 7 Bytes JMP 28006A70 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] USER32.dll!PeekMessageW 7615045A 5 Bytes JMP 28004630 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] USER32.dll!TrackPopupMenuEx 76160CE7 5 Bytes JMP 28004F10 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] USER32.dll!MessageBoxIndirectW 7618D5D3 5 Bytes JMP 28006280 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] SHELL32.dll!Shell_NotifyIconW 76F18626 5 Bytes JMP 280033B0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] ole32.dll!CoRegisterClassObject 76977DB6 5 Bytes JMP 28002360 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] ole32.dll!CoCreateInstance 769B9EA6 5 Bytes JMP 28002600 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] ole32.dll!CoInitializeEx 769BAD63 5 Bytes JMP 28002260 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] WININET.dll!InternetReadFile 7685654B 5 Bytes JMP 2800A090 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] WININET.dll!InternetCloseHandle 76859088 5 Bytes JMP 2800A240 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
                        .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5012] WININET.dll!HttpOpenRequestA
                        1. Contributeur sécurité
                          ok

                          tu peux vider la quarantaine

                          fais ceci stp pour vérifier que tu es tranquille

                          /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

                          ▶ Télécharge : Gmer (by Przemyslaw Gmerek)

                          http://www.gmer.net/

                          ▶ Dezippe gmer ,cliques sur l'onglet rootkit,lances le scan,des lignes rouges vont apparaitre.

                          ▶ Les lignes rouges indiquent la presence d'un rootkit.Postes moi le rapport gmer (cliques sur copy,puis vas dans demarrer ,puis ouvres le bloc note,vas dans edition et cliques sur coller,le rapport gmer va apparaitre,postes moi le)
                          1. Rapport MBAM

                            Malwarebytes' Anti-Malware 1.44
                            Version de la base de données: 3862
                            Windows 6.0.6002 Service Pack 2
                            Internet Explorer 8.0.6001.18882

                            13/03/2010 11:43:26
                            mbam-log-2010-03-13 (11-43-26).txt

                            Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|J:\|)
                            Eléments examinés: 395020
                            Temps écoulé: 3 hour(s), 45 minute(s), 14 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 0
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 1

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            C:\$RECYCLE.BIN\S-1-5-21-3242307328-3026939525-2831412068-1000\$RDUFHSE.Keymaker-CORE\keymaker.exe (Trojan.Agent.CK) -> Quarantined and deleted successfully.
                            1. Contributeur sécurité
                              j'ai bien vu ta question...on voit ca à la fin

                              si j'oublie, reparles m'en
                              1. Sinon,tu m'as pas repondu:
                                tu me conseilles quel antivirus?J'ai AVG actuellement mais vu tout le boxon,vvaut mieux passser a un truc plus performant.

                                Le rapport usbfix:

                                ############################## | UsbFix V6.099 |

                                User : Schizoprenic (Administrateurs) # SCHYZOPHRENIC
                                Update on 11/03/2010 by El Desaparecido , C_XX & Chimay8
                                Start at: 07:43:10 | 13/03/2010
                                Website : http://pagesperso-orange.fr/NosTools/index.html
                                Contact : FindyKill.Contact@gmail.com

                                Intel(R) Core(TM)2 Duo CPU T7250 @ 2.00GHz
                                Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                                Internet Explorer 8.0.6001.18882
                                Windows Firewall Status : Enabled

                                C:\ -> Disque fixe local # 158,7 Go (39,64 Go free) [Shaka] # NTFS
                                D:\ -> Disque fixe local # 17,53 Go (13,58 Go free) [Ikki] # NTFS
                                E:\ -> Disque amovible
                                F:\ -> Disque amovible # 1,9 Go (17,75 Mo free) [XTINCTION] # FAT
                                G:\ -> Disque CD-ROM # 7,36 Go (0 Mo free) [PES2010] # UDF
                                H:\ -> Disque CD-ROM

                                ################## | Elements infectieux |

                                Supprimé ! C:\$Recycle.Bin\S-1-5-21-3242307328-3026939525-2831412068-1000
                                Supprimé ! D:\$Recycle.Bin\S-1-5-21-1453738194-2990717095-2334957809-1000
                                Supprimé ! D:\$Recycle.Bin\S-1-5-21-1453738194-2990717095-2334957809-500
                                Supprimé ! D:\$Recycle.Bin\S-1-5-21-3242307328-3026939525-2831412068-1000
                                Supprimé ! D:\$Recycle.Bin\S-1-5-21-3242307328-3026939525-2831412068-500
                                (!) Non supprimé ! G:\autorun.inf
                                Supprimé ! J:\winamp_cache_0001.xml

                                ################## | Registre |

                                Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
                                Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                                ################## | Mountpoints2 |

                                Supprimé ! HKCU\...\Explorer\MountPoints2\{c5c6f980-ec1c-11de-986a-806e6f6e6963}\Shell\AutoRun\Command

                                ################## | Listing des fichiers présent |

                                [13/12/2009 01:32|--a------|1024] C:\.rnd
                                [13/12/2009 15:34|--a------|220] C:\aaw7boot.log
                                [01/02/2010 14:43|--a------|319021] C:\AnalysisLog.sr0
                                [18/09/2006 21:43|--a------|24] C:\autoexec.bat
                                [11/04/2009 06:36|-rahs----|333257] C:\bootmgr
                                [21/07/2007 01:27|-ra-s----|8192] C:\BOOTSECT.BAK
                                [13/03/2010 06:49|--a------|116716] C:\ComboFix.txt
                                [18/09/2006 21:43|--a------|10] C:\config.sys
                                [10/07/2009 11:53|-rahs----|0] C:\IO.SYS
                                [27/08/2008 18:14|--a------|2688] C:\LGSInst.Log
                                [17/09/2009 13:45|--a------|78] C:\lxdi.log
                                [10/07/2009 11:53|-rahs----|0] C:\MSDOS.SYS
                                [29/02/2004 15:44|--a------|52576] C:\orange.bmp
                                [?|?|?] C:\pagefile.sys
                                [12/03/2010 17:16|--a------|4384] C:\rapport.txt
                                [04/11/2008 14:02|--a------|11] C:\RPT23432
                                [13/03/2010 07:47|--a------|2504] C:\UsbFix.txt
                                [25/11/2009 23:20|--ah-----|305] D:\.iTunes Preferences.plist
                                [?|?|?] D:\pagefile.sys
                                [04/09/2009 06:11|-ra------|212480] G:\1031.mst
                                [04/09/2009 06:11|-ra------|522752] G:\1034.mst
                                [04/09/2009 06:11|-ra------|523264] G:\1036.mst
                                [04/09/2009 06:11|-ra------|522240] G:\1040.mst
                                [04/09/2009 06:11|-ra------|93696] G:\2070.mst
                                [04/09/2009 06:10|-ra------|214408] G:\autorun.exe
                                [04/09/2009 06:10|-ra------|47] G:\Autorun.inf
                                [04/09/2009 06:11|-ra------|1696256] G:\Pro Evolution Soccer 2010.msi
                                [04/09/2009 06:10|-ra------|1086] G:\readme.html
                                [04/09/2009 06:10|-ra------|64] G:\region.inf
                                [04/09/2009 06:10|-ra------|112008] G:\Setup.exe
                                [29/03/2006 14:08|--ah-----|82] J:\._System Volume Information
                                [02/07/2009 20:58|--ah-----|4096] J:\._.Trashes
                                [13/03/2010 03:15|--a------|41] J:\pmp_usb.ini

                                ################## | Vaccination |

                                # C:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                                # D:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                                # F:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).
                                # J:\autorun.inf -> Dossier créé par UsbFix (El Desaparecido).

                                ################## | Upload |

                                Veuillez envoyer le fichier : C:\UsbFix_Upload_Me_SCHYZOPHRENIC.zip : https://www.ionos.fr/?affiliate_id=77097
                                Merci pour votre contribution .

                                ################## | ! Fin du rapport # UsbFix V6.099 ! |
                                1. Contributeur sécurité
                                  (sourire)

                                  le rapport usbfix doit êtrte posté ici pour que je le vérifie ( C:\UsbFix.txt )

                                  quant au fichier que tu as envoyé au créateur de l'outil, tu peux le supprimer
                                  1. J'ai envoye le rapport d'usbfix et la je lance mbam.

                                    Merci encore et la phrase "J'AI JAMAIS VU UN TRUC PAREIL" meme si c'etait sensé etre alarmant,ca m''a fait rigoler comme un con
                                    1. Contributeur sécurité
                                      le plus gros est fait...

                                      apres usbfix et mbam, on y verra plus clair
                                      1. Arf,je suis allé trop vite en besogne...

                                        http://www.cijoint.fr/cjlink.php?file=cj201003/cijwIDiaf1.txt
                                        Le lien du fichier.
                                        • 1
                                        • 2