Netoyage à effectuer ?

Résolu
Bonjour,

J'ai un PC assez ralentis, y a-t-il un netoyage de fin d'été à réaliser sur la machine ?
Rien détecté sous Malwarebytes.
Merci de votre aide !

Rapport Hijackthis :
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:35:29, on 31/08/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Fichiers communs\Nikon\Monitor\NkMonitor.exe
E:\iTunes\iTunesHelper.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\LogMeIn\x86\RaMaint.exe
C:\Program Files\LogMeIn\x86\LogMeIn.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\VIA\RAID\vialogsv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.bearshare.com/sidebar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?fdr=lc&toHttps=1&redig=FA6AD360E0BE4C719380F8C470A3D3A8
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.footbel.com/fr.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.be/?gws_rd=ssl
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
R3 - URLSearchHook: (no name) - {9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
R3 - URLSearchHook: Messenger Plus Live Belgium Toolbar - {d1a1c8f1-e3d9-48df-802f-20201061ef61} - C:\Program Files\Messenger_Plus_Live_Belgium\tbMes0.dll
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: UrlHelper Class - {74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareIEHelper.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Messenger Plus Live Belgium Toolbar - {d1a1c8f1-e3d9-48df-802f-20201061ef61} - C:\Program Files\Messenger_Plus_Live_Belgium\tbMes0.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: WinAVI FLVSense - {E8DF67A1-B618-4F3F-9E7C-CBE175ADEF5B} - E:\Nouveau dossier\WinAVI FLV Converter\FLVTune.dll
O2 - BHO: UrlHelper Class - {EA35911C-1B6A-4AF3-B803-913BA025C271} - C:\Program Files\Lphant Applications\Lphant MediaBar\LphantIEHelper.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: BearShare MediaBar - {D3DEE18F-DB64-4BEB-9FF1-E1F0A5033E4A} - C:\Program Files\BearShare Applications\BearShare MediaBar\BearShareMediaBar.dll
O3 - Toolbar: Lphant MediaBar - {7FED05BE-14FB-4A41-B0D9-79ABBC36FEE4} - C:\Program Files\Lphant Applications\Lphant MediaBar\LphantMediaBar.dll
O3 - Toolbar: (no name) - {9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
O3 - Toolbar: Messenger Plus Live Belgium Toolbar - {d1a1c8f1-e3d9-48df-802f-20201061ef61} - C:\Program Files\Messenger_Plus_Live_Belgium\tbMes0.dll
O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [VIARaidUtl] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKLM\..\Run: [Nikon Transfer Monitor] C:\Program Files\Fichiers communs\Nikon\Monitor\NkMonitor.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
O8 - Extra context menu item: &Télécharger le FLV avec WinAVI... - E:\Nouveau dossier\WinAVI FLV Converter\flv_link.htm
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\klein\Application Data\Dealio\kb127\res\DealioSearch.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: WinAVI FLV Manager - {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - E:\Nouveau dossier\WinAVI FLV Converter\FLVTune.dll
O9 - Extra 'Tools' menuitem: WinAVI FLV Manager - {DE365254-2F9B-4908-9E3A-7AAA6EC90BCC} - E:\Nouveau dossier\WinAVI FLV Converter\FLVTune.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/fr/uno1/GAME_UNO1.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Service Google Update (gupdate1c9c013bc09c1fc) (gupdate1c9c013bc09c1fc) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VRAID Log Service - Unknown owner - C:\Program Files\VIA\RAID\vialogsv.exe

--
End of file - 14426 bytes

25 réponses

Résumé de la discussion

Problème de lenteur d'un PC Windows XP SP3 se pose et l'utilisateur cherche s'il existe un nettoyage de fin d'été à réaliser, Malwarebytes ne détectant aucune anomalie. Des éléments du rapport HijackThis fourni en fin de message indiquent de nombreuses entrées et modules autoruns, extensions et services potentiellement indésirables, sans démontrer une menace claire. Pour guider l'analyse, la discussion mentionne des éléments tels que les barres d'outils, les moteurs de recherche modifiés et les programmes au démarrage, mais sans verdict sur l'infection. En cas de poursuite, des mesures possibles incluent le nettoyage manuel des entrées de démarrage et la vérification des composants tiers, tout en privilégiant des mises à jour de sécurité et une analyse complémentaire.

Bobot (l’IA à votre service)
  1. ça vient de logitech si j'ai bien lu non ?

    pour le reste, c'est fait :)
    je n'ai plus qu'à utiliser ZHP pour désinstaller tout

    merci encore !
    1. Contributeur sécurité
      il vient de partout celui là....
    2. ok, merci !
    3. Snif, c'est si beaux les problèmes résolus :')
    4. je trouve aussi :)
  2. Contributeur sécurité
    c'est vrai qu'il s'accroche souvent celui là

    pour le reste des manips tu dois pouvoir te passer de moi je suppose

    donc résolu

    bonne continuation
    1. je crois qu'il y a eu des problèmes pour désistaller certains composant (ressource réseau non disponible, c'était pour un ou les Search Settings)

      rapport :
      Rapport de ZHPFix v1.12.3141 par Nicolas Coolman, Update du 27/08/2010
      Fichier d'export Registre :
      Run by klein at 2/09/2010 10:27:57
      Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
      Contact : nicolascoolman@yahoo.fr

      ========== Elément(s) de donnée du Registre ==========
      [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: Modified => Donnée supprimée avec succès

      ========== Logiciel(s) ==========
      O42 - Logiciel: Search Settings 1.2 - (.Pas de propriétaire.) [HKLM] -- {D0C73318-7B4A-4D16-A0C4-3B83F075EA88} => Logiciel supprimé avec succès

      ========== Récapitulatif ==========
      1 : Elément(s) de donnée du Registre
      1 : Logiciel(s)

      End of the scan
      1. Contributeur sécurité
        On termine donc proprement

        1)

        Copie tout le texte présent en gras ci-dessous ( tu le selectionnes avec ta souris / Clique droit dessus et choisis "copier" ou fait Ctrl+C )

        [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: Modified
        O42 - Logiciel: Search Settings 1.2 - (.Pas de propriétaire.) [HKLM] -- {D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
        O42 - Logiciel: Search Settings 1.2 - (.Pas de propriétaire.) [HKLM] -- {D0C73318-7B4A-4D16-A0C4-3B83F075EA88}


        Puis Lance ZHPFix depuis le raccourci du bureau .

        * Une fois l'outil ZHPFix ouvert , clique sur le bouton [ H ] ( "coller les lignes Helper" ) .

        * Dans l'encadré principal tu verras donc les lignes que tu as copié précédemment apparaitrent .

        Vérifie que toutes les lignes que je t'ai demandé de copier (et seulement elles) sont dans la fenêtre.

        Clique sur " Ok " , puis " Tous " et enfin " Nettoyer ".

        Copie/Colle le rapport à l'écran dans ton prochain message

        le rapport se trouve dans le dossier de zhpdiag dans program files sous le nom de ZHPFixReport

        .......................

        2)

        Mettre à jour internet explorer (même si tu ne l'utlises pas)
        https://support.microsoft.com/fr-fr/allproducts

        ..........................

        3)

        Mettre à jour la Console Java ? :
        https://www.java.com/fr/download/uninstalltool.jsp

        et installer la nouvelle version si besoin est (dans ce cas désinstalle avant l'ancienne version).

        voici pour desinstaller :

        JavaRa
        http://raproducts.org/click/click.php?id=1

        Décompresse le fichier sur le Bureau (Clic droit > Extraire tout).
        * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur le répertoire JavaRa.
        * Puis double-clique sur le fichier JavaRa.exe (le exe peut ne pas s'afficher).
        * Choisis Français puis clique sur Select.
        * Clique sur Recherche de mises à jour.
        * Sélectionne Mettre à jour via jucheck.exe puis clique sur Rechercher.
        * Autorise le processus à se connecter s'il le demande, clique sur Installer et suis les instructions d'installation qui prennent quelques minutes.
        * L'installation est terminée, reviens à l'écran de JavaRa et clique sur Effacer les anciennes versions.
        * Clique sur Oui pour confirmer. Laisse travailler et clique ensuite sur OK, puis une deuxième fois sur OK.
        * Un rapport va s'ouvrir. Poste-le dans ta prochaine réponse.
        * Ferme l'application.

        Note : le rapport se trouve aussi dans C:\ sous le nom JavaRa.log.

        .............

        4)

        * Lancez Adobe Reader
        * Cliquez sur Edition --> Préférences --> JavaScript
        * Décochez "Activer Acrobat JavaScript"
        * Validez

        ....................

        5)
        IMPORTANT

        Purger la restauration systeme XP

        http://www.bibou0007.com/windows-xp-f101/purger-la-restauration-du-systeme-sous-windows-xp-t151.htm

        .................

        6)
        Clique droit sur l'icône ZHPFix.exe sur ton Bureau,
        puis sélectionne 'Exécuter en tant qu'administrateur'.

        Clique sur le A rouge (Nettoyeur de Tools).

        Clique sur Nettoyer.

        Fais redémarrer l'ordi pour terminer le nettoyage.

        .................................................

        Recommandations pour l'avenir

        Tu es la meilleure protection pour ton pc que tout autre antivirus, si tu admets un minimum de rigueur dans son utilisation...Les virus sont vigilants et pénètrent ta machine par toutes les portes que tu laisseras ouvertes...
        - logiciels non à jour (windows, internet explorer, java, adobe reader etc)
        - installation de toolbar
        - fréquentation de sites piégés
        - P2P
        - Application de cracks
        - Supports usb

        Pour t'aider dans cette tâche, voici quelques pistes

        Pour naviguer sur internet plus en sécurité et à l'abri des publicités, je te conseille vivement d'installer et d'utiliser le navigateur firefox
        http://www.mozilla-europe.org/fr/firefox/

        Une fois que c'est fait, lances le et installe l'extension de sécurité adblock plus
        pour bloquer les publicités
        http://www.clubic.com/telecharger-fiche45912-adblock-plus.html

        ............................

        WOT - Extension pour ton navigateur internet :
        Voici une extension à télécharger qui te permettra, en faisant tes recherches sur google, de savoir si le site proposé lors de tes recherches est un site de confiance ou un site à éviter car il pourrait infecter ton PC :
        Pour Firefox : https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
        Pour internet explorer : https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp

        ........................

        Pour éviter une infection toolbar, il faut tout lire attentivement lorsque tu installes un programme gratuit, et décocher tous les programmes additionnels qui sont proposés, en particulier les barres d'outils !

        ..........................

        Vaccines tes disques amovibles à l'aide de USBFix (de Chiquitine29 et C_XX)
        http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
        Au menu principal, choisis l'option 3 (Vaccination).
        ............................

        garder Malwarebytes et faire un examen de temps en temps ton PC, avec mise à jour avant chaque scan
        .......................

        Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
        https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

        * Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
        * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
        * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse

        ..........................
        utilitaire pour défragmenter , utilises pour ce faire Defraggler https://www.clubic.com/telecharger-fiche44314-defraggler.html

        ........................
        A lire pour mieux comprendre l'environnement qui t'entoure
        http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html
        https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf

        http://www.libellules.ch/...

        1. Contributeur sécurité
          ok

          comment va le pc ?

          fais un nouveau rapport ZHPdiag et poste le lien de ci joint stp
          1. le PC va bien selon moi

            rapport : http://www.cijoint.fr/cjlink.php?file=cj201009/cijh7FyWxS.txt
        2. je suis en train de lui faire faire un mbam complet pour voir s'il plante pendant (puisque c'était un des trucs qui le faisait planter)

          je te dis quoi

          merci pour ton aide précieuse !
          1. Contributeur sécurité
            ok

            @ plus tard donc...
          2. il en est à + de 34minutes et tout à l'air d'aller bien ! (et il n'a pas trouvé de crasse :p )

            je reposte à la fin du scan
          3. 1h 1min de scan, pas de plantage, voila quelque chose de bien

            il a juste trouvé un truc, voila le rapport :
            Malwarebytes' Anti-Malware 1.46
            www.malwarebytes.org

            Version de la base de données: 4513

            Windows 5.1.2600 Service Pack 3
            Internet Explorer 6.0.2900.5512

            2/09/2010 0:06:43
            mbam-log-2010-09-02 (00-06-43).txt

            Type d'examen: Examen complet (C:\|)
            Elément(s) analysé(s): 264228
            Temps écoulé: 1 heure(s), 1 minute(s), 53 seconde(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 0
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 1
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 0

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            (Aucun élément nuisible détecté)
        3. Contributeur sécurité
          ok

          apres Ccleaner

          dis moi comment se comporte le pc ?
          1. après le redémarage demandé par combofix, il y a un installateur qui n'arrive pas à instyaller ce qu'il veut (PSSWCORE => il ne trouve pas PSSWCORE.msi, ça semble venir d'un truc HP (imprimante) )
            rapport combofix :
            ComboFix 10-09-01.02 - klein 01/09/2010 20:26:24.3.1 - x86
            Microsoft Windows XP Professionnel 5.1.2600.3.1252.32.1036.18.1023.597 [GMT 2:00]
            Lancé depuis: c:\documents and settings\klein\Bureau\ComboFix.exe
            Commutateurs utilisés :: c:\documents and settings\klein\Bureau\CFScript.txt
            AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

            FILE ::
            "c:\windows\temp\Perflib_Perfdata_894.dat"
            .

            ((((((((((((((((((((((((((((( Fichiers créés du 2010-08-01 au 2010-09-01 ))))))))))))))))))))))))))))))))))))
            .

            2010-09-01 17:51 . 2010-09-01 17:55 -------- d-----w- c:\program files\SEAF
            2010-09-01 14:03 . 2010-09-01 17:06 -------- d-----w- C:\Kill'em
            2010-09-01 14:02 . 2010-09-01 17:23 -------- d-----w- c:\program files\List_Kill'em
            2010-08-31 11:23 . 2010-08-31 11:23 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\Conduit
            2010-08-31 11:20 . 2010-08-31 12:00 -------- d-----w- c:\program files\ZHPDiag
            2010-08-31 10:50 . 2010-08-31 10:54 -------- d-----w- c:\program files\Ad-Remover
            2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\GHISLER
            2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\program files\Trend Micro
            2010-08-31 10:30 . 2010-08-31 10:30 -------- d-----w- c:\windows\nvidia icons
            2010-08-31 10:29 . 2008-04-30 15:27 442368 ----a-w- c:\windows\system32\NVUNINST.EXE
            2010-08-31 10:26 . 2010-08-31 10:26 -------- d-----w- c:\program files\SystemRequirementsLab
            2010-08-30 21:48 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
            2010-08-30 21:48 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
            2010-08-30 21:48 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
            2010-08-30 21:48 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
            2010-08-30 21:48 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
            2010-08-30 21:48 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
            2010-08-30 21:48 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
            2010-08-30 21:47 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
            2010-08-30 21:47 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
            2010-08-30 21:47 . 2010-08-30 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
            2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- C:\totalcmd
            2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- c:\documents and settings\klein\Application Data\GHISLER
            2010-08-30 21:08 . 2010-08-31 10:51 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
            2010-08-30 21:08 . 2010-08-30 21:09 -------- d-----w- c:\program files\SpywareBlaster
            2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\klein\Application Data\Malwarebytes
            2010-08-30 21:06 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
            2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
            2010-08-30 21:06 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
            2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2010-09-01 17:54 . 2009-03-23 22:36 -------- d-----w- c:\documents and settings\klein\Application Data\HPAppData
            2010-09-01 14:28 . 2010-09-01 14:28 -------- d-----w- c:\documents and settings\Administrateur\Application Data\GHISLER
            2010-09-01 07:16 . 2009-04-18 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
            2010-09-01 07:15 . 2008-12-24 04:28 -------- d-----w- c:\program files\LogMeIn
            2010-08-31 10:25 . 2008-12-23 23:08 -------- d-----w- c:\program files\Fichiers communs\Java
            2010-08-31 10:25 . 2008-12-23 23:09 -------- d-----w- c:\program files\Java
            2010-08-30 21:47 . 2008-12-24 04:16 -------- d-----w- c:\program files\Alwil Software
            2010-08-30 20:53 . 2008-12-23 23:06 -------- d-----w- c:\program files\CCleaner
            2010-08-30 12:34 . 2010-05-07 16:58 -------- d-----w- c:\program files\Messenger_Plus_Live_Belgium
            2010-08-13 06:37 . 2010-04-01 19:12 -------- d-----w- c:\program files\Messenger Plus! Live
            2010-08-12 15:04 . 2002-02-28 21:58 80856 ----a-w- c:\windows\system32\perfc00C.dat
            2010-08-12 15:04 . 2002-02-28 21:58 500814 ----a-w- c:\windows\system32\perfh00C.dat
            2010-08-03 12:53 . 2010-08-03 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcp71.dll
            2010-08-03 12:53 . 2010-08-03 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\jmc.dll
            2010-08-03 12:53 . 2010-08-03 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcr71.dll
            2010-08-03 12:53 . 2010-08-03 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-sse.dll
            2010-08-03 12:53 . 2010-08-03 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-d3d.dll
            2010-07-29 09:17 . 2008-12-24 04:25 -------- d-----w- c:\documents and settings\klein\Application Data\LimeWire
            2010-07-28 09:25 . 2009-01-10 19:19 -------- d-----w- c:\documents and settings\klein\Application Data\Apple Computer
            2010-07-28 09:18 . 2010-07-28 09:17 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
            2010-07-28 09:18 . 2010-07-28 09:18 -------- d-----w- c:\program files\iPod
            2010-07-28 09:17 . 2009-01-10 19:15 -------- d-----w- c:\program files\Fichiers communs\Apple
            2010-07-28 09:16 . 2010-07-28 09:15 -------- d-----w- c:\program files\QuickTime
            2010-07-28 09:11 . 2010-07-28 09:11 -------- d-----w- c:\program files\Bonjour
            2010-07-28 09:08 . 2010-07-28 09:08 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
            2010-07-23 12:53 . 2010-07-23 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcp71.dll
            2010-07-23 12:53 . 2010-07-23 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\jmc.dll
            2010-07-23 12:53 . 2010-07-23 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcr71.dll
            2010-07-23 12:53 . 2010-07-23 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-sse.dll
            2010-07-23 12:53 . 2010-07-23 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-d3d.dll
            2010-07-17 03:00 . 2010-07-23 12:53 423656 ----a-w- c:\windows\system32\deployJava1.dll
            2010-06-30 12:32 . 2008-04-13 17:33 149504 ----a-w- c:\windows\system32\schannel.dll
            2010-06-24 12:10 . 2008-04-13 17:33 671232 ----a-w- c:\windows\system32\wininet.dll
            2010-06-24 12:10 . 2008-04-13 17:33 81920 ----a-w- c:\windows\system32\ieencode.dll
            2010-06-24 09:02 . 2008-04-13 16:58 1852032 ----a-w- c:\windows\system32\win32k.sys
            2010-06-22 19:38 . 2008-12-24 12:30 64560 ----a-w- c:\documents and settings\klein\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
            2010-06-21 15:27 . 2008-04-13 10:15 354304 ----a-w- c:\windows\system32\drivers\srv.sys
            2010-06-17 14:03 . 2008-04-13 17:33 80384 ----a-w- c:\windows\system32\iccvid.dll
            2010-06-14 14:31 . 2008-12-23 22:17 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
            2010-06-14 07:42 . 2008-04-13 17:33 1172480 ----a-w- c:\windows\system32\msxml3.dll
            2010-06-11 15:32 . 2008-12-24 04:28 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
            2010-06-11 15:32 . 2008-12-24 04:28 29568 ----a-w- c:\windows\system32\LMIport.dll
            2010-06-11 15:32 . 2008-12-24 04:28 87424 ----a-w- c:\windows\system32\LMIinit.dll
            .

            ((((((((((((((((((((((((((((( SnapShot@2010-09-01_09.26.49 )))))))))))))))))))))))))))))))))))))))))
            .
            + 2010-09-01 18:33 . 2010-09-01 18:33 16384 c:\windows\temp\Perflib_Perfdata_400.dat
            .
            ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
            REGEDIT4

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
            "{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]

            [HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]

            [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
            2010-08-30 12:34 2734688 ----a-w- c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
            "{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]

            [HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
            "{D1A1C8F1-E3D9-48DF-802F-20201061EF61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]

            [HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-18 39408]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "VIARaidUtl"="c:\program files\VIA\RAID\raid_tool.exe" [2008-09-24 4918936]
            "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
            "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 63048]
            "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
            "nwiz"="nwiz.exe" [2008-05-03 1630208]
            "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
            "fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-08-05 647520]
            "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-14 188416]
            "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
            "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
            "ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
            "Nikon Transfer Monitor"="c:\program files\Fichiers communs\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
            "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
            "iTunesHelper"="e:\itunes\iTunesHelper.exe" [2010-07-21 141608]
            "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
            "SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
            "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]

            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

            c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
            HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
            ZDWLan Utility.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-12-24 487424]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
            2010-06-11 15:32 87424 ----a-w- c:\windows\system32\LMIinit.dll

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
            "EnableFirewall"= 0 (0x0)

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
            "%windir%\\system32\\sessmgr.exe"=
            "e:\\Emul\\eMule\\emule.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
            "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
            "e:\\Nouveau dossier (3)\\LimeWire\\LimeWire.exe"=
            "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
            "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
            "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
            "e:\\iTunes\\iTunes.exe"=

            R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30/08/2010 23:48 165456]
            R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/08/2010 23:48 17744]
            R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [28/02/2008 16:31 12856]
            R2 VRAID Log Service;VRAID Log Service;c:\program files\VIA\RAID\vialogsv.exe [24/12/2008 0:51 52888]
            S2 gupdate1c9c013bc09c1fc;Service Google Update (gupdate1c9c013bc09c1fc);c:\program files\Google\Update\GoogleUpdate.exe [18/04/2009 12:52 133104]
            S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [15/03/2009 10:34 216232]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
            HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
            hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
            .
            Contenu du dossier 'Tâches planifiées'

            2010-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job
            - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

            2010-09-01 c:\windows\Tasks\Google Software Updater.job
            - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-18 10:51]

            2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]

            2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
            - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]

            2010-09-01 c:\windows\Tasks\OGALogon.job
            - c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
            .
            .
            ------- Examen supplémentaire -------
            .
            uStart Page = hxxp://www.google.com/
            uInternet Connection Wizard,ShellNext = hxxp://www.google.be/
            uInternet Settings,ProxyOverride = *.local
            IE: &Télécharger le FLV avec WinAVI... - e:\nouveau dossier\WinAVI FLV Converter\flv_link.htm
            IE: Compare Prices with &Dealio - c:\documents and settings\klein\Application Data\Dealio\kb127\res\DealioSearch.html
            IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            .

            **************************************************************************

            catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2010-09-01 20:35
            Windows 5.1.2600 Service Pack 3 NTFS

            Recherche de processus cachés ...

            Recherche d'éléments en démarrage automatique cachés ...

            HKLM\Software\Microsoft\Windows\CurrentVersion\Run
            VIARaidUtl = c:\program files\VIA\RAID\raid_tool.exe?ouveau dos

            Recherche de fichiers cachés ...

            Scan terminé avec succès
            Fichiers cachés: 0

            **************************************************************************
            .
            --------------------- CLES DE REGISTRE BLOQUEES ---------------------

            [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h-€|ÿÿÿÿ¤*€|ù*9~*]
            "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
            .
            --------------------- DLLs chargées dans les processus actifs ---------------------

            - - - - - - - > 'winlogon.exe'(652)
            c:\windows\system32\LMIinit.dll
            c:\windows\system32\LMIRfsClientNP.dll

            - - - - - - - > 'explorer.exe'(1824)
            c:\windows\system32\eappprxy.dll
            c:\windows\system32\WPDShServiceObj.dll
            c:\windows\system32\PortableDeviceTypes.dll
            c:\windows\system32\PortableDeviceApi.dll
            .
            ------------------------ Autres processus actifs ------------------------
            .
            c:\program files\Alwil Software\Avast5\AvastSvc.exe
            c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
            c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
            c:\program files\Bonjour\mDNSResponder.exe
            c:\program files\Java\jre6\bin\jqs.exe
            c:\program files\LogMeIn\x86\LMIGuardian.exe
            c:\program files\LogMeIn\x86\RaMaint.exe
            c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ArcCon.ac
            c:\windows\system32\RUNDLL32.EXE
            c:\program files\LogMeIn\x86\LogMeIn.exe
            c:\program files\LogMeIn\x86\LMIGuardian.exe
            c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
            c:\windows\system32\nvsvc32.exe
            c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            c:\program files\iPod\bin\iPodService.exe
            c:\windows\system32\wbem\wmiapsrv.exe
            c:\windows\system32\wscntfy.exe
            c:\windows\system32\msiexec.exe
            c:\windows\system32\MsiExec.exe
            .
            **************************************************************************
            .
            Heure de fin: 2010-09-01 20:40:05 - La machine a redémarré
            ComboFix-quarantined-files.txt 2010-09-01 18:40
            ComboFix2.txt 2010-09-01 11:07
            ComboFix3.txt 2010-09-01 09:32

            Avant-CF: 125.702.303.744 octets libres
            Après-CF: 125.693.571.072 octets libres

            - - End Of File - - F6B4E63E0AFA900A3A83C13ECC2231B8
            1. Contributeur sécurité
              1)

              /!\ ATTENTION /!\ Le script qui suit a été écrit spécialement pour Pimz08, il n'est pas transposable sur un autre ordinateur !

              crées un sur ton bureau un nouveau fichier bloc note que tu nommeras CFScript
              Copies y ce texte dedans et enregistres le

              KillAll::

              File::

              c:\WINDOWS\temp\Perflib_Perfdata_894.dat


              * Désactive tes logiciels de protection
              * Fais un glisser/déposer de ce fichier CFScript.txt sur le fichier Combofix.exe (comme le lien suivant)
              http://apu.mabul.org/up/apu/2008/09/06/ ... 35my8h.gif
              * Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
              * Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
              * Si le fichier ne s'ouvre pas, il se trouve ici ? C:\ComboFix.txt

              ...................

              2)

              Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
              https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

              * Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
              * Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
              * Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse
              1. seaf :
                1. ========================= SEAF 1.0.0.7 - C_XX
                2.
                3. Commencé à: 19:54:41 le 01/09/2010
                4.
                5. Valeur(s) recherchée(s):
                6.
                7. Perflib_Perfdata
                8.
                9. (!) --- Calcul du Hash "MD5"
                10. (!) --- Affichage des ADS
                11. (!) --- Informations supplémentaires
                12. (!) --- Recherche registre
                13.
                14. ====== Fichier(s) (TC: Date de création, TM: Date de modification, DA, Dernier accès) ======
                15.
                16. "c:\WINDOWS\temp\Perflib_Perfdata_894.dat" [ ----AT---- | 16384 ]
                17. TC: 01/09/2010,19:03:58 | TM: 01/09/2010,19:03:58 | DA: 01/09/2010,19:03:58
                18. MD5: DENIED
                19.
                20.
                21.
                22. =========================
                23.
                24. ====== Dossier(s) (TC: Date de création, TM: Date de modification, DA, Dernier accès) ======
                25.
                26. Aucun dossier trouvé
                27.
                28.
                29. ====== Entrée(s) du registre ======
                30.
                31.
                32.
                33. [HKEY_CURRENT_USER\Software\Messenger_Plus_Live_Belgium\toolbar\settings\FindBar\History]
                34. "Value0"="Perflib_Perfdata_580.dat"
                35.
                36. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
                37. "a"="C:\WINDOWS\temp\Perflib_Perfdata_c3c.dat"
                38.
                39. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
                40. "g"="C:\WINDOWS\temp\Perflib_Perfdata_580.dat"
                41.
                42. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dat]
                43. "a"="C:\WINDOWS\temp\Perflib_Perfdata_580.dat"
                44.
                45. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dat]
                46. "b"="C:\WINDOWS\temp\Perflib_Perfdata_c3c.dat"
                47.
                48. [HKEY_USERS\S-1-5-21-1275210071-2146652945-1417001333-1003\Software\Messenger_Plus_Live_Belgium\toolbar\settings\FindBar\History]
                49. "Value0"="Perflib_Perfdata_580.dat"
                50.
                51. [HKEY_USERS\S-1-5-21-1275210071-2146652945-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
                52. "a"="C:\WINDOWS\temp\Perflib_Perfdata_c3c.dat"
                53.
                54. [HKEY_USERS\S-1-5-21-1275210071-2146652945-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\*]
                55. "g"="C:\WINDOWS\temp\Perflib_Perfdata_580.dat"
                56.
                57. [HKEY_USERS\S-1-5-21-1275210071-2146652945-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dat]
                58. "a"="C:\WINDOWS\temp\Perflib_Perfdata_580.dat"
                59.
                60. [HKEY_USERS\S-1-5-21-1275210071-2146652945-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU\dat]
                61. "b"="C:\WINDOWS\temp\Perflib_Perfdata_c3c.dat"
                62.
                63. =========================
                64.
                65. Fin à: 19:55:32 le 01/09/2010 ( E.O.F )
                1. Contributeur sécurité
                  ok

                  apres le clean

                  Télécharge SEAF ( de C__XX ) sur ton bureau :

                  ici http://pagesperso-orange.fr/NosTools/C_XX/SEAF.exe

                  * Double clique sur "SEAF.exe" ( clique droit et "Exécuter en tant qu'administrateur" pour Vista / 7 ) pour lancer l'outil.

                  * Dans l'encardré blanc " Entrez ci dessous...." copie/colle ceci :

                  Perflib_Perfdata_898.dat

                  * Au niveau des " options des fichiers ", fait les réglages suivant :
                  > A "Calculer le checksum" , choisis : MD5
                  > Coche la case devant " Info. supplémentaire ".
                  > Coche la case devant " Afficher les ADS "

                  * Au niveau des " options du registre " :
                  > coche " chercher également dans le registre "

                  ( ne touche à aucun autre réglage )

                  * Clique sur " Lancer la recherche " et laisse travailler l'outil ...
                  ( cela peut-être plus ou moins long suivant les cas ).

                  --> Une fois terminé, une fenêtre avec un log .txt va s'afficher. Enregistre ce rapport de façon à le retrouver facilement ( sur le bureau par exemple ). Sinon il sera en outre sauvegardé à la racine de ton disque dur ( ici > C:\SEAFLog.txt )
                  1. kill'em :
                    ¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.0.2 ¤¤¤¤¤¤¤¤¤¤

                    User : klein (Administrateurs)
                    Update on 30/08/2010 by g3n-h@ckm@n ::::: 15.00
                    Start at: 19:06:22 | 1/09/2010

                    AMD Athlon(tm) XP 2200+
                    Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
                    Internet Explorer 6.0.2900.5512
                    Windows Firewall Status : Disabled
                    AV : avast! Antivirus 5.0.83886674 [ (!) Disabled | Updated ]

                    A:\ -> Lecteur de disquettes 3 ½ pouces
                    C:\ -> Disque fixe local | 149,04 Go (117,06 Go free) | NTFS
                    D:\ -> Disque CD-ROM
                    E:\ -> Disque fixe local | 37,27 Go (22,8 Go free) [Nouveau nom] | NTFS

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Processes ------- Memory(Ko)

                    C:\WINDOWS\System32\smss.exe ----400 Ko
                    C:\WINDOWS\system32\csrss.exe ----4456 Ko
                    C:\WINDOWS\system32\winlogon.exe ----4848 Ko
                    C:\WINDOWS\system32\services.exe ----3568 Ko
                    C:\WINDOWS\system32\lsass.exe ----6116 Ko
                    C:\WINDOWS\system32\svchost.exe ----5280 Ko
                    C:\WINDOWS\system32\svchost.exe ----4696 Ko
                    C:\WINDOWS\System32\svchost.exe ----20472 Ko
                    C:\WINDOWS\system32\svchost.exe ----3484 Ko
                    C:\WINDOWS\system32\svchost.exe ----3780 Ko
                    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe ----22212 Ko
                    C:\WINDOWS\Explorer.EXE ----24420 Ko
                    C:\Program Files\VIA\RAID\raid_tool.exe ----5768 Ko
                    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe ----2908 Ko
                    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe ----6604 Ko
                    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe ----2508 Ko
                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe ----1932 Ko
                    C:\Program Files\Fichiers communs\Nikon\Monitor\NkMonitor.exe ----3324 Ko
                    E:\iTunes\iTunesHelper.exe ----12740 Ko
                    C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe ----5188 Ko
                    C:\Program Files\Fichiers communs\Java\Java Update\jusched.exe ----2388 Ko
                    C:\WINDOWS\system32\RUNDLL32.EXE ----3380 Ko
                    C:\Program Files\LogMeIn\x86\LMIGuardian.exe ----2220 Ko
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe ----10992 Ko
                    C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe ----5032 Ko
                    C:\WINDOWS\system32\spoolsv.exe ----6036 Ko
                    C:\WINDOWS\system32\svchost.exe ----3440 Ko
                    C:\Program Files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe ----2304 Ko
                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe ----2628 Ko
                    C:\Program Files\Bonjour\mDNSResponder.exe ----3652 Ko
                    C:\WINDOWS\system32\svchost.exe ----9536 Ko
                    C:\Program Files\Java\jre6\bin\jqs.exe ----1380 Ko
                    C:\Program Files\LogMeIn\x86\RaMaint.exe ----3224 Ko
                    C:\Program Files\LogMeIn\x86\LogMeIn.exe ----12224 Ko
                    C:\Program Files\LogMeIn\x86\LMIGuardian.exe ----2220 Ko
                    C:\WINDOWS\System32\svchost.exe ----2848 Ko
                    C:\WINDOWS\system32\nvsvc32.exe ----4092 Ko
                    C:\WINDOWS\System32\svchost.exe ----3176 Ko
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe ----7808 Ko
                    C:\WINDOWS\system32\svchost.exe ----4296 Ko
                    C:\Program Files\VIA\RAID\vialogsv.exe ----3720 Ko
                    C:\WINDOWS\system32\wbem\wmiprvse.exe ----5292 Ko
                    C:\WINDOWS\system32\wuauclt.exe ----8060 Ko
                    C:\WINDOWS\system32\wbem\wmiprvse.exe ----8088 Ko
                    C:\Program Files\Windows Live\Toolbar\wltuser.exe ----6352 Ko
                    C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe ----3980 Ko
                    C:\Program Files\iPod\bin\iPodService.exe ----3904 Ko
                    C:\WINDOWS\system32\wscntfy.exe ----1972 Ko
                    C:\WINDOWS\system32\wbem\wmiapsrv.exe ----4448 Ko
                    C:\WINDOWS\System32\alg.exe ----3492 Ko
                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe ----8540 Ko
                    C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe ----3644 Ko
                    C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe ----7044 Ko
                    C:\WINDOWS\system32\wuauclt.exe ----4012 Ko
                    C:\WINDOWS\system32\cmd.exe ----2876 Ko
                    C:\Program Files\List_Kill'em\ERUNT.EXE ----3096 Ko
                    C:\Program Files\List_Kill'em\pv.exe ----2704 Ko

                    ¤¤¤¤¤¤¤¤¤¤ Files/folders :

                    Quarantined & Deleted !! : C:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadD500.exe
                    Quarantined & Deleted !! : C:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadX800.exe
                    Quarantined & Deleted !! : C:\Program Files\Samsung\Samsung PC Studio 3\Update\util\UnZipTemp\OrgLoadZ510.exe
                    Quarantined & Deleted !! : C:\WINDOWS\SET3.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\SET4.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\SET8.tmp

                    Quarantined & Deleted !! : C:\WINDOWS\system32\AbaleZip.dll
                    Quarantined & Deleted !! : C:\WINDOWS\System32\drivers\etc\hosts.msn
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET169.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET175.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET17E.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET17F.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET180.tmp
                    Quarantined & Deleted !! : C:\WINDOWS\System32\SET183.tmp

                    ¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤

                    127.0.0.1 localhost

                    ¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤

                    Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser : {0E5CBF21-D15F-11D0-8301-00AA005B4383}
                    Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
                    Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer : NoDrives
                    Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Install.exe"
                    Deleted : "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\Setup.exe"
                    Deleted : HKCR\Interface\{f9c23cd1-6da9-4e0b-8367-c6f9f1f78baf}
                    Deleted : HKCU\Software\Conduit
                    Deleted : HKLM\software\classes\installer\Products\A28B4D68DEBAA244EB686953B7074FEF
                    Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\741B4ADF27276464790022C965AB6DA8
                    Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\7DE196B10195F5647A2B21B761F3DE01
                    Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\9D4F5849367142E4685ED8C25E44C5ED
                    Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A5875B04372C19545BEB90D4D606C472
                    Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\A876D9E80B896EC44A8620248CC79296
                    Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Components\B66FFAB725B92594C986DE826A867888
                    Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF

                    ¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    Local Page = C:\WINDOWS\system32\blank.htm
                    Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    Start Page = https://www.google.com/?gws_rd=ssl
                    Local Page = C:\WINDOWS\system32\blank.htm
                    Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

                    ¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                    FirstRunDisabled = 1 ()
                    AntiVirusDisableNotify = 0 (0x0)
                    FirewallDisableNotify = 0 (0x0)
                    UpdatesDisableNotify = 0 (0x0)
                    AntiVirusOverride = 0 (0x0)
                    FirewallOverride = 0 (0x0)

                    ¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤

                    Ndisuio : Start = 3
                    EapHost : Start = 2
                    Ip6Fw : Start = 2
                    SharedAccess : Start = 2
                    wuauserv : Start = 2
                    wscsvc : Start = 2

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                    Disk Cleaned
                    anti-ver blaster : OK
                    Prefetch cleaned
                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

                    FEATURE_BROWSER_EMULATION | svchost :
                    ====================================

                    Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

                    device: opened successfully
                    user: MBR read successfully
                    called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys videX32.sys PCIIDEX.SYS
                    kernel: MBR read successfully
                    user & kernel MBR OK

                    ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
                2. Contributeur sécurité
                  1)

                  pour virus total

                  copie colle le lien de la page

                  .................

                  2)

                  Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
                  mais cette fois-ci :

                  choisis l'option CLEAN
                  ton PC va redemarrer,

                  laisse travailler l'outil.

                  en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

                  colle le contenu dans ta reponse

                  1. pour virus total, je n'ai plus le fichier que tu m'as demandé de scanner et je n'arrivais pas à le scanner, il ne générait pas de rapport.

                    je vais lancer le clean.
                3. je ne sais pas réaliser la manipulation avec virustotal, il ne crée pas le rapport (j'ai essayer de copier le fichier sur le bureau mais c'est impossible, fichier illisible)

                  more.txt : http://www.cijoint.fr/cjlink.php?file=cj201009/cijDx5oHWy.txt
                  list'em.txt : http://www.cijoint.fr/cjlink.php?file=cj201009/cijxiOardX.txt
                  1. Contributeur sécurité
                    ok

                    1)

                    Rends toi sur ce site :

                    https://www.virustotal.com/gui/

                    Clique sur parcourir et cherche ce fichier :

                    c:\windows\temp\Perflib_Perfdata_898.dat

                    Clique sur Send File.

                    Un rapport va s'élaborer ligne à ligne.

                    Attends la fin. Il doit comprendre la taille du fichier envoyé.

                    Sauvegarde le rapport avec le bloc-note.

                    Copie le dans ta réponse.

                    Si tu ne trouves pas le fichier alors

                    Affiche tous les fichiers et dossiers :

                    Pour cela :
                    Clique sur démarrer/panneau de configuration/option des dossiers/affichage

                    Cocher afficher les dossiers cachés

                    Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                    Décocher masquer les extensions dont le type est connu

                    Puis fais «appliquer» pour valider les changements.

                    Et OK


                    tuto pour t'aider


                    http://www.bibou0007.com/scans-en-ligne-f75/tutorial-sur-virustotal-t190.htm

                    ......................

                    2)


                    DESACTIVE TON ANTIVIRUS ET TON PAREFEU SI PRESENTS !!!!!(car il est detecté a tort comme infection)


                    Télécharge ici :List_Kill'em et enregistre le sur ton bureau

                    http://sd-4.archive-host.com/membres/up/829108531491024/Mes_Tools/List_Killem_Install.exe

                    ou

                    http://www.archive-host.com

                    si tu as XP => double clique
                    si tu as Vista ou windows 7 => clic droit "executer en tant que...."

                    sur le raccourci sur ton bureau pour lancer l'installation

                    Laisse coché :

                    Executer List_Kill'em

                    une fois terminée , clic sur "terminer" et le programme se lancera seul

                    choisis l'option Search

                    laisse travailler l'outil

                    il se peut qu'une boite de dialogue s'ouvre , dans ce cas clique sur "ok" ou "Agree"

                    à l'apparition de la fenetre blanche , c'est un peu long , c'est normal ,c'est une recherche supplementaire de fichiers cachés , le programme n'est pas bloqué.

                    Poste le contenu du rapport qui s'ouvre aux 100 % du scan à l'ecran "COMPLETED"

                    NE LE POSTE PAS SUR LE FORUM

                    Pour me le transmettre clique sur ce lien : http://www.cijoint.fr/

                    Clique sur Parcourir et cherche le fichier ci-dessus.

                    Clique sur Ouvrir.

                    Clique sur "Cliquez ici pour déposer le fichier".

                    Un lien de cette forme :

                    http://www.cijoint.fr/cjlink.php?file=265368/cijSKAP5fU.txt

                    est ajouté dans la page.

                    Copie ce lien dans ta réponse.

                    Fais de même avec more.txt qui se trouve sur ton bureau
                    1. ComboFix 10-08-31.02 - klein 01/09/2010 12:52:33.2.1 - x86
                      Microsoft Windows XP Professionnel 5.1.2600.3.1252.32.1036.18.1023.593 [GMT 2:00]
                      Lancé depuis: c:\documents and settings\klein\Bureau\ComboFix.exe
                      Commutateurs utilisés :: c:\documents and settings\klein\Bureau\CFScript.txt
                      AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}

                      FILE ::
                      "c:\windows\ARJ.PIF"
                      "c:\windows\LHA.PIF"
                      "c:\windows\NOCLOSE.PIF"
                      "c:\windows\PKUNZIP.PIF"
                      "c:\windows\PKZIP.PIF"
                      "c:\windows\RAR.PIF"
                      "c:\windows\UC.PIF"
                      .

                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      c:\windows\ARJ.PIF
                      c:\windows\LHA.PIF
                      c:\windows\NOCLOSE.PIF
                      c:\windows\PKUNZIP.PIF
                      c:\windows\PKZIP.PIF
                      c:\windows\RAR.PIF
                      c:\windows\UC.PIF

                      .
                      ((((((((((((((((((((((((((((( Fichiers créés du 2010-08-01 au 2010-09-01 ))))))))))))))))))))))))))))))))))))
                      .

                      2010-08-31 11:23 . 2010-08-31 11:23 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\Conduit
                      2010-08-31 11:20 . 2010-08-31 12:00 -------- d-----w- c:\program files\ZHPDiag
                      2010-08-31 10:50 . 2010-08-31 10:54 -------- d-----w- c:\program files\Ad-Remover
                      2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\GHISLER
                      2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\program files\Trend Micro
                      2010-08-31 10:30 . 2010-08-31 10:30 -------- d-----w- c:\windows\nvidia icons
                      2010-08-31 10:29 . 2008-04-30 15:27 442368 ----a-w- c:\windows\system32\NVUNINST.EXE
                      2010-08-31 10:26 . 2010-08-31 10:26 -------- d-----w- c:\program files\SystemRequirementsLab
                      2010-08-30 21:48 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
                      2010-08-30 21:48 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
                      2010-08-30 21:48 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
                      2010-08-30 21:48 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
                      2010-08-30 21:48 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
                      2010-08-30 21:48 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
                      2010-08-30 21:48 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
                      2010-08-30 21:47 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
                      2010-08-30 21:47 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
                      2010-08-30 21:47 . 2010-08-30 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
                      2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- C:\totalcmd
                      2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- c:\documents and settings\klein\Application Data\GHISLER
                      2010-08-30 21:08 . 2010-08-31 10:51 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
                      2010-08-30 21:08 . 2010-08-30 21:09 -------- d-----w- c:\program files\SpywareBlaster
                      2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\klein\Application Data\Malwarebytes
                      2010-08-30 21:06 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                      2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                      2010-08-30 21:06 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
                      2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2010-09-01 10:49 . 2009-03-23 22:36 -------- d-----w- c:\documents and settings\klein\Application Data\HPAppData
                      2010-09-01 07:16 . 2009-04-18 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
                      2010-09-01 07:15 . 2008-12-24 04:28 -------- d-----w- c:\program files\LogMeIn
                      2010-08-31 10:25 . 2008-12-23 23:08 -------- d-----w- c:\program files\Fichiers communs\Java
                      2010-08-31 10:25 . 2008-12-23 23:09 -------- d-----w- c:\program files\Java
                      2010-08-30 21:47 . 2008-12-24 04:16 -------- d-----w- c:\program files\Alwil Software
                      2010-08-30 20:53 . 2008-12-23 23:06 -------- d-----w- c:\program files\CCleaner
                      2010-08-30 12:34 . 2010-05-07 16:58 -------- d-----w- c:\program files\Messenger_Plus_Live_Belgium
                      2010-08-13 06:37 . 2010-04-01 19:12 -------- d-----w- c:\program files\Messenger Plus! Live
                      2010-08-12 15:04 . 2002-02-28 21:58 80856 ----a-w- c:\windows\system32\perfc00C.dat
                      2010-08-12 15:04 . 2002-02-28 21:58 500814 ----a-w- c:\windows\system32\perfh00C.dat
                      2010-08-03 12:53 . 2010-08-03 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcp71.dll
                      2010-08-03 12:53 . 2010-08-03 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\jmc.dll
                      2010-08-03 12:53 . 2010-08-03 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcr71.dll
                      2010-08-03 12:53 . 2010-08-03 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-sse.dll
                      2010-08-03 12:53 . 2010-08-03 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-d3d.dll
                      2010-07-29 09:17 . 2008-12-24 04:25 -------- d-----w- c:\documents and settings\klein\Application Data\LimeWire
                      2010-07-28 09:25 . 2009-01-10 19:19 -------- d-----w- c:\documents and settings\klein\Application Data\Apple Computer
                      2010-07-28 09:18 . 2010-07-28 09:17 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
                      2010-07-28 09:18 . 2010-07-28 09:18 -------- d-----w- c:\program files\iPod
                      2010-07-28 09:17 . 2009-01-10 19:15 -------- d-----w- c:\program files\Fichiers communs\Apple
                      2010-07-28 09:16 . 2010-07-28 09:15 -------- d-----w- c:\program files\QuickTime
                      2010-07-28 09:11 . 2010-07-28 09:11 -------- d-----w- c:\program files\Bonjour
                      2010-07-28 09:08 . 2010-07-28 09:08 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
                      2010-07-23 12:53 . 2010-07-23 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcp71.dll
                      2010-07-23 12:53 . 2010-07-23 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\jmc.dll
                      2010-07-23 12:53 . 2010-07-23 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcr71.dll
                      2010-07-23 12:53 . 2010-07-23 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-sse.dll
                      2010-07-23 12:53 . 2010-07-23 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-d3d.dll
                      2010-07-17 03:00 . 2010-07-23 12:53 423656 ----a-w- c:\windows\system32\deployJava1.dll
                      2010-06-30 12:32 . 2008-04-13 17:33 149504 ----a-w- c:\windows\system32\schannel.dll
                      2010-06-24 12:10 . 2008-04-13 17:33 671232 ----a-w- c:\windows\system32\wininet.dll
                      2010-06-24 12:10 . 2008-04-13 17:33 81920 ----a-w- c:\windows\system32\ieencode.dll
                      2010-06-24 09:02 . 2008-04-13 16:58 1852032 ----a-w- c:\windows\system32\win32k.sys
                      2010-06-22 19:38 . 2008-12-24 12:30 64560 ----a-w- c:\documents and settings\klein\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                      2010-06-21 15:27 . 2008-04-13 10:15 354304 ----a-w- c:\windows\system32\drivers\srv.sys
                      2010-06-17 14:03 . 2008-04-13 17:33 80384 ----a-w- c:\windows\system32\iccvid.dll
                      2010-06-14 14:31 . 2008-12-23 22:17 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
                      2010-06-14 07:42 . 2008-04-13 17:33 1172480 ----a-w- c:\windows\system32\msxml3.dll
                      2010-06-11 15:32 . 2008-12-24 04:28 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
                      2010-06-11 15:32 . 2008-12-24 04:28 29568 ----a-w- c:\windows\system32\LMIport.dll
                      2010-06-11 15:32 . 2008-12-24 04:28 87424 ----a-w- c:\windows\system32\LMIinit.dll
                      .

                      ((((((((((((((((((((((((((((( SnapShot@2010-09-01_09.26.49 )))))))))))))))))))))))))))))))))))))))))
                      .
                      + 2010-09-01 11:00 . 2010-09-01 11:00 16384 c:\windows\temp\Perflib_Perfdata_898.dat
                      .
                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                      REGEDIT4

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                      "{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]

                      [HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]

                      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
                      2010-08-30 12:34 2734688 ----a-w- c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                      "{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]

                      [HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                      "{D1A1C8F1-E3D9-48DF-802F-20201061EF61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]

                      [HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-18 39408]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "VIARaidUtl"="c:\program files\VIA\RAID\raid_tool.exe" [2008-09-24 4918936]
                      "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
                      "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 63048]
                      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
                      "nwiz"="nwiz.exe" [2008-05-03 1630208]
                      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
                      "fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-08-05 647520]
                      "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-14 188416]
                      "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
                      "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
                      "ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
                      "Nikon Transfer Monitor"="c:\program files\Fichiers communs\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
                      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
                      "iTunesHelper"="e:\itunes\iTunesHelper.exe" [2010-07-21 141608]
                      "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
                      "SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
                      "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]

                      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

                      c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
                      HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
                      ZDWLan Utility.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-12-24 487424]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
                      2010-06-11 15:32 87424 ----a-w- c:\windows\system32\LMIinit.dll

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                      "EnableFirewall"= 0 (0x0)

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                      "%windir%\\system32\\sessmgr.exe"=
                      "e:\\Emul\\eMule\\emule.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                      "e:\\Nouveau dossier (3)\\LimeWire\\LimeWire.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                      "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                      "e:\\iTunes\\iTunes.exe"=

                      R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30/08/2010 23:48 165456]
                      R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/08/2010 23:48 17744]
                      R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [28/02/2008 16:31 12856]
                      R2 VRAID Log Service;VRAID Log Service;c:\program files\VIA\RAID\vialogsv.exe [24/12/2008 0:51 52888]
                      S2 gupdate1c9c013bc09c1fc;Service Google Update (gupdate1c9c013bc09c1fc);c:\program files\Google\Update\GoogleUpdate.exe [18/04/2009 12:52 133104]
                      S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [15/03/2009 10:34 216232]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                      HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                      hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
                      .
                      Contenu du dossier 'Tâches planifiées'

                      2010-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job
                      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

                      2010-09-01 c:\windows\Tasks\Google Software Updater.job
                      - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-18 10:51]

                      2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                      - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]

                      2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                      - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]

                      2010-09-01 c:\windows\Tasks\OGALogon.job
                      - c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
                      .
                      .
                      ------- Examen supplémentaire -------
                      .
                      uStart Page = hxxp://www.footbel.com/fr.html
                      uInternet Connection Wizard,ShellNext = hxxp://www.google.be/
                      uInternet Settings,ProxyOverride = *.local
                      IE: &Télécharger le FLV avec WinAVI... - e:\nouveau dossier\WinAVI FLV Converter\flv_link.htm
                      IE: Compare Prices with &Dealio - c:\documents and settings\klein\Application Data\Dealio\kb127\res\DealioSearch.html
                      IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      .

                      **************************************************************************

                      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2010-09-01 13:03
                      Windows 5.1.2600 Service Pack 3 NTFS

                      Recherche de processus cachés ...

                      Recherche d'éléments en démarrage automatique cachés ...

                      HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                      VIARaidUtl = c:\program files\VIA\RAID\raid_tool.exe?ouveau dos

                      Recherche de fichiers cachés ...

                      Scan terminé avec succès
                      Fichiers cachés: 0

                      **************************************************************************
                      .
                      --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                      [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h-€|ÿÿÿÿ¤*€|ù*9~*]
                      "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                      .
                      --------------------- DLLs chargées dans les processus actifs ---------------------

                      - - - - - - - > 'winlogon.exe'(644)
                      c:\windows\system32\LMIinit.dll
                      c:\windows\system32\LMIRfsClientNP.dll

                      - - - - - - - > 'explorer.exe'(4020)
                      c:\windows\system32\eappprxy.dll
                      c:\windows\system32\WPDShServiceObj.dll
                      c:\windows\system32\PortableDeviceTypes.dll
                      c:\windows\system32\PortableDeviceApi.dll
                      .
                      ------------------------ Autres processus actifs ------------------------
                      .
                      c:\program files\Alwil Software\Avast5\AvastSvc.exe
                      c:\program files\LogMeIn\x86\LMIGuardian.exe
                      c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
                      c:\windows\system32\RUNDLL32.EXE
                      c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                      c:\program files\Bonjour\mDNSResponder.exe
                      c:\program files\Java\jre6\bin\jqs.exe
                      c:\program files\LogMeIn\x86\RaMaint.exe
                      c:\program files\LogMeIn\x86\LogMeIn.exe
                      c:\program files\LogMeIn\x86\LMIGuardian.exe
                      c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                      c:\windows\system32\nvsvc32.exe
                      c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      c:\program files\iPod\bin\iPodService.exe
                      c:\windows\system32\wbem\wmiapsrv.exe
                      c:\windows\system32\wscntfy.exe
                      c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
                      c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
                      c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
                      .
                      **************************************************************************
                      .
                      Heure de fin: 2010-09-01 13:07:06 - La machine a redémarré
                      ComboFix-quarantined-files.txt 2010-09-01 11:07
                      ComboFix2.txt 2010-09-01 09:32

                      Avant-CF: 125.713.920.000 octets libres
                      Après-CF: 125.705.990.144 octets libres

                      - - End Of File - - 11FC43E12472DE1F72C9EAA2CB3E9820
                      1. Contributeur sécurité
                        /!\ ATTENTION /!\ Le script qui suit a été écrit spécialement pour Pimz08, il n'est pas transposable sur un autre ordinateur !

                        crées un sur ton bureau un nouveau fichier bloc note que tu nommeras CFScript
                        Copies y ce texte dedans et enregistres le

                        KillAll::

                        File::

                        c:\windows\UC.PIF
                        c:\windows\RAR.PIF
                        c:\windows\PKZIP.PIF
                        c:\windows\PKUNZIP.PIF
                        c:\windows\NOCLOSE.PIF
                        c:\windows\LHA.PIF
                        c:\windows\ARJ.PIF


                        * Désactive tes logiciels de protection
                        * Fais un glisser/déposer de ce fichier CFScript.txt sur le fichier Combofix.exe
                        * Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal ! Ne touche à rien tant que le scan n'est pas terminé.
                        * Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                        * Si le fichier ne s'ouvre pas, il se trouve ici ? C:\ComboFix.txt
                        1. ComboFix 10-08-31.02 - klein 01/09/2010 11:20:07.1.1 - x86
                          Microsoft Windows XP Professionnel 5.1.2600.3.1252.32.1036.18.1023.624 [GMT 2:00]
                          Lancé depuis: c:\documents and settings\klein\Bureau\ComboFix.exe
                          AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
                          .

                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          c:\program files\Lphant Applications\Lphant MediaBar\LphantIEHelper.dll
                          c:\program files\Lphant Applications\Lphant MediaBar\LphantMediaBar.dll
                          c:\windows\system32\scrrnfr.dll

                          .
                          ((((((((((((((((((((((((((((( Fichiers créés du 2010-08-01 au 2010-09-01 ))))))))))))))))))))))))))))))))))))
                          .

                          2010-08-31 11:23 . 2010-08-31 11:23 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\Conduit
                          2010-08-31 11:20 . 2010-08-31 12:00 -------- d-----w- c:\program files\ZHPDiag
                          2010-08-31 10:50 . 2010-08-31 10:54 -------- d-----w- c:\program files\Ad-Remover
                          2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\documents and settings\klein\Local Settings\Application Data\GHISLER
                          2010-08-31 10:35 . 2010-08-31 10:35 -------- d-----w- c:\program files\Trend Micro
                          2010-08-31 10:30 . 2010-08-31 10:30 -------- d-----w- c:\windows\nvidia icons
                          2010-08-31 10:29 . 2008-04-30 15:27 442368 ----a-w- c:\windows\system32\NVUNINST.EXE
                          2010-08-31 10:26 . 2010-08-31 10:26 -------- d-----w- c:\program files\SystemRequirementsLab
                          2010-08-30 21:48 . 2010-06-28 20:32 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
                          2010-08-30 21:48 . 2010-06-28 20:37 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
                          2010-08-30 21:48 . 2010-06-28 20:33 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
                          2010-08-30 21:48 . 2010-06-28 20:37 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
                          2010-08-30 21:48 . 2010-06-28 20:32 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
                          2010-08-30 21:48 . 2010-06-28 20:32 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
                          2010-08-30 21:48 . 2010-06-28 20:32 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
                          2010-08-30 21:47 . 2010-06-28 20:57 38848 ----a-w- c:\windows\avastSS.scr
                          2010-08-30 21:47 . 2010-06-28 20:57 165032 ----a-w- c:\windows\system32\aswBoot.exe
                          2010-08-30 21:47 . 2010-08-30 21:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Alwil Software
                          2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- C:\totalcmd
                          2010-08-30 21:21 . 2010-08-30 21:21 -------- d-----w- c:\documents and settings\klein\Application Data\GHISLER
                          2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\UC.PIF
                          2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\RAR.PIF
                          2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\PKZIP.PIF
                          2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\PKUNZIP.PIF
                          2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\NOCLOSE.PIF
                          2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\LHA.PIF
                          2010-08-30 21:21 . 2010-07-07 05:55 545 ----a-w- c:\windows\ARJ.PIF
                          2010-08-30 21:08 . 2010-08-31 10:51 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
                          2010-08-30 21:08 . 2010-08-30 21:09 -------- d-----w- c:\program files\SpywareBlaster
                          2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\klein\Application Data\Malwarebytes
                          2010-08-30 21:06 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
                          2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                          2010-08-30 21:06 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
                          2010-08-30 21:06 . 2010-08-30 21:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                          2010-08-03 12:53 . 2010-08-03 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcp71.dll
                          2010-08-03 12:53 . 2010-08-03 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\jmc.dll
                          2010-08-03 12:53 . 2010-08-03 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-5cdea610-n\msvcr71.dll
                          2010-08-03 12:53 . 2010-08-03 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-sse.dll
                          2010-08-03 12:53 . 2010-08-03 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-1dd7bc75-n\decora-d3d.dll

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2010-09-01 09:04 . 2009-03-23 22:36 -------- d-----w- c:\documents and settings\klein\Application Data\HPAppData
                          2010-09-01 07:16 . 2009-04-18 10:51 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater
                          2010-09-01 07:15 . 2008-12-24 04:28 -------- d-----w- c:\program files\LogMeIn
                          2010-08-31 10:25 . 2008-12-23 23:08 -------- d-----w- c:\program files\Fichiers communs\Java
                          2010-08-31 10:25 . 2008-12-23 23:09 -------- d-----w- c:\program files\Java
                          2010-08-30 21:47 . 2008-12-24 04:16 -------- d-----w- c:\program files\Alwil Software
                          2010-08-30 20:53 . 2008-12-23 23:06 -------- d-----w- c:\program files\CCleaner
                          2010-08-30 12:34 . 2010-05-07 16:58 -------- d-----w- c:\program files\Messenger_Plus_Live_Belgium
                          2010-08-13 06:37 . 2010-04-01 19:12 -------- d-----w- c:\program files\Messenger Plus! Live
                          2010-08-12 15:04 . 2002-02-28 21:58 80856 ----a-w- c:\windows\system32\perfc00C.dat
                          2010-08-12 15:04 . 2002-02-28 21:58 500814 ----a-w- c:\windows\system32\perfh00C.dat
                          2010-07-29 09:17 . 2008-12-24 04:25 -------- d-----w- c:\documents and settings\klein\Application Data\LimeWire
                          2010-07-28 09:25 . 2009-01-10 19:19 -------- d-----w- c:\documents and settings\klein\Application Data\Apple Computer
                          2010-07-28 09:18 . 2010-07-28 09:17 -------- d-----w- c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
                          2010-07-28 09:18 . 2010-07-28 09:18 -------- d-----w- c:\program files\iPod
                          2010-07-28 09:17 . 2009-01-10 19:15 -------- d-----w- c:\program files\Fichiers communs\Apple
                          2010-07-28 09:16 . 2010-07-28 09:15 -------- d-----w- c:\program files\QuickTime
                          2010-07-28 09:11 . 2010-07-28 09:11 -------- d-----w- c:\program files\Bonjour
                          2010-07-28 09:08 . 2010-07-28 09:08 73000 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.1.5\SetupAdmin.exe
                          2010-07-23 12:53 . 2010-07-23 12:53 503808 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcp71.dll
                          2010-07-23 12:53 . 2010-07-23 12:53 499712 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\jmc.dll
                          2010-07-23 12:53 . 2010-07-23 12:53 348160 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-56a3ac07-n\msvcr71.dll
                          2010-07-23 12:53 . 2010-07-23 12:53 61440 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-sse.dll
                          2010-07-23 12:53 . 2010-07-23 12:53 12800 ----a-w- c:\documents and settings\klein\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-56e3ac03-n\decora-d3d.dll
                          2010-07-17 03:00 . 2010-07-23 12:53 423656 ----a-w- c:\windows\system32\deployJava1.dll
                          2010-06-30 12:32 . 2008-04-13 17:33 149504 ----a-w- c:\windows\system32\schannel.dll
                          2010-06-24 12:10 . 2008-04-13 17:33 671232 ----a-w- c:\windows\system32\wininet.dll
                          2010-06-24 12:10 . 2008-04-13 17:33 81920 ----a-w- c:\windows\system32\ieencode.dll
                          2010-06-24 09:02 . 2008-04-13 16:58 1852032 ----a-w- c:\windows\system32\win32k.sys
                          2010-06-22 19:38 . 2008-12-24 12:30 64560 ----a-w- c:\documents and settings\klein\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
                          2010-06-21 15:27 . 2008-04-13 10:15 354304 ----a-w- c:\windows\system32\drivers\srv.sys
                          2010-06-17 14:03 . 2008-04-13 17:33 80384 ----a-w- c:\windows\system32\iccvid.dll
                          2010-06-14 14:31 . 2008-12-23 22:17 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
                          2010-06-14 07:42 . 2008-04-13 17:33 1172480 ----a-w- c:\windows\system32\msxml3.dll
                          2010-06-11 15:32 . 2008-12-24 04:28 83360 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
                          2010-06-11 15:32 . 2008-12-24 04:28 29568 ----a-w- c:\windows\system32\LMIport.dll
                          2010-06-11 15:32 . 2008-12-24 04:28 87424 ----a-w- c:\windows\system32\LMIinit.dll
                          .

                          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                          REGEDIT4

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                          "{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]

                          [HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]

                          [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]
                          2010-08-30 12:34 2734688 ----a-w- c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                          "{d1a1c8f1-e3d9-48df-802f-20201061ef61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]

                          [HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]

                          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                          "{D1A1C8F1-E3D9-48DF-802F-20201061EF61}"= "c:\program files\Messenger_Plus_Live_Belgium\tbMes0.dll" [2010-08-30 2734688]

                          [HKEY_CLASSES_ROOT\clsid\{d1a1c8f1-e3d9-48df-802f-20201061ef61}]

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-04-18 39408]

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "VIARaidUtl"="c:\program files\VIA\RAID\raid_tool.exe" [2008-09-24 4918936]
                          "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 32768]
                          "LogMeIn GUI"="c:\program files\LogMeIn\x86\LogMeInSystray.exe" [2008-02-28 63048]
                          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
                          "nwiz"="nwiz.exe" [2008-05-03 1630208]
                          "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
                          "fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-08-05 647520]
                          "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb07.exe" [2003-05-14 188416]
                          "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
                          "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
                          "ArcSoft Connection Service"="c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-03-18 207360]
                          "Nikon Transfer Monitor"="c:\program files\Fichiers communs\Nikon\Monitor\NkMonitor.exe" [2009-09-15 479232]
                          "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
                          "iTunesHelper"="e:\itunes\iTunesHelper.exe" [2010-07-21 141608]
                          "avast5"="c:\progra~1\ALWILS~1\Avast5\avastUI.exe" [2010-06-28 2837864]
                          "SunJavaUpdateSched"="c:\program files\Fichiers communs\Java\Java Update\jusched.exe" [2010-05-14 248552]
                          "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-05-03 86016]

                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                          "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

                          c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
                          HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
                          ZDWLan Utility.lnk - c:\program files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe [2008-12-24 487424]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
                          2010-06-11 15:32 87424 ----a-w- c:\windows\system32\LMIinit.dll

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                          "EnableFirewall"= 0 (0x0)

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                          "%windir%\\system32\\sessmgr.exe"=
                          "e:\\Emul\\eMule\\emule.exe"=
                          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpiscnapp.exe"=
                          "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                          "e:\\Nouveau dossier (3)\\LimeWire\\LimeWire.exe"=
                          "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                          "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
                          "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                          "e:\\iTunes\\iTunes.exe"=

                          R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [30/08/2010 23:48 165456]
                          R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [30/08/2010 23:48 17744]
                          R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\rainfo.sys [28/02/2008 16:31 12856]
                          R2 VRAID Log Service;VRAID Log Service;c:\program files\VIA\RAID\vialogsv.exe [24/12/2008 0:51 52888]
                          S2 gupdate1c9c013bc09c1fc;Service Google Update (gupdate1c9c013bc09c1fc);c:\program files\Google\Update\GoogleUpdate.exe [18/04/2009 12:52 133104]
                          S3 maconfservice;Ma-Config Service;c:\program files\ma-config.com\maconfservice.exe [15/03/2009 10:34 216232]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                          HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                          hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
                          .
                          Contenu du dossier 'Tâches planifiées'

                          2010-08-05 c:\windows\Tasks\AppleSoftwareUpdate.job
                          - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

                          2010-09-01 c:\windows\Tasks\Google Software Updater.job
                          - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-04-18 10:51]

                          2010-09-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                          - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]

                          2010-08-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                          - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-18 10:52]

                          2010-09-01 c:\windows\Tasks\OGALogon.job
                          - c:\windows\system32\OGAEXEC.exe [2009-08-03 14:07]
                          .
                          .
                          ------- Examen supplémentaire -------
                          .
                          uStart Page = hxxp://www.footbel.com/fr.html
                          uInternet Connection Wizard,ShellNext = hxxp://www.google.be/
                          uInternet Settings,ProxyOverride = *.local
                          IE: &Télécharger le FLV avec WinAVI... - e:\nouveau dossier\WinAVI FLV Converter\flv_link.htm
                          IE: Compare Prices with &Dealio - c:\documents and settings\klein\Application Data\Dealio\kb127\res\DealioSearch.html
                          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          .
                          - - - - ORPHELINS SUPPRIMES - - - -

                          URLSearchHooks-{9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
                          BHO-{9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
                          Toolbar-{9b339f6e-ddcd-401b-8764-230adbd01761} - (no file)
                          WebBrowser-{9B339F6E-DDCD-401B-8764-230ADBD01761} - (no file)
                          HKLM-Run-Cmaudio - cmicnfg.cpl

                          **************************************************************************

                          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2010-09-01 11:29
                          Windows 5.1.2600 Service Pack 3 NTFS

                          Recherche de processus cachés ...

                          Recherche d'éléments en démarrage automatique cachés ...

                          HKLM\Software\Microsoft\Windows\CurrentVersion\Run
                          VIARaidUtl = c:\program files\VIA\RAID\raid_tool.exe?ouveau dos

                          Recherche de fichiers cachés ...

                          Scan terminé avec succès
                          Fichiers cachés: 0

                          **************************************************************************
                          .
                          --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                          [HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\h-€|ÿÿÿÿ¤*€|ù*9~*]
                          "C040110900063D11C8EF10054038389C"="C?\\WINDOWS\\system32\\FM20ENU.DLL"
                          .
                          --------------------- DLLs chargées dans les processus actifs ---------------------

                          - - - - - - - > 'winlogon.exe'(648)
                          c:\windows\system32\LMIinit.dll
                          c:\windows\system32\LMIRfsClientNP.dll

                          - - - - - - - > 'explorer.exe'(2560)
                          c:\windows\system32\eappprxy.dll
                          c:\windows\system32\WPDShServiceObj.dll
                          c:\windows\system32\PortableDeviceTypes.dll
                          c:\windows\system32\PortableDeviceApi.dll
                          .
                          ------------------------ Autres processus actifs ------------------------
                          .
                          c:\program files\Alwil Software\Avast5\AvastSvc.exe
                          c:\windows\system32\RUNDLL32.EXE
                          c:\program files\LogMeIn\x86\LMIGuardian.exe
                          c:\program files\Fichiers communs\ArcSoft\Connection Service\Bin\ACService.exe
                          c:\program files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                          c:\program files\Bonjour\mDNSResponder.exe
                          c:\program files\Java\jre6\bin\jqs.exe
                          c:\program files\LogMeIn\x86\RaMaint.exe
                          c:\program files\LogMeIn\x86\LogMeIn.exe
                          c:\program files\LogMeIn\x86\LMIGuardian.exe
                          c:\program files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                          c:\windows\system32\nvsvc32.exe
                          c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          c:\windows\system32\wscntfy.exe
                          c:\program files\iPod\bin\iPodService.exe
                          c:\windows\system32\wbem\wmiapsrv.exe
                          c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
                          c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
                          c:\program files\HP\Digital Imaging\bin\hpqgpc01.exe
                          .
                          **************************************************************************
                          .
                          Heure de fin: 2010-09-01 11:32:39 - La machine a redémarré
                          ComboFix-quarantined-files.txt 2010-09-01 09:32

                          Avant-CF: 125.579.198.464 octets libres
                          Après-CF: 125.710.671.872 octets libres

                          WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
                          [boot loader]
                          timeout=2
                          default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                          [operating systems]
                          c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                          UnsupportedDebug="do not select this" /debug
                          multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect

                          - - End Of File - - E406FF64DA21D94E3A8C9677933EE735
                          1. Contributeur sécurité
                            pas convaincu

                            puisque tu es pret à formater, alors autant pas se priver

                            Attention, avant de commencer, lit attentivement la procédure, et imprime la

                            Aide à l'utilisation
                            https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                            Télécharge ComboFix de sUBs sur ton Bureau :

                            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                            /!\ Déconnecte-toi du net et <gras>DESACTIVES TOUTES LES DEFENSES, antivirus et antispyware y compris /!\ </gras>

                            ---> Double-clique sur ComboFix.exe
                            Un "pop-up" va apparaître qui dit que ComboFix est utilisé à vos risques et avec aucune garantie... Clique sur oui pour accepter

                            SURTOUT INSTALLES LA CONSOLE DE RECUPERATION
                            (si il te propose de l'installer remets internet)

                            ---> Mets-le en langue française F
                            Tape sur la touche 1 (Yes) pour démarrer le scan.

                            Ne touche à rien(souris, clavier) tant que le scan n'est pas terminé, car tu risques de planter ton PC

                            En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                            Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                            /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                            Note : Le rapport se trouve également là : C:\ComboFix.txt

                            1. pas convaincu ? dans quel sens ?
                              pret à reformater : oui mais si je peux m'en tirer sans le faire, ça m'intéresse :)

                              analyse en cours
                          2. virustotal :
                            Antivirus Version Last Update Result
                            AhnLab-V3 2010.09.01.00 2010.09.01 -
                            AntiVir 8.2.4.46 2010.09.01 -
                            Antiy-AVL 2.0.3.7 2010.09.01 -
                            Authentium 5.2.0.5 2010.09.01 -
                            Avast 4.8.1351.0 2010.09.01 -
                            Avast5 5.0.594.0 2010.09.01 -
                            AVG 9.0.0.851 2010.08.31 -
                            BitDefender 7.2 2010.09.01 -
                            CAT-QuickHeal 11.00 2010.09.01 -
                            ClamAV 0.96.2.0-git 2010.09.01 -
                            Comodo 5931 2010.09.01 -
                            DrWeb 5.0.2.03300 2010.09.01 -
                            Emsisoft 5.0.0.37 2010.09.01 -
                            eSafe 7.0.17.0 2010.08.30 -
                            eTrust-Vet 36.1.7830 2010.09.01 -
                            F-Prot 4.6.1.107 2010.08.31 -
                            F-Secure 9.0.15370.0 2010.09.01 -
                            Fortinet 4.1.143.0 2010.08.31 -
                            GData 21 2010.09.01 -
                            Ikarus T3.1.1.88.0 2010.09.01 -
                            Jiangmin 13.0.900 2010.08.30 -
                            K7AntiVirus 9.63.2406 2010.08.31 -
                            Kaspersky 7.0.0.125 2010.09.01 -
                            McAfee 5.400.0.1158 2010.09.01 -
                            McAfee-GW-Edition 2010.1B 2010.09.01 -
                            Microsoft 1.6103 2010.09.01 -
                            NOD32 5414 2010.09.01 -
                            Norman 6.05.11 2010.08.31 -
                            nProtect 2010-09-01.01 2010.09.01 -
                            Panda 10.0.2.7 2010.08.31 -
                            PCTools 7.0.3.5 2010.09.01 -
                            Prevx 3.0 2010.09.01 -
                            Rising 22.63.02.04 2010.09.01 -
                            Sophos 4.56.0 2010.09.01 -
                            Sunbelt 6820 2010.09.01 -
                            SUPERAntiSpyware 4.40.0.1006 2010.09.01 -
                            Symantec 20101.1.1.7 2010.09.01 -
                            TheHacker 6.5.2.1.360 2010.09.01 -
                            TrendMicro 9.120.0.1004 2010.09.01 -
                            TrendMicro-HouseCall 9.120.0.1004 2010.09.01 -
                            VBA32 3.12.14.0 2010.08.31 -
                            ViRobot 2010.8.31.4017 2010.09.01 -
                            VirusBuster 5.0.27.0 2010.08.31 -
                            Additional informationShow all
                            MD5 : a79594bc46ada0e4b7af852d3b2c7713
                            SHA1 : 86dbe686efe57d607716739c1dc5b3dbcaa4ed18
                            SHA256: c1f00ca28d1aa26f1588e0939b482f001b8679f8850d40ee669d7a6ac3565498
                            1. Contributeur sécurité
                              attend avant de formater

                              poste moi le rapport et

                              Rends toi sur ce site :

                              https://www.virustotal.com/gui/

                              Clique sur parcourir et cherche ce fichier :

                              C:\WINDOWS\PKUNZIP.PIF

                              Clique sur Send File.

                              Un rapport va s'élaborer ligne à ligne.

                              Attends la fin. Il doit comprendre la taille du fichier envoyé.

                              Sauvegarde le rapport avec le bloc-note.

                              Copie le dans ta réponse.

                              Si tu ne trouves pas le fichier alors

                              Affiche tous les fichiers et dossiers :

                              Pour cela :
                              Clique sur démarrer/panneau de configuration/option des dossiers/affichage

                              Cocher afficher les dossiers cachés

                              Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                              Décocher masquer les extensions dont le type est connu

                              Puis fais «appliquer» pour valider les changements.

                              Et OK


                              tuto pour t'aider


                              http://www.bibou0007.com/scans-en-ligne-f75/tutorial-sur-virustotal-t190.htm
                              1. je vais essayer de faire la deuxième étape mais je ne sais pas te fournir le rapport de malwarebytes car lorsque le PC s'étient, aucun rapports n'a encore été généré (analyse non terminée).
                            • 1
                            • 2