Sos spyware secure

Bonjour, g fait analyse ac navilog et il me demand de transmetre le appor et apres que faire vp
merci pr vs reponses

Search Navipromo version 3.3.6 commencé le 08/12/2007 à 10:08:57,34

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 14.11.2007 à 18h00 par IL-MAFIOSO

Microsoft Windows Vista 6.0.6000
Internet Explorer : 7.0.6000.16546

*** Recherche Programmes installés ***

*** Recherche dossiers dans C:\Windows ***

*** Recherche dossiers dans C:\Program Files ***

*** Recherche dossiers dans C:\ProgramData ***

*** Recherche dossiers dans C:\ProgramData\Microsoft\Windows\Start Menu\Programs ***

*** Recherche dossiers dans C:\USERS\BIZOUX\APPDATA\ROAMING\MICROS~1\WINDOWS\STARTM~1\PROGRAMS ***

*** Recherche dossiers dans C:\Users\bizoux\AppData\Local\virtualstore\Program Files ***

*** Recherche dossiers dans C:\Users\bizoux\AppData\Roaming ***

*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Fichier(s) caché(s) :

C:\Users\bizoux\AppData\Local\zfsgshlekx.dat
C:\Users\bizoux\AppData\Local\zfsgshlekx.exe
C:\Users\bizoux\AppData\Local\zfsgshlekx_nav.dat
C:\Users\bizoux\AppData\Local\zfsgshlekx_navps.dat

Processus caché(s) :

C:\Users\bizoux\AppData\Local\zfsgshlekx.exe

*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans C:\Windows\system32 *

* Recherche dans C:\Users\bizoux\AppData\Local\Microsoft *

* Recherche dans C:\Users\bizoux\AppData\Local\virtualstore\windows\system32 *

* Recherche dans C:\Users\bizoux\AppData\Local *

Fichiers trouvés :

zfsgshlekx.exe trouvé !
zfsgshlekx.dat trouvé !
zfsgshlekx_nav.dat trouvé !
zfsgshlekx_navps.dat trouvé !

*** Recherche fichiers ***

C:\Windows\system32\nvs2.inf trouvé !

*** Recherche clés spécifiques dans le Registre ***

HKEY_CURRENT_USER\Software\Lanconfig trouvé !

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche fichiers connus:

2)Recherche Heuristique :

C:\Users\bizoux\AppData\Local\zfsgshlekx.dat trouvé !
C:\Users\bizoux\AppData\Local\zfsgshlekx_nav.dat trouvé !

3)Recherche Certificats :

Certificat Egroup trouvé !

*** Analyse terminée le 08/12/2007 à 10:10:11,48 ***
Configuration: Windows Vista
Internet Explorer 7.0

25 réponses

  1. Contributeur
    oui en effet il faudra reprendre le rapport combo
    0
    1. citation

      selectionne ceci

      registry::

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f 46-9bf0-11dc-b961-001c252f163f}]
      \shell\Auto\command - ufpyzntyt.exe
      \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe
      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c5 96-92d8-11dc-b60e-001c252f163f}]
      \shell\Auto\command - ufpyzntyt.exe
      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4 fa-9abc-11dc-a4de-001c252f163f}]
      \shell\Auto\command - F:\hhbgkpudh.exe
      \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe


      pas de commande donc ça peut pas marcher
      [-HKEY_CURRENT_USER.....
      0
      1. hello
        j'ai viré bitdefender
        souci!!!
        0
        1. Contributeur
          ressaye quand même bitdefender
          normalement il passe avec vista
          @+
          0
          1. Contributeur
            ok je cherche un scan valable pour vista
            @+
            0
            1. CA NE MARCHE PAS CAR KASPERSKY N'EST PAS CONFIGURé POUR VISTA! Par contre si tu as autrre chose jsui open
              0
              1. il me met scan failed impossible d'analyser l'ordinateur contre les virus
                0
                1. Contributeur
                  ton anti virus est avast

                  le scan en ligne de bitdefender
                  n'est en aucun cas gênant avec ton anti virus
                  donc il faut faire le scan
                  @+
                  0
                  1. j'ai désinstaler bit defender car j'ai avast?que faire
                    0
                    1. Contributeur
                      Fais un scan antivirus en ligne avec Internet Explorer
                      https://www.bitdefender.fr/
                      et copie colle le résultat ici
                      = En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
                      = Dans la nouvelle fenêtre, clique sur I agree
                      = La fenêtre change encore, clique sur Click here to scan
                      = Les signatures se chargent, etc.

                      tuto en image

                      http://pageperso.aol.fr/rginformatique/mapage/defender.htm

                      et
                      reposte un nouveau rapport hijackthis
                      0
                      1. ComboFix 07-12-08.1 - bizoux 2007-12-08 22:52:15.2 - NTFSx86
                        Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.68 [GMT 1:00]
                        Running from: C:\Users\bizoux\Desktop\ComboFix.exe
                        Command switches used :: C:\Users\bizoux\Documents\CFScript.txt
                        * Created a new restore point
                        .

                        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                        .

                        K:\Autorun.inf

                        .
                        ((((((((((((((((((((((((((((( Fichiers créés 2007-11-08 to 2007-12-08 ))))))))))))))))))))))))))))))))))))
                        .

                        2007-12-08 14:19 . 2007-12-08 14:19 <REP> d-------- C:\Program Files\PowerISO
                        2007-12-08 12:30 . 2007-12-08 12:30 <REP> d-------- C:\Program Files\test.exe
                        2007-12-08 12:29 . 2007-12-08 12:29 <REP> d-------- C:\Program Files\Trend Micro
                        2007-12-08 10:47 . 2007-12-08 10:47 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Media Player Classic
                        2007-12-08 10:33 . 2007-12-08 10:36 <REP> d-------- C:\Program Files\a-squared FreeTROJAN
                        2007-12-08 10:27 . 2007-12-08 10:27 6,479,600 --a------ C:\Users\bizoux\sunbelt-personal-firewall.exe
                        2007-12-08 10:06 . 2007-12-08 12:24 <REP> d-------- C:\Program Files\Navilog1
                        2007-12-08 10:04 . 2007-12-08 10:04 557,992 --a------ C:\Users\bizoux\Navilog1.exe
                        2007-12-02 20:17 . 2007-12-02 20:22 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Winamp
                        2007-12-02 20:17 . 2007-12-02 20:18 <REP> d-------- C:\Program Files\Winamp
                        2007-12-02 20:17 . 2007-03-08 00:51 129,784 --------- C:\Windows\System32\pxafs.dll
                        2007-11-30 20:44 . 2007-11-30 20:44 <REP> d-------- C:\Users\bizoux\AppData\Roaming\eSobi
                        2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\Users\All Users\LightScribe
                        2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\ProgramData\LightScribe
                        2007-11-24 19:40 . 2007-09-06 12:00 95,608 --a------ C:\Windows\System32\AvastSS.scr
                        2007-11-24 19:40 . 2007-09-06 12:02 42,912 --a------ C:\Windows\System32\drivers\aswTdi.sys
                        2007-11-24 19:40 . 2007-09-06 12:03 23,152 --a------ C:\Windows\System32\drivers\aswRdr.sys
                        2007-11-24 19:39 . 2007-11-24 19:39 <REP> d-------- C:\Program Files\Alwil Software
                        2007-11-24 19:39 . 2007-09-06 12:09 801,144 --a------ C:\Windows\System32\aswBoot.exe
                        2007-11-24 19:39 . 2004-01-09 11:13 380,928 --a------ C:\Windows\System32\actskin4.ocx
                        2007-11-24 19:39 . 2007-09-06 12:02 45,648 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
                        2007-11-24 17:06 . 2006-10-05 03:42 2,560 --------- C:\Windows\System32\drivers\cdralw2k.sys
                        2007-11-24 17:06 . 2006-10-05 03:42 2,432 --------- C:\Windows\System32\drivers\cdr4_xp.sys
                        2007-11-24 17:05 . 2007-11-24 17:06 <REP> d-------- C:\Program Files\Picasa2
                        2007-11-24 17:05 . 2007-11-24 17:05 <REP> d-------- C:\Program Files\Google
                        2007-11-24 16:29 . 2007-11-24 17:25 <REP> d-------- C:\Program Files\BitComet
                        2007-11-24 16:26 . 2007-11-24 16:26 <REP> d-------- C:\Program Files\CCleaner
                        2007-11-24 16:25 . 2007-11-24 16:25 <REP> d-------- C:\Program Files\RegCleaner
                        2007-11-22 22:08 . 2007-11-22 22:10 <REP> d-------- C:\Program Files\Spyware-Secure
                        2007-11-19 19:50 . 2007-11-19 19:50 <REP> d-------- C:\Program Files\ARCHPR
                        2007-11-19 19:50 . 2007-11-19 19:53 1,201 --a------ C:\Windows\ARCHPR.INI
                        2007-11-19 19:30 . 2007-11-19 19:30 <REP> d-------- C:\HiTRUSTDrive
                        2007-11-18 21:30 . 2007-11-18 21:30 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Nero
                        2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Users\All Users\Nero
                        2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\ProgramData\Nero
                        2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Program Files\Nero
                        2007-11-18 21:21 . 2007-11-18 21:25 <REP> d-------- C:\Program Files\Common Files\Nero
                        2007-11-17 13:14 . 2006-04-05 02:05 73,216 --a------ C:\Windows\System32\E_FLBBVE.DLL
                        2007-11-17 13:14 . 2005-04-11 02:01 62,976 --a------ C:\Windows\System32\E_FD4BBVE.DLL
                        2007-11-17 13:10 . 2004-09-10 20:12 49,152 --a------ C:\Windows\System32\E_DCINST.DLL
                        2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\Users\All Users\EPSON
                        2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\ProgramData\EPSON
                        2007-11-17 12:39 . 2007-11-17 13:15 <REP> d-------- C:\Program Files\epson
                        2007-11-17 12:39 . 2006-03-20 00:00 63,488 --a------ C:\Windows\System32\escwiad.dll
                        2007-11-17 12:39 . 2007-11-17 12:39 25 --a------ C:\Windows\CDE DX5000EFDG.ini
                        2007-11-16 22:11 . 2007-11-16 22:11 <REP> d-------- C:\Users\bizoux\AppData\Roaming\vlc
                        2007-11-16 22:04 . 2007-11-16 22:04 <REP> d-------- C:\Program Files\K-Lite Codec Pack
                        2007-11-16 22:03 . 2007-11-16 22:03 <REP> d-------- C:\Program Files\VideoLAN
                        2007-11-15 23:44 . 2007-11-15 23:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Creative
                        2007-11-15 23:41 . 2000-05-22 09:58 647,872 --------- C:\Windows\System32\Mscomct2.ocx
                        2007-11-15 23:41 . 1999-10-10 18:00 41,984 --------- C:\Windows\Ctregrun.exe
                        2007-11-15 23:40 . 2007-11-30 20:43 <REP> d-------- C:\Program Files\Audible
                        2007-11-15 23:40 . 2001-08-17 22:43 24,576 --------- C:\Windows\System32\msxml3a.dll
                        2007-11-15 23:37 . 1999-12-12 18:01 44,032 --------- C:\Windows\System32\CTSVCCDA.EXE
                        2007-11-15 23:37 . 1999-11-17 18:00 25,088 --------- C:\Windows\System32\CTSVCCTL.EXE
                        2007-11-15 23:36 . 2007-11-15 23:39 <REP> d--h----- C:\Program Files\Creative Installation Information
                        2007-11-15 23:36 . 2007-11-15 23:36 <REP> d-------- C:\Program Files\Common Files\Creative
                        2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\Users\All Users\Creative
                        2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\ProgramData\Creative
                        2007-11-15 23:33 . 2007-11-15 23:41 <REP> d-------- C:\Program Files\Creative
                        2007-11-15 23:24 . 2007-11-15 23:24 <REP> d-------- C:\Users\bizoux\AppData\Roaming\CyberLink
                        2007-11-14 22:45 . 2007-11-14 22:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\AdobeUM
                        2007-11-14 21:59 . 2007-12-08 22:57 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Azureus
                        2007-11-14 21:53 . 2007-09-24 23:31 69,632 --a------ C:\Windows\System32\javacpl.cpl
                        2007-11-14 21:52 . 2007-11-14 21:53 <REP> d-------- C:\Program Files\Java
                        2007-11-14 21:51 . 2007-11-14 21:51 <REP> d-------- C:\Program Files\Common Files\Java
                        2007-11-14 21:48 . 2007-11-14 21:48 <REP> d-------- C:\Program Files\Azureus
                        2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\Users\All Users\Yahoo! Companion
                        2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\ProgramData\Yahoo! Companion
                        2007-11-14 08:25 . 2007-11-14 08:25 205,824 --a------ C:\Windows\System32\msoeacct.dll
                        2007-11-14 08:25 . 2007-11-14 08:25 87,040 --a------ C:\Windows\System32\msoert2.dll
                        2007-11-14 08:25 . 2007-11-14 08:25 39,424 --a------ C:\Windows\System32\ACCTRES.dll
                        2007-11-14 08:24 . 2007-11-14 08:24 376,320 --a------ C:\Windows\System32\winsrv.dll
                        2007-11-14 08:24 . 2007-11-14 08:24 49,664 --a------ C:\Windows\System32\csrsrv.dll
                        2007-11-14 08:22 . 2007-11-14 08:22 414,208 --a------ C:\Windows\System32\msscp.dll
                        2007-11-14 08:22 . 2007-11-14 08:22 2,048 --a------ C:\Windows\System32\tzres.dll
                        2007-11-14 08:21 . 2007-11-14 08:21 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
                        2007-11-14 08:21 . 2007-11-14 08:21 396,800 --a------ C:\Windows\System32\MPSSVC.dll
                        2007-11-14 08:21 . 2007-11-14 08:21 392,192 --a------ C:\Windows\System32\FirewallAPI.dll
                        2007-11-14 08:21 . 2007-11-14 08:21 178,688 --a------ C:\Windows\System32\iphlpsvc.dll
                        2007-11-14 08:21 . 2007-11-14 08:21 86,016 --a------ C:\Windows\System32\icfupgd.dll
                        2007-11-14 08:21 . 2007-11-14 08:21 63,488 --a------ C:\Windows\System32\drivers\mpsdrv.sys
                        2007-11-14 08:21 . 2007-11-14 08:21 61,952 --a------ C:\Windows\System32\cmifw.dll
                        2007-11-14 08:21 . 2007-11-14 08:21 23,040 --a------ C:\Windows\System32\drivers\tunnel.sys
                        2007-11-14 08:21 . 2007-11-14 08:21 16,896 --a------ C:\Windows\System32\wfapigp.dll
                        2007-11-14 08:21 . 2007-11-14 08:21 15,360 --a------ C:\Windows\System32\drivers\TUNMP.SYS
                        2007-11-14 08:20 . 2007-11-14 08:20 8,147,968 --a------ C:\Windows\System32\wmploc.DLL
                        2007-11-14 08:20 . 2007-11-14 08:20 1,191,936 --a------ C:\Windows\System32\msxml3.dll
                        2007-11-14 08:20 . 2007-11-14 08:20 7,680 --a------ C:\Windows\System32\spwmp.dll
                        2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\msdxm.ocx
                        2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\dxmasf.dll
                        2007-11-14 08:20 . 2007-11-14 08:20 2,048 --a------ C:\Windows\System32\msxml3r.dll
                        2007-11-14 08:19 . 2007-11-14 08:19 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
                        2007-11-14 08:17 . 2007-11-14 08:17 1,335,296 --a------ C:\Windows\System32\msxml6.dll
                        2007-11-14 08:17 . 2007-11-14 08:17 737,792 --a------ C:\Windows\System32\inetcomm.dll
                        2007-11-14 08:17 . 2007-11-14 08:17 84,480 --a------ C:\Windows\System32\INETRES.dll
                        2007-11-14 08:17 . 2007-11-14 08:17 2,048 --a------ C:\Windows\System32\msxml6r.dll
                        2007-11-14 08:16 . 2007-11-14 08:16 788,992 --a------ C:\Windows\System32\rpcrt4.dll
                        2007-11-14 08:16 . 2007-11-14 08:16 152,576 --a------ C:\Windows\System32\imagehlp.dll
                        2007-11-14 08:16 . 2007-11-14 08:16 12,800 --a------ C:\Windows\System32\drivers\fs_rec.sys

                        .
                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2007-12-08 16:45 --------- d-----w C:\ProgramData\Microsoft Help
                        2007-12-02 18:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
                        2007-12-01 18:04 --------- d-----w C:\Program Files\Common Files\NewTech Infosystems
                        2007-11-30 19:46 --------- d-----w C:\Program Files\eSobi
                        2007-11-30 19:43 --------- d-----w C:\ProgramData\eSobi
                        2007-11-18 10:28 --------- d-----w C:\Program Files\Acer Arcade Live
                        2007-11-18 10:23 --------- d-----w C:\ProgramData\CyberLink
                        2007-11-14 17:54 --------- d-----w C:\Program Files\Common Files\Symantec Shared
                        2007-11-14 17:53 --------- d-----w C:\ProgramData\Symantec
                        2007-11-14 07:31 --------- d-----w C:\Program Files\Windows Mail
                        2007-11-14 07:18 56,320 ----a-w C:\Windows\System32\iesetup.dll
                        2007-11-14 07:18 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
                        2007-11-14 07:18 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
                        2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Modèles
                        2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Menu Démarrer
                        2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Favoris
                        2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Bureau
                        2007-11-13 22:05 --------- d-sh--w C:\Program Files\Fichiers communs
                        2007-10-18 10:31 51,224 ----a-w C:\Windows\System32\sirenacm.dll
                        2007-09-28 17:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
                        2007-09-28 17:05 81,920 ----a-w C:\Windows\System32\dpl100.dll
                        2007-09-28 17:05 739,840 ----a-w C:\Windows\System32\divx.dll
                        2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
                        .

                        ((((((((((((((((((((((((((((( snapshot@2007-12-08_13.16.48,36 )))))))))))))))))))))))))))))))))))))))))
                        .
                        - 2007-12-08 11:23:34 67,584 --s-a-w C:\Windows\bootstat.dat
                        + 2007-12-08 15:13:21 67,584 --s-a-w C:\Windows\bootstat.dat
                        - 2007-12-08 11:25:11 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
                        + 2007-12-08 15:15:57 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
                        + 2007-12-08 15:15:57 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
                        - 2007-12-08 11:25:16 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
                        + 2007-12-08 15:15:52 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
                        + 2007-12-08 15:15:52 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
                        - 2007-12-08 11:24:05 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                        + 2007-12-08 19:30:29 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                        - 2007-12-08 11:24:05 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                        + 2007-12-08 19:30:29 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                        - 2007-12-08 11:24:05 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                        + 2007-12-08 19:30:29 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                        + 2007-08-07 00:15:07 33,052 ----a-w C:\Windows\System32\drivers\scdemu.sys
                        - 2007-12-08 08:57:57 103,726 ----a-w C:\Windows\System32\perfc009.dat
                        + 2007-12-08 14:06:51 103,726 ----a-w C:\Windows\System32\perfc009.dat
                        - 2007-12-08 08:57:57 117,366 ----a-w C:\Windows\System32\perfc00C.dat
                        + 2007-12-08 14:06:52 117,366 ----a-w C:\Windows\System32\perfc00C.dat
                        - 2007-12-08 08:57:57 609,944 ----a-w C:\Windows\System32\perfh009.dat
                        + 2007-12-08 14:06:52 609,944 ----a-w C:\Windows\System32\perfh009.dat
                        - 2007-12-08 08:57:58 690,594 ----a-w C:\Windows\System32\perfh00C.dat
                        + 2007-12-08 14:06:52 690,594 ----a-w C:\Windows\System32\perfh00C.dat
                        - 2007-12-08 11:25:32 6,422 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-37221999-100896607-4100886726-1000_UserData.bin
                        + 2007-12-08 15:16:56 6,462 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-37221999-100896607-4100886726-1000_UserData.bin
                        - 2007-12-08 11:25:32 52,574 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
                        + 2007-12-08 15:16:54 52,756 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
                        - 2007-12-08 11:25:31 46,522 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
                        + 2007-12-08 13:26:19 47,010 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
                        .
                        ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        REGEDIT4
                        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 13:35]
                        "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 12:04 C:\Windows\RtHDVCpl.exe]
                        "Acer Tour"="" []
                        "WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 20:48]
                        "eRecoveryService"="" []
                        "Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]
                        "Apanel"="C:\ACERSW\config\NewSetApanel.cmd" []
                        "SystrayORAHSS"="C:\Program Files\Orange HSS\Systray\SystrayApp.exe" [2007-07-24 19:55]
                        "ORAHSSSessionManager"="C:\Program Files\Orange HSS\SessionManager\SessionManager.exe" [2007-07-24 19:03]
                        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
                        "NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
                        "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 09:25]
                        "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
                        "MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 10:45]
                        "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-08-07 01:05]

                        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                        "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
                        "Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]

                        C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
                        Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-05-06 20:28:40]
                        Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]

                        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
                        C:\Program Files\Windows Defender\MSASCui.exe -hide

                        R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys
                        R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys
                        R2 int15;int15;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
                        R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                        R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys
                        R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys
                        R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys
                        S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                        LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f46-9bf0-11dc-b961-001c252f163f}]
                        \shell\Auto\command - ufpyzntyt.exe
                        \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c596-92d8-11dc-b60e-001c252f163f}]
                        \shell\Auto\command - ufpyzntyt.exe
                        \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL K:\

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4fa-9abc-11dc-a4de-001c252f163f}]
                        \shell\Auto\command - F:\hhbgkpudh.exe
                        \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe

                        .
                        **************************************************************************

                        catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2007-12-08 22:57:19
                        Windows 6.0.6000 NTFS

                        scanning hidden processes ...

                        scanning hidden autostart entries ...

                        scanning hidden files ...

                        scan completed successfully
                        hidden files: 0

                        **************************************************************************
                        .
                        Completion time: 2007-12-08 22:59:23
                        C:\ComboFix2.txt ... 2007-12-08 13:19
                        .
                        --- E O F ---
                        0
                        1. Contributeur
                          selectionne ceci

                          registry::

                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f 46-9bf0-11dc-b961-001c252f163f}]
                          \shell\Auto\command - ufpyzntyt.exe
                          \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe
                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c5 96-92d8-11dc-b60e-001c252f163f}]
                          \shell\Auto\command - ufpyzntyt.exe
                          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4 fa-9abc-11dc-a4de-001c252f163f}]
                          \shell\Auto\command - F:\hhbgkpudh.exe
                          \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe


                          * Copie le texte sélectionné (CTRL+C).
                          * Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
                          * Colle le texte copié dans ce bloc-notes (CTRL+V).
                          * Sauvegarde ce fichier sous le nom de CFScript.txt
                          * Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe
                          * Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
                          * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal!
                          Ne touche à rien tant que le scan n'est pas terminé.
                          * Une fois le scan achevé, un rapport va s'afficher : Poste son contenu.
                          * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                          @+
                          0
                          1. Contributeur
                            j'analyse ton rapport
                            et je te répond un peu plus tard
                            @+
                            0
                            1. ComboFix 07-12-08.1 - bizoux 2007-12-08 13:12:00.1 - NTFSx86
                              Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.116 [GMT 1:00]
                              Running from: C:\Users\bizoux\Desktop\ComboFix.exe
                              * Created a new restore point
                              .

                              ((((((((((((((((((((((((((((( Fichiers créés 2007-11-08 to 2007-12-08 ))))))))))))))))))))))))))))))))))))
                              .

                              2007-12-08 12:30 . 2007-12-08 12:30 <REP> d-------- C:\Program Files\test.exe
                              2007-12-08 12:29 . 2007-12-08 12:29 <REP> d-------- C:\Program Files\Trend Micro
                              2007-12-08 10:47 . 2007-12-08 10:47 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Media Player Classic
                              2007-12-08 10:33 . 2007-12-08 10:36 <REP> d-------- C:\Program Files\a-squared FreeTROJAN
                              2007-12-08 10:27 . 2007-12-08 10:27 6,479,600 --a------ C:\Users\bizoux\sunbelt-personal-firewall.exe
                              2007-12-08 10:06 . 2007-12-08 12:24 <REP> d-------- C:\Program Files\Navilog1
                              2007-12-08 10:04 . 2007-12-08 10:04 557,992 --a------ C:\Users\bizoux\Navilog1.exe
                              2007-12-02 20:17 . 2007-12-02 20:22 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Winamp
                              2007-12-02 20:17 . 2007-12-02 20:18 <REP> d-------- C:\Program Files\Winamp
                              2007-12-02 20:17 . 2007-03-08 00:51 129,784 --------- C:\Windows\System32\pxafs.dll
                              2007-11-30 20:44 . 2007-11-30 20:44 <REP> d-------- C:\Users\bizoux\AppData\Roaming\eSobi
                              2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\Users\All Users\LightScribe
                              2007-11-25 14:54 . 2007-11-25 14:54 <REP> d-------- C:\ProgramData\LightScribe
                              2007-11-24 19:40 . 2007-09-06 12:00 95,608 --a------ C:\Windows\System32\AvastSS.scr
                              2007-11-24 19:40 . 2007-09-06 12:02 42,912 --a------ C:\Windows\System32\drivers\aswTdi.sys
                              2007-11-24 19:40 . 2007-09-06 12:03 23,152 --a------ C:\Windows\System32\drivers\aswRdr.sys
                              2007-11-24 19:39 . 2007-11-24 19:39 <REP> d-------- C:\Program Files\Alwil Software
                              2007-11-24 19:39 . 2007-09-06 12:09 801,144 --a------ C:\Windows\System32\aswBoot.exe
                              2007-11-24 19:39 . 2004-01-09 11:13 380,928 --a------ C:\Windows\System32\actskin4.ocx
                              2007-11-24 19:39 . 2007-09-06 12:02 45,648 --a------ C:\Windows\System32\drivers\aswMonFlt.sys
                              2007-11-24 17:06 . 2006-10-05 03:42 2,560 --------- C:\Windows\System32\drivers\cdralw2k.sys
                              2007-11-24 17:06 . 2006-10-05 03:42 2,432 --------- C:\Windows\System32\drivers\cdr4_xp.sys
                              2007-11-24 17:05 . 2007-11-24 17:06 <REP> d-------- C:\Program Files\Picasa2
                              2007-11-24 17:05 . 2007-11-24 17:05 <REP> d-------- C:\Program Files\Google
                              2007-11-24 16:29 . 2007-11-24 17:25 <REP> d-------- C:\Program Files\BitComet
                              2007-11-24 16:26 . 2007-11-24 16:26 <REP> d-------- C:\Program Files\CCleaner
                              2007-11-24 16:25 . 2007-11-24 16:25 <REP> d-------- C:\Program Files\RegCleaner
                              2007-11-22 22:08 . 2007-11-22 22:10 <REP> d-------- C:\Program Files\Spyware-Secure
                              2007-11-19 19:50 . 2007-11-19 19:50 <REP> d-------- C:\Program Files\ARCHPR
                              2007-11-19 19:50 . 2007-11-19 19:53 1,201 --a------ C:\Windows\ARCHPR.INI
                              2007-11-19 19:30 . 2007-11-19 19:30 <REP> d-------- C:\HiTRUSTDrive
                              2007-11-18 21:30 . 2007-11-18 21:30 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Nero
                              2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Users\All Users\Nero
                              2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\ProgramData\Nero
                              2007-11-18 21:21 . 2007-11-18 21:21 <REP> d-------- C:\Program Files\Nero
                              2007-11-18 21:21 . 2007-11-18 21:25 <REP> d-------- C:\Program Files\Common Files\Nero
                              2007-11-17 13:14 . 2006-04-05 02:05 73,216 --a------ C:\Windows\System32\E_FLBBVE.DLL
                              2007-11-17 13:14 . 2005-04-11 02:01 62,976 --a------ C:\Windows\System32\E_FD4BBVE.DLL
                              2007-11-17 13:10 . 2004-09-10 20:12 49,152 --a------ C:\Windows\System32\E_DCINST.DLL
                              2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\Users\All Users\EPSON
                              2007-11-17 13:08 . 2007-11-17 13:12 <REP> d-------- C:\ProgramData\EPSON
                              2007-11-17 12:39 . 2007-11-17 13:15 <REP> d-------- C:\Program Files\epson
                              2007-11-17 12:39 . 2006-03-20 00:00 63,488 --a------ C:\Windows\System32\escwiad.dll
                              2007-11-17 12:39 . 2007-11-17 12:39 25 --a------ C:\Windows\CDE DX5000EFDG.ini
                              2007-11-16 22:11 . 2007-11-16 22:11 <REP> d-------- C:\Users\bizoux\AppData\Roaming\vlc
                              2007-11-16 22:04 . 2007-11-16 22:04 <REP> d-------- C:\Program Files\K-Lite Codec Pack
                              2007-11-16 22:03 . 2007-11-16 22:03 <REP> d-------- C:\Program Files\VideoLAN
                              2007-11-15 23:44 . 2007-11-15 23:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Creative
                              2007-11-15 23:41 . 2000-05-22 09:58 647,872 --------- C:\Windows\System32\Mscomct2.ocx
                              2007-11-15 23:41 . 1999-10-10 18:00 41,984 --------- C:\Windows\Ctregrun.exe
                              2007-11-15 23:40 . 2007-11-30 20:43 <REP> d-------- C:\Program Files\Audible
                              2007-11-15 23:40 . 2001-08-17 22:43 24,576 --------- C:\Windows\System32\msxml3a.dll
                              2007-11-15 23:37 . 1999-12-12 18:01 44,032 --------- C:\Windows\System32\CTSVCCDA.EXE
                              2007-11-15 23:37 . 1999-11-17 18:00 25,088 --------- C:\Windows\System32\CTSVCCTL.EXE
                              2007-11-15 23:36 . 2007-11-15 23:39 <REP> d--h----- C:\Program Files\Creative Installation Information
                              2007-11-15 23:36 . 2007-11-15 23:36 <REP> d-------- C:\Program Files\Common Files\Creative
                              2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\Users\All Users\Creative
                              2007-11-15 23:35 . 2007-11-15 23:35 <REP> d-------- C:\ProgramData\Creative
                              2007-11-15 23:33 . 2007-11-15 23:41 <REP> d-------- C:\Program Files\Creative
                              2007-11-15 23:24 . 2007-11-15 23:24 <REP> d-------- C:\Users\bizoux\AppData\Roaming\CyberLink
                              2007-11-14 22:45 . 2007-11-14 22:45 <REP> d-------- C:\Users\bizoux\AppData\Roaming\AdobeUM
                              2007-11-14 21:59 . 2007-12-08 13:16 <REP> d-------- C:\Users\bizoux\AppData\Roaming\Azureus
                              2007-11-14 21:53 . 2007-09-24 23:31 69,632 --a------ C:\Windows\System32\javacpl.cpl
                              2007-11-14 21:52 . 2007-11-14 21:53 <REP> d-------- C:\Program Files\Java
                              2007-11-14 21:51 . 2007-11-14 21:51 <REP> d-------- C:\Program Files\Common Files\Java
                              2007-11-14 21:48 . 2007-11-14 21:48 <REP> d-------- C:\Program Files\Azureus
                              2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\Users\All Users\Yahoo! Companion
                              2007-11-14 19:53 . 2007-11-14 19:53 <REP> d-------- C:\ProgramData\Yahoo! Companion
                              2007-11-14 08:25 . 2007-11-14 08:25 205,824 --a------ C:\Windows\System32\msoeacct.dll
                              2007-11-14 08:25 . 2007-11-14 08:25 87,040 --a------ C:\Windows\System32\msoert2.dll
                              2007-11-14 08:25 . 2007-11-14 08:25 39,424 --a------ C:\Windows\System32\ACCTRES.dll
                              2007-11-14 08:24 . 2007-11-14 08:24 376,320 --a------ C:\Windows\System32\winsrv.dll
                              2007-11-14 08:24 . 2007-11-14 08:24 49,664 --a------ C:\Windows\System32\csrsrv.dll
                              2007-11-14 08:22 . 2007-11-14 08:22 414,208 --a------ C:\Windows\System32\msscp.dll
                              2007-11-14 08:22 . 2007-11-14 08:22 2,048 --a------ C:\Windows\System32\tzres.dll
                              2007-11-14 08:21 . 2007-11-14 08:21 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
                              2007-11-14 08:21 . 2007-11-14 08:21 396,800 --a------ C:\Windows\System32\MPSSVC.dll
                              2007-11-14 08:21 . 2007-11-14 08:21 392,192 --a------ C:\Windows\System32\FirewallAPI.dll
                              2007-11-14 08:21 . 2007-11-14 08:21 178,688 --a------ C:\Windows\System32\iphlpsvc.dll
                              2007-11-14 08:21 . 2007-11-14 08:21 86,016 --a------ C:\Windows\System32\icfupgd.dll
                              2007-11-14 08:21 . 2007-11-14 08:21 63,488 --a------ C:\Windows\System32\drivers\mpsdrv.sys
                              2007-11-14 08:21 . 2007-11-14 08:21 61,952 --a------ C:\Windows\System32\cmifw.dll
                              2007-11-14 08:21 . 2007-11-14 08:21 23,040 --a------ C:\Windows\System32\drivers\tunnel.sys
                              2007-11-14 08:21 . 2007-11-14 08:21 16,896 --a------ C:\Windows\System32\wfapigp.dll
                              2007-11-14 08:21 . 2007-11-14 08:21 15,360 --a------ C:\Windows\System32\drivers\TUNMP.SYS
                              2007-11-14 08:20 . 2007-11-14 08:20 8,147,968 --a------ C:\Windows\System32\wmploc.DLL
                              2007-11-14 08:20 . 2007-11-14 08:20 1,191,936 --a------ C:\Windows\System32\msxml3.dll
                              2007-11-14 08:20 . 2007-11-14 08:20 7,680 --a------ C:\Windows\System32\spwmp.dll
                              2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\msdxm.ocx
                              2007-11-14 08:20 . 2007-11-14 08:20 4,096 --a------ C:\Windows\System32\dxmasf.dll
                              2007-11-14 08:20 . 2007-11-14 08:20 2,048 --a------ C:\Windows\System32\msxml3r.dll
                              2007-11-14 08:19 . 2007-11-14 08:19 1,383,424 --a------ C:\Windows\System32\mshtml.tlb
                              2007-11-14 08:17 . 2007-11-14 08:17 1,335,296 --a------ C:\Windows\System32\msxml6.dll
                              2007-11-14 08:17 . 2007-11-14 08:17 737,792 --a------ C:\Windows\System32\inetcomm.dll
                              2007-11-14 08:17 . 2007-11-14 08:17 84,480 --a------ C:\Windows\System32\INETRES.dll
                              2007-11-14 08:17 . 2007-11-14 08:17 2,048 --a------ C:\Windows\System32\msxml6r.dll
                              2007-11-14 08:16 . 2007-11-14 08:16 788,992 --a------ C:\Windows\System32\rpcrt4.dll
                              2007-11-14 08:16 . 2007-11-14 08:16 152,576 --a------ C:\Windows\System32\imagehlp.dll
                              2007-11-14 08:16 . 2007-11-14 08:16 12,800 --a------ C:\Windows\System32\drivers\fs_rec.sys
                              2007-11-14 08:16 . 2007-11-14 08:16 5,120 --a------ C:\Windows\System32\wmi.dll

                              .
                              (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              2007-12-02 18:38 --------- d--h--w C:\Program Files\InstallShield Installation Information
                              2007-12-01 18:04 --------- d-----w C:\Program Files\Common Files\NewTech Infosystems
                              2007-11-30 19:46 --------- d-----w C:\Program Files\eSobi
                              2007-11-30 19:43 --------- d-----w C:\ProgramData\eSobi
                              2007-11-18 10:28 --------- d-----w C:\Program Files\Acer Arcade Live
                              2007-11-18 10:23 --------- d-----w C:\ProgramData\CyberLink
                              2007-11-14 17:54 --------- d-----w C:\Program Files\Common Files\Symantec Shared
                              2007-11-14 17:53 --------- d-----w C:\ProgramData\Symantec
                              2007-11-14 07:31 --------- d-----w C:\Program Files\Windows Mail
                              2007-11-14 07:25 --------- d-----w C:\ProgramData\Microsoft Help
                              2007-11-14 07:18 56,320 ----a-w C:\Windows\System32\iesetup.dll
                              2007-11-14 07:18 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
                              2007-11-14 07:18 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
                              2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Modèles
                              2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Menu Démarrer
                              2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Favoris
                              2007-11-13 22:05 --------- d-sh--w C:\ProgramData\Bureau
                              2007-11-13 22:05 --------- d-sh--w C:\Program Files\Fichiers communs
                              2007-10-18 10:31 51,224 ----a-w C:\Windows\System32\sirenacm.dll
                              2007-09-28 17:07 3,596,288 ----a-w C:\Windows\System32\qt-dx331.dll
                              2007-09-28 17:05 81,920 ----a-w C:\Windows\System32\dpl100.dll
                              2007-09-28 17:05 739,840 ----a-w C:\Windows\System32\divx.dll
                              2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
                              .

                              ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                              .
                              .
                              REGEDIT4
                              *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                              [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2006-11-02 13:35]
                              "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 13:35]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                              "RtHDVCpl"="RtHDVCpl.exe" [2007-03-23 12:04 C:\Windows\RtHDVCpl.exe]
                              "Acer Tour"="" []
                              "WarReg_PopUp"="C:\Acer\WR_PopUp\WarReg_PopUp.exe" [2006-11-05 20:48]
                              "eRecoveryService"="" []
                              "Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]
                              "Apanel"="C:\ACERSW\config\NewSetApanel.cmd" []
                              "SystrayORAHSS"="C:\Program Files\Orange HSS\Systray\SystrayApp.exe" [2007-07-24 19:55]
                              "ORAHSSSessionManager"="C:\Program Files\Orange HSS\SessionManager\SessionManager.exe" [2007-07-24 19:03]
                              "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
                              "NeroFilterCheck"="C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57]
                              "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-08-08 09:25]
                              "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 12:06]
                              "MSConfig"="C:\Windows\system32\msconfig.exe" [2006-11-02 10:45]

                              [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                              "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 11:35]
                              "Acer Tour Reminder"="C:\Acer\AcerTour\Reminder.exe" [2007-02-15 17:39]

                              C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
                              Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-05-06 20:28:40]
                              Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06]

                              [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
                              C:\Program Files\Windows Defender\MSASCui.exe -hide

                              R0 AtiPcie;ATI PCI Express (3GIO) Filter;C:\Windows\system32\DRIVERS\AtiPcie.sys
                              R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys
                              R2 int15;int15;\??\C:\Acer\Empowering Technology\eRecovery\int15.sys
                              R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3;C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                              R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys
                              R3 PCASp50;PCASp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCASp50.sys
                              R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys
                              S3 PCAMp50;PCAMp50 NDIS Protocol Driver;C:\Windows\system32\Drivers\PCAMp50.sys

                              [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                              LocalSystemNetworkRestricted REG_MULTI_SZ hidserv UxSms WdiSystemHost Netman trkwks AudioEndpointBuilder WUDFSvc irmon sysmain IPBusEnum dot3svc PcaSvc EMDMgmt TabletInputService wlansvc WPDBusEnum

                              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{06955f46-9bf0-11dc-b961-001c252f163f}]
                              \shell\Auto\command - ufpyzntyt.exe
                              \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL ufpyzntyt.exe

                              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c0c7c596-92d8-11dc-b60e-001c252f163f}]
                              \shell\Auto\command - ufpyzntyt.exe
                              \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL K:\

                              [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e44ef4fa-9abc-11dc-a4de-001c252f163f}]
                              \shell\Auto\command - F:\hhbgkpudh.exe
                              \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\hhbgkpudh.exe

                              *Newly Created Service* - PROCEXP90
                              voila le résultat

                              .
                              **************************************************************************

                              catchme 0.3.1331 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                              Rootkit scan 2007-12-08 13:16:12
                              Windows 6.0.6000 NTFS

                              scanning hidden processes ...

                              scanning hidden autostart entries ...

                              scanning hidden files ...

                              scan completed successfully
                              hidden files: 0

                              **************************************************************************
                              .
                              Completion time: 2007-12-08 13:19:22
                              .
                              --- E O F ---
                              0
                              1. Contributeur
                                Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                                et sauvegarde le sur ton bureau et pas ailleurs!

                                Double-clic sur combofix,
                                Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
                                0
                                • 1
                                • 2