Problemes de spyware.aidez moi !!! merci

Bonjour à tous, voila j'ai continuellement des pages internet qui apparaissent contre ma volonté et je ne sais pas comment resoudre ce probleme.
Merci le moindre conseil sera le bienvenue.
A+
Configuration: Windows XP
Internet Explorer 7.0

28 réponses

Résumé de la discussion

Une personne est confrontée à des pages internet qui s’ouvrent sans consentement sous Windows XP et Internet Explorer 7, et cherche comment résoudre ce problème et nettoyer le système. Des solutions proposées incluent l’utilisation d’outils de nettoyage comme ComboFix avec CFScript.txt, la génération et l’analyse de rapports via navilog, et l’emploi de packs tels que Clean.zip. D’autres conseils recommandent aussi d’inspecter les démarrages et les fichiers Run, de lancer des scans en mode sans échec et de partager les rapports pour orienter les manipulations. En pratique, le fil suggère une approche progressive et documentée, avec répétitions de scan et vérifications des éléments de démarrage suspects, afin d’éviter des réinfections et de stabiliser le système.

Bobot (l’IA à votre service)
  1. Contributeur
    tu as remis le rapport de avg
    il faut bitdefender
    0
    1. avg antispyware

      ---------------------------------------------------------
      AVG Anti-Spyware - Rapport d'analyse
      ---------------------------------------------------------

      + Créé à: 14:07:26 17/02/2008

      + Résultat de l'analyse:

      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP440\A0213363.exe -> Adware.AdWeb : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP459\A0225381.exe -> Backdoor.Hupigon : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP440\A0213200.exe -> Downloader.Agent.hjs : Nettoyé.
      C:\Program Files\Navilog1\Backupnavi\winsys64.exe -> Downloader.Alphabet.c : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP447\A0220712.dll -> Downloader.Small.hkd : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP447\A0220713.dll -> Downloader.Small.hkd : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP447\A0220714.dll -> Downloader.Small.hkd : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP447\A0220715.dll -> Downloader.Small.hkd : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP440\A0213372.dll -> Downloader.Zlob.fvi : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP440\A0213373.dll -> Downloader.Zlob.fvi : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP434\A0209081.dll -> Not-A-Virus.Adware.ZenoSearch : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP459\A0225383.exe -> Not-A-Virus.BadJoke.Win32.Enfin.a : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP440\A0212236.exe -> Not-A-Virus.Hoax.Win32.Renos.hx : Nettoyé.
      C:\Documents and Settings\Maxence\Cookies\maxence@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
      C:\Documents and Settings\Maxence\Cookies\maxence@atdmt[3].txt -> TrackingCookie.Atdmt : Nettoyé.
      C:\Documents and Settings\Maxence\Cookies\maxence@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
      C:\Documents and Settings\Maxence\Cookies\maxence@bluestreak[3].txt -> TrackingCookie.Bluestreak : Nettoyé.
      C:\Documents and Settings\Maxence\Cookies\maxence@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
      C:\Documents and Settings\Maxence\Cookies\maxence@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
      C:\Documents and Settings\Maxence\Cookies\maxence@statcounter[1].txt -> TrackingCookie.Statcounter : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP449\A0221811.dll -> Trojan.Dialer.yz : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP454\A0224066.dll -> Trojan.Dialer.yz : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP454\A0224067.dll -> Trojan.Dialer.yz : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP454\A0224068.dll -> Trojan.Dialer.yz : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP454\A0224069.dll -> Trojan.Dialer.yz : Nettoyé.
      C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP434\A0210139.dll -> Trojan.Obfuscated.mi : Nettoyé.

      Fin du rapport
      0
      1. Contributeur
        Bonjour
        oui surement long mais ça valait le coup ;-)

        maintenant il faut bitdefender
        surement très long aussi ;-)

        @+
        0
        1. bonjour ep44

          voila le AVG scan complet
          (tres long !!mdr)

          AVG Anti-Spyware - Rapport d'analyse
          ---------------------------------------------------------

          + Créé à: 14:07:26 17/02/2008

          + Résultat de l'analyse:

          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP440\A0213363.exe -> Adware.AdWeb : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP459\A0225381.exe -> Backdoor.Hupigon : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP440\A0213200.exe -> Downloader.Agent.hjs : Nettoyé.
          C:\Program Files\Navilog1\Backupnavi\winsys64.exe -> Downloader.Alphabet.c : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP447\A0220712.dll -> Downloader.Small.hkd : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP447\A0220713.dll -> Downloader.Small.hkd : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP447\A0220714.dll -> Downloader.Small.hkd : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP447\A0220715.dll -> Downloader.Small.hkd : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP440\A0213372.dll -> Downloader.Zlob.fvi : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP440\A0213373.dll -> Downloader.Zlob.fvi : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP434\A0209081.dll -> Not-A-Virus.Adware.ZenoSearch : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP459\A0225383.exe -> Not-A-Virus.BadJoke.Win32.Enfin.a : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP440\A0212236.exe -> Not-A-Virus.Hoax.Win32.Renos.hx : Nettoyé.
          C:\Documents and Settings\Maxence\Cookies\maxence@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
          C:\Documents and Settings\Maxence\Cookies\maxence@atdmt[3].txt -> TrackingCookie.Atdmt : Nettoyé.
          C:\Documents and Settings\Maxence\Cookies\maxence@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
          C:\Documents and Settings\Maxence\Cookies\maxence@bluestreak[3].txt -> TrackingCookie.Bluestreak : Nettoyé.
          C:\Documents and Settings\Maxence\Cookies\maxence@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
          C:\Documents and Settings\Maxence\Cookies\maxence@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
          C:\Documents and Settings\Maxence\Cookies\maxence@statcounter[1].txt -> TrackingCookie.Statcounter : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP449\A0221811.dll -> Trojan.Dialer.yz : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP454\A0224066.dll -> Trojan.Dialer.yz : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP454\A0224067.dll -> Trojan.Dialer.yz : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP454\A0224068.dll -> Trojan.Dialer.yz : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP454\A0224069.dll -> Trojan.Dialer.yz : Nettoyé.
          C:\System Volume Information\_restore{136A0B01-BE72-4E2C-A2C4-F4D9FA710B63}\RP434\A0210139.dll -> Trojan.Obfuscated.mi : Nettoyé.

          Fin du rapport
          0
          1. ok ep44 je le fais dès demain matin
            Je te remercie encore pour ta patience
            a+
            bonne nuit ;)
            0
            1. Contributeur
              bon maintenant ce que tu vas faire prend du temps
              donc il faut être patient
              ok ;-)

              Télécharge:
              http://www.grisoft.cz/filedir/inst/avgas-setup-7.5.1.43.exe AVG-AntiSpyware
              = Installer
              = Le lancer
              = Clic : Mise à jour
              ------
              = Redémarre en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
              Attention, pas d’accès à internet dans ce mode. Enregistre ou imprime les consignes.

              Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
              Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel
              -------
              = Dans ANALYSE ( en forme de loupe )
              ==> Paramètres ==> sous COMMENT REAGIR==>clic sur Actions recommandées ==>Quarantaine
              ==> Clic : Analyse complète du système
              En fin de scan ( qui est assez long)
              ==> Clic Appliquer toutes les actions <== ceci Très important
              ==> Clic Sauvegarder rapport puis Enregistrer sous et choisir bureau
              -------
              En mode normal
              colle le rapport

              ensuite fait un scan en ligne

              avec bitdefender et colle le rapport

              https://www.bitdefender.com/toolbox/

              un tuto
              http://pageperso.aol.fr/rginformatique/mapage/defender.htm
              @+
              0
              1. clean

                Script execute en mode sans echec
                Rapport clean par Malekal_morte - http://www.malekal.com
                Script execute en mode sans echec 16/02/2008 a 23:05:18,59

                Microsoft Windows XP [version 5.1.2600]

                *** Suppression des fichiers dans C:

                *** Suppression des fichiers dans C:\windows\

                *** Suppression des fichiers dans C:\windows\system32

                *** Suppression des fichiers dans C:\Program Files

                *** Suppression des clefs du registre effectuee..
                *** Fin du rapport !
                0
                1. enfin clean ;)

                  Script execute en mode sans echec
                  Rapport clean par Malekal_morte - http://www.malekal.com
                  Script execute en mode sans echec 16/02/2008 a 23:05:18,59

                  Microsoft Windows XP [version 5.1.2600]

                  *** Suppression des fichiers dans C:

                  *** Suppression des fichiers dans C:\windows\

                  *** Suppression des fichiers dans C:\windows\system32

                  *** Suppression des fichiers dans C:\Program Files

                  *** Suppression des clefs du registre effectuee..
                  *** Fin du rapport !
                  0
                  1. Nouveau combofix

                    ComboFix 08-02-15.1 - Maxence 2008-02-16 22:40:09.3 - NTFSx86
                    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.558 [GMT 1:00]
                    Endroit: C:\Documents and Settings\Maxence\Bureau\ComboFix.exe
                    Command switches used :: C:\Documents and Settings\Maxence\Bureau\CFScript.txt
                    * Création d'un nouveau point de restauration

                    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                    FILE
                    C:\windows\system32\slahdgwr.ini2
                    C:\windows\system32\srutv.bak1
                    C:\windows\system32\srutv.bak2
                    C:\windows\system32\srutv.ini2
                    .

                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    C:\windows\system32\slahdgwr.ini2
                    C:\windows\system32\srutv.bak1
                    C:\windows\system32\srutv.bak2
                    C:\windows\system32\srutv.ini2

                    .
                    ((((((((((((((((((((((((((((( Fichiers créés 2008-01-16 to 2008-02-16 ))))))))))))))))))))))))))))))))))))
                    .

                    2008-02-16 21:49 . 2008-02-16 21:49 <REP> d-------- C:\upload_moi_PC-MAXENCE
                    2008-02-16 21:48 . 2008-02-16 21:48 29,090,333 --a------ C:\upload_moi_PC-MAXENCE.tar.gz
                    2008-02-14 14:57 . 2008-02-14 14:56 691,545 --a------ C:\WINDOWS\unins000.exe
                    2008-02-14 14:57 . 2008-02-14 14:57 3,454 --a------ C:\WINDOWS\unins000.dat
                    2008-02-09 12:39 . 2008-02-09 12:39 <REP> d-------- C:\Program Files\Paint.NET

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2008-02-16 21:37 --------- d-----w C:\Program Files\Wanadoo
                    2008-02-16 21:06 --------- d-----w C:\Program Files\Navilog1
                    2008-02-16 17:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                    2008-02-10 19:55 22,328 ----a-w C:\windows\system32\drivers\PnkBstrK.sys
                    2008-02-10 19:55 103,736 ----a-w C:\windows\system32\PnkBstrB.exe
                    2008-02-10 01:29 --------- d-----w C:\Documents and Settings\Maxence\Application Data\LimeWire
                    2008-01-26 19:21 66,872 ----a-w C:\windows\system32\PnkBstrA.exe
                    2008-01-19 18:16 --------- d-----w C:\Program Files\Java
                    2008-01-12 13:17 22,328 ----a-w C:\Documents and Settings\Maxence\Application Data\PnkBstrK.sys
                    2008-01-05 22:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
                    2008-01-05 22:09 --------- d-----w C:\Program Files\Activision
                    2007-12-30 20:20 3,570 ----a-w C:\windows\system32\tmp.reg
                    2007-12-30 14:24 --------- d-----w C:\Program Files\Spyware Terminator
                    2007-12-30 14:24 --------- d-----w C:\Documents and Settings\Maxence\Application Data\Spyware Terminator
                    2007-12-30 14:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
                    2007-12-30 13:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
                    2007-12-30 13:30 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
                    2007-12-30 13:29 135,936 ----a-w C:\windows\system32\drivers\sp_rsdrv2.sys
                    2007-12-30 13:29 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Spyware Terminator
                    2007-12-27 12:43 --------- d-----w C:\Program Files\Spyware Doctor
                    2007-12-27 02:00 --------- d-----w C:\Documents and Settings\Maxence\Application Data\Grisoft
                    2007-12-27 02:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
                    2007-12-25 02:47 --------- d-----w C:\Documents and Settings\Maxence\Application Data\Media Player Classic
                    2007-12-25 02:47 --------- d-----w C:\Documents and Settings\Maxence\Application Data\DivX
                    2007-12-20 22:11 81,920 ----a-w C:\windows\system32\IEDFix.exe
                    2007-12-18 09:51 179,584 ----a-w C:\windows\system32\drivers\mrxdav.sys
                    2007-12-16 16:20 --------- d-----w C:\Program Files\Fichiers communs\Real
                    2007-12-09 12:05 2,162,688 ----a-w C:\Documents and Settings\Maxence\Application Data\sa3125_02_fus_eng.exe
                    2007-12-07 02:08 824,832 ----a-w C:\windows\system32\wininet.dll
                    2007-12-05 04:56 499,712 ----a-w C:\windows\system32\msvcp71.dll
                    2007-12-05 04:56 348,160 ----a-w C:\windows\system32\msvcr71.dll
                    2007-12-04 18:41 550,912 ------w C:\windows\system32\oleaut32.dll
                    2007-11-22 23:41 139,264 ----a-w C:\windows\system32\hpzjrd01.dll
                    .

                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    REGEDIT4
                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FFCFA460-55B0-4634-8907-4AED1593C246}]

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 13:50 122880]
                    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 12:49 153136]
                    "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 17:23 102400]
                    "DAEMON Tools"="D:\Bureautique\daemon tools\daemon.exe" [2007-08-16 12:24 167368]
                    "Steam"="H:\jeux videos\Counter Strike condition zero\stream\Steam.exe" [2007-12-16 09:43 1266936]
                    "SpybotSD TeaTimer"="D:\Bureautique\Spybot\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "nTrayFw"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-04-29 17:22 266240]
                    "SoundMan"="SOUNDMAN.EXE" [2004-11-15 11:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
                    "NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2004-12-06 11:06 532480]
                    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-07-16 10:09 7110656]
                    "nwiz"="nwiz.exe" [2005-07-16 10:09 1519616 C:\WINDOWS\system32\nwiz.exe]
                    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-07-16 10:09 86016]
                    "HP Software Update"="D:\Programmes\Imprimante HP PSC1500\HP Software Update\HPWuSchd2.exe" [2005-05-11 22:12 49152]
                    "Home Theater SchSvr"="C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" [2004-04-22 03:23 155648]
                    "WINCINEMAMGR"="D:\Programmes\InterVideo\Common\Bin\WinCinemaMgr.exe" [2004-04-30 03:52 200704]
                    "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 13:49 20480]
                    "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 15:55 32768]
                    "NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-09 17:53 153136]
                    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
                    "Adobe Reader Speed Launcher"="D:\Programmes\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
                    "!AVG Anti-Spyware"="D:\Bureautique\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
                    "SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-12-30 14:28 2940928]
                    "PKR Pal"="H:\jeux videos\PKR Poker\pkrpal.exe" [2008-02-09 23:54 2269800]

                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]

                    C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                    HP Digital Imaging Monitor.lnk - D:\Programmes\Imprimante HP PSC1500\Digital Imaging\bin\hpqtra08.exe [2005-05-11 22:23:26 282624]
                    InterVideo WinCinema Manager.lnk - D:\Programmes\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-04-19 14:28:17 200704]
                    WinZip Quick Pick.lnk - D:\Bureautique\WinZip\WZQKPICK.EXE [2007-04-23 15:50:59 122880]

                    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office Outlook 2003.lnk]

                    [HKLM\~\startupfolder\C:^Documents and Settings^Maxence^Menu Démarrer^Programmes^Démarrage^Xfire.lnk]

                    R1 fwdrv;Firewall Driver;C:\windows\system32\drivers\fwdrv.sys [2007-03-16 09:56]
                    R1 khips;Kerio HIPS Driver;C:\windows\system32\drivers\khips.sys [2007-03-16 09:56]
                    R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\windows\system32\drivers\sp_rsdrv2.sys [2007-12-30 14:29]
                    S3 MSControlService;Microsoft cache control;C:\windows\system32\windows []

                    .
                    **************************************************************************

                    catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2008-02-16 22:43:54
                    Windows 5.1.2600 Service Pack 2 NTFS

                    Balayage processus cachés ...

                    Balayage caché autostart entries ...

                    Balayage des fichiers cachés ...

                    Scan terminé avec succès
                    Les fichiers cachés: 0

                    **************************************************************************
                    .
                    Temps d'accomplissement: 2008-02-16 22:45:25
                    ComboFix-quarantined-files.txt 2008-02-16 21:45:19
                    ComboFix2.txt 2008-02-16 20:37:09
                    ComboFix3.txt 2008-02-16 18:31:48
                    .
                    2008-01-09 02:02:25 --- E O F ---
                    0
                    1. Contributeur
                      parfai maintenant il faut clean et combo
                      ;-)
                      0
                      1. voila navilog option 2

                        Clean Navipromo version 3.4.5 commencé le 16/02/2008 à 22:03:59,25

                        Outil exécuté depuis C:\Program Files\navilog1
                        Mise à jour le 11.02.2008 à 20h00 par IL-MAFIOSO

                        Microsoft Windows XP [version 5.1.2600]
                        Internet Explorer : 7.0.5730.13
                        Système de fichiers : NTFS

                        Mode suppression automatique
                        avec prise en charge résultats Catchme et GNS

                        *** fsbl1.txt non trouvé ***
                        (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                        *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                        * Suppression dans C:\windows\System32 *

                        * Suppression dans "C:\Documents and Settings\Maxence\locals~1\applic~1" *

                        *** Suppression dossiers dans C:\windows ***

                        *** Suppression dossiers dans C:\Program Files ***

                        *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

                        *** Suppression dossiers dans "C:\Documents and Settings\Maxence\applic~1" ***

                        *** Suppression dossiers dans "C:\Documents and Settings\Maxence\locals~1\applic~1" ***

                        *** Suppression dossiers dans "C:\Documents and Settings\Maxence\MENUDM~1\PROGRA~1" ***

                        *** Suppression dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                        *** Suppression fichiers ***

                        *** Suppression fichiers temporaires ***

                        Nettoyage contenu C:\windows\Temp effectué !
                        Nettoyage contenu C:\Documents and Settings\Maxence\locals~1\Temp effectué !

                        *** Traitement Recherche complémentaire ***
                        (Recherche fichiers spécifiques)

                        1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                        2)Recherche, création sauvegardes et suppression Heuristique :

                        * Dans C:\windows\system32 *

                        asevaypy.exe trouvé !
                        Copie asevaypy.exe réalisée avec succès !
                        asevaypy.exe supprimé !

                        bmqgkwtq.exe trouvé !
                        Copie bmqgkwtq.exe réalisée avec succès !
                        bmqgkwtq.exe supprimé !

                        btvhkkay.exe trouvé !
                        Copie btvhkkay.exe réalisée avec succès !
                        btvhkkay.exe supprimé !

                        ceqxbrmm.exe trouvé !
                        Copie ceqxbrmm.exe réalisée avec succès !
                        ceqxbrmm.exe supprimé !

                        cqxxeshj.exe trouvé !
                        Copie cqxxeshj.exe réalisée avec succès !
                        cqxxeshj.exe supprimé !

                        edsuvthh.exe trouvé !
                        Copie edsuvthh.exe réalisée avec succès !
                        edsuvthh.exe supprimé !

                        ewnbjwog.exe trouvé !
                        Copie ewnbjwog.exe réalisée avec succès !
                        ewnbjwog.exe supprimé !

                        fhvgfplh.exe trouvé !
                        Copie fhvgfplh.exe réalisée avec succès !
                        fhvgfplh.exe supprimé !

                        jogclsmm.exe trouvé !
                        Copie jogclsmm.exe réalisée avec succès !
                        jogclsmm.exe supprimé !

                        pknskoku.exe trouvé !
                        Copie pknskoku.exe réalisée avec succès !
                        pknskoku.exe supprimé !

                        sjmsyamn.exe trouvé !
                        Copie sjmsyamn.exe réalisée avec succès !
                        sjmsyamn.exe supprimé !

                        vukrfyqc.exe trouvé !
                        Copie vukrfyqc.exe réalisée avec succès !
                        vukrfyqc.exe supprimé !

                        xuqillrp.exe trouvé !
                        Copie xuqillrp.exe réalisée avec succès !
                        xuqillrp.exe supprimé !

                        * Dans "C:\Documents and Settings\Maxence\locals~1\applic~1" *

                        *** Sauvegarde du Registre vers dossier Backupnavi ***

                        sauvegarde du Registre réalisée avec succès !

                        *** Nettoyage Registre ***

                        Nettoyage Registre Ok

                        *** Certificats ***

                        Certificat Egroup absent !

                        *** Nettoyage terminé le 16/02/2008 à 22:06:55,28 ***
                        0
                        1. Contributeur
                          désolé je n'avais pas vu clean

                          tu redémarre en mode sans échec et tu le relance et tu choisis l'option 2
                          et poste le rapport
                          @+
                          0
                          1. Contributeur
                            pour navilog tu le relance et tu choisit l'option 2
                            et poste le rapport

                            ensuite on refais la manip avec combofix

                            selectionne ceci

                            File::

                            C:\windows\system32\slahdgwr.ini2
                            C:\windows\system32\srutv.bak1
                            C:\windows\system32\srutv.bak2
                            C:\windows\system32\srutv.ini2


                            * Copie le texte sélectionné (CTRL+C).
                            * Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
                            * Colle le texte copié dans ce bloc-notes (CTRL+V).
                            * Sauvegarde ce fichier sous le nom de CFScript.txt
                            * Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe
                            * Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
                            * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal!
                            Ne touche à rien tant que le scan n'est pas terminé.
                            * Une fois le scan achevé, un rapport va s'afficher : Poste son contenu.
                            * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                            pour clean tu le trouveras dans c:

                            @+
                            0
                            1. voila le dernier malekal

                              16/02/2008 a 21:48:10,34

                              *** Recherche des fichiers dans C:

                              *** Recherche des fichiers dans C:\windows\

                              *** Recherche des fichiers dans C:\windows\system32
                              C:\windows\system32\grwinsthlp.exe FOUND

                              *** Recherche des fichiers dans C:\Program Files
                              *** Fin du rapport !
                              0
                              1. voici fixnavi

                                Search Navipromo version 3.4.5 commencé le 16/02/2008 à 21:40:39,59

                                !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                                !!! Postez ce rapport sur le forum pour le faire analyser !!!
                                !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                                Outil exécuté depuis C:\Program Files\navilog1
                                Mise à jour le 11.02.2008 à 20h00 par IL-MAFIOSO

                                Microsoft Windows XP [version 5.1.2600]
                                Internet Explorer : 7.0.5730.13
                                Système de fichiers : NTFS

                                Executé en mode normal

                                *** Recherche Programmes installés ***

                                *** Recherche dossiers dans C:\windows ***

                                *** Recherche dossiers dans C:\Program Files ***

                                *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

                                *** Recherche dossiers dans "C:\Documents and Settings\Maxence\applic~1" ***

                                *** Recherche dossiers dans "C:\Documents and Settings\Maxence\locals~1\applic~1" ***

                                *** Recherche dossiers dans "C:\Documents and Settings\Maxence\MENUDM~1\PROGRA~1" ***

                                *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

                                *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                                pour + d'infos : http://www.gmer.net

                                Aucun Fichier trouvé

                                *** Recherche avec GenericNaviSearch ***
                                !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                                !!! A vérifier impérativement avant toute suppression manuelle !!!

                                * Recherche dans C:\windows\system32 *

                                * Recherche dans "C:\Documents and Settings\Maxence\locals~1\applic~1" *

                                *** Recherche fichiers ***

                                *** Recherche clés spécifiques dans le Registre ***

                                *** Module de Recherche complémentaire ***
                                (Recherche fichiers spécifiques)

                                1)Recherche nouveaux fichiers Instant Access :

                                2)Recherche Heuristique :

                                * Dans C:\windows\system32 :

                                asevaypy.exe trouvé !
                                bmqgkwtq.exe trouvé !
                                btvhkkay.exe trouvé !
                                ceqxbrmm.exe trouvé !
                                cqxxeshj.exe trouvé !
                                edsuvthh.exe trouvé !
                                ewnbjwog.exe trouvé !
                                fhvgfplh.exe trouvé !
                                jogclsmm.exe trouvé !
                                pknskoku.exe trouvé !
                                sjmsyamn.exe trouvé !
                                vukrfyqc.exe trouvé !
                                xuqillrp.exe trouvé !

                                * Dans "C:\Documents and Settings\Maxence\locals~1\applic~1" :

                                3)Recherche Certificats :

                                Certificat Egroup absent !

                                4)Recherche fichiers connus :

                                C:\windows\system32\slahdgwr.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
                                C:\windows\system32\srutv.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
                                C:\windows\system32\srutv.bak1 trouvé ! infection Vundo possible non traitée par cet outil !
                                C:\windows\system32\srutv.bak2 trouvé ! infection Vundo possible non traitée par cet outil !

                                *** Analyse terminée le 16/02/2008 à 21:44:50,87 ***
                                0
                                1. nouveau rapport combofix

                                  ComboFix 08-02-15.1 - Maxence 2008-02-16 21:31:30.2 - NTFSx86
                                  Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.517 [GMT 1:00]
                                  Endroit: C:\Documents and Settings\Maxence\Bureau\ComboFix.exe
                                  Command switches used :: C:\Documents and Settings\Maxence\Bureau\CFScript.txt
                                  * Création d'un nouveau point de restauration

                                  [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                                  .

                                  ((((((((((((((((((((((((((((( Fichiers créés 2008-01-16 to 2008-02-16 ))))))))))))))))))))))))))))))))))))
                                  .

                                  2008-02-14 14:57 . 2008-02-14 14:56 691,545 --a------ C:\WINDOWS\unins000.exe
                                  2008-02-14 14:57 . 2008-02-14 14:57 3,454 --a------ C:\WINDOWS\unins000.dat
                                  2008-02-09 12:39 . 2008-02-09 12:39 <REP> d-------- C:\Program Files\Paint.NET

                                  .
                                  (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                  .
                                  2008-02-16 18:29 --------- d-----w C:\Program Files\Wanadoo
                                  2008-02-16 17:26 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                                  2008-02-10 19:55 22,328 ----a-w C:\windows\system32\drivers\PnkBstrK.sys
                                  2008-02-10 19:55 103,736 ----a-w C:\windows\system32\PnkBstrB.exe
                                  2008-02-10 01:29 --------- d-----w C:\Documents and Settings\Maxence\Application Data\LimeWire
                                  2008-01-26 19:21 66,872 ----a-w C:\windows\system32\PnkBstrA.exe
                                  2008-01-19 18:16 --------- d-----w C:\Program Files\Java
                                  2008-01-12 13:17 22,328 ----a-w C:\Documents and Settings\Maxence\Application Data\PnkBstrK.sys
                                  2008-01-05 22:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
                                  2008-01-05 22:09 --------- d-----w C:\Program Files\Activision
                                  2007-12-30 20:20 3,570 ----a-w C:\windows\system32\tmp.reg
                                  2007-12-30 14:24 --------- d-----w C:\Program Files\Spyware Terminator
                                  2007-12-30 14:24 --------- d-----w C:\Documents and Settings\Maxence\Application Data\Spyware Terminator
                                  2007-12-30 14:24 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spyware Terminator
                                  2007-12-30 13:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
                                  2007-12-30 13:30 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
                                  2007-12-30 13:29 135,936 ----a-w C:\windows\system32\drivers\sp_rsdrv2.sys
                                  2007-12-30 13:29 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Spyware Terminator
                                  2007-12-27 12:43 --------- d-----w C:\Program Files\Spyware Doctor
                                  2007-12-27 02:00 --------- d-----w C:\Documents and Settings\Maxence\Application Data\Grisoft
                                  2007-12-27 02:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Grisoft
                                  2007-12-25 02:47 --------- d-----w C:\Documents and Settings\Maxence\Application Data\Media Player Classic
                                  2007-12-25 02:47 --------- d-----w C:\Documents and Settings\Maxence\Application Data\DivX
                                  2007-12-20 22:11 81,920 ----a-w C:\windows\system32\IEDFix.exe
                                  2007-12-18 09:51 179,584 ----a-w C:\windows\system32\drivers\mrxdav.sys
                                  2007-12-16 16:20 --------- d-----w C:\Program Files\Fichiers communs\Real
                                  2007-12-09 12:05 2,162,688 ----a-w C:\Documents and Settings\Maxence\Application Data\sa3125_02_fus_eng.exe
                                  2007-12-07 02:08 824,832 ----a-w C:\windows\system32\wininet.dll
                                  2007-12-05 04:56 499,712 ----a-w C:\windows\system32\msvcp71.dll
                                  2007-12-05 04:56 348,160 ----a-w C:\windows\system32\msvcr71.dll
                                  2007-12-04 18:41 550,912 ------w C:\windows\system32\oleaut32.dll
                                  2007-11-22 23:41 139,264 ----a-w C:\windows\system32\hpzjrd01.dll
                                  2007-11-13 09:05 1,038,715 --sh--w C:\windows\system32\slahdgwr.ini2
                                  2007-08-05 17:00 6,638 -csh--w C:\windows\system32\srutv.bak1
                                  2007-08-06 00:19 6,877 -csh--w C:\windows\system32\srutv.bak2
                                  2007-08-06 10:52 6,542 -csh--w C:\windows\system32\srutv.ini2
                                  .

                                  ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                  .
                                  .
                                  REGEDIT4
                                  *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 13:50 122880]
                                  "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 12:49 153136]
                                  "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 17:23 102400]
                                  "DAEMON Tools"="D:\Bureautique\daemon tools\daemon.exe" [2007-08-16 12:24 167368]
                                  "Steam"="H:\jeux videos\Counter Strike condition zero\stream\Steam.exe" [2007-12-16 09:43 1266936]
                                  "SpybotSD TeaTimer"="D:\Bureautique\Spybot\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "nTrayFw"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe" [2005-04-29 17:22 266240]
                                  "SoundMan"="SOUNDMAN.EXE" [2004-11-15 11:20 77824 C:\WINDOWS\SOUNDMAN.EXE]
                                  "NVIDIA nTune"="C:\Program Files\NVIDIA Corporation\nTune\\nTune.exe" [2004-12-06 11:06 532480]
                                  "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-07-16 10:09 7110656]
                                  "nwiz"="nwiz.exe" [2005-07-16 10:09 1519616 C:\WINDOWS\system32\nwiz.exe]
                                  "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-07-16 10:09 86016]
                                  "HP Software Update"="D:\Programmes\Imprimante HP PSC1500\HP Software Update\HPWuSchd2.exe" [2005-05-11 22:12 49152]
                                  "Home Theater SchSvr"="C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe" [2004-04-22 03:23 155648]
                                  "WINCINEMAMGR"="D:\Programmes\InterVideo\Common\Bin\WinCinemaMgr.exe" [2004-04-30 03:52 200704]
                                  "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 13:49 20480]
                                  "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 15:55 32768]
                                  "NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-09 17:53 153136]
                                  "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
                                  "Adobe Reader Speed Launcher"="D:\Programmes\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
                                  "!AVG Anti-Spyware"="D:\Bureautique\AVG antispyware\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
                                  "SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2007-12-30 14:28 2940928]

                                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                  "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]

                                  C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                                  HP Digital Imaging Monitor.lnk - D:\Programmes\Imprimante HP PSC1500\Digital Imaging\bin\hpqtra08.exe [2005-05-11 22:23:26 282624]
                                  InterVideo WinCinema Manager.lnk - D:\Programmes\InterVideo\Common\Bin\WinCinemaMgr.exe [2007-04-19 14:28:17 200704]
                                  WinZip Quick Pick.lnk - D:\Bureautique\WinZip\WZQKPICK.EXE [2007-04-23 15:50:59 122880]

                                  [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office Outlook 2003.lnk]

                                  [HKLM\~\startupfolder\C:^Documents and Settings^Maxence^Menu Démarrer^Programmes^Démarrage^Xfire.lnk]

                                  R1 fwdrv;Firewall Driver;C:\windows\system32\drivers\fwdrv.sys [2007-03-16 09:56]
                                  R1 khips;Kerio HIPS Driver;C:\windows\system32\drivers\khips.sys [2007-03-16 09:56]
                                  R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\windows\system32\drivers\sp_rsdrv2.sys [2007-12-30 14:29]
                                  S3 MSControlService;Microsoft cache control;C:\windows\system32\windows []

                                  .
                                  **************************************************************************

                                  catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                  Rootkit scan 2008-02-16 21:35:26
                                  Windows 5.1.2600 Service Pack 2 NTFS

                                  Balayage processus cachés ...

                                  Balayage caché autostart entries ...

                                  Balayage des fichiers cachés ...

                                  Scan terminé avec succès
                                  Les fichiers cachés: 0

                                  **************************************************************************
                                  .
                                  Temps d'accomplissement: 2008-02-16 21:37:07
                                  ComboFix-quarantined-files.txt 2008-02-16 20:37:00
                                  ComboFix2.txt 2008-02-16 18:31:48
                                  .
                                  2008-01-09 02:02:25 --- E O F ---
                                  0
                                  1. Contributeur
                                    selectionne ceci

                                    registry::

                                    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3B0692CD-14B7-4D2C-90B5-11385C22EB04}]

                                    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{76F262CF-0308-0FB4-F7A3-043266F3A47C}]

                                    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7A5565EF-A594-46E4-AF56-FE71AEAFD7D5}]

                                    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7abc5ccb-ef43-4796-b69a-c2257035f4c0}]

                                    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{975E73FC-CE62-4928-9DBE-C5C8080EE94F}]

                                    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}]

                                    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF6D94CF-0006-40AB-B3DA-F006D09B1CE9}]

                                    -[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCFA460-55B0-4634-8907-4AED1593C246}]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "CTDrive"=-
                                    "e839571c"=-
                                    "PKR Pal"=-

                                    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vturs]

                                    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winrzf32]

                                    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\xxyvttt]

                                    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ydumpjai]

                                    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bdrmbfxmhc]

                                    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bhsxvd]

                                    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uhkxefqh.exe]



                                    * Copie le texte sélectionné (CTRL+C).
                                    * Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
                                    * Colle le texte copié dans ce bloc-notes (CTRL+V).
                                    * Sauvegarde ce fichier sous le nom de CFScript.txt
                                    * Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe
                                    * Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
                                    * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal!
                                    Ne touche à rien tant que le scan n'est pas terminé.
                                    * Une fois le scan achevé, un rapport va s'afficher : Poste son contenu.
                                    * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                                    pour vérif
                                    Télécharge sur le bureau : [url=http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe]navilog.exe/url

                                    = installe le
                                    = Double-Clic navilog1 qui est sur le bureau
                                    = Appuyer sur une touche jusqu' arriver aux options
                                    = Choisir option 1 ( = taper 1 )
                                    ne pas utiliser les autres sans avis , il peut y avoir des processus légitimes

                                    le rapport se trouve dans c: fixnavi.txt

                                    tu postes ce rapport.

                                    ---------------------
                                    Télecharge http://www.malekal.com/download/clean.zip sur le bureau
                                    Dézippe sur le bureau.
                                    = ouvrir le dossier clean
                                    = clique sur le symbole roue dentée avec le nom clean
                                    = choisir l'option 1 et laisser clean travailler jusqu'à l'apparition du texte "appuyer sur une touche pour continuer"
                                    = ensuite colle le rapport

                                    @+
                                    0
                                    • 1
                                    • 2