J'ai un rootkit sur mon pc

Résolu
Bonjour,
j'ai laissé mon pc allumer cette nuit et en me levant un message est apparu sur mon écran comme quoi mon pc était infecté par un rootkit j'ai du faire plusieur analyses en rédémarrant mon pc mais je viens de voir sur internet qu'il peut toujours y etre car cacher.......

est ce que quelqu'un pourrait m'aider a y voir plus clair?..
Merci d'avance pour votre aide
Configuration: Windows XP
Internet Explorer 7.0

28 réponses

Résumé de la discussion

Une infection rootkit est signalée sur un PC Windows XP après une mise sous tension, suscitant des doutes sur une persistance cachée même après plusieurs analyses et redémarrages. Plusieurs réponses proposent des outils et méthodes variés comme HijackThis, SDFix, OTMoveIt 2, ComboFix et CFScript pour identifier, isoler et supprimer les éléments malveillants et nettoyer le système. D'autres conseils consistent à générer des rapports, réparer des entrées suspectes, nettoyer les cookies et revenir une configuration saine, tout en renforçant la sécurité et en désactivant temporairement la restauration système. Pour finir, les échanges suggèrent ensuite de supprimer les outils obsolètes, de laisser AVG et CCleaner, puis de réactiver une restauration système propre et d'améliorer durablement la sécurité.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Re,

    Un trojan comporte 2 parties : un client et un serveur. Il permet au pirate de prendre possession du pc en ouvrant un backdoor (tu en avais 2) et/ou de transformer le pc en zombi afin de mener des attaques contre des sites ou pour relayer du spam.
    Un trojan peut s'installer par visite d'un site piégé, ou plus fréquemment par des logiciels de téléchargement (Emule etc...) et par téléchargement de cracks, c'est-à-dire par des programmes qui permettent d'utiliser gratuitement et illégalement des produits payants. C'est de cette façon-là que tu as été infecté :

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Télécharger des logiciels.exe Infected: Backdoor.Win32.Hupigon.bnca
    C:\SDFix\backups\backups.zip/backups/TEMP1.ZIP/Installer-Crack-Keygen.exe


    Certains cracks véhiculent bagle, qui casse le wi-fi, détruit pare-feu et antivirus et stocke du contenu illégal sur le pc de la victime.

    Alors prudence !

    FillPCA
    0
    1. dsl encore une petite question...comment est entré ce pirate??

      merci infiniment
      0
      1. Merci beaucoup de ton aide mon pc va beaucoup mieux !!!! je vais appliquer ce que tu m'as dit mais une question !!!!

        - c'est quoi les cracks et le p2p???

        desole pas trop caler dans ces trucs !!

        et encore merci
        0
        1. Contributeur sécurité
          Re,

          Peux-tu me dire si tout est rentré dans l'ordre ?

          Ton pc était très infecté. Il était contrôlé par un pirate qui pouvait en faire ce que bon lui semble. Je te conseille fortement d'arrêter les cracks et le p2p, sinon, tu seras de nouveau infecté.

          1/
          · Télécharge Toolscleaner de A.Rothstein sur ton Bureau : http://a-rothstein.changelog.fr/TC/ToolsCleaner2.exe
          · Double-clique sur ToolsCleaner2.exe>Recherche puis Suppression,
          · Ton Bureau va disparaître. Ceci est normal.
          · S'il ne réapparait pas, fais ceci : CTRL+ALT+SUP pour faire apparaître le gestionnaire de tâches.
          Rends-toi à l'onglet Processus, clique en haut à gauche sur "Fichiers" et choisis "Exécuter". Tape "explorer" et valide. Cela te fera ré-apparaître ton Bureau.

          2/ Tu peux supprimer tous les logiciels que nous avons utilisés (Type: SmitFraufix, Blacklight, SDFix, lopxpMH, ect.....) qui traitent des infections spécifiques et qui sont mis à jour régulièrement. Il est inutile de les garder sur ton PC.
          Tu peux par contre, garder AVG Antispyware et CCleaner.
          3/ /!\ Maintenant que ton PC n'est plus infecté, désactive puis réactive ta "Restauration du système" afin de créer un point de restauration sain.
          Pour désactiver ou activer la Restauration du système, tu dois ouvrir une session Administrateur sous Windows XP.
          Désactivation:
          Cliquer droit sur le "Poste de travail" > Propriétés > onglet "Restauration du système" > cocher la case "Désactiver la Restauration du système sur tous les lecteurs"
          > Appliquer et Ok.
          Activation:
          Suivre le même chemin ; décocher la case "Désactiver la Restauration du système sur tous les lecteurs"
          > Appliquer et Ok. Redémarrer l'ordinateur.
          Comment faire pour...(lettre A): https://forum.pcastuces.com/comment_faire_pour__-f25s3902.htm

          4/ Pour améliorer la sécurité de ton PC prend quelques instants pour lire:
          Sécuriser son PC +WIFI (versions "hot" & "light"): https://forum.pcastuces.com/default.asp
          5/ Dénonce ton infection pour faire condamner les auteurs.

          Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être les plus nombreux possibles, alors rends compte de ton infection :
          - Voir les règles du forum : https://malwarecomplaints.info/
          - Après t'être enregistré à l'aide du bouton en haut se nommant "Register"
          Si tu as plus de 13 ans, choisir : "I Agree to these terms and am over or exactly 13 years of age"
          Si tu as moins, clique sur : "I Agree to these terms and am under 13 years of age"

          Tu as alors, sous forme de liste, un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).

          *** Tes infections : Backdoor.IRCBot.bci, backdoor hupigon ***
          >> https://malwarecomplaints.info/
          Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), crée un message dans le sujet Autres infections, conforme au règle du forum (âge, ville, département etc..)
          Indique aussi le nom du Forum qui t'a aidé : CCM
          6/ Tu peux marquer ton sujet comme résolu en cliquant sur le bouton.
          7/ Je te conseille enfin de défragmenter ton PC : http://www.coupdepoucepc.com/modules/news/article.php?storyid=218

          Bon surf !

          FillPCA
          0
          1. merci voila le dernier rapport jsp !!!!

            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Télécharger des logiciels.exe moved successfully.
            < EmptyTemp >
            File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
            File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DF86C9.tmp scheduled to be deleted on reboot.
            File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DF8993.tmp scheduled to be deleted on reboot.
            File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF209.tmp scheduled to be deleted on reboot.
            File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF224.tmp scheduled to be deleted on reboot.
            File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hsperfdata_ANGELIQUE VIRATELLE\3616 scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_174.dat scheduled to be deleted on reboot.
            File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
            Temp folders emptied.
            IE temp folders emptied.

            OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04152008_202425

            Files moved on Reboot...
            C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hpodvd09.log moved successfully.
            File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DF86C9.tmp not found!
            File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DF8993.tmp not found!
            File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF209.tmp not found!
            File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF224.tmp not found!
            File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hsperfdata_ANGELIQUE VIRATELLE\3616 not found!
            C:\WINDOWS\temp\Perflib_Perfdata_174.dat moved successfully.
            File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
            0
            1. Contributeur sécurité
              Re,

              * Télécharge OTMoveIt2 (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
              * Double-clique sur OTMoveIt.exe pour lancer le programme,
              * Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste List of Files/Folders to Move" :

              C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Télécharger des logiciels.exe
              EmptyTemp


              * Clique sur MoveIt! pour lancer la suppression,
              * Le résultat appraraîtra dans le cadre Results.
              * Clique sur Exit pour fermer le programme.
              * Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
              * Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.

              Edite ce rapport.

              Dis-moi comment se porte le pc et je te donne les dernières instructions.

              FillPCA
              0
              1. jsp que c'est le bon !!!

                il m'a dit qu'il y avait une erreur....

                Tuesday, April 15, 2008 7:49:37 PM
                Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
                Kaspersky Online Scanner version: 5.0.98.0
                Kaspersky Anti-Virus database last update: 15/04/2008
                Kaspersky Anti-Virus database records: 633711
                Scan Settings
                Scan using the following antivirus database standard
                Scan Archives true
                Scan Mail Bases true
                Scan Target My Computer
                C:\
                D:\
                E:\
                Scan Statistics
                Total number of scanned objects 75293
                Number of viruses found 1
                Number of infected objects 1
                Number of suspicious objects 0
                Duration of the scan process 01:42:01

                Infected Object Name Virus Name Last Action
                C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
                C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
                C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Télécharger des logiciels.exe Infected: Backdoor.Win32.Hupigon.bnca skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Cookies\index.dat Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Messenger\lacrevette29010@hotmail.com\SharingMetadata\Logs\Dfsr00005.log Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Messenger\lacrevette29010@hotmail.com\SharingMetadata\pending.dat Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Messenger\lacrevette29010@hotmail.com\SharingMetadata\Working\database_E10_D91_100D_80C7\dfsr.db Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Messenger\lacrevette29010@hotmail.com\SharingMetadata\Working\database_E10_D91_100D_80C7\fsr.log Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Messenger\lacrevette29010@hotmail.com\SharingMetadata\Working\database_E10_D91_100D_80C7\fsrtmp.log Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Messenger\lacrevette29010@hotmail.com\SharingMetadata\Working\database_E10_D91_100D_80C7\tmp.edb Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Windows Live Contacts\lacrevette29010@hotmail.com\real\members.stg Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Windows Live Contacts\lacrevette29010@hotmail.com\shadow\members.stg Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Application Data\Microsoft\Windows Media\11.0\WMSDKNSD.XML Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Historique\History.IE5\MSHist012008041420080415\index.dat Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Historique\History.IE5\MSHist012008041520080416\index.dat Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Temp\hpodvd09.log Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Temp\hsperfdata_ANGELIQUE VIRATELLE\3452 Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Temp\~DF86C9.tmp Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Temp\~DF8993.tmp Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Temp\~DFF209.tmp Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Temp\~DFF224.tmp Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\NTUSER.DAT Object is locked skipped
                C:\Documents and Settings\ANGELIQUE VIRATELLE\NtUser.dat.LOG Object is locked skipped
                C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
                C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
                C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
                C:\Documents and Settings\LocalService\Local Settings\Historique\History.IE5\index.dat Object is locked skipped
                C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
                C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
                C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
                C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
                C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
                C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
                C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
                C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\logs\starwind.2008-04-14.19-14-05.log Object is locked skipped
                C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
                C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
                C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
                C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
                C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
                C:\Program Files\Alwil Software\Avast4\DATA\report\Protection résidente.txt Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\debug.log.idx Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\error.log.idx Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\hips.log.idx Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\ids.log.idx Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\network.log.idx Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\system.log.idx Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\warning.log.idx Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log Object is locked skipped
                C:\Program Files\Sunbelt Software\Personal Firewall\logs\web.log.idx Object is locked skipped
                C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
                C:\System Volume Information\_restore{FB4B2250-333B-428F-AF39-3B5238FFA13A}\RP53\change.log Object is locked skipped
                C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
                C:\WINDOWS\SchedLgU.Txt Object is locked skipped
                C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
                C:\WINDOWS\Sti_Trace.log Object is locked skipped
                C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
                C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
                C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
                C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
                C:\WINDOWS\system32\config\default Object is locked skipped
                C:\WINDOWS\system32\config\default.LOG Object is locked skipped
                C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
                C:\WINDOWS\system32\config\SAM Object is locked skipped
                C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
                C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
                C:\WINDOWS\system32\config\SECURITY Object is locked skipped
                C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
                C:\WINDOWS\system32\config\software Object is locked skipped
                C:\WINDOWS\system32\config\software.LOG Object is locked skipped
                C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
                C:\WINDOWS\system32\config\system Object is locked skipped
                C:\WINDOWS\system32\config\system.LOG Object is locked skipped
                C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
                C:\WINDOWS\system32\drivers\sptd8221.sys Object is locked skipped
                C:\WINDOWS\system32\h323log.txt Object is locked skipped
                C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
                C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
                C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
                C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
                C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
                C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
                C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
                C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
                C:\WINDOWS\Temp\Perflib_Perfdata_174.dat Object is locked skipped
                C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
                C:\WINDOWS\wiadebug.log Object is locked skipped
                C:\WINDOWS\wiaservc.log Object is locked skipped
                C:\WINDOWS\WindowsUpdate.log Object is locked skipped
                Scan process completed.
                0
                1. oh desole je recommence !!!
                  0
                  1. Contributeur sécurité
                    Re,

                    Tu as fait un scan critical area avec Kaspersky. Il faut recommencer en choisissant "My computer".

                    FillPCA
                    0
                    1. et voici le dernier rapport du scan :

                      Tuesday, April 15, 2008 5:37:41 PM
                      Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
                      Kaspersky Online Scanner version: 5.0.98.0
                      Kaspersky Anti-Virus database last update: 15/04/2008
                      Kaspersky Anti-Virus database records: 633711
                      Scan Settings
                      Scan using the following antivirus database standard
                      Scan Archives true
                      Scan Mail Bases true
                      Scan Target Critical Areas
                      C:\WINDOWS
                      C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\
                      Scan Statistics
                      Total number of scanned objects 15983
                      Number of viruses found 0
                      Number of infected objects 0
                      Number of suspicious objects 0
                      Duration of the scan process 00:14:33

                      Infected Object Name Virus Name Last Action
                      C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
                      C:\WINDOWS\SchedLgU.Txt Object is locked skipped
                      C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
                      C:\WINDOWS\Sti_Trace.log Object is locked skipped
                      C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
                      C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
                      C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
                      C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
                      C:\WINDOWS\system32\config\default Object is locked skipped
                      C:\WINDOWS\system32\config\default.LOG Object is locked skipped
                      C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
                      C:\WINDOWS\system32\config\SAM Object is locked skipped
                      C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
                      C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
                      C:\WINDOWS\system32\config\SECURITY Object is locked skipped
                      C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
                      C:\WINDOWS\system32\config\software Object is locked skipped
                      C:\WINDOWS\system32\config\software.LOG Object is locked skipped
                      C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
                      C:\WINDOWS\system32\config\system Object is locked skipped
                      C:\WINDOWS\system32\config\system.LOG Object is locked skipped
                      C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
                      C:\WINDOWS\system32\drivers\sptd8221.sys Object is locked skipped
                      C:\WINDOWS\system32\h323log.txt Object is locked skipped
                      C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped
                      C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
                      C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
                      C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
                      C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
                      C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
                      C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
                      C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
                      C:\WINDOWS\Temp\Perflib_Perfdata_174.dat Object is locked skipped
                      C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
                      C:\WINDOWS\wiadebug.log Object is locked skipped
                      C:\WINDOWS\wiaservc.log Object is locked skipped
                      C:\WINDOWS\WindowsUpdate.log Object is locked skipped
                      C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hpodvd09.log Object is locked skipped
                      C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hsperfdata_ANGELIQUE VIRATELLE\2112 Object is locked skipped
                      C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DF86C9.tmp Object is locked skipped
                      C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DF8993.tmp Object is locked skipped
                      C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF209.tmp Object is locked skipped
                      C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF224.tmp Object is locked skipped
                      Scan process completed.
                      0
                      1. je t'ai envoyé 2 fois le meme quel nul !!!

                        voici l'autre celui d'AVG :

                        + Créé à: 16:37:10 15/04/2008

                        + Résultat de l'analyse:

                        C:\SDFix\backups\backups.zip/backups/TEMP1.ZIP/Installer-Crack-Keygen.exe -> Backdoor.IRCBot.bci : Nettoyé et sauvegardé (mise en quarantaine).
                        C:\Documents and Settings\ANGELIQUE VIRATELLE\Cookies\angelique_viratelle@247realmedia[1].txt -> TrackingCookie.247realmedia : Nettoyé.
                        C:\Documents and Settings\ANGELIQUE VIRATELLE\Cookies\angelique_viratelle@2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
                        C:\Documents and Settings\ANGELIQUE VIRATELLE\Cookies\angelique_viratelle@electronicarts.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
                        C:\Documents and Settings\ANGELIQUE VIRATELLE\Cookies\angelique_viratelle@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Nettoyé.
                        C:\Documents and Settings\ANGELIQUE VIRATELLE\Cookies\angelique_viratelle@realmedia[1].txt -> TrackingCookie.Realmedia : Nettoyé.

                        Fin du rapport
                        0
                        1. je t'envoi les 2 premiers rapport en attendant le dernier .....

                          C:\Program Files\svchosts.tbe moved successfully.
                          < EmptyTemp >
                          File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
                          File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF8F2.tmp scheduled to be deleted on reboot.
                          File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF90D.tmp scheduled to be deleted on reboot.
                          File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hsperfdata_ANGELIQUE VIRATELLE\2324 scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_174.dat scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                          Temp folders emptied.
                          IE temp folders emptied.

                          OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04152008_151840

                          Files moved on Reboot...
                          File move failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hpodvd09.log scheduled to be moved on reboot.
                          File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF8F2.tmp not found!
                          File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF90D.tmp not found!
                          File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hsperfdata_ANGELIQUE VIRATELLE\2324 not found!
                          File move failed. C:\WINDOWS\temp\Perflib_Perfdata_174.dat scheduled to be moved on reboot.
                          File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.

                          C:\Program Files\svchosts.tbe moved successfully.
                          < EmptyTemp >
                          File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hpodvd09.log scheduled to be deleted on reboot.
                          File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF8F2.tmp scheduled to be deleted on reboot.
                          File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF90D.tmp scheduled to be deleted on reboot.
                          File delete failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hsperfdata_ANGELIQUE VIRATELLE\2324 scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_174.dat scheduled to be deleted on reboot.
                          File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                          Temp folders emptied.
                          IE temp folders emptied.

                          OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 04152008_151840

                          Files moved on Reboot...
                          File move failed. C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hpodvd09.log scheduled to be moved on reboot.
                          File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF8F2.tmp not found!
                          File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\~DFF90D.tmp not found!
                          File C:\DOCUME~1\ANGELI~1\LOCALS~1\Temp\hsperfdata_ANGELIQUE VIRATELLE\2324 not found!
                          File move failed. C:\WINDOWS\temp\Perflib_Perfdata_174.dat scheduled to be moved on reboot.
                          File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot.
                          0
                          1. désole FillPCA mais ça prend du temps !!
                            0
                            1. Contributeur sécurité
                              Re,

                              OK pour smitfraud. J'ai cru à un dossier suspect dans %PROGRAMFILES%

                              1/ * Télécharge OTMoveIt2 (de Old_Timer) sur ton bureau : http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
                              * Double-clique sur OTMoveIt.exe pour lancer le programme,
                              * Copie la liste de fichiers ou de dossiers ci-dessous et colle-la dans la fenêtre du programme "Paste List of Files/Folders to Move" :

                              C:\Program Files\svchosts.tbe
                              EmptyTemp


                              * Clique sur MoveIt! pour lancer la suppression,
                              * Le résultat appraraîtra dans le cadre Results.
                              * Clique sur Exit pour fermer le programme.
                              * Poste le rapport qui est situé ici : C:\\\_OTMoveIt\MovedFiles
                              * Il te sera peut-être demandé de redémarrer ton PC. Dans ce cas, clique sur Yes.

                              2/ Télécharge Ccleaner Basic https://www.ccleaner.com/ccleaner/download

                              Ouvre Ccleaner, clique sur "lancer le nettoyage".

                              3/ Télécharge AVGantispyware : https://www.avg.com/en-ww/free-antivirus-download
                              Tu l'installes.
                              Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente.

                              Clique sur le bouton Analyse (de la barre d'outils)
                              Puis sur l'onglets Comment réagir, clique sur Actions recommandées. Sélectionne Quarantaine.
                              Reviens à l'onglet Analyse. Clique sur Analyse complète du système.
                              A la fin du scan, choisis l'option " Appliquer toutes les actions " en bas. Ensuite.
                              Clique sur "Enregistrer le rapport". Ceci génère un rapport en fichier texte qui se trouve dans le dossier Reports du dossier d'AVG Anti-Spyware.

                              4/ * Fais un scan en ligne en cliquant ici : http://assiste.com.free.fr/...
                              * Choisis Kaspersky.
                              * Tu dois réaliser le scan en utilisant Internet explorer. Une information apparait en haut, près de la barre d'état. Tu dois accepter et installer l'activeX proposé. La mise à jour de l'antivirus se lance.
                              * Réalise un scan complet du système.
                              * Sauvegarde le rapport en mode texte à l'issue du scan.

                              5/ Edite le rapport OTMoveIt, le rapport AVGantispyware et le rapport Kaspersky.

                              FillPCA

                              0
                              1. j'ai fait comme tu m'a dit et voici le rapport :

                                SmitFraudFix v2.314

                                Rapport fait à 14:45:44,12, 15/04/2008
                                Executé à partir de C:\Documents and Settings\ANGELIQUE VIRATELLE\Bureau\SmitfraudFix
                                OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                                Le type du système de fichiers est NTFS
                                Fix executé en mode normal

                                »»»»»»»»»»»»»»»»»»»»»»»» Process

                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                C:\Program Files\Bonjour\mDNSResponder.exe
                                c:\Program Files\Microsoft LifeCam\MSCamS32.exe
                                C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                                C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                                C:\WINDOWS\System32\PAStiSvc.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                                C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                                C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
                                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                C:\Program Files\QuickTime\qttask.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                C:\WINDOWS\explorer.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                C:\Program Files\Internet Explorer\iexplore.exe
                                C:\HJT.exe
                                C:\WINDOWS\system32\cmd.exe

                                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ANGELIQUE VIRATELLE

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\ANGELIQUE VIRATELLE\Application Data

                                »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ANGELI~1\Favoris

                                »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                                »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                IEDFix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                VACFix
                                Credits: Malware Analysis & Diagnostic
                                Code: S!Ri

                                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                SrchSTS.exe by S!Ri
                                Search SharedTaskScheduler's .dll

                                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                "AppInit_DLLs"=""

                                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                                !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
                                "System"=""

                                »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                Description: VIA Rhine II Fast Ethernet Adapter - Miniport d'ordonnancement de paquets
                                DNS Server Search Order: 80.58.61.250
                                DNS Server Search Order: 80.58.61.254

                                HKLM\SYSTEM\CCS\Services\Tcpip\..\{9D2D5E47-FF5A-4B5B-A606-33282365D5C4}: DhcpNameServer=80.58.61.250 80.58.61.254
                                HKLM\SYSTEM\CS1\Services\Tcpip\..\{9D2D5E47-FF5A-4B5B-A606-33282365D5C4}: DhcpNameServer=80.58.61.250 80.58.61.254
                                HKLM\SYSTEM\CS3\Services\Tcpip\..\{9D2D5E47-FF5A-4B5B-A606-33282365D5C4}: DhcpNameServer=80.58.61.250 80.58.61.254
                                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=80.58.61.250 80.58.61.254
                                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=80.58.61.250 80.58.61.254
                                HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=80.58.61.250 80.58.61.254

                                »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                                »»»»»»»»»»»»»»»»»»»»»»»» Fin
                                0
                                1. Contributeur sécurité
                                  Re,

                                  1/ Installe Hijackthis dans un dossier spécifique comme C:\HJT et non sur le Bureau.
                                  2/ Ouvre Hijackthis>"Do a scan only" et coche ceci :
                                  R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
                                  R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)


                                  Clique sur fix/réparer.

                                  3/ * Télécharger smitfraudfix (de S!Ri) sur le bureau : http://siri.urz.free.fr/Fix/SmitfraudFix.exe
                                  * Clique sur smitfraudfix.exe
                                  * Choisis l'option 1 et colle dans ta réponse le rapport généré par smitfraudfix. Ce rapport se trouve dans la fenêtre du bloc-note qui s’ouvre.
                                  * Ferme l'application en tapant sur la touche Q.

                                  4/ Edite ce rapport Smitfraudfix.

                                  FillPCA
                                  0
                                  1. voici le rapport Combofix :

                                    ComboFix 08-04-13.3 - ANGELIQUE VIRATELLE 2008-04-15 13:53:47.2 - NTFSx86
                                    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.168 [GMT 2:00]
                                    Endroit: C:\Documents and Settings\ANGELIQUE VIRATELLE\Bureau\ComboFix.exe
                                    Command switches used :: C:\Documents and Settings\ANGELIQUE VIRATELLE\Bureau\CFScript.txt
                                    * Création d'un nouveau point de restauration

                                    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                                    FILE ::
                                    C:\WINDOWS\system32\754EDB317E.sys
                                    .

                                    ((((((((((((((((((((((((((((( Fichiers créés 2008-03-15 to 2008-04-15 ))))))))))))))))))))))))))))))))))))
                                    .

                                    2008-04-14 17:36 . 2008-04-14 17:36 <REP> d----c--- C:\_OTMoveIt
                                    2008-04-14 16:01 . 2008-04-14 16:01 13,865,846 --a--c--- C:\upload_moi_ANGELIQUE.tar.gz
                                    2008-04-14 15:32 . 2008-04-14 15:32 <REP> d-------- C:\WINDOWS\ERUNT
                                    2008-04-14 15:30 . 2008-04-14 15:30 165 --a------ C:\WINDOWS\system32\drivers\fwdrv.err
                                    2008-04-14 15:27 . 2008-04-14 15:49 <REP> d----c--- C:\SDFix
                                    2008-04-10 12:01 . 2008-04-10 12:03 1,374 --a------ C:\WINDOWS\imsins.BAK
                                    2008-04-04 20:39 . 2008-04-04 20:39 <REP> d-------- C:\Program Files\Safari
                                    2008-04-04 20:29 . 2008-04-04 20:29 <REP> d-------- C:\Program Files\iPod
                                    2008-04-03 15:45 . 2008-03-29 19:31 75,856 --a------ C:\WINDOWS\system32\drivers\aswSP.sys
                                    2008-04-03 15:45 . 2008-03-29 19:35 20,560 --a------ C:\WINDOWS\system32\drivers\aswFsBlk.sys
                                    2008-03-30 13:22 . 2008-03-30 13:23 105,220 --a------ C:\WINDOWS\hpqins16.dat
                                    2008-03-30 13:19 . 2008-03-30 13:19 <REP> d-------- C:\Documents and Settings\ANGELIQUE VIRATELLE\Application Data\Image Zone Express
                                    2008-03-28 23:37 . 2008-03-28 23:37 90,112 --a------ C:\WINDOWS\system32\QuickTimeVR.qtx
                                    2008-03-28 23:37 . 2008-03-28 23:37 57,344 --a------ C:\WINDOWS\system32\QuickTime.qts
                                    2008-03-27 18:18 . 2008-03-27 18:18 0 --a------ C:\WINDOWS\hpqEmlSz.INI
                                    2008-03-27 18:11 . 2008-03-27 18:11 71,540 --a------ C:\WINDOWS\hpqins09.dat
                                    2008-03-26 13:50 . 2008-03-26 13:50 <REP> d-------- C:\Program Files\Emoticons-plus.com

                                    .
                                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2008-04-15 06:39 --------- d-----w C:\Documents and Settings\ANGELIQUE VIRATELLE\Application Data\uTorrent
                                    2008-04-09 13:19 --------- d-----w C:\Program Files\eMule
                                    2008-04-07 15:42 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
                                    2008-04-04 22:22 --------- d-----w C:\Documents and Settings\ANGELIQUE VIRATELLE\Application Data\Apple Computer
                                    2008-04-04 18:29 --------- d-----w C:\Program Files\iTunes
                                    2008-04-04 18:27 --------- d-----w C:\Program Files\QuickTime
                                    2008-03-29 17:45 1,146,232 ----a-w C:\WINDOWS\system32\aswBoot.exe
                                    2008-03-29 17:35 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
                                    2008-03-29 17:29 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
                                    2008-03-29 17:27 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
                                    2008-03-29 17:26 26,944 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
                                    2008-03-29 17:23 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
                                    2008-03-28 10:33 --------- d-----w C:\Documents and Settings\ANGELIQUE VIRATELLE\Application Data\OpenOffice.org2
                                    2008-03-27 16:12 --------- d-----w C:\Program Files\HP
                                    2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
                                    2008-03-14 15:21 --------- d-----w C:\Program Files\Pogo FR
                                    2008-03-14 15:20 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sandlot Games
                                    2008-03-13 17:42 --------- d-----w C:\Program Files\Windows Live
                                    2008-03-13 17:27 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                                    2008-03-09 22:00 --------- d--h--w C:\Program Files\InstallShield Installation Information
                                    2008-03-09 21:58 --------- d-----w C:\Program Files\MyFree Codec
                                    2008-03-09 21:50 --------- d-----w C:\Program Files\Panda Security
                                    2008-03-09 21:49 --------- d-----w C:\Program Files\RogueRemover FREE
                                    2008-03-09 19:24 37,888 ----a-w C:\WINDOWS\system32\rar.exe
                                    2008-03-09 19:08 69,689 ----a-w C:\WINDOWS\UNZIP.DLL
                                    2008-03-09 19:08 507,904 ----a-w C:\WINDOWS\TMUPDATE.DLL
                                    2008-03-09 19:08 286,720 ----a-w C:\WINDOWS\PATCH.EXE
                                    2008-03-09 19:04 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
                                    2008-03-05 19:21 --------- d-----w C:\Program Files\Java
                                    2008-03-01 12:58 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
                                    2008-02-28 11:47 --------- d-----w C:\Documents and Settings\ANGELIQUE VIRATELLE\Application Data\ma-config.com
                                    2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
                                    2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
                                    2008-02-17 12:02 --------- d-----w C:\Program Files\Windows Live Safety Center
                                    2008-01-29 10:02 107,368 ----a-w C:\WINDOWS\system32\GEARAspi.dll
                                    2008-01-19 11:42 2,516 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
                                    2006-08-27 14:38 1,015,973 -csha-r C:\Program Files\serial.tde
                                    2006-08-27 14:19 56,239 -c--a-w C:\Program Files\svchosts.tbe
                                    2005-05-11 22:36 12,288 -c--a-w C:\WINDOWS\Fonts\RandFont.dll
                                    .

                                    ((((((((((((((((((((((((((((( snapshot@2008-04-14_19.18.23.28 )))))))))))))))))))))))))))))))))))))))))
                                    .
                                    + 2008-04-14 17:14:08 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_174.dat
                                    .
                                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    REGEDIT4
                                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "msnmsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
                                    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-05-12 00:12 49152]
                                    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
                                    "AudioDeck"="C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe" [2007-08-09 16:48 528384]
                                    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
                                    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
                                    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-03-28 23:37 413696]
                                    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]

                                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

                                    C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                                    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]

                                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
                                    "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                    "WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe
                                    "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                                    "LifeCam"="c:\Program Files\Microsoft LifeCam\LifeExp.exe"
                                    "VX3000"=C:\WINDOWS\vVX3000.exe
                                    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                    "VTTimer"=VTTimer.exe

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                                    "EnableFirewall"= 0 (0x0)

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                    "%windir%\\system32\\sessmgr.exe"=
                                    "C:\\Program Files\\NetMeeting\\conf.exe"=
                                    "C:\\Program Files\\Messenger\\msmsgs.exe"=
                                    "C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
                                    "C:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
                                    "C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
                                    "C:\\Program Files\\Sunbelt Software\\Personal Firewall\\kpf4gui.exe"=
                                    "C:\\Program Files\\Telefonica\\AsistCfg71\\awcbrwsr.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                                    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                                    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                                    "C:\\Program Files\\uTorrent\\uTorrent.exe"=
                                    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                                    "C:\\Program Files\\iTunes\\iTunes.exe"=

                                    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-03-29 19:31]
                                    R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-04-26 11:21]
                                    R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-04-26 11:21]
                                    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-03-29 19:35]
                                    R2 MSCamSvc;MSCamSvc;"c:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-05-17 15:45]
                                    R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe" [2007-04-26 11:21]
                                    R2 UxTuneUp;TuneUp Extension de thème;C:\WINDOWS\System32\svchost.exe [2004-08-05 14:00]
                                    S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\DNINDIS5.SYS [2003-07-24 13:10]
                                    S3 INFUSB;INFUSB;C:\WINDOWS\system32\drivers\infusb.sys [2002-09-30 17:16]
                                    S3 TWLAN;Telsey 802.11g Wireless USB2.0 Adapter;C:\WINDOWS\system32\DRIVERS\TWLANnd5.sys []
                                    S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
                                    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 00:08]

                                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
                                    UxTuneUp

                                    .
                                    Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                                    "2008-04-14 09:48:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                                    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                                    "2008-04-15 10:00:01 C:\WINDOWS\Tasks\HPpromotions journeysoftware.job"
                                    - C:\Program Files\hp\digital imaging\bin\hp promotions\journeysoftware\HPpromo.exe
                                    "2008-02-06 22:48:34 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
                                    - C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
                                    .
                                    **************************************************************************

                                    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2008-04-15 13:58:18
                                    Windows 5.1.2600 Service Pack 2 NTFS

                                    Balayage processus cachés ...

                                    Balayage caché autostart entries ...

                                    Balayage des fichiers cachés ...

                                    Scan terminé avec succès
                                    Les fichiers cachés: 0

                                    **************************************************************************
                                    .
                                    Temps d'accomplissement: 2008-04-15 14:00:07
                                    ComboFix-quarantined-files.txt 2008-04-15 11:59:59
                                    ComboFix2.txt 2008-04-14 17:19:32

                                    Pre-Run: 89,547,149,312 octets libres
                                    Post-Run: 89,555,030,016 octets libres
                                    .
                                    2008-04-15 10:01:08 --- E O F ---

                                    et le rapport Hijackthis :

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 14:00:33, on 15/04/2008
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    C:\Program Files\Bonjour\mDNSResponder.exe
                                    c:\Program Files\Microsoft LifeCam\MSCamS32.exe
                                    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                                    C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                                    C:\WINDOWS\System32\PAStiSvc.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                                    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                                    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe
                                    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                    C:\Program Files\QuickTime\qttask.exe
                                    C:\Program Files\iTunes\iTunesHelper.exe
                                    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    C:\Program Files\iPod\bin\iPodService.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                    C:\WINDOWS\explorer.exe
                                    C:\WINDOWS\system32\notepad.exe
                                    C:\Documents and Settings\ANGELIQUE VIRATELLE\Bureau\HiJackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60327
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60327
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
                                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                    O4 - HKLM\..\Run: [AudioDeck] C:\Program Files\VIA\VIAudioi\SBADeck\ADeck.exe 1
                                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                                    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                                    O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
                                    O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
                                    O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
                                    O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab57213.cab
                                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: Pml Driver HPZ12 - Unknown owner - C:\WINDOWS\system32\HPZipm12.exe
                                    O23 - Service: Sunbelt Personal Firewall 4 (SPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                                    O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                                    O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
                                    0
                                    1. Contributeur sécurité
                                      Salut,

                                      Oui, c'est normal car il est rootkité. Il faut que tu copies/colles ce qui est en gras dans le bloc-note et que tu enregistre ce document sur ton Bureau sous le nom CFScript.txt
                                      Ensuite, tu fais un glisser-déposer comme ceci : http://img267.imageshack.us/img267/8971/cfscriptiv6.gif

                                      Edite le rapport Combofix et le rapport Hijackthis.

                                      FillPCA
                                      0
                                      1. Bonjour FillPCA desole pour hier soir mais pas eu assez de temps et la je viens de voir ton message mais je ne trouve pas le fichier 754EDB317E.sys est ce normal??
                                        0
                                        1. Contributeur sécurité
                                          Re,

                                          * Sélectionne le texte suivant :

                                          File::
                                          C:\WINDOWS\system32\754EDB317E.sys


                                          * Copie le texte sélectionné (CTRL+C).
                                          * Ouvre le bloc-note (programme>Accessoire>bloc-note).
                                          * Colle le texte copié dans ce bloc-note (CTRL+V).
                                          * Sauvegarde ce fichier sous le nom de CFScript.txt
                                          * Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe.
                                          * Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
                                          * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
                                          Ne touche à rien tant que le scan n'est pas terminé.
                                          * Une fois le scan achevé, un rapport va s'afficher: Poste son contenu.
                                          * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                                          Edite aussi un rapport Hijackthis.

                                          FillPCA
                                          0
                                          • 1
                                          • 2