Trojan.Generic.188571.

Bonjour,

depuis quelques jours, quand je navigue sur le web, des pages internet s'ouvrent toutes seules (ulla, poker, credit ...). j'ai procédé à une analyse de tout mon système avec bit-defender et il a trouvé une infection qu'il ne peut désinfecter ni déplacer : Trojan.Generic.188571.

merci de votre aide, malgré les choses gratuites sur internet je trouve pas mon bonheur pour m'en débarrasser.

rapport:

Produit BitDefender Antivirus v10
// Produit 10.2
//
// Créé le: 04/06/2008 18:23:33
//
//-----------------------------------------------------------------

Statistiques

Chemin cible: C:\
D:\
F:\
Dossiers : 10394
Fichiers : 286608
Processus Mémoire analysés : 54
Archives : 4994
Fichiers enpaquetés : 12511
Virus trouvés : 1
Fichiers infectés : 1
Processus Mémoire infectés : 0
Fichiers suspects : 0
Alertes : 0
Fichiers désinfectés : 0
Fichiers effacés : 0
Fichiers déplacés : 0
Erreurs I/O : 66
Temps d'analyse :=00:37:38
Fichiers/seconde :126

Statistiques Spywares

Registres analysés : 373
Registres infectés : 0
Cookies analysés : 29
Cookies infectés : 0
Fichiers spyware infectés : 0
Menaces Spyware détectées : 0

Définitions virus : 1256122
Plugins d'analyse : 16
Plugins archives : 42
Plug-ins décompression : 7
Plug-ins messagerie : 6
Plug-ins système : 5

Options d'analyse

Détection
[X] Analyser le secteur de boot
[X] Processus mémoire
[X] Analyser les archives
[X] Analyser les fichiers enpaquetés
[X] Analyser la messagerie

Masque fichiers
[ ] Programmes
[X] Tous les fichiers
[ ] Extensions définies par l'utilisateur:
[ ] Exclure les extensions: ;

Action

Objets infectés
[ ] Ignorer
[X] Désinfecter
[ ] Effacer
[ ] Mettre en quarantaine
[ ] Demander l'action

Seconde action
[ ] Ignorer
[ ] Effacer
[X] Mettre en quarantaine
[ ] Demander l'action

Options d'analyse
[X] Activer les alertes
[X] Activer l'heuristique
[ ] Afficher tous les fichiers dans le journal
[X] Fichier journal: C:\ProgramData\Bitdefender\Desktop\Profiles\Logs\deep_scan\1212596613.log

Options d'analyse Spyware

[X] Analyse contre les risques non-viraux
[ ] Ecarter de l'analyse les dialers et les applications
[X] Clés de registres
[X] Cookies

Résumé:

F:\Recycled\De1\I386\CABTOOL.EX_=>CABTOOL.EXE Infecté: Trojan.Generic.188571
F:\Recycled\De1\I386\CABTOOL.EX_=>CABTOOL.EXE Désinfection impossible
F:\Recycled\De1\I386\CABTOOL.EX_=>CABTOOL.EXE Déplacement impossible
Configuration: Windows Vista
Firefox 2.0.0.14

37 réponses

Résumé de la discussion

Une infection par Trojan.Generic.188571 provoque l'ouverture automatique de pages web et persiste malgré une analyse BitDefender incapable de désinfecter le fichier infecté, ce qui gêne gravement la navigation et nécessite des mesures avancées. Plusieurs intervenants recommandent d'exécuter des outils comme Navipromo et Catchme en mode sans échec pour identifier les composants indésirables et préparer une suppression efficace et de vérifier les rapports. Des conseils ajoutés orientent vers Malwarebytes pour un balayage complet, puis le nettoyage en mode sans échec, avec sauvegarde des journaux et publication des rapports pour analyse par un spécialiste. En cas de doute, les retours soulignent l'importance d'éviter la désinfection précipitée et de prendre en compte les risques pour la sécurité avant toute manipulation.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bon si tu n'as pas fixer c'est normal que ton hijackthis me donne les même truc bizare quand même que tu est toujours une infection magicControl aprés le passage de navilog et smitfraudfix tu as pour smitfraudfix bien fais le nettoyage en mode sans echec attend le retour de geoffrey5 car il n'a pas la même opproche que moi et comme c'est lui qui te suis depuis le début normal qu'il continue sinon pourrrais tu passer malwarebytes pour voir plus claire merci de poster le rapport

    Telecharge malwarebytes

    -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    Tu l´instales; le programme va se mettre automatiquement a jour.

    Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

    Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

    Puis click sur "rechercher".

    Laisse le scanner le pc...

    Si des elements on ete trouvés > click sur supprimer la selection.

    si il t´es demandé de redemarrer > click sur "yes".

    A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

    Copie et colle le rapport stp.

    ps : les rapport sont aussi rangé dans l onglet rapport/log
    1. Contributeur sécurité
      geoffrey5 bonjour, comme c'est une infection magiccontole et que navilog et smitfraudfix ont été passé je pensais que l'infection était réglé et que seul la ligne restait et en regardant à nouveau le rapport de navilog et bien il ne la même pas trouvé il en a trouvé et supprimer un autre que l'hijackthis "Scan saved at 21:43:40, on 05/06/2008" ne donnait pas dans les lignes infectées sinon ok pour une suppression manuel en mode sans echec mais il faut faire apparaitre les fichiers cachés sinon application data n'est pas accésible
      1. Contributeur sécurité
        Jacques.gache : ON NE FIX PAS LES LIGNES INFECTEES !! deuxième fois !!

        Olivinho : Tu as toujours l infection et elle ne veut vraiment pas partir..

        Vas la supprimer manuellement sur ton disque dur, voici le chemin : c:\users\oliv\appdata\local\sfzfbmym.exe

        Si tu n arrives pas à la supprimer, fais le en mode sans échec.

        Ensuite refais un hijackthis pour vérifier
        1. salut,

          le fichier que tu me dis de supprimer ne possede pas la meme extension, le fichier c'est sfzfbmym.bat (fichier de commande windows de 1Ko) et non sfzfbmym.exe .

          je le supprime quand meme.
        2. bon bah je l'ai supprimé

          rapport:

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:33:20, on 11/06/2008
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16643)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\RtHDVCpl.exe
          C:\Windows\System32\rundll32.exe
          C:\Program Files\Apoint2K\Apoint.exe
          C:\Program Files\Multimedia Card Reader\readericon10.exe
          C:\Program Files\Power Manager\PM.exe
          C:\Program Files\Hotkey Management\FuncKey.exe
          C:\Program Files\Softwin\BitDefender10\bdmcon.exe
          C:\Program Files\Softwin\BitDefender10\bdagent.exe
          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
          C:\Program Files\Apoint2K\Apntex.exe
          C:\Program Files\Internet Explorer\IEUser.exe
          C:\Windows\system32\wuauclt.exe
          C:\Windows\system32\Taskmgr.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Users\OLIV\Desktop\scan.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
          O4 - HKLM\..\Run: [readericon10] C:\Program Files\Multimedia Card Reader\readericon10.exe
          O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
          O4 - HKLM\..\Run: [FuncKey] "C:\Program Files\Hotkey Management\FuncKey.exe"
          O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [sfzfbmym] c:\users\oliv\appdata\local\sfzfbmym.exe sfzfbmym
          O4 - Startup: Lop S&D.lnk = C:\Lop SD\LopSD.cmd
          O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
          O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
        3. Contributeur sécurité
          @olivinhobonjour, si tu as fixé les lignes que je t'ai donné avant de faire la suppression manuel c'est surement pour ça que le exe est plus la
      2. Contributeur sécurité
        bonjour, si je peux me permettre tu fixes ces lignes comme expliqué fixer les lignes: http://pageperso.aol.fr/balltrap34/demohijack.htm

        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O4 - HKCU\..\Run: [sfzfbmym] c:\users\oliv\appdata\local\sfzfbmym.exe sfzfbmym
        O4 - Startup: Lop S&D.lnk = C:\Lop SD\LopSD.cmd
        O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe

        et tu me passes Ccleaner dans ses deux modes nettoyeur et registre plusieur fois jusqu'a ce qu'il ne trouve plus rien ccleaner : https://www.malekal.com/tutoriel-ccleaner/ sur la quatrième images du tutoriel pour l'installation tu ne conserves que la première case"ajouter un raccourci sur le bureau" et avant de le lancer tu vas dans options puis avancé et tu décoches "effacer uniquement les fichiers, du dossier temp de windows plus vieux que 48 heures" et une fois fini tu redémarres ton pc et tu me refais un nouveau hijackthis merci
        1. désolé absent ce weekend,

          rapport hijackthis:

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:17:50, on 08/06/2008
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16643)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Apoint2K\Apoint.exe
          C:\Program Files\Multimedia Card Reader\readericon10.exe
          C:\Program Files\Power Manager\PM.exe
          C:\Windows\System32\rundll32.exe
          C:\Program Files\Hotkey Management\FuncKey.exe
          C:\Program Files\Softwin\BitDefender10\bdmcon.exe
          C:\Program Files\Softwin\BitDefender10\bdagent.exe
          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
          C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
          C:\Program Files\Apoint2K\ApMsgFwd.exe
          C:\Program Files\Apoint2K\Apntex.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Windows\system32\wuauclt.exe
          C:\Users\OLIV\Desktop\scan.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
          O4 - HKLM\..\Run: [readericon10] C:\Program Files\Multimedia Card Reader\readericon10.exe
          O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
          O4 - HKLM\..\Run: [FuncKey] "C:\Program Files\Hotkey Management\FuncKey.exe"
          O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [sfzfbmym] c:\users\oliv\appdata\local\sfzfbmym.exe sfzfbmym
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Startup: Lop S&D.lnk = C:\Lop SD\LopSD.cmd
          O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
          O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
          O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
          O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
          1. Contributeur sécurité
            puis refais un hijackthis ( on va l avoir ce c** )
            1. Contributeur sécurité
              ok maintenant :

              Option 2 - Nettoyage :

              Redémarrer l'ordinateur en mode sans échec (tapoter F8 au boot pour obtenir le menu de démarrage).

              Double cliquer sur smitfraudfix.cmd

              Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

              A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

              Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

              Redémarrer en mode normal et poster le rapport.
              1. SmitFraudFix v2.323

                Scan done at 19:54:06,27, 06/06/2008
                Run from C:\Users\OLIV\Desktop\SmitfraudFix
                OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                The filesystem type is NTFS
                Fix run in normal mode

                »»»»»»»»»»»»»»»»»»»»»»»» Process

                C:\Windows\system32\csrss.exe
                C:\Windows\system32\wininit.exe
                C:\Windows\system32\csrss.exe
                C:\Windows\system32\services.exe
                C:\Windows\system32\lsass.exe
                C:\Windows\system32\lsm.exe
                C:\Windows\system32\winlogon.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\SLsvc.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\spoolsv.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\Dwm.exe
                C:\Windows\Explorer.EXE
                C:\Windows\system32\taskeng.exe
                C:\Windows\System32\rundll32.exe
                C:\Windows\RtHDVCpl.exe
                C:\Program Files\Apoint2K\Apoint.exe
                C:\Program Files\Multimedia Card Reader\readericon10.exe
                C:\Program Files\Power Manager\PM.exe
                C:\Program Files\Hotkey Management\FuncKey.exe
                C:\Program Files\Softwin\BitDefender10\bdagent.exe
                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                C:\Program Files\Apoint2K\ApMsgFwd.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                C:\Program Files\Apoint2K\Apntex.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\system32\svchost.exe
                C:\Windows\System32\svchost.exe
                C:\Windows\system32\SearchIndexer.exe
                C:\Windows\system32\DRIVERS\xaudio.exe
                C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                C:\Program Files\Softwin\BitDefender10\vsserv.exe
                C:\Windows\system32\taskeng.exe
                C:\Program Files\Windows Live\Messenger\usnsvc.exe
                C:\Program Files\Windows Media Player\wmpnscfg.exe
                C:\Program Files\Windows Media Player\wmpnetwk.exe
                C:\Windows\system32\conime.exe
                C:\Windows\system32\wuauclt.exe
                C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                C:\Windows\system32\SearchProtocolHost.exe
                C:\Windows\system32\SearchFilterHost.exe
                C:\Windows\system32\cmd.exe
                C:\Windows\system32\wbem\wmiprvse.exe

                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                »»»»»»»»»»»»»»»»»»»»»»»» C:\

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\OLIV

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\OLIV\Application Data

                »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\OLIV\FAVORI~1

                »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                !!!Attention, following keys are not inevitably infected!!!

                IEDFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                !!!Attention, following keys are not inevitably infected!!!

                VACFix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                !!!Attention, following keys are not inevitably infected!!!

                404Fix
                Credits: Malware Analysis & Diagnostic
                Code: S!Ri

                »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                !!!Attention, following keys are not inevitably infected!!!

                SrchSTS.exe by S!Ri
                Search SharedTaskScheduler's .dll

                »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                !!!Attention, following keys are not inevitably infected!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                "AppInit_DLLs"=""

                »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                !!!Attention, following keys are not inevitably infected!!!

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                "Userinit"="C:\\Windows\\system32\\userinit.exe,"
                "System"=""

                »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                »»»»»»»»»»»»»»»»»»»»»»»» DNS

                Description: Fujitsu Siemens Computers WLAN 802.11b/g (SiS163u)
                DNS Server Search Order: 192.168.1.1
                DNS Server Search Order: 0.0.0.0

                HKLM\SYSTEM\CCS\Services\Tcpip\..\{EF5767EE-3DB6-48AC-8D24-DBEDADD8E4E4}: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS1\Services\Tcpip\..\{EF5767EE-3DB6-48AC-8D24-DBEDADD8E4E4}: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS3\Services\Tcpip\..\{EF5767EE-3DB6-48AC-8D24-DBEDADD8E4E4}: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

                »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                »»»»»»»»»»»»»»»»»»»»»»»» End
                1. Contributeur sécurité
                  Option 1 - Recherche :

                  télécharger smitfraudfix : http://telechargement.zebulon.fr/smitfraudfix.html

                  Dézipper la totalité de l'archive smitfraudfix.zip.

                  Double cliquer sur smitfraudfix.cmd
                  Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

                  copier/coller le rapport dans la réponse.
                  1. Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 19:44:59, on 06/06/2008
                    Platform: Windows Vista (WinNT 6.00.1904)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16643)
                    Boot mode: Normal

                    Running processes:
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\System32\rundll32.exe
                    C:\Windows\RtHDVCpl.exe
                    C:\Program Files\Apoint2K\Apoint.exe
                    C:\Program Files\Multimedia Card Reader\readericon10.exe
                    C:\Program Files\Power Manager\PM.exe
                    C:\Program Files\Hotkey Management\FuncKey.exe
                    C:\Program Files\Softwin\BitDefender10\bdagent.exe
                    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                    C:\Program Files\Apoint2K\ApMsgFwd.exe
                    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                    C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                    C:\Program Files\Apoint2K\Apntex.exe
                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                    C:\Windows\system32\conime.exe
                    C:\Windows\system32\wuauclt.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Users\OLIV\Desktop\scan.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                    O4 - HKLM\..\Run: [readericon10] C:\Program Files\Multimedia Card Reader\readericon10.exe
                    O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
                    O4 - HKLM\..\Run: [FuncKey] "C:\Program Files\Hotkey Management\FuncKey.exe"
                    O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
                    O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                    O4 - HKCU\..\Run: [sfzfbmym] c:\users\oliv\appdata\local\sfzfbmym.exe sfzfbmym
                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                    O4 - Startup: Lop S&D.lnk = C:\Lop SD\LopSD.cmd
                    O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O13 - Gopher Prefix:
                    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                    O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                    O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                    O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                    O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                    1. Clean Navipromo version 3.5.8 commencé le 06/06/2008 à 19:19:24,48

                      Outil exécuté depuis C:\Program Files\navilog1
                      Session actuelle : "OLIV"

                      Mise à jour le 05.06.2008 à 18h00 par IL-MAFIOSO

                      Microsoft Windows Vista 6.0.6000
                      Internet Explorer : 7.0.6000.16643
                      Système de fichiers : NTFS

                      Mode suppression automatique
                      avec prise en charge résultats Catchme et GNS

                      [b] Nettoyage executé en mode normal sans redémarrage
                      !! Les résultats ne seront pas optimisés !! [/b]

                      *** fsbl1.txt non trouvé ***
                      (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                      *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                      * Suppression dans "C:\Windows\System32" *

                      * Suppression dans "C:\Users\OLIV\AppData\Local\Microsoft" *

                      * Suppression dans "C:\Users\OLIV\AppData\Local" *

                      *** Suppression dossiers dans "C:\Windows" ***

                      *** Suppression dossiers dans "C:\Program Files" ***

                      *** Suppression dossiers dans "C:\ProgramData" ***

                      *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                      *** Suppression dossiers dans c:\users\oliv\appdata\roaming\micros~1\windows\startm~1\programs ***

                      *** Suppression dossiers dans "C:\Users\OLIV\AppData\Local\virtualstore\Program Files" ***

                      *** Suppression dossiers dans "C:\Users\OLIV\AppData\Roaming" ***

                      *** Suppression fichiers ***

                      *** Suppression fichiers temporaires ***

                      Nettoyage contenu C:\Windows\Temp effectué !
                      Nettoyage contenu C:\Users\OLIV\AppData\Local\Temp effectué !

                      *** Traitement Recherche complémentaire ***
                      (Recherche fichiers spécifiques)

                      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                      2)Recherche, création sauvegardes et suppression Heuristique :

                      * Dans "C:\Windows\system32" *

                      * Dans "C:\Users\OLIV\AppData\Local\Microsoft" *

                      * Dans "C:\Users\OLIV\AppData\Local" *

                      *** Sauvegarde du Registre vers dossier Safebackup ***

                      sauvegarde du Registre réalisée avec succès !

                      *** Nettoyage Registre ***

                      Nettoyage Registre Ok

                      *** Certificats ***

                      Certificat Egroup absent !
                      Certificat Electronic-Group absent !
                      Certificat OOO-Favorit absent !
                      Certificat Sunny-Day-Design-Ltdt absent !

                      *** Nettoyage terminé le 06/06/2008 à 19:27:55,15 ***
                      1. Contributeur sécurité
                        ok maintenant :

                        - Double-Clic navilog1
                        - Choisir cette fois option 2 taper 2
                        note : le bureau disparaît

                        - mettre le rapport dans la réponse

                        puis refais un rapport hijackthis
                        1. voici;

                          Search Navipromo version 3.5.8 commencé le 06/06/2008 à 19:04:56,94

                          !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                          !!! Postez ce rapport sur le forum pour le faire analyser !!!
                          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                          Outil exécuté depuis C:\Program Files\navilog1
                          Session actuelle : "OLIV"

                          Mise à jour le 05.06.2008 à 18h00 par IL-MAFIOSO

                          Microsoft Windows Vista 6.0.6000
                          Internet Explorer : 7.0.6000.16643
                          Système de fichiers : NTFS

                          Recherche executé en mode normal

                          *** Recherche Programmes installés ***

                          *** Recherche dossiers dans "C:\Windows" ***

                          *** Recherche dossiers dans "C:\Program Files" ***

                          *** Recherche dossiers dans "C:\ProgramData" ***

                          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

                          *** Recherche dossiers dans "c:\users\oliv\appdata\roaming\micros~1\windows\startm~1\programs" ***

                          *** Recherche dossiers dans "C:\Users\OLIV\AppData\Local\virtualstore\Program Files" ***

                          *** Recherche dossiers dans "C:\Users\OLIV\AppData\Roaming" ***

                          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                          pour + d'infos : http://www.gmer.net

                          Aucun Fichier trouvé

                          *** Recherche avec GenericNaviSearch ***
                          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                          !!! A vérifier impérativement avant toute suppression manuelle !!!

                          * Recherche dans "C:\Windows\system32" *

                          * Recherche dans "C:\Users\OLIV\AppData\Local\Microsoft" *

                          * Recherche dans "C:\Users\OLIV\AppData\Local" *

                          *** Recherche fichiers ***

                          *** Recherche clés spécifiques dans le Registre ***

                          *** Module de Recherche complémentaire ***
                          (Recherche fichiers spécifiques)

                          1)Recherche nouveaux fichiers Instant Access :

                          2)Recherche Heuristique :

                          * Dans "C:\Windows\system32" :

                          * Dans "C:\Users\OLIV\AppData\Local\Microsoft" :

                          * Dans "C:\Users\OLIV\AppData\Local" :

                          3)Recherche Certificats :

                          Certificat Egroup absent !
                          Certificat Electronic-Group absent !
                          Certificat OOO-Favorit absent !
                          Certificat Sunny-Day-Design-Ltd absent !

                          4)Recherche fichiers connus :

                          *** Analyse terminée le 06/06/2008 à 19:15:33,43 ***
                          1. Contributeur sécurité
                            refais un navilog :

                            = taper F
                            = Appuyer sur une touche jusqu' arriver aux options
                            = Choisir Recherche ( = taper 1 )
                            ne pas utiliser les autres sans avis , il peut y avoir des processus légitimes

                            un rapport : fixnavi.txt
                            dans ==> C :
                            le copier et le coller dans la réponse
                            1. Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 18:23:48, on 06/06/2008
                              Platform: Windows Vista (WinNT 6.00.1904)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16643)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\Explorer.EXE
                              C:\Windows\RtHDVCpl.exe
                              C:\Program Files\Apoint2K\Apoint.exe
                              C:\Program Files\Multimedia Card Reader\readericon10.exe
                              C:\Program Files\Power Manager\PM.exe
                              C:\Program Files\Hotkey Management\FuncKey.exe
                              C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                              C:\Program Files\Softwin\BitDefender10\bdagent.exe
                              C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              C:\Windows\System32\rundll32.exe
                              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                              C:\Program Files\Apoint2K\ApMsgFwd.exe
                              C:\Program Files\Apoint2K\Apntex.exe
                              C:\Windows\system32\wuauclt.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                              C:\Windows\system32\SearchFilterHost.exe
                              C:\Users\OLIV\Desktop\scan.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                              O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
                              O4 - HKLM\..\Run: [readericon10] C:\Program Files\Multimedia Card Reader\readericon10.exe
                              O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
                              O4 - HKLM\..\Run: [FuncKey] "C:\Program Files\Hotkey Management\FuncKey.exe"
                              O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
                              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              O4 - HKCU\..\Run: [sfzfbmym] c:\users\oliv\appdata\local\sfzfbmym.exe sfzfbmym
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O4 - Startup: Lop S&D.lnk = C:\Lop SD\LopSD.cmd
                              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O13 - Gopher Prefix:
                              O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                              O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                              O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                              O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                              O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                              O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
                              O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                              1. Malwarebytes' Anti-Malware 1.14
                                Version de la base de données: 829

                                00:00:49 06/06/2008
                                mbam-log-6-6-2008 (00-00-49).txt

                                Type de recherche: Examen complet (C:\|D:\|)
                                Eléments examinés: 99130
                                Temps écoulé: 38 minute(s), 32 second(s)

                                Processus mémoire infecté(s): 0
                                Module(s) mémoire infecté(s): 0
                                Clé(s) du Registre infectée(s): 0
                                Valeur(s) du Registre infectée(s): 0
                                Elément(s) de données du Registre infecté(s): 0
                                Dossier(s) infecté(s): 0
                                Fichier(s) infecté(s): 0

                                Processus mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Module(s) mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Clé(s) du Registre infectée(s):
                                (Aucun élément nuisible détecté)

                                Valeur(s) du Registre infectée(s):
                                (Aucun élément nuisible détecté)

                                Elément(s) de données du Registre infecté(s):
                                (Aucun élément nuisible détecté)

                                Dossier(s) infecté(s):
                                (Aucun élément nuisible détecté)

                                Fichier(s) infecté(s):
                                (Aucun élément nuisible détecté)
                                1. Contributeur sécurité
                                  maintenant :

                                  Télécharger sur le bureau malware bytes : https://www.besttechie.com/resources/malwarebytes/

                                  = double-clic sur mbam-setup pour lancer l'installation
                                  = Installer simplement sans rien modifier
                                  = Quand le programme lancé ==> cocher Exécuter un examen complet
                                  = Clic Rechercher
                                  = Eventuellement décocher les disque à ne pas analyser
                                  = Clic Lancer l'examen
                                  = En fin de scan , si infection trouvée
                                  ==> Clic Afficher résultat
                                  = Fermer vos applications en cours
                                  = Vérifier si tout est coché et clic Supprimer la sélection

                                  un rapport s'ouvre le copier et le coller dans la réponse

                                  Puis redémarrer le pc !!

                                  Et refais un rapport hijackthis
                                  1. ok, merci. on m'avait dit qu'il ne valait pas trop cumuler plussieurs antivirus anti spyware etc .....
                                    j'ai uniquement bitdefender ativirus v10 et spybot search & destroy.

                                    le dernier rapport:

                                    ComboFix 08-06-05.3 - OLIV 2008-06-05 22:58:06.1 - NTFSx86
                                    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1414 [GMT 2:00]
                                    Endroit: C:\Users\OLIV\Desktop\ComboFix.exe
                                    * Création d'un nouveau point de restauration
                                    * Resident AV is active

                                    .
                                    [color=purple]The following files were disabled during the run:[/color]
                                    C:\Windows\system32\sockspy.dll

                                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .

                                    C:\fsc.tmp\1009078\_desktop.ini
                                    C:\fsc.tmp\1009078\Eula\_desktop.ini

                                    .
                                    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-05 to 2008-06-05 ))))))))))))))))))))))))))))))))))))
                                    .

                                    Pas de nouveau fichier cr‚‚ dans cet espace de temps

                                    .
                                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2008-06-05 21:01 --------- d-----w C:\Users\OLIV\AppData\Roaming\OpenOffice.org2
                                    2008-06-05 20:20 12,978 ----a-w C:\Users\OLIV\AppData\Roaming\nvModes.dat
                                    2008-06-05 20:18 --------- d-----w C:\Program Files\Navilog1
                                    2008-06-04 20:42 --------- d---a-w C:\ProgramData\TEMP
                                    2008-06-01 19:31 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
                                    2008-06-01 18:54 --------- d-----w C:\Program Files\Common Files\Adobe
                                    2008-06-01 18:49 --------- d-----w C:\Program Files\Spybot - Search & Destroy
                                    2008-05-22 16:45 --------- d-----w C:\ProgramData\Lavasoft
                                    2008-05-18 08:46 --------- d-----w C:\Program Files\Windows Mail
                                    2008-05-17 12:25 --------- d-----w C:\Program Files\Windows Live Safety Center
                                    2008-04-14 16:30 --------- d-----w C:\Program Files\Java
                                    2008-04-12 11:58 --------- d-----w C:\Program Files\OpenOffice.org 2.4
                                    2008-04-12 11:56 --------- d-----w C:\Program Files\Common Files\Java
                                    2008-04-10 18:43 --------- d-----w C:\Users\OLIV\AppData\Roaming\Uniblue
                                    2008-04-10 16:54 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
                                    2008-04-05 17:13 --------- d-----w C:\ProgramData\Trymedia
                                    2008-04-05 17:01 174 --sha-w C:\Program Files\desktop.ini
                                    2008-04-05 16:56 --------- d-----w C:\Program Files\Windows Sidebar
                                    2008-04-05 16:56 --------- d-----w C:\Program Files\Windows Defender
                                    2008-04-05 16:56 --------- d-----w C:\Program Files\Windows Calendar
                                    2008-04-05 14:56 70,144 ----a-w C:\Windows\system32\drivers\pacer.sys
                                    2008-04-05 14:56 619,008 ----a-w C:\Windows\system32\drivers\dxgkrnl.sys
                                    2008-04-05 14:56 61,952 ----a-w C:\Windows\system32\drivers\wanarp.sys
                                    2008-04-05 14:56 48,640 ----a-w C:\Windows\system32\drivers\ndproxy.sys
                                    2008-04-05 14:56 20,480 ----a-w C:\Windows\system32\drivers\ndistapi.sys
                                    2008-04-05 14:50 28,344 ----a-w C:\Windows\system32\drivers\battc.sys
                                    2008-04-05 14:50 258,232 ----a-w C:\Windows\system32\drivers\acpi.sys
                                    2008-04-05 14:50 20,920 ----a-w C:\Windows\system32\drivers\compbatt.sys
                                    2008-04-05 14:50 2,923,520 ----a-w C:\Windows\explorer.exe
                                    2008-04-05 14:50 14,208 ----a-w C:\Windows\system32\drivers\CmBatt.sys
                                    2008-04-05 14:48 110,080 ----a-w C:\Windows\system32\drivers\mrxdav.sys
                                    2008-04-05 14:45 54,784 ----a-w C:\Windows\system32\drivers\i8042prt.sys
                                    2008-04-05 14:45 495,160 ----a-w C:\Windows\system32\drivers\Wdf01000.sys
                                    2008-04-05 14:45 35,384 ----a-w C:\Windows\system32\drivers\WdfLdr.sys
                                    2008-04-05 14:45 35,384 ----a-w C:\Windows\system32\drivers\kbdclass.sys
                                    2008-04-05 14:45 34,360 ----a-w C:\Windows\system32\drivers\mouclass.sys
                                    2008-04-05 14:45 19,968 ----a-w C:\Windows\system32\drivers\sermouse.sys
                                    2008-04-05 14:45 15,872 ----a-w C:\Windows\system32\drivers\mouhid.sys
                                    2008-04-05 14:45 15,872 ----a-w C:\Windows\system32\drivers\kbdhid.sys
                                    2008-04-05 14:36 41,984 ----a-w C:\Windows\system32\drivers\monitor.sys
                                    2008-04-05 14:36 1,060,920 ----a-w C:\Windows\system32\drivers\ntfs.sys
                                    2008-04-05 14:32 63,488 ----a-w C:\Windows\system32\drivers\mpsdrv.sys
                                    2008-04-05 14:30 23,040 ----a-w C:\Windows\system32\drivers\tunnel.sys
                                    2008-04-05 14:30 15,360 ----a-w C:\Windows\system32\drivers\TUNMP.SYS
                                    2008-04-05 14:28 45,112 ----a-w C:\Windows\system32\drivers\pciidex.sys
                                    2008-04-05 14:28 211,000 ----a-w C:\Windows\system32\drivers\volsnap.sys
                                    2008-04-05 14:28 21,560 ----a-w C:\Windows\system32\drivers\atapi.sys
                                    2008-04-05 14:28 154,624 ----a-w C:\Windows\system32\drivers\nwifi.sys
                                    2008-04-05 14:28 15,928 ----a-w C:\Windows\system32\drivers\pciide.sys
                                    2008-04-05 14:28 109,624 ----a-w C:\Windows\system32\drivers\ataport.sys
                                    2008-04-05 14:26 803,328 ----a-w C:\Windows\system32\drivers\tcpip.sys
                                    2008-04-05 14:26 216,632 ----a-w C:\Windows\system32\drivers\netio.sys
                                    2008-04-05 14:08 53,760 ----a-w C:\Windows\system32\drivers\hdaudbus.sys
                                    2008-04-05 14:07 84,992 ----a-w C:\Windows\system32\drivers\srvnet.sys
                                    2008-04-05 14:07 58,368 ----a-w C:\Windows\system32\drivers\mrxsmb20.sys
                                    2008-04-05 14:07 130,048 ----a-w C:\Windows\system32\drivers\srv2.sys
                                    2008-04-05 14:07 101,888 ----a-w C:\Windows\system32\drivers\mrxsmb.sys
                                    2008-04-05 14:06 12,800 ----a-w C:\Windows\system32\drivers\fs_rec.sys
                                    2008-04-05 14:05 --------- d-----w C:\Program Files\MSXML 4.0
                                    2008-04-05 12:04 --------- d-----w C:\Users\OLIV\AppData\Roaming\vlc
                                    2008-04-02 21:34 169,017,245 ----a-w C:\Program Files\ChampionshipManager2008_Setup.exe
                                    2008-04-01 18:09 319,984 ----a-w C:\Windows\DIFxAPI.dll
                                    2008-03-08 04:30 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll
                                    2008-03-08 04:30 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
                                    2008-03-08 04:30 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll
                                    2008-03-08 04:30 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
                                    2008-03-08 00:22 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll
                                    .

                                    ------- Sigcheck -------

                                    .
                                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    REGEDIT4
                                    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-04-05 16:09 1232896]
                                    "WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 14:34 2159104 C:\Windows\System32\oobefldr.dll]
                                    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 11:34 5724184]
                                    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]
                                    "sfzfbmym"="c:\users\oliv\appdata\local\sfzfbmym.exe" [ ]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "NvSvc"="C:\Windows\system32\nvsvc.dll" [2006-12-10 14:47 90191]
                                    "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2006-12-10 14:47 7766016]
                                    "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2006-12-10 14:47 81920]
                                    "RtHDVCpl"="RtHDVCpl.exe" [2006-11-09 10:57 3784704 C:\Windows\RtHDVCpl.exe]
                                    "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2006-11-07 20:57 159744]
                                    "readericon10"="C:\Program Files\Multimedia Card Reader\readericon10.exe" [2006-11-17 15:00 143360]
                                    "PowerManager"="C:\Program Files\Power Manager\PM.exe" [2006-11-06 20:19 26112]
                                    "FuncKey"="C:\Program Files\Hotkey Management\FuncKey.exe" [2006-11-23 16:28 20480]
                                    "BDMCon"="C:\Program Files\Softwin\BitDefender10\bdmcon.exe" [2008-04-01 23:00 290816]
                                    "BDAgent"="C:\Program Files\Softwin\BitDefender10\bdagent.exe" [2007-03-26 15:49 69632]
                                    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
                                    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]

                                    C:\Users\OLIV\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                                    Lop S&D.lnk - C:\Lop SD\LopSD.cmd [2008-04-27 17:41:21 39836]
                                    OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe [2008-01-21 15:41:28 393216]

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                    "ConsentPromptBehaviorAdmin"= 0 (0x0)
                                    "EnableLUA"= 0 (0x0)
                                    "EnableVirtualization"= 0 (0x0)
                                    "PromptOnSecureDesktop"= 0 (0x0)

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
                                    --a------ 2006-01-12 15:40 155648 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryBooster 2 d’Uniblue ]
                                    c:\program files\uniblue\registrybooster 2\StartRegistryBooster.exe

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                                    "{DF74FD5E-3FBE-497E-A421-08772FE4F8A9}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
                                    "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

                                    R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
                                    R3 SIS163u;SiS163 USB Wireless LAN Adapter Driver;C:\Windows\system32\DRIVERS\sis163u.sys [2006-11-21 05:26]

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                                    bthsvcs REG_MULTI_SZ BthServ

                                    .
                                    **************************************************************************

                                    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2008-06-05 23:01:41
                                    Windows 6.0.6000 NTFS

                                    Balayage processus cach‚s ...

                                    Balayage cach‚ autostart entries ...

                                    Balayage des fichiers cach‚s ...

                                    Scan termin‚ avec succŠs
                                    Les fichiers cach‚s: 0

                                    **************************************************************************
                                    .
                                    --------------------- DLLs a charg‚ sous des processus courants ---------------------

                                    PROCESS: C:\Windows\Explorer.exe
                                    -> C:\Windows\system32\sockspy.dll
                                    .
                                    ------------------------ Other Running Processes ------------------------
                                    .
                                    C:\Windows\System32\audiodg.exe
                                    C:\Windows\System32\rundll32.exe
                                    C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                                    C:\Program Files\OpenOffice.org 2.4\program\soffice.bin
                                    C:\Program Files\Apoint2K\ApMsgFwd.exe
                                    C:\Program Files\Apoint2K\ApntEx.exe
                                    C:\Windows\System32\drivers\XAudio.exe
                                    C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                                    C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                                    C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                                    C:\Program Files\Softwin\BitDefender10\vsserv.exe
                                    C:\Program Files\Windows Media Player\wmpnscfg.exe
                                    C:\Program Files\Windows Media Player\wmpnetwk.exe
                                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                    C:\Windows\System32\dllhost.exe
                                    .
                                    **************************************************************************
                                    .
                                    Temps d'accomplissement: 2008-06-05 23:04:42 - machine was rebooted
                                    ComboFix-quarantined-files.txt 2008-06-05 21:04:26

                                    Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
                                    Le texte du message associ‚ au num‚ro 0x2379 est introuvable dans le fichier de messages pour Application.

                                    173 --- E O F --- 2008-05-30 16:56:14
                                    1. Contributeur sécurité
                                      télécharge aussi ces programmes ci dessous qui sont tres utiles pour un pc car j ai vu dans ton rapport que tu n es pas tres protégé contre les infections :

                                      ad-aware : https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/11643.html

                                      spybot : https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html

                                      AVG antispyware : https://www.01net.com/telecharger/

                                      Il faut faire des analyses avec chaques programmes au moins une fois par semaine

                                      et un nettoyeur de registre Ccleaner : https://www.zebulon.fr/telechargements/utilitaires/nettoyeurs/ccleaner.html
                                      • 1
                                      • 2