Problème de virus

Résolu
Bonjour,
hier soir mon pc a bug et ma mi 1 page bleue j ais redémarrer et peut après la même chose aider moi jsuis novice merci
Configuration: Windows Vista
Internet Explorer 7.0

23 réponses

Résumé de la discussion

Problème récurrent après un écran bleu sur un PC sous Windows Vista, l'utilisateur observe un redémarrage difficile et recherche des solutions adaptées à une configuration IE7. Plusieurs conseils portent sur l'analyse des rapports HijackThis pour identifier logiciels indésirables, le nettoyage des éléments de démarrage et des barres d'outils, puis l'utilisation d’un scan en ligne Kaspersky pour vérifier l’infection. En cas d'incompatibilité avec Vista ou d’outils obsolètes, plusieurs répondants suggèrent d’évaluer des désinstallations partielles et d’envisager un rétablissement du système, tout en restant prudent et sans conclure. D'autres conseils recommandent un scan en ligne via des outils spécifiques et la vérification des services et modules démarrés, afin d'éviter des infections persistantes lors des redémarrages.

Bobot (l’IA à votre service)
  1. Bonsoir,
    bravo.

    > Fais un scan en ligne avec Kaspersky : https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    N.B. : Le scan ne marche que sous Internet Explorer.
    - Commence par connecter tout ton matériel de stockage à ton PC (clés USB, DD amovible...) si possible. Allume les si necessaire.
    - Sous Démonstration en ligne, on t'explique la marche à suivre, et pour lancer le scan il faut sélectionner < Exécuter l'analyse en ligne >.
    - On va te demander de télécharger un contrôle active x, accepte .
    - Dans le menu < Choisissez la cible de l'analyse >, sélectionne < Poste de travail >. Le scan va commencer.
    - Poste le rapport qui sera généré.
    S'il y a un problème, assure toi que les contrôles active x sont bien configurés dans les options internet comme décrit sur ce lien : http://www.inoculer.com/activex.php3
    Rappel : le scan est à faire sous Internet Explorer
    Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html

    A+
    0
    1. quand j essai l analyse en ligne ça me dit que certains composant sont endommagé ou mal installer veuillez recommencer chose que je fais et ça me dis la même chose
      0
    2. je sais pas comment faire
      0
    3. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:29:42, on 28/07/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16681)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Apoint2K\Apoint.exe
      C:\Program Files\Hotkey Utility\tray.exe
      C:\Program Files\Power Manager\PM.exe
      C:\Program Files\Light Sensor Utility\Sensor.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Apoint2K\ApMsgFwd.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Windows\system32\SearchFilterHost.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2.fr/portail/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - (no file)
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
      O4 - HKLM\..\Run: [FIC HotKey] C:\Program Files\Hotkey Utility\tray.exe
      O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
      O4 - HKLM\..\Run: [Silent Mode] C:\Program Files\Light Sensor Utility\Sensor.exe
      O4 - HKLM\..\Run: [recinfo706] c:\RecInfo\RecInfo.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Crawler Search - tbr:iemenu
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
      O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
  2. Bonsoir,
    Il est où le rapport Kaspersky qu ej e te demandais ici : http://www.commentcamarche.net/forum/affich 7388603 probleme de virus#46

    ?

    A+
    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 01:11:57, on 27/07/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16681)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Apoint2K\Apoint.exe
      C:\Program Files\Hotkey Utility\tray.exe
      C:\Program Files\Power Manager\PM.exe
      C:\Program Files\Light Sensor Utility\Sensor.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Apoint2K\ApMsgFwd.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60327
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2.fr/portail/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
      O4 - HKLM\..\Run: [FIC HotKey] C:\Program Files\Hotkey Utility\tray.exe
      O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
      O4 - HKLM\..\Run: [Silent Mode] C:\Program Files\Light Sensor Utility\Sensor.exe
      O4 - HKLM\..\Run: [recinfo706] c:\RecInfo\RecInfo.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Crawler Search - tbr:iemenu
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
      O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (no file)
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O13 - Gopher Prefix:
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
      O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
      O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
      O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
    2. ComboFix 08-07-26.1 - pierre 2008-07-27 1:26:45.2 - NTFSx86
      Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1245 [GMT 2:00]
      Endroit: C:\Users\pierre\Downloads\ComboFix.exe
      * Création d'un nouveau point de restauration
      .

      ((((((((((((((((((((((((((((( Fichiers créés 2008-06-26 to 2008-07-26 ))))))))))))))))))))))))))))))))))))
      .

      2008-07-22 20:16 . 2008-07-27 00:37 <REP> d-------- C:\Program Files\WinClamAVShield
      2008-07-22 20:14 . 2008-07-26 12:16 <REP> d-------- C:\Users\All Users\Spyware Terminator
      2008-07-22 20:14 . 2008-07-26 12:16 <REP> d-------- C:\ProgramData\Spyware Terminator
      2008-07-22 20:14 . 2008-07-23 14:35 <REP> d-------- C:\Program Files\Spyware Terminator
      2008-07-22 20:14 . 2008-07-22 20:14 141,312 --a------ C:\Windows\System32\drivers\sp_rsdrv2.sys
      2008-07-22 16:16 . 2008-07-22 16:16 <REP> d-------- C:\Program Files\Sun
      2008-07-21 20:50 . 2008-07-21 20:50 <REP> d-------- C:\Program Files\Crawler
      2008-07-21 20:49 . 2008-07-26 12:16 <REP> d-------- C:\Users\pierre\AppData\Roaming\Spyware Terminator
      2008-07-17 20:28 . 2008-07-17 20:38 96,966 --a------ C:\Windows\System32\drivers\klin.dat
      2008-07-17 20:28 . 2008-07-17 20:38 88,774 --a------ C:\Windows\System32\drivers\klick.dat
      2008-07-17 20:26 . 2008-07-27 00:37 <REP> d-------- C:\Users\All Users\Kaspersky Lab
      2008-07-17 20:26 . 2008-07-27 00:37 <REP> d-------- C:\ProgramData\Kaspersky Lab
      2008-07-17 20:26 . 2008-07-17 20:26 <REP> d-------- C:\Program Files\Kaspersky Lab
      2008-07-17 20:26 . 2008-07-21 16:53 1,924,640 --ahs---- C:\Windows\System32\drivers\fidbox.dat
      2008-07-17 20:26 . 2008-07-21 16:53 262,176 --ahs---- C:\Windows\System32\drivers\fidbox2.dat
      2008-07-17 20:26 . 2008-07-21 16:53 17,164 --ahs---- C:\Windows\System32\drivers\fidbox.idx
      2008-07-17 20:26 . 2008-07-21 16:53 1,976 --ahs---- C:\Windows\System32\drivers\fidbox2.idx
      2008-07-17 20:22 . 2008-07-21 16:31 <REP> d-------- C:\Users\All Users\Kaspersky Lab Setup Files
      2008-07-17 20:22 . 2008-07-21 16:31 <REP> d-------- C:\ProgramData\Kaspersky Lab Setup Files
      2008-07-16 22:09 . 2008-07-16 22:09 <REP> d-------- C:\Windows\System32\Kaspersky Lab
      2008-07-16 21:31 . 2008-07-16 21:51 54,156 --ah----- C:\Windows\QTFont.qfn
      2008-07-16 21:31 . 2008-07-16 21:31 1,409 --a------ C:\Windows\QTFont.for
      2008-07-16 18:51 . 2008-07-16 18:51 <REP> d-------- C:\Users\All Users\Nero
      2008-07-16 18:51 . 2008-07-16 18:51 <REP> d-------- C:\ProgramData\Nero
      2008-07-15 21:35 . 2008-07-15 21:35 <REP> d-------- C:\Program Files\VS Revo Group
      2008-07-15 15:12 . 2008-07-15 15:12 69 --a------ C:\Windows\NeroDigital.ini
      2008-07-13 17:37 . 2008-07-13 06:12 <REP> d-------- C:\SDFix
      2008-07-13 15:56 . 2008-07-13 15:56 <REP> d-------- C:\Users\pierre\AppData\Roaming\Malwarebytes
      2008-07-13 15:55 . 2008-07-13 15:55 <REP> d-------- C:\Users\All Users\Malwarebytes
      2008-07-13 15:55 . 2008-07-13 15:55 <REP> d-------- C:\ProgramData\Malwarebytes
      2008-07-13 15:55 . 2008-07-13 15:56 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
      2008-07-13 15:55 . 2008-07-07 17:35 34,296 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
      2008-07-13 15:55 . 2008-07-07 17:35 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
      2008-07-12 15:32 . 2008-07-13 22:05 <REP> d-------- C:\Users\pierre\photos pro'pulsion
      2008-07-09 20:11 . 2008-06-26 02:33 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
      2008-07-09 20:11 . 2008-06-26 02:33 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
      2008-07-09 20:09 . 2008-06-26 02:33 11,722,752 --a------ C:\Windows\System32\NlsLexicons0001.dll
      2008-07-09 15:27 . 2008-07-09 15:26 691,545 --a------ C:\Windows\unins000.exe
      2008-07-09 15:27 . 2008-07-09 15:27 2,545 --a------ C:\Windows\unins000.dat
      2008-06-27 16:49 . 2008-04-23 07:11 1,244,672 --a------ C:\Windows\System32\mcmde.dll
      2008-06-27 16:49 . 2008-04-23 06:27 428,032 --a------ C:\Windows\System32\EncDec.dll
      2008-06-27 16:49 . 2008-04-23 06:27 292,352 --a------ C:\Windows\System32\psisdecd.dll
      2008-06-27 16:49 . 2008-04-23 06:26 218,624 --a------ C:\Windows\System32\psisrndr.ax
      2008-06-27 16:49 . 2008-04-23 06:26 80,896 --a------ C:\Windows\System32\MSNP.ax
      2008-06-27 16:49 . 2008-04-23 06:26 68,608 --a------ C:\Windows\System32\Mpeg2Data.ax
      2008-06-27 16:49 . 2008-04-23 06:26 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
      2008-06-26 18:39 . 2008-07-21 21:16 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
      2008-06-26 18:39 . 2008-07-21 21:16 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
      2008-06-26 18:39 . 2008-07-10 20:40 <REP> d-------- C:\Program Files\Spybot - Search & Destroy

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-07-24 19:07 --------- d-----w C:\Program Files\Trend Micro
      2008-07-23 16:00 --------- d-----w C:\Program Files\TELE2
      2008-07-22 14:15 --------- d-----w C:\Program Files\Java
      2008-07-21 18:25 --------- d-----w C:\Program Files\Yahoo!
      2008-07-16 16:52 --------- d-----w C:\Program Files\Common Files\Ahead
      2008-07-16 14:05 128 ----a-w C:\Users\pierre\AppData\Roaming\wklnhst.dat
      2008-07-15 17:52 --------- d-----w C:\Program Files\Windows Mail
      2008-07-13 14:14 --------- d-----w C:\Program Files\Common Files\Symantec Shared
      2008-07-12 21:46 --------- d-----w C:\Program Files\Common Files\InstallShield
      2008-07-09 18:17 174 --sha-w C:\Program Files\desktop.ini
      2008-06-26 00:34 7,964,672 ----a-w C:\Windows\System32\NlsLexicons0024.dll
      2008-06-26 00:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
      2008-06-23 07:44 62,464 ----a-w C:\Windows\system32\drivers\RTSTOR.sys
      2008-06-18 15:25 --------- d-----w C:\ProgramData\Avira
      2008-06-18 12:52 --------- d-----w C:\Program Files\Apple Software Update
      2008-06-09 13:19 27,430 ----a-w C:\Users\pierre\AppData\Roaming\nvModes.dat
      2008-06-07 12:29 --------- d-----w C:\Users\pierre\AppData\Roaming\Apple Computer
      2008-06-07 12:28 --------- d-----w C:\Program Files\iTunes
      2008-06-07 12:27 --------- d-----w C:\ProgramData\Apple Computer
      2008-06-07 12:27 --------- d-----w C:\Program Files\iPod
      2008-06-07 12:25 --------- d-----w C:\Program Files\Bonjour
      2008-06-07 12:24 --------- d-----w C:\Program Files\QuickTime
      2008-06-07 12:10 --------- d-----w C:\ProgramData\Apple
      2008-06-07 12:10 --------- d-----w C:\Program Files\Common Files\Apple
      2008-06-04 18:43 --------- d-----w C:\ProgramData\F-Secure
      2008-06-02 13:27 --------- d-----w C:\Program Files\Alwil Software
      2008-05-31 21:28 --------- d-----w C:\ProgramData\Lavasoft
      2008-05-30 19:17 --------- d-----w C:\Users\pierre\AppData\Roaming\Media Player Classic
      2008-05-30 19:06 --------- d-----w C:\Program Files\K-Lite Codec Pack
      2008-05-30 12:12 --------- d-----w C:\Program Files\Common Files\Adobe
      2008-05-10 03:30 14,848 ----a-w C:\Windows\System32\wshrm.dll
      2008-04-26 08:02 1,327,104 ----a-w C:\Windows\System32\quartz.dll
      .

      ((((((((((((((((((((((((((((( snapshot@2008-07-14_12.30.42.69 )))))))))))))))))))))))))))))))))))))))))
      .
      - 2008-06-15 10:14:17 51,200 ----a-w C:\Windows\inf\infpub.dat
      + 2008-07-17 18:27:09 51,200 ----a-w C:\Windows\inf\infpub.dat
      - 2008-06-15 10:14:16 86,016 ----a-w C:\Windows\inf\infstor.dat
      + 2008-07-17 18:27:09 86,016 ----a-w C:\Windows\inf\infstor.dat
      - 2008-06-15 10:14:16 86,016 ----a-w C:\Windows\inf\infstrng.dat
      + 2008-07-17 18:27:08 86,016 ----a-w C:\Windows\inf\infstrng.dat
      - 2007-11-16 09:55:44 25,214 ----a-r C:\Windows\Installer\{81CD6232-10F5-4832-B3DA-1B88B1571036}\ARPPRODUCTICON.exe
      + 2008-07-16 16:52:57 25,214 ----a-r C:\Windows\Installer\{81CD6232-10F5-4832-B3DA-1B88B1571036}\ARPPRODUCTICON.exe
      - 2008-07-14 10:08:43 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
      + 2008-07-26 22:36:42 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
      - 2008-07-14 10:08:43 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
      + 2008-07-26 22:36:42 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
      - 2008-07-14 10:11:20 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
      + 2008-07-26 22:39:27 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
      + 2008-07-26 22:39:27 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
      - 2008-07-14 10:11:15 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
      + 2008-07-26 22:39:22 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
      + 2008-07-26 22:39:22 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
      - 2007-08-02 12:32:10 5,631,520 ----a-w C:\Windows\system\DriveIcon.dll
      + 2008-05-06 07:41:30 6,416,928 ----a-w C:\Windows\system\DriveIcon.dll
      - 2008-07-14 10:29:30 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
      + 2008-07-26 22:37:01 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
      + 2008-07-22 19:47:11 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008072220080723\index.dat
      + 2008-07-23 13:09:15 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008072320080724\index.dat
      - 2008-07-14 10:29:30 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
      + 2008-07-26 22:37:01 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
      - 2008-07-14 10:29:30 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
      + 2008-07-26 22:37:01 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
      - 2008-07-14 10:28:06 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
      + 2008-07-26 23:26:39 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
      + 2008-07-26 23:26:39 262,144 ---ha-w C:\Windows\System32\config\systemprofile\ntuser.dat.LOG1
      + 2006-03-31 10:40:58 2,388,176 ----a-w C:\Windows\System32\d3dx9_30.dll
      + 2008-04-16 12:23:44 112,144 ----a-w C:\Windows\System32\drivers\kl1.sys
      + 2008-01-29 16:29:38 32,784 ----a-w C:\Windows\System32\drivers\klbg.sys
      + 2008-03-13 17:02:46 26,640 ----a-w C:\Windows\System32\drivers\klfltdev.sys
      + 2008-03-26 11:10:16 20,496 ----a-w C:\Windows\System32\drivers\klim6.sys
      + 2008-04-25 16:21:06 26,964 ----a-w C:\Windows\System32\drivers\klopp.dat
      + 2008-03-26 11:10:16 20,496 ----a-w C:\Windows\System32\DriverStore\FileRepository\klim6.inf_61c2e785\klim6.sys
      + 2008-05-06 07:41:30 6,416,928 ----a-w C:\Windows\System32\DriverStore\FileRepository\rtusbstor.inf_04412eae\DriveIcon.dll
      + 2008-06-23 07:44:54 62,464 ----a-w C:\Windows\System32\DriverStore\FileRepository\rtusbstor.inf_04412eae\RTSTOR.sys
      - 2004-07-26 15:16:10 1,568,768 ----a-w C:\Windows\System32\imagX7.dll
      + 2004-07-26 14:16:10 1,568,768 ----a-w C:\Windows\System32\imagX7.dll
      - 2004-07-26 15:16:10 476,320 ----a-w C:\Windows\System32\imagXpr7.dll
      + 2004-07-26 14:16:10 476,320 ----a-w C:\Windows\System32\imagXpr7.dll
      - 2004-07-26 15:16:10 262,144 ----a-w C:\Windows\System32\imagXR7.dll
      + 2004-07-26 14:16:10 262,144 ----a-w C:\Windows\System32\imagXR7.dll
      - 2004-07-26 15:16:10 471,040 ----a-w C:\Windows\System32\imagXRA7.dll
      + 2004-07-26 14:16:10 471,040 ----a-w C:\Windows\System32\imagXRA7.dll
      - 2008-02-21 23:23:35 135,168 ----a-w C:\Windows\System32\java.exe
      + 2008-06-09 23:21:01 135,168 ----a-w C:\Windows\System32\java.exe
      - 2008-02-21 23:23:39 135,168 ----a-w C:\Windows\System32\javaw.exe
      + 2008-06-09 23:21:04 135,168 ----a-w C:\Windows\System32\javaw.exe
      - 2008-02-22 00:33:32 139,264 ----a-w C:\Windows\System32\javaws.exe
      + 2008-06-10 00:32:34 139,264 ----a-w C:\Windows\System32\javaws.exe
      + 2005-05-16 17:34:48 213,048 ----a-w C:\Windows\System32\Kaspersky Lab\Kaspersky Online Scanner\kavss.dll
      + 2006-03-20 11:17:24 65,536 ----a-w C:\Windows\System32\Kaspersky Lab\Kaspersky Online Scanner\kavuninstall.exe
      + 2006-03-20 11:17:20 798,720 ----a-w C:\Windows\System32\Kaspersky Lab\Kaspersky Online Scanner\kavwebscan.dll
      + 2008-04-25 16:22:24 206,088 ----a-w C:\Windows\System32\klogon.dll
      - 2007-02-26 18:05:18 95,864 ----a-w C:\Windows\System32\NeroCo.dll
      + 2007-02-26 17:05:18 95,864 ----a-w C:\Windows\System32\NeroCo.dll
      - 2008-07-09 18:16:01 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
      + 2008-07-15 18:14:04 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat
      + 2008-07-15 18:14:04 6,291,456 ----a-w C:\Windows\System32\SMI\Store\Machine\schema.dat_previous
      - 2004-07-09 07:43:56 364,544 ----a-w C:\Windows\System32\TwnLib4.dll
      + 2004-07-09 06:43:56 364,544 ----a-w C:\Windows\System32\TwnLib4.dll
      - 2008-07-14 10:11:21 11,016 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1485623736-812755021-2284708237-1000_UserData.bin
      + 2008-07-26 22:39:03 11,842 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1485623736-812755021-2284708237-1000_UserData.bin
      - 2008-07-14 10:11:20 66,762 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
      + 2008-07-26 22:39:03 67,624 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
      - 2008-07-05 10:05:21 3,008 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
      + 2008-07-17 19:02:33 3,298 ----a-w C:\Windows\System32\WDI\ERCQueuedResolutions.dat
      - 2008-07-14 10:11:08 55,434 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
      + 2008-07-26 22:39:01 58,520 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
      - 2007-02-26 18:21:06 972,336 ----a-w C:\Windows\UNNeroMediaHome.exe
      + 2007-02-26 17:21:06 972,336 ----a-w C:\Windows\UNNeroMediaHome.exe
      - 2007-02-26 18:39:02 972,336 ----a-w C:\Windows\UNNeroShowTime.exe
      + 2007-02-26 17:39:02 972,336 ----a-w C:\Windows\UNNeroShowTime.exe
      - 2007-02-26 19:36:50 972,336 ----a-w C:\Windows\UNNeroVision.exe
      + 2007-02-26 18:36:50 972,336 ----a-w C:\Windows\UNNeroVision.exe
      - 2007-02-26 18:34:18 972,336 ----a-w C:\Windows\UNRecode.exe
      + 2007-02-26 17:34:18 972,336 ----a-w C:\Windows\UNRecode.exe
      - 2008-07-09 18:08:44 31,238,634 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
      + 2008-07-15 18:13:19 31,265,751 ----a-w C:\Windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
      + 2008-06-09 22:40:17 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16699_none_f0498ecc6e94a1be\OESpamFilter.dat
      + 2008-06-09 22:37:40 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.20855_none_f0fa6c058795698f\OESpamFilter.dat
      + 2008-06-11 00:28:21 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18088_none_f2399d146bb3fd67\OESpamFilter.dat
      + 2008-06-09 22:36:23 2,413,032 ----a-w C:\Windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22200_none_f311b8d58497f018\OESpamFilter.dat
      + 2008-07-15 18:13:18 1,233,920 ----a-w C:\Windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9818.0_none_b7e811947b297f6d\msxml4.dll
      .
      -- Snapshot reset to current date --
      .
      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      REGEDIT4
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-04-20 13:36 1232896]
      "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-04-22 12:52 171448]
      "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
      "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-19 01:31 86016]
      "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-19 01:31 8466432]
      "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-19 01:31 81920]
      "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2007-05-25 12:17 159744]
      "FIC HotKey"="C:\Program Files\Hotkey Utility\tray.exe" [2007-07-13 15:38 561152]
      "PowerManager"="C:\Program Files\Power Manager\PM.exe" [2007-05-16 12:42 29696]
      "Silent Mode"="C:\Program Files\Light Sensor Utility\Sensor.exe" [2007-06-27 10:56 253952]
      "recinfo706"="c:\RecInfo\RecInfo.exe" [2007-10-23 14:52 2764800]
      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
      "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
      "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224]
      "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
      "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
      "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 20:46 153136]
      "SpywareTerminator"="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe" [2008-07-22 20:14 1783808]
      "RtHDVCpl"="RtHDVCpl.exe" [2007-04-10 16:01 4431872 C:\Windows\RtHDVCpl.exe]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

      C:\Users\pierre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
      OneNote 2007 - Capture d'‚cran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
      "AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
      "VIDC.YV12"= yv12vfw.dll

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
      "DisableMonitoring"=dword:00000001

      [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
      "DisableMonitoring"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
      "{EE849512-1750-4752-9658-D3527CDB19FD}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
      "{BE11DD08-AA1A-4251-A90A-E1C4F7E46B48}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
      "{0AAE5F62-EA3E-4D98-B20D-446DC72354DD}"= C:\Program Files\CyberLink\PowerDV\PowerDV.exe:CyberLink PowerDV
      "{C4EE3803-388B-4383-A9D5-504EE186984C}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
      "TCP Query User{D461A291-063B-4921-A530-D82B647EB0B1}C:\\program files\\intervideo\\dvd8\\windvd.exe"= UDP:C:\program files\intervideo\dvd8\windvd.exe:WinDVD
      "UDP Query User{D969DD8C-0724-41CD-97EA-D375810DADF7}C:\\program files\\intervideo\\dvd8\\windvd.exe"= TCP:C:\program files\intervideo\dvd8\windvd.exe:WinDVD
      "{0DE9BC89-AF96-4E6F-A0E3-C15E830C05A9}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
      "{C0A3CAF8-F3B0-4856-B5E9-E786BDBF4F34}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
      "{C187D75C-A4FC-408D-BD75-D312351F4223}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
      "{5B6291F5-3107-4EA7-BCF2-6884DDD5603F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
      "TCP Query User{510300B1-DBB9-409B-AD9D-D3D56857D81B}C:\\users\\pierre\\appdata\\local\\temp\\wzse0.tmp\\symnrt.exe"= UDP:C:\users\pierre\appdata\local\temp\wzse0.tmp\symnrt.exe:symnrt.exe
      "UDP Query User{D4192A9F-A54A-49B7-9B98-5EF93B430151}C:\\users\\pierre\\appdata\\local\\temp\\wzse0.tmp\\symnrt.exe"= TCP:C:\users\pierre\appdata\local\temp\wzse0.tmp\symnrt.exe:symnrt.exe
      "TCP Query User{68053F71-8F92-476D-9B49-13F7727199CB}C:\\program files\\common files\\ahead\\nero web\\setupx.exe"= UDP:C:\program files\common files\ahead\nero web\setupx.exe:MSI starter
      "UDP Query User{59E1D1A5-0842-470C-9EC7-B557EC9909A2}C:\\program files\\common files\\ahead\\nero web\\setupx.exe"= TCP:C:\program files\common files\ahead\nero web\setupx.exe:MSI starter
      "TCP Query User{EDF2D800-DCA6-4DA4-8DF0-26D35DAAF4EF}C:\\users\\pierre\\appdata\\local\\temp\\nero web\\setupxu.exe"= UDP:C:\users\pierre\appdata\local\temp\nero web\setupxu.exe:setupxu.exe
      "UDP Query User{E0128A82-24C5-4336-B5C6-7A0AE7F566B1}C:\\users\\pierre\\appdata\\local\\temp\\nero web\\setupxu.exe"= TCP:C:\users\pierre\appdata\local\temp\nero web\setupxu.exe:setupxu.exe
      "TCP Query User{E9C97373-7CFD-4919-8A74-F8A24E4D24F2}C:\\programdata\\kaspersky lab setup files\\kaspersky internet security 2009\\french\\setup.exe"= UDP:C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\french\setup.exe:Programme d'installation de Kaspersky Internet Security 2009
      "UDP Query User{74F08B60-DCC2-4BE9-8257-D214403DD9BE}C:\\programdata\\kaspersky lab setup files\\kaspersky internet security 2009\\french\\setup.exe"= TCP:C:\programdata\kaspersky lab setup files\kaspersky internet security 2009\french\setup.exe:Programme d'installation de Kaspersky Internet Security 2009
      "TCP Query User{85DD36EC-8E70-479D-9F79-9C32E7FFDD08}C:\\programdata\\kaspersky lab setup files\\kaspersky anti-virus 2009\\french\\setup.exe"= UDP:C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\french\setup.exe:Programme d'installation de Kaspersky Anti-Virus 2009
      "UDP Query User{14340551-CA54-417D-92CA-42F621FBC1B5}C:\\programdata\\kaspersky lab setup files\\kaspersky anti-virus 2009\\french\\setup.exe"= TCP:C:\programdata\kaspersky lab setup files\kaspersky anti-virus 2009\french\setup.exe:Programme d'installation de Kaspersky Anti-Virus 2009

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
      "DoNotAllowExceptions"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
      "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

      R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [2008-01-29 18:29]
      R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-16 01:20]
      R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2008-03-26 13:10]
      R1 sp_rsdrv2;Spyware Terminator Driver 2;C:\Windows\system32\drivers\sp_rsdrv2.sys [2008-07-22 20:14]
      R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
      R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-16 01:18]
      R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
      R2 TestHandler;Fujitsu Siemens Computers Diagnostic Testhandler;C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [2006-12-08 11:52]
      R3 KLFLTDEV;Kaspersky Lab KLFltDev;C:\Windows\system32\DRIVERS\klfltdev.sys [2008-03-13 19:02]
      R3 RTSTOR;Realtek USB 2.0 Card Reader;C:\Windows\system32\drivers\RTSTOR.SYS [2008-06-23 09:44]
      S4 nvrd32;NVIDIA nForce RAID Driver;C:\Windows\system32\drivers\nvrd32.sys [2007-07-02 17:37]
      .
      Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
      2008-07-26 C:\Windows\Tasks\User_Feed_Synchronization-{88E50F82-E0EA-4A84-BD14-221F83FDD350}.job - C:\Windows\system32\msfeedssync.exe [2006-11-02 11:45]
      2008-04-20 C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job - s2C:\Program Files\Windows Live Toolbar\MSNTBUP.EXEpierre09< []
      .
      .
      ------- Supplementary Scan -------
      .
      R0 -: HKCU-Main,Start Page = hxxp://www.tele2.fr/portail/
      R1 -: HKCU-Internet Settings,ProxyOverride = *.local
      O8 -: &Windows Live Search - C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 -: Crawler Search - tbr:iemenu
      O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O18 -: Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll

      **************************************************************************

      catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-07-27 01:28:41
      Windows 6.0.6000 NTFS

      Balayage processus cachés ...

      Balayage caché autostart entries ...

      Balayage des fichiers cachés ...

      C:\Windows\TEMP\TMP0000005669AB628FC2D70D1D

      Scan terminé avec succès
      Les fichiers cachés: 1

      **************************************************************************
      .
      Temps d'accomplissement: 2008-07-27 1:29:35
      ComboFix-quarantined-files.txt 2008-07-26 23:29:21

      Pre-Run: 65,432,522,752 octets libres
      Post-Run: 65,521,803,264 octets libres

      295 --- E O F --- 2008-07-25 13:30:56

      cés ça le rapport combix dis moi ce que je dois faire maintenant je le ferais demain après-midi a +
      0
    3. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 18:27:54, on 28/07/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16681)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\system32\taskeng.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Apoint2K\Apoint.exe
      C:\Program Files\Hotkey Utility\tray.exe
      C:\Program Files\Power Manager\PM.exe
      C:\Program Files\Light Sensor Utility\Sensor.exe
      C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Apoint2K\ApMsgFwd.exe
      C:\Program Files\Apoint2K\Apntex.exe
      C:\Program Files\Internet Explorer\ieuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
      C:\Windows\system32\SearchFilterHost.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2.fr/portail/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
      O4 - HKLM\..\Run: [FIC HotKey] C:\Program Files\Hotkey Utility\tray.exe
      O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
      O4 - HKLM\..\Run: [Silent Mode] C:\Program Files\Light Sensor Utility\Sensor.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
      O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
  3. Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 23:45:45, on 26/07/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16681)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\RtHDVCpl.exe
    C:\Program Files\Apoint2K\Apoint.exe
    C:\Program Files\Hotkey Utility\tray.exe
    C:\Program Files\Power Manager\PM.exe
    C:\Program Files\Light Sensor Utility\Sensor.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Spyware Terminator\SpywareTerminatorShield.Exe
    C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Apoint2K\ApMsgFwd.exe
    C:\Program Files\Apoint2K\Apntex.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
    C:\Windows\system32\conime.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60327
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2.fr/portail/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O3 - Toolbar: Barre d'outils &Crawler - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
    O4 - HKLM\..\Run: [FIC HotKey] C:\Program Files\Hotkey Utility\tray.exe
    O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
    O4 - HKLM\..\Run: [Silent Mode] C:\Program Files\Light Sensor Utility\Sensor.exe
    O4 - HKLM\..\Run: [recinfo706] c:\RecInfo\RecInfo.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
    O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe"
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background (User 'Default user')
    O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
    O8 - Extra context menu item: Ajouter à Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ie_banner_deny.htm
    O8 - Extra context menu item: Crawler Search - tbr:iemenu
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
    O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - (no file)
    O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O13 - Gopher Prefix:
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\Toolbar\ctbr.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
    O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    0
    1. aider moi svp kaspersky est toujours la malgré tous ce que vous me dite je dois avoir un virus SVP et je n ais toujours pas acces a mes e-mail
      0
      1. Oui, c'est ça.

        Alors on continue :

        > Lance Hijackthis :
        - Puis sélectionne < Scan >
        - Coche les cases des lignes suivantes :
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) 
        
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL') 
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU') 

        Ensuite,
        - Ferme toutes les autres fenêtres et applications (même internet)
        - Clic sur < fixe checked >

        > Passe un coup de Ccleaner en mode sans échec

        > Relance ton PC en mode normal puis Hijackthis :
        Puis sélectionne < do a system scan and save a logfile >,

        Et envoie, par collier/coller, ton log Hijackthis,

        Je doute d'un fichier aussi,
        > Rends toi sur le site virustotal et fais analyser le/les fichiers suivant(s) : (copie/colle la/les ligne(s) ci-dessous dans le cadre "envoyé un fichier")
        Si problème : http://pageperso.aol.fr/loraline60/virus_total.htm

        c:\RecInfo\RecInfo.exe

        et poste le résultat par copier/coller stp (ou le lien http, c'est plus rapide et plus simple).

        Pour finir,
        > Fais un scan en ligne avec Kaspersky : https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
        N.B. : Le scan ne marche que sous Internet Explorer.
        - Commence par connecter tout ton matériel de stockage à ton PC (clés USB, DD amovible...) si possible. Allume les si necessaire.
        - Sous Démonstration en ligne, on t'explique la marche à suivre, et pour lancer le scan il faut sélectionner < Exécuter l'analyse en ligne >.
        - On va te demander de télécharger un contrôle active x, accepte .
        - Dans le menu < Choisissez la cible de l'analyse >, sélectionne < Poste de travail >. Le scan va commencer.
        - Poste le rapport qui sera généré.
        S'il y a un problème, assure toi que les contrôles active x sont bien configurés dans les options internet comme décrit sur ce lien : http://www.inoculer.com/activex.php3
        Rappel : le scan est à faire sous Internet Explorer
        Tuto ici si problème : http://www.vista-xp.fr/forum/topic109.html

        A+
        0
        1. Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:53:37, on 16/07/2008
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16681)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Windows\System32\rundll32.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Apoint2K\Apoint.exe
          C:\Program Files\Hotkey Utility\tray.exe
          C:\Program Files\Power Manager\PM.exe
          C:\Program Files\Light Sensor Utility\Sensor.exe
          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Program Files\Apoint2K\ApMsgFwd.exe
          C:\Program Files\Apoint2K\Apntex.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2internet.fr/?skip_split_page
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O1 - Hosts: ::1 localhost
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
          O4 - HKLM\..\Run: [FIC HotKey] C:\Program Files\Hotkey Utility\tray.exe
          O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
          O4 - HKLM\..\Run: [Silent Mode] C:\Program Files\Light Sensor Utility\Sensor.exe
          O4 - HKLM\..\Run: [recinfo706] c:\RecInfo\RecInfo.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
          O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
          O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          0
        2. | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español | English
          Virustotal est un service qui analyse les fichiers suspects et facilite la détection rapide des virus, vers, chevaux de Troie et toutes sortes de malwares détectés par les moteurs antivirus. Plus d'informations...
          Fichier RecInfo.exe reçu le 2008.07.16 22:00:41 (CET)
          Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

          Résultat: 0/33 (0%)
          en train de charger les informations du serveur...
          Votre fichier est dans la file d'attente, en position: ___.
          L'heure estimée de démarrage est entre ___ et ___ .
          Ne fermez pas la fenêtre avant la fin de l'analyse.
          L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
          Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
          Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
          les résultats seront affichés au fur et à mesure de leur génération.
          Formaté Impression des résultats
          Votre fichier a expiré ou n'existe pas.
          Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

          Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
          Email:

          Antivirus Version Dernière mise à jour Résultat
          AhnLab-V3 2008.7.17.0 2008.07.16 -
          AntiVir 7.8.0.68 2008.07.16 -
          Authentium 5.1.0.4 2008.07.15 -
          Avast 4.8.1195.0 2008.07.16 -
          AVG 7.5.0.516 2008.07.16 -
          BitDefender 7.2 2008.07.16 -
          CAT-QuickHeal 9.50 2008.07.16 -
          ClamAV 0.93.1 2008.07.16 -
          DrWeb 4.44.0.09170 2008.07.16 -
          eSafe 7.0.17.0 2008.07.16 -
          eTrust-Vet 31.6.5959 2008.07.16 -
          Ewido 4.0 2008.07.16 -
          F-Prot 4.4.4.56 2008.07.15 -
          F-Secure 7.60.13501.0 2008.07.16 -
          Fortinet 3.14.0.0 2008.07.16 -
          GData 2.0.7306.1023 2008.07.16 -
          Ikarus T3.1.1.26.0 2008.07.16 -
          Kaspersky 7.0.0.125 2008.07.16 -
          McAfee 5340 2008.07.16 -
          Microsoft 1.3704 2008.07.16 -
          NOD32v2 3274 2008.07.16 -
          Norman 5.80.02 2008.07.16 -
          Panda 9.0.0.4 2008.07.16 -
          Prevx1 V2 2008.07.16 -
          Rising 20.53.22.00 2008.07.16 -
          Sophos 4.31.0 2008.07.16 -
          Sunbelt 3.1.1536.1 2008.07.15 -
          Symantec 10 2008.07.16 -
          TheHacker 6.2.96.381 2008.07.16 -
          TrendMicro 8.700.0.1004 2008.07.16 -
          VBA32 3.12.8.0 2008.07.16 -
          VirusBuster 4.5.11.0 2008.07.16 -
          Webwasher-Gateway 6.6.2 2008.07.16 -
          Information additionnelle
          File size: 2764800 bytes
          MD5...: 8e382b0c5f16daf17b3c1cf5205846d1
          SHA1..: 9bbcfe2ca30ec4683d3cbb389fb7ffb6d77eede5
          SHA256: 916ef2f99050841fb5aa2662ae0451255eba0429122e4984cbe9d53b15f9e725
          SHA512: 8a3e0441ecb9096921fea7b1f85035119fbc8c38b330fea861f976fab4e7319c
          e892a4c6f6d48c7f551d07768e734f5c986692999454cf27a06eae8a3f13b060
          PEiD..: -
          PEInfo: PE Structure information

          ( base data )
          entrypointaddress.: 0x6a0eee
          timedatestamp.....: 0x471dee89 (Tue Oct 23 12:52:25 2007)
          machinetype.......: 0x14c (I386)

          ( 4 sections )
          name viradd virsiz rawdsiz ntrpy md5
          .text 0x2000 0x29eef4 0x29f000 0.87 8e0bce18abf50795e29b50a822ab8b1a
          .sdata 0x2a2000 0xa6 0x1000 0.41 69bb16bae47cfa7016e13383b6a52f2a
          .rsrc 0x2a4000 0x7f0 0x1000 1.62 4d6c785c8b5c126ed200222995afcc2d
          .reloc 0x2a6000 0xc 0x1000 0.01 5549acc2afdb623692fcff1aa701b9eb

          ( 1 imports )
          > mscoree.dll: _CorExeMain

          ( 0 exports )

          ATTENTION: VirusTotal est un service gratuit offert par Hispasec Sistemas. Il n'y a aucune garantie quant à la disponibilité et la continuité de ce service. Bien que le taux de détection permis par l'utilisation de multiples moteurs antivirus soit bien supérieur à celui offert par seulement un produit, ces résultats NE garantissent PAS qu'un fichier est sans danger. Il n'y a actuellement aucune solution qui offre un taux d'efficacité de 100% pour la détection des virus et malwares.

          VirusTotal © Hispasec Sistemas - Blog - Contact: info@virustotal.com - Terms of Service & Privacy Policy
          0
        3. je t envoi le raport kapersky demain fin d apré midi merci pour tous
          0
        4. bonsoir ta vu mon rapport pour kaspersky
          0
      2. Bonjour,
        J'avais oublié que tu es sous Vista.

        Alors,
        > Télécharge Clean : http://www.malekal.com/download/clean.zip (différent de Ccleaner),
        > Démarre en mode sans échec : (image). Si problème : tuto ici
        - Double-clic sur clean.cmd
        - Une fenêtre va apparaître, choisis l'option 2, suis les consignes et poste le rapport clean
        - Si tu obtiens un fichier C:\upload_moi.zip, alors fais ceci: http://www.malekal.com/tuto_upload_fichiers.php
        NB : Si besoin, clean : http://mickael.barroux.free.fr/securite/clean.php

        Ensuite,
        poste un nouveau rapport HiJackT stp puis on termine.

        Bon courage.

        A+
        0
        1. Clean will delete all those files and folders which are known to be malware.

          La variable d'environnement It is recommended, to apply this option after instru
          ction of an expert of one the following forums: n'est pas définie.
          La variable d'environnement https://www.malwareremoval.com/ n'est pas définie.
          La variable d'environnement http://www.geekstogo.com/forum/index.php n'est pas d
          éfinie.
          La variable d'environnement http://ww25.forums.spywareinfo.com/ n'est pas définie.

          This will last some time. Please be patient and wait until you get the message t
          hat it's finished.

          Appuyez sur une touche pour continuer...

          Option 2, Enter
          Accès refusé - C:\Windows\system32\wininit.exe

          PsKill v1.11 - Terminates processes on local or remote systems
          Copyright (C) 1999-2005 Mark Russinovich
          Sysinternals - www.sysinternals.com

          Unable to kill process C:\Windows\system32\wininit.exe:
          Process does not exist.
          C:\Windows\system32\wininit.exe
          Accès refusé.
          tentative de suppression de C:\Windows\system32\wininit.exe
          Accès refusé - C:\Windows\system32\wininit.exe

          PsKill v1.11 - Terminates processes on local or remote systems
          Copyright (C) 1999-2005 Mark Russinovich
          Sysinternals - www.sysinternals.com

          Unable to kill process C:\Windows\system32\wininit.exe:
          Process does not exist.
          C:\Windows\system32\wininit.exe
          Accès refusé.
          tentative de suppression de C:\Windows\system32\wininit.exe

          Deletion of the registry keys....
          Cliquez sur le bouton "Envoyer le fichier"

          Merci!
          Appuyez sur une touche pour continuer...
          cé 9a que tu voulais?
          0
        2. bonjouLogfile of Trend Micro HijackThis v2.0.2
          Scan saved at 17:55:49, on 16/07/2008
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16681)
          Boot mode: Safe mode with network support

          Running processes:
          C:\Windows\Explorer.EXE
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2internet.fr/?skip_split_page
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O1 - Hosts: ::1 localhost
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
          O4 - HKLM\..\Run: [FIC HotKey] C:\Program Files\Hotkey Utility\tray.exe
          O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
          O4 - HKLM\..\Run: [Silent Mode] C:\Program Files\Light Sensor Utility\Sensor.exe
          O4 - HKLM\..\Run: [recinfo706] c:\RecInfo\RecInfo.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
          O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
          O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          0
      3. Re,
        fais ceci stp :
        > Télécharge ComboFix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe (par sUBs) sur ton Bureau.
        Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement.
        - Double clique combofix.exe
        - Tape sur la touche 1 (Yes) pour démarrer le scan.
        - Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
        NOTE : Le rapport se trouve également ici : C:\Combofix.txt
        Attention : n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer la machine.

        A+
        0
        1. ComboFix 08-07-13.9 - pierre 2008-07-14 12:28:12.1 - NTFSx86
          Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1246 [GMT 2:00]
          Endroit: C:\Users\pierre\Desktop\ComboFix.exe
          * Création d'un nouveau point de restauration
          .

          ((((((((((((((((((((((((((((( Fichiers créés 2008-06-14 to 2008-07-14 ))))))))))))))))))))))))))))))))))))
          .

          2008-07-13 17:37 . 2008-07-13 06:12 <REP> d-------- C:\SDFix
          2008-07-13 15:56 . 2008-07-13 15:56 <REP> d-------- C:\Users\pierre\AppData\Roaming\Malwarebytes
          2008-07-13 15:55 . 2008-07-13 15:55 <REP> d-------- C:\Users\All Users\Malwarebytes
          2008-07-13 15:55 . 2008-07-13 15:55 <REP> d-------- C:\ProgramData\Malwarebytes
          2008-07-13 15:55 . 2008-07-13 15:56 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
          2008-07-13 15:55 . 2008-07-07 17:35 34,296 --a------ C:\Windows\System32\drivers\mbamcatchme.sys
          2008-07-13 15:55 . 2008-07-07 17:35 17,144 --a------ C:\Windows\System32\drivers\mbam.sys
          2008-07-12 15:32 . 2008-07-13 22:05 <REP> d-------- C:\Users\pierre\photos pro'pulsion
          2008-07-09 20:11 . 2008-06-26 02:33 12,240,896 --a------ C:\Windows\System32\NlsLexicons0007.dll
          2008-07-09 20:11 . 2008-06-26 02:33 2,644,480 --a------ C:\Windows\System32\NlsLexicons0009.dll
          2008-07-09 20:09 . 2008-06-26 02:33 11,722,752 --a------ C:\Windows\System32\NlsLexicons0001.dll
          2008-07-09 15:27 . 2008-07-09 15:26 691,545 --a------ C:\Windows\unins000.exe
          2008-07-09 15:27 . 2008-07-09 15:27 2,545 --a------ C:\Windows\unins000.dat
          2008-06-27 16:49 . 2008-04-23 07:11 1,244,672 --a------ C:\Windows\System32\mcmde.dll
          2008-06-27 16:49 . 2008-04-23 06:27 428,032 --a------ C:\Windows\System32\EncDec.dll
          2008-06-27 16:49 . 2008-04-23 06:27 292,352 --a------ C:\Windows\System32\psisdecd.dll
          2008-06-27 16:49 . 2008-04-23 06:26 218,624 --a------ C:\Windows\System32\psisrndr.ax
          2008-06-27 16:49 . 2008-04-23 06:26 80,896 --a------ C:\Windows\System32\MSNP.ax
          2008-06-27 16:49 . 2008-04-23 06:26 68,608 --a------ C:\Windows\System32\Mpeg2Data.ax
          2008-06-27 16:49 . 2008-04-23 06:26 57,856 --a------ C:\Windows\System32\MSDvbNP.ax
          2008-06-26 18:39 . 2008-07-11 14:17 <REP> d-------- C:\Users\All Users\Spybot - Search & Destroy
          2008-06-26 18:39 . 2008-07-11 14:17 <REP> d-------- C:\ProgramData\Spybot - Search & Destroy
          2008-06-26 18:39 . 2008-07-10 20:40 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
          2008-06-18 17:51 . 2008-06-18 17:51 <REP> d-------- C:\Users\All Users\Yahoo! Companion
          2008-06-18 17:51 . 2008-06-18 17:51 <REP> d-------- C:\ProgramData\Yahoo! Companion
          2008-06-18 17:40 . 2008-06-18 17:40 <REP> d-------- C:\Program Files\Yahoo!
          2008-06-18 17:40 . 2008-06-18 17:40 <REP> d-------- C:\Program Files\CCleaner
          2008-06-18 14:52 . 2008-06-18 14:52 <REP> d-------- C:\Program Files\Apple Software Update
          2008-06-17 21:30 . 2008-06-18 17:25 <REP> d-------- C:\Users\All Users\Avira
          2008-06-17 21:30 . 2008-06-18 17:25 <REP> d-------- C:\ProgramData\Avira

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-07-13 14:14 --------- d-----w C:\Program Files\Common Files\Symantec Shared
          2008-07-12 21:46 --------- d-----w C:\Program Files\Common Files\InstallShield
          2008-07-09 18:17 174 --sha-w C:\Program Files\desktop.ini
          2008-06-27 15:51 --------- d-----w C:\Program Files\Windows Mail
          2008-06-26 00:34 7,964,672 ----a-w C:\Windows\System32\NlsLexicons0024.dll
          2008-06-26 00:33 9,892,864 ----a-w C:\Windows\System32\NlsLexicons000a.dll
          2008-06-09 13:19 27,430 ----a-w C:\Users\pierre\AppData\Roaming\nvModes.dat
          2008-06-07 21:06 --------- d-----w C:\Program Files\Navilog1
          2008-06-07 12:29 --------- d-----w C:\Users\pierre\AppData\Roaming\Apple Computer
          2008-06-07 12:28 --------- d-----w C:\Program Files\iTunes
          2008-06-07 12:27 --------- d-----w C:\ProgramData\Apple Computer
          2008-06-07 12:27 --------- d-----w C:\Program Files\iPod
          2008-06-07 12:25 --------- d-----w C:\Program Files\Bonjour
          2008-06-07 12:24 --------- d-----w C:\Program Files\QuickTime
          2008-06-07 12:10 --------- d-----w C:\ProgramData\Apple
          2008-06-07 12:10 --------- d-----w C:\Program Files\Common Files\Apple
          2008-06-04 18:43 --------- d-----w C:\ProgramData\F-Secure
          2008-06-03 18:37 --------- d-----w C:\Program Files\Trend Micro
          2008-06-02 13:27 --------- d-----w C:\Program Files\Alwil Software
          2008-05-31 21:28 --------- d-----w C:\ProgramData\Lavasoft
          2008-05-30 19:17 --------- d-----w C:\Users\pierre\AppData\Roaming\Media Player Classic
          2008-05-30 19:06 --------- d-----w C:\Program Files\K-Lite Codec Pack
          2008-05-30 12:12 --------- d-----w C:\Program Files\Common Files\Adobe
          2008-05-20 18:24 --------- d-----w C:\Program Files\Microsoft Silverlight
          2008-05-15 23:18 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
          2008-05-14 14:13 --------- d-----w C:\ProgramData\Microsoft Help
          2008-05-10 03:30 14,848 ----a-w C:\Windows\System32\wshrm.dll
          2008-04-26 08:02 1,327,104 ----a-w C:\Windows\System32\quartz.dll
          2008-04-25 04:23 826,368 ----a-w C:\Windows\System32\wininet.dll
          2008-04-25 04:23 56,320 ----a-w C:\Windows\System32\iesetup.dll
          2008-04-25 04:23 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
          2008-04-25 04:22 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
          2008-04-20 11:38 24,064 ----a-w C:\Windows\System32\netcfg.exe
          2008-04-20 11:38 22,016 ----a-w C:\Windows\System32\netiougc.exe
          2008-04-20 11:38 194,560 ----a-w C:\Windows\System32\WebClnt.dll
          2008-04-20 11:38 167,424 ----a-w C:\Windows\System32\tcpipcfg.dll
          2008-04-20 11:37 9,728 ----a-w C:\Windows\System32\LAPRXY.DLL
          2008-04-20 11:37 296,448 ----a-w C:\Windows\System32\gdi32.dll
          2008-04-20 11:37 223,232 ----a-w C:\Windows\System32\WMASF.DLL
          2008-04-20 11:37 2,048 ----a-w C:\Windows\System32\asferror.dll
          2008-04-20 11:37 2,027,008 ----a-w C:\Windows\System32\win32k.sys
          2008-04-20 11:36 11,776 ----a-w C:\Windows\System32\sbunattend.exe
          2008-04-20 11:35 83,968 ----a-w C:\Windows\System32\dnsrslvr.dll
          2008-04-20 11:35 24,576 ----a-w C:\Windows\System32\dnscacheugc.exe
          2008-04-20 11:34 2,048 ----a-w C:\Windows\System32\tzres.dll
          2008-04-20 11:11 53,080 ----a-w C:\Windows\System32\wuauclt.exe
          2008-04-20 11:11 43,352 ----a-w C:\Windows\System32\wups2.dll
          2008-04-20 11:11 1,712,984 ----a-w C:\Windows\System32\wuaueng.dll
          2008-04-20 11:11 1,524,224 ----a-w C:\Windows\System32\wucltux.dll
          2008-04-20 11:10 80,896 ----a-w C:\Windows\System32\wudriver.dll
          2008-04-20 11:10 549,720 ----a-w C:\Windows\System32\wuapi.dll
          2008-04-20 11:10 33,624 ----a-w C:\Windows\System32\wups.dll
          2008-04-20 11:10 31,232 ----a-w C:\Windows\System32\wuapp.exe
          2008-04-20 11:10 163,000 ----a-w C:\Windows\System32\wuwebv.dll
          2008-02-19 16:12 0 ------w C:\Users\pierre\AppData\Roaming\wklnhst.dat
          .

          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          REGEDIT4
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-04-20 13:36 1232896]
          "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
          "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-04-22 12:52 171448]
          "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 11:34 5724184]
          "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-07-19 01:31 86016]
          "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-07-19 01:31 8466432]
          "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-07-19 01:31 81920]
          "Apoint"="C:\Program Files\Apoint2K\Apoint.exe" [2007-05-25 12:17 159744]
          "FIC HotKey"="C:\Program Files\Hotkey Utility\tray.exe" [2007-07-13 15:38 561152]
          "PowerManager"="C:\Program Files\Power Manager\PM.exe" [2007-05-16 12:42 29696]
          "Silent Mode"="C:\Program Files\Light Sensor Utility\Sensor.exe" [2007-06-27 10:56 253952]
          "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-02-26 21:46 153136]
          "recinfo706"="c:\RecInfo\RecInfo.exe" [2007-10-23 14:52 2764800]
          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
          "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
          "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-16 01:19 79224]
          "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
          "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
          "RtHDVCpl"="RtHDVCpl.exe" [2007-04-10 16:01 4431872 C:\Windows\RtHDVCpl.exe]

          C:\Users\pierre\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
          OneNote 2007 - Capture d'‚cran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 04:45:42 101784]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
          "VIDC.YV12"= yv12vfw.dll

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
          "DisableMonitoring"=dword:00000001

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
          "{EE849512-1750-4752-9658-D3527CDB19FD}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
          "{BE11DD08-AA1A-4251-A90A-E1C4F7E46B48}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
          "{0AAE5F62-EA3E-4D98-B20D-446DC72354DD}"= C:\Program Files\CyberLink\PowerDV\PowerDV.exe:CyberLink PowerDV
          "{C4EE3803-388B-4383-A9D5-504EE186984C}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
          "TCP Query User{D461A291-063B-4921-A530-D82B647EB0B1}C:\\program files\\intervideo\\dvd8\\windvd.exe"= UDP:C:\program files\intervideo\dvd8\windvd.exe:WinDVD
          "UDP Query User{D969DD8C-0724-41CD-97EA-D375810DADF7}C:\\program files\\intervideo\\dvd8\\windvd.exe"= TCP:C:\program files\intervideo\dvd8\windvd.exe:WinDVD
          "{0DE9BC89-AF96-4E6F-A0E3-C15E830C05A9}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
          "{C0A3CAF8-F3B0-4856-B5E9-E786BDBF4F34}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
          "{C187D75C-A4FC-408D-BD75-D312351F4223}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
          "{5B6291F5-3107-4EA7-BCF2-6884DDD5603F}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
          "TCP Query User{510300B1-DBB9-409B-AD9D-D3D56857D81B}C:\\users\\pierre\\appdata\\local\\temp\\wzse0.tmp\\symnrt.exe"= UDP:C:\users\pierre\appdata\local\temp\wzse0.tmp\symnrt.exe:symnrt.exe
          "UDP Query User{D4192A9F-A54A-49B7-9B98-5EF93B430151}C:\\users\\pierre\\appdata\\local\\temp\\wzse0.tmp\\symnrt.exe"= TCP:C:\users\pierre\appdata\local\temp\wzse0.tmp\symnrt.exe:symnrt.exe

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
          "DoNotAllowExceptions"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
          "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

          R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-16 01:20]
          R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
          R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-16 01:18]
          R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 11:43]
          R2 TestHandler;Fujitsu Siemens Computers Diagnostic Testhandler;C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe [2006-12-08 11:52]
          R3 RTSTOR;USB Mass Storage Device;C:\Windows\system32\drivers\RTSTOR.SYS [2008-02-15 14:22]
          S2 MBAMService;MBAMService;C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2008-07-07 17:35]
          S4 nvrd32;NVIDIA nForce RAID Driver;C:\Windows\system32\drivers\nvrd32.sys [2007-07-02 17:37]

          .
          Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
          "2008-07-13 15:05:25 C:\Windows\Tasks\User_Feed_Synchronization-{88E50F82-E0EA-4A84-BD14-221F83FDD350}.job"
          - C:\Windows\system32\msfeedssync.exe
          "2008-04-20 10:37:16 C:\Windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
          - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
          .
          **************************************************************************

          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-07-14 12:30:15
          Windows 6.0.6000 NTFS

          Balayage processus cachés ...

          Balayage caché autostart entries ...

          Balayage des fichiers cachés ...

          Scan terminé avec succès
          Les fichiers cachés: 0

          **************************************************************************
          .
          Temps d'accomplissement: 2008-07-14 12:31:01
          ComboFix-quarantined-files.txt 2008-07-14 10:30:51

          Pre-Run: 64,806,191,104 octets libres
          Post-Run: 64,824,549,376 octets libres

          180 --- E O F --- 2008-07-09 18:14:25

          cés ça que tu voulais
          0
        2. @mark9qui peut m aider
          0
        3. tés la?
          0
        4. slt je fais quoi aprés stp
          0
      4. nous aussi on n en sait rien , tu ne mets aucun rapport et repond a aucune question.

        dlld finit car j en ai marre.
        des differences sur le hijack :oui mais le rapport malware ou est il?
        0
        1. Malwarebytes' Anti-Malware 1.20
          Version de la base de données: 944
          Windows 6.0.6000

          20:03:56 13/07/2008
          mbam-log-7-13-2008 (20-03-56).txt

          Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
          Eléments examinés: 93998
          Temps écoulé: 19 minute(s), 24 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 0

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          (Aucun élément nuisible détecté)
          voila le raport malwar en mode sans echec
          0
      5. Salut,
        Et le rapport MalwaresByte's ?

        Tu l'as ?

        C'est MBAM et Ccleaner qu'il faut faire en MSE pas HiJackT !

        Alors,
        on continue :
        > Télécharge Clean (de Malekal Morte) (différent de Ccleaner)

        > Télécharge SDFix (de AndyManchesta) sur ton bureau :
        - Double clique sur l'archive SDFix qui à été créé sur le Bureau et installe le programme (l'installation va créer un dossier (à la racine du disque dur par défaut) nommé SDFix. Ferme ensuite le programme.

        > Commence par faire un copier/coller de ce poste (cette manip.): (conseillé)
        Ouvre un nouveau fichier Bloc notes (clique sur "Démarrer" => "Programmes" =>"Accessoires" => "Bloc notes"),
        puis fait un copier/coller de tout le contenu de la fenêtre de ce poste dans le fichier texte.
        Sauvegarde le sur le bureau, tu pourras alors y avoir accès même déconnecté ou en mode sans échec.

        > Démarre en mode sans échec : (image). Si problème : tuto ici

        > Pour Clean (encore en mode sans échec) :
        - Double-clic sur clean.cmd
        - Une fenêtre va apparaître, choisis l'option 2, suis les consignes et poste le rapport clean (Le rapport clean se trouve ici : C:\rapport_clean.txt)
        NB : Si besoin : Tuto

        > Pour SDFix (toujours en mode sans échec) :
        - Vas dans c:/SDFix et double-clique sur RunThis.bat
        - Appuie sur < Y > puis < Entrée >....Le nettoyage commence....patience...
        - Le programme va te demander de relancer le PC, frappe une touche...
        - Le nettoyage se termine...un rapport apparait...
        -Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse

        > Relance ton PC en mode normal

        > Relance Hijackthis :
        Puis sélectionne < do a system scan and save a logfile >,
        Et envoie moi, par collier/coller, ton log Hijackthis,

        Bon courage,

        A+
        0
        1. Malwarebytes' Anti-Malware 1.20
          Version de la base de données: 945
          Windows 6.0.6000

          20:46:20 13/07/2008
          mbam-log-7-13-2008 (20-46-20).txt

          Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
          Eléments examinés: 94178
          Temps écoulé: 17 minute(s), 27 second(s)

          Processus mémoire infecté(s): 0
          Module(s) mémoire infecté(s): 0
          Clé(s) du Registre infectée(s): 0
          Valeur(s) du Registre infectée(s): 0
          Elément(s) de données du Registre infecté(s): 0
          Dossier(s) infecté(s): 0
          Fichier(s) infecté(s): 10

          Processus mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Module(s) mémoire infecté(s):
          (Aucun élément nuisible détecté)

          Clé(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Valeur(s) du Registre infectée(s):
          (Aucun élément nuisible détecté)

          Elément(s) de données du Registre infecté(s):
          (Aucun élément nuisible détecté)

          Dossier(s) infecté(s):
          (Aucun élément nuisible détecté)

          Fichier(s) infecté(s):
          C:\Users\pierre\AppData\Local\Temp\byXRhfEU.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Users\pierre\AppData\Local\Temp\ddcyWQkI.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Users\pierre\AppData\Local\Temp\pnxjlknq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Users\pierre\AppData\Local\Temp\tmp0000ed1b (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Users\pierre\AppData\Local\Temp\tmp00010b36 (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Users\pierre\AppData\Local\Temp\tmp00011006 (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Users\pierre\AppData\Local\Temp\tmp000119b7 (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Users\pierre\AppData\Local\Temp\urqNdBUo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Users\pierre\AppData\Local\Temp\vsifrvel.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
          C:\Users\pierre\AppData\Local\Temp\vxxppajn.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
          0
      6. Si tu veux tout savoir,
        tes crasses se trouvent ici :

        O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\pierre\AppData\Local\Temp\efcBuRJC.dll,c
        O4 - HKCU\..\Run: [a893dd27] rundll32.exe "C:\Users\pierre\AppData\Local\Temp\fujxnjvm.dll",b


        Alors fait le MBAM et le Ccleaner puis poste un Nouveau HiJackT.

        Ne fixe pas dans HJT pour l'instant.

        A+
        0
        1. ok je suis entrain de faire l analyse je te tien aux courant ce soir merçi a +
          0
        2. @mark9De rien en MSE l'analyse.

          c'est mieux....
          0
        3. @Utilisateur anonymeLogfile of Trend Micro HijackThis v2.0.2
          Scan saved at 17:02:50, on 13/07/2008
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16681)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Windows Defender\MSASCui.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Apoint2K\Apoint.exe
          C:\Program Files\Hotkey Utility\tray.exe
          C:\Program Files\Power Manager\PM.exe
          C:\Program Files\Light Sensor Utility\Sensor.exe
          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Windows\system32\wbem\unsecapp.exe
          C:\Program Files\Apoint2K\ApMsgFwd.exe
          C:\Program Files\Apoint2K\Apntex.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.tele2internet.fr/?skip_split_page
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O1 - Hosts: ::1 localhost
          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {43F7497C-7687-4DEA-A057-F21BD81BC896} - (no file)
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
          O4 - HKLM\..\Run: [FIC HotKey] C:\Program Files\Hotkey Utility\tray.exe
          O4 - HKLM\..\Run: [PowerManager] C:\Program Files\Power Manager\PM.exe
          O4 - HKLM\..\Run: [Silent Mode] C:\Program Files\Light Sensor Utility\Sensor.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [recinfo706] c:\RecInfo\RecInfo.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
          O23 - Service: Planificateur LiveUpdate automatique - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
          O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
          O23 - Service: Fujitsu Siemens Computers Diagnostic Testhandler (TestHandler) - Fujitsu Siemens Computers - C:\firststeps\OnlineDiagnostic\TestManager\TestHandler.exe
          O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
          0
      7. fais malware mais tu ne m as toujours pas repondu.

        et pour malware lis comme il faut, c est pas complique de faire ce qui est indique
        0
        1. j ais lancer l analyse mais je ne vois tjr pas a quoi je ne té toujour pas répondu
          0
      8. dsl j avais pas tout lu je fais et je vous tient au courant plus tard merçi a tous a +
        0
        1. bien vu
          0
          1. jespere que ces ça que tu voulais j aten ton avis
            0
        2. Bonjour,

          Fais ceci :
          > Rends toi sur le site virustotal et fais analyser le fichier suivant stp : (copie/colle la ligne dans le cadre "envoyé un fichier")
          Si problème : http://pageperso.aol.fr/loraline60/virus_total.htm

          C:\Program Files\Light Sensor Utility\Sensor.exe

          et poste le résultat par copier/coller stp (ou le lien http, c'est plus rapide et plus simple).

          Ensuite,
          > Les logiciels suivants (MalwareByte's Anti-Malware et Ccleaner) te seront utiles par la suite - ils sont à conserver...

          > Télécharge MalwareByte's Anti-Malware :
          - Installe le programme puis lance le stp.
          NB : S'il te manque COMCTL32.OCX alors télécharge le ici
          - Fais les mises à jour (clique sur "Mises à jour" puis "Recherche de mises à jour") puis ferme le programme.
          NB : Si tu as besoin : Tuto

          > Télécharge et installe Ccleaner :
          - Fais les mises à jour puis ferme le programme.
          Si besoin est tu trouveras des Tutoriaux : ici, ici et là.

          > Commence par faire un copier/coller de ce poste (cette manip.): (conseillé)
          Ouvre un nouveau fichier Bloc notes (clique sur "Démarrer" => "Programmes" =>"Accessoires" => "Bloc notes"),
          puis fait un copier/coller de tout le contenu de la fenêtre de ce poste dans le fichier texte.
          Sauvegarde le sur le bureau, tu pourras alors y avoir accès même déconnecté ou en mode sans échec.

          > Démarre en mode sans échec : (image). Si problème : tuto ici

          > Lance MalwareByte's Anti-Malware,
          - Clique sur "Executer un examen complet" puis "Rechercher" et sélectionne tous tes disques durs => le scan débute....patiente...
          - A la fin du scanne, clique sur "supprimer" (Si des éléments sont difficiles à supprimer, un message te demandera de redémarrer : clique sur "Oui" alors)
          - après suppression des infections : un rapport va être généré : sauvegarde le et poste le sur forum.

          > Lance Ccleaner,
          - Choisi l’onglet "Options" puis clique sur "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures" (tout doit être supprimé).
          - Dans l'onglet "Nettoyeur" clique sur "Analyse".
          - Une fois l'analyse terminée, clique sur "Lancer le Nettoyage".
          - Dans l'onglet "registre" => Recherches des erreurs => Réparer les erreurs sélectionnées => enregistre une sauvegarde => corriger toutes erreurs sélectionnées => ok => fermer.
          N.B : Si Ccleaner te propose d'enregistrer une sauvegarde, reponds oui et enregistre sous 'Bureau'
          Recommence jusqu’à ce qu’il ne trouve plus rien (cela varie en général entre 1 et 4 fois).

          > Relance ton PC en mode normal

          > Relance Hijackthis :
          Puis sélectionne < do a system scan and save a logfile >,
          Et envoie moi, par collier/coller, ton log Hijackthis,

          Bon courage,

          A+
          0
          1. ok
            0
          2. @mark9Au passage tu as mal désinstallé Norton.

            Utilise cet utilitaire pour bien le supprimer : http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

            A+
            0
          3. ces ça? | עברית | | Slovenščina | Dansk | Русский | Română | Türkçe | Nederlands | Ελληνικά | Svenska | Português | Italiano | | | Magyar | Deutsch | Česky | Polski | Español | English
            Virustotal est un service qui analyse les fichiers suspects et facilite la détection rapide des virus, vers, chevaux de Troie et toutes sortes de malwares détectés par les moteurs antivirus. Plus d'informations...
            Fichier Sensor.exe reçu le 2008.07.13 16:07:39 (CET)
            Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

            Résultat: 0/33 (0%)
            en train de charger les informations du serveur...
            Votre fichier est dans la file d'attente, en position: ___.
            L'heure estimée de démarrage est entre ___ et ___ .
            Ne fermez pas la fenêtre avant la fin de l'analyse.
            L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
            Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
            Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
            les résultats seront affichés au fur et à mesure de leur génération.
            Formaté Impression des résultats
            Votre fichier a expiré ou n'existe pas.
            Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

            Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
            Email:

            Antivirus Version Dernière mise à jour Résultat
            AhnLab-V3 2008.7.11.0 2008.07.11 -
            AntiVir 7.8.0.64 2008.07.11 -
            Authentium 5.1.0.4 2008.07.13 -
            Avast 4.8.1195.0 2008.07.13 -
            AVG 7.5.0.516 2008.07.12 -
            BitDefender 7.2 2008.07.13 -
            CAT-QuickHeal 9.50 2008.07.11 -
            ClamAV 0.93.1 2008.07.13 -
            DrWeb 4.44.0.09170 2008.07.12 -
            eSafe 7.0.17.0 2008.07.13 -
            eTrust-Vet 31.6.5949 2008.07.12 -
            Ewido 4.0 2008.07.13 -
            F-Prot 4.4.4.56 2008.07.13 -
            F-Secure 7.60.13501.0 2008.07.12 -
            Fortinet 3.14.0.0 2008.07.13 -
            GData 2.0.7306.1023 2008.07.13 -
            Ikarus T3.1.1.26.0 2008.07.13 -
            Kaspersky 7.0.0.125 2008.07.13 -
            McAfee 5337 2008.07.11 -
            Microsoft 1.3704 2008.07.13 -
            NOD32v2 3263 2008.07.11 -
            Norman 5.80.02 2008.07.11 -
            Panda 9.0.0.4 2008.07.13 -
            Prevx1 V2 2008.07.13 -
            Rising 20.52.62.00 2008.07.13 -
            Sophos 4.31.0 2008.07.13 -
            Sunbelt 3.1.1536.1 2008.07.12 -
            Symantec 10 2008.07.13 -
            TheHacker 6.2.96.378 2008.07.13 -
            TrendMicro 8.700.0.1004 2008.07.11 -
            VBA32 3.12.6.9 2008.07.12 -
            VirusBuster 4.5.11.0 2008.07.12 -
            Webwasher-Gateway 6.6.2 2008.07.11 -
            Information additionnelle
            File size: 253952 bytes
            MD5...: 1ee4ae45b9f00a5b0868db019bd66b63
            SHA1..: 93ded1ad21f83f1fa18fc7a5ad7ba311f087f5b1
            SHA256: 864e003ddceeae160df4e034df562220b54dee564b1e7043c38ea74e9aeb110b
            SHA512: 910427f3b4c457d428f473f701d8316e9744a452a0b8072bb2df9c74e4394e2b
            629d6c2f4a96f31762fb65ff40e2c7b302de286cfdf65aab4479fe151cabf9ef
            PEiD..: -
            PEInfo: PE Structure information

            ( base data )
            entrypointaddress.: 0x417139
            timedatestamp.....: 0x4681c3c4 (Wed Jun 27 01:56:20 2007)
            machinetype.......: 0x14c (I386)

            ( 4 sections )
            name viradd virsiz rawdsiz ntrpy md5
            .text 0x1000 0x27896 0x28000 6.62 6c98951f0ce91a57766bbdeda7649ecd
            .rdata 0x29000 0xa442 0xb000 4.74 201941ae3cf355316ea8ebe522ef2468
            .data 0x34000 0x5d3c 0x3000 2.99 3d3df4a634eecaeb97a1053f43e793db
            .rsrc 0x3a000 0x61c8 0x7000 3.32 7188148765afce9cf75658c82a4f5ee2

            ( 10 imports )
            > WINIO.dll: GetPortVal, ShutdownWinIo, InitializeWinIo, RemoveWinIoDriver, InstallWinIoDriver, SetPortVal
            > WTSAPI32.dll: WTSRegisterSessionNotification, WTSUnRegisterSessionNotification
            > KERNEL32.dll: GetCurrentProcess, CreateFileA, SetErrorMode, ExitProcess, RtlUnwind, HeapAlloc, HeapFree, HeapReAlloc, VirtualAlloc, GetCommandLineA, GetProcessHeap, GetStartupInfoA, RaiseException, HeapSize, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetACP, GetStdHandle, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, VirtualFree, HeapDestroy, HeapCreate, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, FlushFileBuffers, SetFilePointer, WriteFile, ReadFile, WritePrivateProfileStringA, GetOEMCP, GetCPInfo, GlobalFlags, GetThreadLocale, InterlockedIncrement, TlsFree, DeleteCriticalSection, LocalReAlloc, TlsSetValue, TlsAlloc, InitializeCriticalSection, GlobalHandle, GlobalReAlloc, EnterCriticalSection, TlsGetValue, LeaveCriticalSection, LocalAlloc, GetCurrentThread, ConvertDefaultLocale, EnumResourceLanguagesA, GetLocaleInfoA, lstrcmpA, FreeResource, GetCurrentThreadId, GlobalFindAtomA, GlobalDeleteAtom, lstrcmpW, GetVersionExA, GetCurrentProcessId, LoadLibraryA, GlobalGetAtomNameA, GlobalAddAtomA, FreeLibrary, InterlockedDecrement, GetModuleFileNameW, GetModuleHandleA, GetProcAddress, GlobalFree, GlobalAlloc, GlobalLock, GlobalUnlock, FormatMessageA, LocalFree, MulDiv, SetLastError, lstrlenA, CompareStringA, GetVersion, MultiByteToWideChar, InterlockedExchange, CreateMutexA, GetLastError, GetPrivateProfileStringA, GetModuleFileNameA, SetCurrentDirectoryA, WideCharToMultiByte, FindResourceA, LoadResource, LockResource, SizeofResource, Sleep, OpenEventA, WaitForSingleObject, CloseHandle
            > USER32.dll: GetDC, ReleaseDC, GetWindowDC, BeginPaint, EndPaint, ValidateRect, TranslateMessage, GetMessageA, ShowOwnedPopups, GetSysColorBrush, LoadCursorA, UnregisterClassA, InflateRect, GetMenuItemInfoA, IsDialogMessageA, SetMenuItemBitmaps, GetMenuCheckMarkDimensions, LoadBitmapA, ModifyMenuA, EnableMenuItem, CheckMenuItem, SendDlgItemMessageA, GetClassLongA, SetPropA, GetPropA, RemovePropA, GetWindowTextA, GetForegroundWindow, DispatchMessageA, BeginDeferWindowPos, EndDeferWindowPos, GetTopWindow, DestroyWindow, GetMessageTime, GetMessagePos, MapWindowPoints, GetClientRect, CreateWindowExA, ClientToScreen, RegisterClassA, AdjustWindowRectEx, ScreenToClient, DeferWindowPos, DefWindowProcA, CallWindowProcA, SystemParametersInfoA, GetWindowPlacement, GetSystemMetrics, UnpackDDElParam, ReuseDDElParam, GetClassNameA, GetSysColor, WinHelpA, SetWindowPos, SetFocus, GetWindowThreadProcessId, GetFocus, EqualRect, SetWindowLongA, GetKeyState, GetDlgCtrlID, GetMenu, SetCursor, PeekMessageA, GetCapture, ReleaseCapture, LoadAcceleratorsA, SetActiveWindow, IsWindowVisible, InvalidateRect, IsIconic, InsertMenuItemA, CreatePopupMenu, GetClassInfoA, IntersectRect, OffsetRect, SetRectEmpty, CopyRect, GetLastActivePopup, BringWindowToTop, SetMenu, GetDesktopWindow, GetWindow, ShowWindow, GetWindowLongA, IsWindow, TranslateAcceleratorA, GetMenuState, GetMenuItemID, GetMenuItemCount, EnumDisplaySettingsExA, GetDlgItem, SetWindowTextA, GetParent, GetWindowRect, PtInRect, GrayStringA, DrawTextExA, DrawTextA, TabbedTextOutA, FillRect, PostQuitMessage, CreateDialogIndirectParamA, GetNextDlgTabItem, EndDialog, GetClassInfoExA, MoveWindow, FindWindowA, EnableWindow, UpdateWindow, GetCursorPos, LoadMenuA, SendMessageA, PostMessageA, GetSubMenu, SetForegroundWindow, TrackPopupMenu, DestroyMenu, RegisterWindowMessageA, GetActiveWindow, SetWindowsHookExA, LoadIconA, DestroyIcon, SetTimer, MessageBoxA, KillTimer, CallNextHookEx, UnhookWindowsHookEx, IsWindowEnabled
            > GDI32.dll: RectVisible, TextOutA, ExtTextOutA, Escape, SelectObject, SetViewportOrgEx, OffsetViewportOrgEx, SetViewportExtEx, ScaleViewportExtEx, SetWindowExtEx, ScaleWindowExtEx, DeleteDC, CreatePatternBrush, GetStockObject, PtVisible, CreateSolidBrush, CreateFontIndirectA, GetTextExtentPoint32A, DeleteObject, GetPixel, BitBlt, GetObjectA, SetBkColor, SetTextColor, GetClipBox, CreateCompatibleDC, CreateCompatibleBitmap, GetDeviceCaps, SetMapMode, SetBkMode, RestoreDC, SaveDC, CreateBitmap
            > WINSPOOL.DRV: OpenPrinterA, ClosePrinter, DocumentPropertiesA
            > ADVAPI32.dll: RegQueryValueA, RegEnumKeyA, RegOpenKeyExA, RegDeleteKeyA, RegDeleteValueA, RegOpenKeyA, RegQueryValueExA, RegCreateKeyA, RegSetValueExA, RegCloseKey, RegCreateKeyExA
            > SHELL32.dll: DragFinish, DragQueryFileA, Shell_NotifyIconA
            > SHLWAPI.dll: PathFindFileNameA, PathFindExtensionA
            > OLEAUT32.dll: -, -, -

            ( 0 exports )

            ATTENTION: VirusTotal est un service gratuit offert par Hispasec Sistemas. Il n'y a aucune garantie quant à la disponibilité et la continuité de ce service. Bien que le taux de détection permis par l'utilisation de multiples moteurs antivirus soit bien supérieur à celui offert par seulement un produit, ces résultats NE garantissent PAS qu'un fichier est sans danger. Il n'y a actuellement aucune solution qui offre un taux d'efficacité de 100% pour la détection des virus et malwares.

            VirusTotal © Hispasec Sistemas - Blog - Contact: info@virustotal.com - Terms of Service & Privacy Policy
            0
          4. @Utilisateur anonymeok merci je le vire correctement maintenant(jespere)et pour mon probleme de virus sans et ouje fais quoi svp
            0
        3. as tu bien fais pour le compte d utilisateur, tu veux que je t aide mais tu ne reponds pas aux questions mais bon peu importe.

          Telecharges malwares bytes anti malwares :

          Malwarebytes Anti-Malware: http://www.malwarebytes.org/mbam/program/mbam-setup.exe

          Tutoriel Malwarebytes Anti-Malware: https://forum.pcastuces.com/malwarebytes_antimalwares___tutoriel-f31s3.htm
          fais comme indique,mise a jour , scan complet en mode sans echec et les rapports.

          garde le et lance un scan tout les mois comme indique.
          0
          1. il me semble t avoir repondu a tou j ai desactiver mon compte je fais le reste je te tien au couran
            0
          2. @mark9ou m as tu repondu????a ces questions il faut me le montrer.
            0
        • 1
        • 2