Virus Spyware

Bonjour, J'ai un nouveau soucis avec mon ordinateur.

Suite à un téléchargement, j'ai attraper un virus qui m'empêchais tout d'abord d'aller sur internet, avec un message m'affichant que mon ordinateur souffre d'un "manque de protection". Donc impossible d'aller sur une page internet.

De plus, il m'était conseillé d'installer un logiciel qui soit disant protègerait mieu mon ordinateur, je crois que c'était: ie-av.exe le nom.

Voilà suite à un entretient avec une personne du site, j'ai utiliser Malware Byte's, qui m'a trouver pas mal de fichier infectés.

Mais après quoi j'ai des fenêtres qui s'ouvrent toutes seules, et me demande de télécharger des logiciels de protection.

Que dois-je faire? Merci d'avance !!
Configuration: Windows Vista
Internet Explorer 7.0

33 réponses

Résumé de la discussion

Une infection par un virus et ses composants malveillants survient après un téléchargement, bloquant l'accès à Internet et affichant un message de manque de protection, tout en suggérant l'installation d'un logiciel prétendument protecteur. Des analyses avec Malwarebytes' Anti-Malware ont détecté de nombreux éléments infectés, notamment Trojan.Vundo, et ont permis leur mise en quarantaine et suppression partielle. Le rapport HiJackThis après désinfection montre des entrées suspectes et des composants malveillants supprimés ou quarantinés, attestant d'un nettoyage important mais nécessitant une vérification approfondie des extensions et des scripts actifs. Des éléments utiles indiquent que la navigation et les téléchargements doivent être surveillés et que des mesures complémentaires comme l'examen des paramètres proxy et des barres d'outils sont recommandées pour prévenir une réinfection.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    -> Relance HijackThis cliques sur « scanner seulement » ou (« do a scan only »),
    coche les cases devant ces lignes :

    O2 - BHO: (no name) - {42C613FF-E3E7-4733-AB08-04227896E440} - (no file)
    O2 - BHO: (no name) - {e10b3d67-90f8-207a-3363-3efaf17a96f2} - (no file)


    et ensuite ferme toutes les fenêtres actives autres que HijackThis!, navigateur inclus,
    puis clique "Fix checked"( ou « fixer objet »). Ferme HijackThis!

    tu as installé de nouveaux prog ?

    Il va falloir analyser un ou des fichier(s) suspect(s) !

    Il se peut qu'il se trouvent dans les " dossiers cachés " du systeme.
    Il faut donc les rendre visibles pour le scan.

    Pour afficher les dossiers et fichiers cachés:

    Panneau de configuration > Options des dossiers > onglet Affichage.

    Coche Afficher les fichiers et dossiers cachés,
    Décoche Masquer les extensions de fichiers connus
    Décoche Masquer les fichiers protégés du Système.
    Un message de mise en garde va apparaitre. Clique sur OK pour confirmer ton choix.
    Les fichiers et dossiers cachés du système apparaitront alors dans l'explorateur Windows en transparence.

    Rends toi sur ce site :

    https://www.virustotal.com/gui/

    Clique sur parcourir et cherche ces fichiers : C:\Program Files\GameSpy\Comrade\Comrade.exe
    C:\Windows\system32\mbftpemgpduqfg.dll


    Clique sur Send File.

    Un rapport va s'élaborer ligne à ligne.

    Attends la fin. Il doit comprendre la taille du fichier envoyé.

    Sauvegarde le rapport avec le bloc-note.
    ---------------------------------------------------------------------------------------------------------------------------------------------------------------

    Télécharge MSNFix.zip (de !aur3n7) sur ton bureau:
    http://sosvirus.changelog.fr/MSNFix.zip

    Décompresse-le (clic droit >> Extraire ici) et place les fichiers dans C:\MSNFix (très important).

    Double cliquer sur le fichier MSNFix.bat.
    - Exécutez l'option R.
    -- Si l'infection est détectée, un message l'indiquera et il suffira de presser une touche pour lancer le nettoyage

    Note :
    Si une erreur de suppression est détectée un message s'affichera demandant de redémarrer l'ordinateur afin de terminer les opérations. Dans ce cas il suffit de redémarrer l'ordinateur en mode normal

    - Le rapport sera enregistré dans le même dossier que MSNFix sous forme date_heure.txt

    pour VISTA :

    désactive l'UAC:https://forum.malekal.com/viewtopic.php?f=59&t=6517

    Copie le dans ta réponse.
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:31:29, on 17/08/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16681)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Softwin\BitDefender10\bdmcon.exe
      C:\Program Files\Softwin\BitDefender10\bdagent.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Windows\FixCamera.exe
      C:\Windows\System32\rundll32.exe
      C:\Windows\tsnp2std.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Windows\vsnp2std.exe
      C:\Program Files\PowerISO\PWRISOVM.EXE
      C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\ehome\ehtray.exe
      C:\Windows\ehome\ehmsas.exe
      C:\Program Files\Steam\Steam.exe
      C:\Program Files\Ares\Ares.exe
      C:\Windows\System32\mobsync.exe
      C:\Program Files\DAEMON Tools Lite\daemon.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\explorer.exe
      C:\Users\nicolas\AppData\Local\Temp\Rar$EX00.194\TeamSpeak 3.exe
      C:\Users\nicolas\AppData\Local\Temp\Rar$EX00.461\TeamSpeak 3.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\HiJackThis\HiJackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: D - {0BDA86A8-FFF1-3332-8473-748579FC625D} - C:\Windows\wxml46820.dll
      O2 - BHO: (no name) - {42C613FF-E3E7-4733-AB08-04227896E440} - (no file)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: (no name) - {e10b3d67-90f8-207a-3363-3efaf17a96f2} - (no file)
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\GoogleEULA\EULALauncher.exe
      O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [FixCamera] C:\Windows\FixCamera.exe
      O4 - HKLM\..\Run: [tsnp2std] C:\Windows\tsnp2std.exe
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
      O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
      O4 - HKLM\..\Run: [{62dd4334-c0ca-6610-794f-b2f11170595d}] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\mbftpemgpduqfg.dll" DllStart
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
      O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
      O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
      O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
      O4 - HKCU\..\Run: [Comrade.exe] C:\Program Files\GameSpy\Comrade\Comrade.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
      O13 - Gopher Prefix:
      O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
      O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
      O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
      O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
      O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
      O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
      O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
      O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
      1. Contributeur sécurité
        Est-ce que je dois supprimer le dossier: ReadyBoot aussi?

        A toi de voir , Readyboost sert a "booster" ton pc avec un disque amovible (du style cle usb); il allege la memoire vive en greffant une partie sur une clé ou autre . tu peux le garder comme tu peux le virer ,a savoir si tu t'en servira ?

        recolle moi un hijack pour finir ensuite .
        1. Voilà j'ai fais CleanUp, maintenant je vais supprimer les fichiers.

          Est-ce que je dois supprimer le dossier: ReadyBoot aussi?
          1. Contributeur sécurité
            Drwebcureit a fait du bon boulot !

            tu vas ajouter ceci :

            Vide tes fichiers temporaires avec ceci:
            ->Clean Up 40:
            http://pageperso.aol.fr/balltrap34/CleanUp40.exe
            ->aide en image:(merci a Balltrap34)
            http://pageperso.aol.fr/balltrap34/democleanup.htm

            click sur option et décoche la case devant : delete prefect files

            vide le manuellement :

            :: Le contenu du dossier prefetch ::

            * C:\WINDOWS\Prefetch <= sauf le fichier layout.ini

            * Ne pas oublier de vider la corbeille !
            1. D'accord voici le rapport:

              winauq32.rom;c:\windows\system32;Trojan.Mssmsgs.2;Supprimé.;
              psexec.cfexe;C:\327882R2FWJFW;Program.PsExec.171;Irréparable.Quarantaine.;
              kb65666[1];C:\Documents and Settings\nicolas\AppData\Local\Application Data\Microsoft\Windows\Temporary Internet Files\Content.IE5\14D69ZP;Trojan.Starter.561;Supprimé.;
              rbadsvag.exe;C:\Windows\System32;Trojan.Starter.561;Supprimé.;
              1. Contributeur sécurité
                Je l'ouvre avec un fichier .txt? oui pas de soucis .
                1. Merci beaucoup pour tes réponses c'est vraiment sympa.
                  Je voudrais pouvoir mettre le rapport DrWeb.csv sur le forum, mais comment faire? Je l'ouvre avec un fichier .txt?
                  1. Ok j'utiliserais cette méthode quand j'aurais terminer avec Dr.Web.
                    Sinon pour pas m'embêter, Mozilla Firefox est peut-être une bonne solution !
                    1. Contributeur sécurité
                      On va essayer ca pour explorer :

                      télécharge Iefix a cette adresse : IEFIX

                      décompresse le et exécute le .
                      1. Bah un message d'erreur comment dire... Ca me dit: "Internet Explorer à cesser de fonctionner". Dans ce message j'ai deux solution: Soit je redémarre Internet Explorer, soit je cherche en ligne une solution.

                        Je suis en train de faire l'analyse que tu m'as demandé de faire.
                        1. Contributeur sécurité
                          est ce que tu me donné ce message d'erreur ?pour faire avancer les choses .
                          1. Avant de faire quoi que ce soit, est-ce que ça résoudra le nouveau problème, c'est-à-dire que ma fenêtre internet m'affiche un message d'erreur toutes les minutes et se ferme automatiquement?
                            1. Contributeur sécurité
                              ca ne sert a rien d'ouvrir cinquante topics en meme temps (si juste a planter ton pc peut etre !)

                              poste moi le rapport de Drweb cureIt .
                              1. Contributeur sécurité
                                Voilà suite à un entretient avec une personne du site, j'ai utiliser Malware Byte's, qui m'a trouver pas mal de fichier infectés. >>>c'est pour cela que je ne t'ais pas fait repasser MBAM !
                                tu as du faire un scan sans supprimer ce qu'il avais trouvé !

                                Qui t'as demandé de télécharger Vundofix ??

                                1. Avant d'utiliser ta méthode j'ai refais une analyse Malware Byte's, voici le rapport d'ailleur :

                                  ***************************************************

                                  Malwarebytes' Anti-Malware 1.24
                                  Version de la base de données: 1026
                                  Windows 6.0.6000

                                  20:26:28 13/08/2008
                                  mbam-log-8-13-2008 (20-26-28).txt

                                  Type de recherche: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|J:\|L:\|)
                                  Eléments examinés: 168417
                                  Temps écoulé: 31 minute(s), 37 second(s)

                                  Processus mémoire infecté(s): 0
                                  Module(s) mémoire infecté(s): 1
                                  Clé(s) du Registre infectée(s): 34
                                  Valeur(s) du Registre infectée(s): 11
                                  Elément(s) de données du Registre infecté(s): 2
                                  Dossier(s) infecté(s): 2
                                  Fichier(s) infecté(s): 32

                                  Processus mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Module(s) mémoire infecté(s):
                                  C:\Windows\System32\hgGvsSjh.dll (Trojan.Vundo) -> Delete on reboot.

                                  Clé(s) du Registre infectée(s):
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90fbeab0-1f63-4d52-9589-a28816c6ab86} (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\CLSID\{90fbeab0-1f63-4d52-9589-a28816c6ab86} (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cf75561a-9b03-4bc0-8ffc-bda86f4d636a} (Trojan.Vundo) -> Delete on reboot.
                                  HKEY_CLASSES_ROOT\CLSID\{cf75561a-9b03-4bc0-8ffc-bda86f4d636a} (Trojan.Vundo) -> Delete on reboot.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1ae61c0e-c13a-4bff-aef6-26ef67fc5fba} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\CLSID\{1ae61c0e-c13a-4bff-aef6-26ef67fc5fba} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fb6731bf-ff71-44e5-b184-93a6708e4499} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\CLSID\{fb6731bf-ff71-44e5-b184-93a6708e4499} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\Interface\{0b6ef17e-18e5-4449-86ea-64c82d596eae} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\Interface\{b1e68d42-02c4-465b-8368-5ed9b732e22d} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\Typelib\{6d0111e3-3060-4d23-b2bc-42ed86cbe9a3} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\CLSID\{72a128e0-2240-40c8-9e92-5387d64f839e} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\xmllib.xmldp (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\xmllib.xmldp.1 (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\Interface\{4937d5d1-2039-409a-bd83-fec9b39b2356} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\Interface\{caf9d798-c659-4b9b-8e19-ee27c3d04ee7} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\Typelib\{15c7d7ad-a87a-4c0d-9d8b-637fcd3488ef} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\CLSID\{d26aab3b-b0dd-456c-a7e5-4da9565fd6ee} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d26aab3b-b0dd-456c-a7e5-4da9565fd6ee} (Trojan.BHO) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\IEAntiVirus (Rogue.IEAntiVirus) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\IE AntiVirus (Rogue.IEAntiVirus) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\CLSID\{fffb03ad-a461-4b99-9a23-d3b127d7c995} (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\bhonew.bho (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                  HKEY_CLASSES_ROOT\bhonew.bho.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.

                                  Valeur(s) du Registre infectée(s):
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\1222ffb9 (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\runner1 (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antispy (Rogue.IEAntiVirus) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm1111cc25 (Trojan.Agent) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Host Process (Worm.IRCBot) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Malware.Trace) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{fffb03ad-a461-4b99-9a23-d3b127d7c995} (Trojan.Vundo) -> Quarantined and deleted successfully.

                                  Elément(s) de données du Registre infecté(s):
                                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\hggvssjh -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\hggvssjh -> Delete on reboot.

                                  Dossier(s) infecté(s):
                                  C:\Windows\System32\kBin02 (Trojan.Agent) -> Quarantined and deleted successfully.
                                  C:\Program Files\IEAntiVirus (Rogue.IEAntiVirus) -> Quarantined and deleted successfully.

                                  Fichier(s) infecté(s):
                                  C:\Windows\System32\skxdol.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\hgGvsSjh.dll (Trojan.Vundo) -> Delete on reboot.
                                  C:\Windows\System32\hjSsvGgh.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\hjSsvGgh.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\hqwyfjto.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\otjfywqh.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Users\nicolas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N8MJYLAQ\3077htsbdjyf[1].dll (Trojan.BHO) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\ihkxosrx.dll (Trojan.BHO) -> Quarantined and deleted successfully.
                                  C:\Windows\mrofinu1188.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  C:\Windows\xml2u32h.dll (Trojan.BHO) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\goldman.dll (Trojan.BHO) -> Quarantined and deleted successfully.
                                  C:\wmcodec_update.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                  C:\Users\nicolas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SN3LXJR5\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Users\nicolas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XH5U0ZO7\17PHolmes[1].cmt (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  C:\Users\nicolas\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XH5U0ZO7\kb767887[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\fyprjxst.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\kBin02\kBin022328.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  C:\Program Files\IEAntiVirus\ieav.db2 (Rogue.IEAntiVirus) -> Quarantined and deleted successfully.
                                  C:\Program Files\IEAntiVirus\ieav.db3 (Rogue.IEAntiVirus) -> Quarantined and deleted successfully.
                                  C:\Program Files\IEAntiVirus\scan.exe (Rogue.IEAntiVirus) -> Quarantined and deleted successfully.
                                  C:\Program Files\IEAntiVirus\uninst.exe (Rogue.IEAntiVirus) -> Quarantined and deleted successfully.
                                  C:\Program Files\KB46903.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\ergwjxoa.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\pac.txt (Malware.Trace) -> Quarantined and deleted successfully.
                                  C:\Users\nicolas\svchost.exe (Worm.IRCBot) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\mlJYqRig.dll (Malware.Trace) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\mlJCVPiH.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\ljJASjHB.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Windows\System32\fccbCvTN.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                  C:\Users\nicolas\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IE AntiVirus 3.4.lnk (Rogue.IEAntiVirus) -> Quarantined and deleted successfully.
                                  C:\Users\nicolas\Desktop\IE AntiVirus 3.4.lnk (Rogue.IEAntiVirus) -> Quarantined and deleted successfully.
                                  C:\Users\nicolas\ctfmon.exe (Trojan.Agent) -> Quarantined and deleted successfully.

                                  Et voici le rapport HiJackThis après la désinfection de Malware Byte's :

                                  ***************************************************************

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 10:37:18, on 15/08/2008
                                  Platform: Windows Vista (WinNT 6.00.1904)
                                  MSIE: Internet Explorer v7.00 (7.00.6000.16681)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\Explorer.EXE
                                  C:\Program Files\Windows Defender\MSASCui.exe
                                  C:\Windows\RtHDVCpl.exe
                                  C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                                  C:\Program Files\Softwin\BitDefender10\bdagent.exe
                                  C:\Windows\System32\rundll32.exe
                                  C:\Windows\System32\rundll32.exe
                                  C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                  C:\Windows\FixCamera.exe
                                  C:\Windows\tsnp2std.exe
                                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                  C:\Program Files\QuickTime\qttask.exe
                                  C:\Windows\vsnp2std.exe
                                  C:\Program Files\PowerISO\PWRISOVM.EXE
                                  C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Windows\ehome\ehtray.exe
                                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                  C:\Program Files\Steam\Steam.exe
                                  C:\Windows\ehome\ehmsas.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Program Files\Skype\Phone\Skype.exe
                                  C:\Program Files\DAEMON Tools Lite\daemon.exe
                                  C:\Windows\System32\rundll32.exe
                                  C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  C:\Program Files\Skype\Plugin Manager\skypePM.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                  C:\Program Files\Internet Explorer\iexplore.exe
                                  C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                                  C:\Program Files\Teamspeak2_RC2\TeamSpeak.exe
                                  C:\HiJackThis\HiJackThis.exe

                                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://actus.sfr.fr
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                  O1 - Hosts: ::1 localhost
                                  O2 - BHO: D - {0BDA86A8-FFF1-3332-8473-748579FC625D} - C:\Windows\wxml46820.dll
                                  O2 - BHO: (no name) - {42C613FF-E3E7-4733-AB08-04227896E440} - (no file)
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                  O2 - BHO: (no name) - {e10b3d67-90f8-207a-3363-3efaf17a96f2} - (no file)
                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                  O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\GoogleEULA\EULALauncher.exe
                                  O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
                                  O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                                  O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [FixCamera] C:\Windows\FixCamera.exe
                                  O4 - HKLM\..\Run: [tsnp2std] C:\Windows\tsnp2std.exe
                                  O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                  O4 - HKLM\..\Run: [snp2std] C:\Windows\vsnp2std.exe
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [UVS11 Preload] C:\Program Files\Ulead Systems\Ulead VideoStudio 11\uvPL.exe
                                  O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
                                  O4 - HKLM\..\Run: [{62dd4334-c0ca-6610-794f-b2f11170595d}] C:\Windows\System32\Rundll32.exe "C:\Windows\system32\mbftpemgpduqfg.dll" DllStart
                                  O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                  O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
                                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                  O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                                  O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
                                  O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                                  O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                                  O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
                                  O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                                  O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
                                  O4 - HKCU\..\Run: [MSSMSGS] rundll32.exe winauq32.rom,UHeRun
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe -startup
                                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                  O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                  O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                  O13 - Gopher Prefix:
                                  O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                  O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
                                  O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Common Files\Softwin\BitDefender Scan Server\bdss.exe
                                  O23 - Service: Capture Device Service - InterVideo Inc. - C:\Program Files\Common Files\InterVideo\DeviceService\DevSvc.exe
                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                  O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Common Files\Softwin\BitDefender Update Service\livesrv.exe
                                  O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                                  O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                                  O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\SYSTEM32\VundoFixSVC.exe
                                  O23 - Service: BitDefender Communicator (XCOMM) - SOFTWIN S.R.L - C:\Program Files\Common Files\Softwin\BitDefender Communicator\xcommsvr.exe
                                  End of file - 9415 bytes

                                  Y'a-t-il un changement particulier?
                                  1. Contributeur sécurité
                                    Bon on va tenter autre chose :

                                    Télécharge Dr.Web CureIt sur ton Bureau:
                                    ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

                                    * Démarre en mode sans échec.
                                    * Double clique drweb-cureit.exe et ensuite clique sur Analyse ;
                                    * Clique Ok à l'invite de l'analyse rapide. Ce scan permet l'analyse des processus chargés en mémoire ; s'il trouve des processus infectés, clique le bouton Oui pour tout à l'invite.
                                    **Note : une fenêtre s'ouvrira avec options pour "Commander" ou "50% de réduction" ; vous pouvez quitter en cliquant le "X"
                                    * Lorsque le scan rapide est terminé, Clique sur le menu Options >> Changer la configuration;
                                    * Choisis l'onglet "Scanner", et décoche "Analyse heuristique". Clique "Ok"
                                    * De retour à la fenêtre principale : clique pour activer "Analyse complète";
                                    * Clique le bouton avec flèche verte sur la droite, et le scan débutera.
                                    * Clique Oui pour tout à l'invite "Désinfecter ?" lorsqu'un fichier est détecté, et ensuite clique "Désinfecter".
                                    * Lorsque le scan sera complété, regarde si tu peux cliquer sur cet icône, adjacent aux fichiers détectés :
                                    * Si oui, alors clique dessus et ensuite clique sur l'icône "Suivant", au dessous, et choisis Déplacer en quarantaine l'objet indésirable
                                    * Du menu principal de l'outil, au haut à gauche, clique sur le menu Fichier et choisis Enregistrer le rapport
                                    * Sauvegarde le rapport sur ton Bureau. Ce dernier se nommera DrWeb.csv
                                    * Ferme Dr.Web Cureit
                                    * Redémarre ton ordi (*très important*), car certains fichiers peuvent être déplacés/réparés au redémarrage.
                                    * Suite au redémarrage, poste (Copie/Colle) le contenu du rapport de l'outil Dr.Web dans ta prochaine réponse.
                                    • 1
                                    • 2