Virus :cryp fake av not cleanable

Résolu
Bonjour,
j ai un virus :cryp fake av not cleanable avec secuser et avast ne le voit pas ....quelqu un serai assez sympa pour m aider merci d avance
Configuration: Windows XP
Internet Explorer 7.0

18 réponses

  1. comment ces tu le virus que tu a si ton anti-virus ne le trouve pas?
    0
    1. Contributeur
      Salut,

      repost un nouveau rapport hijack this stp

      @+
      0
      1. non parler trop vite secuser en a trouve encore 2 mais ne peux rien en faire
        s il y a encore quelqu unn debout pour maider merci
        0
        1. on dirai que tou est propre faut il redemarer sans restauration de systeme ?
          merci
          0
          1. voila le rapport girly :
            Malwarebytes' Anti-Malware 1.25
            Version de la base de données: 1096
            Windows 5.1.2600 Service Pack 3

            22:53:21 29/08/2008
            mbam-log-08-29-2008 (22-53-21).txt

            Type de recherche: Examen complet (C:\|K:\|)
            Eléments examinés: 158446
            Temps écoulé: 39 minute(s), 51 second(s)

            Processus mémoire infecté(s): 0
            Module(s) mémoire infecté(s): 0
            Clé(s) du Registre infectée(s): 1
            Valeur(s) du Registre infectée(s): 0
            Elément(s) de données du Registre infecté(s): 0
            Dossier(s) infecté(s): 0
            Fichier(s) infecté(s): 2

            Processus mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Module(s) mémoire infecté(s):
            (Aucun élément nuisible détecté)

            Clé(s) du Registre infectée(s):
            HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} (Adware.Agent) -> Quarantined and deleted successfully.

            Valeur(s) du Registre infectée(s):
            (Aucun élément nuisible détecté)

            Elément(s) de données du Registre infecté(s):
            (Aucun élément nuisible détecté)

            Dossier(s) infecté(s):
            (Aucun élément nuisible détecté)

            Fichier(s) infecté(s):
            C:\Program Files\SAV\sav0.dat (Rogue.SystemAntivirus) -> Quarantined and deleted successfully.
            C:\Program Files\SAV\sav1.dat (Rogue.SystemAntivirus) -> Quarantined and deleted successfully.
            0
            1. Contributeur
              je me disais bien aussi :)

              maintenant plus long

              Fais un scan avec cet antispyware :

              Telecharge malwarebytes + tutoriel :

              -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

              Tu l´instale; le programme va se mettre automatiquement a jour.

              Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

              Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

              Puis click sur "rechercher".

              Laisse le scanner le pc...

              Si des elements on ete trouvés > click sur supprimer la selection.

              si il t´es demandé de redemarrer > click sur "yes".

              A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

              Copie et colle le rapport stp.

              @+
              0
              1. voila girly le rapport de sd:

                [b]SDFix: Version 1.220 [/b]
                Run by moi on 29/08/2008 at 21:45

                Microsoft Windows XP [version 5.1.2600]
                Running From: C:\SDFix

                [b]Checking Services [/b]:

                Restoring Default Security Values
                Restoring Default Hosts File

                Rebooting

                [b]Checking Files [/b]:

                Trojan Files Found:

                C:\WINDOWS\SYSTEM32\55073.EXE - Deleted
                C:\WINDOWS\system32\msxml71.dll - Deleted

                Removing Temp Files

                [b]ADS Check [/b]:

                [b]Final Check [/b]:

                catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-08-29 21:51:50
                Windows 5.1.2600 Service Pack 3 FAT NTAPI

                scanning hidden processes ...

                scanning hidden services ...

                scanning hidden autostart entries ...

                scanning hidden files ...

                scan completed successfully
                hidden processes: 0
                hidden services: 0
                hidden files: 0

                [b]Remaining Services [/b]:

                Authorized Application Key Export:

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
                "C:\\StubInstaller.exe"="C:\\StubInstaller.exe:*:Enabled:LimeWire swarmed installer"
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"="C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
                "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"="C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword"
                "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"="C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss"
                "C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"="C:\\Program Files\\Winamp Remote\\bin\\Orb.exe:*:Enabled:Orb"
                "C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe:*:Enabled:OrbTray"
                "C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"="C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
                "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"
                "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
                "C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"="C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe:*:Enabled:avast! Antivirus"
                "C:\\Program Files\\MSN Messenger\\MSNMSGR.EXE"="C:\\Program Files\\MSN Messenger\\MSNMSGR.EXE:*:Enabled:Windows Live Messenger 8.1"
                "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
                "C:\\Program Files\\MSN Messenger\\MSNMSGR.EXE"="C:\\Program Files\\MSN Messenger\\MSNMSGR.EXE:*:Enabled:Windows Live Messenger 8.1"
                "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                [b]Remaining Files [/b]:

                File Backups: - C:\SDFix\backups\backups.zip

                [b]Files with Hidden Attributes [/b]:

                Wed 17 May 2006 1,024 ...HR --- "C:\WINDOWS\system32\NTICDMK32.dll"
                Mon 22 May 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                Fri 29 Aug 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
                Fri 4 May 2007 20 A..H. --- "C:\Documents and Settings\Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
                Mon 22 May 2006 4,348 ...H. --- "C:\Documents and Settings\Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
                Wed 28 Jun 2006 400 A.SH. --- "C:\Documents and Settings\Propri‚taire\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"

                [b]Finished![/b]

                et celui d hijack :
                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 21:53:14, on 29/08/2008
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\Ati2evxx.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\WINDOWS\system32\notepad.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\WINDOWS\SOUNDMAN.EXE
                C:\WINDOWS\Mixer.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                C:\Program Files\MSN Messenger\msnmsgr.exe
                C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe
                C:\Program Files\Poste de Travail Sans Fil Labtec\MagicKey.exe
                C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                R3 - URLSearchHook: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O2 - BHO: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
                O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                O4 - Global Startup: Activer le Poste de Travail Sans Fil Labtec.lnk = C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe
                O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O14 - IERESET.INF: START_PAGE_URL=https://www.acer.com/worldwide/selection.html
                O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - https://www.f-secure.com/en/home/support
                O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
                O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - https://www.eset.com/
                O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
                O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
                O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
                0
                1. Contributeur
                  combofix est un nettoyeur bien particulier, il a beaucoup de malware dans sa base de donnée, là je peux voir; c´est pour cela que je te demande de passer sdfix, pour affiner...
                  0
                  1. Contributeur
                    passe celui la encore :

                    Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
                    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
                    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                    • Redémarre ton ordinateur
                    • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                    • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                    • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                    • Choisis ton compte.
                    Déroule la liste des instructions ci-dessous :
                    • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                    • Appuie sur Y pour commencer le processus de nettoyage.
                    • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                    • Appuie sur une touche pour redémarrer le PC.
                    • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                    • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                    • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                    • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                    • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

                    @+
                    0
                    1. o fait girly combofix et un antivir ou un nettoyeur de registre ,c est juste par curriositee merci
                      0
                      1. voila le rapport :
                        ComboFix 08-08-29.01 - moi 2008-08-29 21:19:51.1 - [color=red][b]FAT32[/b][/color]x86
                        Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.445 [GMT 2:00]
                        Endroit: C:\Documents and Settings\moi\Mes documents\ComboFix.exe
                        * Création d'un nouveau point de restauration

                        [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                        .

                        (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                        .

                        C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat
                        C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat
                        C:\WINDOWS\Downloaded Program Files\setup.inf
                        C:\WINDOWS\system32\_000005_.tmp.dll
                        C:\WINDOWS\system32\ektedcpb.ini
                        C:\WINDOWS\system32\MSINET.oca

                        ----- BITS: Possible sites infectés -----

                        http://freefile.kristopherw.us
                        .
                        ((((((((((((((((((((((((((((( Fichiers créés 2008-07-28 to 2008-08-29 ))))))))))))))))))))))))))))))))))))
                        .

                        2008-08-29 20:58 . 2008-08-29 20:58 <REP> d-------- C:\Program Files\Trend Micro
                        2008-08-29 20:30 . 2008-08-29 20:30 <REP> d-------- C:\WINDOWS\AU_Temp
                        2008-08-29 19:42 . 2008-08-29 19:41 23,249,241 --a------ C:\WINDOWS\LPT$VPN.507
                        2008-08-29 19:41 . 2008-08-29 19:41 23,249,241 --a------ C:\WINDOWS\VPTNFILE.507
                        2008-08-29 18:33 . 2008-08-29 18:33 <REP> d-------- C:\Program Files\SAV
                        2008-08-29 18:33 . 2008-08-29 18:33 110,596 --a------ C:\WINDOWS\system32\msxml71.dll
                        2008-08-29 15:16 . 2008-08-29 15:16 25 --a------ C:\WINDOWS\mixerdef.ini
                        2008-08-29 15:06 . 2008-04-13 20:45 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys
                        2008-08-29 15:06 . 2008-04-13 20:45 10,624 --a------ C:\WINDOWS\system32\dllcache\gameenum.sys
                        2008-08-29 15:05 . 2002-01-28 10:16 1,228,800 -ra------ C:\WINDOWS\mixer.exe
                        2008-08-29 15:05 . 2002-01-29 03:43 370,382 -ra------ C:\WINDOWS\system32\drivers\cmaudio.sys
                        2008-08-29 15:05 . 2002-01-11 07:54 135,168 -ra------ C:\WINDOWS\cmuninst.exe
                        2008-08-29 15:05 . 2001-11-12 04:38 32,768 -ra------ C:\WINDOWS\system32\cmnprop.dll
                        2008-08-28 19:31 . 2008-08-28 19:31 169 --a------ C:\WINDOWS\RtlRack.ini
                        2008-08-27 11:45 . 2008-08-27 11:45 <REP> d-------- C:\Program Files\MSN Messenger
                        2008-08-27 10:56 . 2008-08-27 10:56 <REP> d-------- C:\Documents and Settings\All Users\Application Data\SymplisIT
                        2008-08-26 18:01 . 2008-08-26 18:01 <REP> d--hs---- C:\FOUND.052
                        2008-08-24 19:41 . 2008-08-24 19:41 <REP> d--hs---- C:\FOUND.051
                        2008-08-19 08:42 . 2008-08-19 08:42 <REP> d-------- C:\WINDOWS\system32\fr
                        2008-08-19 08:42 . 2008-08-19 08:42 <REP> d-------- C:\WINDOWS\l2schemas
                        2008-08-19 07:33 . 2008-04-14 04:33 200,704 --------- C:\WINDOWS\system32\napmontr.dll
                        2008-08-19 07:32 . 2006-12-28 21:01 19,569 --a------ C:\WINDOWS\[u]0[/u]05444_.tmp
                        2008-08-19 07:32 . 2008-04-14 04:10 2,524 --------- C:\WINDOWS\system32\pid.inf
                        2008-08-15 08:36 . 2008-05-01 16:36 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
                        2008-08-15 08:35 . 2008-04-11 21:05 691,712 --------- C:\WINDOWS\system32\dllcache\inetcomm.dll
                        2008-07-31 20:44 . 2008-07-31 20:44 <REP> d-------- C:\Documents and Settings\moi\Application Data\Sony Corporation
                        2008-07-31 20:41 . 2003-08-26 17:03 757,760 --a------ C:\WINDOWS\system32\CDDBUI.dll
                        2008-07-31 20:41 . 2003-08-26 17:01 630,784 --a------ C:\WINDOWS\system32\CDDBControl.dll
                        2008-07-31 20:41 . 2003-07-11 14:23 110,592 --a------ C:\WINDOWS\system32\CddbLangFR.dll
                        2008-07-31 20:40 . 2008-07-31 20:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Sony Corporation
                        2008-07-31 20:39 . 2008-07-31 20:39 <REP> d-------- C:\Program Files\Sony
                        2008-07-31 20:39 . 2008-07-31 20:39 <REP> d-------- C:\Program Files\Fichiers communs\Sony Shared
                        2008-07-31 20:39 . 2001-10-24 16:00 524,288 --a------ C:\WINDOWS\system32\TDI-SonyOMG.dll
                        2008-07-31 20:39 . 2001-10-24 16:00 2,271 --a------ C:\WINDOWS\system32\TDI-SonyOMG.sc

                        .
                        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        2008-08-29 18:30 91,744 ----a-w C:\WINDOWS\BPMNT.dll
                        2008-08-29 18:30 1,213,784 ----a-w C:\WINDOWS\vsapi32.dll
                        2008-08-29 17:41 71,749 ----a-w C:\WINDOWS\hcextoutput.dll
                        2008-08-29 17:41 333,576 ----a-w C:\WINDOWS\tsc.exe
                        2008-08-26 22:39 12,642 ----a-w C:\Documents and Settings\moi\Application Data\wklnhst.dat
                        2008-07-26 14:51 --------- d-----w C:\Program Files\Poste de Travail Sans Fil Labtec
                        2008-07-23 15:30 --------- d-----w C:\Program Files\Windows Media Connect 2
                        2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
                        2008-07-18 20:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
                        2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
                        2008-07-18 20:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
                        2008-07-18 20:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
                        2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
                        2008-07-18 20:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
                        2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
                        2008-07-18 20:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
                        2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
                        2008-07-18 20:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
                        2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
                        2008-07-18 20:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
                        2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
                        2008-07-18 20:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
                        2008-07-18 20:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
                        2008-07-18 20:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
                        2008-07-07 20:28 253,952 ----a-w C:\WINDOWS\system32\es.dll
                        2008-07-07 20:28 253,952 ------w C:\WINDOWS\system32\dllcache\es.dll
                        2008-06-24 16:44 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
                        2008-06-24 16:44 74,240 ------w C:\WINDOWS\system32\dllcache\mscms.dll
                        2008-06-24 08:28 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
                        2008-06-23 09:21 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
                        2008-06-23 09:21 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
                        2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
                        2008-06-21 05:23 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
                        2008-06-20 17:47 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
                        2008-06-20 17:47 247,808 ------w C:\WINDOWS\system32\dllcache\mswsock.dll
                        2008-06-20 17:47 147,968 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
                        2008-06-20 11:51 361,600 ------w C:\WINDOWS\system32\dllcache\tcpip.sys
                        2008-06-20 11:40 138,496 ------w C:\WINDOWS\system32\dllcache\afd.sys
                        2008-06-20 11:08 225,856 ------w C:\WINDOWS\system32\dllcache\tcpip6.sys
                        2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\dllcache\bthport.sys
                        2007-06-09 13:02 58,272 ----a-w C:\Documents and Settings\moi\Application Data\GDIPFONTCACHEV1.DAT
                        .

                        ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                        .
                        .
                        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                        REGEDIT4

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                        "{de44fda9-805d-413c-8322-65a08f7c99b9}"= "C:\Program Files\fullanimes.free.fr\tbful1.dll" [2008-03-03 07:42 1470488]

                        [HKEY_CLASSES_ROOT\clsid\{de44fda9-805d-413c-8322-65a08f7c99b9}]

                        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{de44fda9-805d-413c-8322-65a08f7c99b9}]
                        2008-03-03 07:42 1470488 --a------ C:\Program Files\fullanimes.free.fr\tbful1.dll

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                        "{de44fda9-805d-413c-8322-65a08f7c99b9}"= "C:\Program Files\fullanimes.free.fr\tbful1.dll" [2008-03-03 07:42 1470488]

                        [HKEY_CLASSES_ROOT\clsid\{de44fda9-805d-413c-8322-65a08f7c99b9}]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                        "{DE44FDA9-805D-413C-8322-65A08F7C99B9}"= "C:\Program Files\fullanimes.free.fr\tbful1.dll" [2008-03-03 07:42 1470488]

                        [HKEY_CLASSES_ROOT\clsid\{de44fda9-805d-413c-8322-65a08f7c99b9}]

                        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 04:34 15360]
                        "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 18:41 1832272]
                        "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                        "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 16:38 78008]
                        "SoundMan"="SOUNDMAN.EXE" [2003-09-23 02:09 57344 C:\WINDOWS\SOUNDMAN.EXE]
                        "C-Media Mixer"="Mixer.exe" [2002-01-28 10:16 1228800 C:\WINDOWS\mixer.exe]

                        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                        "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2008-04-14 04:34 15360]

                        C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                        HP Digital Imaging Monitor.lnk - C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2007-01-02 21:40:10 210520]
                        Activer le Poste de Travail Sans Fil Labtec.lnk - C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe [2008-07-26 16:51:50 253952]

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                        "VIDC.YV12"= yv12vfw.dll

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                        "EnableFirewall"= 0 (0x0)

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                        "%windir%\\system32\\sessmgr.exe"=
                        "C:\\Program Files\\Messenger\\msmsgs.exe"=
                        "C:\\StubInstaller.exe"=
                        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                        "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
                        "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword.exe"=
                        "C:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Beyond the Sword\\Civ4BeyondSword_PitBoss.exe"=
                        "C:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
                        "C:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
                        "C:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
                        "C:\\Program Files\\LimeWire\\LimeWire.exe"=
                        "C:\\Program Files\\uTorrent\\uTorrent.exe"=
                        "C:\\Program Files\\Alwil Software\\Avast4\\ashAvast.exe"=
                        "C:\\Program Files\\MSN Messenger\\MSNMSGR.EXE"=
                        "C:\\Program Files\\MSN Messenger\\livecall.exe"=

                        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                        "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

                        R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
                        R1 kbfilter;Keyboard Filter Driver;C:\WINDOWS\system32\drivers\kbfilter.sys [2002-10-15 14:48]
                        R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
                        R3 C4C_BSC2;C4C_BSC2;C:\WINDOWS\system32\DRIVERS\C4C_BSC2.sys [2002-07-08 19:32]
                        R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 20:45]
                        S3 amdtools;AMD Special Tools Driver;C:\WINDOWS\system32\DRIVERS\AmdTools.sys []
                        S3 Boonty Games;Boonty Games;C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe []
                        S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2007-05-02 11:11]
                        S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2007-05-02 11:11]
                        S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2007-05-02 11:11]
                        S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 20:45]

                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                        HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
                        hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
                        \Shell\Auto\command - msnmsgr_plus.exe
                        \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL msnmsgr_plus.exe

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d6a2f22-e677-11da-9fa2-806d6172696f}]
                        \Shell\AutoRun\command - D:\autorun.exe

                        [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{327b964a-51b4-11dd-82fd-003054c37b0c}]
                        \Shell\Auto\command - msnmsgr_plus.exe
                        \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL msnmsgr_plus.exe

                        *Newly Created Service* - CATCHME
                        *Newly Created Service* - PROCEXP90
                        .
                        Contenu du dossier 'Scheduled Tasks/Tâches planifiées'

                        2008-08-29 C:\WINDOWS\Tasks\User_Feed_Synchronization-{A1584641-0D50-4433-BE61-7A3F6D9FBD6C}.job
                        - C:\WINDOWS\system32\msfeedssync.exe [2006-10-17 11:58]

                        2008-08-29 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
                        - C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
                        .
                        .
                        ------- Supplementary Scan -------
                        .
                        FireFox -: Profile - C:\Documents and Settings\moi\Application Data\Mozilla\Firefox\Profiles\pixslb5u.default\
                        FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://lo.st
                        FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://french.icrfast.com/index.php?rvs=hompag
                        FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://french.icrfast.com/index.php?rvs=hompag
                        FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://french.icrfast.com/index.php?rvs=hompag
                        .

                        **************************************************************************

                        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2008-08-29 21:23:03
                        Windows 5.1.2600 Service Pack 3 FAT NTAPI

                        Balayage processus cachés ...

                        Balayage caché autostart entries ...

                        Balayage des fichiers cachés ...

                        Scan terminé avec succès
                        Les fichiers cachés: 0

                        **************************************************************************
                        .
                        Temps d'accomplissement: 2008-08-29 21:23:43
                        ComboFix-quarantined-files.txt 2008-08-29 19:23:42

                        Pre-Run: 35,163,013,120 octets libres
                        Post-Run: 35,201,777,664 octets libres

                        204 --- E O F --- 2008-08-20 07:04:46
                        0
                        1. Contributeur
                          samuel,

                          moi non plus je ne voie rien...

                          a part boonty etun plug de winanp inofenssif...

                          passe ceci on va etre fixé :

                          Télécharge combofix.exe (par sUBs) sur ton Bureau.

                          -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                          -> Double clique combofix.exe.
                          -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                          -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                          NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                          Avant d'utiliser ComboFix :

                          -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                          -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

                          Une fois fait, sur ton bureau double-clic sur Combofix.exe.

                          - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                          /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                          - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                          - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                          -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                          -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

                          -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                          @+
                          0
                          1. bon soir girly merci de maccorder un peu de temps voila le rapport:

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 20:59:25, on 29/08/2008
                            Platform: Windows XP SP3 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\Ati2evxx.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            C:\WINDOWS\SOUNDMAN.EXE
                            C:\WINDOWS\Mixer.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                            C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe
                            C:\Program Files\Poste de Travail Sans Fil Labtec\MagicKey.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSTE08.exe
                            C:\Program Files\uTorrent\uTorrent.exe
                            C:\Program Files\Internet Explorer\iexplore.exe
                            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.01net.com/telecharger/
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.01net.com/telecharger/
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                            R3 - URLSearchHook: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
                            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
                            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
                            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O2 - BHO: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
                            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O3 - Toolbar: fullanimes.free.fr Toolbar - {de44fda9-805d-413c-8322-65a08f7c99b9} - C:\Program Files\fullanimes.free.fr\tbful1.dll
                            O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
                            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                            O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
                            O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe
                            O4 - Global Startup: Activer le Poste de Travail Sans Fil Labtec.lnk = C:\Program Files\Poste de Travail Sans Fil Labtec\MulMouse.exe
                            O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
                            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                            O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
                            O16 - DPF: {0B79F48A-E8D6-11DB-9283-E25056D89593} (F-Secure Online Scanner 3.1) - https://www.f-secure.com/en/home/support
                            O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
                            O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - https://www.eset.com/
                            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                            O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
                            O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                            O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                            O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                            O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                            O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
                            O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Pacsptisvr.exe
                            O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\Sptisrv.exe
                            0
                            1. Contributeur
                              Télécharge HijackThis ici :

                              -> http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

                              Tutoriel d´instalation : (Merci a Balltrap34 pour cette réalisation)

                              -> http://pageperso.aol.fr/balltrap34/Hijenr.gif

                              Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

                              -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

                              Post le rapport généré ici stp...
                              0