Rapport hitjakis

Résolu
Bonjour,
kelk1 pourrai t il m aider a lire ce rapport et m expliquer pour la suite merci
Configuration: Windows Vista
Firefox 3.0.2

28 réponses

Résumé de la discussion

Plusieurs échanges portent sur le nettoyage d'un système Windows Vista infecté et sur la lecture d'un rapport d'infection, avec des explications sur les démarches à suivre pour comprendre la suite. Des instructions claires décrivent le démarrage en mode sans échec et l'exécution de SmitfraudFix pour supprimer les fichiers malveillants, nettoyer le registre et remplacer le fichier infecté, avec un redémarrage éventuel. En alternative, d'autres messages proposent ComboFix, suggèrent de déconnecter le réseau et de poster le contenu des rapports générés, notamment le fichier C:\ComboFix.txt. Des éléments récurrents dans les rapports incluent les chemins d'exécution et les entrées de démarrage observées, soulignant la nécessité d'une approche multi-outils et d'une vérification des programmes.

Bobot (l’IA à votre service)
  1. je te remercie mais c bon ca y est plus de probleme avec les pub grace a navilog
    1. alors messieurs ca dit koi ce rapport ??? merci
      1. pas bon
        relance ceci
        Fais un scan avec cet antispyware :

        Telecharge malwarebytes + tutoriel :

        -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

        Tu l´instale; le programme va se mettre automatiquement a jour.

        Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

        Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

        Puis click sur "rechercher".

        Laisse le scanner le pc...

        Si des elements on ete trouvés > click sur supprimer la selection.

        si il t´es demandé de redemarrer > click sur "yes".

        A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

        Copie et colle le rapport stp.
    2. et voila le rapport hijtjakis

      Scan saved at 22:18:23, on 27/09/2008
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18000)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Windows\vVX1000.exe
      C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      C:\Windows\RtHDVCpl.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\System32\rundll32.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
      R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
      O1 - Hosts: ::1 localhost
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file)
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
      O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
      O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
      O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
      O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\RunOnce: [WLuSetup] C:\Program Files\Symantec\LiveUpdate\luupdate.exe -p wlumsp.msp
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
      O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S87E3.tmp" /EF "HKCU"
      O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series (Copie 1)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S6A17.tmp" /EF "HKCU"
      O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series (Copie 2)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S1810.tmp" /EF "HKCU"
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [ieugasw] "c:\users\eric\appdata\local\ieugasw.exe" ieugasw
      O4 - HKCU\..\Run: [wmuak] "c:\users\eric\appdata\local\wmuak.exe" wmuak
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
      O4 - Global Startup: OFFICE One Startup v7.lnk = ?
      O8 - Extra context menu item: &Search - ?p=ZCxdm873MXFR
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
      O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
      O13 - Gopher Prefix:
      O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} -
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_05) -
      O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} -
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} -
      O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
      O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
      O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
      O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
      O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
      O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
      O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
      O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
      O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
      O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
      1. Contributeur
        Ouep pas de traces de ces fichiers ,

        Relance Navilog
        # Sur le menu, choisis Désinfection automatique l'option 2
        # Le fix va se mettre à travailler... sois patient!
        # Cliques simplement sur OK si des fenêtres apparaissent.

        Un rapport va être générer sur ton disque C:\ qui sera en option 2 >> Envoi le

        >>> Si ton bureau ne réapparait pas après le fix ce n'est rien ! <<<
        Fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
        Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
        Tape explorer et valide. Celà te fera apparaitre ton bureau.

        Puis poste un nouveau rapport hijack this.

        Bon courage à vous deux ;))

        @++
        1. voici le rapport de navilog en desinfection

          Outil exécuté depuis C:\Program Files\navilog1
          Session actuelle : "eric"

          Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO

          Microsoft Windows Vista 6.0.6001
          Internet Explorer : 7.0.6001.18000
          Système de fichiers : NTFS

          Mode suppression automatique
          avec prise en charge résultats Catchme et GNS

          [b] Nettoyage executé en mode normal sans redémarrage
          !! Les résultats ne seront pas optimisés !! [/b]

          *** fsbl1.txt non trouvé ***
          (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

          *** Suppression avec sauvegardes résultats GenericNaviSearch ***

          * Suppression dans "C:\Windows\System32" *

          * Suppression dans "C:\Users\eric\AppData\Local\Microsoft" *

          * Suppression dans "C:\Users\eric\AppData\Local\virtualstore\windows\system32" *

          * Suppression dans "C:\Users\eric\AppData\Local" *

          *** Suppression dossiers dans "C:\Windows" ***

          *** Suppression dossiers dans "C:\Program Files" ***

          *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

          *** Suppression dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

          *** Suppression dossiers dans "C:\ProgramData" ***

          *** Suppression dossiers dans c:\users\eric\appdata\roaming\micros~1\windows\startm~1\programs ***

          *** Suppression dossiers dans "C:\Users\eric\AppData\Local\virtualstore\Program Files" ***

          *** Suppression dossiers dans "C:\Users\eric\AppData\Roaming" ***

          *** Suppression fichiers ***

          *** Suppression fichiers temporaires ***

          Nettoyage contenu C:\Windows\Temp effectué !
          Nettoyage contenu C:\Users\eric\AppData\Local\Temp effectué !

          *** Traitement Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

          2)Recherche, création sauvegardes et suppression Heuristique :

          * Dans "C:\Windows\system32" *

          * Dans "C:\Users\eric\AppData\Local\Microsoft" *

          * Dans "C:\Users\eric\AppData\Local\virtualstore\windows\system32" *

          * Dans "C:\Users\eric\AppData\Local" *

          *** Sauvegarde du Registre vers dossier Safebackup ***

          sauvegarde du Registre réalisée avec succès !

          *** Nettoyage Registre ***

          Nettoyage Registre Ok

          *** Certificats ***

          Certificat Egroup absent !
          Certificat Electronic-Group supprimé !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit supprimé !
          Certificat Sunny-Day-Design-Ltdt absent !

          *** Nettoyage terminé le 27/09/2008 à 22:14:09,98 ***
      2. ok et je te remercie de ton coup de pouce
        1. Tu clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
          Au menu principal, choisis 2 et valide.
          (ne fais pas le choix ,3 ou 4 sans notre avis/accord)

          Le fix va t'informer qu'il va alors redémarrer ton PC
          Fermes toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
          Appuies sur une touche comme demandé.
          (si ton Pc ne redémarre pas automatiquement, fais le toi même)
          Au redémarrage de ton PC, choisis ta session habituelle.

          Patiente jusqu'au message :
          *** Nettoyage Termine le ..... ***
          Le bloc-notes va s'ouvrir.
          Sauvegarde le rapport de manière à le retrouver
          Referme le bloc-notes. Ton bureau va réapparaitre

          PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
          Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
          Tape explorer et valide. Celà te fera apparaitre ton bureau.

          Poste le rapport
      3. Contributeur
        Bonsoir archet9 et kipoui en passant ,
        Un ptit coup de navilog serait suffisant non ? Pour les deux lignes ci dessous ?
        >> O4 - HKCU\..\Run: [ieugasw] "c:\users\eric\appdata\local\ieugasw.exe" ieugasw
        >> O4 - HKCU\..\Run: [wmuak] "c:\users\eric\appdata\local\wmuak.exe" wmuak

        kipoui,
        Désactive l'UAC >> Démarrer, puis Panneau de configuration.
        Choisis l'affichage classique sur la gauche et double-clique sur Comptes d'utilisateurs.
        Cliques ensuite sur désactiver le contrôle des comptes d'utilisateurs.
        Tu le réactiveras à la fin de la désinfection.

        Télécharge Navilog1 depuis-ce lien :
        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

        Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
        Ensuite double clique sur navilog1.exe pour lancer l'installation.

        Une fois l'installation terminée, le fix s'exécutera automatiquement.
        (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

        Au menu principal, Fais le choix 1
        Laisse toi guider et patiente.
        Patiente jusqu'au message :
        *** Analyse Termine le ..... ***
        Appuie sur une touche le bloc note va s'ouvrir.
        Copie-colle le rapport ici.

        @++
        1. !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
          !!! Postez ce rapport sur le forum pour le faire analyser !!!
          !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

          Outil exécuté depuis C:\Program Files\navilog1
          Session actuelle : "eric"

          Mise à jour le 22.08.2008 à 17h30 par IL-MAFIOSO

          Microsoft Windows Vista 6.0.6001
          Internet Explorer : 7.0.6001.18000
          Système de fichiers : NTFS

          Recherche executé en mode normal

          *** Recherche Programmes installés ***

          *** Recherche dossiers dans "C:\Windows" ***

          *** Recherche dossiers dans "C:\Program Files" ***

          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***

          *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1" ***

          *** Recherche dossiers dans "C:\ProgramData" ***

          *** Recherche dossiers dans "c:\users\eric\appdata\roaming\micros~1\windows\startm~1\programs" ***

          *** Recherche dossiers dans "C:\Users\eric\AppData\Local\virtualstore\Program Files" ***

          *** Recherche dossiers dans "C:\Users\eric\AppData\Roaming" ***

          *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
          pour + d'infos : http://www.gmer.net

          *** Recherche avec GenericNaviSearch ***
          !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
          !!! A vérifier impérativement avant toute suppression manuelle !!!

          * Recherche dans "C:\Windows\system32" *

          * Recherche dans "C:\Users\eric\AppData\Local\Microsoft" *

          * Recherche dans "C:\Users\eric\AppData\Local\virtualstore\windows\system32" *

          * Recherche dans "C:\Users\eric\AppData\Local" *

          *** Recherche fichiers ***

          *** Recherche clés spécifiques dans le Registre ***

          *** Module de Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Recherche nouveaux fichiers Instant Access :

          2)Recherche Heuristique :

          * Dans "C:\Windows\system32" :

          * Dans "C:\Users\eric\AppData\Local\Microsoft" :

          * Dans "C:\Users\eric\AppData\Local\virtualstore\windows\system32" :

          * Dans "C:\Users\eric\AppData\Local" :

          3)Recherche Certificats :

          Certificat Egroup absent !
          Certificat Electronic-Group trouvé !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit trouvé !
          Certificat Sunny-Day-Design-Ltd absent !

          4)Recherche fichiers connus :

          *** Analyse terminée le 27/09/2008 à 21:51:57,46 ***
      4. Scan saved at 20:43:13, on 27/09/2008
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v7.00 (7.00.6001.18000)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Windows\vVX1000.exe
        C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        C:\Windows\RtHDVCpl.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avcenter.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
        R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
        O1 - Hosts: ::1 localhost
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file)
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
        O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
        O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
        O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
        O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKLM\..\RunOnce: [WLuSetup] C:\Program Files\Symantec\LiveUpdate\luupdate.exe -p wlumsp.msp
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
        O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S87E3.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series (Copie 1)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S6A17.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series (Copie 2)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S1810.tmp" /EF "HKCU"
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKCU\..\Run: [ieugasw] "c:\users\eric\appdata\local\ieugasw.exe" ieugasw
        O4 - HKCU\..\Run: [wmuak] "c:\users\eric\appdata\local\wmuak.exe" wmuak
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
        O4 - Global Startup: OFFICE One Startup v7.lnk = ?
        O8 - Extra context menu item: &Search - ?p=ZCxdm873MXFR
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
        O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
        O13 - Gopher Prefix:
        O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
        O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} -
        O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_05) -
        O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} -
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} -
        O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA} (Java Plug-in 1.6.0_02) -
        O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} (Java Plug-in 1.6.0_03) -
        O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
        O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_05) -
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
        O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
        O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
        O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
        O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
        O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
        O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
        1. fait ca
          ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
          http://download.bleepingcomputer.com/sUBs/ComboFix.exe

          /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

          ---> Double-clique sur Combofix.exe
          Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
          Accepte en cliquant sur "Oui"

          ---> Mets-le en langue française F
          Tape sur la touche 1 (Yes) pour démarrer le scan.

          /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

          En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

          Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

          /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

          Note : Le rapport se trouve également là : C:\ComboFix.txt
        2. @archet9Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.375 [GMT 2:00]
          Lancé depuis: C:\Users\eric\Downloads\ComboFix.exe
          * Un nouveau point de restauration a été créé
          .

          ((((((((((((((((((((((((((((( Fichiers créés du 2008-08-27 au 2008-09-27 ))))))))))))))))))))))))))))))))))))
          .

          2008-09-27 19:48 . 2008-09-27 19:48 691 --a------ C:\Users\eric\AppData\Roaming\GetValue.vbs
          2008-09-27 19:48 . 2008-09-27 19:48 35 --a------ C:\Users\eric\AppData\Roaming\SetValue.bat
          2008-09-27 16:19 . 2008-09-27 16:19 <REP> d-------- C:\Users\All Users\Avira
          2008-09-27 16:19 . 2008-09-27 16:19 <REP> d-------- C:\ProgramData\Avira
          2008-09-27 16:19 . 2008-09-27 16:19 <REP> d-------- C:\Program Files\Avira
          2008-09-27 15:17 . 2008-09-25 04:31 <REP> d-------- C:\SDFix
          2008-09-27 09:24 . 2008-09-27 09:24 <REP> d-------- C:\Users\eric\AppData\Roaming\Malwarebytes
          2008-09-27 09:24 . 2008-09-27 09:24 <REP> d-------- C:\Users\All Users\Malwarebytes
          2008-09-27 09:24 . 2008-09-27 09:24 <REP> d-------- C:\ProgramData\Malwarebytes
          2008-09-27 09:24 . 2008-09-27 09:24 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
          2008-09-27 09:24 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
          2008-09-27 09:24 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys
          2008-09-24 17:40 . 2008-09-24 17:40 <REP> d-------- C:\Program Files\Trend Micro
          2008-09-10 09:20 . 2008-07-31 03:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
          2008-09-10 09:20 . 2008-08-02 03:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
          2008-09-10 09:20 . 2008-06-26 05:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
          2008-09-10 09:20 . 2008-06-26 05:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
          2008-09-10 09:20 . 2008-05-08 21:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
          2008-09-10 09:20 . 2008-05-20 04:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
          2008-09-10 09:20 . 2008-06-26 05:29 45,056 --a------ C:\Windows\System32\dataclen.dll
          2008-09-10 09:20 . 2008-08-02 05:26 36,864 --a------ C:\Windows\System32\cdd.dll
          2008-09-10 09:20 . 2008-07-31 05:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll

          .
          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2008-09-27 18:57 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
          2008-09-27 18:23 --------- d-----w C:\ProgramData\Symantec
          2008-09-27 17:48 2,236 ----a-w C:\Windows\System32\tmp.reg
          2008-09-27 09:35 --------- d-----w C:\ProgramData\Google Updater
          2008-09-26 10:22 --------- d-----w C:\Program Files\Norton Security Scan
          2008-09-26 08:15 --------- d-----w C:\Users\eric\AppData\Roaming\OFFICEOne7
          2008-09-24 18:35 --------- d-----w C:\Users\eric\AppData\Roaming\dvdcss
          2008-09-24 15:51 --------- d-----w C:\Users\eric\AppData\Roaming\DNA
          2008-09-23 17:29 --------- d-----w C:\Program Files\Windows Live Toolbar
          2008-09-23 12:24 --------- d-----w C:\Users\eric\AppData\Roaming\Packard Bell
          2008-09-19 10:26 82,944 ----a-w C:\Windows\System32\o4Patch.exe
          2008-09-19 10:26 82,944 ----a-w C:\Windows\System32\IEDFix.C.exe
          2008-09-08 21:38 88,576 ----a-w C:\Windows\System32\AntiXPVSTFix.exe
          2008-09-02 14:51 86,528 ----a-w C:\Windows\System32\VACFix.exe
          2008-08-31 19:31 --------- d-----w C:\Program Files\Messenger Plus! Live
          2008-08-25 10:36 --------- d-----w C:\Program Files\Spybot - Search & Destroy
          2008-08-20 08:38 --------- d-----w C:\Program Files\Microsoft Silverlight
          2008-08-14 15:07 --------- d-----w C:\Program Files\Windows Mail
          2008-08-09 17:59 --------- d-----w C:\Program Files\Google
          2008-08-09 17:06 --------- d-----w C:\Program Files\CCleaner
          2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
          2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
          2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
          2008-07-30 15:42 23,888 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
          2008-07-30 15:28 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
          2008-07-30 15:28 10,537 ----a-w C:\Windows\system32\drivers\coh_mon.cat
          2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
          2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
          2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
          2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
          2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
          2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
          2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
          2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
          2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
          2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
          2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll
          2008-05-04 15:24 174 --sha-w C:\Program Files\desktop.ini
          2008-04-03 15:54 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
          2008-04-03 15:54 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
          2008-04-03 15:54 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
          .

          ((((((((((((((((((((((((((((( snapshot@2008-09-27_12.44.06.37 )))))))))))))))))))))))))))))))))))))))))
          .
          - 2008-09-27 09:23:51 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
          + 2008-09-27 18:04:49 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
          - 2008-09-27 09:23:51 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
          + 2008-09-27 18:04:49 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
          - 2008-09-27 09:25:31 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
          + 2008-09-27 18:06:40 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
          + 2008-09-27 18:06:40 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
          - 2008-09-27 09:25:26 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
          + 2008-09-27 18:06:35 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
          - 2008-09-27 10:34:57 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
          + 2008-09-27 18:22:31 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
          - 2008-09-27 10:34:57 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
          + 2008-09-27 18:22:31 65,536 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
          - 2008-09-27 10:34:57 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
          + 2008-09-27 18:22:31 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
          - 2008-09-27 10:36:44 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
          + 2008-09-27 19:02:43 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
          + 2008-06-27 13:03:55 75,072 ----a-w C:\Windows\System32\drivers\avipbb.sys
          + 2007-03-01 08:34:22 28,352 ----a-w C:\Windows\System32\drivers\ssmdrv.sys
          + 2004-07-31 16:50:36 51,200 ----a-w C:\Windows\System32\dumphive.exe
          + 2008-05-18 19:40:35 82,944 ----a-w C:\Windows\System32\IEDFix.exe
          + 2003-06-05 19:13:00 53,248 ----a-w C:\Windows\System32\Process.exe
          + 2006-04-27 15:49:30 288,417 ----a-w C:\Windows\System32\SrchSTS.exe
          + 2007-09-05 22:22:23 289,144 ----a-w C:\Windows\System32\VCCLSID.exe
          - 2008-09-27 06:51:19 12,810 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2092978202-2183225848-1542360598-1002_UserData.bin
          + 2008-09-27 13:25:14 12,810 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2092978202-2183225848-1542360598-1002_UserData.bin
          - 2008-09-27 09:25:41 69,978 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
          + 2008-09-27 13:25:13 69,978 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
          - 2008-09-27 09:25:39 62,026 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
          + 2008-09-27 18:06:51 62,292 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
          + 2007-10-03 22:36:46 25,600 ----a-w C:\Windows\System32\WS2Fix.exe
          .
          -- Instantané actualisé --
          .
          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
          REGEDIT4

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
          "SmpcSys"="C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe" [2006-10-23 1092152]
          "EPSON Stylus DX4400 Series"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 180736]
          "EPSON Stylus DX4400 Series (Copie 1)"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 180736]
          "EPSON Stylus DX4400 Series (Copie 2)"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 180736]
          "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
          "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
          "ieugasw"="c:\users\eric\appdata\local\ieugasw.exe" [BU]
          "wmuak"="c:\users\eric\appdata\local\wmuak.exe" [BU]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "VX1000"="C:\Windows\vVX1000.exe" [2007-04-10 709992]
          "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
          "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-14 51048]
          "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 86016]
          "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 8497696]
          "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-12 81920]
          "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
          "RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 C:\Windows\RtHDVCpl.exe]

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
          "WLuSetup"="C:\Program Files\Symantec\LiveUpdate\luupdate.exe" [2008-08-01 636280]

          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
          "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]

          C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
          OFFICE One Startup v7.lnk - C:\Program Files\OFFICE One v7\OFFICE One Startup v7\oostartupv7.exe [2007-01-26 713728]

          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
          "EnableUIADesktopToggle"= 0 (0x0)

          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
          "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

          [HKEY_LOCAL_MACHINE\software\microsoft\security center]
          "UacDisableNotify"=dword:00000001
          "InternetSettingsDisableNotify"=dword:00000001
          "AutoUpdateDisableNotify"=dword:00000001
          "AntiVirusDisableNotify"="0x00000000"
          "UpdatesDisableNotify"="0x00000000"

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
          "DisableMonitoring"=dword:00000001

          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
          "DisableMonitoring"=dword:00000001

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
          "{ADDE03A0-D901-4BFD-B31D-4BA4AA1C418D}"= UDP:C:\Program Files\Common Files\aol\acs\AOLDial.exe:AOL Autoconnect
          "{B1D80A3F-D4A7-4F03-819E-73485D705789}"= TCP:C:\Program Files\Common Files\aol\acs\AOLDial.exe:AOL Autoconnect
          "{0D4296E0-6061-4063-BE9D-94969428B856}"= UDP:C:\Program Files\Common Files\aol\acs\AOLacsd.exe:module de connexion AOL
          "{845C6C47-FE62-494B-AD22-7F068B1C68B3}"= TCP:C:\Program Files\Common Files\aol\acs\AOLacsd.exe:module de connexion AOL
          "{68B85345-9E1A-4AF2-B6FF-207E4AFCE139}"= UDP:C:\Program Files\AOL 9.0 VR\waol.exe:AOL
          "{ADD39238-AC6C-4EF6-B161-386EDBB7A39F}"= TCP:C:\Program Files\AOL 9.0 VR\waol.exe:AOL
          "{8C68DD4C-1C01-434E-9787-5081C3F9119F}"= UDP:C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
          "{234DCABD-0039-4FA0-A5DE-C1A901996ACA}"= TCP:C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
          "{1277E6F4-727E-41B0-9007-C076684379D9}"= UDP:C:\Program Files\Common Files\aol\Loader\aolload.exe:AOL Loader
          "{48063463-827B-437B-84A4-538980A954C1}"= TCP:C:\Program Files\Common Files\aol\Loader\aolload.exe:AOL Loader
          "{E315DDEE-0E3D-401A-8168-918A8F7B83B3}"= UDP:C:\Program Files\Common Files\aol\System Information\sinf.exe:AOL System Information
          "{869C9CE4-E55D-4735-980F-C11A0DD2722A}"= TCP:C:\Program Files\Common Files\aol\System Information\sinf.exe:AOL System Information
          "{AA4D537B-838B-4C83-A609-39EA23F9BE5C}"= UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
          "{30420E5A-120A-4494-BDF3-4D1F42E8B819}"= TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
          "{7613496D-7695-4B24-83BE-1EC655C2CF70}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
          "{D685F731-DB7F-4115-B20D-F29D5020DA29}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
          "{E506F35C-82B0-4AE5-B89E-18BB5248260F}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
          "{DC720A66-5815-4534-8D1D-17190DDDA20C}"= UDP:C:\Program Files\BitTorrent_DNA\dna.exe:BitTorrent DNA
          "{AB1AC2FA-7C0B-425B-8D4B-81E137E57BD9}"= TCP:C:\Program Files\BitTorrent_DNA\dna.exe:BitTorrent DNA
          "{4D8F97EB-9C37-4BE7-9523-927CAE9F2DF5}"= UDP:C:\Users\Public\Downloads\BitTorrent\bittorrent.exe:BitTorrent
          "{51ED9E3D-4E62-4EE1-962B-84C02AA66930}"= TCP:C:\Users\Public\Downloads\BitTorrent\bittorrent.exe:BitTorrent
          "{6204CE5D-40C4-422F-8068-F98FFD6CCBCB}"= UDP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
          "{5853664F-567E-435F-9DAF-30738D40D3C9}"= TCP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
          "{53F10D07-7CF3-4824-A061-DBC663D6FAF5}"= UDP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
          "{9868A2CA-7E90-4216-8C6E-B6D9B40959B0}"= TCP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
          "TCP Query User{1BDF372A-309C-4286-9EF5-E1A8726716FB}C:\\program files\\ares\\ares.exe"= UDP:C:\program files\ares\ares.exe:Ares p2p for windows
          "UDP Query User{7EDC8F1D-CC99-4308-BCAF-3618FF2E74A8}C:\\program files\\ares\\ares.exe"= TCP:C:\program files\ares\ares.exe:Ares p2p for windows
          "TCP Query User{A8F96B2C-147E-43CD-9092-C72BBA6DAA78}C:\\users\\eric\\program files\\bittorrent_dna\\dna.exe"= UDP:C:\users\eric\program files\bittorrent_dna\dna.exe:dna.exe
          "UDP Query User{7BC9567C-A7E3-4371-A812-173FECE625F1}C:\\users\\eric\\program files\\bittorrent_dna\\dna.exe"= TCP:C:\users\eric\program files\bittorrent_dna\dna.exe:dna.exe
          "{1A2578A3-DE09-469E-8E1C-D1598659A206}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
          "EnableFirewall"= 0 (0x0)

          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
          "C:\\Users\\Public\\Downloads\\BitTorrent\\bittorrent.exe"= C:\Users\Public\Downloads\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

          R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080923.001\IDSvix86.sys [2008-09-12 270384]
          R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-14 149864]
          R2 MSCamSvc;MSCamSvc;C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2007-05-17 271720]
          R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-06-15 71096]
          R3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver;C:\Windows\system32\DRIVERS\fetnd6v.sys [2008-06-25 44032]
          R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-08-13 41008]
          R3 VX1000;VX-1000;C:\Windows\system32\DRIVERS\VX1000.sys [2007-04-10 1966312]
          S3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
          S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\Windows\system32\DRIVERS\fetnd5bv.sys [2008-01-02 43520]
          S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-03-13 29744]
          S3 UsbSagCom;Mobile Device Full USB Driver;C:\Windows\system32\DRIVERS\UsbSagCom.sys [2007-06-29 51712]

          [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be58341e-b2d6-11dc-a198-00038a000015}]
          \shell\AutoRun\command - I:\ClickMe.exe

          *Newly Created Service* - COMHOST
          *Newly Created Service* - SSMDRV
          .
          Contenu du dossier 'Tâches planifiées'
          .
          .
          ------- Examen supplémentaire -------
          .
          FireFox -: Profile - C:\Users\eric\AppData\Roaming\Mozilla\Firefox\Profiles\4366ydqn.default\
          FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
          FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.msn.fr/
          FF -: plugin - C:\Program Files\BitTorrent_DNA\npbtdna.dll
          FF -: plugin - C:\Program Files\Google\Google Updater\2.3.1314.1135\npCIDetect12.dll
          FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
          FF -: plugin - C:\Users\eric\Program Files\DNA\plugins\npbtdna.dll
          .

          **************************************************************************

          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-09-27 21:07:57
          Windows 6.0.6001 Service Pack 1 NTFS

          Recherche de processus cachés ...

          Recherche d'éléments en démarrage automatique cachés ...

          Recherche de fichiers cachés ...

          Scan terminé avec succès
          Fichiers cachés: 0

          **************************************************************************
          .
          Heure de fin: 2008-09-27 21:11:24
          ComboFix-quarantined-files.txt 2008-09-27 19:10:35
          ComboFix2.txt 2008-09-27 10:45:50

          Avant-CF: 84ÿ724ÿ142ÿ080 octets libres
          Après-CF: 84,688,818,176 octets libres

          240 --- E O F --- 2008-09-26 05:35:57

          et voila
      5. Run from C:\Users\eric\Downloads\SmitfraudFix
        OS: Microsoft Windows [version 6.0.6001] - Windows_NT
        The filesystem type is NTFS
        Fix run in safe mode

        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
        !!!Attention, following keys are not inevitably infected!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»
        »»»»»»»»»»»»»»»»»»»»»»»» VACFix

        VACFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

        S!Ri's WS2Fix: LSP not Found.

        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

        GenericRenosFix by S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

        IEDFix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

        404Fix
        Credits: Malware Analysis & Diagnostic
        Code: S!Ri

        »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

        »»»»»»»»»»»»»»»»»»»»»»»» RK

        »»»»»»»»»»»»»»»»»»»»»»»» DNS

        HKLM\SYSTEM\CCS\Services\Tcpip\..\{6C3F2C15-587F-46E0-ADFA-D4C1CE3F7DAA}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS1\Services\Tcpip\..\{6C3F2C15-587F-46E0-ADFA-D4C1CE3F7DAA}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS3\Services\Tcpip\..\{6C3F2C15-587F-46E0-ADFA-D4C1CE3F7DAA}: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

        »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
        !!!Attention, following keys are not inevitably infected!!!

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
        "System"=""

        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

        Registry Cleaning done.

        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
        !!!Attention, following keys are not inevitably infected!!!

        SrchSTS.exe by S!Ri
        Search SharedTaskScheduler's .dll

        »»»»»»»»»»»»»»»»»»»»»»»» End

        »»»»»»»»»»»»»»»»»»»» Killing process

        je te le remet la
        1. bah voila j espere ke c ca ???
          1. ????????
          2. @archet9ah!!! c pas ca ??? le rapport de smitfraud
          3. @kipouipas grave
            si tu as bien lancé smitfraudfix desinfection
            il a du bien travailler.....
            colle 1 NOUVEAU rapport hijackthis stp
            a+
        2. Scan done at 19:48:08,03, 27/09/2008
          Run from C:\Users\eric\Downloads\SmitfraudFix
          OS: Microsoft Windows [version 6.0.6001] - Windows_NT
          The filesystem type is NTFS
          Fix run in safe mode

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»
          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

          S!Ri's WS2Fix: LSP not Found.

          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

          GenericRenosFix by S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{6C3F2C15-587F-46E0-ADFA-D4C1CE3F7DAA}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{6C3F2C15-587F-46E0-ADFA-D4C1CE3F7DAA}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\..\{6C3F2C15-587F-46E0-ADFA-D4C1CE3F7DAA}: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

          »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

          Registry Cleaning done.

          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» End

          »»»»»»»»»»»»»»»»»»»» Killing process
          1. on ne peux pas le fer sans eteindre l ordi?? et pk??
            1. non c est comme ca......
              mais si ca te derange d eteindre ton pc ce soir,
              fait le quand tu pourras....
              j aurai quand meme ton message....
              a+
          2. Scan done at 19:21:51,74, 27/09/2008
            Run from C:\Users\eric\Downloads\SmitfraudFix
            OS: Microsoft Windows [version 6.0.6001] - Windows_NT
            The filesystem type is NTFS
            Fix run in normal mode

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\spoolsv.exe
            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            C:\Windows\Explorer.EXE
            C:\Program Files\Microsoft LifeCam\MSCamS32.exe
            C:\Program Files\CDBurnerXP\NMSAccessU.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Windows\vVX1000.exe
            C:\Windows\RtHDVCpl.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
            C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Windows Media Player\wmpnetwk.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
            C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\Program Files\Windows Live\Messenger\usnsvc.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Windows\system32\SearchProtocolHost.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Windows\system32\cmd.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            hosts file corrupted !

            127.0.0.1 www.legal-at-spybot.info
            127.0.0.1 legal-at-spybot.info

            »»»»»»»»»»»»»»»»»»»»»»»» C:\

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\eric

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\eric\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\eric\FAVORI~1

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop

            »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

            »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
            !!!Attention, following keys are not inevitably infected!!!

            o4Patch
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
            !!!Attention, following keys are not inevitably infected!!!

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
            !!!Attention, following keys are not inevitably infected!!!

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
            !!!Attention, following keys are not inevitably infected!!!

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
            !!!Attention, following keys are not inevitably infected!!!

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, following keys are not inevitably infected!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~2\\GOEC62~1.DLL"

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
            !!!Attention, following keys are not inevitably infected!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="C:\\Windows\\system32\\userinit.exe,"
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: VIA Rhine II Fast Ethernet Adapter
            DNS Server Search Order: 192.168.1.1

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{6C3F2C15-587F-46E0-ADFA-D4C1CE3F7DAA}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{6C3F2C15-587F-46E0-ADFA-D4C1CE3F7DAA}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS3\Services\Tcpip\..\{6C3F2C15-587F-46E0-ADFA-D4C1CE3F7DAA}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

            »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

            »»»»»»»»»»»»»»»»»»»»»»»» End

            voila le rapport
            1. ok

              Suite de la manipe ( nettoyage ), fais exactement ce qui suit :

              * Impératif : Redémarrer l'ordinateur en mode sans échec .
              Comment aller en Mode sans échec
              1) Redémarre ton ordi
              2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
              3) Tu verras un écran avec options de démarrage apparaître
              4) Choisis la première option : Sans Échec, et valide avec "Entrée"
              5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
              ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copies ou imprimes bien les info ci-dessous ...)

              *Double click sur SmitfraudFix.exe

              * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

              -> Si besion :
              * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presser Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

              ( Le correctif déterminera si le fichier wininet.dll est infecté.)

              * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
              pour remplacer le fichier corrompu.

              * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

              Le rapport se trouve à la racine de C\:
              (dans le fichier "rapport.txt")

              Postes moi ce dernier rapport ... Attention , il va être trop long pour être poster entièrement sur le forum
              --> donc postes moi seulement le début et la fin ( coupes la listes des "fichiers hosts" )
          3. en plus ca marche pas !!! kan je tape f8 je ne suis pas du tout ou tu m a dit il n y a pas d otre moyen plus simple
            1. ok
              laisse tomber sdfix
              fait ceci
              Télécharge SmitfraudFix (de de S!Ri, balltrap34 et moe31) :
              http://siri.urz.free.fr/Fix/SmitfraudFix.exe ou http://www.geekstogo.com/forum/files/file/6-smitfraudfix/

              - Enregistre-le sur le bureau

              - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée

              - Un rapport sera généré, poste-le dans ta prochaine réponse.

              [*] process.exe est détecté par certains antivirus comme étant un risktool. Il ne s'agit pas d'un virus mais d'un utilitaire destiné à mettre fin à des processus.[*]

              ** Ne fais l'étape 2 que si on te le demande, on doit d'abord examiner le premier rapport de SmitfraudFix
          4. houla!!! ca me parait bien compliker tout ca !!! tu as pas une methode plus simple je suis k1 novice lol
            1. voila alors le diagnostic docteur mdr
              1. c est pas bon

                Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
                http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
                Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                • Redémarre ton ordinateur
                • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                • Choisis ton compte.
                Déroule la liste des instructions ci-dessous :
                • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                • Appuie sur Y pour commencer le processus de nettoyage.
                • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                • Appuie sur une touche pour redémarrer le PC.
                • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum
            2. Scan saved at 13:24:19, on 27/09/2008
              Platform: Windows Vista SP1 (WinNT 6.00.1905)
              MSIE: Internet Explorer v7.00 (7.00.6001.18000)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\taskeng.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\RtHDVCpl.exe
              C:\Windows\System32\rundll32.exe
              C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
              C:\Program Files\Windows Media Player\wmpnscfg.exe
              C:\Windows\System32\rundll32.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Windows\system32\conime.exe
              C:\Windows\Explorer.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - URLSearchHook: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
              R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
              O1 - Hosts: ::1 localhost
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - (no file)
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\coIEPlg.dll
              O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
              O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\PROGRA~1\COMMON~1\SYMANT~1\IDS\IPSBHO.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
              O3 - Toolbar: Afficher Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\2.0\CoIEPlg.dll
              O4 - HKLM\..\Run: [VX1000] C:\Windows\vVX1000.exe
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
              O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\RunOnce: [WLuSetup] C:\Program Files\Symantec\LiveUpdate\luupdate.exe -p wlumsp.msp
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
              O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S87E3.tmp" /EF "HKCU"
              O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series (Copie 1)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S6A17.tmp" /EF "HKCU"
              O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series (Copie 2)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S1810.tmp" /EF "HKCU"
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [ieugasw] "c:\users\eric\appdata\local\ieugasw.exe" ieugasw
              O4 - HKCU\..\Run: [wmuak] "c:\users\eric\appdata\local\wmuak.exe" wmuak
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
              O4 - Global Startup: OFFICE One Startup v7.lnk = ?
              O8 - Extra context menu item: &Search - ?p=ZCxdm873MXFR
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
              O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
              O13 - Gopher Prefix:
              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
              O16 - DPF: {BA162249-F2C5-4851-8ADC-FC58CB424243} (Image Uploader Control) - http://copainsdavant.linternaute.com/html_include_bibliotheque/objimageuploader/5.0.15.0/ImageUploader5.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O16 - DPF: {D71F9A27-723E-4B8B-B428-B725E47CBA3E} - http://imikimi.com/download/imikimi_plugin_0.5.1.cab
              O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
              O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
              O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
              O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
              O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
              O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
              O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
              O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
              O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
              O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
              O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
              O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
              O23 - Service: Symantec Core LC - Unknown owner - C:\PROGRA~1\COMMON~1\SYMANT~1\CCPD-LC\symlcsvc.exe
              O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
              1. allez !!!dit moi ke ca y est!! ke mon pc est soigner et ke je n orai plus toutes ces pub envahissantes !! lol
                1. on va verifier
                  pour cela fait 1 nouveau scan hijackthis et colle le stp
              2. Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.407 [GMT 2:00]
                Lancé depuis: C:\Users\eric\Downloads\ComboFix.exe
                .

                ((((((((((((((((((((((((((((( Fichiers créés du 2008-08-27 au 2008-09-27 ))))))))))))))))))))))))))))))))))))
                .

                2008-09-27 09:24 . 2008-09-27 09:24 <REP> d-------- C:\Users\eric\AppData\Roaming\Malwarebytes
                2008-09-27 09:24 . 2008-09-27 09:24 <REP> d-------- C:\Users\All Users\Malwarebytes
                2008-09-27 09:24 . 2008-09-27 09:24 <REP> d-------- C:\ProgramData\Malwarebytes
                2008-09-27 09:24 . 2008-09-27 09:24 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                2008-09-27 09:24 . 2008-09-10 00:04 38,528 --a------ C:\Windows\System32\drivers\mbamswissarmy.sys
                2008-09-27 09:24 . 2008-09-10 00:03 17,200 --a------ C:\Windows\System32\drivers\mbam.sys
                2008-09-24 17:40 . 2008-09-24 17:40 <REP> d-------- C:\Program Files\Trend Micro
                2008-09-10 09:20 . 2008-07-31 03:13 4,240,384 --a------ C:\Windows\System32\GameUXLegacyGDFs.dll
                2008-09-10 09:20 . 2008-08-02 03:01 625,152 --a------ C:\Windows\System32\drivers\dxgkrnl.sys
                2008-09-10 09:20 . 2008-06-26 05:29 565,248 --a------ C:\Windows\System32\emdmgmt.dll
                2008-09-10 09:20 . 2008-06-26 05:29 303,616 --a------ C:\Windows\System32\wmpeffects.dll
                2008-09-10 09:20 . 2008-05-08 21:21 211,968 --a------ C:\Windows\System32\drivers\mrxsmb10.sys
                2008-09-10 09:20 . 2008-05-20 04:07 148,480 --a------ C:\Windows\System32\drivers\nwifi.sys
                2008-09-10 09:20 . 2008-06-26 05:29 45,056 --a------ C:\Windows\System32\dataclen.dll
                2008-09-10 09:20 . 2008-08-02 05:26 36,864 --a------ C:\Windows\System32\cdd.dll
                2008-09-10 09:20 . 2008-07-31 05:32 28,160 --a------ C:\Windows\System32\Apphlpdm.dll

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-09-27 09:35 --------- d-----w C:\ProgramData\Google Updater
                2008-09-27 07:06 --------- d-----w C:\ProgramData\Symantec
                2008-09-26 10:22 --------- d-----w C:\Program Files\Norton Security Scan
                2008-09-26 09:07 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
                2008-09-26 08:15 --------- d-----w C:\Users\eric\AppData\Roaming\OFFICEOne7
                2008-09-24 18:35 --------- d-----w C:\Users\eric\AppData\Roaming\dvdcss
                2008-09-24 15:51 --------- d-----w C:\Users\eric\AppData\Roaming\DNA
                2008-09-23 17:29 --------- d-----w C:\Program Files\Windows Live Toolbar
                2008-09-23 12:24 --------- d-----w C:\Users\eric\AppData\Roaming\Packard Bell
                2008-08-31 19:31 --------- d-----w C:\Program Files\Messenger Plus! Live
                2008-08-25 10:36 --------- d-----w C:\Program Files\Spybot - Search & Destroy
                2008-08-20 08:38 --------- d-----w C:\Program Files\Microsoft Silverlight
                2008-08-14 15:07 --------- d-----w C:\Program Files\Windows Mail
                2008-08-09 17:59 --------- d-----w C:\Program Files\Google
                2008-08-09 17:06 --------- d-----w C:\Program Files\CCleaner
                2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
                2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
                2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
                2008-07-30 15:42 23,888 ----a-w C:\Windows\system32\drivers\COH_Mon.sys
                2008-07-30 15:28 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf
                2008-07-30 15:28 10,537 ----a-w C:\Windows\system32\drivers\coh_mon.cat
                2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
                2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
                2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
                2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
                2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
                2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
                2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
                2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
                2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
                2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
                2008-06-27 04:15 827,392 ----a-w C:\Windows\System32\wininet.dll
                2008-05-04 15:24 174 --sha-w C:\Program Files\desktop.ini
                2008-04-03 15:54 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
                2008-04-03 15:54 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
                2008-04-03 15:54 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
                .

                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                REGEDIT4

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
                "SmpcSys"="C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe" [2006-10-23 1092152]
                "EPSON Stylus DX4400 Series"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 180736]
                "EPSON Stylus DX4400 Series (Copie 1)"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 180736]
                "EPSON Stylus DX4400 Series (Copie 2)"="C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE" [2007-03-01 180736]
                "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 1832272]
                "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "VX1000"="C:\Windows\vVX1000.exe" [2007-04-10 709992]
                "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
                "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2008-02-14 51048]
                "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-09-12 86016]
                "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-09-12 8497696]
                "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-09-12 81920]
                "RtHDVCpl"="RtHDVCpl.exe" [2007-03-01 C:\Windows\RtHDVCpl.exe]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                "WLuSetup"="C:\Program Files\Symantec\LiveUpdate\luupdate.exe" [2008-08-01 636280]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "Picasa Media Detector"="C:\Program Files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]

                C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
                OFFICE One Startup v7.lnk - C:\Program Files\OFFICE One v7\OFFICE One Startup v7\oostartupv7.exe [2007-01-26 713728]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                "EnableUIADesktopToggle"= 0 (0x0)

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL

                [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                "UacDisableNotify"=dword:00000001
                "InternetSettingsDisableNotify"=dword:00000001
                "AutoUpdateDisableNotify"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
                "DisableMonitoring"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
                "DisableMonitoring"=dword:00000001

                [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                "DisableMonitoring"=dword:00000001

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
                "EnableFirewall"= 0 (0x0)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
                "{ADDE03A0-D901-4BFD-B31D-4BA4AA1C418D}"= UDP:C:\Program Files\Common Files\aol\acs\AOLDial.exe:AOL Autoconnect
                "{B1D80A3F-D4A7-4F03-819E-73485D705789}"= TCP:C:\Program Files\Common Files\aol\acs\AOLDial.exe:AOL Autoconnect
                "{0D4296E0-6061-4063-BE9D-94969428B856}"= UDP:C:\Program Files\Common Files\aol\acs\AOLacsd.exe:module de connexion AOL
                "{845C6C47-FE62-494B-AD22-7F068B1C68B3}"= TCP:C:\Program Files\Common Files\aol\acs\AOLacsd.exe:module de connexion AOL
                "{68B85345-9E1A-4AF2-B6FF-207E4AFCE139}"= UDP:C:\Program Files\AOL 9.0 VR\waol.exe:AOL
                "{ADD39238-AC6C-4EF6-B161-386EDBB7A39F}"= TCP:C:\Program Files\AOL 9.0 VR\waol.exe:AOL
                "{8C68DD4C-1C01-434E-9787-5081C3F9119F}"= UDP:C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
                "{234DCABD-0039-4FA0-A5DE-C1A901996ACA}"= TCP:C:\Program Files\Common Files\aol\TopSpeed\3.0\aoltpsd3.exe:AOL TopSpeed
                "{1277E6F4-727E-41B0-9007-C076684379D9}"= UDP:C:\Program Files\Common Files\aol\Loader\aolload.exe:AOL Loader
                "{48063463-827B-437B-84A4-538980A954C1}"= TCP:C:\Program Files\Common Files\aol\Loader\aolload.exe:AOL Loader
                "{E315DDEE-0E3D-401A-8168-918A8F7B83B3}"= UDP:C:\Program Files\Common Files\aol\System Information\sinf.exe:AOL System Information
                "{869C9CE4-E55D-4735-980F-C11A0DD2722A}"= TCP:C:\Program Files\Common Files\aol\System Information\sinf.exe:AOL System Information
                "{AA4D537B-838B-4C83-A609-39EA23F9BE5C}"= UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
                "{30420E5A-120A-4494-BDF3-4D1F42E8B819}"= TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
                "{7613496D-7695-4B24-83BE-1EC655C2CF70}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
                "{D685F731-DB7F-4115-B20D-F29D5020DA29}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
                "{E506F35C-82B0-4AE5-B89E-18BB5248260F}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
                "{DC720A66-5815-4534-8D1D-17190DDDA20C}"= UDP:C:\Program Files\BitTorrent_DNA\dna.exe:BitTorrent DNA
                "{AB1AC2FA-7C0B-425B-8D4B-81E137E57BD9}"= TCP:C:\Program Files\BitTorrent_DNA\dna.exe:BitTorrent DNA
                "{4D8F97EB-9C37-4BE7-9523-927CAE9F2DF5}"= UDP:C:\Users\Public\Downloads\BitTorrent\bittorrent.exe:BitTorrent
                "{51ED9E3D-4E62-4EE1-962B-84C02AA66930}"= TCP:C:\Users\Public\Downloads\BitTorrent\bittorrent.exe:BitTorrent
                "{6204CE5D-40C4-422F-8068-F98FFD6CCBCB}"= UDP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
                "{5853664F-567E-435F-9DAF-30738D40D3C9}"= TCP:C:\Program Files\Microsoft LifeCam\LifeExp.exe:LifeExp.exe
                "{53F10D07-7CF3-4824-A061-DBC663D6FAF5}"= UDP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
                "{9868A2CA-7E90-4216-8C6E-B6D9B40959B0}"= TCP:C:\Program Files\Microsoft LifeCam\LifeCam.exe:LifeCam.exe
                "TCP Query User{1BDF372A-309C-4286-9EF5-E1A8726716FB}C:\\program files\\ares\\ares.exe"= UDP:C:\program files\ares\ares.exe:Ares p2p for windows
                "UDP Query User{7EDC8F1D-CC99-4308-BCAF-3618FF2E74A8}C:\\program files\\ares\\ares.exe"= TCP:C:\program files\ares\ares.exe:Ares p2p for windows
                "TCP Query User{A8F96B2C-147E-43CD-9092-C72BBA6DAA78}C:\\users\\eric\\program files\\bittorrent_dna\\dna.exe"= UDP:C:\users\eric\program files\bittorrent_dna\dna.exe:dna.exe
                "UDP Query User{7BC9567C-A7E3-4371-A812-173FECE625F1}C:\\users\\eric\\program files\\bittorrent_dna\\dna.exe"= TCP:C:\users\eric\program files\bittorrent_dna\dna.exe:dna.exe
                "{1A2578A3-DE09-469E-8E1C-D1598659A206}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
                "EnableFirewall"= 0 (0x0)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
                "EnableFirewall"= 0 (0x0)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
                "C:\\Users\\Public\\Downloads\\BitTorrent\\bittorrent.exe"= C:\Users\Public\Downloads\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

                R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\ipsdefs\20080923.001\IDSvix86.sys [2008-09-12 270384]
                R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe [2008-02-14 149864]
                R2 MSCamSvc;MSCamSvc;C:\Program Files\Microsoft LifeCam\MSCamS32.exe [2007-05-17 271720]
                R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-06-15 71096]
                R3 COH_Mon;COH_Mon;C:\Windows\system32\Drivers\COH_Mon.sys [2008-07-30 23888]
                R3 FETND6V;VIA Rhine Family Fast Ethernet Adapter Driver;C:\Windows\system32\DRIVERS\fetnd6v.sys [2008-06-25 44032]
                R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2007-08-13 41008]
                R3 VX1000;VX-1000;C:\Windows\system32\DRIVERS\VX1000.sys [2007-04-10 1966312]
                S3 FET5X86V;VIA Rhine-Family Fast-Ethernet Adapter Driver Service;C:\Windows\system32\DRIVERS\fetnd5bv.sys [2008-01-02 43520]
                S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-03-13 29744]
                S3 UsbSagCom;Mobile Device Full USB Driver;C:\Windows\system32\DRIVERS\UsbSagCom.sys [2007-06-29 51712]

                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{be58341e-b2d6-11dc-a198-00038a000015}]
                \shell\AutoRun\command - I:\ClickMe.exe

                *Newly Created Service* - CATCHME
                *Newly Created Service* - COMHOST
                *Newly Created Service* - PROCEXP90
                .
                Contenu du dossier 'Tâches planifiées'
                .
                - - - - ORPHELINS SUPPRIMES - - - -

                HKCU-Run-ieugasw - c:\users\eric\appdata\local\ieugasw.exe
                HKCU-Run-wmuak - c:\users\eric\appdata\local\wmuak.exe
                HKCU-Run-mqciyak - c:\users\eric\appdata\local\mqciyak.exe
                HKCU-RunOnce-Shockwave Updater - C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100429 -Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SIMBAR={72CA96CB-BAF1-11DC-925F-00038A000015}; FunWebProducts; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506; .NET

                .
                ------- Examen supplémentaire -------
                .
                FireFox -: Profile - C:\Users\eric\AppData\Roaming\Mozilla\Firefox\Profiles\4366ydqn.default\
                FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
                FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://www.msn.fr/
                FF -: plugin - C:\Program Files\BitTorrent_DNA\npbtdna.dll
                FF -: plugin - C:\Program Files\Google\Google Updater\2.3.1314.1135\npCIDetect12.dll
                FF -: plugin - C:\Program Files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
                FF -: plugin - C:\Users\eric\Program Files\DNA\plugins\npbtdna.dll
                .

                **************************************************************************

                catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-09-27 12:42:40
                Windows 6.0.6001 Service Pack 1 NTFS

                Recherche de processus cachés ...

                Recherche d'éléments en démarrage automatique cachés ...

                Recherche de fichiers cachés ...

                Scan terminé avec succès
                Fichiers cachés: 0

                **************************************************************************
                .
                Heure de fin: 2008-09-27 12:45:49
                ComboFix-quarantined-files.txt 2008-09-27 10:45:21

                Avant-CF: 86ÿ266ÿ912ÿ768 octets libres
                Après-CF: 86,252,265,472 octets libres

                192 --- E O F --- 2008-09-26 05:35:57
                • 1
                • 2