Trojan help......

Bonjour,
nous avons fait un scan et a priori nous avons toujours des virus trojan virtumonde et autres....
comment peut on nettoyer completement le pc
je suis totalement novice en la matiere
nous utilisons bit defender comme antivir et antispyware...
merci d avance pour votre aide
pano27
ci joint scan comLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:42:46, on 09/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\documents and settings\arnaud\local settings\application data\sekkqyg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\trend micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lo.st
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://eo.st
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [ItsTV] "C:\Program Files\ItsLabel\ItsTV.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [sekkqyg] "c:\documents and settings\arnaud\local settings\application data\sekkqyg.exe" sekkqyg
O4 - HKCU\..\Run: [SfKg6wIPu] C:\Documents and Settings\Arnaud\Application Data\Microsoft\Windows\tpytddiy.exe
O4 - HKCU\..\Run: [WinButler] C:\Documents and Settings\Arnaud\Application Data\WinButler\WinButler.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.1.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin2.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab
O20 - AppInit_DLLs: liwoia.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PTK License-FIGHTERS-297811811 - Unknown owner - C:\Program Files\Fighters\licenseservice.exe (file missing)
O23 - Service: PTK Live Update-FIGHTERS-297811811 - Unknown owner - C:\Program Files\Fighters\updateservice.exe (file missing)
O23 - Service: PTK Scanner-FIGHTERS-297811811 - Unknown owner - C:\Program Files\Fighters\ScannerService.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 8153 bytes
plet
Configuration: Windows XP
Internet Explorer 7.0

31 réponses

Résumé de la discussion

Une machine Windows XP est infestée par des trojans Vundo et Navipromo, provoquant des redirections et des comportements publicitaires, nécessitant une désinfection complète et des traces persistantes dans le registre. Plusieurs outils ont été employés pour nettoyer l’ordinateur, notamment ComboFix et Malwarebytes Anti-Malware, avec suppression et quarantine de composants, puis redémarrage en mode sans échec et vérifications complémentaires. Des suppressions manuelles de clés de registre et de programmes au démarrage ont été suggérées et effectuées, et les rapports montrent des éléments tels que des fichiers et services infectés supprimés ou mis en quarantaine. En cas de réinfection, il est recommandé de vérifier les sources de téléchargements et de maintenir les mises à jour des logiciels de sécurité pour prévenir la réapparition des menaces.

Bobot (l’IA à votre service)
  1. ci joint 2eme rapport=====Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
    Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-10-31 2436160]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
    Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - BitDefender Toolbar - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll [2008-12-02 86016]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "BitDefender Antiphishing Helper"=C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe [2007-10-09 61440]
    "BDAgent"=C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe [2008-12-02 368640]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"=C:\windows\system32\ctfmon.exe [2008-04-13 15360]
    "eqysmqe"=c:\documents and settings\arnaud\local settings\application data\eqysmqe.exe [2009-01-11 212992]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
    C:\windows\system32\wlnotify.dll [2008-04-13 94208]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
    C:\windows\system32\WgaLogon.dll [2008-09-05 267304]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
    C:\windows\system32\wlnotify.dll [2008-04-13 94208]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
    C:\windows\system32\wlnotify.dll [2008-04-13 94208]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
    C:\windows\system32\wlnotify.dll [2008-04-13 94208]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\dimsntfy]
    C:\windows\System32\dimsntfy.dll [2008-04-13 19456]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
    C:\windows\system32\Ati2evxx.dll [2006-02-07 61440]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
    PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - C:\windows\system32\SHELL32.dll [2008-04-13 8517632]
    CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - C:\windows\system32\SHELL32.dll [2008-04-13 8517632]
    WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SRService]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sr.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\HelpSvc]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\DcomLaunch]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CryptSvc]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\termservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdtcp.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\tdpipe.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SRService]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sr.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SharedAccess]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdsessmgr]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpwd.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpdd.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\rdpcdd.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ipnat.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\ip6fw.sys]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\HelpSvc]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\DcomLaunch]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\CryptSvc]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "DisableTaskMgr"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=
    "NoDrives"=
    "NoDriveAutoRun"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
    "C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Enabled:hpqtra08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
    "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
    "C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
    "C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
    "C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

    ======List of files/folders created in the last 1 months======

    2009-01-14 22:02:02 ----HDC---- C:\windows\$NtUninstallKB958687$
    2009-01-06 00:03:33 ----D---- C:\Program Files\Spyware-Secure
    2008-12-30 11:27:54 ----D---- C:\rsit
    2008-12-24 15:18:33 ----A---- C:\cleannavi.txt
    2008-12-22 10:01:05 ----D---- C:\Documents and Settings\Arnaud\Application Data\Help

    ======List of files/folders modified in the last 1 months======

    2009-01-21 15:24:41 ----D---- C:\windows\Prefetch
    2009-01-21 15:22:48 ----D---- C:\windows\temp
    2009-01-21 02:09:25 ----D---- C:\Program Files\Original-Solitaire
    2009-01-20 22:30:25 ----D---- C:\windows\system32
    2009-01-18 00:40:12 ----D---- C:\Documents and Settings\Arnaud\Application Data\Image Zone Express
    2009-01-15 23:08:16 ----HD---- C:\windows\inf
    2009-01-15 20:53:42 ----D---- C:\windows\system32\ias
    2009-01-15 20:53:42 ----D---- C:\windows\system32\CatRoot2
    2009-01-14 22:08:56 ----D---- C:\WINDOWS
    2009-01-14 22:07:38 ----A---- C:\windows\SchedLgU.Txt
    2009-01-14 22:07:17 ----A---- C:\windows\bdagent.INI
    2009-01-14 22:02:04 ----RSHDC---- C:\windows\system32\dllcache
    2009-01-14 22:02:04 ----D---- C:\windows\system32\drivers
    2009-01-14 22:01:54 ----HD---- C:\windows\$hf_mig$
    2009-01-10 02:35:28 ----A---- C:\windows\system32\MRT.exe
    2009-01-07 10:59:43 ----SHD---- C:\windows\Installer
    2009-01-07 10:59:43 ----HD---- C:\Config.Msi
    2009-01-06 00:03:33 ----RD---- C:\Program Files
    2008-12-26 23:02:17 ----SHD---- C:\System Volume Information
    2008-12-26 23:02:17 ----D---- C:\windows\system32\Restore
    2008-12-24 15:23:44 ----D---- C:\Program Files\Navilog1
    2008-12-23 01:25:01 ----A---- C:\fixnavi.txt
    2008-12-22 16:50:02 ----D---- C:\Program Files\trend micro
    2008-12-22 15:56:12 ----D---- C:\windows\Help

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 bdftdif;bdftdif; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Firewall\bdftdif.sys []
    R1 Imapi;Pilote de filtre de gravure CD; C:\windows\system32\DRIVERS\imapi.sys [2008-04-13 42112]
    R1 intelppm;Pilote de processeur Intel; C:\windows\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
    R1 RDPCDD;RDPCDD; C:\windows\System32\DRIVERS\RDPCDD.sys [2001-08-28 4224]
    R1 TermDD;Pilote de périphérique terminal; C:\windows\system32\DRIVERS\termdd.sys [2008-04-13 40840]
    R2 ElbyCDIO;ElbyCDIO Driver; C:\windows\System32\Drivers\ElbyCDIO.sys [2004-01-27 9728]
    R3 Arp1394;Protocole client ARP 1394; C:\windows\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
    R3 ati2mtag;ati2mtag; C:\windows\system32\DRIVERS\ati2mtag.sys [2006-02-07 1480704]
    R3 bdfsfltr;bdfsfltr; 730079007300740065006D00330032005C0044005200490056004500520053005C00620064006600730066006C00740072002E007300790073000000 []
    R3 BDSelfPr;BDSelfPr; \??\C:\Program Files\BitDefender\BitDefender 2008\bdselfpr.sys []
    R3 ElbyDelay;ElbyDelay; C:\windows\System32\Drivers\ElbyDelay.sys [2004-01-27 3840]
    R3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\windows\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
    R3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\windows\system32\DRIVERS\HPZid412.sys [2005-10-28 49664]
    R3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\windows\system32\DRIVERS\HPZipr12.sys [2005-10-28 16496]
    R3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\windows\system32\DRIVERS\HPZius12.sys [2005-10-28 21568]
    R3 HTTP;HTTP; C:\windows\System32\Drivers\HTTP.sys [2008-04-13 264832]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\windows\system32\drivers\RtkHDAud.sys [2008-04-17 4707328]
    R3 MRxDAV;Redirecteur client WebDav; C:\windows\system32\DRIVERS\mrxdav.sys [2008-04-13 180608]
    R3 mssmbios;Pilote BIOS de gestion de systèmes Microsoft; C:\windows\system32\DRIVERS\mssmbios.sys [2008-04-13 15488]
    R3 NIC1394;Pilote réseau 1394; C:\windows\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
    R3 Ps2;PS2; C:\windows\system32\DRIVERS\PS2.sys [2005-12-12 19072]
    R3 PSched;Planificateur de paquets QoS; C:\windows\system32\DRIVERS\psched.sys [2008-04-13 69120]
    R3 RasPppoe;Pilote PPPOE d'accès à distance; C:\windows\system32\DRIVERS\raspppoe.sys [2008-04-13 41472]
    R3 rdpdr;Pilote de redirecteur de périphérique Terminal Server; C:\windows\system32\DRIVERS\rdpdr.sys [2008-04-13 196224]
    R3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\windows\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
    R3 Trufos;Trufos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\trufos.sys []
    R3 usbccgp;Pilote parent générique USB Microsoft; C:\windows\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
    R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\windows\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
    R3 usbhub;Pilote de concentrateur standard USB Microsoft; C:\windows\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
    R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\windows\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
    R3 usbprint;Classe d'imprimantes USB Microsoft; C:\windows\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
    R3 usbscan;Pilote de scanneur USB; C:\windows\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
    R3 usbstor;Pilote de stockage de masse USB; C:\windows\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
    S1 i2omgmt;i2omgmt; C:\windows\system32\drivers\i2omgmt.sys []
    S3 aec;Suppresseur d'écho acoustique (Noyau Microsoft); C:\windows\system32\drivers\aec.sys [2008-04-13 142592]
    S3 catchme;catchme; \??\C:\DOCUME~1\Arnaud\LOCALS~1\Temp\catchme.sys []
    S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\windows\system32\drivers\drmkaud.sys [2008-04-13 2944]
    S3 HidUsb;Pilote de classe HID Microsoft; C:\windows\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
    S3 Ip6Fw;Pilote du pare-feu Windows IPv6; C:\windows\system32\DRIVERS\Ip6Fw.sys [2008-04-13 36608]
    S3 PDCOMP;PDCOMP; C:\windows\system32\drivers\PDCOMP.sys []
    S3 PDFRAME;PDFRAME; C:\windows\system32\drivers\PDFRAME.sys []
    S3 PDRELI;PDRELI; C:\windows\system32\drivers\PDRELI.sys []
    S3 PDRFRAME;PDRFRAME; C:\windows\system32\drivers\PDRFRAME.sys []
    S3 Profos;Profos; \??\C:\Program Files\Fichiers communs\BitDefender\BitDefender Threat Scanner\profos.sys []
    S3 RDPWD;RDPWD; C:\windows\system32\drivers\RDPWD.sys [2008-04-13 139656]
    S3 Secdrv;Secdrv; C:\windows\system32\DRIVERS\secdrv.sys [2008-04-13 20480]
    S3 ser2pl;USB Filter Driver; C:\windows\system32\DRIVERS\ser2pl.sys [2007-02-02 42496]
    S3 splitter;Splitter audio du noyau Microsoft; C:\windows\system32\drivers\splitter.sys [2008-04-13 6272]
    S3 StillCam;Pilote d'appareil photo numérique série; C:\windows\system32\DRIVERS\serscan.sys [2001-08-23 6912]
    S3 TDPIPE;TDPIPE; C:\windows\system32\drivers\TDPIPE.sys [2008-04-13 12040]
    S3 TDTCP;TDTCP; C:\windows\system32\drivers\TDTCP.sys [2008-04-13 21896]
    S3 WDICA;WDICA; C:\windows\system32\drivers\WDICA.sys []
    S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\windows\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
    S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\windows\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
    S4 AliIde;AliIde; C:\windows\system32\drivers\AliIde.sys []
    S4 cbidf2k;cbidf2k; C:\windows\system32\drivers\cbidf2k.sys [2001-08-28 13952]
    S4 CmdIde;CmdIde; C:\windows\system32\drivers\CmdIde.sys []
    S4 dac2w2k;dac2w2k; C:\windows\system32\drivers\dac2w2k.sys []
    S4 dpti2o;dpti2o; C:\windows\system32\drivers\dpti2o.sys []
    S4 hpn;hpn; C:\windows\system32\drivers\hpn.sys []
    S4 i2omp;i2omp; C:\windows\system32\drivers\i2omp.sys []
    S4 IntelIde;IntelIde; C:\windows\system32\drivers\IntelIde.sys []
    S4 perc2;perc2; C:\windows\system32\drivers\perc2.sys []
    S4 perc2hib;perc2hib; C:\windows\system32\drivers\perc2hib.sys []
    S4 ql12160;ql12160; C:\windows\system32\drivers\ql12160.sys []
    S4 ql1280;ql1280; C:\windows\system32\drivers\ql1280.sys []
    S4 sym_u3;sym_u3; C:\windows\system32\drivers\sym_u3.sys []
    S4 TosIde;TosIde; C:\windows\system32\drivers\TosIde.sys []
    S4 ultra;ultra; C:\windows\system32\drivers\ultra.sys []
    S4 ViaIde;ViaIde; C:\windows\system32\drivers\ViaIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 Ati HotKey Poller;Ati HotKey Poller; C:\windows\system32\Ati2evxx.exe [2006-02-07 405504]
    R2 AudioSrv;Audio Windows; C:\windows\System32\svchost.exe [2008-04-13 14336]
    R2 CryptSvc;Services de cryptographie; C:\windows\system32\svchost.exe [2008-04-13 14336]
    R2 DcomLaunch;Lanceur de processus serveur DCOM; C:\windows\system32\svchost -k DcomLaunch []
    R2 ERSvc;Error Reporting Service; C:\windows\System32\svchost.exe [2008-04-13 14336]
    R2 helpsvc;Aide et support; C:\windows\System32\svchost.exe [2008-04-13 14336]
    R2 LIVESRV;BitDefender Desktop Update Service; C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe [2008-12-02 1179648]
    R2 ShellHWDetection;Détection matériel noyau; C:\windows\System32\svchost.exe [2008-04-13 14336]
    R2 srservice;Service de restauration système; C:\windows\system32\svchost.exe [2008-04-13 14336]
    R2 stisvc;Acquisition d'image Windows (WIA); C:\windows\system32\svchost.exe [2008-04-13 14336]
    R2 Themes;Thèmes; C:\windows\System32\svchost.exe [2008-04-13 14336]
    R2 VSSERV;BitDefender Virus Shield; C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe [2008-12-02 1261568]
    R2 WebClient;WebClient; C:\windows\system32\svchost.exe [2008-04-13 14336]
    R2 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
    R2 wscsvc;Centre de sécurité; C:\windows\System32\svchost.exe [2008-04-13 14336]
    R2 XCOMM;BitDefender Communicator; C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe [2008-12-02 86016]
    R3 ALG;Service de la passerelle de la couche Application; C:\windows\System32\alg.exe [2008-04-13 44544]
    R3 FastUserSwitchingCompatibility;Compatibilité avec le Changement rapide d'utilisateur; C:\windows\System32\svchost.exe [2008-04-13 14336]
    R3 HTTPFilter;HTTP SSL; C:\windows\System32\svchost.exe [2008-04-13 14336]
    R3 Nla;NLA (Network Location Awareness); C:\windows\system32\svchost.exe [2008-04-13 14336]
    R3 scan;BitDefender Threat Scanner; C:\windows\System32\svchost.exe [2008-04-13 14336]
    R3 SSDPSRV;Service de découvertes SSDP; C:\windows\system32\svchost.exe [2008-04-13 14336]
    R3 TermService;Services Terminal Server; C:\windows\System32\svchost -k DComLaunch []
    R3 upnphost;Hôte de périphérique universel Plug-and-Play; C:\windows\system32\svchost.exe [2008-04-13 14336]
    R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
    S3 aspnet_state;Service d'état ASP.NET; C:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
    S3 COMSysApp;Application système COM+; C:\WINDOWS\system32\dllhost.exe [2008-04-13 5120]
    S3 Dot3svc;Configuration automatique de réseau câblé; C:\windows\System32\svchost.exe [2008-04-13 14336]
    S3 EapHost;Service Protocole EAP (Extensible Authentication Protocol); C:\windows\System32\svchost.exe [2008-04-13 14336]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-31 138168]
    S3 hkmsvc;Service Gestion des clés et des certificats d'intégrité; C:\windows\System32\svchost.exe [2008-04-13 14336]
    S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
    S3 ImapiService;Service COM de gravage de CD IMAPI; C:\windows\system32\imapi.exe [2008-04-13 150528]
    S3 napagent;Agent de protection d'accès réseau; C:\windows\System32\svchost.exe [2008-04-13 14336]
    S3 RDSessMgr;Gestionnaire de session d'aide sur le Bureau à distance; C:\WINDOWS\system32\sessmgr.exe [2008-04-13 142848]
    S3 SwPrv;MS Software Shadow Copy Provider; C:\WINDOWS\system32\dllhost.exe [2008-04-13 5120]
    S3 VSS;Cliché instantané de volume; C:\windows\System32\vssvc.exe [2008-04-13 295424]
    S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
    S3 WmdmPmSN;Service de numéro de série du lecteur multimédia portable; C:\windows\System32\svchost.exe [2008-04-13 14336]
    S3 WmiApSrv;Carte de performance WMI; C:\WINDOWS\system32\wbem\wmiapsrv.exe [2008-04-13 126464]
    S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\windows\system32\svchost.exe [2008-04-13 14336]
    S3 xmlprov;Service d'approvisionnement réseau; C:\windows\System32\svchost.exe [2008-04-13 14336]
    S4 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-02-09 520192]
    S4 HidServ;Accès du périphérique d'interface utilisateur; C:\windows\System32\svchost.exe [2008-04-13 14336]
    S4 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2007-12-03 869672]
    S4 NMIndexingService;NMIndexingService; C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe [2007-12-13 447784]
    S4 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2007-08-09 73728]
    S4 PTK License-FIGHTERS-297811811;PTK License-FIGHTERS-297811811; C:\Program Files\Fighters\licenseservice.exe []
    S4 PTK Live Update-FIGHTERS-297811811;PTK Live Update-FIGHTERS-297811811; C:\Program Files\Fighters\updateservice.exe []
    S4 PTK Scanner-FIGHTERS-297811811;PTK Scanner-FIGHTERS-297811811; C:\Program Files\Fighters\ScannerService.exe []

    -----------------EOF-----------------
    1. ci joint 2eme rapport comme demande
      a priori nous avons un souci adware detecte par bitdifender....
      desolee pas trop le temps de nous en occuper dernierement
      merci encore pour ton aide
      1. Contributeur sécurité
        L'infection est encore revenue, les fichiers ont seulement changé de nom... je n'avais jamais vu ça !

        • Télécharge Random's System Information Tool (RSIT) de random/random, et enregistre le sur ton Bureau.
        • Double clique sur RSIT.exe pour lancer l'outil.
        • Clique sur ' continue ' à l'écran Disclaimer.
        • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.
        • Une fois le scan terminé, deux rapports vont apparaitre : poste les tous les deux (dans deux messages différents)

        1. suite message du 27.12.08ci joint 1er rapport

          Logfile of random's system information tool 1.05 (written by random/random)
          Run by Arnaud at 2009-01-21 15:24:38
          Microsoft Windows XP Professionnel
          System drive C: has 59 GB (62%) free of 95 GB
          Total RAM: 447 MB (30% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:24:48, on 21/01/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16762)
          Boot mode: Normal

          Running processes:
          C:\windows\System32\smss.exe
          C:\windows\system32\winlogon.exe
          C:\windows\system32\services.exe
          C:\windows\system32\lsass.exe
          C:\windows\system32\Ati2evxx.exe
          C:\windows\system32\svchost.exe
          C:\windows\System32\svchost.exe
          C:\windows\system32\spoolsv.exe
          C:\windows\System32\svchost.exe
          C:\windows\system32\svchost.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          C:\windows\System32\svchost.exe
          C:\windows\system32\Ati2evxx.exe
          C:\windows\system32\WgaTray.exe
          C:\windows\Explorer.EXE
          C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
          C:\windows\system32\ctfmon.exe
          C:\documents and settings\arnaud\local settings\application data\eqysmqe.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Documents and Settings\Arnaud\Local Settings\Temporary Internet Files\Content.IE5\XK3GMXR3\RSIT[1].exe
          C:\Program Files\trend micro\HijackThis\Arnaud.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
          O4 - HKCU\..\Run: [eqysmqe] "c:\documents and settings\arnaud\local settings\application data\eqysmqe.exe" eqysmqe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
        2. suite message du 27.12.08ci joint 1er rapport

          Logfile of random's system information tool 1.05 (written by random/random)
          Run by Arnaud at 2009-01-21 15:24:38
          Microsoft Windows XP Professionnel
          System drive C: has 59 GB (62%) free of 95 GB
          Total RAM: 447 MB (30% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 15:24:48, on 21/01/2009
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16762)
          Boot mode: Normal

          Running processes:
          C:\windows\System32\smss.exe
          C:\windows\system32\winlogon.exe
          C:\windows\system32\services.exe
          C:\windows\system32\lsass.exe
          C:\windows\system32\Ati2evxx.exe
          C:\windows\system32\svchost.exe
          C:\windows\System32\svchost.exe
          C:\windows\system32\spoolsv.exe
          C:\windows\System32\svchost.exe
          C:\windows\system32\svchost.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          C:\windows\System32\svchost.exe
          C:\windows\system32\Ati2evxx.exe
          C:\windows\system32\WgaTray.exe
          C:\windows\Explorer.EXE
          C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
          C:\windows\system32\ctfmon.exe
          C:\documents and settings\arnaud\local settings\application data\eqysmqe.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Documents and Settings\Arnaud\Local Settings\Temporary Internet Files\Content.IE5\XK3GMXR3\RSIT[1].exe
          C:\Program Files\trend micro\HijackThis\Arnaud.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
          O4 - HKCU\..\Run: [eqysmqe] "c:\documents and settings\arnaud\local settings\application data\eqysmqe.exe" eqysmqe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      2. Contributeur sécurité
        • Fais un clic droit sur poste de travail (qui est sur ton Bureau ou dans le menu démarrer), puis propriétés.
        • Sélectionne l'onglet restauration du système
        • Coche l'option Désactiver la restauration du système sur tous les lecteurs
        • Clique sur OK.

        Puis refais la manipulation inverse pour réactiver la restauration système.

        Ensuite, redémarre ton ordinateur, et poste encore un nouveau rapport hijackthis

        1. ci joint nouveau rapport hijackthis
          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 23:13:17, on 26/12/2008
          Platform: Windows XP SP3 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16762)
          Boot mode: Normal

          Running processes:
          C:\windows\System32\smss.exe
          C:\windows\system32\winlogon.exe
          C:\windows\system32\services.exe
          C:\windows\system32\lsass.exe
          C:\windows\system32\Ati2evxx.exe
          C:\windows\system32\svchost.exe
          C:\windows\System32\svchost.exe
          C:\windows\system32\spoolsv.exe
          C:\windows\System32\svchost.exe
          C:\windows\system32\svchost.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
          C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          C:\windows\System32\svchost.exe
          C:\windows\system32\Ati2evxx.exe
          C:\windows\system32\WgaTray.exe
          C:\windows\Explorer.EXE
          C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
          C:\windows\system32\ctfmon.exe
          C:\Program Files\Windows Media Player\WMPNSCFG.exe
          C:\documents and settings\arnaud\local settings\application data\sgkke.exe
          C:\Program Files\trend micro\HijackThis\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
          O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
          O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [sgkke] "c:\documents and settings\arnaud\local settings\application data\sgkke.exe" sgkke
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
          O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
          O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
          O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      3. Contributeur sécurité
        *** Recherche Programmes installés ***

        Favorit
        Favorit
        Favorit


        Navilog détecte encore ce programme infecté :-S
        Je crois que Favorit correspond à InternetGameBox

        Essaye comme ça : menu démarrer --> panneau de configuration --> ajout/suppression de programmes --> cherche Favorit ou InternetGameBox et désinstalle le.

        Puis redémarre l'ordinateur, relance navilog et choisis l'étape 2 et poste le rapport.

        1. ci joint nouveau rapport
          bon noel
          Clean Navipromo version 3.7.0 commencé le 24/12/2008 à 15:18:33,01

          Outil exécuté depuis C:\Program Files\navilog1

          Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO

          Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
          X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) D CPU 3.20GHz )
          BIOS : BIOS Date: 01/18/2007 Ver: 08.00.12
          USER : Arnaud ( Administrator )
          BOOT : Normal boot

          Antivirus : Bitdefender Antivirus 8.0 (Activated)

          C:\ (Local Disk) - NTFS - Total:92 Go (Free:56 Go)
          D:\ (Local Disk) - NTFS - Total:93 Go (Free:93 Go)
          E:\ (USB)
          F:\ (USB)
          G:\ (USB)
          H:\ (USB)
          I:\ (CD or DVD)

          Mode suppression automatique
          avec prise en charge résultats Catchme et GNS

          Nettoyage exécuté au redémarrage de l'ordinateur

          *** fsbl1.txt non trouvé ***
          (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

          *** Suppression avec sauvegardes résultats GenericNaviSearch ***

          * Suppression dans "C:\windows\System32" *

          * Suppression dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *

          *** Suppression dossiers dans "C:\windows" ***

          *** Suppression dossiers dans "C:\Program Files" ***

          *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

          *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\applic~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" ***

          *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\menudm~1\progra~1" ***

          *** Suppression fichiers ***

          *** Suppression fichiers temporaires ***

          Nettoyage contenu C:\windows\Temp effectué !
          Nettoyage contenu C:\Documents and Settings\Arnaud\locals~1\Temp effectué !

          *** Traitement Recherche complémentaire ***
          (Recherche fichiers spécifiques)

          1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

          2)Recherche, création sauvegardes et suppression Heuristique :

          * Dans "C:\windows\system32" *

          * Dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *

          *** Sauvegarde du Registre vers dossier Safebackup ***

          sauvegarde du Registre réalisée avec succès !

          *** Nettoyage Registre ***

          Nettoyage Registre Ok

          *** Certificats ***

          Certificat Egroup absent !
          Certificat Electronic-Group absent !
          Certificat Montorgueil absent !
          Certificat OOO-Favorit absent !
          Certificat Sunny-Day-Design-Ltdt absent !

          *** Recherche autres dossiers et fichiers connus ***

          *** Nettoyage terminé le 24/12/2008 à 15:23:44,43 ***
      4. ci joint nouveau rapport navilog
        joyeux noel a toi et a nouveau merci pour ton aide

        Search Navipromo version 3.7.0 commencé le 23/12/2008 à 1:22:39,40

        !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
        !!! Postez ce rapport sur le forum pour le faire analyser !!!
        !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

        Outil exécuté depuis C:\Program Files\navilog1

        Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO

        Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
        X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) D CPU 3.20GHz )
        BIOS : BIOS Date: 01/18/2007 Ver: 08.00.12
        USER : Arnaud ( Administrator )
        BOOT : Normal boot

        Antivirus : Bitdefender Antivirus 8.0 (Activated)

        C:\ (Local Disk) - NTFS - Total:92 Go (Free:56 Go)
        D:\ (Local Disk) - NTFS - Total:93 Go (Free:93 Go)
        E:\ (USB)
        F:\ (USB)
        G:\ (USB)
        H:\ (USB)
        I:\ (CD or DVD)

        Recherche executé en mode normal

        *** Recherche Programmes installés ***

        Favorit
        Favorit
        Favorit

        *** Recherche dossiers dans "C:\windows" ***

        *** Recherche dossiers dans "C:\Program Files" ***

        *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

        *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

        *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

        *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\applic~1" ***

        *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" ***

        *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\menudm~1\progra~1" ***

        *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
        pour + d'infos : http://www.gmer.net

        *** Recherche avec GenericNaviSearch ***
        !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
        !!! A vérifier impérativement avant toute suppression manuelle !!!

        * Recherche dans "C:\windows\system32" *

        * Recherche dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *

        *** Recherche fichiers ***

        *** Recherche clés spécifiques dans le Registre ***
        !! Les clés trouvées ne sont pas forcément infectées !!

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "wsqow"="\"c:\\documents and settings\\arnaud\\local settings\\application data\\wsqow.exe\" wsqow"

        *** Module de Recherche complémentaire ***
        (Recherche fichiers spécifiques)

        1)Recherche nouveaux fichiers Instant Access :

        2)Recherche Heuristique :

        * Dans "C:\windows\system32" :

        * Dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" :

        wsqow.exe trouvé !
        wsqow.dat trouvé !
        wsqow_nav.dat trouvé !
        wsqow_navps.dat trouvé !

        3)Recherche Certificats :

        Certificat Egroup absent !
        Certificat Electronic-Group absent !
        Certificat Montorgueil absent !
        Certificat OOO-Favorit absent !
        Certificat Sunny-Day-Design-Ltd absent !

        4)Recherche autres dossiers et fichiers connus :

        *** Analyse terminée le 23/12/2008 à 1:25:01,12 ***
        1. Contributeur sécurité
          Je ne comprends pas... Pour vérifier :

          Relance navilog à partir du raccourci présent sur le Bureau

          Au menu principal, Fais le choix 1
          Laisse toi guider et patiente.
          Patiente jusqu'au message :
          *** Analyse Termine le ..... ***
          Appuie sur une touche le bloc note va s'ouvrir.
          Copie-colle l'intégralité du rapport ici.

          1. SUITE A TON MESSAGE DE CE JOUR. C EST JURE NOUS N AVONS RIEN TELECHARGE DEPUIS QUE TU NOUS A AVERTI.NOUS AVONS UTILISE LES MESSAGERIES ET MSN MESSENGER. CELA PEUT IL VENIR DE LA?????
            1. Contributeur sécurité
              L'infection s'est à nouveau réinstallée... Quels programmes as-tu réinstallé depuis le dernier passage de navilog ?

              1. Contributeur sécurité
                Re,

                Très bien, navilog a supprimé les fichiers infectés. J'espère que tu n'as pas réinstallé de programmes piégés depuis...
                Redémarre ton ordinateur et poste un nouveau rapport hijackthis stp

                Pour répondre, je te conseille de taper ton texte directement dans le cadre en bas, plutôt que de cliquer sur "Répondre à anthony5151", sinon tes messages se retrouvent sur la première page.

                1. ci joint nouveau scan
                  bonne soiree
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 16:52:05, on 22/12/2008
                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v7.00 (7.00.6000.16762)
                  Boot mode: Normal

                  Running processes:
                  C:\windows\System32\smss.exe
                  C:\windows\system32\winlogon.exe
                  C:\windows\system32\services.exe
                  C:\windows\system32\lsass.exe
                  C:\windows\system32\Ati2evxx.exe
                  C:\windows\system32\svchost.exe
                  C:\windows\System32\svchost.exe
                  C:\windows\system32\spoolsv.exe
                  C:\windows\System32\svchost.exe
                  C:\windows\system32\svchost.exe
                  C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
                  C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                  C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                  C:\windows\System32\svchost.exe
                  C:\windows\system32\Ati2evxx.exe
                  C:\windows\system32\WgaTray.exe
                  C:\windows\Explorer.EXE
                  C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                  C:\windows\system32\ctfmon.exe
                  C:\documents and settings\arnaud\local settings\application data\wsqow.exe
                  C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Program Files\trend micro\HijackThis\HijackThis.exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                  O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
                  O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                  O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
                  O4 - HKCU\..\Run: [wsqow] "c:\documents and settings\arnaud\local settings\application data\wsqow.exe" wsqow
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                  O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                  O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                  O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
              2. Contributeur sécurité
                *** Recherche Programmes installés ***

                Favorit
                Favorit
                Favorit
                Favorit


                Toujours pareil, ce programme est infecté, attention à ne plus télécharger n'importe quoi... Préviens les autres utilisateurs du PC stp

                Autre chose importante : ne fais pas de restauration système avant la fin de la désinfection.

                Relance Navilog à l'aide du raccourci navilog1 présent sur le bureau et laisse-toi guider.

                Au menu principal, choisis 2 et valide.
                Le fix va t'informer qu'il va alors redémarrer ton PC
                Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
                Appuie sur une touche comme demandé.
                (si ton Pc ne redémarre pas automatiquement, fais le toi même)
                Au redémarrage de ton PC, choisis ta session habituelle.

                Patiente jusqu'au message :
                *** Nettoyage Termine le ..... ***

                Le bloc note va s'ouvrir, copie/colle ici le rapport, comme tu l’as fait pour l’autre.

                1. Contributeur sécurité
                  Re,

                  Désolé pour le délai de réponse.

                  # Télécharge ToolsCleaner sur ton Bureau pour nettoyer l'ordi de tous les outils qu'on a utilisé : ToolsCleaner
                  Lance le, clique sur Recherche et laisse le scan se finir, puis clique sur Suppression pour nettoyer.
                  Tu peux aussi supprimer les fichiers temporaires.
                  S'il ne supprime pas tout, supprime manuellement ce qui reste.

                  Vérifie en particulier que navilog a bien été supprimé.

                  # Ensuite, désactive le TeaTimer de Spybot (je te conseille de ne pas le réactiver ensuite...)
                  Lance Spybot --> clique sur Mode => coche Mode avancé => Outils => Résident => décoche la case Résident Tea Timer → redémarre ton ordinateur

                  # Puis télécharge à nouveau Navilog1 depuis-ce lien : http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

                  Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
                  Ensuite double clique sur navilog1.exe pour lancer l'installation.
                  Une fois l'installation terminée, lance Navilog depuis le raccourci présent sur le bureau

                  Au menu principal, Fais le choix 1
                  Laisse toi guider et patiente.
                  Patiente jusqu'au message :
                  *** Analyse Termine le ..... ***
                  Appuie sur une touche le bloc note va s'ouvrir.
                  Copie-colle l'intégralité du rapport ici.

                  1. Contributeur sécurité
                    Re,

                    L'un des utilisateurs de l'ordinateur a réinstallé l'infection navipromo que nous avions supprimé... Pour rappel, cette infection s'installe à partir des logiciels piégés suivants :

                    * go-astro
                    * GoRecord
                    * HotTVPlayer / HotTVPlayer & Paris Hilton
                    * Live-Player
                    * MailSkinner
                    * Messenger Skinner
                    * Instant Access
                    * InternetGameBox
                    * Officiale Emule (Version d'Emule modifiée)
                    * Sudoplanet
                    * Webmediaplayer

                    Attention à ce que tu télécharges, et pense à prévenir tous les utilisateurs de l'ordinateur...

                    Poste un nouveau rapport hijackthis stp

                    1. CI JOINT RAPPORT HIJACKTHIS
                      PANO27

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 21:28:55, on 16/12/2008
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16762)
                      Boot mode: Normal

                      Running processes:
                      C:\windows\System32\smss.exe
                      C:\windows\system32\winlogon.exe
                      C:\windows\system32\services.exe
                      C:\windows\system32\lsass.exe
                      C:\windows\system32\Ati2evxx.exe
                      C:\windows\system32\svchost.exe
                      C:\windows\System32\svchost.exe
                      C:\windows\system32\spoolsv.exe
                      C:\windows\System32\svchost.exe
                      C:\windows\system32\svchost.exe
                      C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
                      C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                      C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                      C:\windows\System32\svchost.exe
                      C:\windows\system32\Ati2evxx.exe
                      C:\windows\system32\WgaTray.exe
                      C:\windows\Explorer.EXE
                      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
                      C:\windows\system32\ctfmon.exe
                      C:\Program Files\trend micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
                      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
                      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [wgmmuco] "c:\documents and settings\arnaud\local settings\application data\wgmmuco.exe" wgmmuco
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
                      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
                      O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
                    2. CI JOINT RAPPORT navilog1.exe

                      Search Navipromo version 3.7.0 commencé le 18/12/2008 à 23:58:14,87

                      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                      !!! Postez ce rapport sur le forum pour le faire analyser !!!
                      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

                      Outil exécuté depuis C:\Program Files\navilog1

                      Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO

                      Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
                      X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) D CPU 3.20GHz )
                      BIOS : BIOS Date: 01/18/2007 Ver: 08.00.12
                      USER : Arnaud ( Administrator )
                      BOOT : Normal boot

                      Antivirus : Bitdefender Antivirus 8.0 (Activated)

                      C:\ (Local Disk) - NTFS - Total:92 Go (Free:57 Go)
                      D:\ (Local Disk) - NTFS - Total:93 Go (Free:93 Go)
                      E:\ (USB)
                      F:\ (USB)
                      G:\ (USB)
                      H:\ (USB)
                      I:\ (CD or DVD)

                      Recherche executé en mode normal

                      *** Recherche Programmes installés ***

                      Favorit
                      Favorit
                      Favorit
                      Favorit

                      *** Recherche dossiers dans "C:\windows" ***

                      *** Recherche dossiers dans "C:\Program Files" ***

                      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                      *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                      *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\applic~1" ***

                      *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" ***

                      *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\menudm~1\progra~1" ***

                      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
                      pour + d'infos : http://www.gmer.net

                      *** Recherche avec GenericNaviSearch ***
                      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
                      !!! A vérifier impérativement avant toute suppression manuelle !!!

                      * Recherche dans "C:\windows\system32" *

                      * Recherche dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *

                      *** Recherche fichiers ***

                      *** Recherche clés spécifiques dans le Registre ***
                      !! Les clés trouvées ne sont pas forcément infectées !!

                      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "wgmmuco"="\"c:\\documents and settings\\arnaud\\local settings\\application data\\wgmmuco.exe\" wgmmuco"

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "emseeyk"="\"c:\\documents and settings\\arnaud\\local settings\\application data\\emseeyk.exe\" emseeyk"

                      *** Module de Recherche complémentaire ***
                      (Recherche fichiers spécifiques)

                      1)Recherche nouveaux fichiers Instant Access :

                      2)Recherche Heuristique :

                      * Dans "C:\windows\system32" :

                      * Dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" :

                      emseeyk.exe trouvé !
                      emseeyk.dat trouvé !
                      emseeyk_nav.dat trouvé !
                      emseeyk_navps.dat trouvé !

                      3)Recherche Certificats :

                      Certificat Egroup absent !
                      Certificat Electronic-Group trouvé !
                      Certificat Montorgueil absent !
                      Certificat OOO-Favorit trouvé !
                      Certificat Sunny-Day-Design-Ltd absent !

                      4)Recherche autres dossiers et fichiers connus :

                      *** Analyse terminée le 19/12/2008 à 0:00:53,34 ***
                    3. merci pour ton aide
                      comme convenu voilà le rapport Navilog que tu as demandé

                      Clean Navipromo version 3.7.0 commencé le 19/12/2008 à 22:59:23,67

                      Outil exécuté depuis C:\Program Files\navilog1

                      Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO

                      Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
                      X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) D CPU 3.20GHz )
                      BIOS : BIOS Date: 01/18/2007 Ver: 08.00.12
                      USER : Arnaud ( Administrator )
                      BOOT : Normal boot

                      Antivirus : Bitdefender Antivirus 8.0 (Activated)

                      C:\ (Local Disk) - NTFS - Total:92 Go (Free:57 Go)
                      D:\ (Local Disk) - NTFS - Total:93 Go (Free:93 Go)
                      E:\ (USB)
                      F:\ (USB)
                      G:\ (USB)
                      H:\ (USB)
                      I:\ (CD or DVD)

                      Mode suppression automatique
                      avec prise en charge résultats Catchme et GNS

                      Nettoyage exécuté au redémarrage de l'ordinateur

                      *** fsbl1.txt non trouvé ***
                      (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)

                      *** Suppression avec sauvegardes résultats GenericNaviSearch ***

                      * Suppression dans "C:\windows\System32" *

                      * Suppression dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *

                      *** Suppression dossiers dans "C:\windows" ***

                      *** Suppression dossiers dans "C:\Program Files" ***

                      *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***

                      *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***

                      *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***

                      *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\applic~1" ***

                      *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" ***

                      *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\menudm~1\progra~1" ***

                      *** Suppression fichiers ***

                      *** Suppression fichiers temporaires ***

                      Nettoyage contenu C:\windows\Temp effectué !
                      Nettoyage contenu C:\Documents and Settings\Arnaud\locals~1\Temp effectué !

                      *** Traitement Recherche complémentaire ***
                      (Recherche fichiers spécifiques)

                      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

                      2)Recherche, création sauvegardes et suppression Heuristique :

                      * Dans "C:\windows\system32" *

                      C:\windows\prefetch\emseeyk*.pf trouvé !
                      Copie C:\windows\prefetch\emseeyk*.pf réalisée avec succès !
                      C:\windows\prefetch\emseeyk*.pf supprimé !

                      C:\windows\prefetch\wgmmuco*.pf trouvé !
                      Copie C:\windows\prefetch\wgmmuco*.pf réalisée avec succès !
                      C:\windows\prefetch\wgmmuco*.pf supprimé !

                      * Dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *

                      emseeyk.exe trouvé !
                      Copie emseeyk.exe réalisée avec succès !
                      emseeyk.exe supprimé !

                      emseeyk.dat trouvé !
                      Copie emseeyk.dat réalisée avec succès !
                      emseeyk.dat supprimé !

                      emseeyk_nav.dat trouvé !
                      Copie emseeyk_nav.dat réalisée avec succès !
                      emseeyk_nav.dat supprimé !

                      emseeyk_navps.dat trouvé !
                      Copie emseeyk_navps.dat réalisée avec succès !
                      emseeyk_navps.dat supprimé !

                      *** Sauvegarde du Registre vers dossier Safebackup ***

                      sauvegarde du Registre réalisée avec succès !

                      *** Nettoyage Registre ***

                      Nettoyage Registre Ok

                      *** Certificats ***

                      Certificat Egroup absent !
                      Certificat Electronic-Group supprimé !
                      Certificat Montorgueil absent !
                      Certificat OOO-Favorit supprimé !
                      Certificat Sunny-Day-Design-Ltdt absent !

                      *** Recherche autres dossiers et fichiers connus ***

                      *** Nettoyage terminé le 19/12/2008 à 23:03:26,32 ***
                    4. bonjour,
                      comme convenu les rapports (RSIT) que tu as demandé dans deux messages différents

                      le premier

                      info.txt logfile of random's system information tool 1.05 2008-12-30 11:28:08

                      ======Uninstall list======

                      -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
                      -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
                      -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
                      -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
                      -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
                      -->C:\WINDOWS\UNRecode.exe /UNINSTALL
                      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
                      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                      Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
                      Ad-remover-->C:\Program Files\Ad-remover\Uninstal.exe
                      Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
                      ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
                      Avanquest update-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -l0x40c
                      BitDefender Antivirus 2008-->MsiExec.exe /I{7764592F-FFE0-4292-82B7-9732C66F10E5}
                      Casino Spin Palace-->C:\MicroGaming\Casino\SpinPalace\install.exe -uninstall
                      CloneDVD2-->"C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
                      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
                      Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
                      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
                      DVD Decoder Pak for Windows XP-->MsiExec.exe /X{92C5DB3D-9D6F-4324-BB11-57825F4C2635}
                      DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
                      Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /u
                      Favorit-->"c:\documents and settings\arnaud\local settings\application data\sgkke.exe" -uninstall
                      Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
                      Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
                      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
                      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
                      HP Extended Capabilities 6.1-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
                      HP Imaging Device Functions 6.1-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
                      HP Photosmart Essential-->MsiExec.exe /X{D7CAE58E-26DE-49B7-A75D-EAEDF76726BE}
                      HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
                      HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
                      HP PSC & OfficeJet 6.1.A-->"C:\Program Files\HP\Digital Imaging\{E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}\setup\hpzscr01.exe" -datfile hposcr08.dat
                      HP Solution Center and Imaging Support Tools 6.1-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
                      ItsTV 3.0-->"C:\Program Files\ItsLabel\unins000.exe"
                      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
                      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                      Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
                      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
                      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
                      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
                      Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
                      Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
                      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\windows\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\windows\$NtUninstallKB954600$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\windows\$NtUninstallKB956802$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
                      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
                      Mise à jour pour Windows XP (KB955839)-->"C:\windows\$NtUninstallKB955839$\spuninst\spuninst.exe"
                      mobile PhoneTools-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F18E8A0F-BE99-4305-96A5-6C0FD9D7D999}\setup.exe" -l0x40c
                      MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
                      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
                      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
                      Navilog1 3.7.0-->"C:\Program Files\Navilog1\unins000.exe"
                      Nero 8-->MsiExec.exe /X{5FCCD531-1B38-4A94-924C-127F722F1036}
                      neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
                      Original-Solitaire-->C:\Program Files\Original-Solitaire\uninst.exe
                      Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe"
                      QCad-->C:\WINDOWS\iun3405.exe C:\Program Files\QCad
                      QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
                      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
                      Shareaza 2.3.1.0-->"C:\Program Files\Shareaza\Uninstall\unins000.exe"
                      TV sur PC-->C:\Program Files\Neuf\TV_PC\uninstall.exe
                      VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
                      VirginMega.Fr Premium-->MsiExec.exe /I{EE467474-04A8-48D5-8DDF-0F8D3A3CCBE5}
                      Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
                      Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
                      Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
                      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
                      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
                      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"

                      System event log

                      Computer Name: PCDEARNAUD
                      Event Code: 7035
                      Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

                      Record Number: 5965
                      Source Name: Service Control Manager
                      Time Written: 20081116140405.000000+060
                      Event Type: Informations
                      User: PCDEARNAUD\Arnaud

                      Computer Name: PCDEARNAUD
                      Event Code: 7036
                      Message: Le service Téléphonie est entré dans l'état : en cours d'exécution.

                      Record Number: 5964
                      Source Name: Service Control Manager
                      Time Written: 20081116140405.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: PCDEARNAUD
                      Event Code: 35
                      Message: Le service de temps synchronise maintenant l'heure système avec la
                      source de temps time.windows.com (ntp.m|0x1|192.168.1.20:123->207.46.197.32:123).

                      Record Number: 5963
                      Source Name: W32Time
                      Time Written: 20081116140404.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: PCDEARNAUD
                      Event Code: 7036
                      Message: Le service Service de la passerelle de la couche Application est entré dans l'état : en cours d'exécution.

                      Record Number: 5962
                      Source Name: Service Control Manager
                      Time Written: 20081116140400.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: PCDEARNAUD
                      Event Code: 7035
                      Message: Un contrôle Démarrer a correctement été envoyé au service Service de la passerelle de la couche Application.

                      Record Number: 5961
                      Source Name: Service Control Manager
                      Time Written: 20081116140400.000000+060
                      Event Type: Informations
                      User: AUTORITE NT\SYSTEM

                      Application event log

                      Computer Name: PCDEARNAUD
                      Event Code: 105
                      Message: The service was started.

                      Record Number: 6007
                      Source Name: ATI Smart
                      Time Written: 20081107205535.000000+060
                      Event Type: Informations
                      User:

                      Computer Name: PCDEARNAUD
                      Event Code: 1524
                      Message: Windows ne peut pas décharger vos classes fichier de Registre - il est en cours d'utilisation par d'autres applications ou services. Le fichier sera déchargé quand il ne sera plus utilisé.

                      Record Number: 6006
                      Source Name: Userenv
                      Time Written: 20081107205350.000000+060
                      Event Type: Avertissement
                      User: PCDEARNAUD\Arnaud

                      Computer Name: PCDEARNAUD
                      Event Code: 1002
                      Message: Application bloquée iexplore.exe, version 7.0.6000.16735, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

                      Record Number: 6005
                      Source Name: Application Hang
                      Time Written: 20081107203802.000000+060
                      Event Type: erreur
                      User:

                      Computer Name: PCDEARNAUD
                      Event Code: 1002
                      Message: Application bloquée ItsTV.exe, version 1.0.0.1, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

                      Record Number: 6004
                      Source Name: Application Hang
                      Time Written: 20081107203519.000000+060
                      Event Type: erreur
                      User:

                      Computer Name: PCDEARNAUD
                      Event Code: 1002
                      Message: Application bloquée ItsTV.exe, version 1.0.0.1, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

                      Record Number: 6003
                      Source Name: Application Hang
                      Time Written: 20081107203519.000000+060
                      Event Type: erreur
                      User:

                      ======Environment variables======

                      "ComSpec"=%SystemRoot%\system32\cmd.exe
                      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
                      "windir"=%SystemRoot%
                      "FP_NO_HOST_CHECK"=NO
                      "OS"=Windows_NT
                      "PROCESSOR_ARCHITECTURE"=x86
                      "PROCESSOR_LEVEL"=15
                      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 6 Stepping 4, GenuineIntel
                      "PROCESSOR_REVISION"=0604
                      "NUMBER_OF_PROCESSORS"=1
                      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                      "TEMP"=%SystemRoot%\TEMP
                      "TMP"=%SystemRoot%\TEMP

                      -----------------EOF-----------------
                  2. Contributeur sécurité
                    Bonsoir,

                    Le problème c'est qu'en 10 jours, si tu as réutilisé ton PC, il y a des chances que d'autres fichiers infectés se soient créés... Pour vérifier :
                    - Relance MalwareBytes anti-malware et mets le à jour
                    - Puis va dans l'onglet "Recherche", coche "Exécuter un examen rapide" puis "Rechercher"
                    - Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
                    - A la fin du scan, clique sur Afficher les résultats
                    - Coche tous les éléments détectés puis clique sur Supprimer la sélection
                    - Enregistre le rapport
                    - S'il t'est demandé de redémarrer, clique sur Yes

                    Poste le rapport de scan après la suppression ici

                    Pour le message de Windows, ce n'est pas grave, il va juste falloir refaire l'activation :
                    * Menu Démarrer
                    * Tous les programmes
                    * Accessoires
                    * Outils système
                    * Clique sur Activation de Windows et laisse toi guider.

                    1. bonsoir ci joint nouveau scan
                      Malwarebytes' Anti-Malware 1.31
                      Version de la base de données: 1501
                      Windows 5.1.2600 Service Pack 3

                      15/12/2008 20:16:32
                      mbam-log-2008-12-15 (20-16-32).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 48586
                      Temps écoulé: 4 minute(s), 34 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 4

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      C:\Documents and Settings\Arnaud\Local Settings\Application Data\wgmmuco_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Arnaud\Local Settings\Application Data\wgmmuco_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Arnaud\Local Settings\Application Data\wgmmuco.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
                      C:\Documents and Settings\Arnaud\Local Settings\Application Data\wgmmuco.exe (Adware.Navipromo.H) -> Delete on reboot.
                  3. Contributeur sécurité
                    Tu as essayé avec quelle touche ? C'est généralement sur la touche F8 qu'il faut appuyer, mais c'est aussi F5 sur certains PC. Il faut tapoter plusieurs fois de suite dessus avant l'apparition du logo Windows.

                    Quand tu le fais, rien ne se passe ?

                    1. bonsoir.desolee j ai peu suivi l affaire depuis 10 jours.un peu debordee par ailleurs.
                      ci joint rapport moveit comme demande
                      ========== PROCESSES ==========
                      Process explorer.exe killed successfully.
                      ========== FILES ==========
                      LoadLibrary failed for c:\windows\system32\onvwcdwj.dll
                      c:\windows\system32\onvwcdwj.dll NOT unregistered.
                      c:\windows\system32\onvwcdwj.dll moved successfully.
                      LoadLibrary failed for c:\windows\system32\frbrkrss.dll
                      c:\windows\system32\frbrkrss.dll NOT unregistered.
                      c:\windows\system32\frbrkrss.dll moved successfully.
                      LoadLibrary failed for c:\windows\system32\iykddgbl.dll
                      c:\windows\system32\iykddgbl.dll NOT unregistered.
                      c:\windows\system32\iykddgbl.dll moved successfully.
                      LoadLibrary failed for c:\windows\system32\gktuugme.dll
                      c:\windows\system32\gktuugme.dll NOT unregistered.
                      c:\windows\system32\gktuugme.dll moved successfully.
                      LoadLibrary failed for c:\windows\system32\skajlyvl.dll
                      c:\windows\system32\skajlyvl.dll NOT unregistered.
                      c:\windows\system32\skajlyvl.dll moved successfully.
                      LoadLibrary failed for c:\windows\system32\fyufljuu.dll
                      c:\windows\system32\fyufljuu.dll NOT unregistered.
                      c:\windows\system32\fyufljuu.dll moved successfully.
                      c:\windows\system32\vxqdchdy.tmp moved successfully.
                      c:\windows\system32\lnkljube.tmp moved successfully.
                      ========== REGISTRY ==========
                      Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows\\AppInit_DLLs not found.
                      ========== COMMANDS ==========
                      User's Temp folder emptied.
                      User's Temporary Internet Files folder emptied.
                      User's Internet Explorer cache folder emptied.
                      Local Service Temp folder emptied.
                      File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                      Local Service Temporary Internet Files folder emptied.
                      Windows Temp folder emptied.
                      Temp folders emptied.
                      Explorer started successfully

                      OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12142008_220318

                      SUITE AU REDEMARRAGE EN MODE SANS ECHEC J AI UN SOUCIS AVEC WINDOWS
                      LE MESSAGE SUIVANT APPARAIT
                      Cette copie de Windows n'a pas pu être validée.
                      La clé de produit Windows détectée sur votre ordinateur n'a pas été attribuée par Microsoft.

                      QUE DOIS JE FAIRE?????
                      MERCI D AVANCE PANO 27
                  4. Contributeur sécurité
                    Le rapport est daté du 27 novembre... On va utiliser un autre logiciel :

                    ---> Télécharge OTMoveIt3 (de OldTimer) sur ton Bureau : http://oldtimer.geekstogo.com/OTMoveIt3.exe

                    --> Redémarre en mode sans échec : Tuto
                    Attention, n'utilise surtout pas la méthode avec l'utilitaire de configuration système !

                    ---> Double-clique sur OTMoveIt3.exe afin de le lancer.
                    ---> Copie/colle le texte suivant dans le cadre « Paste Instructions for Items to be Moved » et clique sur Moveit :

                    :processes 
                    explorer.exe 
                    
                    :files 
                    c:\windows\system32\onvwcdwj.dll 
                    c:\windows\system32\frbrkrss.dll 
                    c:\windows\system32\iykddgbl.dll 
                    c:\windows\system32\gktuugme.dll 
                    c:\windows\system32\skajlyvl.dll 
                    c:\windows\system32\fyufljuu.dll 
                    c:\windows\system32\vxqdchdy.tmp 
                    c:\windows\system32\lnkljube.tmp 
                    
                    :Reg 
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] 
                    "AppInit_DLLs"=- 
                    
                    :commands 
                    [purity] 
                    [emptytemp] 
                    [start explorer] 
                    [reboot] 


                    Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.

                    ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles
                    Le nom du rapport correspond au moment de sa création : date_heure.log

                    1. bonjour
                      je n arrive pas a redemarrer en mode sans échec ya t il une subtilite que je ne connais pas????
                      merci davance
                  5. Contributeur sécurité
                    Le script n'a pas été pris en compte...
                    De plus, tu as oublié de désactiver ton antivirus avant de lancer le scan, tu prends des risques...

                    Pour le script, vérifie qu'il n'y a aucune ligne blanche au début (la première ligne est File:: ) et qu'il est complet.

                    1. bonjour
                      ci joint nouveau combo fix nous avons refait toute la manip en désactivant bitdefender normalement.
                      a+ pano2
                      ComboFix 08-11-27.03 - Arnaud 2008-12-02 23:36:04.8 - NTFSx86
                      Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.144 [GMT 1:00]
                      Lancé depuis: c:\documents and settings\Arnaud\Bureau\ComboFix.exe
                      Commutateurs utilisés :: c:\documents and settings\Arnaud\Bureau\CFScript.txt
                      * Un nouveau point de restauration a été créé
                      * Resident AV is active

                      [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
                      .

                      ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
                      .

                      2008-12-02 18:48 . 2008-12-02 18:48 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Bitdefender
                      2008-12-02 18:48 . 2008-12-02 18:48 <REP> d-------- c:\documents and settings\All Users\Application Data\BitDefender
                      2008-11-28 19:41 . 2008-11-28 19:41 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Yahoo!
                      2008-11-28 19:39 . 2008-12-02 14:32 <REP> d-------- c:\program files\Yahoo!
                      2008-11-26 00:52 . 2008-11-26 01:08 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Azureus
                      2008-11-26 00:52 . 2008-11-26 00:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Azureus
                      2008-11-26 00:51 . 2008-11-26 01:30 <REP> d-------- c:\program files\Vuze
                      2008-11-26 00:51 . 2008-11-26 00:51 <REP> d-------- c:\program files\Fichiers communs\i4j_jres
                      2008-11-23 16:44 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
                      2008-11-23 16:40 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
                      2008-11-23 16:14 . 2008-11-23 16:35 122 --a------ c:\windows\system32\privacy.xml
                      2008-11-23 13:10 . 2008-12-02 14:30 <REP> d-------- c:\program files\eMule
                      2008-11-21 22:35 . 2008-11-21 22:35 <REP> d-------- c:\windows\system32\Adobe
                      2008-11-17 19:28 . 2008-11-27 21:38 <REP> d-------- c:\program files\Ad-remover
                      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Malwarebytes
                      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                      2008-11-16 22:05 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                      2008-11-16 22:05 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                      2008-11-16 13:05 . 2008-11-28 00:48 <REP> d-------- c:\program files\Navilog1
                      2008-11-16 12:08 . 2008-11-16 12:08 912 --a------ c:\windows\system32\onvwcdwj.dll
                      2008-11-16 11:55 . 2008-11-16 11:55 912 --a------ c:\windows\system32\frbrkrss.dll
                      2008-11-15 10:43 . 2008-11-15 10:43 912 --a------ c:\windows\system32\iykddgbl.dll
                      2008-11-14 20:20 . 2008-11-14 20:20 912 --a------ c:\windows\system32\gktuugme.dll
                      2008-11-14 10:41 . 2008-11-14 10:41 912 --a------ c:\windows\system32\skajlyvl.dll
                      2008-11-13 22:12 . 2008-11-13 22:12 <REP> d-------- c:\program files\Original-Solitaire
                      2008-11-12 19:28 . 2008-11-12 19:28 <REP> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
                      2008-11-09 13:39 . 2008-11-09 13:39 91 --a------ c:\windows\wininit.ini
                      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\program files\Spybot - Search & Destroy
                      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                      2008-11-04 23:01 . 2008-11-04 23:01 912 --a------ c:\windows\system32\fyufljuu.dll
                      2008-11-03 23:01 . 2008-11-03 23:01 120 ---hs---- c:\windows\system32\vxqdchdy.tmp
                      2008-11-02 19:51 . 2008-11-29 14:42 81,984 --a------ c:\windows\system32\bdod.bin
                      2008-11-02 18:28 . 2008-11-02 18:29 120 ---hs---- c:\windows\system32\lnkljube.tmp

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2008-12-02 17:48 --------- d-----w c:\program files\Fichiers communs\BitDefender
                      2008-11-28 23:55 --------- d-----w c:\program files\DivX
                      2008-11-23 12:52 --------- d-----w c:\documents and settings\Arnaud\Application Data\Image Zone Express
                      2008-11-12 15:54 --------- d-----w c:\program files\ItsLabel
                      2008-11-07 21:03 --------- d-----w c:\documents and settings\All Users\Application Data\Software Licensors
                      2008-11-07 19:51 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
                      2008-11-02 21:13 --------- d--h--w c:\program files\InstallShield Installation Information
                      2008-11-02 21:07 --------- d-----w c:\program files\Fighters
                      2008-11-01 12:08 --------- d-----w c:\program files\BitDefender
                      2008-11-01 11:10 --------- d-----w c:\program files\trend micro
                      2008-10-31 16:39 --------- d-----w c:\documents and settings\All Users\Application Data\Fighters
                      2008-10-31 08:06 --------- d-----w c:\program files\Google
                      2008-10-30 18:02 --------- d-----w c:\documents and settings\Arnaud\Application Data\WinButler
                      2008-10-27 14:38 --------- d-----w c:\documents and settings\All Users\Application Data\Microgaming
                      2008-10-27 14:38 --------- d-----w c:\documents and settings\All Users\Application Data\MGS
                      2008-10-24 22:07 --------- d-----w c:\program files\Microsoft Silverlight
                      2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
                      2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
                      2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
                      2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
                      2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
                      2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
                      2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
                      2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
                      2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
                      2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
                      2008-10-08 18:39 --------- d-----w c:\program files\Fichiers communs\InstallShield
                      2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
                      2008-09-25 08:03 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
                      2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
                      2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll
                      2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
                      2008-05-19 20:09 16,304 ----a-w c:\documents and settings\Arnaud\Application Data\GDIPFONTCACHEV1.DAT
                      .

                      ((((((((((((((((((((((((((((( snapshot_2008-11-29_14.44.11.10 )))))))))))))))))))))))))))))))))))))))))
                      .
                      - 2008-11-24 21:42:17 61,440 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\helpicon.exe
                      + 2008-12-02 17:49:09 61,440 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\helpicon.exe
                      - 2008-11-24 21:42:17 32,768 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\maintenance_icon.exe
                      + 2008-12-02 17:49:09 32,768 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\maintenance_icon.exe
                      - 2008-11-24 21:42:17 22,486 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\register_icon.exe
                      + 2008-12-02 17:49:09 22,486 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\register_icon.exe
                      - 2008-11-24 21:42:17 57,344 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\texticon.exe
                      + 2008-12-02 17:49:08 57,344 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\texticon.exe
                      - 2008-01-07 16:41:34 196,368 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
                      + 2007-08-02 15:03:44 188,432 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
                      + 2007-07-20 13:54:30 77,824 ----a-w c:\windows\system32\xcomm.dll
                      .
                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                      REGEDIT4

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
                      "BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2007-10-31 311296]

                      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                      "AntiVirusOverride"=dword:00000001

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                      "DisableNotifications"= 1 (0x1)

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                      "%windir%\\system32\\sessmgr.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

                      S4 PTK License-FIGHTERS-297811811;PTK License-FIGHTERS-297811811;c:\program files\Fighters\licenseservice.exe []
                      S4 PTK Live Update-FIGHTERS-297811811;PTK Live Update-FIGHTERS-297811811;c:\program files\Fighters\updateservice.exe []
                      S4 PTK Scanner-FIGHTERS-297811811;PTK Scanner-FIGHTERS-297811811;c:\program files\Fighters\ScannerService.exe []

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                      bdx REG_MULTI_SZ scan

                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1534df1-4b3d-11dd-ba25-0016ec83fae1}]
                      \Shell\AutoRun\command - J:\
                      \Shell\explore\Command - RECYCLED\INFO.exe
                      \Shell\open\Command - RECYCLED\INFO.exe

                      *Newly Created Service* - BDFSFLTR
                      .

                      **************************************************************************

                      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2008-12-02 23:38:08
                      Windows 5.1.2600 Service Pack 3 NTFS

                      Recherche de processus cachés ...

                      Recherche d'éléments en démarrage automatique cachés ...

                      Recherche de fichiers cachés ...

                      Scan terminé avec succès
                      Fichiers cachés: 0

                      **************************************************************************

                      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
                      "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\

                      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
                      "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
                      .
                      --------------------- DLLs chargées dans les processus actifs ---------------------

                      - - - - - - - > 'winlogon.exe'(592)
                      c:\windows\system32\Ati2evxx.dll
                      .
                      Heure de fin: 2008-12-02 23:38:59
                      ComboFix-quarantined-files.txt 2008-12-02 22:38:52
                      ComboFix2.txt 2008-12-02 13:49:22
                      ComboFix3.txt 2008-11-29 13:45:01
                      ComboFix4.txt 2008-11-25 20:34:38
                      ComboFix5.txt 2008-12-02 20:43:05

                      Avant-CF: 61 821 313 024 octets libres
                      Après-CF: 61,851,443,200 octets libres

                      166 --- E O F --- 2008-11-23 21:03:59
                      7
                  6. Contributeur sécurité
                    Oula, oui tu as raison, quel boulet je suis :(
                    Merci de l'avoir signalé !

                    @ pano27 :

                    Excuse moi...
                    Toujours avec toutes les protections désactivées, fais ceci :

                    Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
                    Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

                    ----------------------------------------------------------
                    File::
                    c:\windows\system32\onvwcdwj.dll
                    c:\windows\system32\frbrkrss.dll
                    c:\windows\system32\iykddgbl.dll
                    c:\windows\system32\gktuugme.dll
                    c:\windows\system32\skajlyvl.dll
                    c:\windows\system32\fyufljuu.dll
                    c:\windows\system32\vxqdchdy.tmp
                    c:\windows\system32\lnkljube.tmp

                    Registry::
                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                    "AppInit_DLLs"=-

                    ------------------------------------------------------------------

                    - Enregistre ce fichier sur ton bureau (et pas ailleurs !) sous le nom CFScript.txt
                    - Quitte le Bloc Notes

                    · Fais un glisser/déposer de ce fichier CFScript sur le fichier C-Fix.exe (combofix) comme sur ce lien : http://apu.mabul.org/up/apu/2008/09/06/img-2258535my8h.gif

                    * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
                    Ne touche à rien tant que le scan n'est pas terminé.
                    * Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                    * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                    1. voilà le rapport comme convenu

                      ComboFix 08-11-27.03 - Arnaud 2008-12-02 23:36:04.8 - NTFSx86
                      Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.144 [GMT 1:00]
                      Lancé depuis: c:\documents and settings\Arnaud\Bureau\ComboFix.exe
                      Commutateurs utilisés :: c:\documents and settings\Arnaud\Bureau\CFScript.txt
                      * Un nouveau point de restauration a été créé
                      * Resident AV is active

                      [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
                      .

                      ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
                      .

                      2008-12-02 18:48 . 2008-12-02 18:48 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Bitdefender
                      2008-12-02 18:48 . 2008-12-02 18:48 <REP> d-------- c:\documents and settings\All Users\Application Data\BitDefender
                      2008-11-28 19:41 . 2008-11-28 19:41 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Yahoo!
                      2008-11-28 19:39 . 2008-12-02 14:32 <REP> d-------- c:\program files\Yahoo!
                      2008-11-26 00:52 . 2008-11-26 01:08 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Azureus
                      2008-11-26 00:52 . 2008-11-26 00:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Azureus
                      2008-11-26 00:51 . 2008-11-26 01:30 <REP> d-------- c:\program files\Vuze
                      2008-11-26 00:51 . 2008-11-26 00:51 <REP> d-------- c:\program files\Fichiers communs\i4j_jres
                      2008-11-23 16:44 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
                      2008-11-23 16:40 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
                      2008-11-23 16:14 . 2008-11-23 16:35 122 --a------ c:\windows\system32\privacy.xml
                      2008-11-23 13:10 . 2008-12-02 14:30 <REP> d-------- c:\program files\eMule
                      2008-11-21 22:35 . 2008-11-21 22:35 <REP> d-------- c:\windows\system32\Adobe
                      2008-11-17 19:28 . 2008-11-27 21:38 <REP> d-------- c:\program files\Ad-remover
                      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
                      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Malwarebytes
                      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
                      2008-11-16 22:05 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
                      2008-11-16 22:05 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
                      2008-11-16 13:05 . 2008-11-28 00:48 <REP> d-------- c:\program files\Navilog1
                      2008-11-16 12:08 . 2008-11-16 12:08 912 --a------ c:\windows\system32\onvwcdwj.dll
                      2008-11-16 11:55 . 2008-11-16 11:55 912 --a------ c:\windows\system32\frbrkrss.dll
                      2008-11-15 10:43 . 2008-11-15 10:43 912 --a------ c:\windows\system32\iykddgbl.dll
                      2008-11-14 20:20 . 2008-11-14 20:20 912 --a------ c:\windows\system32\gktuugme.dll
                      2008-11-14 10:41 . 2008-11-14 10:41 912 --a------ c:\windows\system32\skajlyvl.dll
                      2008-11-13 22:12 . 2008-11-13 22:12 <REP> d-------- c:\program files\Original-Solitaire
                      2008-11-12 19:28 . 2008-11-12 19:28 <REP> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
                      2008-11-09 13:39 . 2008-11-09 13:39 91 --a------ c:\windows\wininit.ini
                      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\program files\Spybot - Search & Destroy
                      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
                      2008-11-04 23:01 . 2008-11-04 23:01 912 --a------ c:\windows\system32\fyufljuu.dll
                      2008-11-03 23:01 . 2008-11-03 23:01 120 ---hs---- c:\windows\system32\vxqdchdy.tmp
                      2008-11-02 19:51 . 2008-11-29 14:42 81,984 --a------ c:\windows\system32\bdod.bin
                      2008-11-02 18:28 . 2008-11-02 18:29 120 ---hs---- c:\windows\system32\lnkljube.tmp

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2008-12-02 17:48 --------- d-----w c:\program files\Fichiers communs\BitDefender
                      2008-11-28 23:55 --------- d-----w c:\program files\DivX
                      2008-11-23 12:52 --------- d-----w c:\documents and settings\Arnaud\Application Data\Image Zone Express
                      2008-11-12 15:54 --------- d-----w c:\program files\ItsLabel
                      2008-11-07 21:03 --------- d-----w c:\documents and settings\All Users\Application Data\Software Licensors
                      2008-11-07 19:51 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
                      2008-11-02 21:13 --------- d--h--w c:\program files\InstallShield Installation Information
                      2008-11-02 21:07 --------- d-----w c:\program files\Fighters
                      2008-11-01 12:08 --------- d-----w c:\program files\BitDefender
                      2008-11-01 11:10 --------- d-----w c:\program files\trend micro
                      2008-10-31 16:39 --------- d-----w c:\documents and settings\All Users\Application Data\Fighters
                      2008-10-31 08:06 --------- d-----w c:\program files\Google
                      2008-10-30 18:02 --------- d-----w c:\documents and settings\Arnaud\Application Data\WinButler
                      2008-10-27 14:38 --------- d-----w c:\documents and settings\All Users\Application Data\Microgaming
                      2008-10-27 14:38 --------- d-----w c:\documents and settings\All Users\Application Data\MGS
                      2008-10-24 22:07 --------- d-----w c:\program files\Microsoft Silverlight
                      2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
                      2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
                      2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
                      2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
                      2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
                      2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
                      2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
                      2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
                      2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
                      2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
                      2008-10-08 18:39 --------- d-----w c:\program files\Fichiers communs\InstallShield
                      2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
                      2008-09-25 08:03 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
                      2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
                      2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll
                      2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
                      2008-05-19 20:09 16,304 ----a-w c:\documents and settings\Arnaud\Application Data\GDIPFONTCACHEV1.DAT
                      .

                      ((((((((((((((((((((((((((((( snapshot_2008-11-29_14.44.11.10 )))))))))))))))))))))))))))))))))))))))))
                      .
                      - 2008-11-24 21:42:17 61,440 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\helpicon.exe
                      + 2008-12-02 17:49:09 61,440 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\helpicon.exe
                      - 2008-11-24 21:42:17 32,768 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\maintenance_icon.exe
                      + 2008-12-02 17:49:09 32,768 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\maintenance_icon.exe
                      - 2008-11-24 21:42:17 22,486 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\register_icon.exe
                      + 2008-12-02 17:49:09 22,486 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\register_icon.exe
                      - 2008-11-24 21:42:17 57,344 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\texticon.exe
                      + 2008-12-02 17:49:08 57,344 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\texticon.exe
                      - 2008-01-07 16:41:34 196,368 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
                      + 2007-08-02 15:03:44 188,432 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
                      + 2007-07-20 13:54:30 77,824 ----a-w c:\windows\system32\xcomm.dll
                      .
                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                      REGEDIT4

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
                      "BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2007-10-31 311296]

                      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                      "AntiVirusOverride"=dword:00000001

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                      "DisableNotifications"= 1 (0x1)

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                      "%windir%\\system32\\sessmgr.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

                      S4 PTK License-FIGHTERS-297811811;PTK License-FIGHTERS-297811811;c:\program files\Fighters\licenseservice.exe []
                      S4 PTK Live Update-FIGHTERS-297811811;PTK Live Update-FIGHTERS-297811811;c:\program files\Fighters\updateservice.exe []
                      S4 PTK Scanner-FIGHTERS-297811811;PTK Scanner-FIGHTERS-297811811;c:\program files\Fighters\ScannerService.exe []

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                      bdx REG_MULTI_SZ scan

                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1534df1-4b3d-11dd-ba25-0016ec83fae1}]
                      \Shell\AutoRun\command - J:\
                      \Shell\explore\Command - RECYCLED\INFO.exe
                      \Shell\open\Command - RECYCLED\INFO.exe

                      *Newly Created Service* - BDFSFLTR
                      .

                      **************************************************************************

                      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2008-12-02 23:38:08
                      Windows 5.1.2600 Service Pack 3 NTFS

                      Recherche de processus cachés ...

                      Recherche d'éléments en démarrage automatique cachés ...

                      Recherche de fichiers cachés ...

                      Scan terminé avec succès
                      Fichiers cachés: 0

                      **************************************************************************

                      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
                      "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\

                      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
                      "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
                      .
                      --------------------- DLLs chargées dans les processus actifs ---------------------

                      - - - - - - - > 'winlogon.exe'(592)
                      c:\windows\system32\Ati2evxx.dll
                      .
                      Heure de fin: 2008-12-02 23:38:59
                      ComboFix-quarantined-files.txt 2008-12-02 22:38:52
                      ComboFix2.txt 2008-12-02 13:49:22
                      ComboFix3.txt 2008-11-29 13:45:01
                      ComboFix4.txt 2008-11-25 20:34:38
                      ComboFix5.txt 2008-12-02 20:43:05

                      Avant-CF: 61 821 313 024 octets libres
                      Après-CF: 61,851,443,200 octets libres

                      166 --- E O F --- 2008-11-23 21:03:59
                  7. Contributeur sécurité
                    Là tu as fait un nouveau scan avec Combofix (et tu as oublié de désactiver ton antivirus, tu risques d'endommager ton ordinateur...)

                    Ce qu'il faut que tu fasses, c'est le CFScript comme indiqué plus bas

                    • 1
                    • 2