Tr/hijacker.gen

Résolu


voila depuis aujourd'hui des alertes de mon anti virus avira sont régulières, il note la présence de tr/ hijacker que je mets en quarantaine systématiquement.
sans succés apparemment. je lis votre forum, j'ai téléchargé RSIT que je ne sais bien sur pas interpréter, surtout j'ai peur de me planter car je ne lis pas l'anglais. est ce que quelqu'un peut m'aider à virer ça. C'est la première fois en dix ans d'utilisation d'ordi que je tombe sur cette bestiole.
merci pour votre aide
Béatrice

42 réponses

Résumé de la discussion

Le fil décrit une infection informatique sur Windows Vista avec Firefox 3.6.3 où l’antivirus Avira signale régulièrement la présence de tr/ hijacker et la quarantaine échoue à éliminer le problème. Des mesures d’analyse et de désinfection sont proposées, en commençant par l’utilisation d’un outil rootkit (GMER) et l’interprétation des rapports RSIT pour cibler les composants malveillants. Des outils complémentaires comme MalwareBytes pour les scans et la suppression, puis Kill'em, ZHPFix et ComboFix peuvent être utilisés selon les rapports pour nettoyer les éléments détectés. En cas de doute sur l’origine des alertes, il est utile de vérifier l’authenticité et la licéité du système, car des mises à jour manquantes et des failles de sécurité peuvent aggraver l’infection.

Bobot (l’IA à votre service)
  1. Salut,

    Peux-tu commencer par mettre les rapport de RSIT comme ceci :

    ● Va sur le site ci-joint.fr

    ● Clique sur le bouton parcourir

    ● Recherche le fichier log.txt qui se trouve dans le dossier C:\rsit et clique sur Ouvrir

    ● Clique sur le bouton "Cliquez ici pour déposer le fichier"

    ● Copie ensuite le lien qui est affiché dans ta réponse.

    Refais la manipulation avec le fichier info.txt
    2
    1. voila j'ai fait ce que tu m'indique mais quelle frousse !! une page c'est ouverte avec des alertes dans tous les sens mais bon avira lui ne dit rien.
      est-ce que je mets là les liens que cijoint me donne ?
      0
  2. Oui, tout à fait, mets les deux liens de ci-joint.
    0
    1. lien info.txt
      http://www.cijoint.fr/cjlink.php?file=cj201004/cijug8bkRB.txt

      lien log.txt
      http://www.cijoint.fr/cjlink.php?file=cj201004/cijzjkUMEV.txt

      j'espère sans erreur !
      0
  3. Le lien info.txt ne fonctionne pas, essaie de le refaire.

    Ensuite :

    ● Télécharge gmer sur ton bureau à partir de ce lien ==> http://www.gmer.net/#files en cliquant sur le bouton "Download EXE".
    Note : le fichier téléchargé aura un nom aléatoire, c'est normal, garde ce nom

    ● Lance gmer à partir du fichier au nom aléatoire

    ● Un scan va se lancer dès le lancement, laisse le faire.

    ● Si il détecte tout de suite le rootkit, il va te proposer de scanner le PC en entier, accepte.
    ● Sinon, coche sur la droite les cases "Services", "Registry" et "Files" et clique sur le bouton scan

    ● Laisse travailler l'outil

    ● A la fin du scan, clique sur le bouton Save... et enregistre le rapport sur ton bureau

    ● Copie/colle le contenu du rapport dans ta réponse
    2
    1. voici un autre lien http://www.cijoint.fr/cjlink.php?file=cj201004/cijkX10RtM.text

      pour le lien GMER ça bloque je réessaye
      0
    2. ça me dit que gmer rencontre un pb et ça arrête le scan
      0
  4. Essaie après avoir désactiver l'UAC Aide en images.

    Et lance gmer en faisant un clic droit dessus et en choisissant "exécuter en tant qu'administrateur".
    0
    1. mais ce qui me chiffone c'est que je ne suis pas sous windows vista mais windows xp sweet
      c'est plus longtemps pour suivre les chemins qu'il propose
      0
    2. mon ordinateur refuse l'accés
      0
  5. Salut,

    "windows xp sweet" : ok, le soucis doit venir de là..
    0
    1. qu'est ce que je peux faire alors ???
      0
  6. Fais ceci :

    ● Télécharge Malwarebytes' Anti-Malware (MBAM)

    ● Double clique sur mbam-setup.exe pour lancer l'installation

    ● Laisse les options par défaut lors de l'installation

    ● Lance MBAM et laisse les Mises à jour se télécharger

    ● Va dans l'onglet Recherche, choisis "Exécuter un examen complet" puis clique sur Rechercher
    Note : le scan peut durer plusieurs heures en fonction de la quantité de données présente sur ton PC

    ● A la fin du scan, clique sur Afficher les résultats

    ● Coche tous les éléments détectés puis clique sur Supprimer la sélection

    ● S'il t'est demandé de redémarrer, clique sur Yes

    ● Un rapport va s'ouvrir, copie/colle le dans ta réponse

    ▲ Le rapport se trouve dans l'onglet Rapports/Logs de MBAM
    1
    1. voici le rapport MBAM
      Malwarebytes' Anti-Malware 1.45
      www.malwarebytes.org

      Version de la base de données: 4042

      Windows 5.1.2600 Service Pack 3
      Internet Explorer 7.0.5730.13

      27/04/2010 17:00:46
      mbam-log-2010-04-27 (17-00-46).txt

      Type d'examen: Examen complet (C:\|)
      Elément(s) analysé(s): 187367
      Temps écoulé: 1 heure(s), 2 minute(s), 17 seconde(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 1
      Valeur(s) du Registre infectée(s): 1
      Elément(s) de données du Registre infecté(s): 4
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 2

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cbssreg (Trojan.Agent) -> No action taken.

      Valeur(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\forceclassiccontrolpanel (Hijack.ControlPanelStyle) -> No action taken.

      Elément(s) de données du Registre infecté(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\msnmls.exe) Good: (userinit.exe) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\Program Files\CMenu\Utilities\plugins\ZDRx.dll (Malware.Packer.Gen) -> No action taken.
      C:\WINDOWS\Temp\oxbr.tmp\svchost.exe (Trojan.Inject) -> No action taken.
      0
    2. quand j'ai redémarré l'ordinateur après le scan une nouvelle alerte est apparue
      0
    3. C'est normal, tu n'as pas fait ça

      ? Coche tous les éléments détectés puis clique sur Supprimer la sélection
      0
    4. c'est ce que j'ai fait !!
      0
    5. je vais redémarrer encore une fois
      0
  7. Il faut que tu refasses le scan avec Malwarebytes et que tu penses à bien cocher tous les éléments détectés puis à cliquer sur "Supprimer la sélection".
    1
    1. ça y est chef , lui aussi me dit qu'aucun élément nuisible n'est détecté.
      0
  8. Bien, on va analyser ton PC :

    ● Télécharge ZHPDiag de Nicolas Coolman sur ton bureau en cliquant sur le bouton télécharger

    ● Double clique sur le fichier téléchargé pour lancer l'installation

    ● Laisse toi guider pendant l'installation. Coche la case pour créer un raccourci sur le bureau et exécute ZHPDiag à la fin de l'installation

    ● Clique sur l'icône représentant une loupe ("Lancer le diagnostic") et patiente pendant le scan

    ● Clique sur l'icône représentant une disquette ("Sauvegarder le fichier sous") et enregistre le rapport sur ton bureau

    ● Ferme ZHPDiag, héberge le rapport ZHPDiag.txt sur le site ci-joint puis copie/colle le lien fourni dans ta réponse

    ► Aide en images
    0
    1. Ok j'essaie ça merci encore
      0
  9. Je te laisse un autre lien pour ZHPDiag (le premier ne fonctionne pas actuellement) ==> http://www.premiumorange.com/zeb-help-process/download/ZHPDiag.zip
    0
    1. j'ai fait cet autre lien ça fonctionne jusqu'au moment d'héberger le rapport, là, la connexion s'interrompt à chaque fois( trois essais) (erreur de chargement page m'indique t-on la liaison a été interrompue en cours ) j'insiste encore un peu et je te dis.
      0
    2. c'est récurrent , ça coupe systématiquement la connexion
      0
  10. Dans ce cas, essaie de copier/coller le rapport ici, il faudra sans doute que tu le coupes en plusieurs parties.
    0
    1. comment je fais on me demande de démarrer javascript ???

      je coupe le rapport , c'est la panique !!!!

      Windows sécuity alert me signale 9 attaques trojans et compagnie avec bien sur l'achat d'un anti virus !!!!! pourquoi avira et malva ne les voyent-ils pas ?*
      ils sont tous apparemment dans administrateur\recent\ ce fichier je ne le trouve pas.

      bon un bout du rapport.

      Run by Administrateur at 27/04/2010 20:04:08
      Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html

      ---\\ Web Browser
      MSIE: Internet Explorer v7.0.5730.13
      MFIE: Mozilla Firefox (3.0)

      ---\\ System Information
      Platform : Microsoft Windows XP (5.1.2600) Service Pack 3
      Processor: x86 Family 16 Model 6 Stepping 2, AuthenticAMD
      Operating System: 32 Bits
      Boot mode: Normal (Normal boot)
      Total RAM: 1919 MB (70% free)
      System drive C: has 316 GB (67%) free of 466 GB

      ---\\ Logged in mode
      Computer Name: SWEET-E8A020C74
      User Name: Administrateur
      Logged in as Administrator
      0
    2. la suite

      ---\\ DOS/Devices
      C:\ Hard drive, Flash drive, Thumb drive (Free 316 Go of 466 Go)
      D:\ CD-ROM drive (Not Inserted)
      E:\ CD-ROM drive (Not Inserted)
      F:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
      G:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
      H:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
      I:\ Floppy drive, Flash card reader, USB Key (Not Inserted)
      K:\ Floppy drive, Flash card reader, USB Key (Not Inserted)

      ---\\ Security Center & Tools Informations
      [HKLM\SOFTWARE\Microsoft\Security Center] AntiVirusDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Security Center] FirewallDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Security Center] UpdatesDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiSpywareOverride: OK
      [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusOverride: OK
      [HKLM\SOFTWARE\Microsoft\Security Center\Svc] AntiVirusDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Security Center\Svc] FirewallOverride: OK
      [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UpdatesDisableNotify: OK
      [HKLM\SOFTWARE\Microsoft\Security Center\Svc] UacDisableNotify: OK
      [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableTaskMgr: OK
      [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] DisableRegistryTools: OK
      [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system] NoDispScrSavPage: OK

      ---\\ Processus lancés
      [MD5.DEC495FBCE14CB92BBCC6280C1C7B34C] - (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- C:\WINDOWS\system32\NvCpl.dll [13524992]
      [MD5.C464FEE5A2FFE71E9A25D8EBE3D43AC4] - (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\mmm.exe [828416]
      [MD5.403E928BA217E38485009636C793F3C9] - (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Unlocker\UnlockerAssistant.exe [15872]
      [MD5.804FBB66EC6CA862B840D173EFC638A7] - (.DAEMON'S HOME - Virtual DAEMON Manager.) -- C:\Program Files\D-Tools\daemon.exe [81920]
      [MD5.290D597F0B5315F704F8CB9F296613A1] - (.VIA Technologies, Inc. - HDeck MFC Application.) -- C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe [33628160]
      [MD5.29680A793F690EEF4AAA68479D2A6DF8] - (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [209153]
      [MD5.F91F52F4EA5D88DAB6245682A16F3A72] - (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [36272]
      [MD5.DB1DB28467111A24664933AB8908CBCE] - (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe [952768]
      [MD5.1C3CA3E7807F915933BB4E08E599DDAB] - (.Scansoft, Inc. - SSBkgdUpdate.) -- C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [155648]
      [MD5.4400C3143778C1DF92D46C98688A9925] - (.ScanSoft, Inc. - PaperPort Print to Desktop for NT.) -- C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [57393]
      [MD5.3CA11F2A1B30C2246081EFA892EEA295] - (.ScanSoft, Inc. - PaperPort IndexSearch.) -- C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [40960]
      [MD5.84CB03C25256C5AB11613A5077AF0F35] - (.Brother Industries, Ltd. - ControlCenter2 Main Program.) -- C:\Program Files\Brother\ControlCenter2\brctrcen.exe [933888]
      [MD5.55D7A219AD8D0DB8980528944152A6FD] - (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe [417792]
      [MD5.8DC7685764B22DB97891012026FA7ED1] - (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe [141608]
      [MD5.BF98AF55736FB805FC208B89A09E0C4F] - (.Andreas Eliasson (EliasAE) - WinMover executable.) -- C:\Program Files\WinMover\WinMover.exe [10240]
      [MD5.18B4B12358EFCF68D76812058A26181F] - (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe [3883856]
      [MD5.9015BC03F62940527EC92D45EE89E46F] - (.Avira GmbH - Antivirus Scheduler.) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe [108289]
      [MD5.B8720A787C1223492E6F319465E996CE] - (.Avira GmbH - Antivirus On-Access Service.) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe [185089]
      [MD5.4B5AE15E5C73EB4DC8DBEC2788230D41] - (.Apple Inc. - Apple Mobile Device Service.) -- C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [144672]
      [MD5.E4BDF223CD75478BF44567B4D5C2634D] - (.Microsoft Corporation - Generic Host Process for Win32 Services.) -- C:\WINDOWS\System32\svchost.exe [14336]
      [MD5.169CD306ECD78E84E878AB4B2470B9A0] - (.Discordia Limited - Bandoo Coordinator.) -- C:\PROGRA~1\Bandoo\Bandoo.exe [1678272]
      [MD5.3F56903E124E820AEECE6D471583C6C1] - (.Apple Inc. - Bonjour Service.) -- C:\Program Files\Bonjour\mDNSResponder.exe [238888]
      [MD5.D3FACB34FFF5DB91ADB70987838F8BA7] - (.brother Industries Ltd - brsvc01a.) -- C:\WINDOWS\system32\brsvc01a.exe [57344]
      [MD5.54CB50058851D95E56EC70D09F70857F] - (.Microsoft Corporation - Applications Services et Contrôleur.) -- C:\WINDOWS\system32\services.exe [109056]
      [MD5.8F0DE4FEF8201E306F9938B0905AC96A] - (.Google Inc. - Programme d'installation de Google.) -- C:\Program Files\Google\Update\GoogleUpdate.exe [135664]
      [MD5.DFD4EEEE83EDAF7FFE6C26D8B8F566C2] - (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 174.7.) -- C:\WINDOWS\system32\nvsvc32.exe [155716]
      [MD5.91E6024D6D4DCDECDB36C43ECF9BBECB] - (.Microsoft Corporation - LSA Shell (Export Version).) -- C:\WINDOWS\system32\lsass.exe [13312]
      [MD5.D358E077A0A05D9B12DA22D137EE8464] - (.Microsoft Corp. - Microsoft SeaPort Search Enhancement Broker.) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [226656]
      [MD5.460E4CE148BD07218DA0B6A3D31885A9] - (.Microsoft Corporation - Spooler SubSystem App.) -- C:\WINDOWS\system32\spoolsv.exe [57856]
      0
    3. la suite .....

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

      ---\\ Internet Explorer URLSearchHook (R3)
      R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} . (.Microsoft Corporation - Internet Explorer.) (7.00.6000.20815 (vista_ldr.080415-1732)) -- C:\WINDOWS\system32\ieframe.dll

      ---\\ Browser Helper Objects de navigateur (O2)
      O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} . (.Adobe Systems Incorporated - Adobe PDF Helper for Internet Explorer.) -- C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: (no name) - {3A0E0801-C19E-406F-8690-7BD1D557EB58} . (.Microsoft Corporation - Net Remote Admin Protocol DLL.) -- c:\windows\system32\rnkbgxq.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} . (.Pas de propriétaire - Pas de description.) -- (.not file.)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} . (.Microsoft Corp. - Microsoft Search Helper Extention.) -- C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} . (.Microsoft Corporation - WindowsLiveLogin.dll.) -- C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} . (.IniCom Networks, Inc. - Pas de description.) -- C:\PROGRA~1\FlashFXP\IEFlash.dll
      O2 - BHO: Bandoo IE Plugin - {EB5CEE80-030A-4ED8-8E20-454E9C68380F} . (.Discordia Limited - Bandoo IE Plugin.) -- C:\Program Files\Bandoo\Plugins\IE\ieplugin.dll

      ---\\ Internet Explorer Toolbars (O3)
      O3 - Toolbar: SYSTRAN Web Translator 5.0 - {A5899B52-3AF9-4F56-85FE-AD7B3BE8490F} . (.SYSTRAN - Pas de description.) -- C:\Program Files\SYSTRAN\5.0\Personal\IEPlugIn.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} . (.Microsoft Corporation - Windows Live Toolbar Core.) -- C:\Program Files\Windows Live\Toolbar\wltcore.dll

      ---\\ Applications démarrées automatiquement par le registre (O4)
      O4 - HKLM\..\Run: [NvCplDaemon] . (.NVIDIA Corporation - NVIDIA Display Properties Extension.) -- C:\WINDOWS\system32\NvCpl.dll
      O4 - HKLM\..\Run: [Mmm] . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\system32\mmm.exe
      O4 - HKLM\..\Run: [UnlockerAssistant] . (.Pas de propriétaire - Pas de description.) -- C:\Program Files\Unlocker\UnlockerAssistant.exe
      O4 - HKLM\..\Run: [DAEMON Tools-1033] . (.DAEMON'S HOME - Virtual DAEMON Manager.) -- C:\Program Files\D-Tools\daemon.exe
      O4 - HKLM\..\Run: [HDAudDeck] . (.VIA Technologies, Inc. - HDeck MFC Application.) -- C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
      O4 - HKLM\..\Run: [avgnt] . (.Avira GmbH - Antivirus System Tray Tool.) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] . (.Adobe Systems Incorporated - Adobe Acrobat SpeedLauncher.) -- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
      O4 - HKLM\..\Run: [Adobe ARM] . (.Adobe Systems Incorporated - Adobe Reader and Acrobat Manager.) -- C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe
      O4 - HKLM\..\Run: [SSBkgdUpdate] . (.Scansoft, Inc. - SSBkgdUpdate.) -- C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe
      O4 - HKLM\..\Run: [PaperPort PTD] . (.ScanSoft, Inc. - PaperPort Print to Desktop for NT.) -- C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
      O4 - HKLM\..\Run: [IndexSearch] . (.ScanSoft, Inc. - PaperPort IndexSearch.) -- C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
      O4 - HKLM\..\Run: [ControlCenter2.0] . (.Brother Industries, Ltd. - ControlCenter2 Main Program.) -- C:\Program Files\Brother\ControlCenter2\brctrcen.exe
      O4 - HKLM\..\Run: [QuickTime Task] . (.Apple Inc. - QuickTime Task.) -- C:\Program Files\QuickTime\QTTask.exe
      O4 - HKLM\..\Run: [iTunesHelper] . (.Apple Inc. - iTunesHelper.) -- C:\Program Files\iTunes\iTunesHelper.exe
      O4 - HKCU\..\Run: [WinMover] . (.Andreas Eliasson (EliasAE) - WinMover executable.) -- C:\Program Files\WinMover\WinMover.exe
      O4 - HKCU\..\Run: [msnmsgr] . (.Microsoft Corporation - Windows Live Messenger.) -- C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      O4 - Global Startup: Contrôleur d'état.lnk . (.Brother Industries, Ltd. - Status Monitor (Main).) -- C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
      O4 - Global Startup: Notification de cadeaux MSN.lnk . (.Microsoft Corporation - Notification de cadeaux MSN.) -- C:\Documents and Settings\Administrateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe

      ---\\ Lignes supplémentaires dans le menu contextuel d'Internet Explorer (O8)
      O8 - Extra context menu item: E&xporter vers Microsoft Excel . (.Microsoft Corporation - Microsoft Office Excel.) -- C:\PROGRA~1\MICROS~2\Office12\EXCEL.exe
      0
    4. ---\\ Boutons situés sur la barre d'outils principale d'Internet Explorer (O9)
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} . (.not file.) - (.not file.)
      O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} . (.Microsoft Corporation - Windows Live Writer Blog This Extension.) -- C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} . (.Pas de propriétaire - Pas de description.) -- C:\PROGRA~1\MICROS~2\Office12\REFBARH.ICO
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} . (.not file.) - (.not file.)

      ---\\ Winsock hijacker (Layered Service Provider) (O10)
      O10 - WLSP:\000000000001\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
      O10 - WLSP:\000000000002\Winsock LSP File . (.Microsoft Corporation - LDAP RnR Provider DLL.) -- C:\WINDOWS\system32\winrnr.dll
      O10 - WLSP:\000000000003\Winsock LSP File . (.Microsoft Corporation - Fournisseur de service Sockets 2.0 de Microsoft Windows.) -- C:\WINDOWS\system32\mswsock.dll
      O10 - WLSP:\000000000004\Winsock LSP File . (.Apple Inc. - Bonjour Namespace Provider.) -- C:\Program Files\Bonjour\mdnsNSP.dll

      ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
      O20 - Winlogon Notify: dimsntfy . (.Microsoft Corporation - DIMS Notification Handler.) -- C:\WINDOWS\System32\dimsntfy.dll

      ---\\ Valeur de Registre AppInit_DLLs et sous-clés Winlogon Notify (autorun) (O20)
      O20 - AppInit_DLLs: . (.Discordia Limited - BndHook.) - c:\progra~1\bandoo\bndhook.dll

      ---\\ Clé de Registre autorun ShellServiceObjectDelayLoad (SSODL) (O21)
      O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} . (.Microsoft Corporation - Web Site Monitor.) -- C:\WINDOWS\system32\webcheck.dll
      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} . (.Microsoft Corporation - Windows Portable Device Shell Service Objec.) -- C:\WINDOWS\system32\wpdshserviceobj.dll
      O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
      O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} . (.Microsoft Corporation - DLL commune du shell Windows.) -- C:\WINDOWS\system32\SHELL32.dll
      O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} . (.Microsoft Corporation - Objet du service d'environnement Systray.) -- C:\WINDOWS\system32\stobject.dll

      ---\\ Clé de Registre autorun SharedTaskScheduler (STS) (O22)
      O22 - SharedTaskScheduler: (no name) - {8C7461EF-2B13-11d2-BE35-3078302C2030} . (.Microsoft Corporation - Bibliothèque de l'interface utilisateur du.) -- C:\WINDOWS\system32\browseui.dll

      ---\\ Liste des services NT non Microsoft et non désactivés (O23)
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) . (.Avira GmbH - Antivirus Scheduler.) - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) . (.Avira GmbH - Antivirus On-Access Service.) - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Apple Mobile Device (Apple Mobile Device) . (.Apple Inc. - Apple Mobile Device Service.) - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Bandoo Coordinator (Bandoo Coordinator) . (.Discordia Limited - Bandoo Coordinator.) - C:\PROGRA~1\Bandoo\Bandoo.exe
      O23 - Service: Service Bonjour (Bonjour Service) . (.Apple Inc. - Bonjour Service.) - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: BrSplService (Brother XP spl Service) . (.brother Industries Ltd - brsvc01a.) - C:\WINDOWS\system32\brsvc01a.exe
      O23 - Service: Service Google Update (gupdate) (gupdate) . (.Google Inc. - Programme d'installation de Google.) - C:\Program Files\Google\Update\GoogleUpdate.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) . (.NVIDIA Corporation - NVIDIA Driver Helper Service, Version 174.7.) - C:\WINDOWS\system32\nvsvc32.exe
      0
    5. ---\\ Tâches planifiées en automatique (O39)
      O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
      O39 - APT:Automatic Planified Task - C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1cac6ea8e983b8e.job

      ---\\ Composants installés (ActiveSetup Installed Components) (O40)
      O40 - ASIC: Personnalisation du navigateur - >{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS . (.Pas de propriétaire - Pas de description.) -- RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP
      O40 - ASIC: Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608500} . (.Sun Microsystems, Inc. - Java(TM) Platform SE binary.) -- C:\Program Files\Java\jre1.6.0_06\bin\regutils.dll
      O40 - ASIC: Adobe Shockwave Director 11.0 - {233C1507-6A77-46A4-9443-F871F945D258} . (.Adobe Systems, Inc. - Shockwave ActiveX Control.) -- C:\WINDOWS\system32\Adobe\Director\SwDir.dll
      O40 - ASIC: NetMeeting 3.01 - {44BBA842-CC51-11CF-AAFA-00AA00B6015B} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\msnetmtg.inf
      O40 - ASIC: Microsoft Windows Media Player - {6BF52A52-394A-11d3-B153-00C04F79FAA6} . (.Pas de propriétaire - Pas de description.) -- C:\WINDOWS\INF\wmp.inf
      O40 - ASIC: Macromedia Shockwave Flash - {D27CDB6E-AE6D-11cf-96B8-444553540000} . (.Adobe Systems, Inc. - Adobe Flash Player 9.0 r124.) -- C:\WINDOWS\system32\Macromed\Flash\Flash9f.ocx

      ---\\ Pilotes lancés au démarrage (O41)
      O41 - Driver: Pilote de processeur AMD HwPState (AmdPPM) . (.Advanced Micro Devices - AMD Processor Driver.) - C:\WINDOWS\system32\DRIVERS\AmdPPM.sys
      O41 - Driver: avgio (avgio) . (.Avira GmbH - Avira AntiVir Support for Minifilter.) - C:\Program Files\Avira\AntiVir Desktop\avgio.sys
      O41 - Driver: avipbb (avipbb) . (.Avira GmbH - Avira Driver for RootKit Detection.) - C:\WINDOWS\system32\DRIVERS\avipbb.sys
      O41 - Driver: ssmdrv (ssmdrv) . (.Avira GmbH - AVIRA SnapShot Driver.) - C:\WINDOWS\system32\DRIVERS\ssmdrv.sys

      ---\\ Logiciels installés (O42)
      O42 - Logiciel: 2007 Microsoft Office Suite Service Pack 1 (SP1) - (.Microsoft.) [HKLM]
      O42 - Logiciel: ACDSee 10 Gestionnaire de photos - (.ACD Systems International.) [HKLM]
      O42 - Logiciel: AHV content for Acrobat and Flash - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: AMD Processor Driver - (.AMD.) [HKLM]
      O42 - Logiciel: Adobe After Effects CS3 Presets - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Anchor Service CS3 - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Asset Services CS3 - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Bridge CS3 - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Bridge Start Meeting - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe BridgeTalk Plugin CS3 - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe CMaps - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Camera Raw 4.0 - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Color - Photoshop Specific - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Color Common Settings - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Color EU Recommended Settings - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Color JA Extra Settings - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Color NA Extra Settings - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Creative Suite 3 Master Collection - (.Adobe Systems Incorporated.) [HKLM]
      O42 - Logiciel: Adobe Default Language CS3 - (.Adobe Systems Incorporated.) [HKLM]
      0
  11. Contributeur sécurité
    Je regarde çà et te donne la suite plus tard.
    0
    1. bonjour h3rv3 je n'avais pas vu le changement de personne merci de me donner un coup de main
      0
  12. Contributeur sécurité
    Je suis la même personne, j'ai juste changé de pseudo :).

    Peux-tu essayer d'héberger le rapport sur un des sites de la liste suivante, en espérant qu'un de ceux là fonctionnera..
    https://www.commentcamarche.net/image-son/photo/25189-partage-de-photos-8-services-simples-et-gratuits/
    0
    1. avira a disparu de mon ordi , malwarebyte m'a détecté 73 virus , mon ordi est une vrai passoire et dès que j'essaie des liens pour le rapport les connexions s'arrêtent ou la page est indisponible , je cherche toujours .
      0
  13. Contributeur sécurité
    Bon essaie ceci :

    ● Télécharge ComboFix (de sUBs) sur ton Bureau de cette manière :
    Fais un clic droit sur ce lien

    ● Choisis "enregistrer la cible sous ... " et dans la fenêtre qui s'ouvre choisis ton bureau pour l'emplacement et tape CBFix.exe pour le nom.

    ● Déconnecte toi de internet et désactive tout tes logiciels de protection

    ● Sous XP : Double clique sur CBFix.exe
    ● Sous Vista/7 : Fais un clic droit sur CBFix.exe et sélectionne "Exécuter en tant qu'administrateur"

    ● Clique sur le bouton Oui dans la fenêtre d'avertissement

    ● Si tu es sous XP et que la console de récupération n'est pas installée, ComboFix va te proposer de l'installer, accepte en cliquant sur Oui.

    ● Laisse travailler l'outil et si il te demande de redémarrer le PC, accepte.

    ● Un rapport va s'ouvrir à la fin du processus, copie/colle le dans ta réponse
    ▲ Le rapport est sauvegardé dans C:\ComboFix.txt

    Tutorial officiel de ComboFix
    1
    1. eh bien c'est pas de la tarte, boulot famille et virus !!!

      bon j'ai le rapport de comboFix
      ComboFix 10-05-01.01 - Administrateur 01/05/2010 20:16:09.1.2 - x86
      Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.1919.1554 [GMT 2:00]
      Lancé depuis: c:\documents and settings\Administrateur\Bureau\ComboFix.exe
      AV: AntiVir Desktop *On-access scanning disabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{1d1c9c49-e8d4-4927-b46d-da92698a1004}
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{1d1c9c49-e8d4-4927-b46d-da92698a1004}\chrome.manifest
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{1d1c9c49-e8d4-4927-b46d-da92698a1004}\chrome\xulcache.jar
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{1d1c9c49-e8d4-4927-b46d-da92698a1004}\defaults\preferences\xulcache.js
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{1d1c9c49-e8d4-4927-b46d-da92698a1004}\install.rdf
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{bb26d1e2-b43e-4525-9602-677239e23343}
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{bb26d1e2-b43e-4525-9602-677239e23343}\chrome.manifest
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{bb26d1e2-b43e-4525-9602-677239e23343}\chrome\xulcache.jar
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{bb26d1e2-b43e-4525-9602-677239e23343}\defaults\preferences\xulcache.js
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{bb26d1e2-b43e-4525-9602-677239e23343}\install.rdf
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{f5f85493-2a7f-46ea-a18f-c8d78e2ec19b}
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{f5f85493-2a7f-46ea-a18f-c8d78e2ec19b}\chrome.manifest
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{f5f85493-2a7f-46ea-a18f-c8d78e2ec19b}\chrome\xulcache.jar
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{f5f85493-2a7f-46ea-a18f-c8d78e2ec19b}\defaults\preferences\xulcache.js
      c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{f5f85493-2a7f-46ea-a18f-c8d78e2ec19b}\install.rdf
      c:\documents and settings\Administrateur\Recent\cb.dll
      c:\documents and settings\Administrateur\Recent\ddv.sys
      c:\documents and settings\Administrateur\Recent\SM.tmp
      c:\documents and settings\All Users.\documents\settings
      c:\documents and settings\All Users\Menu Démarrer\Programmes\Internet Explorer.lnk
      c:\program files\WindowsUpdate
      c:\windows\system32\akniqaev.dll
      c:\windows\system32\drivers\bprwrils.sys
      c:\windows\system32\drivers\zgdnhgob.sys
      c:\windows\system32\rnkbgxq.dll
      c:\windows\system32\skykecu.dll

      Une copie infectée de c:\windows\system32\drivers\disk.sys a été trouvée et désinfectée
      Copie restaurée à partir de - Kitty had a snack :p
      .
      ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Legacy_MIYKZGPN
      -------\Legacy_ZGDNHGOB
      -------\Service_miykzgpn
      -------\Service_zgdnhgob

      ((((((((((((((((((((((((((((( Fichiers créés du 2010-04-01 au 2010-05-01 ))))))))))))))))))))))))))))))))))))
      .

      2010-05-01 13:25 . 2010-05-01 13:25 -------- d-----w- c:\program files\Yahoo!
      2010-05-01 13:25 . 2010-05-01 13:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
      2010-05-01 13:25 . 2010-05-01 13:25 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Yahoo!
      2010-05-01 13:25 . 2010-05-01 13:25 -------- d-----w- c:\program files\CCleaner
      2010-04-30 15:54 . 2008-05-29 21:13 710144 ----a-w- c:\documents and settings\All Users\Application Data\c9c3302\mozcrt19.dll
      2010-04-30 15:54 . 2008-05-29 21:13 414208 ----a-w- c:\documents and settings\All Users\Application Data\c9c3302\sqlite3.dll
      2010-04-30 15:52 . 2010-04-30 15:52 -------- d-sh--w- c:\documents and settings\All Users\Application Data\MSXNPIWE
      2010-04-30 15:50 . 2010-05-01 16:45 -------- d-sh--w- c:\documents and settings\All Users\Application Data\c9c3302
      2010-04-27 18:03 . 2010-04-27 18:04 -------- d-----w- c:\program files\ZHPDiag
      2010-04-27 14:26 . 2010-04-30 15:11 664 ----a-w- c:\windows\system32\d3d9caps.dat
      2010-04-27 13:27 . 2010-04-27 13:27 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
      2010-04-27 13:27 . 2010-03-29 22:46 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
      2010-04-27 13:27 . 2010-04-27 13:27 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
      2010-04-27 13:27 . 2010-04-27 13:27 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
      2010-04-27 13:27 . 2010-03-29 22:45 20824 ----a-w- c:\windows\system32\drivers\mbam.sys
      2010-04-21 19:09 . 2010-04-22 18:54 -------- d-----w- c:\program files\trend micro
      2010-04-21 19:09 . 2010-04-22 18:37 -------- d-----w- C:\rsit
      2010-04-16 15:21 . 2008-12-03 23:25 120832 ----a-w- c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}\plugins\npietab.dll

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2010-05-01 18:20 . 2008-06-25 17:30 85022 ----a-w- c:\windows\system32\perfc00C.dat
      2010-05-01 18:20 . 2008-06-25 17:30 511066 ----a-w- c:\windows\system32\perfh00C.dat
      2010-05-01 18:18 . 2009-12-11 14:38 86331 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
      2010-05-01 08:14 . 2009-12-11 15:51 -------- d-----w- c:\program files\Avira
      2010-04-16 20:41 . 2010-02-16 21:14 -------- d-----w- c:\program files\Google
      2010-03-24 18:10 . 2010-03-24 18:10 37072 ---ha-w- c:\windows\system32\mlfcache.dat
      2010-03-23 19:11 . 2010-03-23 18:45 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Apple Computer
      2010-03-23 19:10 . 2009-12-11 14:59 59832 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2010-03-23 18:45 . 2010-03-23 18:44 -------- d-----w- c:\program files\iTunes
      2010-03-23 18:45 . 2010-03-23 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
      2010-03-23 18:44 . 2010-03-23 18:44 -------- d-----w- c:\program files\iPod
      2010-03-23 18:44 . 2010-03-23 18:43 -------- d-----w- c:\program files\Fichiers communs\Apple
      2010-03-23 18:44 . 2010-03-23 18:44 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
      2010-03-23 18:44 . 2009-12-12 11:50 -------- d-----w- c:\program files\Bonjour
      2010-03-23 18:44 . 2010-03-23 18:44 -------- d-----w- c:\program files\QuickTime
      2010-03-23 18:44 . 2010-03-23 18:44 -------- d-----w- c:\program files\Apple Software Update
      2010-03-23 18:43 . 2010-03-23 18:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
      2010-03-17 20:10 . 2010-03-17 20:10 50354 ----a-w- c:\documents and settings\Administrateur\Application Data\Facebook\uninstall.exe
      2010-03-17 20:10 . 2010-03-17 20:10 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Facebook
      2010-03-15 17:02 . 2009-12-11 14:47 -------- d-----w- c:\program files\Mozilla Thunderbird
      2010-03-14 15:55 . 2009-12-11 14:58 -------- d-----w- c:\program files\Unlocker
      2010-03-12 17:36 . 2010-03-12 17:36 86576 ----a-w- c:\documents and settings\Administrateur\Application Data\Microsoft\Services Windows Live\Raccourci Galerie de Photos Windows Live.exe
      2010-03-12 17:36 . 2010-03-12 17:36 132672 ----a-w- c:\documents and settings\Administrateur\Application Data\Microsoft\Services Windows Live\Raccourci Windows Live Messenger.exe
      2010-03-12 17:36 . 2010-03-12 17:36 392728 ----a-w- c:\documents and settings\Administrateur\Application Data\Microsoft\Services Windows Live\Services Windows Live.dll
      2010-03-12 17:36 . 2010-03-12 17:36 135680 ----a-w- c:\documents and settings\Administrateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
      2010-03-06 05:30 . 2010-03-06 05:30 847040 ----a-w- c:\documents and settings\Administrateur\Application Data\Facebook\axfbootloader.dll
      2010-03-06 05:30 . 2010-03-06 05:30 5582848 ----a-w- c:\documents and settings\Administrateur\Application Data\Facebook\npfbplugin_1_0_3.dll
      2010-03-03 14:21 . 2010-03-03 14:21 13312 ----a-w- c:\windows\system32\svrapi.dll
      2010-02-23 19:19 . 2010-02-23 19:19 192 ----a-w- c:\documents and settings\Administrateur\Local Settings\Application Data\GLF105.tmp
      2010-02-15 17:41 . 2010-02-15 17:41 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
      2010-02-03 18:41 . 2010-02-03 17:28 57 ----a-w- c:\documents and settings\All Users\Application Data\Brother\BrLog\BrCollectDir\BR_cat.bat
      2010-02-03 18:36 . 2010-02-03 17:31 50 ----a-w- c:\windows\system32\bridf05a.dat
      .

      ------- Sigcheck -------

      [-] 2008-06-25 . 6E7A77E1E13D3DAFE77AF1012112A2C3 . 361344 . . [5.1.2600.5512] . . c:\windows\system32\drivers\tcpip.sys

      [-] 2008-06-25 . DE669722494CF41F6E39A62B3B08525C . 561152 . . [5.1.2600.5512] . . c:\windows\system32\winlogon.exe

      [-] 2008-06-25 . D449DF66B6335B443508A58B1E8DB996 . 647680 . . [5.82] . . c:\windows\system32\comctl32.dll

      [-] 2008-06-25 . A9DB7B8FAE4D18FBF86331C2E33BD6F7 . 2287104 . . [5.1.2600.5512] . . c:\windows\system32\ntoskrnl.exe

      [-] 2008-06-25 . DE4A4AC7328FC80156034E7EB283676D . 579584 . . [5.1.2600.5512] . . c:\windows\system32\user32.dll

      [-] 2008-06-25 . B8FCD84F253A7EB9F14DE1163FD68379 . 971264 . . [7.00.6000.20815] . . c:\windows\system32\wininet.dll

      [-] 2008-06-25 . 3C127370AA63C7D9FD756BB4BE173427 . 1573888 . . [6.00.2900.5512] . . c:\windows\explorer.exe

      [-] 2008-06-25 . 58DB2EE838D5B7BAD0F7F10A6C920390 . 40960 . . [5.1.2600.5512] . . c:\windows\system32\ctfmon.exe

      [-] 2008-06-25 . 338D062FC6F9631BC55980A75ED809A4 . 2165760 . . [5.1.2600.5512] . . c:\windows\system32\ntkrnlpa.exe
      .
      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F}]
      2010-01-18 23:31 2074048 ----a-w- c:\program files\Bandoo\Plugins\IE\ieplugin.dll

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "WinMover"="c:\program files\WinMover\WinMover.exe" [2005-12-02 10240]
      "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-03-24 13524992]
      "Mmm"="c:\windows\system32\mmm.exe" [2005-07-05 828416]
      "UnlockerAssistant"="c:\program files\Unlocker\UnlockerAssistant.exe" [2008-05-01 15872]
      "DAEMON Tools-1033"="c:\program files\D-Tools\daemon.exe" [2004-08-22 81920]
      "HDAudDeck"="c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe" [2009-06-05 33628160]
      "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-04-04 36272]
      "Adobe ARM"="c:\program files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe" [2010-03-24 952768]
      "SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
      "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
      "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
      "ControlCenter2.0"="c:\program files\Brother\ControlCenter2\brctrcen.exe" [2005-05-17 933888]
      "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-10 417792]
      "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-15 141608]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
      "ShowDeskFix"="shell32" [X]

      c:\documents and settings\Administrateur\Menu D'marrer\Programmes\D'marrage\
      Notification de cadeaux MSN.lnk - c:\documents and settings\Administrateur\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe [2010-3-12 135680]

      c:\documents and settings\All Users\Menu D'marrer\Programmes\D'marrage\
      Contr"leur d''tat.lnk - c:\program files\Brother\Brmfcmon\BrMfcWnd.exe [2010-2-3 802816]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
      "NoSMBalloonTip"= 0 (0x0)
      "NoSMConfigurePrograms"= 1 (0x1)

      [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
      "NoSMBalloonTip"= 0 (0x0)
      "NoSMConfigurePrograms"= 1 (0x1)
      "ForceClassicControlPanel"= 1 (0x1)

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
      "AppInit_DLLs"=c:\progra~1\Bandoo\BndHook.dll

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)
      "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
      "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

      R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [11/12/2009 16:58 155136]
      R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [11/12/2009 16:58 5248]
      R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [11/12/2009 17:13 1374464]
      S2 AntiVirSchedulerService;Avira AntiVir Planificateur;"c:\program files\Avira\AntiVir Desktop\sched.exe" --> c:\program files\Avira\AntiVir Desktop\sched.exe [?]
      S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [16/02/2010 23:14 135664]

      --- Autres Services/Pilotes en mémoire ---

      *NewlyCreated* - ZGDNHGOB
      *Deregistered* - zgdnhgob
      .
      Contenu du dossier 'Tâches planifiées'

      2010-03-23 c:\windows\Tasks\AppleSoftwareUpdate.job
      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

      2010-03-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore1cac6ea8e983b8e.job
      - c:\program files\Google\Update\GoogleUpdate.exe [2010-02-16 21:14]
      .
      .
      ------- Examen supplémentaire -------
      .
      uInternet Connection Wizard,ShellNext = iexplore
      uInternet Settings,ProxyOverride = *.local
      IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
      FF - ProfilePath - c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://www.bing.com/search?FORM=IEFM1&q=
      FF - prefs.js: browser.startup.homepage - hxxp://fr.msn.com/
      FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?mkt=fr-FR&form=IEFM1&q=
      FF - component: c:\documents and settings\Administrateur\Application Data\Mozilla\Firefox\Profiles\mteietq8.default\extensions\firefox@bandoo.com\components\FFPlugin.dll
      FF - plugin: c:\documents and settings\Administrateur\Application Data\Facebook\npfbplugin_1_0_3.dll
      FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll
      FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll
      FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
      FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
      .
      - - - - ORPHELINS SUPPRIMES - - - -

      BHO-{01E1316D-E7A5-40BE-B852-2AECF42332A4} - c:\windows\system32\akniqaev.dll
      ShellIconOverlayIdentifiers-{3A0E0801-C19E-406F-8690-7BD1D557EB58} - (no file)
      HKLM-Run-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe
      AddRemove-Avira AntiVir Desktop - c:\program files\Avira\AntiVir Desktop\setup.exe

      **************************************************************************

      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2010-05-01 20:22
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      HKLM\Software\Microsoft\Windows\CurrentVersion\Run
      HDAudDeck = c:\program files\VIA\VIAudioi\HDADeck\HDeck.exe 1????????????????????????????????????????????????

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************

      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

      device: opened successfully
      user: MBR read successfully
      called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x8989F1B8]<<
      kernel: MBR read successfully
      detected MBR rootkit hooks:
      \Driver\Disk -> CLASSPNP.SYS @ 0xba8fcf28
      \Driver\ACPI -> ACPI.sys @ 0xba758cb8
      \Driver\atapi -> 0x8989f1b8
      IoDeviceObjectType -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
      ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
      \Device\Harddisk0\DR0 -> DeleteProcedure -> ntkrnlpa.exe @ 0x805836a8
      ParseProcedure -> ntkrnlpa.exe @ 0x805827e8
      NDIS: NVIDIA nForce 10/100/1000 Mbps Ethernet -> SendCompleteHandler -> NDIS.sys @ 0xba5cbbb0
      PacketIndicateHandler -> NDIS.sys @ 0xba5d8a21
      SendHandler -> NDIS.sys @ 0xba5b687b
      Warning: possible MBR rootkit infection !
      user & kernel MBR OK

      **************************************************************************
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'winlogon.exe'(656)
      c:\windows\system32\SETUPAPI.dll
      c:\windows\system32\cscui.dll

      - - - - - - - > 'lsass.exe'(712)
      c:\windows\system32\setupapi.dll
      c:\windows\system32\scecli.dll

      - - - - - - - > 'explorer.exe'(3792)
      c:\windows\system32\SHDOCVW.dll
      c:\program files\Unlocker\UnlockerHook.dll
      c:\windows\system32\COMRes.dll
      c:\windows\System32\cscui.dll
      c:\windows\system32\msi.dll
      c:\windows\system32\SETUPAPI.dll
      c:\windows\system32\NETSHELL.dll
      c:\windows\system32\credui.dll
      c:\windows\system32\MSVCP60.dll
      c:\windows\system32\eappprxy.dll
      c:\windows\system32\wpdshserviceobj.dll
      c:\windows\system32\portabledevicetypes.dll
      c:\windows\system32\portabledeviceapi.dll
      .
      ------------------------ Autres processus actifs ------------------------
      .
      c:\windows\system32\brss01a.exe
      c:\program files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      c:\program files\Bonjour\mDNSResponder.exe
      c:\windows\system32\nvsvc32.exe
      c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
      c:\progra~1\Bandoo\Bandoo.exe
      c:\windows\system32\wscntfy.exe
      c:\program files\iPod\bin\iPodService.exe
      .
      **************************************************************************
      .
      Heure de fin: 2010-05-01 20:24:21 - La machine a redémarré
      ComboFix-quarantined-files.txt 2010-05-01 18:24

      Avant-CF: 341 616 943 104 octets libres
      Après-CF: 341 523 812 352 octets libres

      WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
      [boot loader]
      timeout=2
      default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
      [operating systems]
      c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
      multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /noexecute=optin /fastdetect /usepmtimer

      - - End Of File - - A868B75923F2906959C7BD0AA79E2793
      0
  14. Contributeur sécurité
    Tu es bien infecté !

    Fais ceci :

    ● Télécharge Load_tdsskiller.exe sur ton bureau

    ● Double clique sur Load_tdsskiller.exe, l'outil va se connecter, accepte les éventuelles alertes de ton pare-feu

    ● Patiente pendant que l'outil travaille

    ● Un rapport va s'ouvrir, copie/colle le dans ta réponse

    ▲ Le rapport est sauvegardé dans C:\tdsskiller\report.txt
    1
    1. je croyais que combo avait fait le ménage.
      voici le rapport de tdskiller
      22:18:31:859 1636 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
      22:18:31:859 1636 ================================================================================
      22:18:31:859 1636 SystemInfo:

      22:18:31:859 1636 OS Version: 5.1.2600 ServicePack: 3.0
      22:18:31:859 1636 Product type: Workstation
      22:18:31:859 1636 ComputerName: SWEET-E8A020C74
      22:18:31:859 1636 UserName: Administrateur
      22:18:31:859 1636 Windows directory: C:\WINDOWS
      22:18:31:859 1636 Processor architecture: Intel x86
      22:18:31:859 1636 Number of processors: 2
      22:18:31:859 1636 Page size: 0x1000
      22:18:31:859 1636 Boot type: Normal boot
      22:18:31:859 1636 ================================================================================
      22:18:31:859 1636 UnloadDriverW: NtUnloadDriver error 2
      22:18:31:859 1636 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
      22:18:31:859 1636 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
      22:18:31:859 1636 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
      22:18:31:859 1636 wfopen_ex: Trying to KLMD file open
      22:18:31:859 1636 wfopen_ex: File opened ok (Flags 2)
      22:18:31:859 1636 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
      22:18:31:859 1636 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
      22:18:31:859 1636 wfopen_ex: Trying to KLMD file open
      22:18:31:859 1636 wfopen_ex: File opened ok (Flags 2)
      22:18:31:859 1636 Initialize success
      22:18:31:859 1636
      22:18:31:859 1636 Scanning Services ...
      22:18:32:203 1636 Raw services enum returned 337 services
      22:18:32:203 1636
      22:18:32:203 1636 Scanning Kernel memory ...
      22:18:32:203 1636 Devices to scan: 12
      22:18:32:203 1636
      22:18:32:203 1636 Driver Name: Disk
      22:18:32:203 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:203 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:203 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:203 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:203 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:203 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:203 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:203 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:203 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:203 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:203 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:203 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:203 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:203 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:203 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:203 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:203 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:203 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:203 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:203 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:203 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:203 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:203 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:203 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:203 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:203 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:203 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:234 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:234 1636
      22:18:32:234 1636 Driver Name: USBSTOR
      22:18:32:234 1636 IRP_MJ_CREATE : BAC75218
      22:18:32:234 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:234 1636 IRP_MJ_CLOSE : BAC75218
      22:18:32:234 1636 IRP_MJ_READ : BAC7523C
      22:18:32:234 1636 IRP_MJ_WRITE : BAC7523C
      22:18:32:234 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:234 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:234 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:234 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:234 1636 IRP_MJ_FLUSH_BUFFERS : 804F4552
      22:18:32:234 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:234 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:234 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:234 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:234 1636 IRP_MJ_DEVICE_CONTROL : BAC75180
      22:18:32:234 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BAC709E6
      22:18:32:234 1636 IRP_MJ_SHUTDOWN : 804F4552
      22:18:32:234 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:234 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:234 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:234 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:234 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:234 1636 IRP_MJ_POWER : BAC745F0
      22:18:32:234 1636 IRP_MJ_SYSTEM_CONTROL : BAC72A6E
      22:18:32:234 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:234 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:234 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: Disk
      22:18:32:250 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: Disk
      22:18:32:250 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: Disk
      22:18:32:250 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: Disk
      22:18:32:250 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: USBSTOR
      22:18:32:250 1636 IRP_MJ_CREATE : BAC75218
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BAC75218
      22:18:32:250 1636 IRP_MJ_READ : BAC7523C
      22:18:32:250 1636 IRP_MJ_WRITE : BAC7523C
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BAC75180
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BAC709E6
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : 804F4552
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BAC745F0
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BAC72A6E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: USBSTOR
      22:18:32:250 1636 IRP_MJ_CREATE : BAC75218
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BAC75218
      22:18:32:250 1636 IRP_MJ_READ : BAC7523C
      22:18:32:250 1636 IRP_MJ_WRITE : BAC7523C
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BAC75180
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BAC709E6
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : 804F4552
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BAC745F0
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BAC72A6E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:265 1636 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1
      22:18:32:265 1636
      22:18:32:265 1636 Driver Name: USBSTOR
      22:18:32:265 1636 IRP_MJ_CREATE : BAC75218
      22:18:32:265 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:265 1636 IRP_MJ_CLOSE : BAC75218
      22:18:32:265 1636 IRP_MJ_READ : BAC7523C
      22:18:32:265 1636 IRP_MJ_WRITE : BAC7523C
      22:18:32:265 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_FLUSH_BUFFERS : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_DEVICE_CONTROL : BAC75180
      22:18:32:265 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BAC709E6
      22:18:32:265 1636 IRP_MJ_SHUTDOWN : 804F4552
      22:18:32:265 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:265 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_POWER : BAC745F0
      22:18:32:265 1636 IRP_MJ_SYSTEM_CONTROL : BAC72A6E
      22:18:32:265 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:265 1636 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1
      22:18:32:265 1636
      22:18:32:265 1636 Driver Name: USBSTOR
      22:18:32:265 1636 IRP_MJ_CREATE : BAC75218
      22:18:32:265 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:265 1636 IRP_MJ_CLOSE : BAC75218
      22:18:32:265 1636 IRP_MJ_READ : BAC7523C
      22:18:32:265 1636 IRP_MJ_WRITE : BAC7523C
      22:18:32:265 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_FLUSH_BUFFERS : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_DEVICE_CONTROL : BAC75180
      22:18:32:265 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BAC709E6
      22:18:32:265 1636 IRP_MJ_SHUTDOWN : 804F4552
      22:18:32:265 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:265 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_POWER : BAC745F0
      22:18:32:265 1636 IRP_MJ_SYSTEM_CONTROL : BAC72A6E
      22:18:32:265 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:265 1636 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1
      22:18:32:265 1636
      22:18:32:265 1636 Driver Name: Disk
      22:18:32:265 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:265 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:265 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:265 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:265 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:265 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:265 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:265 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:265 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:265 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:265 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:265 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:265 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:265 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:265 1636
      22:18:32:265 1636 Driver Name: atapi
      22:18:32:265 1636 IRP_MJ_CREATE : 899F3D08
      22:18:32:265 1636 IRP_MJ_CREATE_NAMED_PIPE : 899F3D08
      22:18:32:265 1636 IRP_MJ_CLOSE : 899F3D08
      22:18:32:265 1636 IRP_MJ_READ : 899F3D08
      22:18:32:265 1636 IRP_MJ_WRITE : 899F3D08
      22:18:32:265 1636 IRP_MJ_QUERY_INFORMATION : 899F3D08
      22:18:32:265 1636 IRP_MJ_SET_INFORMATION : 899F3D08
      22:18:32:265 1636 IRP_MJ_QUERY_EA : 899F3D08
      22:18:32:265 1636 IRP_MJ_SET_EA : 899F3D08
      22:18:32:265 1636 IRP_MJ_FLUSH_BUFFERS : 899F3D08
      22:18:32:265 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 899F3D08
      22:18:32:265 1636 IRP_MJ_SET_VOLUME_INFORMATION : 899F3D08
      22:18:32:265 1636 IRP_MJ_DIRECTORY_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_DEVICE_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_SHUTDOWN : 899F3D08
      22:18:32:265 1636 IRP_MJ_LOCK_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_CLEANUP : 899F3D08
      22:18:32:265 1636 IRP_MJ_CREATE_MAILSLOT : 899F3D08
      22:18:32:265 1636 IRP_MJ_QUERY_SECURITY : 899F3D08
      22:18:32:265 1636 IRP_MJ_SET_SECURITY : 899F3D08
      22:18:32:265 1636 IRP_MJ_POWER : 899F3D08
      22:18:32:265 1636 IRP_MJ_SYSTEM_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_DEVICE_CHANGE : 899F3D08
      22:18:32:265 1636 IRP_MJ_QUERY_QUOTA : 899F3D08
      22:18:32:265 1636 IRP_MJ_SET_QUOTA : 899F3D08
      22:18:32:296 1636 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1
      22:18:32:296 1636
      22:18:32:296 1636 Completed
      22:18:32:296 1636
      22:18:32:296 1636 Results:
      22:18:32:296 1636 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
      22:18:32:296 1636 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
      22:18:32:296 1636 File objects infected / cured / cured on reboot: 0 / 0 / 0
      22:18:32:296 1636
      22:18:32:296 1636 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
      22:18:32:296 1636 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
      22:18:32:296 1636 KLMD(ARK) unloaded successfully
      0
  15. Contributeur sécurité
    Bien, ton PC va t-il mieux ??

    On continue :

    ● Télécharge Defogger.exe sur ton bureau

    ● Double clique sur Defogger.exe

    ● Une fenêtre apparaît, clique sur Disable

    ● Redémarre ton PC si l'outil le demande

    Puis :

    ● Télécharge gmer sur ton bureau à partir de ce lien ==> http://www.gmer.net/#files en cliquant sur le bouton "Download EXE".
    Note : le fichier téléchargé aura un nom aléatoire, c'est normal, garde ce nom

    ● Lance gmer à partir du fichier au nom aléatoire

    ● Un scan va se lancer dès le lancement, laisse le faire.

    ● Si il détecte tout de suite le rootkit, il va te proposer de scanner le PC en entier, accepte.
    ● Sinon, coche sur la droite les cases "Services", "Registry" et "Files" et clique sur le bouton scan

    ● Laisse travailler l'outil

    ● A la fin du scan, clique sur le bouton Save... et enregistre le rapport sur ton bureau

    ● Copie/colle le contenu du rapport dans ta réponse
    1
    1. bonsoir, les psudos !!! aujourd'hui à l'ouverture du pc pas d'alerte, ouf un peu de stabilité . Hier j'ai retéléchargé avira j'espère que je n'ai pas fait de connerie. j'ai bien téléchargé deffoger mais je rencontre quelques difficultés pour le scan de gmer, ça beugue , la page est blanche. Je vais fermer toutes les applications et me déconnecter pour refaire ça tranquille. Merci encore, c'est de longue haleine mais je ne perd pas courage ;;;la suite bientôt avec le rapport
      0
    2. bon et ben c'est compliqué tout ça , maintenant au démarrage un messag "virtual SCSI driver not detected" s'affiche , je ne sais pas si faut que je clique sur ok ou pas ?

      puis voici le rapport de Deffoger puis celui de gmer enfin !!! mais se fut laborieux et l'annonce "the file has been saved successfully" s'est affiché ???? pour gmer

      22:18:31:859 1636 TDSS rootkit removing tool 2.2.8.1 Mar 22 2010 10:43:04
      22:18:31:859 1636 ================================================================================
      22:18:31:859 1636 SystemInfo:

      22:18:31:859 1636 OS Version: 5.1.2600 ServicePack: 3.0
      22:18:31:859 1636 Product type: Workstation
      22:18:31:859 1636 ComputerName: SWEET-E8A020C74
      22:18:31:859 1636 UserName: Administrateur
      22:18:31:859 1636 Windows directory: C:\WINDOWS
      22:18:31:859 1636 Processor architecture: Intel x86
      22:18:31:859 1636 Number of processors: 2
      22:18:31:859 1636 Page size: 0x1000
      22:18:31:859 1636 Boot type: Normal boot
      22:18:31:859 1636 ================================================================================
      22:18:31:859 1636 UnloadDriverW: NtUnloadDriver error 2
      22:18:31:859 1636 ForceUnloadDriverW: UnloadDriverW(klmd21) error 2
      22:18:31:859 1636 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\system
      22:18:31:859 1636 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
      22:18:31:859 1636 wfopen_ex: Trying to KLMD file open
      22:18:31:859 1636 wfopen_ex: File opened ok (Flags 2)
      22:18:31:859 1636 wfopen_ex: Trying to open file C:\WINDOWS\system32\config\software
      22:18:31:859 1636 wfopen_ex: MyNtCreateFileW error 32 (C0000043)
      22:18:31:859 1636 wfopen_ex: Trying to KLMD file open
      22:18:31:859 1636 wfopen_ex: File opened ok (Flags 2)
      22:18:31:859 1636 Initialize success
      22:18:31:859 1636
      22:18:31:859 1636 Scanning Services ...
      22:18:32:203 1636 Raw services enum returned 337 services
      22:18:32:203 1636
      22:18:32:203 1636 Scanning Kernel memory ...
      22:18:32:203 1636 Devices to scan: 12
      22:18:32:203 1636
      22:18:32:203 1636 Driver Name: Disk
      22:18:32:203 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:203 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:203 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:203 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:203 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:203 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:203 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:203 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:203 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:203 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:203 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:203 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:203 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:203 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:203 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:203 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:203 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:203 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:203 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:203 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:203 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:203 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:203 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:203 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:203 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:203 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:203 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:234 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:234 1636
      22:18:32:234 1636 Driver Name: USBSTOR
      22:18:32:234 1636 IRP_MJ_CREATE : BAC75218
      22:18:32:234 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:234 1636 IRP_MJ_CLOSE : BAC75218
      22:18:32:234 1636 IRP_MJ_READ : BAC7523C
      22:18:32:234 1636 IRP_MJ_WRITE : BAC7523C
      22:18:32:234 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:234 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:234 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:234 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:234 1636 IRP_MJ_FLUSH_BUFFERS : 804F4552
      22:18:32:234 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:234 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:234 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:234 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:234 1636 IRP_MJ_DEVICE_CONTROL : BAC75180
      22:18:32:234 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BAC709E6
      22:18:32:234 1636 IRP_MJ_SHUTDOWN : 804F4552
      22:18:32:234 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:234 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:234 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:234 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:234 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:234 1636 IRP_MJ_POWER : BAC745F0
      22:18:32:234 1636 IRP_MJ_SYSTEM_CONTROL : BAC72A6E
      22:18:32:234 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:234 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:234 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: Disk
      22:18:32:250 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: Disk
      22:18:32:250 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: Disk
      22:18:32:250 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: Disk
      22:18:32:250 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:250 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: USBSTOR
      22:18:32:250 1636 IRP_MJ_CREATE : BAC75218
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BAC75218
      22:18:32:250 1636 IRP_MJ_READ : BAC7523C
      22:18:32:250 1636 IRP_MJ_WRITE : BAC7523C
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BAC75180
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BAC709E6
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : 804F4552
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BAC745F0
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BAC72A6E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:250 1636 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1
      22:18:32:250 1636
      22:18:32:250 1636 Driver Name: USBSTOR
      22:18:32:250 1636 IRP_MJ_CREATE : BAC75218
      22:18:32:250 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:250 1636 IRP_MJ_CLOSE : BAC75218
      22:18:32:250 1636 IRP_MJ_READ : BAC7523C
      22:18:32:250 1636 IRP_MJ_WRITE : BAC7523C
      22:18:32:250 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:250 1636 IRP_MJ_FLUSH_BUFFERS : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:250 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_DEVICE_CONTROL : BAC75180
      22:18:32:250 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BAC709E6
      22:18:32:250 1636 IRP_MJ_SHUTDOWN : 804F4552
      22:18:32:250 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:250 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:250 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:250 1636 IRP_MJ_POWER : BAC745F0
      22:18:32:250 1636 IRP_MJ_SYSTEM_CONTROL : BAC72A6E
      22:18:32:250 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:250 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:250 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:265 1636 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1
      22:18:32:265 1636
      22:18:32:265 1636 Driver Name: USBSTOR
      22:18:32:265 1636 IRP_MJ_CREATE : BAC75218
      22:18:32:265 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:265 1636 IRP_MJ_CLOSE : BAC75218
      22:18:32:265 1636 IRP_MJ_READ : BAC7523C
      22:18:32:265 1636 IRP_MJ_WRITE : BAC7523C
      22:18:32:265 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_FLUSH_BUFFERS : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_DEVICE_CONTROL : BAC75180
      22:18:32:265 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BAC709E6
      22:18:32:265 1636 IRP_MJ_SHUTDOWN : 804F4552
      22:18:32:265 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:265 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_POWER : BAC745F0
      22:18:32:265 1636 IRP_MJ_SYSTEM_CONTROL : BAC72A6E
      22:18:32:265 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:265 1636 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1
      22:18:32:265 1636
      22:18:32:265 1636 Driver Name: USBSTOR
      22:18:32:265 1636 IRP_MJ_CREATE : BAC75218
      22:18:32:265 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:265 1636 IRP_MJ_CLOSE : BAC75218
      22:18:32:265 1636 IRP_MJ_READ : BAC7523C
      22:18:32:265 1636 IRP_MJ_WRITE : BAC7523C
      22:18:32:265 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_FLUSH_BUFFERS : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_DEVICE_CONTROL : BAC75180
      22:18:32:265 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BAC709E6
      22:18:32:265 1636 IRP_MJ_SHUTDOWN : 804F4552
      22:18:32:265 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:265 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_POWER : BAC745F0
      22:18:32:265 1636 IRP_MJ_SYSTEM_CONTROL : BAC72A6E
      22:18:32:265 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:265 1636 C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS - Verdict: 1
      22:18:32:265 1636
      22:18:32:265 1636 Driver Name: Disk
      22:18:32:265 1636 IRP_MJ_CREATE : BA8EEBB0
      22:18:32:265 1636 IRP_MJ_CREATE_NAMED_PIPE : 804F4552
      22:18:32:265 1636 IRP_MJ_CLOSE : BA8EEBB0
      22:18:32:265 1636 IRP_MJ_READ : BA8E8D1F
      22:18:32:265 1636 IRP_MJ_WRITE : BA8E8D1F
      22:18:32:265 1636 IRP_MJ_QUERY_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_EA : 804F4552
      22:18:32:265 1636 IRP_MJ_FLUSH_BUFFERS : BA8E92E2
      22:18:32:265 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_VOLUME_INFORMATION : 804F4552
      22:18:32:265 1636 IRP_MJ_DIRECTORY_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_DEVICE_CONTROL : BA8E93BB
      22:18:32:265 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : BA8ECF28
      22:18:32:265 1636 IRP_MJ_SHUTDOWN : BA8E92E2
      22:18:32:265 1636 IRP_MJ_LOCK_CONTROL : 804F4552
      22:18:32:265 1636 IRP_MJ_CLEANUP : 804F4552
      22:18:32:265 1636 IRP_MJ_CREATE_MAILSLOT : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_SECURITY : 804F4552
      22:18:32:265 1636 IRP_MJ_POWER : BA8EAC82
      22:18:32:265 1636 IRP_MJ_SYSTEM_CONTROL : BA8EF99E
      22:18:32:265 1636 IRP_MJ_DEVICE_CHANGE : 804F4552
      22:18:32:265 1636 IRP_MJ_QUERY_QUOTA : 804F4552
      22:18:32:265 1636 IRP_MJ_SET_QUOTA : 804F4552
      22:18:32:265 1636 C:\WINDOWS\system32\DRIVERS\disk.sys - Verdict: 1
      22:18:32:265 1636
      22:18:32:265 1636 Driver Name: atapi
      22:18:32:265 1636 IRP_MJ_CREATE : 899F3D08
      22:18:32:265 1636 IRP_MJ_CREATE_NAMED_PIPE : 899F3D08
      22:18:32:265 1636 IRP_MJ_CLOSE : 899F3D08
      22:18:32:265 1636 IRP_MJ_READ : 899F3D08
      22:18:32:265 1636 IRP_MJ_WRITE : 899F3D08
      22:18:32:265 1636 IRP_MJ_QUERY_INFORMATION : 899F3D08
      22:18:32:265 1636 IRP_MJ_SET_INFORMATION : 899F3D08
      22:18:32:265 1636 IRP_MJ_QUERY_EA : 899F3D08
      22:18:32:265 1636 IRP_MJ_SET_EA : 899F3D08
      22:18:32:265 1636 IRP_MJ_FLUSH_BUFFERS : 899F3D08
      22:18:32:265 1636 IRP_MJ_QUERY_VOLUME_INFORMATION : 899F3D08
      22:18:32:265 1636 IRP_MJ_SET_VOLUME_INFORMATION : 899F3D08
      22:18:32:265 1636 IRP_MJ_DIRECTORY_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_FILE_SYSTEM_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_DEVICE_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_INTERNAL_DEVICE_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_SHUTDOWN : 899F3D08
      22:18:32:265 1636 IRP_MJ_LOCK_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_CLEANUP : 899F3D08
      22:18:32:265 1636 IRP_MJ_CREATE_MAILSLOT : 899F3D08
      22:18:32:265 1636 IRP_MJ_QUERY_SECURITY : 899F3D08
      22:18:32:265 1636 IRP_MJ_SET_SECURITY : 899F3D08
      22:18:32:265 1636 IRP_MJ_POWER : 899F3D08
      22:18:32:265 1636 IRP_MJ_SYSTEM_CONTROL : 899F3D08
      22:18:32:265 1636 IRP_MJ_DEVICE_CHANGE : 899F3D08
      22:18:32:265 1636 IRP_MJ_QUERY_QUOTA : 899F3D08
      22:18:32:265 1636 IRP_MJ_SET_QUOTA : 899F3D08
      22:18:32:296 1636 C:\WINDOWS\system32\DRIVERS\atapi.sys - Verdict: 1
      22:18:32:296 1636
      22:18:32:296 1636 Completed
      22:18:32:296 1636
      22:18:32:296 1636 Results:
      22:18:32:296 1636 Memory objects infected / cured / cured on reboot: 0 / 0 / 0
      22:18:32:296 1636 Registry objects infected / cured / cured on reboot: 0 / 0 / 0
      22:18:32:296 1636 File objects infected / cured / cured on reboot: 0 / 0 / 0
      22:18:32:296 1636
      22:18:32:296 1636 fclose_ex: Trying to close file C:\WINDOWS\system32\config\system
      22:18:32:296 1636 fclose_ex: Trying to close file C:\WINDOWS\system32\config\software
      22:18:32:296 1636 KLMD(ARK) unloaded successfully

      GMER 1.0.15.15281 - http://www.gmer.net

      Rootkit scan 2010-05-03 21:16:30
      Windows 5.1.2600 Service Pack 3
      Running: sj578hwi.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\awxdrfow.sys

      ---- System - GMER 1.0.15 ----

      SSDT BAFB8706 ZwCreateKey
      SSDT BAFB86FC ZwCreateThread
      SSDT BAFB870B ZwDeleteKey
      SSDT BAFB8715 ZwDeleteValueKey
      SSDT BAFB871A ZwLoadKey
      SSDT BAFB86E8 ZwOpenProcess
      SSDT BAFB86ED ZwOpenThread
      SSDT BAFB8724 ZwReplaceKey
      SSDT BAFB871F ZwRestoreKey
      SSDT BAFB8710 ZwSetValueKey
      SSDT BAFB86F7 ZwTerminateProcess

      ---- Kernel code sections - GMER 1.0.15 ----

      .text ntkrnlpa.exe!ZwCallbackReturn + 2DB8 80504654 4 Bytes CALL 870B41DF
      .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB9DD5360, 0x37192D, 0xE8000020]
      init C:\WINDOWS\system32\drivers\monfilt.sys entry point in "init" section [0xB7818280]

      ---- User code sections - GMER 1.0.15 ----

      .text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[172] ole32.dll!CoRegisterClassObject 774D7E90 5 Bytes JMP 00D14180 c:\Program Files\Bandoo\Plugins\MSN\MSNPlugin.dll (Bandoo MSN Plugin/Discordia Limited)
      .text C:\WINDOWS\Explorer.EXE[1684] SHELL32.dll!SHFileOperationW 7CA80924 5 Bytes JMP 10001102 C:\Program Files\Unlocker\UnlockerHook.dll

      ---- EOF - GMER 1.0.15 ----

      et celui
      0
  16. Contributeur sécurité
    Bien, je crois que l'on tient le bon bout, la suite :

    ● Relance Defogger présent sur ton bureau

    ● Clique sur le bouton "Re-enable"

    ● Redémarre ton PC si nécessaire

    Puis :

    ● Télécharge ZHPDiag de Nicolas Coolman sur ton bureau en cliquant sur le bouton télécharger

    ● Double clique sur le fichier téléchargé pour lancer l'installation

    ● Laisse toi guider pendant l'installation. Coche la case pour créer un raccourci sur le bureau et exécute ZHPDiag à la fin de l'installation

    ● Clique sur l'icône représentant une loupe ("Lancer le diagnostic") et patiente pendant le scan

    ● Clique sur l'icône représentant une disquette ("Sauvegarder le fichier sous") et enregistre le rapport sur ton bureau

    ● Ferme ZHPDiag, héberge le rapport ZHPDiag.txt sur le site ci-joint puis copie/colle le lien fourni dans ta réponse

    ► Aide en images
    1
    1. bonjour, tu m'as déjà fait télécharger ZHPDiag est-ce que je devais le supprimer ?? j'ai gardé sur mon bureau tous les sites que tu me proposes depuis le début.
      je scanne donc à partir de celui que j'ai déjà téléchargé, tu me diras sinon.
      0
    2. voici le rapport sur
      http://www.cijoint.fr/cjlink.php?file=cj201005/cijpLjMjMW.txt
      0
  17. Contributeur sécurité
    On supprimera les outils à la fin de la désinfection, on continue :

    ● Double clique sur ZHPFix qui présent sur ton bureau

    ● Clique sur l'icône représentant un H vert

    ● Copie puis colle le texte suivant dans le cadre jaune de ZHPFix :

    O64 - Services: CurCS - (.not file.) - zgdnhgob (zgdnhgob)  .(.Pas de propriétaire - Pas de description.) - LEGACY_ZGDNHGOB
    MBRFix
    


    ● Clique sur le bouton Tous puis sur Nettoyer

    ● Copie/colle le rapport qui apparaîtra à la fin
    1
    1. voici le rapport le texte que tu proposes était déjà inscrit dans le cadre jaune !!

      Processus mémoire :
      (Néant)

      Module mémoire :
      (Néant)

      Clé du Registre :
      O64 - Services: CurCS - (.not file.) - zgdnhgob (zgdnhgob) .(.Pas de propriétaire - Pas de description.) - LEGACY_ZGDNHGOB => Clé supprimée avec succès

      Valeur du Registre :
      (Néant)

      Elément de données du Registre :
      (Néant)

      Dossier :
      (Néant)

      Fichier :
      (Néant)

      Logiciel :
      (Néant)

      Script Registre :
      (Néant)

      Master Boot Record :
      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

      device: opened successfully
      user: MBR read successfully
      called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x89A8DA78]<<
      kernel: MBR read successfully
      detected MBR rootkit hooks:
      \Driver\atapi -> 0x89a8da78
      Warning: possible MBR rootkit infection !
      user & kernel MBR OK
      Use "Recovery Console" command "fixmbr" to clear infection !

      Resultat après le fix :
      Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

      device: opened successfully
      user: MBR read successfully
      kernel: MBR read successfully
      user & kernel MBR OK

      Autre :
      (Néant)

      Récapitulatif :
      Processus mémoire : 0
      Module mémoire : 0
      Clé du Registre : 1
      Valeur du Registre : 0
      Elément de données du Registre : 0
      Dossier : 0
      Fichier : 0
      Logiciel : 0
      Master Boot Record : 19
      Autre : 0

      End of the scan
      0
  18. Contributeur sécurité
    Parfait, maintenant, lance MalwareBytes, fais une mise à jour et un scan complet de ton PC.
    1
    1. voici le rapport du scan malwarebytes par contre pendant le scan 5 alertes d'avira qui a mis en quarantaine cheval de troie bffff

      Malwarebytes' Anti-Malware 1.45
      www.malwarebytes.org

      Version de la base de données: 4042

      Windows 5.1.2600 Service Pack 3
      Internet Explorer 7.0.5730.13

      05/05/2010 20:21:03
      mbam-log-2010-05-05 (20-21-03).txt

      Type d'examen: Examen complet (C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
      Elément(s) analysé(s): 181555
      Temps écoulé: 28 minute(s), 54 seconde(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 0

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      (Aucun élément nuisible détecté)
      0
    2. info : pendant le scan mon fils était sur msm
      0
  19. Contributeur sécurité
    Ok, fais un scan avec Avira pour être sûr.
    Pense à faire une mise à jour avant et active la recherche de rootkit ==> image
    1
    1. voici le rapport d'avira

      Avira AntiVir Personal
      Date de création du fichier de rapport : mercredi 5 mai 2010 21:39

      La recherche porte sur 2075343 souches de virus.

      Détenteur de la licence : Avira AntiVir Personal - FREE Antivirus
      Numéro de série : 0000149996-ADJIE-0000001
      Plateforme : Windows XP
      Version de Windows : (Service Pack 3) [5.1.2600]
      Mode Boot : Démarré normalement
      Identifiant : Administrateur
      Nom de l'ordinateur : SWEET-E8A020C74

      Informations de version :
      BUILD.DAT : 9.0.0.75 21698 Bytes 22/01/2010 23:14:00
      AVSCAN.EXE : 9.0.3.10 466689 Bytes 01/05/2010 20:23:22
      AVSCAN.DLL : 9.0.3.0 49409 Bytes 03/03/2009 09:21:02
      LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:11
      LUKERES.DLL : 9.0.2.0 13569 Bytes 03/03/2009 09:21:31
      VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 20:23:20
      VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 20:23:20
      VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 20:23:20
      VBASE003.VDF : 7.10.3.75 996864 Bytes 26/01/2010 20:23:20
      VBASE004.VDF : 7.10.4.203 1579008 Bytes 05/03/2010 20:23:20
      VBASE005.VDF : 7.10.6.82 2494464 Bytes 15/04/2010 20:23:20
      VBASE006.VDF : 7.10.6.83 2048 Bytes 15/04/2010 20:23:20
      VBASE007.VDF : 7.10.6.84 2048 Bytes 15/04/2010 20:23:20
      VBASE008.VDF : 7.10.6.85 2048 Bytes 15/04/2010 20:23:20
      VBASE009.VDF : 7.10.6.86 2048 Bytes 15/04/2010 20:23:20
      VBASE010.VDF : 7.10.6.87 2048 Bytes 15/04/2010 20:23:20
      VBASE011.VDF : 7.10.6.88 2048 Bytes 15/04/2010 20:23:20
      VBASE012.VDF : 7.10.6.89 2048 Bytes 15/04/2010 20:23:20
      VBASE013.VDF : 7.10.6.90 2048 Bytes 15/04/2010 20:23:20
      VBASE014.VDF : 7.10.6.123 126464 Bytes 19/04/2010 20:23:20
      VBASE015.VDF : 7.10.6.152 123392 Bytes 21/04/2010 20:23:20
      VBASE016.VDF : 7.10.6.178 122880 Bytes 22/04/2010 20:23:20
      VBASE017.VDF : 7.10.6.206 120320 Bytes 26/04/2010 20:23:20
      VBASE018.VDF : 7.10.6.232 99328 Bytes 28/04/2010 20:23:21
      VBASE019.VDF : 7.10.7.2 155648 Bytes 30/04/2010 20:23:21
      VBASE020.VDF : 7.10.7.26 119808 Bytes 04/05/2010 19:24:13
      VBASE021.VDF : 7.10.7.27 2048 Bytes 04/05/2010 19:24:13
      VBASE022.VDF : 7.10.7.28 2048 Bytes 04/05/2010 19:24:13
      VBASE023.VDF : 7.10.7.29 2048 Bytes 04/05/2010 19:24:13
      VBASE024.VDF : 7.10.7.30 2048 Bytes 04/05/2010 19:24:13
      VBASE025.VDF : 7.10.7.31 2048 Bytes 04/05/2010 19:24:13
      VBASE026.VDF : 7.10.7.32 2048 Bytes 04/05/2010 19:24:13
      VBASE027.VDF : 7.10.7.33 2048 Bytes 04/05/2010 19:24:14
      VBASE028.VDF : 7.10.7.34 2048 Bytes 04/05/2010 19:24:14
      VBASE029.VDF : 7.10.7.35 2048 Bytes 04/05/2010 19:24:14
      VBASE030.VDF : 7.10.7.36 2048 Bytes 04/05/2010 19:24:14
      VBASE031.VDF : 7.10.7.46 102912 Bytes 05/05/2010 19:24:21
      Version du moteur : 8.2.1.236
      AEVDF.DLL : 8.1.2.0 106868 Bytes 01/05/2010 20:23:21
      AESCRIPT.DLL : 8.1.3.28 1298810 Bytes 05/05/2010 19:25:17
      AESCN.DLL : 8.1.5.0 127347 Bytes 01/05/2010 20:23:21
      AESBX.DLL : 8.1.3.1 254324 Bytes 01/05/2010 20:23:21
      AERDL.DLL : 8.1.4.6 541043 Bytes 01/05/2010 20:23:21
      AEPACK.DLL : 8.2.1.1 426358 Bytes 01/05/2010 20:23:21
      AEOFFICE.DLL : 8.1.0.41 201083 Bytes 01/05/2010 20:23:21
      AEHEUR.DLL : 8.1.1.27 2670967 Bytes 05/05/2010 19:25:01
      AEHELP.DLL : 8.1.11.3 242039 Bytes 01/05/2010 20:23:21
      AEGEN.DLL : 8.1.3.7 373106 Bytes 01/05/2010 20:23:21
      AEEMU.DLL : 8.1.2.0 393588 Bytes 01/05/2010 20:23:21
      AECORE.DLL : 8.1.15.1 192886 Bytes 05/05/2010 19:24:25
      AEBB.DLL : 8.1.1.0 53618 Bytes 01/05/2010 20:23:21
      AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:30
      AVPREF.DLL : 9.0.3.0 44289 Bytes 01/05/2010 20:23:21
      AVREP.DLL : 8.0.0.7 159784 Bytes 01/05/2010 20:23:22
      AVREG.DLL : 9.0.0.0 36609 Bytes 07/11/2008 14:24:42
      AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:22
      AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:36:37
      SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
      SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:20:57
      NETNT.DLL : 9.0.0.0 11521 Bytes 07/11/2008 14:40:59
      RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 01/05/2010 20:23:19
      RCTEXT.DLL : 9.0.73.0 88321 Bytes 01/05/2010 20:23:19

      Configuration pour la recherche actuelle :
      Nom de la tâche...............................: Recherche de Rootkits
      Fichier de configuration......................: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\PROFILES\rootkit.avp
      Documentation.................................: bas
      Action principale.............................: interactif
      Action secondaire.............................: ignorer
      Recherche sur les secteurs d'amorçage maître..: marche
      Recherche sur les secteurs d'amorçage.........: marche
      Recherche dans les programmes actifs..........: arrêt
      Recherche en cours sur l'enregistrement.......: arrêt
      Recherche de Rootkits.........................: marche
      Contrôle d'intégrité de fichiers système......: arrêt
      Recherche optimisée...........................: marche
      Fichier mode de recherche.....................: Tous les fichiers
      Recherche sur les archives....................: marche
      Limiter la profondeur de récursivité..........: 20
      Archive Smart Extensions......................: marche
      Heuristique de macrovirus.....................: marche
      Heuristique fichier...........................: élevé
      Catégories de dangers divergentes.............: +SPR,

      Début de la recherche : mercredi 5 mai 2010 21:39

      La recherche d'objets cachés commence.
      '406305' objets ont été contrôlés, '0' objets cachés ont été trouvés.

      La recherche sur les fichiers sélectionnés commence :

      Recherche débutant dans 'C:'
      C:\pagefile.sys
      [AVERTISSEMENT] Impossible d'ouvrir le fichier !
      [REMARQUE] Ce fichier est un fichier système Windows.
      [REMARQUE] Il est correct que ce fichier ne puisse pas être ouvert pour la recherche.
      C:\WINDOWS\system32\cmdow.exe
      [RESULTAT] Contient le modèle de détection du programme SPR/HideWindows.I

      Début de la désinfection :
      C:\WINDOWS\system32\cmdow.exe
      [RESULTAT] Contient le modèle de détection du programme SPR/HideWindows.I
      [REMARQUE] Le fichier a été déplacé dans le répertoire de quarantaine sous le nom '4c45cdc1.qua' !

      Fin de la recherche : mercredi 5 mai 2010 21:56
      Temps nécessaire: 16:43 Minute(s)

      La recherche a été effectuée intégralement

      11574 Les répertoires ont été contrôlés
      196762 Des fichiers ont été contrôlés
      1 Des virus ou programmes indésirables ont été trouvés
      0 Des fichiers ont été classés comme suspects
      0 Des fichiers ont été supprimés
      0 Des virus ou programmes indésirables ont été réparés
      1 Les fichiers ont été déplacés dans la quarantaine
      0 Les fichiers ont été renommés
      1 Impossible de contrôler des fichiers
      196760 Fichiers non infectés
      1581 Les archives ont été contrôlées
      1 Avertissements
      2 Consignes
      406305 Des objets ont été contrôlés lors du Rootkitscan
      0 Des objets cachés ont été trouvés
      0
    2. c'est quoi un Spr ?
      0
  20. Contributeur sécurité
    Je te met la définition de Avira :

    Security Privacy Risk (SPR)
    La désignation "SPR" ("Security or Privacy Risk") concerne un programme qui peut être en mesure d'entraver la sécurité de votre système, de déclencher des activités de programme que vous ne souhaitez pas ou de porter atteinte à votre vie privée.


    Comment va ton PC ?
    0
    1. il me semble plus stable malgré la disparition de ma barre d'outil bureau toute à l'heure lors du scan d'avira .et du coup un redémarrage manuel !!
      J'attend demain pour voir comment il réagit
      merci encore je te tiens informé
      un collègue au bureau m'a parlé de " spybot" qu'est- ce que tu en penses ?
      0
    2. bon aujourd'hui apparemment pas de binzz , pas d'instabilité est-ce que je rescanne ?
      0
    3. Contributeur sécurité
      Oui, refais un essai.
      0
    4. info: échec de certaines mises à jour de windows xp me sont signalées
      0
    5. Contributeur sécurité
      Lesquelles ?
      0
  • 1
  • 2
  • 3