Trjandowloader.xs

Résolu
Bonjour,

Comme nombre de mes camarades j'ai "réussi" à choper un trojan nommé trojandownloader.xs...
Enfin c'est comme ca que l'erreur se désigne en gros, car il s'agit d'une infection contenant énormément de spywares apparemment.
Bref, j'ai besoin d'aide car je suis à la rue... je ne m'en sort pas.

Merci d'avance.

Je post un hijackthis,car j'imagine que ce sera nécesaire:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:25:12, on 08/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\DNA\btdna.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\John\lsass.exe
C:\WINDOWS\444.470
C:\WINDOWS\system32\iftuyszv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\portsv.exe
C:\Program Files\FlashGet\flashget.exe
C:\Documents and Settings\John\Bureau\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\iftuyszv.exe,
O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)
O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)
O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)
O2 - BHO: (no name) - {60220991-5217-4AC4-A2E1-01C22CFA37D6} - C:\WINDOWS\system32\jkkJbyXp.dll (file missing)
O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)
O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)
O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [LSA Shellu] C:\Documents and Settings\John\lsass.exe
O4 - HKLM\..\Run: [28e32193] rundll32.exe "C:\WINDOWS\system32\achfutdr.dll",b
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKLM\..\RunOnce: [SpybotDeletingA2918] command /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC4069] cmd /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingA8045] command /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
O4 - HKLM\..\RunOnce: [SpybotDeletingC3383] cmd /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\RunOnce: [SpybotDeletingB289] command /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD591] cmd /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7868] command /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7777] cmd /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O17 - HKLM\System\CCS\Services\Tcpip\..\{D7266F26-32C0-4C05-BFEA-C7A7EEFFA79B}: NameServer = 192.168.30.1
O20 - Winlogon Notify: efcBsPJy - C:\WINDOWS\SYSTEM32\efcBsPJy.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\444.470.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Plug and Play (RPC) (PlugPlayRPC) - Unknown owner - C:\WINDOWS\portsv.exe

--
End of file - 11786 bytes
Configuration: Windows XP
Internet Explorer 7.0

26 réponses

Résumé de la discussion

Le sujet porte sur une infection par un trojan downloader xs et une multitude de spywares, avec un rapport HijackThis partagé par l'utilisateur pour diagnostiquer la compromission. Plusieurs éléments de réponse recommandent d'utiliser ComboFix, en soulignant notamment la création d'un nouveau point de restauration et le fait que la console de récupération n'était pas installée sur la machine. D'autres éléments indiquent que ComboFix a mis en quarantaine ou supprimé plusieurs fichiers et clés système suspects, et que des éléments comme portsV.exe, achfutdr.dll et jkkJbyXp.dll_old ont été traités. D'autres signes montrent l'installation d'outils comme Malwarebytes et des composants Avast ou Google Updater, ce qui illustre une approche multi-outils de nettoyage avant une réévaluation du système.

Bobot (l’IA à votre service)
  1. salut,

    Telecharge malwarebytes

    -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    Tu l´instale; le programme va se mettre automatiquement a jour.

    Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

    Click maintenant sur l´onglet recherche et coche la case : "executer un examen complet".

    Puis click sur "rechercher".

    Laisse le scanner le pc...

    Si des elements on ete trouvés > click sur supprimer la selection.

    si il t´es demandé de redemarrer > click sur "yes".

    A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

    Copie et colle le rapport stp.

    ps : les rapport sont aussi rangé dans l onglet rapport/log
    1. si tu reviens par la pendant le scan malewarebyte
      fais ça auss :

      réouvre hijackthis
      fais scan only
      cohes ces lignes :

      O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)

      O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
      O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
      O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
      O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
      O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
      O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
      O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)

      O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)
      O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)

      O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)
      O2 - BHO: (no name) - {60220991-5217-4AC4-A2E1-01C22CFA37D6} - C:\WINDOWS\system32\jkkJbyXp.dll (file missing)
      O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)

      O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
      O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)
      O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)

      O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
      O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
      O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
      O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
      O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
      O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)

      O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
      O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
      O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)

      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
      O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com

      TU LES COCHES TOUTES ET TU CLIC SUR FIX CHECKED

      ensuite désinstal java car pas a jours et telecharge et instal cette version :

      https://www.java.com/fr/download/manual.jsp
      1. Deja merci de m'aider chiquitine...vive ceux qui s'y connaissent!

        Ensuite, voici pour commencer le nouveau log hijackthis:

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 11:46:14, on 08/06/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16640)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\Explorer.EXE
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\WINDOWS\SOUNDMAN.EXE
        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE
        C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\Program Files\DNA\btdna.exe
        C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
        C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
        C:\Program Files\MSN Messenger\usnsvc.exe
        C:\Documents and Settings\John\lsass.exe
        C:\WINDOWS\444.470
        C:\WINDOWS\system32\iftuyszv.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\WINDOWS\system32\rundll32.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\WINDOWS\portsv.exe
        C:\Program Files\FlashGet\flashget.exe
        C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
        C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
        C:\Documents and Settings\John\Bureau\HiJackThis.exe
        C:\WINDOWS\system32\ctfmon.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\iftuyszv.exe,
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {60220991-5217-4AC4-A2E1-01C22CFA37D6} - C:\WINDOWS\system32\jkkJbyXp.dll (file missing)
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
        O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
        O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
        O4 - HKLM\..\Run: [LSA Shellu] C:\Documents and Settings\John\lsass.exe
        O4 - HKLM\..\Run: [28e32193] rundll32.exe "C:\WINDOWS\system32\achfutdr.dll",b
        O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
        O4 - HKLM\..\RunOnce: [SpybotDeletingA2918] command /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
        O4 - HKLM\..\RunOnce: [SpybotDeletingC4069] cmd /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
        O4 - HKLM\..\RunOnce: [SpybotDeletingA8045] command /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
        O4 - HKLM\..\RunOnce: [SpybotDeletingC3383] cmd /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
        O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
        O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\RunOnce: [SpybotDeletingB289] command /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
        O4 - HKCU\..\RunOnce: [SpybotDeletingD591] cmd /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
        O4 - HKCU\..\RunOnce: [SpybotDeletingB7868] command /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
        O4 - HKCU\..\RunOnce: [SpybotDeletingD7777] cmd /c del "C:\WINDOWS\system32\jkkJbyXp.dll_old"
        O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
        O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
        O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
        O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
        O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
        O17 - HKLM\System\CCS\Services\Tcpip\..\{D7266F26-32C0-4C05-BFEA-C7A7EEFFA79B}: NameServer = 192.168.30.1
        O20 - Winlogon Notify: efcBsPJy - C:\WINDOWS\SYSTEM32\efcBsPJy.dll
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: MsSecurity Updated (MsSecurity1.209.4) - Unknown owner - C:\WINDOWS\444.470.exe (file missing)
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Plug and Play (RPC) (PlugPlayRPC) - Unknown owner - C:\WINDOWS\portsv.exe
        1. Télécharge clean.zip, de Malekal
          http://www.malekal.com/download/clean.zip

          (1) Dézippe-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.

          (2) Ouvre le dossier clean qui se trouve sur ton bureau, et double-clic sur clean.cmd

          une fenêtre noire va apparaître pendant un instant, laisse la ouverte.

          (3) Choisis l'option 1 puis patiente
          Poste le rapport obtenu

          pour retrouver le rapport : double clique sur > C > double clique sur " rapport_clean txt.
          et copie/colle le sur ta prochaine réponse .

          Ne passe pas à l'option 2 sans notre avis !
          1. Voici le rapport demandé, merci d'avance:

            08/06/2008 a 12:23:12,01

            *** Recherche des fichiers dans C:

            *** Recherche des fichiers dans C:\WINDOWS\
            C:\WINDOWS\internet.exe FOUND
            C:\WINDOWS\sys???????????.exe FOUND

            *** Recherche des fichiers dans C:\WINDOWS\system32
            C:\WINDOWS\accesss.exe FOUND
            C:\WINDOWS\avpcc.dll FOUND
            C:\WINDOWS\clrssn.exe FOUND
            C:\WINDOWS\olehelp.exe FOUND
            C:\WINDOWS\systeem.exe FOUND
            C:\WINDOWS\systemcritical.exe FOUND
            C:\WINDOWS\time.exe FOUND
            C:\WINDOWS\users32.exe FOUND
            C:\WINDOWS\waol.exe FOUND
            C:\WINDOWS\win32e.exe FOUND
            C:\WINDOWS\win64.exe FOUND
            C:\WINDOWS\window.exe FOUND
            C:\WINDOWS\winmgnt.exe FOUND
            C:\WINDOWS\x.exe FOUND
            C:\WINDOWS\y.exe FOUND

            *** Recherche des fichiers dans C:\Program Files
            1. de rien

              > Redémarre en mode sans échec :

              Comment redémarrer en mode sans echec?

              Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
              Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
              Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
              Ps : si F8 ne marche pas utilise la touche F5.

              -> Tuto : http://forum.telecharger.01net.com/forum/

              -> Une fois en mode sans echec, ouvre le dossier que tu auvais crée et click sur clean.cmd et choisis l'option 2.

              -> Redémarre normalement et poste le rapport de clean + un nouveau rapport hijackthis stp
              1. J'ai l'impression que resident de spybot me reinstalle toutes les clefs de registre supprimées, voici le dernier rapport hijackthis:

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 12:37:02, on 08/06/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\system32\iftuyszv.exe
                C:\WINDOWS\Explorer.EXE
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\WINDOWS\SOUNDMAN.EXE
                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                C:\WINDOWS\system32\RUNDLL32.EXE
                C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE
                C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
                C:\Program Files\MSN Messenger\MsnMsgr.Exe
                C:\Program Files\DNA\btdna.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\WINDOWS\system32\nvsvc32.exe
                C:\WINDOWS\portsv.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\WINDOWS\system32\wscntfy.exe
                C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                C:\Documents and Settings\John\Bureau\HiJackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\iftuyszv.exe,
                O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
                O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
                O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
                O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
                O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
                O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
                O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)
                O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
                O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)
                O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)
                O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
                O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
                O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)
                O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
                O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
                O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
                O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
                O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
                O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)
                O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
                O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
                O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
                O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
                O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
                O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
                O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} -
                O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
                O17 - HKLM\System\CCS\Services\Tcpip\..\{D7266F26-32C0-4C05-BFEA-C7A7EEFFA79B}: NameServer = 192.168.30.1
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                O23 - Service: Plug and Play (RPC) (PlugPlayRPC) - Unknown owner - C:\WINDOWS\portsv.exe
                1. 1) désinstal spybot pui sredémarre le pc (tu le réinstallera apres désinfection)

                  2) réouvre hijackthis
                  fais scan only
                  coche ces lignes :

                  O2 - BHO: (no name) - {00110011-4b0b-44d5-9718-90c88817369b} - (no file)

                  O2 - BHO: (no name) - {086ae192-23a6-48d6-96ec-715f53797e85} - (no file)
                  O2 - BHO: (no name) - {150fa160-130d-451f-b863-b655061432ba} - (no file)
                  O2 - BHO: (no name) - {17da0c9e-4a27-4ac5-bb75-5d24b8cdb972} - (no file)
                  O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb1} - (no file)
                  O2 - BHO: (no name) - {1f48aa48-c53a-4e21-85e7-ac7cc6b5ffb2} - (no file)
                  O2 - BHO: (no name) - {2d38a51a-23c9-48a1-a33c-48675aa2b494} - (no file)
                  O2 - BHO: (no name) - {2e9caff6-30c7-4208-8807-e79d4ec6f806} - (no file)

                  O2 - BHO: (no name) - {467faeb2-5f5b-4c81-bae0-2a4752ca7f4e} - (no file)
                  O2 - BHO: (no name) - {5321e378-ffad-4999-8c62-03ca8155f0b3} - (no file)

                  O2 - BHO: (no name) - {587dbf2d-9145-4c9e-92c2-1f953da73773} - (no file)
                  O2 - BHO: (no name) - {6cc1c91a-ae8b-4373-a5b4-28ba1851e39a} - (no file)

                  O2 - BHO: (no name) - {79369d5c-2903-4b7a-ade2-d5e0dee14d24} - (no file)
                  O2 - BHO: (no name) - {799a370d-5993-4887-9df7-0a4756a77d00} - (no file)
                  O2 - BHO: (no name) - {98dbbf16-ca43-4c33-be80-99e6694468a4} - (no file)
                  O2 - BHO: (no name) - {a55581dc-2cdb-4089-8878-71a080b22342} - (no file)

                  O2 - BHO: (no name) - {b847676d-72ac-4393-bfff-43a1eb979352} - (no file)
                  O2 - BHO: (no name) - {bc97b254-b2b9-4d40-971d-78e0978f5f26} - (no file)
                  O2 - BHO: (no name) - {cf021f40-3e14-23a5-cba2-717765721306} - (no file)
                  O2 - BHO: (no name) - {e2ddf680-9905-4dee-8c64-0a5de7fe133c} - (no file)
                  O2 - BHO: (no name) - {e3eebbe8-9cab-4c76-b26a-747e25ebb4c6} - (no file)
                  O2 - BHO: (no name) - {e7afff2a-1b57-49c7-bf6b-e5123394c970} - (no file)

                  O2 - BHO: (no name) - {fcaddc14-bd46-408a-9842-cdbe1c6d37eb} - (no file)
                  O2 - BHO: (no name) - {fd9bc004-8331-4457-b830-4759ff704c22} - (no file)
                  O2 - BHO: (no name) - {ff1bf4c7-4e08-4a28-a43f-9d60a9f7a880} - (no file)

                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} -

                  TU LES COCHES TOUTES ET TU CLIC SUR FIX CHECKED

                  3) Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                  -> Double clique combofix.exe.
                  -> Tape sur la touche 1 (Yes) pour démarrer le scan.
                  -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                  NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                  Avant d'utiliser ComboFix :

                  -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

                  -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

                  Une fois fait, sur ton bureau double-clic sur Combofix.exe.

                  - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

                  /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

                  - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

                  - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

                  -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

                  -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

                  -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

                  1. le rapport de combofix:

                    ComboFix 08-06-07.3 - John 2008-06-08 13:04:57.1 - NTFSx86
                    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.681 [GMT 2:00]
                    Endroit: C:\Downloads\ComboFix.exe
                    * Création d'un nouveau point de restauration

                    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                    .

                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    C:\Temp\1cb
                    C:\Temp\1cb\syscheck.log
                    C:\Temp\vtmp2
                    C:\Temp\vtmp2\ktnv33.log
                    C:\WINDOWS\accesss.exe
                    C:\WINDOWS\astctl32.ocx
                    C:\WINDOWS\avpcc.dll
                    C:\WINDOWS\clrssn.exe
                    C:\WINDOWS\cpan.dll
                    C:\WINDOWS\ctfmon32.exe
                    C:\WINDOWS\ctrlpan.dll
                    C:\WINDOWS\default.htm
                    C:\WINDOWS\directx32.exe
                    C:\WINDOWS\dnsrelay.dll
                    C:\WINDOWS\editpad.exe
                    C:\WINDOWS\explore.exe
                    C:\WINDOWS\explorer32.exe
                    C:\WINDOWS\funniest.exe
                    C:\WINDOWS\funny.exe
                    C:\WINDOWS\gfmnaaa.dll
                    C:\WINDOWS\helpcvs.exe
                    C:\WINDOWS\iedll.exe
                    C:\WINDOWS\iexplorer.exe
                    C:\WINDOWS\inetinf.exe
                    C:\WINDOWS\internet.exe
                    C:\WINDOWS\loader.exe
                    C:\WINDOWS\mainms.vpi
                    C:\WINDOWS\megavid.cdt
                    C:\WINDOWS\msconfd.dll
                    C:\WINDOWS\msspi.dll
                    C:\WINDOWS\mssys.exe
                    C:\WINDOWS\msupdate.exe
                    C:\WINDOWS\mswsc10.dll
                    C:\WINDOWS\mswsc20.dll
                    C:\WINDOWS\mtwirl32.dll
                    C:\WINDOWS\muotr.so
                    C:\WINDOWS\notepad32.exe
                    C:\WINDOWS\olehelp.exe
                    C:\WINDOWS\qttasks.exe
                    C:\WINDOWS\quicken.exe
                    C:\WINDOWS\rundll16.exe
                    C:\WINDOWS\rundll32.vbe
                    C:\WINDOWS\searchword.dll
                    C:\WINDOWS\sistem.exe
                    C:\WINDOWS\svchost32.exe
                    C:\WINDOWS\svcinit.exe
                    C:\WINDOWS\systeem.exe
                    C:\WINDOWS\system32\_000003_.tmp.dll
                    C:\WINDOWS\system32\_000006_.tmp.dll
                    C:\WINDOWS\system32\_000007_.tmp.dll
                    C:\WINDOWS\system32\_000008_.tmp.dll
                    C:\WINDOWS\system32\_000009_.tmp.dll
                    C:\WINDOWS\system32\_000010_.tmp.dll
                    C:\WINDOWS\system32\_000011_.tmp.dll
                    C:\WINDOWS\system32\_000012_.tmp.dll
                    C:\WINDOWS\system32\_000013_.tmp.dll
                    C:\WINDOWS\system32\_000014_.tmp.dll
                    C:\WINDOWS\system32\_000042_.tmp.dll
                    C:\WINDOWS\system32\efcBsPJy.dll
                    C:\WINDOWS\system32\hljwugsf.bin
                    C:\WINDOWS\system32\MSINET.oca
                    C:\WINDOWS\systemcritical.exe
                    C:\WINDOWS\time.exe
                    C:\WINDOWS\users32.exe
                    C:\WINDOWS\waol.exe
                    C:\WINDOWS\win32e.exe
                    C:\WINDOWS\win64.exe
                    C:\WINDOWS\winajbm.dll
                    C:\WINDOWS\window.exe
                    C:\WINDOWS\winmgnt.exe
                    C:\WINDOWS\x.exe
                    C:\WINDOWS\xplugin.dll
                    C:\WINDOWS\xxxvideo.hta
                    C:\WINDOWS\y.exe

                    .
                    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    -------\Legacy_MSSECURITY1.209.4

                    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-08 to 2008-06-08 ))))))))))))))))))))))))))))))))))))
                    .

                    2008-06-08 13:08 . 2008-06-08 13:08 <REP> d-------- C:\WINDOWS\system32\1435
                    2008-06-08 12:23 . 2008-06-08 12:23 10,990,606 --a------ C:\upload_moi_JOHN-6765D73D44.tar.gz
                    2008-06-08 11:32 . 2008-06-08 11:32 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                    2008-06-08 11:32 . 2008-06-08 11:32 <REP> d-------- C:\Documents and Settings\John\Application Data\Malwarebytes
                    2008-06-08 11:32 . 2008-06-08 11:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                    2008-06-08 11:32 . 2008-06-05 16:04 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
                    2008-06-08 11:32 . 2008-06-05 16:04 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                    2008-06-08 11:31 . 2008-06-08 11:31 <REP> d-------- C:\Documents and Settings\LocalService\Mes documents
                    2008-06-08 04:17 . 2008-06-08 04:59 153 --a------ C:\WINDOWS\wininit.ini
                    2008-06-08 03:55 . 2008-06-08 12:52 <REP> d-------- C:\WINDOWS\system32\7364
                    2008-06-08 03:55 . 2008-06-08 03:55 55,808 --a------ C:\WINDOWS\portsv.exe
                    2008-06-08 03:02 . 2008-06-08 12:02 94,208 --------- C:\WINDOWS\system32\achfutdr.dll
                    2008-06-08 02:59 . 2008-06-08 12:02 277,504 --------- C:\WINDOWS\system32\jkkJbyXp.dll_old
                    2008-06-08 02:59 . 2008-06-08 12:04 1,249 --ahs---- C:\WINDOWS\system32\pXybJkkj.ini
                    2008-06-08 02:55 . 2008-06-08 02:55 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
                    2008-06-08 02:55 . 2008-06-08 02:55 87,513 --a------ C:\WINDOWS\system32\iftuyszv.exe
                    2008-06-08 02:55 . 2008-06-08 02:54 30,728 --a------ C:\WINDOWS\444.470
                    2008-06-08 02:54 . 2008-06-08 12:02 <REP> d-------- C:\WINDOWS\system32\vntiho05
                    2008-06-08 02:54 . 2008-06-08 02:54 <REP> d-------- C:\WINDOWS\system32\OBE1
                    2008-06-08 02:54 . 2008-06-08 02:54 <REP> d-------- C:\WINDOWS\system32\kip
                    2008-06-08 02:54 . 2008-06-08 02:54 <REP> d-------- C:\WINDOWS\system32\20541
                    2008-06-08 02:54 . 2008-06-08 13:05 <REP> d-------- C:\Temp
                    2008-06-08 02:54 . 2008-06-08 02:54 121,325 --a------ C:\Temp\dvzer6.exe
                    2008-05-22 00:25 . 2008-06-08 13:03 <REP> d-------- C:\Downloads
                    2008-05-10 01:54 . 2008-05-10 01:54 <REP> d-------- C:\Program Files\Lavalys

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2008-06-08 11:08 --------- d-----w C:\Program Files\Steam
                    2008-06-08 11:06 --------- d-----w C:\Documents and Settings\John\Application Data\DNA
                    2008-06-08 11:04 --------- d-----w C:\Program Files\FlashGet
                    2008-06-08 10:51 --------- d-----w C:\Program Files\Spybot - Search & Destroy
                    2008-06-08 10:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                    2008-06-08 10:03 --------- d-----w C:\Program Files\Java
                    2008-06-08 09:45 --------- d-----w C:\Program Files\ma-config.com
                    2008-06-07 23:53 --------- d-----w C:\Documents and Settings\John\Application Data\LimeWire
                    2008-06-07 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
                    2008-05-25 21:13 --------- d-----w C:\Documents and Settings\John\Application Data\teamspeak2
                    2008-05-23 22:34 --------- d-----w C:\Documents and Settings\John\Application Data\FileZilla
                    2008-05-09 16:04 --------- d-----w C:\Program Files\eMule
                    2008-04-28 12:33 --------- d-----w C:\Program Files\Windows Media Connect 2
                    2008-04-28 10:36 --------- d-----w C:\Program Files\Advanced Font Viewer
                    2008-04-14 22:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\NVIDIA
                    2008-04-14 19:15 --------- d-----w C:\Program Files\DivX
                    2008-04-11 17:01 --------- d-----w C:\Program Files\LimeWire
                    2008-04-09 14:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
                    2008-04-08 10:03 --------- d-----w C:\Documents and Settings\John\Application Data\BitTorrent
                    .

                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    REGEDIT4
                    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "Configuration de la C-BOX"="C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe" [2004-12-21 20:17 395264]
                    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-09 23:35 68856]
                    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:55 5674352]
                    "Steam"="c:\program files\steam\steam.exe" [2008-03-28 13:27 1271032]
                    "BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-05-08 01:09 289088]
                    "Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 18:35 3587120]
                    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
                    "nwiz"="nwiz.exe" [2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe]
                    "SoundMan"="SOUNDMAN.EXE" [2007-04-16 16:28 577536 C:\WINDOWS\soundman.exe]
                    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
                    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 13:22 86016]
                    "EPSON Stylus Photo RX500"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.exe" [2003-09-12 05:00 99840]
                    "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-02-20 13:06 741376]

                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                    "msacm.l3acm"= l3codecp.acm

                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
                    C:\Program Files\Messenger\msmsgs.exe

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                    "%windir%\\system32\\sessmgr.exe"=
                    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
                    "C:\\Program Files\\eMule\\emule.exe"=
                    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                    "C:\\Program Files\\Steam\\steamapps\\john_r4\\counter-strike source\\hl2.exe"=
                    "C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
                    "C:\\Program Files\\Steam\\Steam.exe"=
                    "C:\\Program Files\\DNA\\btdna.exe"=
                    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
                    "C:\\Program Files\\FlashGet\\flashget.exe"=
                    "C:\\Program Files\\Internet Explorer\\iexplore.exe"=
                    "C:\\WINDOWS\\system32\\dpvsetup.exe"=

                    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
                    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
                    R2 PlugPlayRPC;Plug and Play (RPC);C:\WINDOWS\portsv.exe service []

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c5c66347-21d7-11dd-b786-00604cface62}]
                    \Shell\Auto\command - boot.pif
                    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.pif

                    .
                    **************************************************************************

                    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2008-06-08 13:08:47
                    Windows 5.1.2600 Service Pack 2 NTFS

                    Balayage processus cach‚s ...

                    Balayage cach‚ autostart entries ...

                    Balayage des fichiers cach‚s ...

                    Scan termin‚ avec succŠs
                    Les fichiers cach‚s: 0

                    **************************************************************************
                    .
                    ------------------------ Other Running Processes ------------------------
                    .
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\WINDOWS\system32\rundll32.exe
                    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                    C:\WINDOWS\portsv.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                    C:\WINDOWS\system32\verclsid.exe
                    .
                    **************************************************************************
                    .
                    Temps d'accomplissement: 2008-06-08 13:11:28 - machine was rebooted
                    ComboFix-quarantined-files.txt 2008-06-08 11:11:23

                    Pre-Run: 275,191,386,112 octets libres
                    Post-Run: 275,162,382,336 octets libres

                    214 --- E O F --- 2008-05-29 01:00:39

                    Par contre plus d'avast au demarrage de l'ordi...pas d'icones en barre des taches....normal??
                    1. pour avast oui c normal apres passage de combofix de toute façon on va le virer si t es daccord

                      refais un scan hijackthis et post le rapport stp
                      1. En fait, plus aucun message d'alerte comme quoi je suis sous spywares et qu'il me faut une protection complete.
                        En gros ca a l'air sain...
                        Un hijackthis peut-etre?
                        1. Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 13:22:57, on 08/06/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\WINDOWS\SOUNDMAN.EXE
                          C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                          C:\WINDOWS\system32\RUNDLL32.EXE
                          C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE
                          C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                          C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
                          C:\Program Files\MSN Messenger\MsnMsgr.Exe
                          C:\Program Files\DNA\btdna.exe
                          C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                          C:\WINDOWS\portsv.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                          C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                          C:\WINDOWS\explorer.exe
                          C:\Program Files\MSN Messenger\usnsvc.exe
                          C:\Program Files\Internet Explorer\IEXPLORE.EXE
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Documents and Settings\John\Bureau\HiJackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                          O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                          O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
                          O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                          O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
                          O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                          O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                          O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
                          O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                          O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                          O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
                          O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
                          O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                          O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
                          O17 - HKLM\System\CCS\Services\Tcpip\..\{D7266F26-32C0-4C05-BFEA-C7A7EEFFA79B}: NameServer = 192.168.30.1
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: Plug and Play (RPC) (PlugPlayRPC) - Unknown owner - C:\WINDOWS\portsv.exe
                          1. oui un hijackthis il te reste deux trois bricoles encore ....
                            1. aller stp dis moi qu'il ne reste qu'a fix la O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)

                              xD
                              1. Bon je me suis permis de la fixer...

                                Voici le rapport Hijackthis en résultant:

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 13:33:13, on 08/06/2008
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\WINDOWS\SOUNDMAN.EXE
                                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                C:\WINDOWS\system32\RUNDLL32.EXE
                                C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE
                                C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                                C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
                                C:\Program Files\MSN Messenger\MsnMsgr.Exe
                                C:\Program Files\DNA\btdna.exe
                                C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                C:\WINDOWS\portsv.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                                C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                                C:\WINDOWS\explorer.exe
                                C:\Program Files\MSN Messenger\usnsvc.exe
                                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                C:\WINDOWS\system32\wuauclt.exe
                                C:\Documents and Settings\John\Bureau\HiJackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
                                O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                                O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
                                O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                                O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
                                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                                O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
                                O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
                                O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
                                O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                                O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
                                O17 - HKLM\System\CCS\Services\Tcpip\..\{D7266F26-32C0-4C05-BFEA-C7A7EEFFA79B}: NameServer = 192.168.30.1
                                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                O23 - Service: Plug and Play (RPC) (PlugPlayRPC) - Unknown owner - C:\WINDOWS\portsv.exe
                                1. Copie le texte ci-dessous :

                                  File::
                                  C:\upload_moi_JOHN-6765D73D44.tar.gz
                                  C:\WINDOWS\portsv.exe
                                  C:\WINDOWS\system32\achfutdr.dll
                                  C:\WINDOWS\system32\jkkJbyXp.dll_old
                                  C:\WINDOWS\system32\pXybJkkj.ini
                                  C:\Temp\dvzer6.exe
                                  C:\WINDOWS\system32\iftuyszv.exe

                                  Folder::
                                  C:\Documents and Settings\John\Application Data\DNA

                                  Registry::
                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "BitTorrent DNA"=-

                                  Ouvre le Bloc-Notes puis colle le texte copié.
                                  (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
                                  Sauvegarde ce fichier sous le nom de CFScript.txt.

                                  Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

                                  http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

                                  Cela va relancer Combofix,

                                  Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                                  Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                                  Ne touche à rien tant que le scan n'est pas terminé.

                                  Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

                                  S'il n'y a pas de rédémarrage, poste quand même les rapports.

                                  1. Tout d'abord le rapport combofix:

                                    ComboFix 08-06-07.3 - John 2008-06-08 13:43:21.2 - NTFSx86
                                    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.632 [GMT 2:00]
                                    Endroit: C:\Documents and Settings\John\Bureau\ComboFix.exe
                                    Command switches used :: C:\Documents and Settings\John\Bureau\CFScript.txt
                                    * Création d'un nouveau point de restauration

                                    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                                    FILE ::
                                    C:\Temp\dvzer6.exe
                                    C:\upload_moi_JOHN-6765D73D44.tar.gz
                                    C:\WINDOWS\portsv.exe
                                    C:\WINDOWS\system32\achfutdr.dll
                                    C:\WINDOWS\system32\iftuyszv.exe
                                    C:\WINDOWS\system32\jkkJbyXp.dll_old
                                    C:\WINDOWS\system32\pXybJkkj.ini
                                    .

                                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .

                                    C:\Documents and Settings\John\Application Data\DNA
                                    C:\Documents and Settings\John\Application Data\DNA\dht.dat
                                    C:\Documents and Settings\John\Application Data\DNA\resume.dat
                                    C:\Documents and Settings\John\Application Data\DNA\resume.dat.old
                                    C:\Documents and Settings\John\Application Data\DNA\settings.dat
                                    C:\Documents and Settings\John\Application Data\DNA\settings.dat.old
                                    C:\Temp\dvzer6.exe
                                    C:\upload_moi_JOHN-6765D73D44.tar.gz
                                    C:\WINDOWS\portsv.exe
                                    C:\WINDOWS\system32\achfutdr.dll
                                    C:\WINDOWS\system32\iftuyszv.exe
                                    C:\WINDOWS\system32\jkkJbyXp.dll_old
                                    C:\WINDOWS\system32\pXybJkkj.ini

                                    .
                                    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                                    .

                                    -------\Legacy_PlugPlayRPC
                                    -------\Service_PlugPlayRPC

                                    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-08 to 2008-06-08 ))))))))))))))))))))))))))))))))))))
                                    .

                                    2008-06-08 13:08 . 2008-06-08 13:08 <REP> d-------- C:\WINDOWS\system32\1435
                                    2008-06-08 11:32 . 2008-06-08 11:32 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
                                    2008-06-08 11:32 . 2008-06-08 11:32 <REP> d-------- C:\Documents and Settings\John\Application Data\Malwarebytes
                                    2008-06-08 11:32 . 2008-06-08 11:32 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
                                    2008-06-08 11:32 . 2008-06-05 16:04 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
                                    2008-06-08 11:32 . 2008-06-05 16:04 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
                                    2008-06-08 11:31 . 2008-06-08 11:31 <REP> d-------- C:\Documents and Settings\LocalService\Mes documents
                                    2008-06-08 04:17 . 2008-06-08 04:59 153 --a------ C:\WINDOWS\wininit.ini
                                    2008-06-08 03:55 . 2008-06-08 12:52 <REP> d-------- C:\WINDOWS\system32\7364
                                    2008-06-08 02:55 . 2008-06-08 02:55 <REP> dr------- C:\Documents and Settings\LocalService\Favoris
                                    2008-06-08 02:55 . 2008-06-08 02:54 30,728 --a------ C:\WINDOWS\444.470
                                    2008-06-08 02:54 . 2008-06-08 12:02 <REP> d-------- C:\WINDOWS\system32\vntiho05
                                    2008-06-08 02:54 . 2008-06-08 02:54 <REP> d-------- C:\WINDOWS\system32\OBE1
                                    2008-06-08 02:54 . 2008-06-08 02:54 <REP> d-------- C:\WINDOWS\system32\kip
                                    2008-06-08 02:54 . 2008-06-08 02:54 <REP> d-------- C:\WINDOWS\system32\20541
                                    2008-06-08 02:54 . 2008-06-08 13:43 <REP> d-------- C:\Temp
                                    2008-05-22 00:25 . 2008-06-08 13:42 <REP> d-------- C:\Downloads
                                    2008-05-10 01:54 . 2008-05-10 01:54 <REP> d-------- C:\Program Files\Lavalys

                                    .
                                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2008-06-08 11:46 --------- d-----w C:\Program Files\Steam
                                    2008-06-08 11:44 --------- d-----w C:\Program Files\FlashGet
                                    2008-06-08 10:51 --------- d-----w C:\Program Files\Spybot - Search & Destroy
                                    2008-06-08 10:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                                    2008-06-08 10:03 --------- d-----w C:\Program Files\Java
                                    2008-06-08 09:45 --------- d-----w C:\Program Files\ma-config.com
                                    2008-06-07 23:53 --------- d-----w C:\Documents and Settings\John\Application Data\LimeWire
                                    2008-06-07 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
                                    2008-05-25 21:13 --------- d-----w C:\Documents and Settings\John\Application Data\teamspeak2
                                    2008-05-23 22:34 --------- d-----w C:\Documents and Settings\John\Application Data\FileZilla
                                    2008-05-09 16:04 --------- d-----w C:\Program Files\eMule
                                    2008-04-28 12:33 --------- d-----w C:\Program Files\Windows Media Connect 2
                                    2008-04-28 10:36 --------- d-----w C:\Program Files\Advanced Font Viewer
                                    2008-04-14 22:16 --------- d-----w C:\Documents and Settings\All Users\Application Data\NVIDIA
                                    2008-04-14 19:15 --------- d-----w C:\Program Files\DivX
                                    2008-04-11 17:01 --------- d-----w C:\Program Files\LimeWire
                                    2008-04-09 14:42 --------- d--h--w C:\Program Files\InstallShield Installation Information
                                    2008-04-08 10:03 --------- d-----w C:\Documents and Settings\John\Application Data\BitTorrent
                                    .

                                    ((((((((((((((((((((((((((((( snapshot@2008-06-08_13.11.11.10 )))))))))))))))))))))))))))))))))))))))))
                                    .
                                    - 2008-06-08 11:08:05 2,048 --s-a-w C:\WINDOWS\bootstat.dat
                                    + 2008-06-08 11:45:55 2,048 --s-a-w C:\WINDOWS\bootstat.dat
                                    + 2008-06-08 11:46:00 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_57c.dat
                                    .
                                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    REGEDIT4
                                    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "Configuration de la C-BOX"="C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe" [2004-12-21 20:17 395264]
                                    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-09 23:35 68856]
                                    "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 13:55 5674352]
                                    "Steam"="c:\program files\steam\steam.exe" [2008-03-28 13:27 1271032]
                                    "Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 18:35 3587120]
                                    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
                                    "nwiz"="nwiz.exe" [2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe]
                                    "SoundMan"="SOUNDMAN.EXE" [2007-04-16 16:28 577536 C:\WINDOWS\soundman.exe]
                                    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
                                    "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-10-22 13:22 86016]
                                    "EPSON Stylus Photo RX500"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.exe" [2003-09-12 05:00 99840]
                                    "Sony Ericsson PC Suite"="C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" [2007-02-20 13:06 741376]

                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                    "msacm.l3acm"= l3codecp.acm

                                    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
                                    C:\Program Files\Messenger\msmsgs.exe

                                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                    "%windir%\\system32\\sessmgr.exe"=
                                    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                                    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
                                    "C:\\Program Files\\eMule\\emule.exe"=
                                    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                                    "C:\\Program Files\\Steam\\steamapps\\john_r4\\counter-strike source\\hl2.exe"=
                                    "C:\\Program Files\\Veoh Networks\\Veoh\\VeohClient.exe"=
                                    "C:\\Program Files\\Steam\\Steam.exe"=
                                    "C:\\Program Files\\DNA\\btdna.exe"=
                                    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
                                    "C:\\Program Files\\FlashGet\\flashget.exe"=
                                    "C:\\Program Files\\Internet Explorer\\iexplore.exe"=
                                    "C:\\WINDOWS\\system32\\dpvsetup.exe"=

                                    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
                                    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]

                                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c5c66347-21d7-11dd-b786-00604cface62}]
                                    \Shell\Auto\command - boot.pif
                                    \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL boot.pif

                                    .
                                    **************************************************************************

                                    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                    Rootkit scan 2008-06-08 13:46:29
                                    Windows 5.1.2600 Service Pack 2 NTFS

                                    Balayage processus cach‚s ...

                                    Balayage cach‚ autostart entries ...

                                    Balayage des fichiers cach‚s ...

                                    Scan termin‚ avec succŠs
                                    Les fichiers cach‚s: 0

                                    **************************************************************************
                                    .
                                    ------------------------ Other Running Processes ------------------------
                                    .
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\WINDOWS\system32\rundll32.exe
                                    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                                    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                                    C:\WINDOWS\system32\verclsid.exe
                                    .
                                    **************************************************************************
                                    .
                                    Temps d'accomplissement: 2008-06-08 13:48:51 - machine was rebooted
                                    ComboFix-quarantined-files.txt 2008-06-08 11:48:46
                                    ComboFix2.txt 2008-06-08 11:11:29

                                    Pre-Run: 275,076,669,440 octets libres
                                    Post-Run: 275,095,203,840 octets libres

                                    159 --- E O F --- 2008-05-29 01:00:39

                                    et le rapport hijackthis:

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 13:51:14, on 08/06/2008
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\SOUNDMAN.EXE
                                    C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                    C:\WINDOWS\system32\RUNDLL32.EXE
                                    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE
                                    C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
                                    C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
                                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                                    C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\Program Files\Fichiers communs\Teleca Shared\Generic.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\WINDOWS\explorer.exe
                                    C:\Program Files\MSN Messenger\usnsvc.exe
                                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                    C:\Documents and Settings\John\Bureau\HiJackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                    O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
                                    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                    O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0K2.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
                                    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                                    O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\Cegetel\C-BOX\Wizard\QuickAccess.exe
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                                    O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                    O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
                                    O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
                                    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                                    O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exe
                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
                                    O17 - HKLM\System\CCS\Services\Tcpip\..\{D7266F26-32C0-4C05-BFEA-C7A7EEFFA79B}: NameServer = 192.168.30.1
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                    • 1
                                    • 2