Se connecter / S'enregistrer
Votre question

Redirection google et ralentissement

Tags :
  • Sécurité
Dernière réponse : dans Sécurité et virus
24 Mars 2011 20:50:35

Bonjour,
après un ccleaner, spybot, avast qui m'a trouvé plusieurs trojan et ver je n'arrive pas à me débarrasser de ce problème. j'ai lu plusieurs posts à ce sujet mais je ne comprends rien aux actions qu'il faut faire.
Si quelqu'un a une solution simple !
merci d'avance

Autres pages sur : redirection google ralentissement

24 Mars 2011 22:22:20

Bonsoir

1


Télécharge DDS et sauvegarde-le sur ton bureau.
  • Désactive tout script bloquant, tels qu'un antivirus, un logiciel comme ad-block, noscript etc.
  • Double-clique sur dds.scr pour lancer l'outil.
  • Une fois le scan fini, un document texte, DDS.txt, va s'ouvrir .
  • Clique Oui à la prochaine invite Optional Scan.
  • Sauvegarde les deux rapports sur ton bureau et poste-moi uniquement le DDS.txt.

    <@_@>**<@_@>**<@_@>**<@_@>**<@_@>**@_@>**<@_@><@_@>**<@_@>**<@_@>**<@_@>**


    2

    telecharge sur ton bureau http://support.kaspersky.com/downloads/utils/tdsskiller... , dezippe le et execute le , un rapport sera crée ici:

    C:\TDSSKillerVersion_Date_Time_log.txt.<< copie_colle son contenu

    tu as aussi directement l'executable là : http://support.kaspersky.com/downloads/utils/tdsskiller...

    o execute le , La fenêtre suivante va s'ouvrir::



    o Clique sur Start scan et laisse l'outil scanner ton disque dur sans l'interrompre et sans utiliser le PC.
    o Si des fichiers infectés sont trouvées, une nouvelle fenêtre va s'ouvrir:



    o Si TDSS.tdl2 est détecté l'option delete sera cochée par défaut.

    o Si TDSS.tdl3 est détecté assure toi que Cure est bien cochée.

    o Si TDSS.tdl4(\HardDisk0\MBR) est détecté assure toi que Cure est bien cochée.

    o Si Suspicious file est indiqué, laisse l'option cochée sur Skip

    o Clique sur Continue puis sur Reboot now pour redémarrer le PC.

    o Copie-colle le rapport généré dans ta prochaine réponse (Il est aussi sauvegardé à la racine de ta partition système sous le nom C:\TDSSKiller_Quarantine\JJ.MM.AA_HH.MM.SS. (JJ.MM.AA date du passage de l'outil, HH.MM.SS heure de passage).

    tutoriel--> http://support.kaspersky.com/viruses/solutions?qid=2082...




    24 Mars 2011 23:50:34

    bonsoir!
    merci pour l'aide je suis seulement a la phase 1!

    le dds demandé c'est bien ça ?

    DDS (Ver_11-03-05.01) - NTFSx86
    Run by Caroline Bienfait at 23:46:24,73 on 24/03/2011
    internet explorer: 7.0.5730.13
    browserjavaversion: 1.6.0_17
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1023.397 [GMT 1:00]
    .
    AV: avast! antivirus 4.8.1368 [VPS 110324-1] *Disabled/Updated* {7591DB91-41F0-48A3-B128-1A293FD8233D}
    .
    ============== Running Processes ===============
    .
    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    svchost.exe
    svchost.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    svchost.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Application Updater\ApplicationUpdater.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\RunDLL32.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
    C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
    C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
    C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\DNA\btdna.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Documents and Settings\Caroline Bienfait\Bureau\dds.scr
    .
    ============== Running Processes ===============
    .
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Application Updater\ApplicationUpdater.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\RunDLL32.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
    C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
    C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
    C:\Program Files\DivX\DivX Update\DivXUpdate.exe
    C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe
    C:\Program Files\Java\jre6\bin\jusched.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\DNA\btdna.exe
    C:\PROGRA~1\MI3AA1~1\rapimgr.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Documents and Settings\Caroline Bienfait\Bureau\dds.scr
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\WINDOWS\System32\svchost.exe -k NetworkService
    C:\WINDOWS\System32\svchost.exe -k LocalService
    C:\WINDOWS\System32\svchost.exe -k LocalService
    C:\WINDOWS\System32\svchost.exe -k imgsvc
    .
    ============== Pseudo HJT Report ===============
    .
    .
    SteelWerX Registry Console Tool 2.0
    Written by Bobbi Flekman 2006 (C)
    .
    HKEY_CURRENT_USER\software\microsoft\internet explorer\main
    Disable Script Debugger REG_SZ yes
    Anchor Underline REG_SZ yes
    Cache_Update_Frequency REG_SZ Once_Per_Session
    Display Inline Images REG_SZ yes
    Do404Search REG_BINARY 01000000
    Save_Session_History_On_Exit REG_SZ no
    Show_FullURL REG_SZ no
    Show_StatusBar REG_SZ yes
    Show_ToolBar REG_SZ yes
    Show_URLinStatusBar REG_SZ yes
    Show_URLToolBar REG_SZ yes
    Use_DlgBox_Colors REG_SZ yes
    Search Page REG_SZ http://www.google.com
    Search Bar REG_SZ http://www.google.com/ie
    XMLHTTP REG_DWORD 1 (0x1)
    UseClearType REG_SZ yes
    SearchMigrated REG_DWORD 1 (0x1)
    SearchMigratedDefaultName REG_SZ Google
    SearchMigratedDefaultURL REG_SZ http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    Move System Caret REG_SZ no
    Expand Alt Text REG_SZ no
    Print_Background REG_SZ no
    Show image placeholders REG_DWORD 0 (0x0)
    Enable AutoImageResize REG_SZ yes
    Play_Animations REG_SZ yes
    Play_Background_Sounds REG_SZ yes
    FavIntelliMenus REG_SZ no
    UseThemes REG_DWORD 1 (0x1)
    Friendly http errors REG_SZ yes
    Error Dlg Displayed On Every Error REG_SZ no
    Page_Transitions REG_DWORD 1 (0x1)
    NotifyDownloadComplete REG_SZ yes
    DisableScriptDebuggerIE REG_SZ yes
    NscSingleExpand REG_DWORD 0 (0x0)
    Force Offscreen Composition REG_DWORD 0 (0x0)
    EnableSearchPane REG_DWORD 0 (0x0)
    AllowWindowReuse REG_DWORD 1 (0x1)
    SmoothScroll REG_DWORD 1 (0x1)
    NoUpdateCheck REG_DWORD 1 (0x1)
    AutoSearch REG_DWORD 4 (0x4)
    FullScreen REG_SZ no
    Window_Placement REG_BINARY 2c00000002000000030000000083ffff0083ffffffffffffffffffff17010000000000003704000058020000
    CompatibilityFlags REG_DWORD 0 (0x0)
    SearchMigratedInstalled REG_DWORD 1 (0x1)
    ShowedCheckBrowser REG_SZ Yes
    Check_Associations REG_SZ no
    Start Page REG_SZ http://www.ask.com/?o=101764&l=dis
    Window Title REG_SZ Alice ADSL
    RunOnceHasShown REG_DWORD 1 (0x1)
    RunOnceComplete REG_DWORD 1 (0x1)
    Use FormSuggest REG_SZ yes
    .
    HKEY_CURRENT_USER\software\microsoft\internet explorer\main\Default Feeds
    .
    HKEY_CURRENT_USER\software\microsoft\internet explorer\main\FeatureControl
    .
    SteelWerX Registry Console Tool 2.0
    Written by Bobbi Flekman 2006 (C)
    .
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main
    Enable_Disk_Cache REG_SZ yes
    Cache_Percent_of_Disk REG_BINARY 0a000000
    Delete_Temp_Files_On_Exit REG_SZ yes
    Anchor_Visitation_Horizon REG_BINARY 01000000
    Use_Async_DNS REG_SZ yes
    Placeholder_Width REG_BINARY 1a000000
    Placeholder_Height REG_BINARY 1a000000
    CompanyName REG_SZ Microsoft Corporation
    Custom_Key REG_SZ MICROSO
    Wizard_Version REG_SZ 6.0.2600.0000
    Default_Secondary_Page_URL REG_MULTI_SZ \0\0
    Extensions Off Page REG_SZ about:NoAdd-ons
    Security Risk Page REG_SZ about:SecurityRisk
    Check_Associations REG_SZ yes
    .
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\ErrorThresholds
    .
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\FeatureControl
    .
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\main\UrlTemplate
    .
    SteelWerX Registry Console Tool 2.0
    Written by Bobbi Flekman 2006 (C)
    .
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings
    User Agent REG_SZ Mozilla/4.0 (compatible; MSIE 7.0; Win32)
    IE5_UA_Backup_Flag REG_SZ 5.0
    NoNetAutodial REG_BINARY 00000000
    MigrateProxy REG_DWORD 1 (0x1)
    EnableNegotiate REG_DWORD 1 (0x1)
    ProxyEnable REG_DWORD 0 (0x0)
    EmailName REG_SZ IEUser@
    AutoConfigProxy REG_SZ wininet.dll
    MimeExclusionListForCache REG_SZ multipart/mixed multipart/x-mixed-replace multipart/x-byteranges
    WarnOnPost REG_BINARY 01000000
    UseSchannelDirectly REG_BINARY 01000000
    EnableHttp1_1 REG_DWORD 1 (0x1)
    PrivacyAdvanced REG_DWORD 0 (0x0)
    PrivDiscUiShown REG_DWORD 1 (0x1)
    WarnOnZoneCrossing REG_DWORD 0 (0x0)
    SecureProtocols REG_DWORD 160 (0xa0)
    EnableAutodial REG_BINARY 00000000
    ProxyServer REG_SZ http=127.0.0.1:50370
    WarnOnIntranet REG_DWORD 1 (0x1)
    DisableIDNPrompt REG_DWORD 0 (0x0)
    EnablePunycode REG_DWORD 1 (0x1)
    UrlEncoding REG_DWORD 0 (0x0)
    ShowPunycode REG_DWORD 0 (0x0)
    ProxyHttp1.1 REG_DWORD 1 (0x1)
    WarnOnPostRedirect REG_DWORD 1 (0x1)
    DisableCachingOfSSLPages REG_DWORD 0 (0x0)
    WarnonBadCertRecving REG_DWORD 1 (0x1)
    CertificateRevocation REG_DWORD 0 (0x0)
    ProxyOverride REG_SZ *.local
    GlobalUserOffline REG_DWORD 0 (0x0)
    .
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\5.0
    .
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Cache
    .
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Connections
    .
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Lockdown_Zones
    .
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\P3P
    .
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Passport
    .
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Protocols
    .
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\ZoneMap
    .
    HKEY_CURRENT_USER\software\microsoft\windows\currentversion\internet settings\Zones
    .
    SteelWerX Registry Console Tool 2.0
    Written by Bobbi Flekman 2006 (C)
    .
    HKEY_CURRENT_USER\software\microsoft\internet explorer\search
    SearchAssistant REG_SZ http://www.google.com/ie
    usearchurl,(default) = hxxp://www.google.com/search?q=%s
    .
    SteelWerX Registry Console Tool 2.0
    Written by Bobbi Flekman 2006 (C)
    .
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\search
    SearchAssistant REG_SZ http://www.google.com/ie
    SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
    Written by Bobbi Flekman 2006 (C)URLSearchHooks: H - No File
    HKEY_CURRENT_USER\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
    {B922D405-6D13-4A2B-AE89-08A030DA4402}URLSearchHooks: H - No File
    {E312764E-7706-43F1-8DAB-FCDD2B1E416D}URLSearchHooks: H - No File
    SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
    Written by Bobbi Flekman 2006 (C)URLSearchHooks: H - No File
    HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
    SteelWerX Registry Console Tool 2.0URLSearchHooks: H - No File
    Written by Bobbi Flekman 2006 (C)URLSearchHooks: H - No File
    HKEY_USERS\.default\software\microsoft\internet explorer\urlsearchhooksURLSearchHooks: H - No File
    .
    SteelWerX Registry Console Tool 2.0
    Written by Bobbi Flekman 2006 (C)
    .
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon
    AutoRestartShell REG_DWORD 1 (0x1)
    DefaultDomainName REG_SZ PC-CAROLINE
    DefaultUserName REG_SZ Caroline Bienfait
    LegalNoticeCaption REG_SZ
    LegalNoticeText REG_SZ
    PowerdownAfterShutdown REG_SZ 0
    ReportBootOk REG_SZ 1
    Shell REG_SZ Explorer.exe
    ShutdownWithoutLogon REG_SZ 0
    System REG_SZ
    Userinit REG_SZ c:\WINDOWS\system32e\userinit.exe,
    VmApplet REG_SZ rundll32 shell32,Control_RunDLL "sysdm.cpl"
    SfcQuota REG_DWORD -1 (0xffffffff)
    allocatecdroms REG_SZ 0
    allocatedasd REG_SZ 0
    allocatefloppies REG_SZ 0
    cachedlogonscount REG_SZ 10
    forceunlocklogon REG_DWORD 0 (0x0)
    passwordexpirywarning REG_DWORD 14 (0xe)
    scremoveoption REG_SZ 0
    AllowMultipleTSSessions REG_DWORD 1 (0x1)
    UIHost REG_EXPAND_SZ logonui.exe
    LogonType REG_DWORD 1 (0x1)
    Background REG_SZ 0 0 0
    DebugServerCommand REG_SZ no
    SFCDisable REG_DWORD 0 (0x0)
    WinStationsDisabled REG_SZ 0
    HibernationPreviouslyEnabled REG_DWORD 1 (0x1)
    ShowLogonOptions REG_DWORD 0 (0x0)
    AltDefaultUserName REG_SZ Caroline Bienfait
    AltDefaultDomainName REG_SZ PC-CAROLINE
    ChangePasswordUseKerberos REG_DWORD 1 (0x1)
    .
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\GPExtensions
    .
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Notify
    .
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\SpecialAccounts
    .
    HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\Credentials
    .
    SteelWerX Registry Console Tool 2.0
    Written by Bobbi Flekman 2006 (C)
    .
    HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon
    ParseAutoexec REG_SZ 1
    ExcludeProfileDirs REG_SZ Local Settings;Temporary Internet Files;Historique;Temp;Local Settings\Application Data\Microsoft\Outlook
    BuildNumber REG_DWORD 2600 (0xa28)
    Shell REG_SZ explorer.exe,c:\Documents and Settings\Caroline Bienfait\Application Data\Microsoft\Windowse\shell.exe
    .
    SteelWerX Registry Console Tool 2.0
    Written by Bobbi Flekman 2006 (C)
    .
    HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows
    DebugOptions REG_SZ 2048
    Documents REG_SZ
    DosPrint REG_SZ no
    NetMessage REG_SZ no
    NullPort REG_SZ None
    Programs REG_SZ com exe bat pif cmd
    Device REG_SZ Microsoft Office Document Image Writer,winspool,Ne02:
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{326E768D-4182-46FD-9C16-1449A49795F4} - No File
    BHO: <NO NAME> - No File
    BHO: NoExplorer - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{53707962-6F74-2D53-2644-206D7942484F} - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{593DDEC6-7468-4cdd-90E1-42DADAA222E9} - No File
    BHO: <NO NAME> - No File
    BHO: NoExplorer - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: <NO NAME> - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - No File
    BHO: <NO NAME> - No File
    BHO: NoExplorer - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File
    BHO: NoExplorer - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{9030D464-4C02-4ABF-8ECC-5164760863C6} - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{B922D405-6D13-4A2B-AE89-08A030DA4402} - No File
    BHO: <NO NAME> - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{DBC80044-A445-435b-BC74-9C25C1C588A9} - No File
    BHO: NoExplorer - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C} - No File
    BHO: <NO NAME> - No File
    BHO: NoExplorer - No File
    BHO: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C} - No File
    urun: [SpybotSD TeaTimer] c:\Program Files\Spybot - Search & Destroye\TeaTimer.exe
    urun: [msnmsgr] "c:\Program Files\Windows Live\Messengere\msnmsgr.exe" /background
    urun: [ctfmon.exe] c:\WINDOWS\system32e\ctfmon.exe
    urun: [MSMSGS] "c:\Program Files\Messengere\msmsgs.exe" /background
    urun: [H/PC Connection Agent] "c:\Program Files\Microsoft ActiveSynce\wcescomm.exe"
    urun: [BitTorrent DNA] "c:\Program Files\DNAe\btdna.exe"
    urun: [Yhufid] rundll32.exe "c:\WINDOWSe\idrinev.dll",Startup
    urun: [MyWebSearch Email Plugin] c:\PROGRA~1\MYWEBS~1\bar\1.bine\mwsoemon.exe
    mrun: [NvCplDaemon] RUNDLL32.EXE c:\WINDOWS\system32e\NvCpl.dll,NvStartup
    mrun: [nwiz] nwiz.exe /install
    mrun: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
    mrun: [avast!] c:\PROGRA~1\ALWILS~1\Avast4e\ashDisp.exe
    mrun: [GhostStartTrayApp] c:\Program Files\Symantec\Norton Ghost 2003e\GhostStartTrayApp.exe
    mrun: [Lexmark X74-X75] "c:\Program Files\Lexmark X74-X75e\lxbbbmgr.exe"
    mrun: [AppleSyncNotifier] c:\Program Files\Fichiers communs\Apple\Mobile Device Support\bine\AppleSyncNotifier.exe
    mrun: [AliceSAV] c:\Program Files\TechCity Solutions\AliceSAVe\AliceAgent.exe
    mrun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    mrun: [QuickTime Task] "c:\Program Files\QuickTimee\QTTask.exe" -atboottime
    mrun: [iTunesHelper] "d:\Documentse\iTunesHelper.exe"
    mrun: [DivXUpdate] "c:\Program Files\DivX\DivX Updatee\DivXUpdate.exe" /CHECKNOW
    mrun: [DivX Download Manager] "c:\Program Files\DivX\DivX Plus Web Playere\DDmService.exe" start
    mrun: [<NO NAME>]
    mrun: [MyWebSearch Email Plugin] c:\PROGRA~1\MYWEBS~1\bar\1.bine\mwsoemon.exe
    mrun: [SearchSettings] c:\Program Files\pdfforge Toolbare\SearchSettings.exe
    mrun: [SunJavaUpdateSched] "c:\Program Files\Java\jre6\bine\jusched.exe"
    drun: [swg] c:\Program Files\Google\GoogleToolbarNotifiere\GoogleToolbarNotifier.exe
    .
    ie: SteelWerX Registry Console Tool 2.0
    ie: Written by Bobbi Flekman 2006 (C)
    .
    ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext
    .
    ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\&Search
    .
    ie: HKEY_CURRENT_USER\software\microsoft\internet explorer\menuext\E&xporter vers Microsoft Excel
    .
    ie: {SteelWerX Registry Console Tool 2.0
    ie: {Written by Bobbi Flekman 2006 (C)
    .
    ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions
    .
    ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{08B0E5C0-4FCB-11CF-AAA5-00401C608501}
    ie: { MenuText - REG_SZ Console Java (Sun)
    .
    ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{2EAF5BB1-070F-11D3-9307-00C04FAE2D4F}
    ie: { Default Visible - REG_SZ Yes
    ie: { Icon - REG_SZ c:\PROGRA~1\MI3AA1~1e\INetRepl.dll,210
    ie: { HotIcon - REG_SZ c:\PROGRA~1\MI3AA1~1e\INetRepl.dll,211
    ie: { ButtonText - REG_SZ Create Mobile Favorite
    .
    ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{2EAF5BB2-070F-11D3-9307-00C04FAE2D4F}
    ie: { MenuCustomize - REG_SZ Tools
    ie: { MenuText - REG_SZ Créer un Favori de l'appareil mobile...
    ie: { MenuStatusBar - REG_SZ Ajouter cette page aux Favoris de l'appareil mobile.
    .
    ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{92780B25-18CC-41C8-B9BE-3C9C571A8263}
    ie: { ButtonText - REG_SZ Recherche
    ie: { Icon - REG_SZ c:\PROGRA~1\MICROS~2\OFFICE11e\REFBAR.ICO
    ie: { Default Visible - REG_SZ Yes
    ie: { HotIcon - REG_SZ c:\PROGRA~1\MICROS~2\OFFICE11e\REFBARH.ICO
    .
    ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{e2e2dd38-d088-4134-82b7-f2ba38496583}
    ie: { MenuText - REG_SZ @xpsp3res.dll,-20001
    ie: { Exec - REG_SZ %windir%\Network Diagnostic\xpnetdiag.exe
    .
    ie: {HKEY_LOCAL_MACHINE\software\microsoft\internet explorer\extensions\{FB5F1910-F110-11d2-BB9E-00C04F795683}
    ie: { ButtonText - REG_SZ Messenger
    ie: { Default Visible - REG_SZ Yes
    ie: { Exec - REG_SZ c:\Program Files\Messengere\msmsgs.exe
    ie: { HotIcon - REG_SZ c:\Program Files\Messengere\msmsgs.exe,302
    ie: { Icon - REG_SZ c:\Program Files\Messengere\msmsgs.exe,301
    ie: { MenuText - REG_SZ Windows Messenger
    ie: { ToolTip - REG_SZ Windows Messenger
    IE: { CLSID - REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
    IE: { ClsidExtension - REG_SZ {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC} - {cafeefac-0016-0000-0017-abcdeffedcbc}\inprocserver32 does not exist!
    IE: { CLSID - REG_SZ {1FBA04EE-3024-11D2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
    IE: { clsidExtension - REG_SZ {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - {2eaf5bb0-070f-11d3-9307-00c04fae2d4f}\inprocserver32 does not exist!
    IE: { CLSID - REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
    IE: { clsidExtension - REG_SZ {2EAF5BB0-070F-11D3-9307-00C04FAE2D4F} - {2eaf5bb0-070f-11d3-9307-00c04fae2d4f}\inprocserver32 does not exist!
    IE: { BandCLSID - REG_SZ {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - {ff059e31-cc5a-4e2e-bf3b-96e929d65503}\inprocserver32 does not exist!
    IE: { CLSID - REG_SZ {E0DD6CAB-2D10-11D2-8F1A-0000F87ABD16} - {e0dd6cab-2d10-11d2-8f1a-0000f87abd16}\inprocserver32 does not exist!
    IE: { CLSID - REG_SZ {1FBA04EE-3024-11d2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
    IE: { CLSID - REG_SZ {1FBA04EE-3024-11D2-8F1F-0000F87ABD16} - {1fba04ee-3024-11d2-8f1f-0000f87abd16}\inprocserver32 does not exist!
    .
    Contenus similaires
    25 Mars 2011 00:19:32

    et voilà le résultat de kapersky!
    je dois faire quoi maintenant?
    merci.

    2011/03/25 00:06:38.0390 3640 TDSS rootkit removing tool 2.4.21.0 Mar 10 2011 12:26:28
    2011/03/25 00:06:38.0671 3640 ================================================================================
    2011/03/25 00:06:38.0671 3640 SystemInfo:
    2011/03/25 00:06:38.0671 3640
    2011/03/25 00:06:38.0671 3640 OS Version: 5.1.2600 ServicePack: 3.0
    2011/03/25 00:06:38.0671 3640 Product type: Workstation
    2011/03/25 00:06:38.0671 3640 ComputerName: PC-CAROLINE
    2011/03/25 00:06:38.0734 3640 UserName: Caroline Bienfait
    2011/03/25 00:06:38.0734 3640 Windows directory: C:\WINDOWS
    2011/03/25 00:06:38.0734 3640 System windows directory: C:\WINDOWS
    2011/03/25 00:06:38.0734 3640 Processor architecture: Intel x86
    2011/03/25 00:06:38.0734 3640 Number of processors: 1
    2011/03/25 00:06:38.0734 3640 Page size: 0x1000
    2011/03/25 00:06:38.0734 3640 Boot type: Normal boot
    2011/03/25 00:06:38.0734 3640 ================================================================================
    2011/03/25 00:06:39.0046 3640 Initialize success
    2011/03/25 00:06:45.0078 3300 ================================================================================
    2011/03/25 00:06:45.0078 3300 Scan started
    2011/03/25 00:06:45.0078 3300 Mode: Manual;
    2011/03/25 00:06:45.0078 3300 ================================================================================
    2011/03/25 00:06:45.0453 3300 Aavmker4 (2ccfa74242741ca22a4267cce9b586f4) C:\WINDOWS\system32\drivers\Aavmker4.sys
    2011/03/25 00:06:45.0859 3300 ACPI (e5e6dbfc41ea8aad005cb9a57a96b43b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
    2011/03/25 00:06:46.0062 3300 ACPIEC (e4abc1212b70bb03d35e60681c447210) C:\WINDOWS\system32\drivers\ACPIEC.sys
    2011/03/25 00:06:46.0234 3300 aeaudio (11c04b17ed2abbb4833694bcd644ac90) C:\WINDOWS\system32\drivers\aeaudio.sys
    2011/03/25 00:06:46.0359 3300 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
    2011/03/25 00:06:46.0468 3300 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
    2011/03/25 00:06:46.0593 3300 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
    2011/03/25 00:06:47.0484 3300 Aspi32 (ed8cee58c1e4c5893f5b2fd686a272bf) C:\WINDOWS\system32\drivers\Aspi32.sys
    2011/03/25 00:06:47.0593 3300 aswFsBlk (b4079a98f294a3e262872cb76f4849f0) C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys
    2011/03/25 00:06:47.0781 3300 aswMon2 (dbee7b5ecb50fc2cf9323f52cbf41141) C:\WINDOWS\system32\drivers\aswMon2.sys
    2011/03/25 00:06:48.0015 3300 aswRdr (8080d683489c99cbace813f6fa4069cc) C:\WINDOWS\system32\drivers\aswRdr.sys
    2011/03/25 00:06:48.0125 3300 aswSP (2e5a2ad5004b55df39b7606130a88142) C:\WINDOWS\system32\drivers\aswSP.sys
    2011/03/25 00:06:48.0234 3300 aswTdi (d4c83a37efadfa2c398362e0776e3773) C:\WINDOWS\system32\drivers\aswTdi.sys
    2011/03/25 00:06:48.0343 3300 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
    2011/03/25 00:06:48.0468 3300 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
    2011/03/25 00:06:48.0687 3300 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
    2011/03/25 00:06:48.0843 3300 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
    2011/03/25 00:06:49.0078 3300 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
    2011/03/25 00:06:49.0203 3300 BlueletAudio (04e84c8049ee93614a2ff6d676d1e247) C:\WINDOWS\system32\DRIVERS\blueletaudio.sys
    2011/03/25 00:06:49.0328 3300 BT (d1813668a0117ae05bc0b81c874f91d4) C:\WINDOWS\system32\DRIVERS\btnetdrv.sys
    2011/03/25 00:06:49.0437 3300 Btcsrusb (7304acc25455746912de37d7ded387ed) C:\WINDOWS\system32\Drivers\btcusb.sys
    2011/03/25 00:06:49.0562 3300 BTHidEnum (161969d2dd1d39cd2f1edbc60c61fa99) C:\WINDOWS\system32\DRIVERS\vbtenum.sys
    2011/03/25 00:06:49.0687 3300 BTHidMgr (a9164c2a39bd917b9f42ae087560ac3d) C:\WINDOWS\system32\Drivers\BTHidMgr.sys
    2011/03/25 00:06:49.0812 3300 BTNetFilter (6b05fdc0cfc3753b520d2d4176cc32d0) C:\WINDOWS\system32\drivers\BTNetFilter.sys
    2011/03/25 00:06:49.0953 3300 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
    2011/03/25 00:06:50.0062 3300 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys
    2011/03/25 00:06:50.0265 3300 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
    2011/03/25 00:06:50.0390 3300 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
    2011/03/25 00:06:50.0531 3300 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys
    2011/03/25 00:06:51.0000 3300 ctsfm2k (b459ae4afca570088adddbe55eabbc92) C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys
    2011/03/25 00:06:51.0281 3300 DCamUSBIntel (b1da501b82e63e54d234008adbccdf55) C:\WINDOWS\system32\DRIVERS\mltcap.sys
    2011/03/25 00:06:51.0406 3300 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
    2011/03/25 00:06:51.0531 3300 dmboot (f5deadd42335fb33edca74ecb2f36cba) C:\WINDOWS\system32\drivers\dmboot.sys
    2011/03/25 00:06:51.0671 3300 dmio (5a7c47c9b3f9fb92a66410a7509f0c71) C:\WINDOWS\system32\drivers\dmio.sys
    2011/03/25 00:06:51.0765 3300 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
    2011/03/25 00:06:51.0953 3300 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
    2011/03/25 00:06:52.0093 3300 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
    2011/03/25 00:06:52.0203 3300 E100B (98b46b331404a951cabad8b4877e1276) C:\WINDOWS\system32\DRIVERS\e100b325.sys
    2011/03/25 00:06:52.0343 3300 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
    2011/03/25 00:06:52.0453 3300 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
    2011/03/25 00:06:52.0562 3300 Fips (31f923eb2170fc172c81abda0045d18c) C:\WINDOWS\system32\drivers\Fips.sys
    2011/03/25 00:06:52.0718 3300 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
    2011/03/25 00:06:52.0984 3300 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
    2011/03/25 00:06:53.0093 3300 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
    2011/03/25 00:06:53.0203 3300 Ftdisk (a86859b77b908c18c2657f284aa29fe3) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
    2011/03/25 00:06:53.0312 3300 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
    2011/03/25 00:06:53.0390 3300 GhPciScan (4d0e1ddfc571285a0bbabb0a534f4d3d) C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys
    2011/03/25 00:06:53.0500 3300 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
    2011/03/25 00:06:53.0609 3300 hidusb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
    2011/03/25 00:06:53.0828 3300 HSFHWBS2 (5bb6ce6c3fac28d4ef5c147e02c19e0b) C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys
    2011/03/25 00:06:53.0984 3300 HSF_DP (842b23035f8f68e79675efb436b6aa94) C:\WINDOWS\system32\DRIVERS\HSF_DP.sys
    2011/03/25 00:06:54.0140 3300 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys
    2011/03/25 00:06:54.0421 3300 i8042prt (a09bdc4ed10e3b2e0ec27bb94af32516) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    2011/03/25 00:06:54.0546 3300 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
    2011/03/25 00:06:54.0750 3300 intelppm (ad340800c35a42d4de1641a37feea34c) C:\WINDOWS\system32\DRIVERS\intelppm.sys
    2011/03/25 00:06:54.0875 3300 ip6fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
    2011/03/25 00:06:54.0953 3300 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
    2011/03/25 00:06:55.0062 3300 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
    2011/03/25 00:06:55.0156 3300 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
    2011/03/25 00:06:55.0281 3300 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
    2011/03/25 00:06:55.0390 3300 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
    2011/03/25 00:06:55.0515 3300 isapnp (355836975a67b6554bca60328cd6cb74) C:\WINDOWS\system32\DRIVERS\isapnp.sys
    2011/03/25 00:06:55.0625 3300 Kbdclass (16813155807c6881f4bfbf6657424659) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    2011/03/25 00:06:55.0734 3300 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
    2011/03/25 00:06:55.0828 3300 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys
    2011/03/25 00:06:56.0046 3300 mdmxsdk (aeb54ef22cb7c7e3f405f69f048d696c) C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys
    2011/03/25 00:06:56.0156 3300 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
    2011/03/25 00:06:56.0265 3300 Modem (510ade9327fe84c10254e1902697e25f) C:\WINDOWS\system32\drivers\Modem.sys
    2011/03/25 00:06:56.0375 3300 Mouclass (027c01bd7ef3349aaebc883d8a799efb) C:\WINDOWS\system32\DRIVERS\mouclass.sys
    2011/03/25 00:06:56.0484 3300 mouhid (124d6846040c79b9c997f78ef4b2a4e5) C:\WINDOWS\system32\DRIVERS\mouhid.sys
    2011/03/25 00:06:56.0578 3300 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
    2011/03/25 00:06:56.0796 3300 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
    2011/03/25 00:06:56.0937 3300 MRxSmb (f3aefb11abc521122b67095044169e98) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
    2011/03/25 00:06:57.0093 3300 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
    2011/03/25 00:06:57.0203 3300 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
    2011/03/25 00:06:57.0312 3300 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
    2011/03/25 00:06:57.0421 3300 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
    2011/03/25 00:06:57.0531 3300 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
    2011/03/25 00:06:57.0640 3300 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys
    2011/03/25 00:06:57.0890 3300 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
    2011/03/25 00:06:58.0109 3300 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys
    2011/03/25 00:06:58.0218 3300 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
    2011/03/25 00:06:58.0328 3300 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys
    2011/03/25 00:06:58.0453 3300 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
    2011/03/25 00:06:58.0562 3300 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
    2011/03/25 00:06:58.0671 3300 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
    2011/03/25 00:06:58.0812 3300 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys
    2011/03/25 00:06:58.0937 3300 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
    2011/03/25 00:06:59.0046 3300 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
    2011/03/25 00:06:59.0218 3300 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
    2011/03/25 00:06:59.0328 3300 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
    2011/03/25 00:06:59.0468 3300 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
    2011/03/25 00:06:59.0703 3300 nv (ba1b732c1a70cfea0c1b64f2850bf44f) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
    2011/03/25 00:06:59.0937 3300 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
    2011/03/25 00:07:00.0046 3300 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
    2011/03/25 00:07:00.0156 3300 OMCI (cec7e2c6c1fa00c7ab2f5434f848ae51) C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS
    2011/03/25 00:07:00.0296 3300 ossrv (c720c25b2d0c93dc425155f5b6a707f3) C:\WINDOWS\system32\DRIVERS\ctoss2k.sys
    2011/03/25 00:07:00.0453 3300 P16X (f051107ff80f132882e71e3a5d302ec1) C:\WINDOWS\system32\drivers\P16X.sys
    2011/03/25 00:07:00.0593 3300 Parport (8fd0bdbea875d06ccf6c945ca9abaf75) C:\WINDOWS\system32\DRIVERS\parport.sys
    2011/03/25 00:07:00.0703 3300 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
    2011/03/25 00:07:00.0828 3300 ParVdm (9575c5630db8fb804649a6959737154c) C:\WINDOWS\system32\drivers\ParVdm.sys
    2011/03/25 00:07:00.0968 3300 PCI (043410877bda580c528f45165f7125bc) C:\WINDOWS\system32\DRIVERS\pci.sys
    2011/03/25 00:07:01.0140 3300 PCIIde (93a3ac4be09fb39b3fb5dbb2b83e2192) C:\WINDOWS\system32\DRIVERS\pciide.sys
    2011/03/25 00:07:01.0140 3300 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\pciide.sys. Real md5: 93a3ac4be09fb39b3fb5dbb2b83e2192, Fake md5: f4bfde7209c14a07aaa61e4d6ae69eac
    2011/03/25 00:07:01.0156 3300 PCIIde - detected Rootkit.Win32.TDSS.tdl3 (0)
    2011/03/25 00:07:01.0281 3300 Pcmcia (f0406cbc60bdb0394a0e17ffb04cdd3d) C:\WINDOWS\system32\drivers\Pcmcia.sys
    2011/03/25 00:07:01.0656 3300 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
    2011/03/25 00:07:01.0765 3300 Processor (e19c9632ac828f6f214391e2bdda11cb) C:\WINDOWS\system32\DRIVERS\processr.sys
    2011/03/25 00:07:01.0906 3300 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
    2011/03/25 00:07:02.0015 3300 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
    2011/03/25 00:07:02.0125 3300 PxHelp20 (153d02480a0a2f45785522e814c634b6) C:\WINDOWS\system32\Drivers\PxHelp20.sys
    2011/03/25 00:07:02.0687 3300 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
    2011/03/25 00:07:02.0906 3300 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
    2011/03/25 00:07:03.0156 3300 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
    2011/03/25 00:07:03.0250 3300 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
    2011/03/25 00:07:03.0375 3300 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
    2011/03/25 00:07:03.0484 3300 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
    2011/03/25 00:07:03.0593 3300 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
    2011/03/25 00:07:03.0734 3300 redbook (d8eb2a7904db6c916eb5361878ddcbae) C:\WINDOWS\system32\DRIVERS\redbook.sys
    2011/03/25 00:07:03.0843 3300 ROOTMODEM (d8b0b4ade32574b2d9c5cc34dc0dbbe7) C:\WINDOWS\system32\Drivers\RootMdm.sys
    2011/03/25 00:07:04.0015 3300 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
    2011/03/25 00:07:04.0171 3300 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
    2011/03/25 00:07:04.0281 3300 Serial (93d313c31f7ad9ea2b75f26075413c7c) C:\WINDOWS\system32\DRIVERS\serial.sys
    2011/03/25 00:07:04.0437 3300 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
    2011/03/25 00:07:04.0625 3300 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys
    2011/03/25 00:07:04.0734 3300 smwdm (31fd0707c7dbe715234f2823b27214fe) C:\WINDOWS\system32\drivers\smwdm.sys
    2011/03/25 00:07:04.0937 3300 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
    2011/03/25 00:07:05.0046 3300 sr (39626e6dc1fb39434ec40c42722b660a) C:\WINDOWS\system32\DRIVERS\sr.sys
    2011/03/25 00:07:05.0171 3300 Srv (0f6aefad3641a657e18081f52d0c15af) C:\WINDOWS\system32\DRIVERS\srv.sys
    2011/03/25 00:07:05.0296 3300 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys
    2011/03/25 00:07:05.0406 3300 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
    2011/03/25 00:07:05.0500 3300 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
    2011/03/25 00:07:06.0000 3300 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
    2011/03/25 00:07:06.0109 3300 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
    2011/03/25 00:07:06.0234 3300 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
    2011/03/25 00:07:06.0343 3300 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
    2011/03/25 00:07:06.0484 3300 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
    2011/03/25 00:07:06.0734 3300 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
    2011/03/25 00:07:06.0968 3300 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
    2011/03/25 00:07:07.0093 3300 USBAAPL (f340199e8cb097e1acd58a967c665919) C:\WINDOWS\system32\Drivers\usbaapl.sys
    2011/03/25 00:07:07.0218 3300 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
    2011/03/25 00:07:07.0328 3300 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
    2011/03/25 00:07:07.0421 3300 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
    2011/03/25 00:07:07.0531 3300 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
    2011/03/25 00:07:07.0640 3300 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
    2011/03/25 00:07:07.0859 3300 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
    2011/03/25 00:07:08.0125 3300 usb_rndisx (b6cc50279d6cd28e090a5d33244adc9a) C:\WINDOWS\system32\DRIVERS\usb8023x.sys
    2011/03/25 00:07:08.0250 3300 VComm (9ebee4a060c5364a31aeaa04eac2af1e) C:\WINDOWS\system32\DRIVERS\VComm.sys
    2011/03/25 00:07:08.0375 3300 VcommMgr (630bbdbf5490f8f57abe650da63661a0) C:\WINDOWS\system32\Drivers\VcommMgr.sys
    2011/03/25 00:07:08.0484 3300 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
    2011/03/25 00:07:08.0703 3300 VolSnap (46de1126684369bace4849e4fc8c43ca) C:\WINDOWS\system32\drivers\VolSnap.sys
    2011/03/25 00:07:08.0859 3300 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
    2011/03/25 00:07:09.0000 3300 wceusbsh (46a247f6617526afe38b6f12f5512120) C:\WINDOWS\system32\DRIVERS\wceusbsh.sys
    2011/03/25 00:07:09.0203 3300 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
    2011/03/25 00:07:09.0328 3300 winachsf (bcdcc21314add47e26f1dfa1605e11c9) C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys
    2011/03/25 00:07:09.0515 3300 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS
    2011/03/25 00:07:09.0640 3300 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
    2011/03/25 00:07:09.0750 3300 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
    2011/03/25 00:07:10.0078 3300 ================================================================================
    2011/03/25 00:07:10.0078 3300 Scan finished
    2011/03/25 00:07:10.0078 3300 ================================================================================
    2011/03/25 00:07:10.0125 3448 Detected object count: 1
    2011/03/25 00:08:49.0703 3448 PCIIde (93a3ac4be09fb39b3fb5dbb2b83e2192) C:\WINDOWS\system32\DRIVERS\pciide.sys
    2011/03/25 00:08:49.0703 3448 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\pciide.sys. Real md5: 93a3ac4be09fb39b3fb5dbb2b83e2192, Fake md5: f4bfde7209c14a07aaa61e4d6ae69eac
    2011/03/25 00:08:51.0468 3448 Backup copy found, using it..
    2011/03/25 00:08:51.0484 3448 C:\WINDOWS\system32\DRIVERS\pciide.sys - will be cured after reboot
    2011/03/25 00:08:51.0484 3448 Rootkit.Win32.TDSS.tdl3(PCIIde) - User select action: Cure
    2011/03/25 00:09:07.0390 4016 Deinitialize success
    25 Mars 2011 21:06:03

    Bonsoir

    bon, ça commence bien:
    TDL est mouru ;O)

    Citation :
    2011/03/25 00:07:10.0125 3448 Detected object count: 1
    2011/03/25 00:08:49.0703 3448 PCIIde (93a3ac4be09fb39b3fb5dbb2b83e2192) C:\WINDOWS\system32\DRIVERS\pciide.sys
    2011/03/25 00:08:49.0703 3448 Suspicious file (Forged): C:\WINDOWS\system32\DRIVERS\pciide.sys. Real md5: 93a3ac4be09fb39b3fb5dbb2b83e2192, Fake md5: f4bfde7209c14a07aaa61e4d6ae69eac
    2011/03/25 00:08:51.0468 3448 Backup copy found, using it..
    2011/03/25 00:08:51.0484 3448 C:\WINDOWS\system32\DRIVERS\pciide.sys - will be cured after reboot
    2011/03/25 00:08:51.0484 3448 Rootkit.Win32.TDSS.tdl3(PCIIde) - User select action: Cure
    2011/03/25 00:09:07.0390 4016 Deinitialize success


    par contre ton rapport DDS n'est pas complet

    vu qu'apparemment il y a encore du ménage à faire, relance-le et poste le rapport en entier en utilisant ceci:
  • Clique sur ce lien : http://www.cijoint.fr/
  • Clique sur Parcourir... et cherche le fichier du rapport que tu souhaites me transmettre.
  • Clique sur Ouvrir.
  • Clique sur Cliquez ici pour déposer le fichier.
  • Un lien de cette forme, hxxp://www.cijoint.fr/cjlink.php?file=cj200905/cijSKAP5fU.txt, est ajouté dans la page.
  • Copie-colle ce lien dans ta réponse.
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS