Se connecter / S'enregistrer
Votre question

résolu virus help me , erreur survenue, action de déboguage

Tags :
  • Virus
  • Sécurité
Dernière réponse : dans Sécurité et virus
13 Avril 2008 20:45:36

Bonjour
je vous sollicite car mon ordi me marque sans cesse q'une erreur est survenue suite un bogage et me propose une action de débogage
Cela fait suite à un virus détecté sur une clé par avast !
Ce message de débogage revient si je mets oui et il faut appuyer plusieurs fois sur non pour qu'il se ferme .
Je viens de voir sur d'autres sujets des problèmes avec des messages similaires et il s'agissait bien d'un virus
j'attend votre aide et vous remercie d'avance, encore une fois
ps : c'est pour l'ordi d'un ami

Autres pages sur : resolu virus help erreur survenue action deboguage

13 Avril 2008 21:38:17

voilà le rapport,
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:37:12, on 13/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Synaptics\SynTP\Toshiba.exe
C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Sonic\RecordNow!\RecordNow.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\MSNMES~1\msnmsgr.exe
C:\Documents and Settings\jojo\Local Settings\Temporary Internet Files\Content.IE5\IFKL6HKF\HiJackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKLM\..\Policies\Explorer\Run: [alpha] c:\DriverLoad\windrv0.exe
O4 - HKLM\..\Policies\Explorer\Run: [beta] c:\DriverLoad\windrv0.exe
O4 - HKLM\..\Policies\Explorer\Run: [gamma] c:\DriverLoad\windrv0.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [SystemDriverLoad] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [SystemDriver] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [FDriver] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [ADriver] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [CDriver] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [DDriver] (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [alpha] c:\DriverLoad\windrv0.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [beta] c:\DriverLoad\windrv0.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [gamma] c:\DriverLoad\windrv0.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

--
End of file - 10114 bytes
Contenus similaires
13 Avril 2008 21:57:20

Re,

Télécharge Deckard's System Scanner (DSS) (ou DSS) sur ton Bureau.
NB : Tu dois être connecté avec des droits d'Administrateur.
  • ferme toutes les applications et fenêtres
  • double-clique sur dss.exe pour le lancer et suis les instructions ci-dessous
    Attention, il est conseillé de stopper temporairement les logiciels résidents de protection (pare-feu, antivirus, etc.)
  • s'il s'agit d'une première utilisation ou d'une nouvelle version de DSS :
  • tu devras cliquer 2 fois sur le OK des boîtes de dialogue
    Attention, si tu tardes trop, la réponse Abandon sera automatiquement validée
  • quand le traitement est terminé (clique sur OK), deux fichiers texte s'affichent :
    main.txt <- ouvert en premier plan et en plein écran
    extra.txt <- ouvert en second plan et en fenêtré (regarde la barre des taches)
    S'il s'agit d'une utilisation supplémentaire de DSS :
  • tu n'auras pas de boîte de dialogue (pas de OK)
  • quand le traitement est terminé, un fichier texte s'affiche :
    main.txt <- ouvert en premier plan et en plein écran

  • copie (Ctrl+A puis Ctrl+C) et colle (Ctrl+V) le contenu de main.txt dans ton prochain post
  • copie de même le contenu de extra.txt dans ton prochain post, si tu as ce fichier (première utilisation)
  • n'oublie pas de réactiver les protections si elles ont été stoppées.



    Ce que fait DSS :
  • crée un point de restauration dans Windows XP et Vista
  • nettoie les fichiers temporaires, DPF-Downloaded Program Files et le Cache Internet, vide la Corbeille de tous les lecteurs
  • vérifie quelques zones importantes de ton système et établit un rapport pour examen par ton conseiller en sécurité. DSS lance automatiquement HijackThis pour toi; il va aussi créer un raccourci HijackThis sur ton Bureau si tu n'as pas déjà HijackThis d'installé.

    ;) 
    13 Avril 2008 22:13:44

    j'éspère que j'ai bien fait , voilà
    Deckard's System Scanner v20071014.68
    Run by jojo on 2008-04-13 22:03:41
    Computer is in Normal Mode.
    --------------------------------------------------------------------------------

    -- System Restore --------------------------------------------------------------

    Successfully created a Deckard's System Scanner Restore Point.


    -- Last 5 Restore Point(s) --
    53: 2008-04-13 20:03:51 UTC - RP196 - Deckard's System Scanner Restore Point
    52: 2008-04-13 14:16:38 UTC - RP195 - Point de vérification système
    51: 2008-04-11 16:28:33 UTC - RP194 - Point de vérification système
    50: 2008-04-09 21:09:22 UTC - RP193 - Point de vérification système
    49: 2008-04-08 17:01:20 UTC - RP192 - Point de vérification système


    -- First Restore Point --
    1: 2008-01-14 21:31:22 UTC - RP144 - Installé iTunes


    Backed up registry hives.
    Performed disk cleanup.



    -- HijackThis (run as jojo.exe) ------------------------------------------------

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:04:58, on 13/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Sonic\RecordNow!\RecordNow.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
    C:\WINDOWS\system32\igfxsrvc.exe
    C:\PROGRA~1\MSNMES~1\msnmsgr.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Documents and Settings\jojo\Bureau\dss.exe
    C:\DOCUME~1\jojo\LOCALS~1\TEMPOR~1\Content.IE5\IFKL6HKF\jojo.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
    O4 - HKLM\..\Policies\Explorer\Run: [alpha] c:\DriverLoad\windrv0.exe
    O4 - HKLM\..\Policies\Explorer\Run: [beta] c:\DriverLoad\windrv0.exe
    O4 - HKLM\..\Policies\Explorer\Run: [gamma] c:\DriverLoad\windrv0.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [SystemDriverLoad] (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [SystemDriver] (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [FDriver] (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [ADriver] (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [CDriver] (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [DDriver] (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [alpha] c:\DriverLoad\windrv0.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [beta] c:\DriverLoad\windrv0.exe (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\Run: [gamma] c:\DriverLoad\windrv0.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

    --
    End of file - 9651 bytes

    -- File Associations -----------------------------------------------------------

    All associations okay.


    -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

    R1 StarOpen - c:\windows\system32\drivers\staropen.sys
    R2 AegisP (AEGIS Protocol (IEEE 802.1x) v3.4.9.0) - c:\windows\system32\drivers\aegisp.sys <Not Verified; Meetinghouse Data Communications; AEGIS Client 3.4.9.0>
    R2 Netdevio (TOSHIBA Network Device Usermode I/O Protocol) - c:\windows\system32\drivers\netdevio.sys <Not Verified; TOSHIBA Corporation.; TOSHIBA Network Device Usermode I/O protocol>
    R2 s24trans (Transport RLAN) - c:\windows\system32\drivers\s24trans.sys <Not Verified; Intel Corporation; Intel Wireless LAN Packet Driver>
    R3 Iviaspi (IVI ASPI Shell) - c:\windows\system32\drivers\iviaspi.sys <Not Verified; InterVideo, Inc.; InterVideo ASPI Shell>
    R3 Pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus(R) ASPI Shell>
    R3 qkbfiltr (Quanta HotKey Keyboard Filter Driver) - c:\windows\system32\drivers\qkbfiltr.sys <Not Verified; Quanta Computer, Inc.; Quanta HotKey Keyboard Filter Driver>
    R3 qmofiltr (Quanta HotKey Mouse Filter Driver) - c:\windows\system32\drivers\qmofiltr.sys <Not Verified; Quanta Computer, Inc.; Quanta Mouse Filter Device Driver>

    S3 o1394bul - c:\docume~1\jojo\locals~1\temp\o1394bul.sys (file missing)
    S3 PCAMPR5 (PCAMPR5 NDIS Protocol Driver) - c:\windows\system32\pcampr5.sys (file missing)
    S3 PCANDIS5 (PCANDIS5 NDIS Protocol Driver) - c:\windows\system32\pcandis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
    S3 StickCap (Digital TV DVB-T USB Stick adapter service) - c:\windows\system32\drivers\stickcap.sys <Not Verified; Ultima Electronics Corp.; Digital TV stick USB 2.0>
    S3 stickload (Digital TV stick firmware loader service) - c:\windows\system32\drivers\stickload.sys <Not Verified; Ultima Electronics Corp.; Digital TV T14>
    S3 SYMIDSCO - c:\progra~1\fichie~1\symant~1\symcdata\idsdefs\20070525.001\symidsco.sys (file missing)
    S3 tosrfec (Bluetooth ACPI from TOSHIBA) - c:\windows\system32\drivers\tosrfec.sys <Not Verified; TOSHIBA Corporation; TOSHIBA Bluetooth EC Driver>
    S3 UIUSys (Conexant Setup API) - c:\windows\system32\drivers\uiusys.sys (file missing)


    -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

    R2 Apple Mobile Device - "c:\program files\fichiers communs\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service>
    R2 CCALib8 (Canon Camera Access Library 8) - c:\program files\canon\cal\calmain.exe <Not Verified; Canon Inc.; >
    R2 CFSvcs (ConfigFree Service) - c:\program files\toshiba\configfree\cfsvcs.exe <Not Verified; TOSHIBA CORPORATION; ConfigFree(TM)>
    R2 FTRTSVC (France Telecom Routing Table Service) - c:\windows\system32\ftrtsvc.exe <Not Verified; France Telecom; FTRTSVC NT Service>
    R2 RegSrvc (Intel(R) PROSet/Wireless Registry Service) - c:\program files\intel\wireless\bin\regsrvc.exe <Not Verified; Intel Corporation; Intel(R) PROSet/Wireless Registry Service>
    R2 x10nets (X10 Device Network Service) - c:\progra~1\common~1\x10\common\x10nets.exe <Not Verified; X10; x10 Module>


    -- Device Manager: Disabled ----------------------------------------------------

    Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
    Description: Intel(R) PRO/1000 PL Network Connection
    Device ID: PCI\VEN_8086&DEV_109A&SUBSYS_FF311179&REV_00\4&192AC53F&0&00E0
    Manufacturer: Intel
    Name: Intel(R) PRO/1000 PL Network Connection
    PNP Device ID: PCI\VEN_8086&DEV_109A&SUBSYS_FF311179&REV_00\4&192AC53F&0&00E0
    Service: e1express


    -- Scheduled Tasks -------------------------------------------------------------

    2008-01-14 23:30:21 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job


    -- Files created between 2008-03-13 and 2008-04-13 -----------------------------

    2008-04-03 01:17:20 0 dr-h----- C:\Documents and Settings\jojo\Recent
    2008-04-03 00:59:13 0 d-------- C:\Program Files\CCleaner
    2008-03-27 22:44:58 0 d-------- C:\Documents and Settings\jojo\Application Data\MailFrontier
    2008-03-26 20:13:05 32768 --a------ C:\WINDOWS\system32\WooDial2000.dll <Not Verified; France Télécom R&D; Kit de Connexion et de Services>
    2008-03-26 20:13:00 0 d-------- C:\WINDOWS\system32\AlertModule
    2008-03-26 20:12:54 94208 --a------ C:\WINDOWS\system32\W32n50.dll <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
    2008-03-26 20:12:54 16128 -----n--- C:\WINDOWS\system32\PCANDIS5.SYS <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
    2008-03-26 20:12:50 36864 --a------ C:\WINDOWS\system32\IfHelper.dll <Not Verified; France Télécom R&D; IfHelper>
    2008-03-26 20:12:50 40960 --a------ C:\WINDOWS\system32\FTRTSVC.exe <Not Verified; France Telecom; FTRTSVC NT Service>
    2008-03-26 20:10:59 0 d-------- C:\Program Files\Wanadoo
    2008-03-26 19:51:21 0 d-------- C:\Program Files\SAGEM
    2008-03-24 18:50:02 0 d-------- C:\Program Files\Securitoo
    2008-03-16 03:44:41 0 d-------- C:\Program Files\Incomplete
    2008-03-16 03:43:46 0 d-------- C:\Program Files\LimeWire


    -- Find3M Report ---------------------------------------------------------------

    2008-04-13 17:47:36 0 d-------- C:\Documents and Settings\jojo\Application Data\LimeWire
    2008-04-13 16:48:55 0 d-------- C:\Program Files\Everest Poker
    2008-04-01 18:22:47 448428 --a------ C:\WINDOWS\system32\perfh00C.dat
    2008-04-01 18:22:47 64930 --a------ C:\WINDOWS\system32\perfc00C.dat
    2008-03-26 19:51:20 0 d--h----- C:\Program Files\InstallShield Installation Information


    -- Registry Dump ---------------------------------------------------------------

    *Note* empty entries & legit default entries are not shown


    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [05/08/2005 14:34]
    "nwiz"="nwiz.exe" [16/02/2006 16:34 C:\WINDOWS\system32\nwiz.exe]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [16/02/2006 16:34]
    "High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [29/12/2005 23:21 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [03/03/2006 01:02]
    "Toshiba Hotkey Utility"="C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" [15/03/2006 19:12]
    "NDSTray.exe"="NDSTray.exe" []
    "SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [17/05/2005 10:24]
    "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [06/10/2005 06:20]
    "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [05/12/2005 12:37]
    "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [28/11/2005 11:41]
    "CFSServ.exe"="CFSServ.exe" []
    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [04/12/2007 15:00]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [09/03/2007 00:02]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [19/02/2006 02:41]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [11/12/2007 11:56]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [11/12/2007 13:10]
    "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [23/08/2004 15:49]
    "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [14/10/2004 17:55]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [11/04/2005 17:08]
    "DriverLoad"="" []
    "DriverCheck"="" []
    "SystemDriverLoad"="" []
    "SystemDriver"="" []
    "FDriver"="" []
    "ADriver"="" []
    "CDriver"="" []
    "DDriver"="" []
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [10/08/2004 15:00]
    "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [23/08/2004 15:50]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "DriverLoad"=
    "DriverCheck"=
    "SystemDriverLoad"=
    "SystemDriver"=
    "FDriver"=
    "ADriver"=
    "CDriver"=
    "DDriver"=
    "alpha"=c:\DriverLoad\windrv0.exe
    "beta"=c:\DriverLoad\windrv0.exe
    "gamma"=c:\DriverLoad\windrv0.exe

    C:\Documents and Settings\jojo\Menu D‚marrer\Programmes\D‚marrage\
    Lancement rapide de Microsoft Office OneNote 2003.lnk - C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE [17/03/2005 15:06:14]

    C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [19/02/2006 04:21:22]
    Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [23/09/2005 23:05:26]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\Run]
    "DriverLoad"=
    "DriverCheck"=
    "SystemDriverLoad"=
    "Winhost"=
    "Winhost1"=
    "Winhost2"=
    "Winhost3"=
    "Winhost4"=
    "SystemDriver"=
    "FDriver"=
    "ADriver"=
    "CDriver"=
    "DDriver"=
    "alpha"=c:\DriverLoad\windrv0.exe
    "beta"=c:\DriverLoad\windrv0.exe
    "gamma"=c:\DriverLoad\windrv0.exe

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    "Authentication Packages"= msv1_0 nwprovau


    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2f8d630c-dc0f-11dc-adec-0013022d9c0b}]
    AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe MS32DLL.dll.vbs




    -- End of Deckard's System Scanner: finished at 2008-04-13 22:05:42 ------------

    13 Avril 2008 22:19:32

    Re,

    Réponse demain :) 

    Fais un up du sujet demain.

    Bonne soirée :hello: 
    13 Avril 2008 22:21:17

    ok merci , bonne nuit
    14 Avril 2008 01:09:17

    Re,

    Cette procédure doit être imprimée pour que tu puisses l’avoir sous les yeux quand tu seras en mode sans échec.

    Télécharge SDFix(créé par AndyManchesta) et sauvegarde le sur ton Bureau.
    ***Si le lien ne fonctionne pas, essaie celui-ci : http://download.bleepingcomputer.com/andymanchesta/SDFi... ***
    Guide d'utilisation : http://mickael.barroux.free.fr/securite/sdfix.php
    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
  • Redémarre ton ordinateur
  • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
  • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
  • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
  • Choisis ton compte.
    Déroule la liste des instructions ci-dessous :
  • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
  • Appuie sur Y pour commencer le processus de nettoyage.
  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
  • Appuie sur une touche pour redémarrer le PC.
  • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
  • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
  • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !
    N.B.:
    - Le fichier SDFIX_README.htm (dans le dossier SDFix) contient la liste des malwares pris en compte par l'outil.
    - Andy fait plusieurs mises à jour, souvent plus d'une par jour... N'hésitez donc pas à demander de télécharger une nouvelle version lorsque le nettoyage dure et que l'outil ne semble pas tout voir.

    + nouveau rapport hijackthis.

    ;) 
    14 Avril 2008 10:27:38

    voilà les rapports


    SDFix: Version 1.171
    Run by jojo on 14/04/2008 at 10:13

    Microsoft Windows XP [version 5.1.2600]
    Running From: C:\SDFix

    Checking Services :


    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting


    Checking Files :

    No Trojan Files Found




    Folder C:\DriverLoad - Removed


    Removing Temp Files

    ADS Check :



    Final Check :

    catchme 0.3.1351.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-04-14 10:19:29
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden services & system hive ...

    scanning hidden registry entries ...

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
    "TracesProcessed"=dword:000000af
    "TracesSuccessful"=dword:00000003

    scanning hidden files ...

    scan completed successfully
    hidden processes: 0
    hidden services: 0
    hidden files: 0


    Remaining Services :



    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe:*:Enabled:hpqnrs08.exe"
    "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
    "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
    "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
    "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

    Remaining Files :


    File Backups: - C:\SDFix\backups\backups.zip

    Files with Hidden Attributes :

    Mon 14 Jan 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP145\A0023445.sys"
    Fri 18 Jan 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP146\A0023468.sys"
    Sat 19 Jan 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP147\A0023502.sys"
    Sun 20 Jan 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP149\A0023537.sys"
    Tue 22 Jan 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP152\A0023570.sys"
    Sat 26 Jan 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP155\A0024572.sys"
    Mon 28 Jan 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP155\A0024588.sys"
    Tue 29 Jan 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP156\A0024608.sys"
    Wed 30 Jan 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP157\A0024626.sys"
    Mon 4 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP157\A0024644.sys"
    Mon 4 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP159\A0024691.sys"
    Thu 7 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP160\A0024723.sys"
    Sat 9 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP160\A0025725.sys"
    Sat 9 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP161\A0025746.sys"
    Mon 11 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP161\A0026748.sys"
    Mon 11 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP162\A0026764.sys"
    Tue 12 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP162\A0026780.sys"
    Tue 12 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP162\A0026793.sys"
    Wed 13 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP164\A0026863.sys"
    Fri 15 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP165\A0026883.sys"
    Fri 15 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP165\A0026906.sys"
    Sun 17 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP166\A0026921.sys"
    Sun 17 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP166\A0026947.sys"
    Mon 18 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP167\A0026962.sys"
    Tue 19 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP168\A0026986.sys"
    Wed 20 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP169\A0027002.sys"
    Fri 22 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP169\A0027015.sys"
    Fri 22 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP170\A0027033.sys"
    Sat 23 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP171\A0027051.sys"
    Thu 28 Feb 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP171\A0027065.sys"
    Tue 4 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP171\A0027080.sys"
    Tue 11 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP172\A0027093.sys"
    Wed 12 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP174\A0027128.sys"
    Thu 13 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP174\A0027141.sys"
    Fri 14 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP174\A0027154.sys"
    Fri 14 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP175\A0027178.sys"
    Sat 15 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP175\A0027193.sys"
    Sat 15 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP176\A0027225.sys"
    Sun 16 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP176\A0027271.sys"
    Mon 17 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP177\A0027295.sys"
    Mon 17 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP177\A0027308.sys"
    Tue 18 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP178\A0027325.sys"
    Wed 19 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP179\A0027343.sys"
    Sat 22 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP180\A0027359.sys"
    Sat 22 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP181\A0027428.sys"
    Mon 24 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP182\A0027452.sys"
    Mon 24 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP182\A0027465.sys"
    Tue 25 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP183\A0027495.sys"
    Wed 26 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027682.sys"
    Wed 26 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027701.sys"
    Thu 27 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027717.sys"
    Thu 27 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027766.sys"
    Fri 28 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027780.sys"
    Fri 28 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027796.sys"
    Fri 28 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027822.sys"
    Sat 29 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027844.sys"
    Sat 29 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027856.sys"
    Sat 29 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027875.sys"
    Sun 30 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0027887.sys"
    Sun 30 Mar 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP185\A0028891.sys"
    Tue 1 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP186\A0028918.sys"
    Tue 1 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP186\A0028935.sys"
    Wed 2 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP186\A0028951.sys"
    Wed 2 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP186\A0029951.sys"
    Wed 2 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP187\A0030133.sys"
    Thu 3 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP188\A0030155.sys"
    Fri 4 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP189\A0030178.sys"
    Sat 5 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP190\A0030194.sys"
    Sun 6 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP190\A0030215.sys"
    Sun 6 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP190\A0030254.sys"
    Mon 7 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP191\A0030451.sys"
    Tue 8 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP191\A0030463.sys"
    Tue 8 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP191\A0030473.sys"
    Tue 8 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP192\A0030499.sys"
    Wed 9 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP193\A0030522.sys"
    Thu 10 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP193\A0030541.sys"
    Fri 11 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP194\A0030566.sys"
    Sun 13 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP194\A0031581.sys"
    Sun 13 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP196\A0031634.sys"
    Mon 14 Apr 2008 72 A..H. --- "C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP197\A0031758.sys"
    Fri 5 Oct 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
    Mon 14 Apr 2008 72 A..H. --- "C:\Program Files\Common Files\X10\Common\x10prod.sys"

    Finished!


    et le rapport hijackthis

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:25:56, on 14/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\jojo\Local Settings\Temporary Internet Files\Content.IE5\IFKL6HKF\HiJackThis[1].exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

    --
    End of file - 8999 bytes

    merci, à plus tard
    14 Avril 2008 11:11:03

    :hello: 

    1) Affiche les fichiers et dossiers cachés …
    Pour ce faire, tu vas dans un dossier, par ex. "Mes Images".
    Ensuite, clique sur > Outils > Options des dossiers ...
    clique sur l' onglet « Affichage » et ...
    coche ---> Afficher les fichiers et dossiers cachés
    décoche > Masquer les extensions des fichiers dont le type est connu
    décoche > Masquer les fichiers protégés du système d' exploitation (recommandé).
    « Appliquer » et « OK ».

    2) Désactive toute protection résidente ( antivirus…) !
    Déconnecte-toi d’internet, ferme tous les programmes en cours et laisse combofix travailler : ne fais donc pas autre chose en même temps !


    Télécharge Combofix de sUBs
    Sauvegarde le sur ton bureau et pas ailleurs !
    Redémarre en mode sans échecs : aide ici >>>
    http://forum.telecharger.01net.com/telecharger/virus_et...
    /!\ Ne jamais redémarrer en mode sans échec via msconfig ! /!\

    Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider, laisse toi guider.
    Attends que combofix ait terminé, un rapport sera créé. Poste le rapport. Il se trouve ici : C:\Combofix.txt

    3) Copie/colle un nouveau rapport HiJackThis avec.

    ;) 
    14 Avril 2008 11:42:19

    voilà pour le premier

    ComboFix 08-04-13.3 - jojo 2008-04-14 11:26:12.1 - NTFSx86 MINIMAL
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.822 [GMT 2:00]
    Endroit: C:\Documents and Settings\jojo\Bureau\ComboFix.exe

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\Administrateur\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
    C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-14 to 2008-04-14 ))))))))))))))))))))))))))))))))))))
    .

    2008-04-14 10:02 . 2008-04-14 10:02 <REP> d-------- C:\WINDOWS\ERUNT
    2008-04-14 09:57 . 2008-04-14 10:22 <REP> d-------- C:\SDFix
    2008-04-14 09:33 . 2008-04-14 09:35 1,374 --a------ C:\WINDOWS\imsins.BAK
    2008-04-14 01:17 . 2008-04-14 01:17 244 --ah----- C:\sqmnoopt08.sqm
    2008-04-14 01:17 . 2008-04-14 01:17 232 --ah----- C:\sqmdata08.sqm
    2008-04-13 22:03 . 2008-04-13 22:03 <REP> d-------- C:\Deckard
    2008-04-13 20:54 . 2008-04-13 20:54 244 --ah----- C:\sqmnoopt07.sqm
    2008-04-13 20:54 . 2008-04-13 20:54 232 --ah----- C:\sqmdata07.sqm
    2008-04-12 01:06 . 2008-04-12 01:06 244 --ah----- C:\sqmnoopt06.sqm
    2008-04-12 01:06 . 2008-04-12 01:06 232 --ah----- C:\sqmdata06.sqm
    2008-04-11 00:05 . 2008-04-11 00:05 244 --ah----- C:\sqmnoopt05.sqm
    2008-04-11 00:05 . 2008-04-11 00:05 232 --ah----- C:\sqmdata05.sqm
    2008-04-09 23:56 . 2008-04-09 23:56 244 --ah----- C:\sqmnoopt04.sqm
    2008-04-09 23:56 . 2008-04-09 23:56 232 --ah----- C:\sqmdata04.sqm
    2008-04-08 23:37 . 2008-04-08 23:37 244 --ah----- C:\sqmnoopt03.sqm
    2008-04-08 23:37 . 2008-04-08 23:37 232 --ah----- C:\sqmdata03.sqm
    2008-04-06 19:51 . 2008-04-06 19:51 244 --ah----- C:\sqmnoopt02.sqm
    2008-04-06 19:51 . 2008-04-06 19:51 232 --ah----- C:\sqmdata02.sqm
    2008-04-03 01:43 . 2008-04-03 01:43 244 --ah----- C:\sqmnoopt01.sqm
    2008-04-03 01:43 . 2008-04-03 01:43 232 --ah----- C:\sqmdata01.sqm
    2008-04-03 00:59 . 2008-04-03 00:59 <REP> d-------- C:\Program Files\CCleaner
    2008-03-27 22:44 . 2008-03-27 22:45 <REP> d-------- C:\Documents and Settings\jojo\Application Data\MailFrontier
    2008-03-26 20:13 . 2008-03-26 20:13 <REP> d-------- C:\WINDOWS\system32\AlertModule
    2008-03-26 20:13 . 2004-08-23 15:50 32,768 --a------ C:\WINDOWS\system32\WooDial2000.dll
    2008-03-26 20:12 . 2003-08-04 15:22 94,208 --a------ C:\WINDOWS\system32\W32n50.dll
    2008-03-26 20:12 . 2004-08-23 15:49 40,960 --a------ C:\WINDOWS\system32\FTRTSVC.exe
    2008-03-26 20:12 . 2005-10-06 15:55 36,864 --a------ C:\WINDOWS\system32\IfHelper.dll
    2008-03-26 20:12 . 2003-08-04 15:22 16,128 --------- C:\WINDOWS\system32\PCANDIS5.SYS
    2008-03-26 20:10 . 2008-04-14 11:21 <REP> d-------- C:\Program Files\Wanadoo
    2008-03-26 19:51 . 2008-03-26 19:51 <REP> d-------- C:\Program Files\SAGEM
    2008-03-24 18:50 . 2008-03-24 18:50 <REP> d-------- C:\Program Files\Securitoo
    2008-03-16 03:44 . 2008-04-14 01:15 <REP> d-------- C:\Program Files\Incomplete
    2008-03-16 03:43 . 2008-04-13 22:30 <REP> d-------- C:\Program Files\LimeWire

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-04-13 21:30 --------- d-----w C:\Documents and Settings\jojo\Application Data\LimeWire
    2008-04-13 14:48 --------- d-----w C:\Program Files\Everest Poker
    2008-03-26 17:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-05-09 00:23 118 ----a-w C:\Documents and Settings\jojo\Application Data\wklnhst.dat
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 17:08 65536]
    "DriverLoad"="" []
    "DriverCheck"="" []
    "SystemDriverLoad"="" []
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15:00 15360]
    "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 15:50 122880]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:34 64512]
    "nwiz"="nwiz.exe" [2006-02-16 16:34 1519616 C:\WINDOWS\system32\nwiz.exe]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-02-16 16:34 7557120]
    "High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2005-12-29 23:21 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 01:02 761948]
    "Toshiba Hotkey Utility"="C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" [2006-03-15 19:12 1769472]
    "NDSTray.exe"="NDSTray.exe" []
    "SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 10:24 118784]
    "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 06:20 122940]
    "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 12:37 667718]
    "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 11:41 602182]
    "CFSServ.exe"="CFSServ.exe" []
    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 15:00 79224]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02 919280]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
    "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 15:49 20480]
    "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 17:55 32768]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 15:00 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
    "C:\\Program Files\\Messenger\\msmsgs.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=

    R3 BoiHwsetup;Access 32bits INT15 routine;C:\WINDOWS\system32\drivers\BoiHwSetup.sys [2005-06-11 06:42]
    R3 qkbfiltr;Quanta HotKey Keyboard Filter Driver;C:\WINDOWS\system32\drivers\qkbfiltr.sys [2006-01-12 17:21]
    R3 qmofiltr;Quanta HotKey Mouse Filter Driver;C:\WINDOWS\system32\drivers\qmofiltr.sys [2005-05-05 15:27]
    R3 X10Hid;X10 Hid Device;C:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 11:45]
    S3 o1394bul;o1394bul;C:\DOCUME~1\jojo\LOCALS~1\Temp\o1394bul.sys []
    S3 SMCB000;SMSC CIR HID Miniport Device Driver;C:\WINDOWS\system32\DRIVERS\hidsmsc.sys [2006-01-17 17:30]
    S3 StickCap;Digital TV DVB-T USB Stick adapter service;C:\WINDOWS\system32\Drivers\stickcap.sys [2005-06-21 06:33]
    S3 stickload;Digital TV stick firmware loader service;C:\WINDOWS\system32\DRIVERS\stickload.sys [2005-06-21 07:23]
    S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-09-09 15:47]
    S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]

    .
    Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
    "2008-01-14 21:30:21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    .
    **************************************************************************

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-04-14 11:33:11
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
    C:\WINDOWS\ehome\ehrecvr.exe
    C:\WINDOWS\ehome\ehSched.exe
    C:\WINDOWS\system32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\PROGRA~1\COMMON~1\X10\Common\X10nets.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehmsas.exe
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\Program Files\Toshiba\ConfigFree\NDSTray.exe
    C:\Program Files\Toshiba\ConfigFree\CFSServ.exe
    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wscntfy.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-04-14 11:36:09 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-04-14 09:36:06

    Pre-Run: 66,831,912,960 octets libres
    Post-Run: 65,671,856,128 octets libres
    .
    2008-04-14 07:35:49 --- E O F ---


    et pour le deuxième


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:41:36, on 14/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
    C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
    C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSServ.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\jojo\Local Settings\Temporary Internet Files\Content.IE5\C3076LKV\HiJackThis[1].exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
    O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [CFSServ.exe] CFSServ.exe -NoClient
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

    --
    End of file - 9083 bytes


    14 Avril 2008 12:20:12

    Re,

    Rends toi sur ce lien : Virus Total
  • Clique sur Parcourir
  • Rends toi jusque sur ce fichier si tu le trouves :

    C:\WINDOWS\system32\FTRTSVC.exe
    C:\WINDOWS\system32\IfHelper.dll
    C:\WINDOWS\system32\DRIVERS\stickload.sys

  • Clique sur Envoyer le fichier et laisse travailler tant que "Situation actuelle : en cours d'analyse" est affiché.
  • Il est possible que le fichier soit mis en file d'attente en raison d'un grand nombre de demandes d'analyses. En ce cas, il te faudra patienter sans actualiser la page.
  • Lorsque l'analyse est terminée ("Situation actuelle: terminé"), clique sur Formaté
  • Une nouvelle fenêtre de ton navigateur va apparaître
  • Clique alors sur cette image :
  • Fais un clic droit sur la page, et choisis Sélectionner tout, puis copier
  • Enfin colle le résultat dans ta prochaine réponse.
    Note : Peu importe le résultat, il est important de me communiquer le résultat de toute l'analyse.
    Il est possible que tes outils de sécurité réagissent à l'envoi du fichier, en ce cas il te faudra ignorer les alertes.

    ;) 
    14 Avril 2008 12:52:37


    Hello, voilà les rapports pour les 3 fichiers


    Fichier FTRTSVC.exe reçu le 2008.04.14 12:27:10 (CET)Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.4.12.0 2008.04.14 -
    AntiVir 7.6.0.85 2008.04.14 -
    Authentium 4.93.8 2008.04.13 -
    Avast 4.8.1169.0 2008.04.14 -
    AVG 7.5.0.516 2008.04.13 -
    BitDefender 7.2 2008.04.14 -
    CAT-QuickHeal 9.50 2008.04.12 -
    ClamAV 0.92.1 2008.04.14 -
    DrWeb 4.44.0.09170 2008.04.14 -
    eSafe 7.0.15.0 2008.04.09 -
    eTrust-Vet 31.3.5697 2008.04.14 -
    Ewido 4.0 2008.04.13 -
    F-Prot 4.4.2.54 2008.04.14 -
    F-Secure 6.70.13260.0 2008.04.14 -
    FileAdvisor 1 2008.04.14 -
    Fortinet 3.14.0.0 2008.04.14 -
    Ikarus T3.1.1.26 2008.04.14 -
    Kaspersky 7.0.0.125 2008.04.14 -
    McAfee 5272 2008.04.11 -
    Microsoft 1.3408 2008.04.14 -
    NOD32v2 3023 2008.04.14 -
    Norman 5.80.02 2008.04.12 -
    Panda 9.0.0.4 2008.04.13 -
    Prevx1 V2 2008.04.14 -
    Rising 20.39.62.00 2008.04.13 -
    Sophos 4.28.0 2008.04.14 -
    Sunbelt 3.0.1041.0 2008.04.12 -
    Symantec 10 2008.04.14 -
    TheHacker 6.2.92.276 2008.04.12 -
    VBA32 3.12.6.4 2008.04.14 -
    VirusBuster 4.3.26:9 2008.04.13 -
    Webwasher-Gateway 6.6.2 2008.04.14 -

    Information additionnelle
    File size: 40960 bytes
    MD5...: d1261099e03eee90976ea19002995b89
    SHA1..: a7f4ee1a57b198bfebac7afac0ec58472c710025
    SHA256: e3fedd3b96122418154d2b080e2b4c42ae3c0c2df3c0fd78f1493fe7f52ef489
    SHA512: dbab8b8c8592dea882561cc9ebb8b31a0e925b2ee667a9667ff9a7d45506f9df<BR>51547bc8ba8aba593d01832ee336852bc4f50805656d29b56264f74d15a51712
    PEiD..: Armadillo v1.71
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x404f42<BR>timedatestamp.....: 0x40a4b67d (Fri May 14 12:07:25 2004)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x45ee 0x5000 5.65 b31880dc74367b50032c334613207aaa<BR>.rdata 0x6000 0x17b4 0x2000 3.91 fdbc58a144b948f30c21331a7f38cdbc<BR>.data 0x8000 0x504 0x1000 1.77 8ce94bee74363bfcaf409b1bf3e83562<BR>.rsrc 0x9000 0xf60 0x1000 3.26 f62ab0f6aff7ab0fa07975aef6fe5024<BR><BR>( 5 imports ) <BR>> KERNEL32.dll: DeleteCriticalSection, InitializeCriticalSection, GetProcAddress, SetEvent, CreateEventA, EnterCriticalSection, CreateMutexA, GetLastError, CloseHandle, OpenMutexA, CreateNamedPipeA, LeaveCriticalSection, lstrlenA, SetLastError, LoadLibraryA, GetModuleFileNameA, lstrcmpiA, FormatMessageA, GetTickCount, Sleep, GetVersionExA, HeapAlloc, GetProcessHeap, HeapFree, ReadFile, WriteFile, GetStartupInfoA, ConnectNamedPipe, WaitForMultipleObjects, ResumeThread, ResetEvent, FlushFileBuffers, DisconnectNamedPipe, WaitForSingleObject, GetCommandLineA, GetModuleHandleA<BR>> ADVAPI32.dll: DeleteService, AddAccessAllowedAce, IsValidSid, GetLengthSid, AllocateAndInitializeSid, InitializeAcl, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, FreeSid, UnlockServiceDatabase, LockServiceDatabase, OpenServiceA, OpenSCManagerA, AddAccessDeniedAce, CreateServiceA, QueryServiceStatus, StartServiceA, ControlService, CloseServiceHandle, StartServiceCtrlDispatcherA, RegOpenKeyExA, RegCreateKeyExA, SetServiceStatus, RegisterServiceCtrlHandlerA, RegCloseKey, RegSetValueExA, RegDeleteValueA, RegDeleteKeyA, RegQueryValueExA<BR>> IfHelper.dll: _FindIfInfoByIpAddress@IfHelper@@QAEHKAAU_tSTRUCTIFINFO@@@Z, _Instance@IfHelper@@SAAAV1@XZ, __0RouteHelper@@QAE@PAU_tSTRUCTIFINFO@@@Z, _CanINice@RouteHelper@@QAE_NXZ, _NiceDefaultRoute@RouteHelper@@QAE_NXZ, _CanIUndo@RouteHelper@@QAE_NXZ, _Undo@RouteHelper@@QAE_NXZ, __0RouteHelper@@QAE@XZ, __1RouteHelper@@QAE@XZ<BR>> MFC42.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR>> MSVCRT.dll: _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp, __getmainargs, _acmdln, exit, _XcptFilter, _exit, __1type_info@@UAE@XZ, _onexit, __dllonexit, memset, _mbscmp, __CxxFrameHandler, _beginthreadex, __p___argc, __p___argv, _CxxThrowException, printf, atoi, _EH_prolog<BR><BR>( 0 exports ) <BR>

    Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.4.12.0 2008.04.14 -
    AntiVir 7.6.0.85 2008.04.14 -
    Authentium 4.93.8 2008.04.13 -
    Avast 4.8.1169.0 2008.04.14 -
    AVG 7.5.0.516 2008.04.13 -
    BitDefender 7.2 2008.04.14 -
    CAT-QuickHeal 9.50 2008.04.12 -
    ClamAV 0.92.1 2008.04.14 -
    DrWeb 4.44.0.09170 2008.04.14 -
    eSafe 7.0.15.0 2008.04.09 -
    eTrust-Vet 31.3.5697 2008.04.14 -
    Ewido 4.0 2008.04.13 -
    F-Prot 4.4.2.54 2008.04.14 -
    F-Secure 6.70.13260.0 2008.04.14 -
    FileAdvisor 1 2008.04.14 -
    Fortinet 3.14.0.0 2008.04.14 -
    Ikarus T3.1.1.26 2008.04.14 -
    Kaspersky 7.0.0.125 2008.04.14 -
    McAfee 5272 2008.04.11 -
    Microsoft 1.3408 2008.04.14 -
    NOD32v2 3023 2008.04.14 -
    Norman 5.80.02 2008.04.12 -
    Panda 9.0.0.4 2008.04.13 -
    Prevx1 V2 2008.04.14 -
    Rising 20.39.62.00 2008.04.13 -
    Sophos 4.28.0 2008.04.14 -
    Sunbelt 3.0.1041.0 2008.04.12 -
    Symantec 10 2008.04.14 -
    TheHacker 6.2.92.276 2008.04.12 -
    VBA32 3.12.6.4 2008.04.14 -
    VirusBuster 4.3.26:9 2008.04.13 -
    Webwasher-Gateway 6.6.2 2008.04.14 -

    Information additionnelle
    File size: 40960 bytes
    MD5...: d1261099e03eee90976ea19002995b89
    SHA1..: a7f4ee1a57b198bfebac7afac0ec58472c710025
    SHA256: e3fedd3b96122418154d2b080e2b4c42ae3c0c2df3c0fd78f1493fe7f52ef489
    SHA512: dbab8b8c8592dea882561cc9ebb8b31a0e925b2ee667a9667ff9a7d45506f9df<BR>51547bc8ba8aba593d01832ee336852bc4f50805656d29b56264f74d15a51712
    PEiD..: Armadillo v1.71
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x404f42<BR>timedatestamp.....: 0x40a4b67d (Fri May 14 12:07:25 2004)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 4 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x45ee 0x5000 5.65 b31880dc74367b50032c334613207aaa<BR>.rdata 0x6000 0x17b4 0x2000 3.91 fdbc58a144b948f30c21331a7f38cdbc<BR>.data 0x8000 0x504 0x1000 1.77 8ce94bee74363bfcaf409b1bf3e83562<BR>.rsrc 0x9000 0xf60 0x1000 3.26 f62ab0f6aff7ab0fa07975aef6fe5024<BR><BR>( 5 imports ) <BR>> KERNEL32.dll: DeleteCriticalSection, InitializeCriticalSection, GetProcAddress, SetEvent, CreateEventA, EnterCriticalSection, CreateMutexA, GetLastError, CloseHandle, OpenMutexA, CreateNamedPipeA, LeaveCriticalSection, lstrlenA, SetLastError, LoadLibraryA, GetModuleFileNameA, lstrcmpiA, FormatMessageA, GetTickCount, Sleep, GetVersionExA, HeapAlloc, GetProcessHeap, HeapFree, ReadFile, WriteFile, GetStartupInfoA, ConnectNamedPipe, WaitForMultipleObjects, ResumeThread, ResetEvent, FlushFileBuffers, DisconnectNamedPipe, WaitForSingleObject, GetCommandLineA, GetModuleHandleA<BR>> ADVAPI32.dll: DeleteService, AddAccessAllowedAce, IsValidSid, GetLengthSid, AllocateAndInitializeSid, InitializeAcl, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, FreeSid, UnlockServiceDatabase, LockServiceDatabase, OpenServiceA, OpenSCManagerA, AddAccessDeniedAce, CreateServiceA, QueryServiceStatus, StartServiceA, ControlService, CloseServiceHandle, StartServiceCtrlDispatcherA, RegOpenKeyExA, RegCreateKeyExA, SetServiceStatus, RegisterServiceCtrlHandlerA, RegCloseKey, RegSetValueExA, RegDeleteValueA, RegDeleteKeyA, RegQueryValueExA<BR>> IfHelper.dll: _FindIfInfoByIpAddress@IfHelper@@QAEHKAAU_tSTRUCTIFINFO@@@Z, _Instance@IfHelper@@SAAAV1@XZ, __0RouteHelper@@QAE@PAU_tSTRUCTIFINFO@@@Z, _CanINice@RouteHelper@@QAE_NXZ, _NiceDefaultRoute@RouteHelper@@QAE_NXZ, _CanIUndo@RouteHelper@@QAE_NXZ, _Undo@RouteHelper@@QAE_NXZ, __0RouteHelper@@QAE@XZ, __1RouteHelper@@QAE@XZ<BR>> MFC42.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -<BR>> MSVCRT.dll: _initterm, __setusermatherr, _adjust_fdiv, __p__commode, __p__fmode, __set_app_type, _except_handler3, _controlfp, __getmainargs, _acmdln, exit, _XcptFilter, _exit, __1type_info@@UAE@XZ, _onexit, __dllonexit, memset, _mbscmp, __CxxFrameHandler, _beginthreadex, __p___argc, __p___argv, _CxxThrowException, printf, atoi, _EH_prolog<BR><BR>( 0 exports ) <BR>



    Fichier IfHelper.dll reçu le 2008.04.14 12:40:45 (CET)Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.4.12.0 2008.04.14 -
    AntiVir 7.6.0.85 2008.04.14 -
    Authentium 4.93.8 2008.04.13 -
    Avast 4.8.1169.0 2008.04.14 -
    AVG 7.5.0.516 2008.04.13 -
    BitDefender 7.2 2008.04.14 -
    CAT-QuickHeal 9.50 2008.04.12 -
    ClamAV 0.92.1 2008.04.14 -
    DrWeb 4.44.0.09170 2008.04.14 -
    eSafe 7.0.15.0 2008.04.09 -
    eTrust-Vet 31.3.5697 2008.04.14 -
    Ewido 4.0 2008.04.13 -
    F-Prot 4.4.2.54 2008.04.14 -
    F-Secure 6.70.13260.0 2008.04.14 -
    FileAdvisor 1 2008.04.14 -
    Fortinet 3.14.0.0 2008.04.14 -
    Ikarus T3.1.1.26 2008.04.14 -
    Kaspersky 7.0.0.125 2008.04.14 -
    McAfee 5272 2008.04.11 -
    Microsoft 1.3408 2008.04.14 -
    NOD32v2 3023 2008.04.14 -
    Norman 5.80.02 2008.04.12 -
    Panda 9.0.0.4 2008.04.13 -
    Prevx1 V2 2008.04.14 -
    Rising 20.39.62.00 2008.04.13 -
    Sophos 4.28.0 2008.04.14 -
    Sunbelt 3.0.1041.0 2008.04.12 -
    Symantec 10 2008.04.14 -
    TheHacker 6.2.92.276 2008.04.12 -
    VBA32 3.12.6.4 2008.04.14 -
    VirusBuster 4.3.26:9 2008.04.13 -
    Webwasher-Gateway 6.6.2 2008.04.14 -

    Information additionnelle
    File size: 36864 bytes
    MD5...: a690ae7f4418401815ce3d73d60b8c6f
    SHA1..: d118f3d3ddaf98c19ab5a0832405db741fe1357b
    SHA256: cd2a6410f01db4b0502802649469e705eb4b2cb76c30f37775c6df6235ca26b1
    SHA512: b8b7388fc95f49c46cc69514dfc58b9b5ce11d032c1dde6dc249702e0127c0a7<BR>401a89099af37c7a86341f59f496e261947524ca006af002786d705c4c167f22
    PEiD..: Armadillo v1.xx - v2.xx
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x10003b8b<BR>timedatestamp.....: 0x43451eb9 (Thu Oct 06 12:55:21 2005)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 5 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x2c72 0x3000 5.66 ade365add2bd5fee9566bfd7195c556b<BR>.rdata 0x4000 0x1365 0x2000 3.98 4ea5ed829486879cc8ca0ddf69e8fda8<BR>.data 0x6000 0x1c8 0x1000 0.68 6f41e2af36794fa34490e930f67d16f1<BR>.rsrc 0x7000 0x3d8 0x1000 1.01 792a666eddd096d1378fdc2a75b54435<BR>.reloc 0x8000 0x1a4 0x1000 0.86 b2071f3d5e0664a1e4f5f187ffb5a46d<BR><BR>( 2 imports ) <BR>> MSVCRT.dll: _adjust_fdiv, malloc, _initterm, free, _onexit, __dllonexit, __CxxFrameHandler, __3@YAXPAX@Z, _endthreadex, __2@YAPAXI@Z, _beginthreadex<BR>> KERNEL32.dll: CreateEventA, DisableThreadLibraryCalls, GlobalFree, GlobalAlloc, SetLastError, GetTickCount, GetProcAddress, LoadLibraryA, ResumeThread, WaitForSingleObject, SetEvent, CloseHandle<BR><BR>( 72 exports ) <BR>__0DhcpIfHelper@@QAE@PAU_tSTRUCTIFINFO@@@Z, __0DhcpIfHelper@@QAE@PAU_tSTRUCTIFINFO_Ex@@@Z, __0IfFuncLoad@@QAE@PBD00@Z, __0IfHelper@@AAE@XZ, __0RouteHelper@@QAE@PAU_tSTRUCTIFINFO@@@Z, __0RouteHelper@@QAE@PAU_tSTRUCTIFINFO_Ex@@@Z, __0RouteHelper@@QAE@XZ, __1DhcpIfHelper@@QAE@XZ, __1IfFuncLoad@@QAE@XZ, __1IfHelper@@QAE@XZ, __1RouteHelper@@QAE@XZ, __4DhcpIfHelper@@QAEAAV0@ABV0@@Z, __4IfFuncLoad@@QAEAAV0@ABV0@@Z, __4IfHelper@@QAEAAV0@ABV0@@Z, __4RouteHelper@@QAEAAV0@ABV0@@Z, _AsyncReleaseDHCP@DhcpIfHelper@@QAE_NXZ, _AsyncRenewDHCP@DhcpIfHelper@@QAE_NXZ, _CanINice@RouteHelper@@QAE_NXZ, _CanIUndo@RouteHelper@@QAE_NXZ, _FindAdapterNames@IfHelper@@AAEXPAU_tSTRUCTIFINFO_Ex@@II@Z, _FindDefaultGateWays@IfHelper@@AAEXPAU_tSTRUCTIFINFO_Ex@@II@Z, _FindIPAdresses@IfHelper@@AAEXPAU_tSTRUCTIFINFO_Ex@@II@Z, _FindIfInfoByIpAddress@IfHelper@@QAEHKAAU_tSTRUCTIFINFO@@@Z, _FindIfInfoExByIpAddress@IfHelper@@QAEHKAAU_tSTRUCTIFINFO_Ex@@AAI@Z, _FindInterfaces@IfHelper@@AAEHPAU_tSTRUCTIFINFO_Ex@@IAAI@Z, _GetIfTable@IfFuncLoad@@QAEKPAU_MIB_IFTABLE@@PAKH@Z, _GetInterfaceInfo@IfFuncLoad@@QAEKPAU_IP_INTERFACE_INFO@@PAK@Z, _GetIpAddrTable@IfFuncLoad@@QAEKPAU_MIB_IPADDRTABLE@@PAKH@Z, _GetIpForwardTable@IfFuncLoad@@QAEKPAU_MIB_IPFORWARDTABLE@@PAKH@Z, _GetIpInterfaces@IfHelper@@QAEHPAU_tSTRUCTIFINFO@@AAI@Z, _GetIpInterfacesEx@IfHelper@@QAEHPAU_tSTRUCTIFINFO_Ex@@AAI1@Z, _GetRTTAndHopCount@IfFuncLoad@@QAEHKPAKK0@Z, _IcmpCloseHandle@IfFuncLoad@@QAEHPAX@Z, _IcmpCreateFile@IfFuncLoad@@QAEPAXXZ, _IcmpSendEcho@IfFuncLoad@@QAEKPAXK0GPAUip_option_information@@0KK@Z, _IfInfo_Ex_2_IfInfo@IfHelper@@SAXAAU_tSTRUCTIFINFO@@ABU_tSTRUCTIFINFO_Ex@@@Z, _Init@IfFuncLoad@@QAEHKPAPAXPAUAsnObjectIdentifier@@@Z, _InitEx@IfFuncLoad@@QAEHPAUAsnObjectIdentifier@@@Z, _Instance@IfHelper@@SAAAV1@XZ, _IpReleaseAddress@IfFuncLoad@@QAEKPAU_IP_ADAPTER_INDEX_MAP@@@Z, _IpReleaseAddress@IfHelper@@QAEHPAU_IP_ADAPTER_INDEX_MAP@@@Z, _IpRenewAddress@IfFuncLoad@@QAEKPAU_IP_ADAPTER_INDEX_MAP@@@Z, _IpRenewAddress@IfHelper@@QAEHPAU_IP_ADAPTER_INDEX_MAP@@@Z, _NiceDefaultRoute@RouteHelper@@QAE_NXZ, _Query@IfFuncLoad@@QAEHEPAUSnmpVarBindList@@PAJ1@Z, _SetIpForwardEntry@IfFuncLoad@@QAEKPAU_MIB_IPFORWARDROW@@@Z, _SyncReleaseDHCP@DhcpIfHelper@@QAE_NXZ, _Trap@IfFuncLoad@@QAEHPAUAsnObjectIdentifier@@PAJ1PAKPAUSnmpVarBindList@@@Z, _Undo@RouteHelper@@QAE_NXZ, __AsyncReleaseDHCP@DhcpIfHelper@@CGIPAX@Z, __AsyncRenewDHCP@DhcpIfHelper@@CGIPAX@Z, __Init@RouteHelper@@AAEXPAU_tSTRUCTIFINFO@@@Z, _ms_Close@IfFuncLoad@@0P6GXXZA, _ms_GetIfTable@IfFuncLoad@@0P6GKPAU_MIB_IFTABLE@@PAKH@ZA, _ms_GetInterfaceInfo@IfFuncLoad@@0P6GKPAU_IP_INTERFACE_INFO@@PAK@ZA, _ms_GetIpAddrTable@IfFuncLoad@@0P6GKPAU_MIB_IPADDRTABLE@@PAKH@ZA, _ms_GetIpForwardTable@IfFuncLoad@@0P6GKPAU_MIB_IPFORWARDTABLE@@PAKH@ZA, _ms_GetRTTAndHopCount@IfFuncLoad@@0P6GHKPAKK0@ZA, _ms_IcmpCloseHandle@IfFuncLoad@@0P6GHPAX@ZA, _ms_IcmpCreateFile@IfFuncLoad@@0P6GPAXXZA, _ms_IcmpSendEcho@IfFuncLoad@@0P6GKPAXK0GPAUip_option_information@@0KK@ZA, _ms_Init@IfFuncLoad@@0P6GHKPAPAXPAUAsnObjectIdentifier@@@ZA, _ms_InitEx@IfFuncLoad@@0P6GHPAUAsnObjectIdentifier@@@ZA, _ms_IpReleaseAddress@IfFuncLoad@@0P6GKPAU_IP_ADAPTER_INDEX_MAP@@@ZA, _ms_IpRenewAddress@IfFuncLoad@@0P6GKPAU_IP_ADAPTER_INDEX_MAP@@@ZA, _ms_Query@IfFuncLoad@@0P6GHEPAUSnmpVarBindList@@PAJ1@ZA, _ms_SetIpForwardEntry@IfFuncLoad@@0P6GKPAU_MIB_IPFORWARDROW@@@ZA, _ms_Trap@IfFuncLoad@@0P6GHPAUAsnObjectIdentifier@@PAJ1PAKPAUSnmpVarBindList@@@ZA, _ms_bInited@IfFuncLoad@@0HA, _ms_hInstICMP@IfFuncLoad@@0PAUHINSTANCE__@@A, _ms_hInstIpHlp@IfFuncLoad@@0PAUHINSTANCE__@@A, _ms_hInstMIB@IfFuncLoad@@0PAUHINSTANCE__@@A<BR>

    Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.4.12.0 2008.04.14 -
    AntiVir 7.6.0.85 2008.04.14 -
    Authentium 4.93.8 2008.04.13 -
    Avast 4.8.1169.0 2008.04.14 -
    AVG 7.5.0.516 2008.04.13 -
    BitDefender 7.2 2008.04.14 -
    CAT-QuickHeal 9.50 2008.04.12 -
    ClamAV 0.92.1 2008.04.14 -
    DrWeb 4.44.0.09170 2008.04.14 -
    eSafe 7.0.15.0 2008.04.09 -
    eTrust-Vet 31.3.5697 2008.04.14 -
    Ewido 4.0 2008.04.13 -
    F-Prot 4.4.2.54 2008.04.14 -
    F-Secure 6.70.13260.0 2008.04.14 -
    FileAdvisor 1 2008.04.14 -
    Fortinet 3.14.0.0 2008.04.14 -
    Ikarus T3.1.1.26 2008.04.14 -
    Kaspersky 7.0.0.125 2008.04.14 -
    McAfee 5272 2008.04.11 -
    Microsoft 1.3408 2008.04.14 -
    NOD32v2 3023 2008.04.14 -
    Norman 5.80.02 2008.04.12 -
    Panda 9.0.0.4 2008.04.13 -
    Prevx1 V2 2008.04.14 -
    Rising 20.39.62.00 2008.04.13 -
    Sophos 4.28.0 2008.04.14 -
    Sunbelt 3.0.1041.0 2008.04.12 -
    Symantec 10 2008.04.14 -
    TheHacker 6.2.92.276 2008.04.12 -
    VBA32 3.12.6.4 2008.04.14 -
    VirusBuster 4.3.26:9 2008.04.13 -
    Webwasher-Gateway 6.6.2 2008.04.14 -

    Information additionnelle
    File size: 36864 bytes
    MD5...: a690ae7f4418401815ce3d73d60b8c6f
    SHA1..: d118f3d3ddaf98c19ab5a0832405db741fe1357b
    SHA256: cd2a6410f01db4b0502802649469e705eb4b2cb76c30f37775c6df6235ca26b1
    SHA512: b8b7388fc95f49c46cc69514dfc58b9b5ce11d032c1dde6dc249702e0127c0a7<BR>401a89099af37c7a86341f59f496e261947524ca006af002786d705c4c167f22
    PEiD..: Armadillo v1.xx - v2.xx
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x10003b8b<BR>timedatestamp.....: 0x43451eb9 (Thu Oct 06 12:55:21 2005)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 5 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x1000 0x2c72 0x3000 5.66 ade365add2bd5fee9566bfd7195c556b<BR>.rdata 0x4000 0x1365 0x2000 3.98 4ea5ed829486879cc8ca0ddf69e8fda8<BR>.data 0x6000 0x1c8 0x1000 0.68 6f41e2af36794fa34490e930f67d16f1<BR>.rsrc 0x7000 0x3d8 0x1000 1.01 792a666eddd096d1378fdc2a75b54435<BR>.reloc 0x8000 0x1a4 0x1000 0.86 b2071f3d5e0664a1e4f5f187ffb5a46d<BR><BR>( 2 imports ) <BR>> MSVCRT.dll: _adjust_fdiv, malloc, _initterm, free, _onexit, __dllonexit, __CxxFrameHandler, __3@YAXPAX@Z, _endthreadex, __2@YAPAXI@Z, _beginthreadex<BR>> KERNEL32.dll: CreateEventA, DisableThreadLibraryCalls, GlobalFree, GlobalAlloc, SetLastError, GetTickCount, GetProcAddress, LoadLibraryA, ResumeThread, WaitForSingleObject, SetEvent, CloseHandle<BR><BR>( 72 exports ) <BR>__0DhcpIfHelper@@QAE@PAU_tSTRUCTIFINFO@@@Z, __0DhcpIfHelper@@QAE@PAU_tSTRUCTIFINFO_Ex@@@Z, __0IfFuncLoad@@QAE@PBD00@Z, __0IfHelper@@AAE@XZ, __0RouteHelper@@QAE@PAU_tSTRUCTIFINFO@@@Z, __0RouteHelper@@QAE@PAU_tSTRUCTIFINFO_Ex@@@Z, __0RouteHelper@@QAE@XZ, __1DhcpIfHelper@@QAE@XZ, __1IfFuncLoad@@QAE@XZ, __1IfHelper@@QAE@XZ, __1RouteHelper@@QAE@XZ, __4DhcpIfHelper@@QAEAAV0@ABV0@@Z, __4IfFuncLoad@@QAEAAV0@ABV0@@Z, __4IfHelper@@QAEAAV0@ABV0@@Z, __4RouteHelper@@QAEAAV0@ABV0@@Z, _AsyncReleaseDHCP@DhcpIfHelper@@QAE_NXZ, _AsyncRenewDHCP@DhcpIfHelper@@QAE_NXZ, _CanINice@RouteHelper@@QAE_NXZ, _CanIUndo@RouteHelper@@QAE_NXZ, _FindAdapterNames@IfHelper@@AAEXPAU_tSTRUCTIFINFO_Ex@@II@Z, _FindDefaultGateWays@IfHelper@@AAEXPAU_tSTRUCTIFINFO_Ex@@II@Z, _FindIPAdresses@IfHelper@@AAEXPAU_tSTRUCTIFINFO_Ex@@II@Z, _FindIfInfoByIpAddress@IfHelper@@QAEHKAAU_tSTRUCTIFINFO@@@Z, _FindIfInfoExByIpAddress@IfHelper@@QAEHKAAU_tSTRUCTIFINFO_Ex@@AAI@Z, _FindInterfaces@IfHelper@@AAEHPAU_tSTRUCTIFINFO_Ex@@IAAI@Z, _GetIfTable@IfFuncLoad@@QAEKPAU_MIB_IFTABLE@@PAKH@Z, _GetInterfaceInfo@IfFuncLoad@@QAEKPAU_IP_INTERFACE_INFO@@PAK@Z, _GetIpAddrTable@IfFuncLoad@@QAEKPAU_MIB_IPADDRTABLE@@PAKH@Z, _GetIpForwardTable@IfFuncLoad@@QAEKPAU_MIB_IPFORWARDTABLE@@PAKH@Z, _GetIpInterfaces@IfHelper@@QAEHPAU_tSTRUCTIFINFO@@AAI@Z, _GetIpInterfacesEx@IfHelper@@QAEHPAU_tSTRUCTIFINFO_Ex@@AAI1@Z, _GetRTTAndHopCount@IfFuncLoad@@QAEHKPAKK0@Z, _IcmpCloseHandle@IfFuncLoad@@QAEHPAX@Z, _IcmpCreateFile@IfFuncLoad@@QAEPAXXZ, _IcmpSendEcho@IfFuncLoad@@QAEKPAXK0GPAUip_option_information@@0KK@Z, _IfInfo_Ex_2_IfInfo@IfHelper@@SAXAAU_tSTRUCTIFINFO@@ABU_tSTRUCTIFINFO_Ex@@@Z, _Init@IfFuncLoad@@QAEHKPAPAXPAUAsnObjectIdentifier@@@Z, _InitEx@IfFuncLoad@@QAEHPAUAsnObjectIdentifier@@@Z, _Instance@IfHelper@@SAAAV1@XZ, _IpReleaseAddress@IfFuncLoad@@QAEKPAU_IP_ADAPTER_INDEX_MAP@@@Z, _IpReleaseAddress@IfHelper@@QAEHPAU_IP_ADAPTER_INDEX_MAP@@@Z, _IpRenewAddress@IfFuncLoad@@QAEKPAU_IP_ADAPTER_INDEX_MAP@@@Z, _IpRenewAddress@IfHelper@@QAEHPAU_IP_ADAPTER_INDEX_MAP@@@Z, _NiceDefaultRoute@RouteHelper@@QAE_NXZ, _Query@IfFuncLoad@@QAEHEPAUSnmpVarBindList@@PAJ1@Z, _SetIpForwardEntry@IfFuncLoad@@QAEKPAU_MIB_IPFORWARDROW@@@Z, _SyncReleaseDHCP@DhcpIfHelper@@QAE_NXZ, _Trap@IfFuncLoad@@QAEHPAUAsnObjectIdentifier@@PAJ1PAKPAUSnmpVarBindList@@@Z, _Undo@RouteHelper@@QAE_NXZ, __AsyncReleaseDHCP@DhcpIfHelper@@CGIPAX@Z, __AsyncRenewDHCP@DhcpIfHelper@@CGIPAX@Z, __Init@RouteHelper@@AAEXPAU_tSTRUCTIFINFO@@@Z, _ms_Close@IfFuncLoad@@0P6GXXZA, _ms_GetIfTable@IfFuncLoad@@0P6GKPAU_MIB_IFTABLE@@PAKH@ZA, _ms_GetInterfaceInfo@IfFuncLoad@@0P6GKPAU_IP_INTERFACE_INFO@@PAK@ZA, _ms_GetIpAddrTable@IfFuncLoad@@0P6GKPAU_MIB_IPADDRTABLE@@PAKH@ZA, _ms_GetIpForwardTable@IfFuncLoad@@0P6GKPAU_MIB_IPFORWARDTABLE@@PAKH@ZA, _ms_GetRTTAndHopCount@IfFuncLoad@@0P6GHKPAKK0@ZA, _ms_IcmpCloseHandle@IfFuncLoad@@0P6GHPAX@ZA, _ms_IcmpCreateFile@IfFuncLoad@@0P6GPAXXZA, _ms_IcmpSendEcho@IfFuncLoad@@0P6GKPAXK0GPAUip_option_information@@0KK@ZA, _ms_Init@IfFuncLoad@@0P6GHKPAPAXPAUAsnObjectIdentifier@@@ZA, _ms_InitEx@IfFuncLoad@@0P6GHPAUAsnObjectIdentifier@@@ZA, _ms_IpReleaseAddress@IfFuncLoad@@0P6GKPAU_IP_ADAPTER_INDEX_MAP@@@ZA, _ms_IpRenewAddress@IfFuncLoad@@0P6GKPAU_IP_ADAPTER_INDEX_MAP@@@ZA, _ms_Query@IfFuncLoad@@0P6GHEPAUSnmpVarBindList@@PAJ1@ZA, _ms_SetIpForwardEntry@IfFuncLoad@@0P6GKPAU_MIB_IPFORWARDROW@@@ZA, _ms_Trap@IfFuncLoad@@0P6GHPAUAsnObjectIdentifier@@PAJ1PAKPAUSnmpVarBindList@@@ZA, _ms_bInited@IfFuncLoad@@0HA, _ms_hInstICMP@IfFuncLoad@@0PAUHINSTANCE__@@A, _ms_hInstIpHlp@IfFuncLoad@@0PAUHINSTANCE__@@A, _ms_hInstMIB@IfFuncLoad@@0PAUHINSTANCE__@@A<BR>



    Fichier stickload.sys reçu le 2008.04.14 12:49:24 (CET)Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.4.12.0 2008.04.14 -
    AntiVir 7.6.0.85 2008.04.14 -
    Authentium 4.93.8 2008.04.13 -
    Avast 4.8.1169.0 2008.04.14 -
    AVG 7.5.0.516 2008.04.13 -
    BitDefender 7.2 2008.04.14 -
    CAT-QuickHeal 9.50 2008.04.12 -
    ClamAV 0.92.1 2008.04.14 -
    DrWeb 4.44.0.09170 2008.04.14 -
    eSafe 7.0.15.0 2008.04.09 -
    eTrust-Vet 31.3.5697 2008.04.14 -
    Ewido 4.0 2008.04.13 -
    F-Prot 4.4.2.54 2008.04.14 -
    F-Secure 6.70.13260.0 2008.04.14 -
    FileAdvisor 1 2008.04.14 -
    Fortinet 3.14.0.0 2008.04.14 -
    Ikarus T3.1.1.26.0 2008.04.14 -
    Kaspersky 7.0.0.125 2008.04.14 -
    McAfee 5272 2008.04.11 -
    Microsoft 1.3408 2008.04.14 -
    NOD32v2 3023 2008.04.14 -
    Norman 5.80.02 2008.04.12 -
    Panda 9.0.0.4 2008.04.13 -
    Prevx1 V2 2008.04.14 -
    Rising 20.39.62.00 2008.04.13 -
    Sophos 4.28.0 2008.04.14 -
    Sunbelt 3.0.1041.0 2008.04.12 -
    Symantec 10 2008.04.14 -
    TheHacker 6.2.92.276 2008.04.12 -
    VBA32 3.12.6.4 2008.04.14 -
    VirusBuster 4.3.26:9 2008.04.13 -
    Webwasher-Gateway 6.6.2 2008.04.14 -

    Information additionnelle
    File size: 16128 bytes
    MD5...: b6e374c4ffeedbcbf3c247c4337089dd
    SHA1..: 1ebb3c2125b787c5c63bad92b3d44204f3fc83ec
    SHA256: d869f2a031203e5efc63b272ca3ea62019f77b2fc40ea470a1382452ff9191e6
    SHA512: 1e767452dc80551bb9d20e636835ef789a48da5390de3843b1a1c6c6e8d16085<BR>067fc1e7b936a68f4713185f2db51302ada803f5e8a883e771c5dcf2b9097e1c
    PEiD..: -
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x109a8<BR>timedatestamp.....: 0x42b7a44b (Tue Jun 21 05:23:23 2005)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 6 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x480 0x553 0x580 6.05 d813c77f4b02a9c0389405cb2a4548bf<BR>.rdata 0xa00 0xae 0x100 3.50 efe361db9708ac41a29f39cf898896f7<BR>.data 0xb00 0x2c42 0x2c80 5.47 f3f5722ad1cab49e0df6fed42f8f2089<BR>INIT 0x3780 0x19c 0x200 4.04 4591eb146c310c228b8a7db12b60db76<BR>.rsrc 0x3980 0x450 0x480 3.18 e37246ad8df5789e20a412462ecf4cf7<BR>.reloc 0x3e00 0x82 0x100 1.91 a22e3d08d67656e738ab8c5bc54f056b<BR><BR>( 1 imports ) <BR>> NTOSKRNL.EXE: IofCallDriver, KeSetEvent, KeWaitForSingleObject, KeInitializeEvent, IofCompleteRequest, IoDeleteDevice, IoDetachDevice, IoAttachDeviceToDeviceStack, IoCreateDevice, IoBuildDeviceIoControlRequest, InterlockedDecrement, InterlockedIncrement, ExFreePool, ExAllocatePoolWithTag<BR><BR>( 0 exports ) <BR>

    Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.4.12.0 2008.04.14 -
    AntiVir 7.6.0.85 2008.04.14 -
    Authentium 4.93.8 2008.04.13 -
    Avast 4.8.1169.0 2008.04.14 -
    AVG 7.5.0.516 2008.04.13 -
    BitDefender 7.2 2008.04.14 -
    CAT-QuickHeal 9.50 2008.04.12 -
    ClamAV 0.92.1 2008.04.14 -
    DrWeb 4.44.0.09170 2008.04.14 -
    eSafe 7.0.15.0 2008.04.09 -
    eTrust-Vet 31.3.5697 2008.04.14 -
    Ewido 4.0 2008.04.13 -
    F-Prot 4.4.2.54 2008.04.14 -
    F-Secure 6.70.13260.0 2008.04.14 -
    FileAdvisor 1 2008.04.14 -
    Fortinet 3.14.0.0 2008.04.14 -
    Ikarus T3.1.1.26.0 2008.04.14 -
    Kaspersky 7.0.0.125 2008.04.14 -
    McAfee 5272 2008.04.11 -
    Microsoft 1.3408 2008.04.14 -
    NOD32v2 3023 2008.04.14 -
    Norman 5.80.02 2008.04.12 -
    Panda 9.0.0.4 2008.04.13 -
    Prevx1 V2 2008.04.14 -
    Rising 20.39.62.00 2008.04.13 -
    Sophos 4.28.0 2008.04.14 -
    Sunbelt 3.0.1041.0 2008.04.12 -
    Symantec 10 2008.04.14 -
    TheHacker 6.2.92.276 2008.04.12 -
    VBA32 3.12.6.4 2008.04.14 -
    VirusBuster 4.3.26:9 2008.04.13 -
    Webwasher-Gateway 6.6.2 2008.04.14 -

    Information additionnelle
    File size: 16128 bytes
    MD5...: b6e374c4ffeedbcbf3c247c4337089dd
    SHA1..: 1ebb3c2125b787c5c63bad92b3d44204f3fc83ec
    SHA256: d869f2a031203e5efc63b272ca3ea62019f77b2fc40ea470a1382452ff9191e6
    SHA512: 1e767452dc80551bb9d20e636835ef789a48da5390de3843b1a1c6c6e8d16085<BR>067fc1e7b936a68f4713185f2db51302ada803f5e8a883e771c5dcf2b9097e1c
    PEiD..: -
    PEInfo: PE Structure information<BR><BR>( base data )<BR>entrypointaddress.: 0x109a8<BR>timedatestamp.....: 0x42b7a44b (Tue Jun 21 05:23:23 2005)<BR>machinetype.......: 0x14c (I386)<BR><BR>( 6 sections )<BR>name viradd virsiz rawdsiz ntrpy md5<BR>.text 0x480 0x553 0x580 6.05 d813c77f4b02a9c0389405cb2a4548bf<BR>.rdata 0xa00 0xae 0x100 3.50 efe361db9708ac41a29f39cf898896f7<BR>.data 0xb00 0x2c42 0x2c80 5.47 f3f5722ad1cab49e0df6fed42f8f2089<BR>INIT 0x3780 0x19c 0x200 4.04 4591eb146c310c228b8a7db12b60db76<BR>.rsrc 0x3980 0x450 0x480 3.18 e37246ad8df5789e20a412462ecf4cf7<BR>.reloc 0x3e00 0x82 0x100 1.91 a22e3d08d67656e738ab8c5bc54f056b<BR><BR>( 1 imports ) <BR>> NTOSKRNL.EXE: IofCallDriver, KeSetEvent, KeWaitForSingleObject, KeInitializeEvent, IofCompleteRequest, IoDeleteDevice, IoDetachDevice, IoAttachDeviceToDeviceStack, IoCreateDevice, IoBuildDeviceIoControlRequest, InterlockedDecrement, InterlockedIncrement, ExFreePool, ExAllocatePoolWithTag<BR><BR>( 0 exports ) <BR>


    14 Avril 2008 14:01:10

    :hello: 

    Désactive toute protection résidente ( antivirus…) !

    Copie le texte se situant dans le cadre ci-dessous, sans le mot citation :

    Citation :
    Driver::
    o1394bul

    Registry::
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "DriverLoad"=-
    "DriverCheck"=-
    "SystemDriverLoad"=-
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "NDSTray.exe"=-
    "CFSServ.exe"=-



    Ouvre le Bloc-Notes puis colle le texte copié.
    (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
    Sauvegarde ce fichier sous le nom de CFScript.txt.

    Glisse maintenant le fichier ComboFix-Do.txt dans Combofix.exe comme ci-dessous :



    Cela va relancer Combofix, tape sur 1 puis valide. Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un nouveau rapport Hijackthis.
    S'il n'y a pas de redémarrage, poste quand même les rapports.

    ;) 
    14 Avril 2008 15:15:16

    voilà , avec un peu de mal

    ComboFix 08-04-13.3 - jojo 2008-04-14 14:52:10.3 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.608 [GMT 2:00]
    Endroit: C:\Documents and Settings\jojo\Bureau\ComboFix.exe
    Command switches used :: C:\Documents and Settings\jojo\Bureau\CFScript.txt
    * Création d'un nouveau point de restauration

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-14 to 2008-04-14 ))))))))))))))))))))))))))))))))))))
    .

    2008-04-14 14:46 . 2008-04-14 14:46 <REP> d-------- C:\Program Files\Trend Micro
    2008-04-14 10:02 . 2008-04-14 10:02 <REP> d-------- C:\WINDOWS\ERUNT
    2008-04-14 09:57 . 2008-04-14 10:22 <REP> d-------- C:\SDFix
    2008-04-14 09:33 . 2008-04-14 09:35 1,374 --a------ C:\WINDOWS\imsins.BAK
    2008-04-14 01:17 . 2008-04-14 01:17 244 --ah----- C:\sqmnoopt08.sqm
    2008-04-14 01:17 . 2008-04-14 01:17 232 --ah----- C:\sqmdata08.sqm
    2008-04-13 22:03 . 2008-04-13 22:03 <REP> d-------- C:\Deckard
    2008-04-13 20:54 . 2008-04-13 20:54 244 --ah----- C:\sqmnoopt07.sqm
    2008-04-13 20:54 . 2008-04-13 20:54 232 --ah----- C:\sqmdata07.sqm
    2008-04-12 01:06 . 2008-04-12 01:06 244 --ah----- C:\sqmnoopt06.sqm
    2008-04-12 01:06 . 2008-04-12 01:06 232 --ah----- C:\sqmdata06.sqm
    2008-04-11 00:05 . 2008-04-11 00:05 244 --ah----- C:\sqmnoopt05.sqm
    2008-04-11 00:05 . 2008-04-11 00:05 232 --ah----- C:\sqmdata05.sqm
    2008-04-09 23:56 . 2008-04-09 23:56 244 --ah----- C:\sqmnoopt04.sqm
    2008-04-09 23:56 . 2008-04-09 23:56 232 --ah----- C:\sqmdata04.sqm
    2008-04-08 23:37 . 2008-04-08 23:37 244 --ah----- C:\sqmnoopt03.sqm
    2008-04-08 23:37 . 2008-04-08 23:37 232 --ah----- C:\sqmdata03.sqm
    2008-04-06 19:51 . 2008-04-06 19:51 244 --ah----- C:\sqmnoopt02.sqm
    2008-04-06 19:51 . 2008-04-06 19:51 232 --ah----- C:\sqmdata02.sqm
    2008-04-03 01:43 . 2008-04-03 01:43 244 --ah----- C:\sqmnoopt01.sqm
    2008-04-03 01:43 . 2008-04-03 01:43 232 --ah----- C:\sqmdata01.sqm
    2008-04-03 00:59 . 2008-04-03 00:59 <REP> d-------- C:\Program Files\CCleaner
    2008-03-27 22:44 . 2008-03-27 22:45 <REP> d-------- C:\Documents and Settings\jojo\Application Data\MailFrontier
    2008-03-26 20:13 . 2008-03-26 20:13 <REP> d-------- C:\WINDOWS\system32\AlertModule
    2008-03-26 20:13 . 2004-08-23 15:50 32,768 --a------ C:\WINDOWS\system32\WooDial2000.dll
    2008-03-26 20:12 . 2003-08-04 15:22 94,208 --a------ C:\WINDOWS\system32\W32n50.dll
    2008-03-26 20:12 . 2004-08-23 15:49 40,960 --a------ C:\WINDOWS\system32\FTRTSVC.exe
    2008-03-26 20:12 . 2005-10-06 15:55 36,864 --a------ C:\WINDOWS\system32\IfHelper.dll
    2008-03-26 20:12 . 2003-08-04 15:22 16,128 --------- C:\WINDOWS\system32\PCANDIS5.SYS
    2008-03-26 20:10 . 2008-04-14 14:41 <REP> d-------- C:\Program Files\Wanadoo
    2008-03-26 19:51 . 2008-03-26 19:51 <REP> d-------- C:\Program Files\SAGEM
    2008-03-24 18:50 . 2008-03-24 18:50 <REP> d-------- C:\Program Files\Securitoo
    2008-03-16 03:44 . 2008-04-14 01:15 <REP> d-------- C:\Program Files\Incomplete
    2008-03-16 03:43 . 2008-04-13 22:30 <REP> d-------- C:\Program Files\LimeWire

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-04-13 21:30 --------- d-----w C:\Documents and Settings\jojo\Application Data\LimeWire
    2008-04-13 14:48 --------- d-----w C:\Program Files\Everest Poker
    2008-03-26 17:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-05-09 00:23 118 ----a-w C:\Documents and Settings\jojo\Application Data\wklnhst.dat
    .

    ((((((((((((((((((((((((((((( snapshot@2008-04-14_11.35.57.21 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-04-14 09:31:41 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2008-04-14 12:54:40 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2008-04-14 12:55:08 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_31c.dat
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TOSCDSPD"="C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 17:08 65536]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15:00 15360]
    "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [2004-08-23 15:50 122880]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 14:34 64512]
    "nwiz"="nwiz.exe" [2006-02-16 16:34 1519616 C:\WINDOWS\system32\nwiz.exe]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-02-16 16:34 7557120]
    "High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2005-12-29 23:21 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-03 01:02 761948]
    "Toshiba Hotkey Utility"="C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" [2006-03-15 19:12 1769472]
    "SmoothView"="C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe" [2005-05-17 10:24 118784]
    "DLA"="C:\WINDOWS\System32\DLA\DLACTRLW.EXE" [2005-10-06 06:20 122940]
    "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-12-05 12:37 667718]
    "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-11-28 11:41 602182]
    "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 15:00 79224]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02 919280]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 02:41 49152]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-12-11 11:56 286720]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-12-11 13:10 267048]
    "WOOWATCH"="C:\PROGRA~1\Wanadoo\Watch.exe" [2004-08-23 15:49 20480]
    "WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\GestMaj.exe" [2004-10-14 17:55 32768]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-10 15:00 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
    "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
    "C:\\Program Files\\Messenger\\msmsgs.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=
    "C:\\Program Files\\LimeWire\\LimeWire.exe"=

    R3 BoiHwsetup;Access 32bits INT15 routine;C:\WINDOWS\system32\drivers\BoiHwSetup.sys [2005-06-11 06:42]
    R3 qkbfiltr;Quanta HotKey Keyboard Filter Driver;C:\WINDOWS\system32\drivers\qkbfiltr.sys [2006-01-12 17:21]
    R3 qmofiltr;Quanta HotKey Mouse Filter Driver;C:\WINDOWS\system32\drivers\qmofiltr.sys [2005-05-05 15:27]
    R3 X10Hid;X10 Hid Device;C:\WINDOWS\system32\Drivers\x10hid.sys [2005-11-28 11:45]
    S3 SMCB000;SMSC CIR HID Miniport Device Driver;C:\WINDOWS\system32\DRIVERS\hidsmsc.sys [2006-01-17 17:30]
    S3 StickCap;Digital TV DVB-T USB Stick adapter service;C:\WINDOWS\system32\Drivers\stickcap.sys [2005-06-21 06:33]
    S3 stickload;Digital TV stick firmware loader service;C:\WINDOWS\system32\DRIVERS\stickload.sys [2005-06-21 07:23]
    S3 tosrfec;Bluetooth ACPI from TOSHIBA;C:\WINDOWS\system32\DRIVERS\tosrfec.sys [2005-09-09 15:47]
    S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]

    .
    Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
    "2008-01-14 21:30:21 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    .
    **************************************************************************

    catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-04-14 14:56:21
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
    C:\WINDOWS\ehome\ehrecvr.exe
    C:\WINDOWS\ehome\ehSched.exe
    C:\WINDOWS\system32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\PROGRA~1\COMMON~1\X10\Common\X10nets.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehmsas.exe
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-04-14 14:59:05 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-04-14 12:59:02
    ComboFix2.txt 2008-04-14 12:42:28
    ComboFix3.txt 2008-04-14 09:36:10

    Pre-Run: 65,721,024,512 octets libres
    Post-Run: 65,704,873,984 octets libres
    .
    2008-04-14 07:35:49 --- E O F ---


    et le higjackthis


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 15:14:22, on 14/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
    C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\notepad.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

    --
    End of file - 8954 bytes

    14 Avril 2008 15:16:43

    Re,

    Désinstalle avast, redémarre et supprime ~~>C:\Program Files\Alwil Software

    Télécharge ccleaner (>>tuto à lire !<<), tu download «the latest version » puis installe le en décochant - Ajouter la Barre d'Outils Yahoo! CCleaner
    Puis lance le nettoyage, puis fais chercher des erreurs et sauvegardes si tu le souhaites.

    Télécharge et installe Antivir. (tuto)
    Pourquoi changer ? : Avast! vs Antivir
    mais aussi:
    14 antivirus au banc d'essai
    Citation :
    Antivir : le plus efficace des gratuits

    Vérifie qu’il soit bien à jour ! Fais une analyse complète en mode sans échec, sauvegarde le rapport et poste le moi.

    ;) 
    14 Avril 2008 18:32:21

    voilà le rapport , en revanche c'est le deuxième car j'en ai fait un premier malheureusement stoppé à 95%, donc j'ai recommencé .Pour infos il y a 4 trojans je crois , que j'ai mis en quarantaine sur le premier scan




    AntiVir PersonalEdition Classic
    Report file date: lundi 14 avril 2008 16:56

    Scanning for 1200071 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: jojo
    Computer name: YOUR-939BDAEA55

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
    ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:31:24
    ANTIVIR2.VDF : 7.0.3.156 795136 Bytes 11/04/2008 13:31:24
    ANTIVIR3.VDF : 7.0.3.161 79360 Bytes 14/04/2008 13:31:24
    AVEWIN32.DLL : 7.6.0.85 3461632 Bytes 14/04/2008 13:31:25
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
    AVPACK32.DLL : 7.6.0.3 360488 Bytes 14/04/2008 13:31:26
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: C:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: lundi 14 avril 2008 16:56

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    11 processes with 11 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '42' files ).


    Starting the file scan:

    Begin scan in 'C:\'
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP200\A0033197.exe
    [DETECTION] Is the Trojan horse TR/Click.Delf.FJ.7
    [INFO] The file was moved to '48338082.qua'!


    End of the scan: lundi 14 avril 2008 18:21
    Used time: 1:25:08 min

    The scan has been done completely.

    5066 Scanning directories
    299588 Files were scanned
    1 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    1 files were moved to quarantine
    0 files were renamed
    1 Files cannot be scanned
    299587 Files not concerned
    7561 Archives were scanned
    1 Warnings
    0 Notes


    14 Avril 2008 18:34:06

    voilà le rapport , en revanche c'est le deuxième car j'en ai fait un premier malheureusement stoppé à 95% par erreur, donc j'ai recommencé .Pour infos il y a 4 trojans je crois , que j'ai mis en quarantaine sur le premier scan




    AntiVir PersonalEdition Classic
    Report file date: lundi 14 avril 2008 16:56

    Scanning for 1200071 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: jojo
    Computer name: YOUR-939BDAEA55

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 12:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 11:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 14:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 11:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 13:27:15
    ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:31:24
    ANTIVIR2.VDF : 7.0.3.156 795136 Bytes 11/04/2008 13:31:24
    ANTIVIR3.VDF : 7.0.3.161 79360 Bytes 14/04/2008 13:31:24
    AVEWIN32.DLL : 7.6.0.85 3461632 Bytes 14/04/2008 13:31:25
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 06:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
    AVPACK32.DLL : 7.6.0.3 360488 Bytes 14/04/2008 13:31:26
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 06:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 11:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 06:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 11:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 11:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 08:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: C:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: lundi 14 avril 2008 16:56

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    11 processes with 11 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '42' files ).


    Starting the file scan:

    Begin scan in 'C:\'
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\System Volume Information\_restore{EB633BA2-4F61-40B6-86F0-A87FDC4A394F}\RP200\A0033197.exe
    [DETECTION] Is the Trojan horse TR/Click.Delf.FJ.7
    [INFO] The file was moved to '48338082.qua'!


    End of the scan: lundi 14 avril 2008 18:21
    Used time: 1:25:08 min

    The scan has been done completely.

    5066 Scanning directories
    299588 Files were scanned
    1 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    1 files were moved to quarantine
    0 files were renamed
    1 Files cannot be scanned
    299587 Files not concerned
    7561 Archives were scanned
    1 Warnings
    0 Notes
    14 Avril 2008 19:39:48

    Re,

    Télécharge MalwareByte's Anti-Malware sur ton Bureau.
    Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.

    Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
    AIDE : Redémarrer en mode sans échec

  • Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
  • Afin de lancer la recherche, clic sur"Rechercher".
  • Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :
    -- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
    -- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
    [#ff0000]REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.[/#f]

    AIDE : Tuto en images sur MBAM

    ;) 
    14 Avril 2008 22:24:34

    bonsoir, je t'envoie quand même le rapport s'il n'a rien trouvé ?

    est ce fini? encore une chose , dois je supprimer les trojans mis en quarantaine par antivir

    merci encore et encore
    15 Avril 2008 00:41:51

    Re,

    Attends ;) 

    Poste un nouveau rapport hijackthis et dis-moi comment va le PC, toujours des problèmes ?

    ;) 
    15 Avril 2008 00:45:29

    J'ai pas l'impression qu'il y ait de problèmes
    voilà le rapport

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 00:43:09, on 15/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
    C:\Program Files\Canon\CAL\CALMAIN.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe
    C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
    C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    C:\Program Files\Synaptics\SynTP\Toshiba.exe
    C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
    C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [Toshiba Hotkey Utility] "C:\Program Files\Toshiba\Windows Utilities\Hotkey.exe" /lang FR
    O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe
    O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
    O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
    O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
    O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

    --
    End of file - 8701 bytes
    15 Avril 2008 00:46:43

    C’est OK, tu n’es plus infecté(e) :p 

    1) Télécharge ToolsCleaner sur ton bureau.
    http://www.commentcamarche.net/telecharger/toolscleaner...

    Ce programme va te faire désinstaller tous les outils que je t’ai faits utiliser.

  • Clique sur Recherche et laisse le scan agir ...
  • Clique sur Suppression pour finaliser.
  • Tu peux, si tu le souhaites, te servir des Options facultatives.
  • Clique sur Quitter pour obtenir le rapport.
  • Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

    2) Télécharge et installe Ccleaner :
    http://www.01net.com/telecharger/windows/Utilitaire/net...
  • Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Ensuite, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Clique sur l'onglet "Nettoyeur" puis sur "Lancer le Nettoyage".
  • Ensuite clique sur l'onglet Registre, clique sur "Chercher des erreurs" puis sur "Réparer les erreurs sélectionnées". Il est inutile de faire des sauvegardes des clés. Répète l'opération autant de fois qu'il le faut jusqu'à qu'il ne trouve plus d'erreurs.
  • Tutorial ici : http://www.infos-du-net.com/forum/272336-7-ccleaner-und...
    3)
  • Désactive ta restauration systeme

  • Réactive ta restauration systeme

  • Tutorial ici : http://www.infos-du-net.com/forum/272480-11-desactiver-...
    ********************************************************************************

    Ajoute maintenant [Résolu] au titre. Pour cela :
    * Clique, dans ton premier message, sur le bouton "Editer"
    * Rajoute la mention [Résolu] au titre
    * Clique ensuite sur "Valider votre message"

    Ce serait sympa de rapporter ton infection sur > Malware-Complaints < pour faire condamner ses auteurs

    - Règles du forum <- ici
    - Poster un message <- ici ( par Malekal )

    Pour t'enregistrer clique sur le bouton register ( en haut )
    Si tu as plus de 13 ans choisis " I Agree to these terms and am over or exactly 13 years of age "
    Si tu as moins de 13 ans choisis " I Agree to these terms and am under 13 years of age "

    Tu auras une liste par type d'infection
    Si ton infection n'est pas dans la liste crée un message dans Autres infections

    a+ et bon surf :hello: 


    Quelques liens intéressants :

    http://mickael.barroux.free.fr/securite/
    http://www.malekal.com/
    http://www.infos-du-net.com/forum/275481-11-dossier-pre...
    15 Avril 2008 01:16:48

    Voilà le dernier rapport
    Un p'tit truc avant : est ce normal qu'il reste toujours des fichiers lorsque je lance l'analyse sur ccleaner ( même après plusieurs nettoyages )il reste ces 2 lignes :
    ANALYSE COMPLETE - (0.014 secs)
    ------------------------------------------------------------------------------------------
    10,05KB ont été supprimés. (Taille approximative)
    ------------------------------------------------------------------------------------------

    Détails des fichiers à supprimer (Note: AUCUN fichier n'a pour l'instant été supprimé)
    ------------------------------------------------------------------------------------------
    C:\WINDOWS\system32\wbem\Logs\wbemess.log 1,22KB
    C:\WINDOWS\Internet Logs\ZALog.txt 8,83KB
    ------------------------------------------------------------------------------------------

    et voilà le rapport tools cleaner

    -->- Recherche:

    C:\Qoobox: trouvé !
    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
    C:\Documents and Settings\jojo\Bureau\Dss.exe: trouvé !
    C:\Documents and Settings\jojo\Bureau\SdFix.exe: trouvé !
    C:\Documents and Settings\jojo\Bureau\HijackThis.lnk: trouvé !
    C:\Documents and Settings\jojo\Bureau\ComboFix.exe: trouvé !
    C:\Documents and Settings\jojo\Bureau\HJTInstall.exe: trouvé !
    C:\Program Files\Trend Micro\HijackThis: trouvé !
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !

    ---------------------------------
    -->- Suppression:

    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
    C:\Documents and Settings\jojo\Bureau\Dss.exe: supprimé !
    C:\Documents and Settings\jojo\Bureau\SdFix.exe: supprimé !
    C:\Documents and Settings\jojo\Bureau\HijackThis.lnk: supprimé !
    C:\Documents and Settings\jojo\Bureau\ComboFix.exe: supprimé !
    C:\Documents and Settings\jojo\Bureau\HJTInstall.exe: supprimé !
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
    C:\Qoobox: supprimé !
    C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
    C:\Program Files\Trend Micro\HijackThis: supprimé !


    et chapeau bas monsieur

    thanks....
    15 Avril 2008 11:13:44

    :hello: 

    Supprime les fichiers manuellement ;) 

    De rien ce fut un plaisir !

    Rapporte ton infection sur malware complain si ce n'est pas fait, c'est important ;) 

    Merci de consulter ce dossier (en pdf) pour en connaître davantage sur les risques du Net.



    Si tu trouves ce document intéressant, n'hésite pas à le transmettre à tes contacts.

    Bonne continuation :hello: 
    15 Avril 2008 11:26:44

    ok , j'vais faire tout ça de suite, bonne journée à toi
    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS