Votre question

Une victime de plus - MSN ta tof sur ce site...

Tags :
  • Sécurité
Dernière réponse : dans Sécurité et virus
7 Avril 2008 13:38:47

Bonjour a tous,

comme le titre l'indique je fais partie des nouvelles victimes contaminées par le virus "ta tof sur ce site". Je suis d'ordinaire qq'un de méfiant et d'averti mais c'est un ami qui me l'a envoyé juste apres m'avoir dit: "je t'envoi les fotos des vacances dans 5 minutes"...

Sacré coincidence qui m'a fait douter. Enfin bref, avant de venir demander de l'aide j'ai regardé tous les sujets similaires et j'ai tout essayé mais rien n'y fait.

Si quelqu'un pouvait m'aider, j'ai tous les rapports, MSNfix, SDfix, Hijack, etc.

Merci d'avance.

Autres pages sur : victime msn tof site

7 Avril 2008 13:48:20

Donne les rapport stp , on effet j'ai faillis etre victime de cette chose mes encore plus bizzare que sa on fait je n'est que 13 ans et je suis un petit genie en informatique , bon deja je pense a TH Pas tokio hotel xD trojan horse qui aurait pus infiltrée les systeme de certaine personne pour se genre de chose , mes il non pas cette fonction je ne croi pas , cela reste a la base comme le virus " I love you , donc sa fonction etais de se rependre dans le pc récupérée le carnat d'adresse et tenter de craquer les mot de passe facile pour les window 94, Sauf que moi la personne etais offline et s'etais en anglais , mon firewall la automatiquement détécter se que spybot avec deja fait , Je te conseille de sois trouver le fichier qui doit-étre cachée ou de reboot ton disque dure , a tu essayer mode sans echec ?
et tu na pas écrit les conséquence de ce "virus
cordialement
Parki
a b 8 Sécurité
7 Avril 2008 14:04:18

Poste pour suivre...
Contenus similaires
7 Avril 2008 15:49:38

Rapport Hijack

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at Alex - 12:34:54, on 07/04/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
C:\program files\powerstrip\pstrip.exe
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\RocketDock\RocketDock.exe
D:\Microsoft ActiveSync\wcescomm.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
D:\MICROS~1\rapimgr.exe
C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Opera\Opera.exe
D:\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {04F4BD15-534C-1958-C0D5-7818DAEC025A} - (no file)
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\%%%.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /wait
O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
O4 - HKLM\..\Run: [NvMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr/
O18 - Filter hijack: text/html - {994D478A-45D0-4DB4-AE77-738B1E346E99} - (no file)
O20 - AppInit_DLLs: Runner.dll,hpdclbic.dll,Runner.dll,jlmkdhnb.dll,oppbkopp.dll,Runner.dll,achkkgkc.dll,SDRunner.dll,mhfllcfd.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVP Control Centre Service (AVPCC) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: KAV Monitor Service (KAVMonitorService) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

--
End of file - 6695 bytes



La ligne qui décone est la F02 je pense mais le soucis c'est que je ne peux pas la fix car elle est utilisée par winlogon.exe...
7 Avril 2008 15:50:09

Voila le rapport msnfix



MSNFix 1.700

C:\MSNFix
Fix exécuté le 07/04/2008 - 13:08:04,51 By Alex
mode normal

************************ Recherche les fichiers présents

... C:\WINDOWS\system32\%%%.exe
... C:\WINDOWS\system32\%%%.exe

************************ Recherche les dossiers présents

Aucun dossier trouvé




************************ Suppression des fichiers

.. OK ... C:\WINDOWS\system32\%.exe
.. OK ... C:\WINDOWS\system32\%.exe
/!\ ... C:\WINDOWS\system32\%%%.exe
/!\ ... C:\WINDOWS\system32\%%%.exe
/!\ ... C:\WINDOWS\system32\%%%.exe
/!\ ... C:\WINDOWS\system32\%%%.exe



************************ Nettoyage du registre



Les fichiers encore présents seront supprimés au prochain redémarrage


Aucun Fichier trouvé
.. OK ... C:\WINDOWS\system32\%.exe



************************ Fichiers suspects

Aucun Fichier trouvé


Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 07042008_13110346.zip

************************ HKLM\...\Winlogon\Userinit

Userinit = C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\%.exe


------------------------------------------------------------------------
Auteur : !aur3n7 Contact: http://changelog.fr
------------------------------------------------------------------------

--------------------------------------------- END ---------------------------------------------

7 Avril 2008 15:50:56

Et finalement le SDfix:



SDFix: Version 1.167
Run by Alex on 07/04/2008 at Alex - 12:28

Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\Alex\Bureau\SDFix

Checking Services :


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting


Checking Files :

Trojan Files Found:

C:\WINDOWS\17PHolmes1423.exe - Deleted
C:\WINDOWS\system32\drivers\etc\BackupHosts.bak - Deleted
C:\WINDOWS\system32\real.txt - Deleted


Could Not Remove C:\WINDOWS\system32\%%%.exe



Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-07 12:32:57
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

? [348]

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...


scan completed successfully
hidden processes: 1
hidden services: 0
hidden files: 0


Remaining Services :



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Overnet\\overnet.exe"="C:\\Program Files\\Overnet\\overnet.exe:*:Enabled:o vernet Application"
"C:\\Program Files\\Java\\j2re1.4.2_06\\BIN\\javaw.exe"="C:\\Program Files\\Java\\j2re1.4.2_06\\BIN\\javaw.exe:*:Enabled:javaw"
"C:\\Program Files\\Jeux classiques\\Bin\\CmCenterV2.exe"="C:\\Program Files\\Jeux classiques\\Bin\\CmCenterV2.exe:*:Enabled:CmCenter Module"
"D:\\Steam\\Steam.exe"="D:\\Steam\\Steam.exe:*:Enabled:Steam"
"D:\\Steam\\SteamApps\\register92@hotmail.com\\counter-strike\\hl.exe"="D:\\Steam\\SteamApps\\register92@hotmail.com\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\HL2\\hl2.exe"="D:\\HL2\\hl2.exe:*:Enabled:hl2"
"C:\\Program Files\\Fichiers communs\\KAV Shared Files\\avpupd.exe"="C:\\Program Files\\Fichiers communs\\KAV Shared Files\\avpupd.exe:*:Enabled:AVP Updater"
"C:\\World of Warcraft\\WoW-1.2.3-Patch-frFR-Downloader.exe"="C:\\World of Warcraft\\WoW-1.2.3-Patch-frFR-Downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\World of Warcraft\\WoW-1.2.4-to-1.3.0-frFR-downloader.exe"="C:\\World of Warcraft\\WoW-1.2.4-to-1.3.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Java\\jre1.5.0_02\\BIN\\javaw.exe"="C:\\Program Files\\Java\\jre1.5.0_02\\BIN\\javaw.exe:*:Enabled:Java(TM) 2 Platform Standard Edition binary"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\World of Warcraft\\WoW-1.3.1.4297-to-1.4.0-frFR-downloader.exe"="C:\\World of Warcraft\\WoW-1.3.1.4297-to-1.4.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\CoolStreaming\\cool.exe"="C:\\Program Files\\CoolStreaming\\cool.exe:*:Enabled:cool"
"D:\\WoW-1.4.2.4375-to-0.5.0-frFR-downloader.exe"="D:\\WoW-1.4.2.4375-to-0.5.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\eDonkey2000\\edonkey2000.exe"="C:\\Program Files\\eDonkey2000\\edonkey2000.exe:*:Enabled:edonkey2000"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"D:\\My Shared Folder\\Ï eMulix V1.0-BIN\\eMulix V1.0.exe"="D:\\My Shared Folder\\Ï eMulix V1.0-BIN\\eMulix V1.0.exe:*:Enabled:eMule"
"C:\\Program Files\\eMule\\eMulix V1.0.exe"="C:\\Program Files\\eMule\\eMulix V1.0.exe:*:Enabled:eMule"
"C:\\World of Warcraft\\WoW-1.4.2.4375-to-1.5.0-frFR-downloader.exe"="C:\\World of Warcraft\\WoW-1.4.2.4375-to-1.5.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\World of Warcraft\\WoW-1.5.1.4449-to-1.6.0-frFR-downloader.exe"="C:\\World of Warcraft\\WoW-1.5.1.4449-to-1.6.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\World of Warcraft\\WoW-1.6.0.4500-to-1.6.1-frFR-downloader.exe"="C:\\World of Warcraft\\WoW-1.6.0.4500-to-1.6.1-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.6.0-frFR-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.6.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\\WoW-1.6.1.4544-to-1.7.0-frFR-downloader.exe"="D:\\WoW-1.6.1.4544-to-1.7.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.7.1.4695-to-1.8.0-frFR-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.7.1.4695-to-1.8.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.7.1.4695-to-0.8.0-enUS-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.7.1.4695-to-0.8.0-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.8.3.4807-to-1.8.4.4878-frFR-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.8.3.4807-to-1.8.4.4878-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.8.3.4807-to-0.9.0-frFR-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.8.3.4807-to-0.9.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.8.4.4878-to-1.9.0.4937-frFR-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.8.4.4878-to-1.9.0.4937-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
"C:\\Program Files\\World of Warcraft\\WoW-1.9.2.4996-to-1.9.3.5059-frFR-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.9.2.4996-to-1.9.3.5059-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\mIRC\\mirc.exe"="C:\\Program Files\\mIRC\\mirc.exe:*:Enabled:mIRC"
"D:\\mIRC\\mirc.exe"="D:\\mIRC\\mirc.exe:*:Enabled:mIRC"
"C:\\WINDOWS\\System32\\RUNDLL32.EXE"="C:\\WINDOWS\\System32\\RUNDLL32.EXE:*:Enabled:Ex‚cuter une DLL en tant qu'application"
"C:\\WINDOWS\\System32\\dpvsetup.exe"="C:\\WINDOWS\\System32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\GlobalSCAPE\\CuteFTP 7 Professional\\ftpte.exe"="C:\\Program Files\\GlobalSCAPE\\CuteFTP 7 Professional\\ftpte.exe:*:Enabled:FTP Transfer Engine"
"C:\\Program Files\\TrackMania Original Demo\\TmOriginalDemo.exe"="C:\\Program Files\\TrackMania Original Demo\\TmOriginalDemo.exe:*:Enabled:TmOriginalDemo"
"C:\\Program Files\\TmSunriseDemoMag\\TmSunriseDemoMag.exe"="C:\\Program Files\\TmSunriseDemoMag\\TmSunriseDemoMag.exe:*:Enabled:TmSunriseDemoMag"
"C:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-frFR-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.10.2.5302-to-1.11.0.5428-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\TrackMania Sunrise Extreme Demo\\TmSunriseExtremeDemo.exe"="C:\\Program Files\\TrackMania Sunrise Extreme Demo\\TmSunriseExtremeDemo.exe:*:Enabled:TmSunriseExtremeDemo"
"D:\\Steam\\SteamApps\\register92@hotmail.com\\day of defeat\\hl.exe"="D:\\Steam\\SteamApps\\register92@hotmail.com\\day of defeat\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Opera\\Opera.exe"="C:\\Program Files\\Opera\\Opera.exe:*:Enabled:o pera Internet Browser"
"D:\\Steam\\SteamApps\\register92@hotmail.com\\day of defeat source\\hl2.exe"="D:\\Steam\\SteamApps\\register92@hotmail.com\\day of defeat source\\hl2.exe:*:Enabled:hl2"
"D:\\Steam\\SteamApps\\register92@hotmail.com\\team fortress classic\\hl.exe"="D:\\Steam\\SteamApps\\register92@hotmail.com\\team fortress classic\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Steam\\SteamApps\\register92@hotmail.com\\ricochet\\hl.exe"="D:\\Steam\\SteamApps\\register92@hotmail.com\\ricochet\\hl.exe:*:Enabled:Half-Life Launcher"
"D:\\Steam\\SteamApps\\register92@hotmail.com\\deathmatch classic\\hl.exe"="D:\\Steam\\SteamApps\\register92@hotmail.com\\deathmatch classic\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0-frFR-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.0-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-frFR-downloader.exe"="C:\\Program Files\\World of Warcraft\\WoW-1.12.0.5595-to-1.12.1.5875-frFR-downloader.exe:*:Enabled:Blizzard Downloader"
"D:\\Starcraft\\starcraft.exe"="D:\\Starcraft\\starcraft.exe:*:Enabled:Starcraft"
"C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"="C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe:*:Enabled:MessengerDiscovery Live the Windows Live Messenger addon"
"C:\\Program Files\\MessengerDiscovery\\Loader.exe"="C:\\Program Files\\MessengerDiscovery\\Loader.exe:*:Enabled:Loader"
"D:\\TrackMania Nations ESWC\\TmNationsESWC.exe"="D:\\TrackMania Nations ESWC\\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"D:\\Worms World Party\\wwp.exe"="D:\\Worms World Party\\wwp.exe:*:Enabled:Worms World Party"
"C:\\Program Files\\M6Video\\M6video.exe"="C:\\Program Files\\M6Video\\M6video.exe:*:Enabled:o neClick"
"C:\\Program Files\\adslTV\\adslTV.exe"="C:\\Program Files\\adslTV\\adslTV.exe:*:Enabled:adslTV"
"C:\\Program Files\\adslTV\\vlc.exe"="C:\\Program Files\\adslTV\\vlc.exe:*:Enabled:VLC media player"
"C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"="C:\\Program Files\\Freeplayer\\vlc\\vlc.exe:*:Enabled:VLC media player"
"D:\\Steam\\SteamApps\\register92@hotmail.com\\counter-strike source\\hl2.exe"="D:\\Steam\\SteamApps\\register92@hotmail.com\\counter-strike source\\hl2.exe:*:Enabled:hl2"
"D:\\Quake\\quake3.exe"="D:\\Quake\\quake3.exe:*:Enabled:quake3"
"C:\\Quake\\quake3.exe"="C:\\Quake\\quake3.exe:*:Enabled:quake3"
"C:\\Program Files\\Warcraft III\\Warcraft III.exe"="C:\\Program Files\\Warcraft III\\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\\Program Files\\Quake\\quake3.exe"="C:\\Program Files\\Quake\\quake3.exe:*:Enabled:quake3"
"C:\\WINDOWS\\system32\\dplaysvr.exe"="C:\\WINDOWS\\system32\\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper"
"D:\\Baldur's Gate\\BGMain.exe"="D:\\Baldur's Gate\\BGMain.exe:*:Enabled:Baldur's Gate, the Game"
"D:\\Pc engine\\Yame038jFR.exe"="D:\\Pc engine\\Yame038jFR.exe:*:D isabled:Yame038jFR"
"E:\\TrackMania Nations ESWC\\TmNationsESWC.exe"="E:\\TrackMania Nations ESWC\\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"D:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="D:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM)"
"D:\\Microsoft ActiveSync\\rapimgr.exe"="D:\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\\Microsoft ActiveSync\\wcescomm.exe"="D:\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\\Microsoft ActiveSync\\WCESMgr.exe"="D:\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"E:\\Pro Evolution Soccer 2008\\PES2008.exe"="E:\\Pro Evolution Soccer 2008\\PES2008.exe:*:Enabled:p ro Evolution Soccer 2008"
"C:\\WINDOWS\\system32\\%%%.exe"="C:\\WINDOWS\\system32\\%%%.exe:*:Enabled:Flash Media"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"D:\\Microsoft ActiveSync\\rapimgr.exe"="D:\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"D:\\Microsoft ActiveSync\\wcescomm.exe"="D:\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"D:\\Microsoft ActiveSync\\WCESMgr.exe"="D:\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

Remaining Files :

C:\WINDOWS\system32\%%%.exe Found

File Backups: - C:\DOCUME~1\Alex\Bureau\SDFix\backups\backups.zip

Files with Hidden Attributes :

Sun 19 Mar 2006 262,144 A.SH. --- "C:\Program Files\MessengerDiscovery\SpellCHK.exe"
Mon 3 Mar 2008 61,440 A..H. --- "C:\Program Files\MSN Messenger\winmm.dll"
Fri 11 Mar 2005 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"

Finished!

a b 8 Sécurité
7 Avril 2008 17:54:59

Pourquoi SDFix ?
7 Avril 2008 17:58:53

J'ai tout simplement suivi les instructions données sur ce forum aux personnes dans la meme situation que moi.
Voyant que ca ne marchait pas, je suis venu donner ma situation précise.
Je n'aurais pas du lancer SDfix?
a b 8 Sécurité
7 Avril 2008 18:05:35

Fais juste ce que je dis :) 

Télécharge MalwareByte's Anti-Malware sur ton Bureau.
Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.

Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
AIDE : Redémarrer en mode sans échec

  • Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
  • Afin de lancer la recherche, clic sur"Rechercher".
  • Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :
    -- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
    -- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
    [#ff0000]REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.[/#f]

    AIDE : Tuto en images sur MBAM
    7 Avril 2008 20:49:32

    Voila le rapport de Malware:

    Malwarebytes' Anti-Malware 1.10
    Version de la base de données: 598

    Type de recherche: Examen complet (C:\|D:\|E:\|H:\|)
    Eléments examinés: 121267
    Temps écoulé: 41 minute(s), 23 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 4

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    H:\mIRC\mirc.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    H:\mIRC\backup\mirc.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
    C:\Program Files\Fichiers communs\System\aux (Trojan.Agent) -> Delete on reboot.
    C:\Documents and Settings\Alex\Local Settings\Temporary Internet Files\Content.IE5\YJKFUJEP\17PHolmes[1].cmt (Trojan.Downloader) -> Quarantined and deleted successfully.

    et un nouveau Hijack:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at Alex - 20:51:15, on 07/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
    C:\program files\powerstrip\pstrip.exe
    C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    C:\WINDOWS\system32\RunDLL32.exe
    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\RocketDock\RocketDock.exe
    D:\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    D:\MICROS~1\rapimgr.exe
    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
    C:\Program Files\Opera\Opera.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    D:\Vundoscan.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {04F4BD15-534C-1958-C0D5-7818DAEC025A} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\%%%.exe
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /wait
    O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
    O4 - HKLM\..\Run: [NvMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
    O4 - HKLM\..\Run: [Flash Media] C:\WINDOWS\system32\%%%.exe
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr/
    O18 - Filter hijack: text/html - {994D478A-45D0-4DB4-AE77-738B1E346E99} - (no file)
    O20 - AppInit_DLLs: Runner.dll,hpdclbic.dll,Runner.dll,jlmkdhnb.dll,oppbkopp.dll,Runner.dll,achkkgkc.dll,SDRunner.dll,mhfllcfd.dll,
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AVP Control Centre Service (AVPCC) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: KAV Monitor Service (KAVMonitorService) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 6723 bytes
    a b 8 Sécurité
    7 Avril 2008 21:43:59

    Re,

    [#ff0000]Désactive tes protections résidentes (antivirus, Spybot...) ![/#f]

  • Télécharge Combofix ([#ff0000]sUBs[/#f]) sur ton Bureau.
  • Double clique sur combofix.exe afin de le lancer.
  • Lorsque le scan sera complété, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.
    7 Avril 2008 22:22:23

    J'ai tout bien desactivé et fermé toutes mes fenetres mais lorsque je le lance, une fenetre bleue s'ouvre et se referme aussitot avant que j'ai pu lire ou faire qq chose...
    7 Avril 2008 23:12:34

    bonjour à tous!
    voilà mon rapport:
    t'es tres jolie sur cet tof...(je me suis servie de Hijackthis)
    la fameuse phrase ....
    je sais pas trop quoi faire maintenant pr m'en débarrasser
    merci d'avance pr l'aide que vs pourrez m'apporter
    a b 8 Sécurité
    8 Avril 2008 12:23:48

    Tu peux essayer en sans échec ?
    8 Avril 2008 21:43:35

    Essayé également hier, meme résultat, la fenetre se ferme immédiatement après avoir été lancée.
    a b 8 Sécurité
    9 Avril 2008 12:59:12

    Supprime ta version de Combofix puis recommence.
    9 Avril 2008 22:59:45

    Bien joué!

    J'ai supprimer combofix puis retéléchargé, ca a fonctionné et apparement il a éradiqué le problème, c'est le seul a y être arrivé a bout.

    Je te poste le log de combofix:


    ComboFix 08-04-09.1 - Alex 2008-04-09 22:52:50.1 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.662 [GMT 2:00]
    Endroit: C:\Documents and Settings\Alex\Bureau\ComboFix.exe

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\Alex\real.txt
    C:\WINDOWS\mrofinu1423.exe.tmp
    C:\WINDOWS\system32\%%%.exe
    C:\WINDOWS\system32\real.txt

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-09 to 2008-04-09 ))))))))))))))))))))))))))))))))))))
    .

    2008-04-08 01:20 . 2008-04-08 01:20 37,376 --a------ C:\WINDOWS\17PHolmes1423.exe
    2008-04-08 01:20 . 2008-04-08 01:20 9,296 --a------ C:\WINDOWS\system32\eqgwqt.exe
    2008-04-08 01:20 . 2008-04-08 01:20 244 --ah----- C:\sqmnoopt09.sqm
    2008-04-08 01:20 . 2008-04-08 01:20 232 --ah----- C:\sqmdata07.sqm
    2008-04-07 19:20 . 2008-04-07 19:20 9,296 --a------ C:\WINDOWS\system32\prwzys.exe
    2008-04-07 19:19 . 2008-04-07 19:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-04-07 19:19 . 2008-04-07 19:19 <REP> d-------- C:\Documents and Settings\Alex\Application Data\Malwarebytes
    2008-04-07 19:18 . 2008-04-07 19:19 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-04-07 13:14 . 2008-04-07 13:14 9,296 --a------ C:\Documents and Settings\Alex\gxsokz.exe
    2008-04-07 12:20 . 2008-04-07 12:20 244 --ah----- C:\sqmnoopt08.sqm
    2008-04-07 12:20 . 2008-04-07 12:20 232 --ah----- C:\sqmdata06.sqm
    2008-04-07 12:06 . 2008-04-07 12:06 244 --ah----- C:\sqmnoopt07.sqm
    2008-04-07 12:06 . 2008-04-07 12:06 232 --ah----- C:\sqmdata05.sqm
    2008-04-07 01:47 . 2008-04-07 01:47 244 --ah----- C:\sqmnoopt06.sqm
    2008-04-07 01:47 . 2008-04-07 01:47 232 --ah----- C:\sqmdata04.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 244 --ah----- C:\sqmnoopt05.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 244 --ah----- C:\sqmnoopt04.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 232 --ah----- C:\sqmdata03.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 232 --ah----- C:\sqmdata02.sqm
    2008-04-06 22:43 . 2008-04-06 22:43 244 --ah----- C:\sqmnoopt03.sqm
    2008-04-06 22:43 . 2008-04-06 22:43 232 --ah----- C:\sqmdata01.sqm
    2008-04-06 22:35 . 2008-04-06 22:35 <REP> d-------- C:\msc
    2008-04-06 21:59 . 2008-04-06 22:09 <REP> d-------- C:\Program Files\StuffPlug3
    2008-04-06 21:47 . 2008-04-06 21:52 <REP> d-------- C:\Program Files\Windows Live
    2008-04-06 20:54 . 2008-04-06 20:55 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-04-06 20:54 . 2008-04-06 21:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-04-06 20:50 . 2008-04-06 20:51 <REP> d-------- C:\Program Files\Unlocker
    2008-04-06 19:57 . 2008-04-06 19:57 244 --ah----- C:\sqmnoopt02.sqm
    2008-04-06 19:57 . 2008-04-06 19:57 232 --ah----- C:\sqmdata00.sqm
    2008-04-06 19:57 . 2008-04-06 19:57 0 --a------ C:\WINDOWS\system32\real.MSNFix
    2008-04-06 19:36 . 2008-04-07 13:11 <REP> d-------- C:\MSNFix
    2008-04-06 19:35 . 2008-04-06 20:45 <REP> d-------- C:\SDFix
    2008-04-06 19:28 . 2008-04-06 19:28 <REP> d-------- C:\WINDOWS\ERUNT
    2008-03-22 20:20 . 2008-03-22 20:20 <REP> d-------- C:\Program Files\Unphuck
    2008-03-22 20:20 . 2008-03-22 20:20 249,856 --------- C:\WINDOWS\Setup1.exe
    2008-03-22 20:20 . 2008-03-22 20:20 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
    2008-03-10 00:15 . 2008-03-10 00:15 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-03-09 16:46 . 2007-07-30 20:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
    2008-03-09 16:46 . 2007-07-30 20:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
    2008-03-09 16:46 . 2007-07-30 20:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
    2008-03-09 11:33 . 2008-03-09 11:33 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
    2008-03-09 11:23 . 2008-03-09 11:32 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
    2008-03-09 11:22 . 2008-04-06 21:47 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-04-06 19:55 --------- d-----w C:\Program Files\MSN Messenger
    2008-04-06 19:55 --------- d-----w C:\Program Files\MessengerDiscovery
    2008-04-06 19:52 --------- d-----w C:\Program Files\eMule
    2008-04-06 12:15 --------- d-----w C:\Program Files\RocketDock
    2008-04-03 09:41 --------- d-----w C:\Documents and Settings\Alex\Application Data\BitTorrent
    2008-03-31 12:04 --------- d-----w C:\Program Files\adslTV
    2008-03-11 06:05 --------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
    2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
    2007-02-04 10:44 1 ----a-w C:\Documents and Settings\Alex\SI.bin
    2006-11-21 17:22 1,505,792 ----a-w C:\WINDOWS\Fonts\VistaPerfection\Shell\WFVP48PX\Shellstyle.dll
    2006-11-21 17:22 1,505,792 ----a-w C:\WINDOWS\Fonts\VistaPerfection\Shell\NormalColor\Shellstyle.dll
    2005-01-17 20:51 76 ---ha-w C:\Program Files\Desktop.ini
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-01-28 04:55 462848]
    "H/PC Connection Agent"="D:\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 21:45 1211176]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AVPCC"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" [2004-09-03 19:33 495729]
    "PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2005-01-26 15:52 635904]
    "NvMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 21:51 131072]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 16:44 101136 C:\WINDOWS\KHALMNPR.Exe]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
    "nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="NvMCTray.dll" [2006-10-22 12:22 86016 C:\WINDOWS\system32\nvmctray.dll]
    "LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 16:02 563984]
    "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 16:06 2027792]
    "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-03-01 07:10 15872]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 17:09 15360]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoResolveTrack"= 1 (0x1)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSimpleStartMenu"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "UIHost"="vistalogonui.exe"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Jeux classiques\\Bin\\CmCenterV2.exe"=
    "C:\\Program Files\\Fichiers communs\\KAV Shared Files\\avpupd.exe"=
    "C:\\Program Files\\eMule\\emule.exe"=
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "C:\\Program Files\\mIRC\\mirc.exe"=
    "C:\\WINDOWS\\System32\\RUNDLL32.EXE"=
    "C:\\WINDOWS\\System32\\dpvsetup.exe"=
    "C:\\Program Files\\Opera\\Opera.exe"=
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
    "C:\\Program Files\\MessengerDiscovery\\Loader.exe"=
    "C:\\Program Files\\adslTV\\adslTV.exe"=
    "C:\\Program Files\\adslTV\\vlc.exe"=
    "C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
    "C:\\WINDOWS\\system32\\dplaysvr.exe"=
    "E:\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
    "D:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
    "D:\Microsoft ActiveSync\rapimgr.exe"= D:\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "D:\Microsoft ActiveSync\wcescomm.exe"= D:\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "D:\Microsoft ActiveSync\WCESMgr.exe"= D:\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "E:\\Pro Evolution Soccer 2008\\PES2008.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "47624:TCP"= 47624:TCP:BG
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R0 Copystar;Copystar;C:\WINDOWS\system32\DRIVERS\copystar.sys [2002-06-01 16:37]
    R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\PStrip.sys [2004-11-10 00:32]
    R3 3xHybrid;Pinnacle PCTV Stereo service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2003-12-05 13:56]
    R3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys [2002-11-11 19:52]
    S2 AVPCC;AVP Control Centre Service;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /service []
    S2 KAVMonitorService;KAV Monitor Service;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe" /service []
    S3 danceflt;XboxCtrl_filt_Service;C:\WINDOWS\system32\DRIVERS\danceflt.sys [2005-09-28 15:22]
    S3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys [2001-08-17 21:19]
    S3 HabuFltr;Habu Mouse;C:\WINDOWS\system32\drivers\habu.sys [2006-08-14 11:21]
    S3 hid8106;hid8106;C:\WINDOWS\system32\drivers\hid8106.sys [2006-11-17 11:35]
    S3 MBAMCatchMe;MBAMCatchMe;C:\Program Files\Malwarebytes' Anti-Malware\catchme.sys [2008-04-01 19:54]
    S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 18:57]
    S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 18:58]
    S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 18:59]
    S3 USB11LDR;M-Audio USB Uno Loader;C:\WINDOWS\system32\drivers\usb11ldr.sys []
    S3 USBMN1X1;M-Audio USB Uno MIDI Driver;C:\WINDOWS\system32\drivers\usbmn1x1.sys []

    .
    **************************************************************************

    catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-04-09 22:56:52
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 0

    **************************************************************************
    .
    --------------------- DLLs a charg‚ sous des processus courants ---------------------

    PROCESS: C:\WINDOWS\explorer.exe
    -> C:\Program Files\RocketDock\RocketDock.dll
    -> C:\Program Files\Unlocker\UnlockerHook.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    D:\MICROS~1\rapimgr.exe
    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-04-09 22:58:28 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-04-09 20:58:21
    Pre-Run: 9,823,426,048 octets libres
    Post-Run: 9,708,162,560 octets libres
    .
    2008-03-16 09:31:14 --- E O F ---



    Et un rapport Hijack également à jour :


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at Alex - 22:59:54, on 09/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\program files\powerstrip\pstrip.exe
    C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\RocketDock\RocketDock.exe
    D:\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    D:\MICROS~1\rapimgr.exe
    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    D:\Vundoscan.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {04F4BD15-534C-1958-C0D5-7818DAEC025A} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /wait
    O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
    O4 - HKLM\..\Run: [NvMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr/
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AVP Control Centre Service (AVPCC) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: KAV Monitor Service (KAVMonitorService) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 6311 bytes



    Voila.
    9 Avril 2008 23:02:31

    J'ai parlé trop vite apparement, certains fichiers ont disparu, dont le fameux %%%.exe dans system 32 mais Kaspersky me détecte toujours le Win32.Small.tnt.trojan...
    a b 8 Sécurité
    10 Avril 2008 18:03:05

    Il le supprime en mode sans échec ?
    10 Avril 2008 20:38:58

    Non en mode normal peu apres que le pc ait démarré dans:

    c:\documents and settings\mon nom\gxskoz.exe et puis un autre du même style. Le nom du fichier change à chaque fois.
    a b 8 Sécurité
    11 Avril 2008 12:40:24

    Ok, refais un scan Combofix.
    11 Avril 2008 20:29:39

    Voila le nouveau rapport Combofix:


    ComboFix 08-04-09.1 - Alex 2008-04-11 20:28:07.2 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.693 [GMT 2:00]
    Endroit: C:\Documents and Settings\Alex\Bureau\ComboFix.exe

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    ((((((((((((((((((((((((((((( Fichiers créés 2008-03-11 to 2008-04-11 ))))))))))))))))))))))))))))))))))))
    .

    2008-04-10 12:11 . 2008-04-10 12:13 1,374 --a------ C:\WINDOWS\imsins.BAK
    2008-04-08 01:20 . 2008-04-08 01:20 244 --ah----- C:\sqmnoopt09.sqm
    2008-04-08 01:20 . 2008-04-08 01:20 232 --ah----- C:\sqmdata07.sqm
    2008-04-07 19:19 . 2008-04-07 19:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-04-07 19:19 . 2008-04-07 19:19 <REP> d-------- C:\Documents and Settings\Alex\Application Data\Malwarebytes
    2008-04-07 19:18 . 2008-04-07 19:19 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-04-07 12:20 . 2008-04-07 12:20 244 --ah----- C:\sqmnoopt08.sqm
    2008-04-07 12:20 . 2008-04-07 12:20 232 --ah----- C:\sqmdata06.sqm
    2008-04-07 12:06 . 2008-04-07 12:06 244 --ah----- C:\sqmnoopt07.sqm
    2008-04-07 12:06 . 2008-04-07 12:06 232 --ah----- C:\sqmdata05.sqm
    2008-04-07 01:47 . 2008-04-07 01:47 244 --ah----- C:\sqmnoopt06.sqm
    2008-04-07 01:47 . 2008-04-07 01:47 232 --ah----- C:\sqmdata04.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 244 --ah----- C:\sqmnoopt05.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 244 --ah----- C:\sqmnoopt04.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 232 --ah----- C:\sqmdata03.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 232 --ah----- C:\sqmdata02.sqm
    2008-04-06 22:43 . 2008-04-06 22:43 244 --ah----- C:\sqmnoopt03.sqm
    2008-04-06 22:43 . 2008-04-06 22:43 232 --ah----- C:\sqmdata01.sqm
    2008-04-06 22:35 . 2008-04-06 22:35 <REP> d-------- C:\msc
    2008-04-06 21:59 . 2008-04-06 22:09 <REP> d-------- C:\Program Files\StuffPlug3
    2008-04-06 21:47 . 2008-04-06 21:52 <REP> d-------- C:\Program Files\Windows Live
    2008-04-06 20:54 . 2008-04-06 20:55 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-04-06 20:54 . 2008-04-06 21:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-04-06 20:50 . 2008-04-06 20:51 <REP> d-------- C:\Program Files\Unlocker
    2008-04-06 19:57 . 2008-04-06 19:57 244 --ah----- C:\sqmnoopt02.sqm
    2008-04-06 19:57 . 2008-04-06 19:57 232 --ah----- C:\sqmdata00.sqm
    2008-04-06 19:57 . 2008-04-06 19:57 0 --a------ C:\WINDOWS\system32\real.MSNFix
    2008-04-06 19:36 . 2008-04-07 13:11 <REP> d-------- C:\MSNFix
    2008-04-06 19:35 . 2008-04-06 20:45 <REP> d-------- C:\SDFix
    2008-04-06 19:28 . 2008-04-06 19:28 <REP> d-------- C:\WINDOWS\ERUNT
    2008-03-22 20:20 . 2008-03-22 20:20 <REP> d-------- C:\Program Files\Unphuck
    2008-03-22 20:20 . 2008-03-22 20:20 249,856 --------- C:\WINDOWS\Setup1.exe
    2008-03-22 20:20 . 2008-03-22 20:20 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
    2008-03-20 10:09 . 2008-03-20 10:09 1,845,376 --------- C:\WINDOWS\system32\dllcache\win32k.sys

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-04-06 19:55 --------- d-----w C:\Program Files\MSN Messenger
    2008-04-06 19:55 --------- d-----w C:\Program Files\MessengerDiscovery
    2008-04-06 19:52 --------- d-----w C:\Program Files\eMule
    2008-04-06 19:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-04-06 12:15 --------- d-----w C:\Program Files\RocketDock
    2008-04-03 09:41 --------- d-----w C:\Documents and Settings\Alex\Application Data\BitTorrent
    2008-03-31 12:04 --------- d-----w C:\Program Files\adslTV
    2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
    2008-03-11 06:05 --------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
    2008-03-09 22:15 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-03-09 09:33 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
    2008-03-09 09:32 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
    2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
    2008-02-20 06:51 282,624 ------w C:\WINDOWS\system32\dllcache\gdi32.dll
    2008-02-20 05:35 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
    2008-02-20 05:35 45,568 ------w C:\WINDOWS\system32\dllcache\dnsrslvr.dll
    2008-02-20 05:35 148,992 ------w C:\WINDOWS\system32\dllcache\dnsapi.dll
    2008-02-16 22:32 3,080,704 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
    2008-02-15 09:23 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe
    2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
    2007-02-04 10:44 1 ----a-w C:\Documents and Settings\Alex\SI.bin
    2006-11-21 17:22 1,505,792 ----a-w C:\WINDOWS\Fonts\VistaPerfection\Shell\WFVP48PX\Shellstyle.dll
    2006-11-21 17:22 1,505,792 ----a-w C:\WINDOWS\Fonts\VistaPerfection\Shell\NormalColor\Shellstyle.dll
    2005-01-17 20:51 76 ---ha-w C:\Program Files\Desktop.ini
    .

    ((((((((((((((((((((((((((((( snapshot@2008-04-09_22.58.06.18 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2008-03-20 07:56:50 1,846,016 ----a-w C:\WINDOWS\$hf_mig$\KB941693\SP2QFE\win32k.sys
    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spmsg.dll
    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB941693\spuninst.exe
    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\spcustom.dll
    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\update.exe
    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB941693\update\updspapi.dll
    + 2007-12-18 14:32:57 450,560 ----a-w C:\WINDOWS\$hf_mig$\KB944338\SP2QFE\jscript.dll
    + 2007-12-18 14:32:57 417,792 ----a-w C:\WINDOWS\$hf_mig$\KB944338\SP2QFE\vbscript.dll
    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB944338\spmsg.dll
    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB944338\spuninst.exe
    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB944338\update\spcustom.dll
    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB944338\update\update.exe
    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB944338\update\updspapi.dll
    + 2008-02-20 05:20:23 147,968 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsapi.dll
    + 2008-02-20 18:50:24 45,568 ----a-w C:\WINDOWS\$hf_mig$\KB945553\SP2QFE\dnsrslvr.dll
    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spmsg.dll
    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB945553\spuninst.exe
    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\spcustom.dll
    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\update.exe
    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB945553\update\updspapi.dll
    + 2008-02-16 09:31:57 1,024,512 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\browseui.dll
    + 2008-02-16 09:31:57 152,064 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\cdfview.dll
    + 2008-02-16 09:31:58 1,056,768 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\danim.dll
    + 2008-02-16 09:31:58 357,888 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\dxtmsft.dll
    + 2008-02-16 09:31:58 205,312 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\dxtrans.dll
    + 2008-02-16 09:31:58 55,808 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\extmgr.dll
    + 2008-02-15 09:07:53 18,432 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\iedw.exe
    + 2008-02-16 09:31:58 251,904 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\iepeers.dll
    + 2008-02-16 09:31:58 96,768 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\inseng.dll
    + 2008-02-16 09:31:58 16,384 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\jsproxy.dll
    + 2008-02-16 09:31:59 3,087,872 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\mshtml.dll
    + 2008-02-16 09:31:59 449,024 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\mshtmled.dll
    + 2008-02-16 09:31:59 146,432 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\msrating.dll
    + 2008-02-16 09:31:59 532,480 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\mstime.dll
    + 2008-02-16 09:31:59 39,424 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\pngfilt.dll
    + 2008-02-16 09:32:00 1,499,648 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\shdocvw.dll
    + 2008-02-16 09:32:00 474,624 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\shlwapi.dll
    + 2008-02-15 23:03:14 370,176 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\spru040c.dll
    + 2008-02-16 09:32:00 620,544 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\urlmon.dll
    + 2008-02-16 09:32:00 670,208 ----a-w C:\WINDOWS\$hf_mig$\KB947864\SP2QFE\wininet.dll
    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB947864\spmsg.dll
    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB947864\spuninst.exe
    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB947864\update\spcustom.dll
    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB947864\update\update.exe
    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB947864\update\updspapi.dll
    + 2008-02-20 06:52:42 282,624 ----a-w C:\WINDOWS\$hf_mig$\KB948590\SP2QFE\gdi32.dll
    + 2007-03-06 01:34:33 15,072 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spmsg.dll
    + 2007-03-06 01:34:38 216,800 ----a-w C:\WINDOWS\$hf_mig$\KB948590\spuninst.exe
    + 2007-03-06 01:34:31 22,752 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\spcustom.dll
    + 2007-03-06 01:34:56 727,776 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\update.exe
    + 2007-03-06 01:35:48 394,976 ----a-w C:\WINDOWS\$hf_mig$\KB948590\update\updspapi.dll
    - 2008-03-16 09:30:08 593,920 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
    + 2008-04-10 10:12:48 593,920 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\accicons.exe
    - 2008-03-16 09:30:08 12,288 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    + 2008-04-10 10:12:48 12,288 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\cagicon.exe
    - 2008-03-16 09:30:08 86,016 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
    + 2008-04-10 10:12:48 86,016 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\inficon.exe
    - 2008-03-16 09:30:08 135,168 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
    + 2008-04-10 10:12:48 135,168 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\misc.exe
    - 2008-03-16 09:30:08 11,264 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    + 2008-04-10 10:12:48 11,264 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\mspicons.exe
    - 2008-03-16 09:30:08 27,136 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    + 2008-04-10 10:12:49 27,136 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\oisicon.exe
    - 2008-03-16 09:30:08 4,096 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    + 2008-04-10 10:12:49 4,096 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\opwicon.exe
    - 2008-03-16 09:30:08 794,624 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
    + 2008-04-10 10:12:49 794,624 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\outicon.exe
    - 2008-03-16 09:30:08 249,856 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
    + 2008-04-10 10:12:48 249,856 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pptico.exe
    - 2008-03-16 09:30:08 61,440 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
    + 2008-04-10 10:12:48 61,440 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\pubs.exe
    - 2008-03-16 09:30:08 23,040 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    + 2008-04-10 10:12:49 23,040 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\unbndico.exe
    - 2008-03-16 09:30:08 286,720 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    + 2008-04-10 10:12:48 286,720 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\wordicon.exe
    - 2008-03-16 09:30:08 409,600 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    + 2008-04-10 10:12:48 409,600 ----a-r C:\WINDOWS\Installer\{9011040C-6000-11D3-8CFE-0150048383C9}\xlicons.exe
    - 2007-12-07 01:07:03 1,024,000 ----a-w C:\WINDOWS\system32\browseui.dll
    + 2008-02-16 09:02:34 1,024,000 ----a-w C:\WINDOWS\system32\browseui.dll
    - 2007-12-07 01:07:03 152,064 ----a-w C:\WINDOWS\system32\cdfview.dll
    + 2008-02-16 09:02:34 152,064 ----a-w C:\WINDOWS\system32\cdfview.dll
    - 2007-12-07 01:07:03 1,056,768 ----a-w C:\WINDOWS\system32\danim.dll
    + 2008-02-16 09:02:34 1,056,768 ----a-w C:\WINDOWS\system32\danim.dll
    - 2007-12-07 01:07:03 1,024,000 ------w C:\WINDOWS\system32\dllcache\browseui.dll
    + 2008-02-16 09:02:34 1,024,000 ------w C:\WINDOWS\system32\dllcache\browseui.dll
    - 2007-12-07 01:07:03 152,064 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
    + 2008-02-16 09:02:34 152,064 ------w C:\WINDOWS\system32\dllcache\cdfview.dll
    - 2007-12-07 01:07:03 1,056,768 ------w C:\WINDOWS\system32\dllcache\danim.dll
    + 2008-02-16 09:02:34 1,056,768 ------w C:\WINDOWS\system32\dllcache\danim.dll
    - 2007-12-07 01:07:03 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
    + 2008-02-16 09:02:34 357,888 ------w C:\WINDOWS\system32\dllcache\dxtmsft.dll
    - 2007-12-07 01:07:03 205,312 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
    + 2008-02-16 09:02:35 205,312 ------w C:\WINDOWS\system32\dllcache\dxtrans.dll
    - 2007-12-07 01:07:04 55,808 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
    + 2008-02-16 09:02:35 55,808 ------w C:\WINDOWS\system32\dllcache\extmgr.dll
    - 2007-12-07 01:07:04 251,392 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
    + 2008-02-16 09:02:35 251,392 ------w C:\WINDOWS\system32\dllcache\iepeers.dll
    - 2007-12-07 01:07:04 96,768 ------w C:\WINDOWS\system32\dllcache\inseng.dll
    + 2008-02-16 09:02:35 96,768 ------w C:\WINDOWS\system32\dllcache\inseng.dll
    - 2007-11-14 07:28:02 450,560 ------w C:\WINDOWS\system32\dllcache\jscript.dll
    + 2007-12-18 14:41:58 450,560 ------w C:\WINDOWS\system32\dllcache\jscript.dll
    - 2007-12-07 01:07:04 16,384 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
    + 2008-02-16 09:02:35 16,384 ------w C:\WINDOWS\system32\dllcache\jsproxy.dll
    - 2007-12-07 01:07:04 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
    + 2008-02-16 09:02:36 449,024 ------w C:\WINDOWS\system32\dllcache\mshtmled.dll
    - 2007-12-07 01:07:04 146,432 ------w C:\WINDOWS\system32\dllcache\msrating.dll
    + 2008-02-16 09:02:37 146,432 ------w C:\WINDOWS\system32\dllcache\msrating.dll
    - 2007-12-07 01:07:04 532,480 ------w C:\WINDOWS\system32\dllcache\mstime.dll
    + 2008-02-16 09:02:37 532,480 ------w C:\WINDOWS\system32\dllcache\mstime.dll
    - 2007-12-07 01:07:04 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
    + 2008-02-16 09:02:37 39,424 ------w C:\WINDOWS\system32\dllcache\pngfilt.dll
    - 2007-12-07 01:07:05 1,495,040 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
    + 2008-02-16 09:02:38 1,495,040 ------w C:\WINDOWS\system32\dllcache\shdocvw.dll
    - 2007-12-07 01:07:05 474,624 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
    + 2008-02-16 09:02:38 474,624 ------w C:\WINDOWS\system32\dllcache\shlwapi.dll
    - 2007-12-07 01:07:05 617,472 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
    + 2008-02-16 09:02:39 617,984 ------w C:\WINDOWS\system32\dllcache\urlmon.dll
    + 2007-12-18 14:41:59 417,792 ------w C:\WINDOWS\system32\dllcache\vbscript.dll
    - 2007-12-07 01:07:05 663,552 ------w C:\WINDOWS\system32\dllcache\wininet.dll
    + 2008-02-16 09:02:39 663,552 ------w C:\WINDOWS\system32\dllcache\wininet.dll
    - 2006-06-26 18:41:32 148,480 ----a-w C:\WINDOWS\system32\dnsapi.dll
    + 2008-02-20 05:35:05 148,992 ----a-w C:\WINDOWS\system32\dnsapi.dll
    - 2007-12-07 01:07:03 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
    + 2008-02-16 09:02:34 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
    - 2007-12-07 01:07:03 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
    + 2008-02-16 09:02:35 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
    - 2007-12-07 01:07:04 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
    + 2008-02-16 09:02:35 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
    - 2008-03-31 08:17:34 224,024 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
    + 2008-04-10 18:32:29 224,024 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
    - 2007-12-07 01:07:04 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
    + 2008-02-16 09:02:35 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
    - 2007-12-07 01:07:04 96,768 ----a-w C:\WINDOWS\system32\inseng.dll
    + 2008-02-16 09:02:35 96,768 ----a-w C:\WINDOWS\system32\inseng.dll
    - 2007-11-14 07:28:02 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
    + 2007-12-18 14:41:58 450,560 ----a-w C:\WINDOWS\system32\jscript.dll
    - 2007-12-07 01:07:04 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
    + 2008-02-16 09:02:35 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
    - 2008-03-05 16:30:54 19,148,408 ----a-w C:\WINDOWS\system32\MRT.exe
    + 2008-04-06 05:56:20 19,836,024 ----a-w C:\WINDOWS\system32\MRT.exe
    - 2007-12-07 14:37:06 3,080,192 ----a-w C:\WINDOWS\system32\mshtml.dll
    + 2008-02-16 22:32:38 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll
    - 2007-12-07 01:07:04 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
    + 2008-02-16 09:02:36 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
    - 2007-12-07 01:07:04 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
    + 2008-02-16 09:02:37 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
    - 2007-12-07 01:07:04 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
    + 2008-02-16 09:02:37 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
    - 2007-12-07 01:07:04 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
    + 2008-02-16 09:02:37 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
    - 2007-12-07 01:07:05 1,495,040 ----a-w C:\WINDOWS\system32\shdocvw.dll
    + 2008-02-16 09:02:38 1,495,040 ----a-w C:\WINDOWS\system32\shdocvw.dll
    - 2007-12-07 01:07:05 474,624 ----a-w C:\WINDOWS\system32\shlwapi.dll
    + 2008-02-16 09:02:38 474,624 ----a-w C:\WINDOWS\system32\shlwapi.dll
    - 2007-12-07 01:07:05 617,472 ----a-w C:\WINDOWS\system32\urlmon.dll
    + 2008-02-16 09:02:39 617,984 ----a-w C:\WINDOWS\system32\urlmon.dll
    - 2004-08-19 15:09:48 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
    + 2007-12-18 14:41:59 417,792 ----a-w C:\WINDOWS\system32\vbscript.dll
    - 2007-12-07 01:07:05 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
    + 2008-02-16 09:02:39 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
    - 2007-12-06 23:40:30 369,152 ----a-w C:\WINDOWS\system32\xpsp3res.dll
    + 2008-02-15 23:03:14 370,176 ----a-w C:\WINDOWS\system32\xpsp3res.dll
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-01-28 04:55 462848]
    "H/PC Connection Agent"="D:\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 21:45 1211176]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AVPCC"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" [2004-09-03 19:33 495729]
    "PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2005-01-26 15:52 635904]
    "NvMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 21:51 131072]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 16:44 101136 C:\WINDOWS\KHALMNPR.Exe]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
    "nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="NvMCTray.dll" [2006-10-22 12:22 86016 C:\WINDOWS\system32\nvmctray.dll]
    "LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 16:02 563984]
    "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 16:06 2027792]
    "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-03-01 07:10 15872]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 17:09 15360]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

    C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2007-05-05 12:59:27 Alex 688128]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoResolveTrack"= 1 (0x1)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSimpleStartMenu"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "UIHost"="vistalogonui.exe"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Jeux classiques\\Bin\\CmCenterV2.exe"=
    "C:\\Program Files\\Fichiers communs\\KAV Shared Files\\avpupd.exe"=
    "C:\\Program Files\\eMule\\emule.exe"=
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "C:\\Program Files\\mIRC\\mirc.exe"=
    "C:\\WINDOWS\\System32\\RUNDLL32.EXE"=
    "C:\\WINDOWS\\System32\\dpvsetup.exe"=
    "C:\\Program Files\\Opera\\Opera.exe"=
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
    "C:\\Program Files\\MessengerDiscovery\\Loader.exe"=
    "C:\\Program Files\\adslTV\\adslTV.exe"=
    "C:\\Program Files\\adslTV\\vlc.exe"=
    "C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
    "C:\\WINDOWS\\system32\\dplaysvr.exe"=
    "E:\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
    "D:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
    "D:\Microsoft ActiveSync\rapimgr.exe"= D:\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "D:\Microsoft ActiveSync\wcescomm.exe"= D:\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "D:\Microsoft ActiveSync\WCESMgr.exe"= D:\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "E:\\Pro Evolution Soccer 2008\\PES2008.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "47624:TCP"= 47624:TCP:BG
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R0 Copystar;Copystar;C:\WINDOWS\system32\DRIVERS\copystar.sys [2002-06-01 16:37]
    R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\PStrip.sys [2004-11-10 00:32]
    R3 3xHybrid;Pinnacle PCTV Stereo service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2003-12-05 13:56]
    R3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys [2002-11-11 19:52]
    S2 AVPCC;AVP Control Centre Service;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /service []
    S2 KAVMonitorService;KAV Monitor Service;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe" /service []
    S3 danceflt;XboxCtrl_filt_Service;C:\WINDOWS\system32\DRIVERS\danceflt.sys [2005-09-28 15:22]
    S3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys [2001-08-17 21:19]
    S3 HabuFltr;Habu Mouse;C:\WINDOWS\system32\drivers\habu.sys [2006-08-14 11:21]
    S3 hid8106;hid8106;C:\WINDOWS\system32\drivers\hid8106.sys [2006-11-17 11:35]
    S3 MBAMCatchMe;MBAMCatchMe;C:\Program Files\Malwarebytes' Anti-Malware\catchme.sys [2008-04-01 19:54]
    S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 18:57]
    S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 18:58]
    S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 18:59]
    S3 USB11LDR;M-Audio USB Uno Loader;C:\WINDOWS\system32\drivers\usb11ldr.sys []
    S3 USBMN1X1;M-Audio USB Uno MIDI Driver;C:\WINDOWS\system32\drivers\usbmn1x1.sys []

    .
    **************************************************************************

    catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-04-11 20:29:28
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************
    .
    --------------------- DLLs a chargé sous des processus courants ---------------------

    PROCESS: C:\WINDOWS\explorer.exe
    -> C:\Program Files\RocketDock\RocketDock.dll
    -> C:\Program Files\Unlocker\UnlockerHook.dll
    .
    Temps d'accomplissement: 2008-04-11 20:29:57
    ComboFix-quarantined-files.txt 2008-04-11 18:29:52
    ComboFix2.txt 2008-04-09 20:58:29
    Pre-Run: 9,604,807,680 octets libres
    Post-Run: 9,591,376,384 octets libres
    .
    2008-04-10 10:13:11 --- E O F ---
    a b 8 Sécurité
    11 Avril 2008 20:52:03

    Re,

    [#ff0000]Désactive tes protections résidentes (antivirus...) ![/#f]
    Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :

    File::
    C:\WINDOWS\system32\eqgwqt.exe
    C:\WINDOWS\system32\prwzys.exe
    C:\Documents and Settings\Alex\gxsokz.exe


    Ouvre le Bloc-Notes puis colle (Ctrl+V) le texte précedemment copié.
    Sauvegarde ce fichier sous le nom de CFScript.txt.

    Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :


    Cela va relancer Combofix, tape sur 1 puis valide. Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
    [#ff0000]NOTE : S'il n'y a pas de rédémarrage, poste quand même les rapports demandés.[/#f]
    11 Avril 2008 22:21:36

    Nouveau log Combofix après manip avec le .txt:


    ComboFix 08-04-09.1 - Alex 2008-04-09 22:52:50.1 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.662 [GMT 2:00]
    Endroit: C:\Documents and Settings\Alex\Bureau\ComboFix.exe

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\Alex\real.txt
    C:\WINDOWS\mrofinu1423.exe.tmp
    C:\WINDOWS\system32\%%%.exe
    C:\WINDOWS\system32\real.txt

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-09 to 2008-04-09 ))))))))))))))))))))))))))))))))))))
    .

    2008-04-08 01:20 . 2008-04-08 01:20 37,376 --a------ C:\WINDOWS\17PHolmes1423.exe
    2008-04-08 01:20 . 2008-04-08 01:20 9,296 --a------ C:\WINDOWS\system32\eqgwqt.exe
    2008-04-08 01:20 . 2008-04-08 01:20 244 --ah----- C:\sqmnoopt09.sqm
    2008-04-08 01:20 . 2008-04-08 01:20 232 --ah----- C:\sqmdata07.sqm
    2008-04-07 19:20 . 2008-04-07 19:20 9,296 --a------ C:\WINDOWS\system32\prwzys.exe
    2008-04-07 19:19 . 2008-04-07 19:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-04-07 19:19 . 2008-04-07 19:19 <REP> d-------- C:\Documents and Settings\Alex\Application Data\Malwarebytes
    2008-04-07 19:18 . 2008-04-07 19:19 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-04-07 13:14 . 2008-04-07 13:14 9,296 --a------ C:\Documents and Settings\Alex\gxsokz.exe
    2008-04-07 12:20 . 2008-04-07 12:20 244 --ah----- C:\sqmnoopt08.sqm
    2008-04-07 12:20 . 2008-04-07 12:20 232 --ah----- C:\sqmdata06.sqm
    2008-04-07 12:06 . 2008-04-07 12:06 244 --ah----- C:\sqmnoopt07.sqm
    2008-04-07 12:06 . 2008-04-07 12:06 232 --ah----- C:\sqmdata05.sqm
    2008-04-07 01:47 . 2008-04-07 01:47 244 --ah----- C:\sqmnoopt06.sqm
    2008-04-07 01:47 . 2008-04-07 01:47 232 --ah----- C:\sqmdata04.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 244 --ah----- C:\sqmnoopt05.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 244 --ah----- C:\sqmnoopt04.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 232 --ah----- C:\sqmdata03.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 232 --ah----- C:\sqmdata02.sqm
    2008-04-06 22:43 . 2008-04-06 22:43 244 --ah----- C:\sqmnoopt03.sqm
    2008-04-06 22:43 . 2008-04-06 22:43 232 --ah----- C:\sqmdata01.sqm
    2008-04-06 22:35 . 2008-04-06 22:35 <REP> d-------- C:\msc
    2008-04-06 21:59 . 2008-04-06 22:09 <REP> d-------- C:\Program Files\StuffPlug3
    2008-04-06 21:47 . 2008-04-06 21:52 <REP> d-------- C:\Program Files\Windows Live
    2008-04-06 20:54 . 2008-04-06 20:55 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-04-06 20:54 . 2008-04-06 21:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-04-06 20:50 . 2008-04-06 20:51 <REP> d-------- C:\Program Files\Unlocker
    2008-04-06 19:57 . 2008-04-06 19:57 244 --ah----- C:\sqmnoopt02.sqm
    2008-04-06 19:57 . 2008-04-06 19:57 232 --ah----- C:\sqmdata00.sqm
    2008-04-06 19:57 . 2008-04-06 19:57 0 --a------ C:\WINDOWS\system32\real.MSNFix
    2008-04-06 19:36 . 2008-04-07 13:11 <REP> d-------- C:\MSNFix
    2008-04-06 19:35 . 2008-04-06 20:45 <REP> d-------- C:\SDFix
    2008-04-06 19:28 . 2008-04-06 19:28 <REP> d-------- C:\WINDOWS\ERUNT
    2008-03-22 20:20 . 2008-03-22 20:20 <REP> d-------- C:\Program Files\Unphuck
    2008-03-22 20:20 . 2008-03-22 20:20 249,856 --------- C:\WINDOWS\Setup1.exe
    2008-03-22 20:20 . 2008-03-22 20:20 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
    2008-03-10 00:15 . 2008-03-10 00:15 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-03-09 16:46 . 2007-07-30 20:19 271,224 --a------ C:\WINDOWS\system32\mucltui.dll
    2008-03-09 16:46 . 2007-07-30 20:19 207,736 --a------ C:\WINDOWS\system32\muweb.dll
    2008-03-09 16:46 . 2007-07-30 20:18 30,072 --a------ C:\WINDOWS\system32\mucltui.dll.mui
    2008-03-09 11:33 . 2008-03-09 11:33 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
    2008-03-09 11:23 . 2008-03-09 11:32 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
    2008-03-09 11:22 . 2008-04-06 21:47 <REP> d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-04-06 19:55 --------- d-----w C:\Program Files\MSN Messenger
    2008-04-06 19:55 --------- d-----w C:\Program Files\MessengerDiscovery
    2008-04-06 19:52 --------- d-----w C:\Program Files\eMule
    2008-04-06 12:15 --------- d-----w C:\Program Files\RocketDock
    2008-04-03 09:41 --------- d-----w C:\Documents and Settings\Alex\Application Data\BitTorrent
    2008-03-31 12:04 --------- d-----w C:\Program Files\adslTV
    2008-03-11 06:05 --------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
    2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
    2007-02-04 10:44 1 ----a-w C:\Documents and Settings\Alex\SI.bin
    2006-11-21 17:22 1,505,792 ----a-w C:\WINDOWS\Fonts\VistaPerfection\Shell\WFVP48PX\Shellstyle.dll
    2006-11-21 17:22 1,505,792 ----a-w C:\WINDOWS\Fonts\VistaPerfection\Shell\NormalColor\Shellstyle.dll
    2005-01-17 20:51 76 ---ha-w C:\Program Files\Desktop.ini
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-01-28 04:55 462848]
    "H/PC Connection Agent"="D:\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 21:45 1211176]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AVPCC"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" [2004-09-03 19:33 495729]
    "PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2005-01-26 15:52 635904]
    "NvMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 21:51 131072]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 16:44 101136 C:\WINDOWS\KHALMNPR.Exe]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
    "nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="NvMCTray.dll" [2006-10-22 12:22 86016 C:\WINDOWS\system32\nvmctray.dll]
    "LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 16:02 563984]
    "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 16:06 2027792]
    "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-03-01 07:10 15872]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 17:09 15360]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoResolveTrack"= 1 (0x1)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSimpleStartMenu"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "UIHost"="vistalogonui.exe"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Jeux classiques\\Bin\\CmCenterV2.exe"=
    "C:\\Program Files\\Fichiers communs\\KAV Shared Files\\avpupd.exe"=
    "C:\\Program Files\\eMule\\emule.exe"=
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "C:\\Program Files\\mIRC\\mirc.exe"=
    "C:\\WINDOWS\\System32\\RUNDLL32.EXE"=
    "C:\\WINDOWS\\System32\\dpvsetup.exe"=
    "C:\\Program Files\\Opera\\Opera.exe"=
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
    "C:\\Program Files\\MessengerDiscovery\\Loader.exe"=
    "C:\\Program Files\\adslTV\\adslTV.exe"=
    "C:\\Program Files\\adslTV\\vlc.exe"=
    "C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
    "C:\\WINDOWS\\system32\\dplaysvr.exe"=
    "E:\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
    "D:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
    "D:\Microsoft ActiveSync\rapimgr.exe"= D:\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "D:\Microsoft ActiveSync\wcescomm.exe"= D:\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "D:\Microsoft ActiveSync\WCESMgr.exe"= D:\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "E:\\Pro Evolution Soccer 2008\\PES2008.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "47624:TCP"= 47624:TCP:BG
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R0 Copystar;Copystar;C:\WINDOWS\system32\DRIVERS\copystar.sys [2002-06-01 16:37]
    R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\PStrip.sys [2004-11-10 00:32]
    R3 3xHybrid;Pinnacle PCTV Stereo service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2003-12-05 13:56]
    R3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys [2002-11-11 19:52]
    S2 AVPCC;AVP Control Centre Service;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /service []
    S2 KAVMonitorService;KAV Monitor Service;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe" /service []
    S3 danceflt;XboxCtrl_filt_Service;C:\WINDOWS\system32\DRIVERS\danceflt.sys [2005-09-28 15:22]
    S3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys [2001-08-17 21:19]
    S3 HabuFltr;Habu Mouse;C:\WINDOWS\system32\drivers\habu.sys [2006-08-14 11:21]
    S3 hid8106;hid8106;C:\WINDOWS\system32\drivers\hid8106.sys [2006-11-17 11:35]
    S3 MBAMCatchMe;MBAMCatchMe;C:\Program Files\Malwarebytes' Anti-Malware\catchme.sys [2008-04-01 19:54]
    S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 18:57]
    S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 18:58]
    S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 18:59]
    S3 USB11LDR;M-Audio USB Uno Loader;C:\WINDOWS\system32\drivers\usb11ldr.sys []
    S3 USBMN1X1;M-Audio USB Uno MIDI Driver;C:\WINDOWS\system32\drivers\usbmn1x1.sys []

    .
    **************************************************************************

    catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-04-09 22:56:52
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 0

    **************************************************************************
    .
    --------------------- DLLs a charg‚ sous des processus courants ---------------------

    PROCESS: C:\WINDOWS\explorer.exe
    -> C:\Program Files\RocketDock\RocketDock.dll
    -> C:\Program Files\Unlocker\UnlockerHook.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    D:\MICROS~1\rapimgr.exe
    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-04-09 22:58:28 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-04-09 20:58:21
    Pre-Run: 9,823,426,048 octets libres
    Post-Run: 9,708,162,560 octets libres
    .
    2008-03-16 09:31:14 --- E O F ---



    Nouveau rapport Hijack:


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at Alex - 22:23:28, on 11/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\program files\powerstrip\pstrip.exe
    C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\RocketDock\RocketDock.exe
    D:\Microsoft ActiveSync\wcescomm.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    D:\MICROS~1\rapimgr.exe
    C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Opera\Opera.exe
    D:\Vundoscan.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {04F4BD15-534C-1958-C0D5-7818DAEC025A} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /wait
    O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
    O4 - HKLM\..\Run: [NvMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr/
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AVP Control Centre Service (AVPCC) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: KAV Monitor Service (KAVMonitorService) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 6397 bytes
    a b 8 Sécurité
    11 Avril 2008 22:24:10

    Recommence avec ce script :

    Rootkit::
    C:\WINDOWS\system32\eqgwqt.exe
    C:\WINDOWS\system32\prwzys.exe
    C:\Documents and Settings\Alex\gxsokz.exe
    11 Avril 2008 23:13:26

    Nouveau rapport Combofix avec nouveau script, cette fois mon pc a reboot à la fin:


    ComboFix 08-04-09.1 - Alex 2008-04-11 23:07:39.4 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.607 [GMT 2:00]
    Endroit: C:\Documents and Settings\Alex\Bureau\ComboFix.exe
    Command switches used :: C:\Documents and Settings\Alex\Bureau\CFScript.txt
    * Création d'un nouveau point de restauration

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\Alex\gxsokz.exe
    C:\WINDOWS\system32\eqgwqt.exe
    C:\WINDOWS\system32\prwzys.exe

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-03-11 to 2008-04-11 ))))))))))))))))))))))))))))))))))))
    .

    2008-04-10 12:11 . 2008-04-10 12:13 1,374 --a------ C:\WINDOWS\imsins.BAK
    2008-04-08 01:20 . 2008-04-08 01:20 244 --ah----- C:\sqmnoopt09.sqm
    2008-04-08 01:20 . 2008-04-08 01:20 232 --ah----- C:\sqmdata07.sqm
    2008-04-07 19:19 . 2008-04-07 19:19 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-04-07 19:19 . 2008-04-07 19:19 <REP> d-------- C:\Documents and Settings\Alex\Application Data\Malwarebytes
    2008-04-07 19:18 . 2008-04-07 19:19 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-04-07 12:20 . 2008-04-07 12:20 244 --ah----- C:\sqmnoopt08.sqm
    2008-04-07 12:20 . 2008-04-07 12:20 232 --ah----- C:\sqmdata06.sqm
    2008-04-07 12:06 . 2008-04-07 12:06 244 --ah----- C:\sqmnoopt07.sqm
    2008-04-07 12:06 . 2008-04-07 12:06 232 --ah----- C:\sqmdata05.sqm
    2008-04-07 01:47 . 2008-04-07 01:47 244 --ah----- C:\sqmnoopt06.sqm
    2008-04-07 01:47 . 2008-04-07 01:47 232 --ah----- C:\sqmdata04.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 244 --ah----- C:\sqmnoopt05.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 244 --ah----- C:\sqmnoopt04.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 232 --ah----- C:\sqmdata03.sqm
    2008-04-06 23:16 . 2008-04-06 23:16 232 --ah----- C:\sqmdata02.sqm
    2008-04-06 22:43 . 2008-04-06 22:43 244 --ah----- C:\sqmnoopt03.sqm
    2008-04-06 22:43 . 2008-04-06 22:43 232 --ah----- C:\sqmdata01.sqm
    2008-04-06 22:35 . 2008-04-06 22:35 <REP> d-------- C:\msc
    2008-04-06 21:59 . 2008-04-06 22:09 <REP> d-------- C:\Program Files\StuffPlug3
    2008-04-06 21:47 . 2008-04-06 21:52 <REP> d-------- C:\Program Files\Windows Live
    2008-04-06 20:54 . 2008-04-06 20:55 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-04-06 20:54 . 2008-04-06 21:37 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-04-06 20:50 . 2008-04-06 20:51 <REP> d-------- C:\Program Files\Unlocker
    2008-04-06 19:57 . 2008-04-06 19:57 244 --ah----- C:\sqmnoopt02.sqm
    2008-04-06 19:57 . 2008-04-06 19:57 232 --ah----- C:\sqmdata00.sqm
    2008-04-06 19:57 . 2008-04-06 19:57 0 --a------ C:\WINDOWS\system32\real.MSNFix
    2008-04-06 19:36 . 2008-04-07 13:11 <REP> d-------- C:\MSNFix
    2008-04-06 19:35 . 2008-04-06 20:45 <REP> d-------- C:\SDFix
    2008-04-06 19:28 . 2008-04-06 19:28 <REP> d-------- C:\WINDOWS\ERUNT
    2008-03-22 20:20 . 2008-03-22 20:20 <REP> d-------- C:\Program Files\Unphuck
    2008-03-22 20:20 . 2008-03-22 20:20 249,856 --------- C:\WINDOWS\Setup1.exe
    2008-03-22 20:20 . 2008-03-22 20:20 73,216 --a------ C:\WINDOWS\ST6UNST.EXE
    2008-03-20 10:09 . 2008-03-20 10:09 1,845,376 --------- C:\WINDOWS\system32\dllcache\win32k.sys

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-04-11 21:06 --------- d-----w C:\Program Files\eMule
    2008-04-06 19:55 --------- d-----w C:\Program Files\MSN Messenger
    2008-04-06 19:55 --------- d-----w C:\Program Files\MessengerDiscovery
    2008-04-06 19:47 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
    2008-04-06 12:15 --------- d-----w C:\Program Files\RocketDock
    2008-04-03 09:41 --------- d-----w C:\Documents and Settings\Alex\Application Data\BitTorrent
    2008-03-31 12:04 --------- d-----w C:\Program Files\adslTV
    2008-03-11 06:05 --------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
    2008-03-09 22:15 --------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
    2008-03-09 09:33 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
    2008-03-09 09:32 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
    2008-02-01 10:17 587,264 ----a-w C:\WINDOWS\WLXPGSS.SCR
    2007-02-04 10:44 1 ----a-w C:\Documents and Settings\Alex\SI.bin
    2006-11-21 17:22 1,505,792 ----a-w C:\WINDOWS\Fonts\VistaPerfection\Shell\WFVP48PX\Shellstyle.dll
    2006-11-21 17:22 1,505,792 ----a-w C:\WINDOWS\Fonts\VistaPerfection\Shell\NormalColor\Shellstyle.dll
    2005-01-17 20:51 76 ---ha-w C:\Program Files\Desktop.ini
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-01-28 04:55 462848]
    "H/PC Connection Agent"="D:\Microsoft ActiveSync\wcescomm.exe" [2006-06-26 21:45 1211176]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AVPCC"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" [2004-09-03 19:33 495729]
    "PowerStrip"="c:\program files\powerstrip\pstrip.exe" [2005-01-26 15:52 635904]
    "NvMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 21:51 131072]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-01-23 16:44 101136 C:\WINDOWS\KHALMNPR.Exe]
    "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 12:22 7700480]
    "nwiz"="nwiz.exe" [2006-10-22 12:22 1622016 C:\WINDOWS\system32\nwiz.exe]
    "NvMediaCenter"="NvMCTray.dll" [2006-10-22 12:22 86016 C:\WINDOWS\system32\nvmctray.dll]
    "LogitechCommunicationsManager"="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-07-25 16:02 563984]
    "LogitechQuickCamRibbon"="C:\Program Files\Logitech\QuickCam\Quickcam.exe" [2007-07-25 16:06 2027792]
    "UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [2008-03-01 07:10 15872]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 17:09 15360]
    "msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoResolveTrack"= 1 (0x1)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoSimpleStartMenu"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "UIHost"="vistalogonui.exe"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
    @=""

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Jeux classiques\\Bin\\CmCenterV2.exe"=
    "C:\\Program Files\\Fichiers communs\\KAV Shared Files\\avpupd.exe"=
    "C:\\Program Files\\eMule\\emule.exe"=
    "C:\\Program Files\\BitTorrent\\bittorrent.exe"=
    "C:\\Program Files\\mIRC\\mirc.exe"=
    "C:\\WINDOWS\\System32\\RUNDLL32.EXE"=
    "C:\\WINDOWS\\System32\\dpvsetup.exe"=
    "C:\\Program Files\\Opera\\Opera.exe"=
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"=
    "C:\\Program Files\\MessengerDiscovery\\Loader.exe"=
    "C:\\Program Files\\adslTV\\adslTV.exe"=
    "C:\\Program Files\\adslTV\\vlc.exe"=
    "C:\\Program Files\\Freeplayer\\vlc\\vlc.exe"=
    "C:\\WINDOWS\\system32\\dplaysvr.exe"=
    "E:\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
    "D:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
    "D:\Microsoft ActiveSync\rapimgr.exe"= D:\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
    "D:\Microsoft ActiveSync\wcescomm.exe"= D:\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
    "D:\Microsoft ActiveSync\WCESMgr.exe"= D:\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
    "E:\\Pro Evolution Soccer 2008\\PES2008.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "47624:TCP"= 47624:TCP:BG
    "26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service

    R0 Copystar;Copystar;C:\WINDOWS\system32\DRIVERS\copystar.sys [2002-06-01 16:37]
    R2 AVPCC;AVP Control Centre Service;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /service []
    R2 KAVMonitorService;KAV Monitor Service;"C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe" /service []
    R2 PStrip;PStrip;C:\WINDOWS\system32\drivers\PStrip.sys [2004-11-10 00:32]
    R3 3xHybrid;Pinnacle PCTV Stereo service;C:\WINDOWS\system32\DRIVERS\3xHybrid.sys [2003-12-05 13:56]
    R3 pctvvbi;PCTVVBI;C:\WINDOWS\system32\DRIVERS\pctvvbi.sys [2002-11-11 19:52]
    S3 danceflt;XboxCtrl_filt_Service;C:\WINDOWS\system32\DRIVERS\danceflt.sys [2005-09-28 15:22]
    S3 ES1370;Creative AudioPCI (ES1370), SB PCI 64/128 (WDM);C:\WINDOWS\system32\drivers\ES1370MP.sys [2001-08-17 21:19]
    S3 HabuFltr;Habu Mouse;C:\WINDOWS\system32\drivers\habu.sys [2006-08-14 11:21]
    S3 hid8106;hid8106;C:\WINDOWS\system32\drivers\hid8106.sys [2006-11-17 11:35]
    S3 MBAMCatchMe;MBAMCatchMe;C:\Program Files\Malwarebytes' Anti-Malware\catchme.sys [2008-04-01 19:54]
    S3 ss_bus;SAMSUNG Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys [2005-08-30 18:57]
    S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys [2005-08-30 18:58]
    S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys [2005-08-30 18:59]
    S3 USB11LDR;M-Audio USB Uno Loader;C:\WINDOWS\system32\drivers\usb11ldr.sys []
    S3 USBMN1X1;M-Audio USB Uno MIDI Driver;C:\WINDOWS\system32\drivers\usbmn1x1.sys []

    .
    **************************************************************************

    catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-04-11 23:11:11
    Windows 5.1.2600 Service Pack 2 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 0

    **************************************************************************
    .
    --------------------- DLLs a charg‚ sous des processus courants ---------------------

    PROCESS: C:\WINDOWS\explorer.exe
    -> C:\Program Files\RocketDock\RocketDock.dll
    -> C:\Program Files\Unlocker\UnlockerHook.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    D:\MICROS~1\rapimgr.exe
    C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-04-11 23:13:28 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-04-11 21:13:19
    ComboFix2.txt 2008-04-11 20:22:54
    ComboFix3.txt 2008-04-11 18:29:58
    ComboFix4.txt 2008-04-09 20:58:29
    Pre-Run: 9,548,015,616 octets libres
    Post-Run: 9,530,225,664 octets libres
    .
    2008-04-10 10:13:11 --- E O F ---



    Nouveau rapport Hijack:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at Alex - 23:15:22, on 11/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
    C:\program files\powerstrip\pstrip.exe
    C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
    C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
    C:\Program Files\Logitech\QuickCam\Quickcam.exe
    C:\Program Files\Unlocker\UnlockerAssistant.exe
    C:\Program Files\RocketDock\RocketDock.exe
    D:\Microsoft ActiveSync\wcescomm.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Logitech\SetPoint\SetPoint.exe
    D:\MICROS~1\rapimgr.exe
    C:\Program Files\Fichiers communs\Logitech\khalshared\KHALMNPR.EXE
    C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
    C:\WINDOWS\explorer.exe
    C:\Program Files\Opera\Opera.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
    D:\Vundoscan.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {04F4BD15-534C-1958-C0D5-7818DAEC025A} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [AVPCC] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe" /wait
    O4 - HKLM\..\Run: [PowerStrip] c:\program files\powerstrip\pstrip.exe
    O4 - HKLM\..\Run: [NvMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
    O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
    O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -H
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\Microsoft ActiveSync\wcescomm.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Logitech SetPoint.lnk = ?
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
    O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - D:\MICROS~1\INetRepl.dll
    O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.google.fr/
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AVP Control Centre Service (AVPCC) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpcc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: KAV Monitor Service (KAVMonitorService) - Kaspersky Labs. - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal Pro\avpm.exe
    O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 6640 bytes
    a b 8 Sécurité
    12 Avril 2008 12:18:48

    Mieux ?
    12 Avril 2008 17:20:40

    Je dirais meme que cette fois ca parait parfait, kaspersky ne detecte plus rien et msn marche correctement.
    a b 8 Sécurité
    13 Avril 2008 11:10:12

    Bon surf !

  • Télécharge ToolsCleaner sur ton Bureau.
  • Clique sur Recherche et laisse le scan se terminer.
  • Clique sur Suppression pour finaliser.
  • Clique sur Quitter, pour que le rapport puisse se créer.
  • Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\)

    Désactive puis réactive la restauration du système : Voir aide

    Ajoute maintenant [Résolu] au titre. Pour cela :
    * Clique, dans ton premier message, sur le bouton "Editer"
    * Rajoute la mention [Résolu] au titre
    * Clique ensuite sur "Valider votre message"

    Lis le dossier dossier sur la prévention et la protection pour ne plus avoir ce genre de problème en cliquant sur l'image ci-dessous :


    Tom's guide dans le monde
    • Allemagne
    • Italie
    • Irlande
    • Royaume Uni
    • Etats Unis
    Suivre Tom's Guide
    Inscrivez-vous à la Newsletter
    • ajouter à twitter
    • ajouter à facebook
    • ajouter un flux RSS