Bonjour
ci joint les 3 rapports de la méthode préliminaire de désinfection
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 22:06:31 27/08/2007
+ Résultat de l'analyse:
HKU\S-1-5-21-3479383672-2939561921-2018322775-1005\Software\ShopperReports -> Adware.HotBar : Aucune action entreprise.
HKU\S-1-5-21-3479383672-2939561921-2018322775-1005\Software\ShopperReports\ShopperReports -> Adware.HotBar : Aucune action entreprise.
HKU\S-1-5-21-3479383672-2939561921-2018322775-1005\Software\ShopperReports\ShopperReports\PostInstaller -> Adware.HotBar : Aucune action entreprise.
C:\Documents and Settings\ANNE\Cookies\anne@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072515.DLL -> Worm.Warezov.oc : Aucune action entreprise.
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP595\A0066339.exe -> Worm.Warezov.op : Aucune action entreprise.
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP595\A0066338.exe -> Worm.Warezov.oq : Aucune action entreprise.
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072513.DLL -> Worm.Warezov.oq : Aucune action entreprise.
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072536.exe -> Worm.Warezov.oq : Aucune action entreprise.
C:\WINDOWS\system32\ero37s.exe -> Worm.Warezov.oq : Aucune action entreprise.
C:\WINDOWS\system32\sgwjaoif.dll -> Worm.Warezov.oq : Aucune action entreprise.
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072220.exe -> Worm.Warezov.zj : Aucune action entreprise.
C:\WINDOWS\system32\cabvconf.exe -> Worm.Warezov.zj : Aucune action entreprise.
C:\WINDOWS\system32\cetk5w3.exe -> Worm.Warezov.zm : Aucune action entreprise.
C:\WINDOWS\system32\kqvom22dv9.dll -> Worm.Warezov.zm : Aucune action entreprise.
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072514.DLL -> Worm.Warezov.zq : Aucune action entreprise.
C:\WINDOWS\system32\hnlo61.exe -> Worm.Warezov.zq : Aucune action entreprise.
C:\WINDOWS\system32\mw97k4hc.dll -> Worm.Warezov.zq : Aucune action entreprise.
Fin du rapport
BitDefender Online Scanner
Scan report generated at: Mon, Aug 27, 2007 - 22:33:45
Scan path: C:\;D:\;F:\;G:\;H:\;I:\;
Statistics
Time
00:21:25
Files
98901
Folders
4483
Boot Sectors
2
Archives
6910
Packed Files
126
Results
Identified Viruses
10
Infected Files
31
Suspect Files
0
Warnings
0
Disinfected
0
Deleted Files
29
Engines Info
Virus Definitions
710796
Engine build
AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)
Scan plugins
2
Archive plugins
10
Unpack plugins
2
E-mail plugins
1
System plugins
1
Scan Settings
First Action
Disinfect
Second Action
Delete
Heuristics
Yes
Enable Warnings
Yes
Scanned Extensions
*;
Exclude Extensions
Scan Emails
Yes
Scan Archives
Yes
Scan Packed
Yes
Scan Files
Yes
Scan Boot
Yes
Scanned File
Status
C:\WINDOWS\system32\vp6vsccb.dll
Infected with: DeepScan:Generic.Stration.AC1F9C4E
C:\WINDOWS\system32\vp6vsccb.dll
Disinfection failed
C:\WINDOWS\system32\vp6vsccb.dll
Delete failed
C:\WINDOWS\system32\cabvconf.exe
Infected with: Win32.Worm.Stration.FP
C:\WINDOWS\system32\cabvconf.exe
Deleted
C:\WINDOWS\system32\dx7vcdmo.dll
Infected with: Win32.Stration.DAW@mm
C:\WINDOWS\system32\dx7vcdmo.dll
Disinfection failed
C:\WINDOWS\system32\dx7vcdmo.dll
Deleted
C:\WINDOWS\system32\d8dv6c.dll
Infected with: Win32.Stration.Gen@mm
C:\WINDOWS\system32\d8dv6c.dll
Disinfection failed
C:\WINDOWS\system32\d8dv6c.dll
Deleted
C:\WINDOWS\system32\uvg6f0.exe
Infected with: Win32.Stration.Gen@mm
C:\WINDOWS\system32\uvg6f0.exe
Disinfection failed
C:\WINDOWS\system32\uvg6f0.exe
Deleted
C:\WINDOWS\system32\flw334.dll
Infected with: Win32.Stration.Gen@mm
C:\WINDOWS\system32\flw334.dll
Disinfection failed
C:\WINDOWS\system32\flw334.dll
Delete failed
C:\WINDOWS\system32\cetk5w3.exe
Infected with: Win32.Stration.Gen@mm
C:\WINDOWS\system32\cetk5w3.exe
Disinfection failed
C:\WINDOWS\system32\cetk5w3.exe
Deleted
C:\WINDOWS\system32\mw97k4hc.dll
Infected with: Win32.Stration.Gen@mm
C:\WINDOWS\system32\mw97k4hc.dll
Disinfection failed
C:\WINDOWS\system32\mw97k4hc.dll
Deleted
C:\WINDOWS\system32\hnlo61.exe
Infected with: Win32.Stration.Gen@mm
C:\WINDOWS\system32\hnlo61.exe
Disinfection failed
C:\WINDOWS\system32\hnlo61.exe
Deleted
C:\WINDOWS\system32\sgwjaoif.dll
Infected with: Win32.Warezov.YP
C:\WINDOWS\system32\sgwjaoif.dll
Disinfection failed
C:\WINDOWS\system32\sgwjaoif.dll
Deleted
C:\WINDOWS\system32\ero37s.exe
Infected with: Win32.Stration.Gen@mm
C:\WINDOWS\system32\ero37s.exe
Disinfection failed
C:\WINDOWS\system32\ero37s.exe
Deleted
C:\WINDOWS\system32\kqvom22dv9.dll
Infected with: Win32.Stration.DAZ
C:\WINDOWS\system32\kqvom22dv9.dll
Disinfection failed
C:\WINDOWS\system32\kqvom22dv9.dll
Deleted
C:\WINDOWS\sys_rsc.exe
Infected with: Dropped:Win32.Stration.Gen@mm
C:\WINDOWS\sys_rsc.exe
Disinfection failed
C:\WINDOWS\sys_rsc.exe
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072220.exe
Infected with: Win32.Stration.DAW@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072220.exe
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072220.exe
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072513.DLL
Infected with: Win32.Stration.Gen@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072513.DLL
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072513.DLL
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072514.DLL
Infected with: Win32.Stration.Gen@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072514.DLL
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072514.DLL
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072515.DLL
Infected with: Win32.Worm.Stration.QRA
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072515.DLL
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072515.DLL
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072536.exe
Infected with: Dropped:Win32.Stration.Gen@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072536.exe
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072536.exe
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072543.exe
Infected with: Win32.Worm.Stration.FP
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072543.exe
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072544.dll
Infected with: Win32.Stration.DAW@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072544.dll
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072544.dll
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072545.dll
Infected with: Win32.Stration.Gen@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072545.dll
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072545.dll
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072546.exe
Infected with: Win32.Stration.Gen@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072546.exe
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072546.exe
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072547.exe
Infected with: Win32.Stration.Gen@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072547.exe
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072547.exe
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072548.dll
Infected with: Win32.Stration.Gen@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072548.dll
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072548.dll
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072549.exe
Infected with: Win32.Stration.Gen@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072549.exe
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072549.exe
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072550.dll
Infected with: Win32.Warezov.YP
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072550.dll
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072550.dll
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072551.exe
Infected with: Win32.Stration.Gen@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072551.exe
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072551.exe
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072552.dll
Infected with: Win32.Stration.DAZ
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072552.dll
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072552.dll
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072553.exe
Infected with: Dropped:Win32.Stration.Gen@mm
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072553.exe
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP645\A0072553.exe
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP595\A0066338.exe
Infected with: Win32.Worm.Stration.QRT
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP595\A0066338.exe
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP595\A0066338.exe
Deleted
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP595\A0066360.exe
Infected with: Dropped:Win32.Worm.Stration.EM
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP595\A0066360.exe
Disinfection failed
C:\System Volume Information\_restore{43C20A85-12EA-4A36-8511-9DEAA69D9756}\RP595\A0066360.exe
Deleted
Logfile of HijackThis v1.99.1
Scan saved at 22:39:18, on 27/08/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/webhp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ntiMUI] C:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [cscrsc.exe] C:\WINDOWS\sys_rsc.exe -s
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\Widgets\YahooWidgetEngine.exe
O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st 800-908\dslmon.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to AMV Convert Tool... - C:\Program Files\MP3 Player Utilities 4.00\AMVConverter\grab.html
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: MediaManager tool grab multimedia file - C:\Program Files\MP3 Player Utilities 4.00\MediaManager\grab.html
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?f2a3db8565f9492990726ca0f43f5aed
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?f2a3db8565f9492990726ca0f43f5aed
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {946B3E9E-E21A-49c8-9F63-900533FAFE15} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://GLOBAL.ACER.COM/
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://signup.msn.com/pages/MsnInstC.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.messenger.msn.com/Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {87AF076E-D86D-4E87-ADDD-F05804E1F150} (VirginMega DownloadManager) - https://www.virginmega.fr/DownloadManager/Release/Prod/DownMan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A13516A3-BE86-4517-813C-B5FF0C8ACDF3} (Toontown Installer ActiveX Control French) - http://downloadtoontown.goa.com/sv1.5.11.8/ttinst-french.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: flw334.dll e1.dll dgork8.dll du5hpe6.dll umanwiav.dll
O20 - Winlogon Notify: vp6vsccb - C:\WINDOWS\system32\vp6vsccb.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

ci joint le rapport,
merci
DiagHelp version v1.1.2 - http://www.malekal.com
excute le 28/08/2007 à 9:41:34,89
Liste des derniers fichies modifies/crees dans windir\system32
C:\WINDOWS\System32/drivers\aswmon.sys -->28/07/2007 00:02:50
C:\WINDOWS\System32/drivers\aswmon2.sys -->28/07/2007 00:02:34
C:\WINDOWS\System32/drivers\aswRdr.sys -->28/07/2007 00:00:40
C:\WINDOWS\System32/drivers\aswTdi.sys -->27/07/2007 23:59:58
C:\WINDOWS\System32/drivers\aavmker4.sys -->27/07/2007 23:58:36
C:\WINDOWS\System32/drivers\UsbSagCom.sys -->29/06/2007 16:20:30
C:\WINDOWS\System32/drivers\AvgAsCln.sys -->30/05/2007 14:10:42
C:\WINDOWS\System32\wpa.dbl -->27/08/2007 21:30:10
C:\WINDOWS\System32\FNTCACHE.DAT -->27/08/2007 21:27:24
C:\WINDOWS\System32\CONFIG.NT -->26/08/2007 09:44:34
C:\WINDOWS\System32\aswBoot.exe -->28/07/2007 00:07:22
C:\WINDOWS\System32\AVASTSS.scr -->27/07/2007 23:57:50
C:\WINDOWS\System32\vp6vsccb.dat -->05/06/2007 09:34:22
C:\WINDOWS\System32\PerfStringBackup.INI -->24/05/2007 19:25:20
C:\WINDOWS\System32\perfh00C.dat -->24/05/2007 19:25:20
C:\WINDOWS\System32\perfc00C.dat -->24/05/2007 19:25:20
C:\WINDOWS\System32\perfh009.dat -->24/05/2007 19:25:20
C:\WINDOWS\System32\perfc009.dat -->24/05/2007 19:25:20
C:\WINDOWS\System32\flw334.dll -->18/05/2007 17:49:04
C:\WINDOWS\System32\dfg32.tmp -->18/05/2007 17:39:42
C:\WINDOWS\System32\vp6vsccb.dll -->17/05/2007 14:19:08
C:\WINDOWS\System32\MRT.exe -->27/04/2007 22:45:12
C:\WINDOWS\System32\msi.dll -->18/04/2007 18:14:18
C:\WINDOWS\System32\wuaucpl.cpl.mui -->16/04/2007 22:47:26
C:\WINDOWS\System32\wuapi.dll.mui -->16/04/2007 22:46:54
C:\WINDOWS\System32\wuaueng.dll -->16/04/2007 22:45:54
C:\WINDOWS\System32\wuapi.dll -->16/04/2007 22:45:48
C:\WINDOWS\System32\wuaueng.dll.mui -->16/04/2007 22:45:42
C:\WINDOWS\System32\wucltui.dll -->16/04/2007 22:45:42
C:\WINDOWS\System32\wuaucpl.cpl -->16/04/2007 22:45:40
C:\WINDOWS\System32\wuweb.dll -->16/04/2007 22:45:36
C:\WINDOWS\System32\cdm.dll -->16/04/2007 22:45:28
C:\WINDOWS\WindowsUpdate.log -->28/08/2007 09:18:02
C:\WINDOWS\setupapi.log -->27/08/2007 22:10:24
C:\WINDOWS\0.log -->27/08/2007 21:28:42
C:\WINDOWS\wiadebug.log -->27/08/2007 21:28:18
C:\WINDOWS\bootstat.dat -->27/08/2007 21:27:26
C:\WINDOWS\SchedLgU.Txt -->27/08/2007 21:26:42
C:\WINDOWS\wiaservc.log -->27/08/2007 21:26:38
C:\WINDOWS\win.ini -->21/08/2007 11:13:14
C:\WINDOWS\Papier-peint.bmp d'ACD -->17/07/2007 19:46:10
C:\WINDOWS\MF_C425.lfa -->12/06/2007 20:42:50
C:\WINDOWS\MF_C421.lfa -->12/06/2007 20:42:50
C:\WINDOWS\MF_C420.lfa -->12/06/2007 20:42:50
C:\WINDOWS\reuc82monx.scf -->05/06/2007 09:34:50
C:\WINDOWS\hjpgtk.dll -->01/06/2007 14:42:28
C:\WINDOWS\kodf.wd54et -->01/06/2007 13:27:30
Le volume dans le lecteur C s'appelle ACER
Le numéro de série du volume est 320D-180E
Répertoire de C:\WINDOWS\system
14/08/2002 15:03 4 672 WOWPOST.EXE
1 fichier(s) 4 672 octets
0 Rép(s) 103 868 956 672 octets libres
Le volume dans le lecteur C s'appelle ACER
Le numéro de série du volume est 320D-180E
Répertoire de C:\WINDOWS\system32
05/08/2004 05:00 6 144 csrss.exe
1 fichier(s) 6 144 octets
0 Rép(s) 103 868 956 672 octets libres
Contenu de Downloaded Program Files
Le volume dans le lecteur C s'appelle ACER
Le numéro de série du volume est 320D-180E
Répertoire de C:\WINDOWS\Downloaded Program Files
16/06/2005 03:08 <REP> .
16/06/2005 03:08 <REP> ..
16/06/2005 03:08 65 desktop.ini
14/07/2005 12:41 322 240 MsnInstC.dll
14/07/2005 14:11 249 MsnInstC.inf
29/05/2003 15:00 160 864 messengerstatsclient.dll
29/05/2003 15:00 84 064 minesweeper.dll
29/05/2003 15:00 86 112 solitaireshowdown.dll
29/05/2003 15:00 77 408 msgrchkr.dll
17/11/2004 22:44 114 728 Zintro.ocx
06/04/2004 19:03 172 072 MessengerStatsPAClient.dll
11/05/2004 11:55 1 277 992 Banksht2.dll
24/08/2005 19:19 405 504 ttinst-french.dll
24/08/2005 19:19 226 ttinst-french.inf
16/11/2005 11:52 490 Medialogic.INF
08/03/2005 12:26 202 setup.inf
18/03/2007 15:50 <REP> CONFLICT.1
22/11/2006 23:22 372 736 GAME_UNO1.dll
22/11/2006 20:50 316 GAME_UNO1.INF
11/06/2007 12:21 5 021 swflash.inf
31/05/2006 04:15 10 oscan81.ocx_x
18/02/2005 16:22 126 live.ini
09/03/2005 15:43 6 828 scanoptions.tsi
09/03/2005 15:42 6 742 lang.ini
01/03/2005 14:08 53 248 ipsupd.dll
01/03/2005 14:08 118 784 bdupd.dll
07/12/2004 16:07 32 libfn.dll
07/12/2004 16:07 32 bdcore.dll
01/06/2006 02:54 471 040 oscan8.ocx
01/06/2006 02:57 1 331 oscan8.inf
27 fichier(s) 3 738 462 octets
Répertoire de C:\WINDOWS\Downloaded Program Files\CONFLICT.1
18/03/2007 15:50 <REP> .
18/03/2007 15:50 <REP> ..
22/02/2007 23:41 304 544 MessengerStatsPAClient.dll
28/02/2007 14:21 130 472 MineSweeper.dll
2 fichier(s) 435 016 octets
Total des fichiers listés :
29 fichier(s) 4 173 478 octets
5 Rép(s) 103 868 956 672 octets libres
Recherche de rootkit! (Merci S!Ri)
Recherche d'infections connues
Export des clefs sensibles..
Liste des fichiers en exception sur le pare-feu XP SP2
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\IncrediMail\\bin\\IMApp.exe"="C:\\Program Files\\IncrediMail\\bin\\IMApp.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\IncMail.exe"="C:\\Program Files\\IncrediMail\\bin\\IncMail.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe"="C:\\Program Files\\IncrediMail\\bin\\ImpCnt.exe:*:Enabled:IncrediMail"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\WINDOWS\\dllsr32.exe"="C:\\WINDOWS\\dllsr32.exe:*:Enabled:SystemVersion"
"C:\\WINDOWS\\sccdbg.exe"="C:\\WINDOWS\\sccdbg.exe:*:Enabled:SystemVersion"
"C:\\WINDOWS\\ssdbg.exe"="C:\\WINDOWS\\ssdbg.exe:*:Enabled:SystemVersion"
"C:\\WINDOWS\\system32\\svct.exe"="C:\\WINDOWS\\System32\\svct.exe:*:Disabled:svct"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
Export de la clef SharedTaskScheduler
[SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"
Rechercher adresses sensibles dans le fichier HOSTS...
Configuration: Windows XP
Internet Explorer 6.0