Virus :des cafard et ecrant bleux

Résolu/Fermé
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008 - 29 mai 2008 à 20:42
 yuba - 4 juil. 2008 à 18:23
Bonjour,
j ai un virus : des cafard aparaisse au bout de 5 minute dinactiviter et mange mon ecrant jai avaste comme entivirus mais sa ne fait rien peux ton m aider je suis un novice du net a laide sa fait 1 joure que je lai attraper aider moi mercie

77 réponses

xenio Messages postés 318 Date d'inscription mercredi 25 juillet 2007 Statut Membre Dernière intervention 6 septembre 2009 41
29 mai 2008 à 20:44
Bonjour
tu es sur que ce n`est pas ton ecran de veille ?...
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
29 mai 2008 à 20:45
ha ha xenio lol
0
xenio Messages postés 318 Date d'inscription mercredi 25 juillet 2007 Statut Membre Dernière intervention 6 septembre 2009 41
29 mai 2008 à 20:47
^^ on sais jamais vu qu`il est novice...
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
29 mai 2008 à 20:50
non se n est pas l ecrant de vielle ses un virus
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
29 mai 2008 à 20:49
non mais pas dans ce cas...

c´est une infection connue...

bouglada

Télécharge HijackThis ici :

-> http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

Tutoriel d´instalation : (Merci a Balltrap34 pour cette réalisation)

-> http://pageperso.aol.fr/balltrap34/Hijenr.gif

Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

-> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

Post le rapport généré ici stp...

@+
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
29 mai 2008 à 20:54
ok je vais telecharger tous sa et quand je dit novice ses juste pour les virus ses pour sa que je me fit a des gens comme vous qui ete caller en la matiaire mercie a tous de suite
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
29 mai 2008 à 21:01
ok

y a juste un logiciel a telecharger, les autres liens sont des tutoriaux pour l´utilisation...

@+
0
Salut,
après recherches, si il n'y a eu aucun autres symptomes, c'est un ECRAN DE VEILLE et PAS UN VIRUS.
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
29 mai 2008 à 21:07
n´importe quoi...
0
Ah oui ... ^^ euh ... comment on fait pour effacer un message ?^^
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
29 mai 2008 à 21:11
trop tard, t´as devoillé ta connerie...
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
29 mai 2008 à 21:12
sa y et mais je ne ses pas comment te le maitre sur le blog
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
29 mai 2008 à 21:17
a laide
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
29 mai 2008 à 21:16
re,
en faite tu copie et colle l´integralité du bloc note ici
tu selectionne tout le texte dans le bloc note appuie sur controle et c simultanement revient ici et presse controle et v simultanement le texte va s´afficher, si tu ne comprends pas ce que je te raconte regarde la video :
tu fais comme expliqué dans la video (tutorial>3eme lien)
@+
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
29 mai 2008 à 21:20
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:04:05, on 29/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Seekmo\bin\10.0.406.0\OEAddOn.exe
C:\WINDOWS\system32\ctfmona.exe
C:\Program Files\AXPFixer\AXPFixer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\OLITEC\Common\RaUI.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?cc=fr&toHttps=1&redig=55729C844D6A45819CAD368B3E178C9F
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: 818646 helper - {54192079-8E8A-43D8-BCBC-3874916159AF} - C:\WINDOWS\system32\818646\818646.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {96134ABB-AD7C-4135-A927-329B735D524F} - C:\WINDOWS\system32\mlJBQHBT.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [ItsTV] "C:\Program Files\EoRezo\EoWeather\ItsTV.exe"
O4 - HKLM\..\Run: [VadeRetro Outlook] "C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe -s"
O4 - HKLM\..\Run: [VadeRetro Outlook Express & Windows Mail] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe"
O4 - HKLM\..\Run: [Spyware-Secure] C:\Program Files\Spyware-Secure\Spyware-Secure.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SeekmoOE] C:\Program Files\Seekmo\bin\10.0.406.0\OEAddOn.exe
O4 - HKLM\..\Run: [SeekmoSA] "C:\Program Files\Seekmo\bin\10.0.406.0\SeekmoSA.exe"
O4 - HKLM\..\Run: [ctfmona] C:\WINDOWS\system32\ctfmona.exe
O4 - HKLM\..\Run: [AXPFixer] C:\Program Files\AXPFixer\AXPFixer.exe
O4 - HKLM\..\Run: [antiviirus] C:\Program Files\antiviirus.exe
O4 - HKLM\..\Run: [AXPDefender] C:\Program Files\AXPDefender\AXPDefender.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [messengerskinner] C:\Program Files\MessengerSkinner\MessengerSkinner.exe
O4 - HKCU\..\Run: [yamyiyrc] c:\documents and settings\fab\local settings\application data\yamyiyrc.exe yamyiyrc
O4 - HKCU\..\Run: [pkopgnmg] c:\documents and settings\fab\local settings\application data\pkopgnmg.exe pkopgnmg
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [xerrugcqs] c:\documents and settings\fab\local settings\application data\xerrugcqs.exe xerrugcqs
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Moniteur reseau 802.11g OLITEC.lnk = C:\Program Files\OLITEC\Common\RaUI.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\Program Files\ShoppingReport\Bin\2.5.0\ShoppingReport.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/install/crusher-kiwen.cab
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: mlJBQHBT - C:\WINDOWS\SYSTEM32\mlJBQHBT.dll
O21 - SSODL: RamMon - {231b0e0c-0884-479f-9971-f5cb197bedeb} - C:\WINDOWS\Resources\RamMon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
29 mai 2008 à 21:22
et bien tu es tres infecté !

Télécharge combofix.exe (par sUBs) sur ton Bureau.

-> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

-> Double clique combofix.exe.
-> Tape sur la touche 1 (Yes) pour démarrer le scan.
-> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

NOTE : Le rapport se trouve également ici : C:\Combofix.txt

Avant d'utiliser ComboFix :

-> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

-> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

Une fois fait, sur ton bureau double-clic sur Combofix.exe.

- Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

/!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

- En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

- Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

-> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

-> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

-> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

Post egalement un nouveau rapport hijack this dans ta reponse

@+
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
29 mai 2008 à 22:18
Scan saved at 22:14:09, on 29/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\AXPFixer\AXPFixer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\OLITEC\Common\RaUI.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [ItsTV] "C:\Program Files\EoRezo\EoWeather\ItsTV.exe"
O4 - HKLM\..\Run: [VadeRetro Outlook] "C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe -s"
O4 - HKLM\..\Run: [VadeRetro Outlook Express & Windows Mail] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [AXPFixer] C:\Program Files\AXPFixer\AXPFixer.exe
O4 - HKLM\..\Run: [AXPDefender] C:\Program Files\AXPDefender\AXPDefender.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Moniteur reseau 802.11g OLITEC.lnk = C:\Program Files\OLITEC\Common\RaUI.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/install/crusher-kiwen.cab
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
29 mai 2008 à 22:18
Scan saved at 22:14:09, on 29/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\AXPFixer\AXPFixer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\OLITEC\Common\RaUI.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: (no name) - {4E7BD74F-2B8D-469E-A0E8-ED6AB685FA7D} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [ItsTV] "C:\Program Files\EoRezo\EoWeather\ItsTV.exe"
O4 - HKLM\..\Run: [VadeRetro Outlook] "C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe -s"
O4 - HKLM\..\Run: [VadeRetro Outlook Express & Windows Mail] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [AXPFixer] C:\Program Files\AXPFixer\AXPFixer.exe
O4 - HKLM\..\Run: [AXPDefender] C:\Program Files\AXPDefender\AXPDefender.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Moniteur reseau 802.11g OLITEC.lnk = C:\Program Files\OLITEC\Common\RaUI.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/install/crusher-kiwen.cab
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
29 mai 2008 à 22:28
ok

la suite :

Copie le texte ci-dessous :

File::
C:\WINDOWS\system32\ctfmonb.bmp
C:\WINDOWS\system32\blackster.scr

Folder::
C:\Program Files\Spyware-Secure
C:\Program Files\EoRezo
C:\Program Files\AXPDefender
C:\Program Files\AXPFixer
C:\Documents and Settings\Fab\Application Data\AXPFixer

Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AXPFixer"=-
"AXPDefender"=-
"EoEngine"=-
"ItsTV"=-
"EoWeather"=-

Ouvre le Bloc-Notes puis colle le texte copié.
(Démarrer\Tous les programmes\Accessoires\Bloc notes.)
Sauvegarde ce fichier sous le nom de CFScript.txt.

Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

Cela va relancer Combofix,

Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

Ne touche à rien tant que le scan n'est pas terminé.

Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

S'il n'y a pas de rédémarrage, poste quand même les rapports.

puis passe ceci :

Fais un clic droit sur ce lien :
http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

Laisse-toi guider. Au menu principal, choisis 1 et valides.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

Patiente jusqu'au message :
*** Analyse Termine le ..... ***
Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
Copie-colle l'intégralité dans une réponse. Referme le blocnote.
Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

puis

fini par ceci enfin pour ce soir...

Fais un scan avec cet antispyware :

Telecharge malwarebytes + tutoriel :

-> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

Tu l´instale; le programme va se mettre automatiquement a jour.

Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

Puis click sur "rechercher".

Laisse le scanner le pc...

Si des elements on ete trouvés > click sur supprimer la selection.

si il t´es demandé de redemarrer > click sur "yes".

A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

Copie et colle le rapport stp.

donc tu post le rapport de combofix2.txt le rapport de navilog option 1 puis le rapport de malwarebytes

bon courrage

@demain`
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 01:47
ComboFix 08-05-29.1 - Fab 2008-05-29 22:50:28.2 - NTFSx86
Endroit: C:\Documents and Settings\Fab\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Fab\Bureau\CFScript.txt..txt
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Fab\Application Data\AXPFixer
C:\Program Files\AXPDefender
C:\Program Files\AXPDefender\AXPDefender.exe.local
C:\Program Files\AXPDefender\AXPDefenderSkin.dll
C:\Program Files\AXPDefender\database.dat
C:\Program Files\AXPDefender\license.txt
C:\Program Files\AXPDefender\MFC71.dll
C:\Program Files\AXPDefender\MFC71ENU.DLL
C:\Program Files\AXPDefender\msvcp71.dll
C:\Program Files\AXPDefender\msvcr71.dll
C:\Program Files\AXPDefender\Uninstall.exe
C:\Program Files\AXPFixer
C:\Program Files\AXPFixer\AXPFixer.exe
C:\Program Files\AXPFixer\AXPFixer.exe.local
C:\Program Files\AXPFixer\AXPFixerSkin.dll
C:\Program Files\AXPFixer\database.dat
C:\Program Files\AXPFixer\license.txt
C:\Program Files\AXPFixer\MFC71.dll
C:\Program Files\AXPFixer\MFC71ENU.DLL
C:\Program Files\AXPFixer\msvcp71.dll
C:\Program Files\AXPFixer\msvcr71.dll
C:\Program Files\AXPFixer\Uninstall.exe
C:\Program Files\Spyware-Secure
C:\Program Files\Spyware-Secure\Gfx_fr.bin
C:\Program Files\Spyware-Secure\guid
C:\Program Files\Spyware-Secure\help\help_Full_FR.zip
C:\Program Files\Spyware-Secure\help\help_Full_FR\explo_intro.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\explo_menu.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\file.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder_f.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder_o.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\fleche.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\folder.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\dowload-file-antispyware.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\menu.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\scstep2.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\key.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\menu.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\support.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\title-hepfile.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\index.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\menu3.js
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\3differentscan.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\contactus.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\found-objects.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\lexic.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\navigtabs.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\quarantine.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\spy.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_coud.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_droit.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_vert.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR.zip
C:\Program Files\Spyware-Secure\help\help_Trial_FR\explo_intro.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\explo_menu.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\file.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder_f.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder_o.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\fleche.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\folder.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\dowload-file-antispyware.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\menu.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\scstep2.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\key.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\menu.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\support.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\title-hepfile.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\index.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\menu3.js
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\3differentscan.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\contactus.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\found-objects.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\lexic.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\navigtabs.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\quarantine.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\register.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\spy.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_coud.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_droit.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_vert.gif
C:\Program Files\Spyware-Secure\language
C:\Program Files\Spyware-Secure\nbmw
C:\Program Files\Spyware-Secure\quarantine.s3db
C:\Program Files\Spyware-Secure\resources\cookies_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesDesc_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesDesc_1-12.dic
C:\Program Files\Spyware-Secure\resources\filesExt_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesMulti_1-12.idx
C:\Program Files\Spyware-Secure\resources\filesSimple_1-12.idx
C:\Program Files\Spyware-Secure\resources\malwaresDB_1-12
C:\Program Files\Spyware-Secure\resources\register_1-12.dat
C:\Program Files\Spyware-Secure\resources\trad_demo_EN.txt
C:\Program Files\Spyware-Secure\resources\trad_demo_ES.txt
C:\Program Files\Spyware-Secure\resources\trad_demo_FR.txt
C:\Program Files\Spyware-Secure\serial
C:\Program Files\Spyware-Secure\skin
C:\Program Files\Spyware-Secure\Spyware-Secure.exe
C:\Program Files\Spyware-Secure\Spyware-Secure.url
C:\Program Files\Spyware-Secure\Spyware-Secure_repaironce.exe
C:\Program Files\Spyware-Secure\sqlite3.dll
C:\Program Files\Spyware-Secure\uninst.exe
C:\Program Files\Spyware-Secure\unrar.dll

.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-28 to 2008-05-29 ))))))))))))))))))))))))))))))))))))
.

2008-05-29 20:59 . 2008-05-29 20:59 <REP> d-------- C:\Program Files\Trend Micro
2008-05-28 23:41 . 2008-05-29 18:49 269,334 --a------ C:\WINDOWS\system32\ctfmonb.bmp
2008-05-28 23:41 . 2008-05-29 18:49 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-05-18 21:00 . 2008-05-18 21:00 <REP> d-------- C:\Program Files\Ascentive
2008-05-18 21:00 . 2008-04-17 16:22 208,896 --a------ C:\WINDOWS\system32\ConTest.dll
2008-05-17 20:41 . 2008-05-17 20:43 <REP> d-------- C:\Program Files\Pet Soccer
2008-05-09 00:19 . 2008-05-09 00:19 268 --ah----- C:\sqmdata04.sqm
2008-05-09 00:19 . 2008-05-09 00:19 268 --ah----- C:\sqmdata03.sqm
2008-05-09 00:19 . 2008-05-09 00:19 244 --ah----- C:\sqmnoopt03.sqm
2008-05-09 00:19 . 2008-05-09 00:19 172 --ah----- C:\sqmnoopt04.sqm
2008-05-08 01:49 . 2008-05-08 01:49 <REP> d-------- C:\Program Files\Sun
2008-05-04 02:55 . 2008-05-04 02:55 <REP> d-------- C:\Program Files\Multi_Media_France
2008-05-04 02:55 . 2008-05-04 02:55 <REP> d-------- C:\Program Files\Conduit
2008-05-02 18:05 . 2008-05-05 00:56 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-04-29 22:23 . 2008-04-29 22:31 <REP> d-------- C:\WINDOWS\system32\Adobe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 23:54 --------- d-----w C:\Documents and Settings\Fab\Application Data\Skype
2008-05-28 22:43 --------- d-----w C:\Documents and Settings\Fab\Application Data\skypePM
2008-05-28 18:30 --------- d-----w C:\Program Files\eMule
2008-05-18 19:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-15 00:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-09 16:29 --------- d-----w C:\Program Files\Google
2008-05-08 20:36 --------- d-----w C:\Program Files\Yahoo!
2008-05-07 23:49 --------- d-----w C:\Program Files\Java
2008-01-24 22:55 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.

((((((((((((((((((((((((((((( snapshot@2008-05-29_22.07.55.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 19:58:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-29 20:56:20 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-29 20:56:46 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_684.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 20:10 1688872]
"Performance Center"="C:\Program Files\Ascentive\Performance Center\APCMain.exe" [2008-03-13 17:35 3239936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 14:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 12:12 102492]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 12:11 692316]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 21:00 344064]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-04-29 09:07 127118]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-06-10 14:48 286720]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-09-13 16:22 180269]
"VadeRetro Outlook"="C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe" [2007-08-31 17:13 44544]
"VadeRetro Outlook Express & Windows Mail"="C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe" [2007-10-09 14:28 296448]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 15:21 2213160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Inventime\\my.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\PeerTV\\PeerCast.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\APPS\\skype\\phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R3 ULI5261;ULi Based Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN.SYS [2004-12-31 15:24]
S3 CIR;Hid Device;C:\WINDOWS\system32\DRIVERS\CIR.sys [2005-05-20 09:01]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2005-11-19 03:13]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]

.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-04-25 08:04:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-10 14:55:58 C:\WINDOWS\Tasks\Rappel d'enregistrement 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-29 22:57:20
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cach‚s ...

Balayage cach‚ autostart entries ...

Balayage des fichiers cach‚s ...

Scan termin‚ avec succŠs
Les fichiers cach‚s: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\APPS\HIDSERVICE\HidService.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\slserv.exe
C:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\OLITEC\Common\RaUI.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-29 23:06:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-29 21:06:40
ComboFix2.txt 2008-05-29 20:08:17

Pre-Run: 27,385,298,944 octets libres
Post-Run: 27,359,285,248 octets libres

258 --- E O F --- 2008-05-28 22:05:52
ComboFix 08-05-29.1 - Fab 2008-05-29 22:50:28.2 - NTFSx86
Endroit: C:\Documents and Settings\Fab\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Fab\Bureau\CFScript.txt..txt
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Fab\Application Data\AXPFixer
C:\Program Files\AXPDefender
C:\Program Files\AXPDefender\AXPDefender.exe.local
C:\Program Files\AXPDefender\AXPDefenderSkin.dll
C:\Program Files\AXPDefender\database.dat
C:\Program Files\AXPDefender\license.txt
C:\Program Files\AXPDefender\MFC71.dll
C:\Program Files\AXPDefender\MFC71ENU.DLL
C:\Program Files\AXPDefender\msvcp71.dll
C:\Program Files\AXPDefender\msvcr71.dll
C:\Program Files\AXPDefender\Uninstall.exe
C:\Program Files\AXPFixer
C:\Program Files\AXPFixer\AXPFixer.exe
C:\Program Files\AXPFixer\AXPFixer.exe.local
C:\Program Files\AXPFixer\AXPFixerSkin.dll
C:\Program Files\AXPFixer\database.dat
C:\Program Files\AXPFixer\license.txt
C:\Program Files\AXPFixer\MFC71.dll
C:\Program Files\AXPFixer\MFC71ENU.DLL
C:\Program Files\AXPFixer\msvcp71.dll
C:\Program Files\AXPFixer\msvcr71.dll
C:\Program Files\AXPFixer\Uninstall.exe
C:\Program Files\Spyware-Secure
C:\Program Files\Spyware-Secure\Gfx_fr.bin
C:\Program Files\Spyware-Secure\guid
C:\Program Files\Spyware-Secure\help\help_Full_FR.zip
C:\Program Files\Spyware-Secure\help\help_Full_FR\explo_intro.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\explo_menu.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\file.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder_f.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder_o.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\fleche.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\folder.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\dowload-file-antispyware.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\menu.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\scstep2.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\key.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\menu.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\support.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\title-hepfile.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\index.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\menu3.js
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\3differentscan.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\contactus.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\found-objects.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\lexic.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\navigtabs.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\quarantine.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\spy.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_coud.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_droit.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_vert.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR.zip
C:\Program Files\Spyware-Secure\help\help_Trial_FR\explo_intro.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\explo_menu.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\file.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder_f.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder_o.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\fleche.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\folder.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\dowload-file-antispyware.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\menu.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\scstep2.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\key.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\menu.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\support.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\title-hepfile.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\index.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\menu3.js
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\3differentscan.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\contactus.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\found-objects.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\lexic.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\navigtabs.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\quarantine.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\register.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\spy.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_coud.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_droit.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_vert.gif
C:\Program Files\Spyware-Secure\language
C:\Program Files\Spyware-Secure\nbmw
C:\Program Files\Spyware-Secure\quarantine.s3db
C:\Program Files\Spyware-Secure\resources\cookies_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesDesc_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesDesc_1-12.dic
C:\Program Files\Spyware-Secure\resources\filesExt_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesMulti_1-12.idx
C:\Program Files\Spyware-Secure\resources\filesSimple_1-12.idx
C:\Program Files\Spyware-Secure\resources\malwaresDB_1-12
C:\Program Files\Spyware-Secure\resources\register_1-12.dat
C:\Program Files\Spyware-Secure\resources\trad_demo_EN.txt
C:\Program Files\Spyware-Secure\resources\trad_demo_ES.txt
C:\Program Files\Spyware-Secure\resources\trad_demo_FR.txt
C:\Program Files\Spyware-Secure\serial
C:\Program Files\Spyware-Secure\skin
C:\Program Files\Spyware-Secure\Spyware-Secure.exe
C:\Program Files\Spyware-Secure\Spyware-Secure.url
C:\Program Files\Spyware-Secure\Spyware-Secure_repaironce.exe
C:\Program Files\Spyware-Secure\sqlite3.dll
C:\Program Files\Spyware-Secure\uninst.exe
C:\Program Files\Spyware-Secure\unrar.dll

.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-28 to 2008-05-29 ))))))))))))))))))))))))))))))))))))
.

2008-05-29 20:59 . 2008-05-29 20:59 <REP> d-------- C:\Program Files\Trend Micro
2008-05-28 23:41 . 2008-05-29 18:49 269,334 --a------ C:\WINDOWS\system32\ctfmonb.bmp
2008-05-28 23:41 . 2008-05-29 18:49 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-05-18 21:00 . 2008-05-18 21:00 <REP> d-------- C:\Program Files\Ascentive
2008-05-18 21:00 . 2008-04-17 16:22 208,896 --a------ C:\WINDOWS\system32\ConTest.dll
2008-05-17 20:41 . 2008-05-17 20:43 <REP> d-------- C:\Program Files\Pet Soccer
2008-05-09 00:19 . 2008-05-09 00:19 268 --ah----- C:\sqmdata04.sqm
2008-05-09 00:19 . 2008-05-09 00:19 268 --ah----- C:\sqmdata03.sqm
2008-05-09 00:19 . 2008-05-09 00:19 244 --ah----- C:\sqmnoopt03.sqm
2008-05-09 00:19 . 2008-05-09 00:19 172 --ah----- C:\sqmnoopt04.sqm
2008-05-08 01:49 . 2008-05-08 01:49 <REP> d-------- C:\Program Files\Sun
2008-05-04 02:55 . 2008-05-04 02:55 <REP> d-------- C:\Program Files\Multi_Media_France
2008-05-04 02:55 . 2008-05-04 02:55 <REP> d-------- C:\Program Files\Conduit
2008-05-02 18:05 . 2008-05-05 00:56 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-04-29 22:23 . 2008-04-29 22:31 <REP> d-------- C:\WINDOWS\system32\Adobe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 23:54 --------- d-----w C:\Documents and Settings\Fab\Application Data\Skype
2008-05-28 22:43 --------- d-----w C:\Documents and Settings\Fab\Application Data\skypePM
2008-05-28 18:30 --------- d-----w C:\Program Files\eMule
2008-05-18 19:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-15 00:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-09 16:29 --------- d-----w C:\Program Files\Google
2008-05-08 20:36 --------- d-----w C:\Program Files\Yahoo!
2008-05-07 23:49 --------- d-----w C:\Program Files\Java
2008-01-24 22:55 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.

((((((((((((((((((((((((((((( snapshot@2008-05-29_22.07.55.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 19:58:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-29 20:56:20 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-29 20:56:46 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_684.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 20:10 1688872]
"Performance Center"="C:\Program Files\Ascentive\Performance Center\APCMain.exe" [2008-03-13 17:35 3239936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 14:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 12:12 102492]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 12:11 692316]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 21:00 344064]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-04-29 09:07 127118]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-06-10 14:48 286720]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-09-13 16:22 180269]
"VadeRetro Outlook"="C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe" [2007-08-31 17:13 44544]
"VadeRetro Outlook Express & Windows Mail"="C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe" [2007-10-09 14:28 296448]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 15:21 2213160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Inventime\\my.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\PeerTV\\PeerCast.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\APPS\\skype\\phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R3 ULI5261;ULi Based Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN.SYS [2004-12-31 15:24]
S3 CIR;Hid Device;C:\WINDOWS\system32\DRIVERS\CIR.sys [2005-05-20 09:01]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2005-11-19 03:13]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]

.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-04-25 08:04:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-10 14:55:58 C:\WINDOWS\Tasks\Rappel d'enregistrement 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-29 22:57:20
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cach‚s ...

Balayage cach‚ autostart entries ...

Balayage des fichiers cach‚s ...

Scan termin‚ avec succŠs
Les fichiers cach‚s: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\APPS\HIDSERVICE\HidService.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\slserv.exe
C:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\OLITEC\Common\RaUI.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-29 23:06:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-29 21:06:40
ComboFix2.txt 2008-05-29 20:08:17

Pre-Run: 27,385,298,944 octets libres
Post-Run: 27,359,285,248 octets libres

258 --- E O F --- 2008-05-28 22:05:52
ComboFix 08-05-29.1 - Fab 2008-05-29 22:50:28.2 - NTFSx86
Endroit: C:\Documents and Settings\Fab\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Fab\Bureau\CFScript.txt..txt
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Fab\Application Data\AXPFixer
C:\Program Files\AXPDefender
C:\Program Files\AXPDefender\AXPDefender.exe.local
C:\Program Files\AXPDefender\AXPDefenderSkin.dll
C:\Program Files\AXPDefender\database.dat
C:\Program Files\AXPDefender\license.txt
C:\Program Files\AXPDefender\MFC71.dll
C:\Program Files\AXPDefender\MFC71ENU.DLL
C:\Program Files\AXPDefender\msvcp71.dll
C:\Program Files\AXPDefender\msvcr71.dll
C:\Program Files\AXPDefender\Uninstall.exe
C:\Program Files\AXPFixer
C:\Program Files\AXPFixer\AXPFixer.exe
C:\Program Files\AXPFixer\AXPFixer.exe.local
C:\Program Files\AXPFixer\AXPFixerSkin.dll
C:\Program Files\AXPFixer\database.dat
C:\Program Files\AXPFixer\license.txt
C:\Program Files\AXPFixer\MFC71.dll
C:\Program Files\AXPFixer\MFC71ENU.DLL
C:\Program Files\AXPFixer\msvcp71.dll
C:\Program Files\AXPFixer\msvcr71.dll
C:\Program Files\AXPFixer\Uninstall.exe
C:\Program Files\Spyware-Secure
C:\Program Files\Spyware-Secure\Gfx_fr.bin
C:\Program Files\Spyware-Secure\guid
C:\Program Files\Spyware-Secure\help\help_Full_FR.zip
C:\Program Files\Spyware-Secure\help\help_Full_FR\explo_intro.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\explo_menu.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\file.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder_f.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder_o.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\fleche.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\folder.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\dowload-file-antispyware.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\menu.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\scstep2.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\key.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\menu.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\support.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\title-hepfile.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\index.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\menu3.js
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\3differentscan.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\contactus.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\found-objects.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\lexic.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\navigtabs.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\quarantine.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\spy.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_coud.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_droit.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_vert.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR.zip
C:\Program Files\Spyware-Secure\help\help_Trial_FR\explo_intro.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\explo_menu.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\file.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder_f.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder_o.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\fleche.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\folder.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\dowload-file-antispyware.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\menu.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\scstep2.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\key.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\menu.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\support.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\title-hepfile.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\index.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\menu3.js
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\3differentscan.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\contactus.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\found-objects.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\lexic.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\navigtabs.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\quarantine.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\register.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\spy.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_coud.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_droit.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_vert.gif
C:\Program Files\Spyware-Secure\language
C:\Program Files\Spyware-Secure\nbmw
C:\Program Files\Spyware-Secure\quarantine.s3db
C:\Program Files\Spyware-Secure\resources\cookies_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesDesc_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesDesc_1-12.dic
C:\Program Files\Spyware-Secure\resources\filesExt_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesMulti_1-12.idx
C:\Program Files\Spyware-Secure\resources\filesSimple_1-12.idx
C:\Program Files\Spyware-Secure\resources\malwaresDB_1-12
C:\Program Files\Spyware-Secure\resources\register_1-12.dat
C:\Program Files\Spyware-Secure\resources\trad_demo_EN.txt
C:\Program Files\Spyware-Secure\resources\trad_demo_ES.txt
C:\Program Files\Spyware-Secure\resources\trad_demo_FR.txt
C:\Program Files\Spyware-Secure\serial
C:\Program Files\Spyware-Secure\skin
C:\Program Files\Spyware-Secure\Spyware-Secure.exe
C:\Program Files\Spyware-Secure\Spyware-Secure.url
C:\Program Files\Spyware-Secure\Spyware-Secure_repaironce.exe
C:\Program Files\Spyware-Secure\sqlite3.dll
C:\Program Files\Spyware-Secure\uninst.exe
C:\Program Files\Spyware-Secure\unrar.dll

.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-28 to 2008-05-29 ))))))))))))))))))))))))))))))))))))
.

2008-05-29 20:59 . 2008-05-29 20:59 <REP> d-------- C:\Program Files\Trend Micro
2008-05-28 23:41 . 2008-05-29 18:49 269,334 --a------ C:\WINDOWS\system32\ctfmonb.bmp
2008-05-28 23:41 . 2008-05-29 18:49 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-05-18 21:00 . 2008-05-18 21:00 <REP> d-------- C:\Program Files\Ascentive
2008-05-18 21:00 . 2008-04-17 16:22 208,896 --a------ C:\WINDOWS\system32\ConTest.dll
2008-05-17 20:41 . 2008-05-17 20:43 <REP> d-------- C:\Program Files\Pet Soccer
2008-05-09 00:19 . 2008-05-09 00:19 268 --ah----- C:\sqmdata04.sqm
2008-05-09 00:19 . 2008-05-09 00:19 268 --ah----- C:\sqmdata03.sqm
2008-05-09 00:19 . 2008-05-09 00:19 244 --ah----- C:\sqmnoopt03.sqm
2008-05-09 00:19 . 2008-05-09 00:19 172 --ah----- C:\sqmnoopt04.sqm
2008-05-08 01:49 . 2008-05-08 01:49 <REP> d-------- C:\Program Files\Sun
2008-05-04 02:55 . 2008-05-04 02:55 <REP> d-------- C:\Program Files\Multi_Media_France
2008-05-04 02:55 . 2008-05-04 02:55 <REP> d-------- C:\Program Files\Conduit
2008-05-02 18:05 . 2008-05-05 00:56 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-04-29 22:23 . 2008-04-29 22:31 <REP> d-------- C:\WINDOWS\system32\Adobe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 23:54 --------- d-----w C:\Documents and Settings\Fab\Application Data\Skype
2008-05-28 22:43 --------- d-----w C:\Documents and Settings\Fab\Application Data\skypePM
2008-05-28 18:30 --------- d-----w C:\Program Files\eMule
2008-05-18 19:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-15 00:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-09 16:29 --------- d-----w C:\Program Files\Google
2008-05-08 20:36 --------- d-----w C:\Program Files\Yahoo!
2008-05-07 23:49 --------- d-----w C:\Program Files\Java
2008-01-24 22:55 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.

((((((((((((((((((((((((((((( snapshot@2008-05-29_22.07.55.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 19:58:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-29 20:56:20 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-29 20:56:46 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_684.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 20:10 1688872]
"Performance Center"="C:\Program Files\Ascentive\Performance Center\APCMain.exe" [2008-03-13 17:35 3239936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 14:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 12:12 102492]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 12:11 692316]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 21:00 344064]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-04-29 09:07 127118]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-06-10 14:48 286720]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-09-13 16:22 180269]
"VadeRetro Outlook"="C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe" [2007-08-31 17:13 44544]
"VadeRetro Outlook Express & Windows Mail"="C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe" [2007-10-09 14:28 296448]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 15:21 2213160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Inventime\\my.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\PeerTV\\PeerCast.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\APPS\\skype\\phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R3 ULI5261;ULi Based Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN.SYS [2004-12-31 15:24]
S3 CIR;Hid Device;C:\WINDOWS\system32\DRIVERS\CIR.sys [2005-05-20 09:01]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2005-11-19 03:13]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]

.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-04-25 08:04:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-10 14:55:58 C:\WINDOWS\Tasks\Rappel d'enregistrement 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-29 22:57:20
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cach‚s ...

Balayage cach‚ autostart entries ...

Balayage des fichiers cach‚s ...

Scan termin‚ avec succŠs
Les fichiers cach‚s: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\APPS\HIDSERVICE\HidService.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\slserv.exe
C:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\OLITEC\Common\RaUI.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-29 23:06:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-29 21:06:40
ComboFix2.txt 2008-05-29 20:08:17

Pre-Run: 27,385,298,944 octets libres
Post-Run: 27,359,285,248 octets libres

258 --- E O F --- 2008-05-28 22:05:52
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008 > bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 02:04
08-05-29 22:50:28.2 - NTFSx86
Endroit: C:\Documents and Settings\Fab\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Fab\Bureau\CFScript.txt..txt
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Fab\Application Data\AXPFixer
C:\Program Files\AXPDefender
C:\Program Files\AXPDefender\AXPDefender.exe.local
C:\Program Files\AXPDefender\AXPDefenderSkin.dll
C:\Program Files\AXPDefender\database.dat
C:\Program Files\AXPDefender\license.txt
C:\Program Files\AXPDefender\MFC71.dll
C:\Program Files\AXPDefender\MFC71ENU.DLL
C:\Program Files\AXPDefender\msvcp71.dll
C:\Program Files\AXPDefender\msvcr71.dll
C:\Program Files\AXPDefender\Uninstall.exe
C:\Program Files\AXPFixer
C:\Program Files\AXPFixer\AXPFixer.exe
C:\Program Files\AXPFixer\AXPFixer.exe.local
C:\Program Files\AXPFixer\AXPFixerSkin.dll
C:\Program Files\AXPFixer\database.dat
C:\Program Files\AXPFixer\license.txt
C:\Program Files\AXPFixer\MFC71.dll
C:\Program Files\AXPFixer\MFC71ENU.DLL
C:\Program Files\AXPFixer\msvcp71.dll
C:\Program Files\AXPFixer\msvcr71.dll
C:\Program Files\AXPFixer\Uninstall.exe
C:\Program Files\Spyware-Secure
C:\Program Files\Spyware-Secure\Gfx_fr.bin
C:\Program Files\Spyware-Secure\guid
C:\Program Files\Spyware-Secure\help\help_Full_FR.zip
C:\Program Files\Spyware-Secure\help\help_Full_FR\explo_intro.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\explo_menu.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\file.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder_f.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\folder_o.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\fleche.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\folder.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\dowload-file-antispyware.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\menu.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\FR\scstep2.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\key.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\menu.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\support.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\images\title-hepfile.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\index.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\menu3.js
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\3differentscan.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\contactus.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\found-objects.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\lexic.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\navigtabs.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\rubs\quarantine.htm
C:\Program Files\Spyware-Secure\help\help_Full_FR\spy.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_coud.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_droit.gif
C:\Program Files\Spyware-Secure\help\help_Full_FR\trait_vert.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR.zip
C:\Program Files\Spyware-Secure\help\help_Trial_FR\explo_intro.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\explo_menu.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\file.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder_f.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\folder_o.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\fleche.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\folder.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\dowload-file-antispyware.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\menu.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\FR\scstep2.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\key.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\menu.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\support.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\images\title-hepfile.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\index.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\menu3.js
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\3differentscan.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\contactus.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\found-objects.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\lexic.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\navigtabs.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\quarantine.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\rubs\register.htm
C:\Program Files\Spyware-Secure\help\help_Trial_FR\spy.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_coud.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_droit.gif
C:\Program Files\Spyware-Secure\help\help_Trial_FR\trait_vert.gif
C:\Program Files\Spyware-Secure\language
C:\Program Files\Spyware-Secure\nbmw
C:\Program Files\Spyware-Secure\quarantine.s3db
C:\Program Files\Spyware-Secure\resources\cookies_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesDesc_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesDesc_1-12.dic
C:\Program Files\Spyware-Secure\resources\filesExt_1-12.dat
C:\Program Files\Spyware-Secure\resources\filesMulti_1-12.idx
C:\Program Files\Spyware-Secure\resources\filesSimple_1-12.idx
C:\Program Files\Spyware-Secure\resources\malwaresDB_1-12
C:\Program Files\Spyware-Secure\resources\register_1-12.dat
C:\Program Files\Spyware-Secure\resources\trad_demo_EN.txt
C:\Program Files\Spyware-Secure\resources\trad_demo_ES.txt
C:\Program Files\Spyware-Secure\resources\trad_demo_FR.txt
C:\Program Files\Spyware-Secure\serial
C:\Program Files\Spyware-Secure\skin
C:\Program Files\Spyware-Secure\Spyware-Secure.exe
C:\Program Files\Spyware-Secure\Spyware-Secure.url
C:\Program Files\Spyware-Secure\Spyware-Secure_repaironce.exe
C:\Program Files\Spyware-Secure\sqlite3.dll
C:\Program Files\Spyware-Secure\uninst.exe
C:\Program Files\Spyware-Secure\unrar.dll

.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-28 to 2008-05-29 ))))))))))))))))))))))))))))))))))))
.

2008-05-29 20:59 . 2008-05-29 20:59 <REP> d-------- C:\Program Files\Trend Micro
2008-05-28 23:41 . 2008-05-29 18:49 269,334 --a------ C:\WINDOWS\system32\ctfmonb.bmp
2008-05-28 23:41 . 2008-05-29 18:49 160,256 --a------ C:\WINDOWS\system32\blackster.scr
2008-05-18 21:00 . 2008-05-18 21:00 <REP> d-------- C:\Program Files\Ascentive
2008-05-18 21:00 . 2008-04-17 16:22 208,896 --a------ C:\WINDOWS\system32\ConTest.dll
2008-05-17 20:41 . 2008-05-17 20:43 <REP> d-------- C:\Program Files\Pet Soccer
2008-05-09 00:19 . 2008-05-09 00:19 268 --ah----- C:\sqmdata04.sqm
2008-05-09 00:19 . 2008-05-09 00:19 268 --ah----- C:\sqmdata03.sqm
2008-05-09 00:19 . 2008-05-09 00:19 244 --ah----- C:\sqmnoopt03.sqm
2008-05-09 00:19 . 2008-05-09 00:19 172 --ah----- C:\sqmnoopt04.sqm
2008-05-08 01:49 . 2008-05-08 01:49 <REP> d-------- C:\Program Files\Sun
2008-05-04 02:55 . 2008-05-04 02:55 <REP> d-------- C:\Program Files\Multi_Media_France
2008-05-04 02:55 . 2008-05-04 02:55 <REP> d-------- C:\Program Files\Conduit
2008-05-02 18:05 . 2008-05-05 00:56 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-04-29 22:23 . 2008-04-29 22:31 <REP> d-------- C:\WINDOWS\system32\Adobe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-28 23:54 --------- d-----w C:\Documents and Settings\Fab\Application Data\Skype
2008-05-28 22:43 --------- d-----w C:\Documents and Settings\Fab\Application Data\skypePM
2008-05-28 18:30 --------- d-----w C:\Program Files\eMule
2008-05-18 19:01 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-15 00:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-05-09 16:29 --------- d-----w C:\Program Files\Google
2008-05-08 20:36 --------- d-----w C:\Program Files\Yahoo!
2008-05-07 23:49 --------- d-----w C:\Program Files\Java
2008-01-24 22:55 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.

((((((((((((((((((((((((((((( snapshot@2008-05-29_22.07.55.06 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-29 19:58:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-29 20:56:20 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-29 20:56:46 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_684.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 20:10 1688872]
"Performance Center"="C:\Program Files\Ascentive\Performance Center\APCMain.exe" [2008-03-13 17:35 3239936]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 14:00 208952]
"PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-02-02 12:12 102492]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-02-02 12:11 692316]
"ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-05-12 21:00 344064]
"SoundMan"="SOUNDMAN.EXE" [2005-01-20 20:04 77824 C:\WINDOWS\SOUNDMAN.EXE]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-04-29 09:07 127118]
"snpstd"="C:\WINDOWS\vsnpstd.exe" [2004-06-10 14:48 286720]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2005-09-13 16:22 180269]
"VadeRetro Outlook"="C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe" [2007-08-31 17:13 44544]
"VadeRetro Outlook Express & Windows Mail"="C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe" [2007-10-09 14:28 296448]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 00:13 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
"NeroFilterCheck"="C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe" [2007-03-01 15:57 153136]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 15:21 2213160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%ProgramFiles%\\AOL 9.0\\aol.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\logo_ubi.exe"=
"%ProgramFiles%\\UBISOFT\\Splinter Cell Pandora Tomorrow\\pandora.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\APPS\\Inventime\\my.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\PeerTV\\PeerCast.exe"=
"C:\\Program Files\\eMule\\emule.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\Program Files\\SopCast\\SopCast.exe"=
"C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
"C:\\Program Files\\TVAnts\\Tvants.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=
"C:\\APPS\\skype\\phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
R3 ULI5261;ULi Based Ethernet NT Driver;C:\WINDOWS\system32\DRIVERS\ULILAN.SYS [2004-12-31 15:24]
S3 CIR;Hid Device;C:\WINDOWS\system32\DRIVERS\CIR.sys [2005-05-20 09:01]
S3 PCASp50;PCASp50 NDIS Protocol Driver;C:\WINDOWS\system32\Drivers\PCASp50.sys [2005-11-19 03:13]
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 23:58]
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]

.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2008-04-25 08:04:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-09-10 14:55:58 C:\WINDOWS\Tasks\Rappel d'enregistrement 3.job"
- C:\WINDOWS\system32\OOBE\oobebaln.exe
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-05-29 22:57:20
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cach‚s ...

Balayage cach‚ autostart entries ...

Balayage des fichiers cach‚s ...

Scan termin‚ avec succŠs
Les fichiers cach‚s: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySqlInventime]
"ImagePath"="c:\mysql\bin\mysqld-max-nt MySqlInventime"
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\ati2evxx.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\APPS\HIDSERVICE\HidService.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\slserv.exe
C:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\OLITEC\Common\RaUI.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-05-29 23:06:45 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-29 21:06:40
ComboFix2.txt 2008-05-29 20:08:17

Pre-Run: 27,385,298,944 octets libres
Post-Run: 27,359,285,248 octets libres

258 --- E O F --- 2008-05-28 22:05:52
je suis fatiguer mon clavier ne marche plus je me saire du clavier virtul peux tu m aider est ce fini je me reconnecterai demain a dix neuf heures en espérant que tu pourra continuer à m aider merci d'avance!!!!!
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
30 mai 2008 à 18:20
salut,

pas la peine de poster 15 fois les rapports ;-)

a quelle moment ton clavier a t-il cessé de fonctionner ?

@´+
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 19:09
salut et mercie mon clavier ne marche plus depuis hier 23heure le virus a boufer les periherie peux tu m aider e galaire avec ma sourie
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008 > bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 19:12
peux tu eux dire sile virus exite toujoure mercie
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
30 mai 2008 à 19:18
tu as regardé dans la fenetre des peripheriques si tu as des points d´exclamations jaunes ?
post un nouveau rapport hijack this stp
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 19:24
v2.0.2
Scan saved at 19:23:20, on 30/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Apps\Powercinema\PCMService.exe
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\vsnpstd.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\ctfmon.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Program Files\OLITEC\Common\RaUI.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\system32\osk.exe
C:\WINDOWS\system32\MSSWCHX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Multi Media France Toolbar - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - C:\Program Files\Multi_Media_France\tbMult.dll
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [VadeRetro Outlook] "C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe -s"
O4 - HKLM\..\Run: [VadeRetro Outlook Express & Windows Mail] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_Oe.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Performance Center] C:\Program Files\Ascentive\Performance Center\APCMain.exe -m
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Moniteur reseau 802.11g OLITEC.lnk = C:\Program Files\OLITEC\Common\RaUI.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://kiw.imgag.com/imgag/cp/install/crusher-kiwen.cab
O16 - DPF: {C36661D7-3590-45B1-80B5-520839E94DAD} (MaxisSimCity4PatcherX Control) - http://simcity.ea.com/update/MaxisSimCity4PatcherX.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MySqlInventime - Unknown owner - c:\mysql\bin\mysqld-max-nt.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 19:26
Windows ne peut pas démarrer ce périphérique matériel car ses informations de configuration (dans le Registre) sont incomplètes ou endommagées. (Code 19)

Cliquez sur Résolution des problèmes pour démarrer la résolution des problèmes pour ce périphérique.
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
30 mai 2008 à 19:35
re,

ok je voie,

tu as le cd d´installation avec tes drivers de base ?

dans ce cas tu click sur resoudre le probleme et insert le cd dans le lecteur il devrait trouver le driver manquant...

sinon ca va mieux enfin le hijack this est propre a mes yeux...

mais il va faloir que tu passe ceci :

Fais un scan avec cet antispyware :

Telecharge malwarebytes + tutoriel :

-> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

Tu l´instale; le programme va se mettre automatiquement a jour.

Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

Puis click sur "rechercher".

Laisse le scanner le pc...

Si des elements on ete trouvés > click sur supprimer la selection.

si il t´es demandé de redemarrer > click sur "yes".

A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

Copie et colle le rapport stp.

@+
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 19:38
oui tu a raison il y un point exclamation jaune que doije faire
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
30 mai 2008 à 19:44
tu as le cd d´installation avec tes drivers de base ?

dans ce cas tu click sur resoudre le probleme et insert le cd dans le lecteur il devrait trouver le driver manquant...
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 19:53
non je n ais pas de cd comment faire et quand j allume msn et que je vais voir mais mail sa me dit la connection que vous utiliser n ais pas securiser et le logo avaste n bas a droit nexite plus que faire
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008 > bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 20:01
et le virus exist il toujour mercie
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
30 mai 2008 à 20:28
re,

tu peux aller ici et telecharger les drivers...

https://www.touslesdrivers.com/index.php?v_page=29

tu clcik sur detection et tu voie ce qu´il te propose...

pour avast laisse le pour le moment et passe ceci :


Telecharge malwarebytes + tutoriel :

-> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

Tu l´instale; le programme va se mettre automatiquement a jour.

Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

Puis click sur "rechercher".

Laisse le scanner le pc...

Si des elements on ete trouvés > click sur supprimer la selection.

si il t´es demandé de redemarrer > click sur "yes".

A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

Copie et colle le rapport stp.

@+
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 20:57
je narrive pas a reparer mon clavier peux tu m aider la je fait le scane etapres je te le poste et surtout mercei m le bosse
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
30 mai 2008 à 20:58
ca ne le fait pas sur tous les drivers ?
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 21:14
je ne comprend pas
0
bouglada Messages postés 25 Date d'inscription jeudi 29 mai 2008 Statut Membre Dernière intervention 30 mai 2008
30 mai 2008 à 21:39
jai un amie qui a cd instalation xp 2000 comme mon pc sa peux marcher
0
g!rly Messages postés 18209 Date d'inscription vendredi 17 août 2007 Statut Contributeur Dernière intervention 30 novembre 2014 406
30 mai 2008 à 21:28
tu peux aller ici et telecharger les drivers...

https://www.touslesdrivers.com/index.php?v_page=29

tu clcik sur detection et tu voie ce qu´il te propose...
0