Se connecter avec
S'enregistrer | Connectez-vous

PUB intempestives arf!!! comment reinstaller partiellement.

Dernière réponse : dans Sécurité

Bonjour

depuis queleques jours j'ai des fenetres de pubs qui apparaissent sans cesse, j'ai installé un anti spyware mais rien n'y fait tout mon pc bug
J'aimerais faire une reinstallation partielle pour ne pas tout perdre mais comment fait faire?
Sur certain PC il faut appuyer sur la touche F10 mais sur le mien sa marche pas j'ai un pc portable asus
pouvez vous me donner la marche à suivre?
Merci
Lassé par la pub ? Créez un compte

Logfile of HijackThis v1.99.1
Scan saved at 19:23:45, on 09/06/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ASWLSVC.exe
C:\WINDOWS\ATKKBService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Progra~1\ASUS\WLAN Card Utilities\Center.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Microsoft Works\WksSb.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\Imgtask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Shareaza\Shareaza.exe
C:\Program Files\Micro Application\12 DICOS Indispensables\MediaDICO12.EXE
C:\Program Files\Micro Application\12 DICOS Indispensables\Rac12.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Asus\Asus ChkMail\ChkMail.exe
C:\Program Files\Asus\ASUS Hotkey\Hotkey.exe
C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
C:\Program Files\WinAce\WinAce.exe
C:\Program Files\WinAce\order.exe
C:\DOCUME~1\CAROLI~1\LOCALS~1\Temp\~AceTemp\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {01A10E80-F95B-48F2-B82F-2B2AE3122ADA} - C:\WINDOWS\system32\tuvSifCT.dll (file missing)
O2 - BHO: (no name) - {02959035-BFB0-4A4F-B3C9-597740D1A1E3} - C:\WINDOWS\system32\nnnljjjk.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1B52F5AF-9646-4D11-8995-9A5E79E32F58} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {AB14E64A-56DE-0425-FF4D-7FA2969B4C95} - C:\WINDOWS\system32\mnlodw.dll (file missing)
O2 - BHO: (no name) - {BD3C6F7C-6C8D-48F6-AC52-5E4071AEB257} - C:\WINDOWS\system32\byXPGXNH.dll (file missing)
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Control Center] C:\Progra~1\ASUS\WLAN Card Utilities\Center.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [ImgTask] C:\WINDOWS\Imgtask.exe
O4 - HKLM\..\Run: [Spam Blocker for Outlook Express] C:\PROGRA~1\SPAMBL~1\bin\102215~1.0\SBInst.exe
O4 - HKLM\..\Run: [SpamBlockerUtilityOE] C:\Program Files\SpamBlockerUtility\bin\10.2.215.0\OEAddOn.exe
O4 - HKLM\..\Run: [SBUSA] "C:\Program Files\SpamBlockerUtility\bin\10.2.215.0\SBUSA.exe"
O4 - HKLM\..\Run: [SBI] C:\Documents and Settings\caroline amory\Local Settings\Temporary Internet Files\Content.IE5\LMNOLR4M\install_sbd_fr[1].exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [BMebf07f68] Rundll32.exe "C:\WINDOWS\system32\encgreyh.dll",s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MediaDico] C:\Program Files\Micro Application\12 DICOS Indispensables\LanceMediaDICO12.exe Lancement
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
O4 - HKCU\..\Run: [WinButler] C:\Documents and Settings\caroline amory\Application Data\WinButler\WinButler.exe
O4 - HKCU\..\Run: [SfKg6wIPu] C:\Documents and Settings\caroline amory\Application Data\Microsoft\Windows\vkqixn.exe
O4 - HKCU\..\Run: [JavaCore] C:\Program Files\\JavaCore\\JavaCore.exe
O4 - HKCU\..\Run: [Svconr] C:\Program Files\Svconr\Svconr.exe
O4 - HKCU\..\Run: [Acmw] "C:\WINDOWS\system32\FNTS~1\dllhost.exe" -vt yazb
O4 - HKCU\..\Run: [Gbu] "C:\Program Files\a?sembly\w?crtupd.exe"
O4 - HKCU\..\Run: [A00F1FCF44C.exe] C:\DOCUME~1\CAROLI~1\LOCALS~1\Temp\_A00F1FCF44C.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: ASUS ChkMail.lnk = C:\Program Files\Asus\Asus ChkMail\ChkMail.exe
O4 - Global Startup: Hotkey.lnk = C:\Program Files\Asus\ASUS Hotkey\Hotkey.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {C5428486-50A0-4a02-9D20-520B59A9F9B2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: ShopperReports - Compare travel rates - {C5428486-50A0-4a02-9D20-520B59A9F9B3} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld...
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://express.foto.com/Newuploader/ImageUploader4.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A94D321C-077E-4AB3-9E37-4C6A819546BC}: NameServer = 80.10.246.2,80.10.246.129
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: byXPGXNH - byXPGXNH.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: __c0089C4A - C:\WINDOWS\system32\__c0089C4A.dat
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASWLSVC - Unknown owner - C:\WINDOWS\system32\ASWLSVC.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe

Voila le scan
qu'es qui eest mauvais
merci de ton aide

Re,

[#ff0000]Désactive tes protections résidentes (antivirus, Spybot-S&D, etc.) ![/#f]

  • Télécharge ComboFix ([#ff0000]sUBs[/#f]) sur ton Bureau.
  • Double clique sur ComboFix.exe (le .exe n'est pas forcément visible) afin de le lancer.
  • Lorsque la recherche sera terminée, un rapport apparaîtra. Poste ce rapport (C:\combofix.txt*) dans ta prochaine réponse.

    AIDE : Un guide et un tutoriel sur l'utilisation de ComboFix
    * le nom de la partition peut changer

    voici le scan avec combo fix
    que dois je faire maintenant

    ComboFix 08-06-08.8 - caroline amory 2008-06-09 21:29:03.2 - FAT32x86
    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.99 [GMT 2:00]
    Endroit: C:\Documents and Settings\\Bureau\ComboFix.exe

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\\Application Data\WeatherDPA
    C:\WINDOWS\BMebf07f68.xml
    C:\WINDOWS\system32\byXRlkJd.dll
    C:\WINDOWS\system32\cerkifvt.dll
    C:\WINDOWS\system32\eanwmbhg.ini
    C:\WINDOWS\system32\encgreyh.dll
    C:\WINDOWS\system32\eyomsphx.ini
    C:\WINDOWS\system32\gfkiybjq.ini
    C:\WINDOWS\system32\jlcnykcs.dll
    C:\WINDOWS\system32\jpjemhqx.dll
    C:\WINDOWS\system32\kjjjlnnn.ini
    C:\WINDOWS\system32\kjjjlnnn.ini2
    C:\WINDOWS\system32\nanrmmds.ini
    C:\WINDOWS\system32\rfhkrtvr.exe
    C:\WINDOWS\system32\TCfiSvut.ini
    C:\WINDOWS\system32\TCfiSvut.ini2
    C:\WINDOWS\system32\unjsffew.dll
    C:\WINDOWS\system32\unmiuxce.exe
    C:\WINDOWS\system32\uwdephxm.exe
    C:\WINDOWS\system32\vjnlqiug.dll
    C:\WINDOWS\system32\wkaqdeho.dll
    .
    ---- Previous Run -------
    .
    C:\Program Files\asembl~1
    C:\Program Files\JavaCore
    C:\Program Files\JavaCore\UnInstall.exe
    C:\Program Files\Spcron
    C:\Program Files\Spcron\Spc.dll
    C:\Program Files\Svconr
    C:\Program Files\Temporary
    C:\WINDOWS\cookies.ini
    C:\WINDOWS\pskt.ini
    C:\WINDOWS\system32\fnts~1
    C:\WINDOWS\system32\fnts~1\F?nts\
    C:\WINDOWS\system32\mcrh.tmp
    C:\xcrashdump.dat
    D:\Autorun.inf

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-05-09 to 2008-06-09 ))))))))))))))))))))))))))))))))))))
    .

    2008-06-09 12:39 . 2008-06-09 12:39 <REP> d--hs---- C:\FOUND.052
    2008-06-08 22:57 . 2008-06-08 22:57 <REP> d-------- C:\Program Files\Alwil Software
    2008-06-08 22:36 . 2008-06-08 22:36 <REP> d--hs---- C:\FOUND.051
    2008-06-08 20:53 . 2008-06-08 20:53 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-06-08 20:53 . 2008-06-08 20:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-06-08 20:23 . 2008-06-08 20:23 <REP> d--hs---- C:\FOUND.050
    2008-06-08 19:28 . 2008-06-08 19:28 <REP> d--hs---- C:\FOUND.049
    2008-06-08 00:29 . 2008-06-08 00:29 37,888 --a------ C:\WINDOWS\system32\~.exe
    2008-06-08 00:29 . 2008-06-09 12:57 25,088 --a------ C:\WINDOWS\system32\__c0089C4A.dat
    2008-06-07 15:16 . 2008-06-07 15:16 <REP> d--hs---- C:\FOUND.048
    2008-06-06 08:51 . 2008-06-06 08:51 13,502 --a------ C:\WINDOWS\system32\JambaIconFR.ico
    2008-06-06 08:51 . 2008-06-06 08:51 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconFR.ico
    2008-06-06 08:31 . 2008-06-06 08:31 372,736 --------- C:\WINDOWS\system32\nnnljjjk.dll_old
    2008-06-06 08:26 . 2008-06-06 08:26 <REP> d-------- C:\Documents and Settings\caroline amory\Application Data\WinButler
    2008-06-06 08:26 . 2008-06-06 08:26 <REP> d-------- C:\Documents and Settings\caroline amory\Application Data\SurfAccuracy
    2008-06-06 08:26 . 59,392 C:\WINDOWS\system32\byXPGXNH.dll
    2008-05-28 13:02 . 2008-05-28 10:02 74,240 --------- C:\WINDOWS\b156.exe_old
    2008-05-12 15:43 . 2008-05-12 12:43 68,096 --------- C:\WINDOWS\b155.exe_old

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
    2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
    2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
    2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
    2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
    2008-03-10 16:03 87,608 ----a-w C:\Documents and Settings\caroline a\Application Data\inst.exe
    2008-03-10 16:03 47,360 ----a-w C:\Documents and Settings\caroline \Application Data\pcouffin.sys
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01A10E80-F95B-48F2-B82F-2B2AE3122ADA}]
    C:\WINDOWS\system32\tuvSifCT.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02959035-BFB0-4A4F-B3C9-597740D1A1E3}]
    C:\WINDOWS\system32\nnnljjjk.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1B52F5AF-9646-4D11-8995-9A5E79E32F58}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AB14E64A-56DE-0425-FF4D-7FA2969B4C95}]
    C:\WINDOWS\system32\mnlodw.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BD3C6F7C-6C8D-48F6-AC52-5E4071AEB257}]
    C:\WINDOWS\system32\byXPGXNH.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
    "MediaDico"="C:\Program Files\Micro Application\12 DICOS Indispensables\LanceMediaDICO12.exe" [2002-12-24 15:31 253952]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" [ ]
    "WOOKIT"="C:\PROGRA~1\WANADOO\Shell.exe" [ ]
    "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
    "Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" [2008-01-01 17:49 4739072]
    "WinButler"="C:\Documents and Settings\caroline a\Application Data\WinButler\WinButler.exe" [ ]
    "SfKg6wIPu"="C:\Documents and Settings\caroline \Application Data\Microsoft\Windows\vkqixn.exe" [ ]
    "Acmw"="C:\WINDOWS\system32\FNTS~1\dllhost.exe" [ ]
    "Gbu"="C:\Program Files\a?sembly\w?crtupd.exe" [ ]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2004-11-03 17:48 94208]
    "ASUS Live Update"="C:\Program Files\ASUS\ASUS Live Update\ALU.exe" [2003-09-19 12:54 172032]
    "Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2004-01-19 16:33 81920]
    "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-20 16:20 98394]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-20 16:20 688218]
    "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-09-09 21:10 344064]
    "Control Center"="C:\Progra~1\ASUS\WLAN Card Utilities\Center.exe" [2004-11-30 11:33 1577472]
    "ccApp"="c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2005-03-23 15:34 58992]
    "SoundMan"="SOUNDMAN.EXE" [2004-09-29 12:38 69632 C:\WINDOWS\soundman.exe]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
    "InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-09-13 11:51 1450096]
    "Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2002-06-26 20:07 725046]
    "Microsoft Works Update Detection"="C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2001-10-05 16:51 28738]
    "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 14:54 241664]
    "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-10-10 13:27 100056]
    "RemoteControl"="C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
    "SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [ ]
    "tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2004-04-20 13:25 1847296]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
    "ImgTask"="C:\WINDOWS\Imgtask.exe" [2006-12-13 04:26 20480]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoExpandedNewMenu"= 1 (0x1)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{BD3C6F7C-6C8D-48F6-AC52-5E4071AEB257}"= C:\WINDOWS\system32\byXPGXNH.dll [ ]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXPGXNH]
    byXPGXNH.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0089C4A]
    C:\WINDOWS\system32\__c0089C4A.dat 2008-06-09 12:57 25088 C:\WINDOWS\system32\__c0089C4A.dat

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OPTENET_GUI]
    --a------ 2006-12-20 10:14 404536 C:\PROGRA~1\CONTRO~1\bin\optgui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "OPTENET_FILTER"=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Messenger\\MSMSGS.EXE"=
    "C:\\Program Files\\SUPPORT.COM\\BIN\\TGCMD.EXE"=
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Documents and Settings\\caroline\\Application Data\\SopCast\\adv\\SopAdver.exe"=
    "C:\\Program Files\\SopCast\\SopCast.exe"=
    "C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
    "C:\\Program Files\\TVAnts\\Tvants.exe"=
    "C:\\Program Files\\Shareaza\\Shareaza.exe"=

    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
    R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\WINDOWS\system32\ASNDIS5.SYS [2002-09-09 19:54]
    R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys [2004-08-26 03:37]
    R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D.sys [2004-07-06 19:56]
    R3 ZD1211U(ASUS);ASUS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ASUS);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-11-29 16:53]
    S3 Asushwio;Asushwio;C:\WINDOWS\system32\drivers\Asushwio.sys [2000-03-29 14:17]
    S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
    S3 ComFiltr;Panda Anti-Dialer;C:\WINDOWS\system32\DRIVERS\COMFiltr.sys []
    S4 OPTENET_FILTER;Orange Contrôle Parental;C:\Program Files\Controle Parental\bin\optproxy.exe []

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
    \Shell\AutoRun\command - F:\Imageviewer.exe

    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-06-09 21:36:13
    Windows 5.1.2600 Service Pack 2 FAT NTAPI

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 0

    **************************************************************************
    .
    --------------------- DLLs a charg‚ sous des processus courants ---------------------

    PROCESS: C:\WINDOWS\system32\winlogon.exe
    -> C:\WINDOWS\system32\__c0089C4A.dat
    -> C:\WINDOWS\system32\byXPGXNH.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
    C:\PROGRAM FILES\AHEAD\INCD\INCDSRV.EXE
    C:\PROGRAM FILES\FICHIERS COMMUNS\SYMANTEC SHARED\CCSETMGR.EXE
    C:\PROGRAM FILES\FICHIERS COMMUNS\SYMANTEC SHARED\CCEVTMGR.EXE
    C:\WINDOWS\SYSTEM32\ATI2EVXX.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASWUPDSV.EXE
    C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST4\ASHSERV.EXE
    C:\WINDOWS\SYSTEM32\ASWLSVC.EXE
    C:\WINDOWS\ATKKBSERVICE.EXE
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\PROGRAM FILES\ASUS\WLAN CARD UTILITIES\CENTER.EXE
    C:\PROGRAM FILES\MICRO APPLICATION\12 DICOS INDISPENSABLES\MEDIADICO12.EXE
    C:\PROGRAM FILES\MICRO APPLICATION\12 DICOS INDISPENSABLES\RAC12.EXE
    C:\PROGRAM FILES\ASUS\ASUS CHKMAIL\CHKMAIL.EXE
    C:\Program Files\Asus\ASUS Hotkey\Hotkey.exe
    C:\PROGRAM FILES\HP\DIGITAL IMAGING\BIN\HPQTRA08.EXE
    C:\WINDOWS\ATK0100\ATKOSD.EXE
    C:\PROGRAM FILES\HP\HPCORETECH\COMP\HPTSKMGR.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\Program Files\HP\hpcoretech\comp\hpdarc.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-06-09 21:39:22 - machine was rebootedComboFix-quarantined-files.txt 2008-06-09 19:39:08

    Pre-Run: 27,546,779,648 octets libres
    Post-Run: 27,736,702,976 octets libres

    212 --- E O F --- 2008-05-17 06:19:51

    Re,

    Télécharge MalwareByte's Anti-Malware sur ton Bureau.
    Installe-le en double-cliquant sur le fichier Download_mbam-setup.exe.

    Une fois l'installation et la mise à jour effectuées, redémarre en mode sans échec.
    AIDE : Redémarrer en mode sans échec

  • Exécute maintenant MalwareByte's Anti-Malware. Si cela n'est pas déjà fait, sélectionne "Exécuter un examen complet".
  • Afin de lancer la recherche, clic sur"Rechercher".
  • Une fois le scan terminé, une fenêtre s'ouvre, clic sur OK. Deux possibilités s'offrent à toi :
    -- si le programme n'a rien trouvé, appuie sur OK. Un rapport va apparaître, ferme-le.
    -- si des infections sont présentes, clic sur "Afficher les résultats" puis sur "Supprimer la sélection". Enregistre le rapport sur ton Bureau afin de le poster dans ta prochaine réponse.
    [#ff0000]REMARQUE : Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.[/#f]

    AIDE : Tuto en images sur MBAM

    voici le log de malwarebyte

    Malwarebytes' Anti-Malware 1.17
    Version de la base de données: 846

    21:05:35 11/06/2008
    mbam-log-6-11-2008 (21-05-35).txt

    Type de recherche: Examen complet (C:\|D:\|)
    Eléments examinés: 92087
    Temps écoulé: 1 hour(s), 51 minute(s), 15 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 2
    Clé(s) du Registre infectée(s): 6
    Valeur(s) du Registre infectée(s): 2
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 1
    Fichier(s) infecté(s): 46

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    C:\WINDOWS\system32\byXPGXNH.dll (Trojan.Vundo) -> Unloaded module successfully.
    C:\WINDOWS\system32\__c0089C4A.dat (Trojan.Agent) -> Unloaded module successfully.

    Clé(s) du Registre infectée(s):
    HKEY_CLASSES_ROOT\CLSID\{bd3c6f7c-6c8d-48f6-ac52-5e4071aeb257} (Trojan.Vundo) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bd3c6f7c-6c8d-48f6-ac52-5e4071aeb257} (Trojan.Vundo) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byxpgxnh (Trojan.Vundo) -> Delete on reboot.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0089c4a (Trojan.Agent) -> Delete on reboot.
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Spcron (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

    Valeur(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{bd3c6f7c-6c8d-48f6-ac52-5e4071aeb257} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform\SpamBlockerUtility 10.2.215.0 (Adware.Hotbar) -> Quarantined and deleted successfully.

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    C:\Documents and Settings\caroline amory\Application Data\SurfAccuracy (Adware.SurfAccuracy) -> Quarantined and deleted successfully.

    Fichier(s) infecté(s):
    C:\WINDOWS\system32\byXPGXNH.dll (Trojan.Vundo) -> Delete on reboot.
    C:\QooBox\Quarantine\C\Program Files\Spcron\Spc.dll.vir (Adware.Agent) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\Program Files\JavaCore\UnInstall.exe.vir (Adware.Insider) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\byXRlkJd.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\jpjemhqx.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\rfhkrtvr.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\unmiuxce.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\QooBox\Quarantine\C\WINDOWS\system32\uwdephxm.exe.vir (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\b155.exe_old (Trojan.BHO) -> Quarantined and deleted successfully.
    C:\WINDOWS\b156.exe_old (Adware.Agent) -> Quarantined and deleted successfully.
    C:\Documents and Settings\caroline amory\Application Data\SurfAccuracy\SAccU.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0176842.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0176860.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0176861.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0176862.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0176864.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0176865.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0176866.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0176867.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0176868.dll (Adware.Hotbar) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177835.dll (Adware.Shoper) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177837.dll (Adware.ClickSpring) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177841.exe (Adware.ClickSpring) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177844.exe (Trojan.BHO) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177845.exe (Adware.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177871.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177881.exe (Adware.SearchAid) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177882.exe (Adware.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177883.exe (Adware.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177912.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177929.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177931.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177932.dll (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177933.exe (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP212\A0177936.dll (Adware.SurfAccuracy) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP213\A0178917.DLL (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP214\A0179034.dll (Adware.Agent) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP214\A0179035.exe (Adware.Insider) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP214\A0181006.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP214\A0181010.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP214\A0181011.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP214\A0181013.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\System Volume Information\_restore{FEB5B9F2-22E9-4D22-9EB1-5305D9609BBC}\RP214\A0181014.exe (Trojan.LowZones) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\__c0089C4A.dat (Trojan.Agent) -> Delete on reboot.
    C:\WINDOWS\system32\~.exe (Trojan.Agent) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

    Voila le nouveau scan hijakthis

    ALogfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:17:06, on 13/06/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\ATK0100\HControl.exe
    C:\Program Files\ASUS\ASUS Live Update\ALU.exe
    C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Progra~1\ASUS\WLAN Card Utilities\Center.exe
    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\Program Files\Microsoft Works\WksSb.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe
    C:\Program Files\Support.com\bin\tgcmd.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\Imgtask.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Micro Application\12 DICOS Indispensables\MediaDICO12.EXE
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Shareaza\Shareaza.exe
    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\Micro Application\12 DICOS Indispensables\Rac12.EXE
    C:\Program Files\Asus\Asus ChkMail\ChkMail.exe
    C:\Program Files\Asus\ASUS Hotkey\Hotkey.exeA
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\WINDOWS\system32\ASWLSVC.exe
    C:\WINDOWS\ATKKBService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\ATK0100\ATKOSD.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Documents and Settings\caroline amory\Bureau\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: (no name) - {01A10E80-F95B-48F2-B82F-2B2AE3122ADA} - C:\WINDOWS\system32\tuvSifCT.dll (file missing)
    O2 - BHO: (no name) - {02959035-BFB0-4A4F-B3C9-597740D1A1E3} - C:\WINDOWS\system32\nnnljjjk.dll (file missing)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: (no name) - {AB14E64A-56DE-0425-FF4D-7FA2969B4C95} - C:\WINDOWS\system32\mnlodw.dll (file missing)
    O2 - BHO: (no name) - {BD3C6F7C-6C8D-48F6-AC52-5E4071AEB257} - C:\WINDOWS\system32\byXPGXNH.dll (file missing)
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - c:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
    O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
    O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [Control Center] C:\Progra~1\ASUS\WLAN Card Utilities\Center.exe
    O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
    O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
    O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\bin\tgcmd.exe" /server /startmonitor
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [ImgTask] C:\WINDOWS\Imgtask.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MediaDico] C:\Program Files\Micro Application\12 DICOS Indispensables\LanceMediaDICO12.exe Lancement
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\WANADOO\Shell.exe appLaunchClientZone.shl|PARAM= cnx
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
    O4 - HKCU\..\Run: [WinButler] C:\Documents and Settings\caroline amory\Application Data\WinButler\WinButler.exe
    O4 - HKCU\..\Run: [SfKg6wIPu] C:\Documents and Settings\caroline amory\Application Data\Microsoft\Windows\vkqixn.exe
    O4 - HKCU\..\Run: [Acmw] "C:\WINDOWS\system32\FNTS~1\dllhost.exe" -vt yazb
    O4 - HKCU\..\Run: [Gbu] "C:\Program Files\a?sembly\w?crtupd.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: ASUS ChkMail.lnk = C:\Program Files\Asus\Asus ChkMail\ChkMail.exe
    O4 - Global Startup: Hotkey.lnk = C:\Program Files\Asus\ASUS Hotkey\Hotkey.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Démarrage rapide du logiciel HP Image Zone.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.asus.com
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld...
    O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://express.foto.com/Newuploader/ImageUploader4.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{A94D321C-077E-4AB3-9E37-4C6A819546BC}: NameServer = 80.10.246.2,80.10.246.129
    O20 - Winlogon Notify: byXPGXNH - byXPGXNH.dll (file missing)
    O20 - Winlogon Notify: __c0089C4A - C:\WINDOWS\system32\__c0089C4A.dat (file missing)
    O23 - Service: ASWLSVC - Unknown owner - C:\WINDOWS\system32\ASWLSVC.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
    O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: InCD Helper (read only) (InCDsrvR) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - c:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe

    --
    End of file - 11680 bytes

    Voila

    ComboFix 08-06-08.8 - caroline amory 2008-06-14 11:17:11.3 - FAT32x86
    Endroit: C:\Documents and Settings\caroline amory\Bureau\ComboFix.exe

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\caroline amory\Application Data\inst.exe
    C:\Documents and Settings\caroline amory\Local Settings\Temporary Internet Files\bestwiner.stt
    C:\Documents and Settings\caroline amory\Local Settings\Temporary Internet Files\CPV.stt

    .
    ((((((((((((((((((((((((((((( Fichiers créés 2008-05-14 to 2008-06-14 ))))))))))))))))))))))))))))))))))))
    .

    2008-06-11 21:14 . 2008-06-11 21:14 215 --a------ C:\WINDOWS\system32\MRT.INI
    2008-06-10 22:03 . 2008-06-10 22:03 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-06-10 22:03 . 2008-06-10 22:03 <REP> d-------- C:\Documents and Settings\caroline amory\Application Data\Malwarebytes
    2008-06-10 22:03 . 2008-06-10 22:03 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-06-10 22:03 . 2008-06-11 15:00 34,296 --a------ C:\WINDOWS\system32\drivers\mbamcatchme.sys
    2008-06-10 22:03 . 2008-06-11 15:00 15,864 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-06-10 19:55 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
    2008-06-10 19:55 . 2008-04-14 17:52 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
    2008-06-09 12:39 . 2008-06-09 12:39 <REP> d--hs---- C:\FOUND.052
    2008-06-08 22:57 . 2008-06-08 22:57 <REP> d-------- C:\Program Files\Alwil Software
    2008-06-08 22:36 . 2008-06-08 22:36 <REP> d--hs---- C:\FOUND.051
    2008-06-08 20:53 . 2008-06-08 20:53 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-06-08 20:53 . 2008-06-08 20:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-06-08 20:23 . 2008-06-08 20:23 <REP> d--hs---- C:\FOUND.050
    2008-06-08 19:28 . 2008-06-08 19:28 <REP> d--hs---- C:\FOUND.049
    2008-06-07 15:16 . 2008-06-07 15:16 <REP> d--hs---- C:\FOUND.048
    2008-06-06 08:51 . 2008-06-06 08:51 13,502 --a------ C:\WINDOWS\system32\JambaIconFR.ico
    2008-06-06 08:51 . 2008-06-06 08:51 9,662 --a------ C:\WINDOWS\system32\ZoneAlarmIconFR.ico
    2008-06-06 08:31 . 2008-06-06 08:31 372,736 --------- C:\WINDOWS\system32\nnnljjjk.dll_old
    2008-06-06 08:26 . 2008-06-06 08:26 <REP> d-------- C:\Documents and Settings\caroline amory\Application Data\WinButler

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\RMCast.sys
    2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
    2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
    2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
    2008-04-17 10:52 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\dllcache\mswstr10.dll
    2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
    2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\dllcache\msjint40.dll
    2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
    2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\dllcache\win32k.sys
    2008-03-10 16:03 47,360 ----a-w C:\Documents and Settings\caroline amory\Application Data\pcouffin.sys
    .

    ((((((((((((((((((((((((((((( snapshot@2008-06-09_21.38.22.56 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-06-09 19:34:20 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2008-06-14 05:59:14 2,048 --s-a-w C:\WINDOWS\bootstat.dat
    + 2008-04-14 15:52:46 272,768 ------w C:\WINDOWS\Driver Cache\i386\bthport.sys
    - 2008-02-16 09:02:34 1,024,000 ----a-w C:\WINDOWS\system32\browseui.dll
    + 2008-04-21 07:02:28 1,024,000 ----a-w C:\WINDOWS\system32\browseui.dll
    - 2008-02-16 09:02:34 152,064 ----a-w C:\WINDOWS\system32\cdfview.dll
    + 2008-04-21 07:02:28 152,064 ----a-w C:\WINDOWS\system32\cdfview.dll
    - 2008-02-16 09:02:34 1,056,768 ----a-w C:\WINDOWS\system32\danim.dll
    + 2008-04-21 07:02:28 1,056,768 ----a-w C:\WINDOWS\system32\danim.dll
    - 2008-02-16 09:02:34 1,024,000 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
    + 2008-04-21 07:02:28 1,024,000 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
    - 2008-02-16 09:02:34 152,064 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
    + 2008-04-21 07:02:28 152,064 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
    - 2008-02-16 09:02:34 1,056,768 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
    + 2008-04-21 07:02:28 1,056,768 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
    - 2008-02-16 09:02:34 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
    + 2008-04-21 07:02:28 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll
    - 2008-02-16 09:02:36 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
    + 2008-04-21 07:02:28 205,312 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll
    - 2008-02-16 09:02:36 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
    + 2008-04-21 07:02:28 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll
    - 2008-02-16 09:02:36 251,392 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
    + 2008-04-21 07:02:30 251,392 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll
    - 2008-02-16 09:02:36 96,768 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
    + 2008-04-21 07:02:30 96,768 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll
    - 2008-02-16 09:02:36 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
    + 2008-04-21 07:02:30 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll
    - 2008-02-16 22:32:38 3,080,704 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
    + 2008-04-21 07:02:34 3,080,704 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
    - 2008-02-16 09:02:36 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
    + 2008-04-21 07:02:34 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll
    - 2008-02-16 09:02:38 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
    + 2008-04-21 07:02:34 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll
    - 2008-02-16 09:02:38 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
    + 2008-04-21 07:02:36 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll
    - 2008-02-16 09:02:38 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
    + 2008-04-21 07:02:36 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll
    - 2008-02-16 09:02:38 1,495,040 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
    + 2008-04-21 07:02:38 1,495,040 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
    - 2008-02-16 09:02:38 474,624 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
    + 2008-04-21 07:02:38 474,624 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
    - 2008-02-16 09:02:40 617,984 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
    + 2008-04-21 07:02:40 617,984 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll
    - 2008-02-16 09:02:40 663,552 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
    + 2008-04-21 07:02:40 663,552 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll
    - 2008-02-16 09:02:34 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
    + 2008-04-21 07:02:28 357,888 ----a-w C:\WINDOWS\system32\dxtmsft.dll
    - 2008-02-16 09:02:36 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
    + 2008-04-21 07:02:28 205,312 ----a-w C:\WINDOWS\system32\dxtrans.dll
    - 2008-02-16 09:02:36 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
    + 2008-04-21 07:02:28 55,808 ----a-w C:\WINDOWS\system32\extmgr.dll
    - 2008-02-16 09:02:36 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
    + 2008-04-21 07:02:30 251,392 ----a-w C:\WINDOWS\system32\iepeers.dll
    - 2008-02-16 09:02:36 96,768 ----a-w C:\WINDOWS\system32\inseng.dll
    + 2008-04-21 07:02:30 96,768 ----a-w C:\WINDOWS\system32\inseng.dll
    - 2008-02-16 09:02:36 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
    + 2008-04-21 07:02:30 16,384 ----a-w C:\WINDOWS\system32\jsproxy.dll
    - 2008-05-09 21:35:04 16,863,864 ----a-w C:\WINDOWS\system32\MRT.exe
    + 2008-05-29 23:35:12 17,486,968 ----a-w C:\WINDOWS\system32\MRT.exe
    - 2008-02-16 22:32:38 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll
    + 2008-04-21 07:02:34 3,080,704 ----a-w C:\WINDOWS\system32\mshtml.dll
    - 2008-02-16 09:02:36 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
    + 2008-04-21 07:02:34 449,024 ----a-w C:\WINDOWS\system32\mshtmled.dll
    - 2008-02-16 09:02:38 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
    + 2008-04-21 07:02:34 146,432 ----a-w C:\WINDOWS\system32\msrating.dll
    - 2008-02-16 09:02:38 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
    + 2008-04-21 07:02:36 532,480 ----a-w C:\WINDOWS\system32\mstime.dll
    - 2008-02-16 09:02:38 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
    + 2008-04-21 07:02:36 39,424 ----a-w C:\WINDOWS\system32\pngfilt.dll
    - 2008-02-16 09:02:38 1,495,040 ----a-w C:\WINDOWS\system32\shdocvw.dll
    + 2008-04-21 07:02:38 1,495,040 ----a-w C:\WINDOWS\system32\shdocvw.dll
    - 2008-02-16 09:02:38 474,624 ----a-w C:\WINDOWS\system32\shlwapi.dll
    + 2008-04-21 07:02:38 474,624 ----a-w C:\WINDOWS\system32\shlwapi.dll
    - 2006-09-25 15:58:48 14,640 ------w C:\WINDOWS\system32\spmsg.dll
    + 2007-11-30 11:19:06 18,296 ------w C:\WINDOWS\system32\spmsg.dll
    - 2008-02-16 09:02:40 617,984 ----a-w C:\WINDOWS\system32\urlmon.dll
    + 2008-04-21 07:02:40 617,984 ----a-w C:\WINDOWS\system32\urlmon.dll
    - 2008-02-16 09:02:40 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
    + 2008-04-21 07:02:40 663,552 ----a-w C:\WINDOWS\system32\wininet.dll
    - 2008-02-15 23:03:14 370,176 ----a-w C:\WINDOWS\system32\xpsp3res.dll
    + 2008-04-17 11:03:46 370,176 ----a-w C:\WINDOWS\system32\xpsp3res.dll
    + 2008-06-14 05:59:28 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_7fc.dat
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01A10E80-F95B-48F2-B82F-2B2AE3122ADA}]
    C:\WINDOWS\system32\tuvSifCT.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02959035-BFB0-4A4F-B3C9-597740D1A1E3}]
    C:\WINDOWS\system32\nnnljjjk.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AB14E64A-56DE-0425-FF4D-7FA2969B4C95}]
    C:\WINDOWS\system32\mnlodw.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
    "MediaDico"="C:\Program Files\Micro Application\12 DICOS Indispensables\LanceMediaDICO12.exe" [2002-12-24 15:31 253952]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe" [ ]
    "WOOKIT"="C:\PROGRA~1\WANADOO\Shell.exe" [ ]
    "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
    "Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" [2008-01-01 17:49 4739072]
    "WinButler"="C:\Documents and Settings\caroline amory\Application Data\WinButler\WinButler.exe" [ ]
    "SfKg6wIPu"="C:\Documents and Settings\caroline amory\Application Data\Microsoft\Windows\vkqixn.exe" [ ]
    "Acmw"="C:\WINDOWS\system32\FNTS~1\dllhost.exe" [ ]
    "Gbu"="C:\Program Files\a?sembly\w?crtupd.exe" [ ]
    "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HControl"="C:\WINDOWS\ATK0100\HControl.exe" [2004-11-03 17:48 94208]
    "ASUS Live Update"="C:\Program Files\ASUS\ASUS Live Update\ALU.exe" [2003-09-19 12:54 172032]
    "Power_Gear"="C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe" [2004-01-19 16:33 81920]
    "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-20 16:20 98394]
    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-20 16:20 688218]
    "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-09-09 21:10 344064]
    "Control Center"="C:\Progra~1\ASUS\WLAN Card Utilities\Center.exe" [2004-11-30 11:33 1577472]
    "ccApp"="c:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2005-03-23 15:34 58992]
    "SoundMan"="SOUNDMAN.EXE" [2004-09-29 12:38 69632 C:\WINDOWS\soundman.exe]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
    "InCD"="C:\Program Files\Ahead\InCD\InCD.exe" [2004-09-13 11:51 1450096]
    "Microsoft Works Portfolio"="C:\Program Files\Microsoft Works\WksSb.exe" [2002-06-26 20:07 725046]
    "Microsoft Works Update Detection"="C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe" [2001-10-05 16:51 28738]
    "HP Component Manager"="C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" [2005-01-12 14:54 241664]
    "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2005-10-10 13:27 100056]
    "RemoteControl"="C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe" [2003-10-31 19:42 32768]
    "SpeedTouch USB Diagnostics"="C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" [ ]
    "tgcmd"="C:\Program Files\Support.com\bin\tgcmd.exe" [2004-04-20 13:25 1847296]
    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2005-02-16 23:11 49152]
    "ImgTask"="C:\WINDOWS\Imgtask.exe" [2006-12-13 04:26 20480]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

    C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
    ASUS ChkMail.lnk - C:\Program Files\Asus\Asus ChkMail\ChkMail.exe [2005-03-02 15:03:48 32768]
    Hotkey.lnk - C:\Program Files\Asus\ASUS Hotkey\Hotkey.exe [2005-03-02 15:04:43 798208]
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2004-05-28 22:31:38 241664]
    D‚marrage rapide du logiciel HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-05-28 23:06:36 53248]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoExpandedNewMenu"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXPGXNH]
    byXPGXNH.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0089C4A]
    C:\WINDOWS\system32\__c0089C4A.dat

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OPTENET_GUI]
    --a------ 2006-12-20 10:14 404536 C:\PROGRA~1\CONTRO~1\bin\optgui.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "OPTENET_FILTER"=2 (0x2)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\Messenger\\MSMSGS.EXE"=
    "C:\\Program Files\\SUPPORT.COM\\BIN\\TGCMD.EXE"=
    "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=
    "C:\\Documents and Settings\\caroline amory\\Application Data\\SopCast\\adv\\SopAdver.exe"=
    "C:\\Program Files\\SopCast\\SopCast.exe"=
    "C:\\Program Files\\SopCast\\adv\\SopAdver.exe"=
    "C:\\Program Files\\TVAnts\\Tvants.exe"=
    "C:\\Program Files\\Shareaza\\Shareaza.exe"=

    R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-16 01:20]
    R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-16 01:16]
    R3 ASNDIS5;ASNDIS5 Protocol Driver;C:\WINDOWS\system32\ASNDIS5.SYS [2002-09-09 19:54]
    R3 HSFHWSIS;HSFHWSIS;C:\WINDOWS\system32\DRIVERS\HSFHWSIS.sys [2004-08-26 03:37]
    R3 Video3D;ASUS Video3D Service;C:\WINDOWS\system32\Drivers\Video3D.sys [2004-07-06 19:56]
    R3 ZD1211U(ASUS);ASUS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ASUS);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-11-29 16:53]
    S3 Asushwio;Asushwio;C:\WINDOWS\system32\drivers\Asushwio.sys [2000-03-29 14:17]
    S3 AvFlt;Antivirus Filter Driver;C:\WINDOWS\system32\drivers\av5flt.sys []
    S3 ComFiltr;Panda Anti-Dialer;C:\WINDOWS\system32\DRIVERS\COMFiltr.sys []
    S4 OPTENET_FILTER;Orange Contrôle Parental;C:\Program Files\Controle Parental\bin\optproxy.exe []

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
    \Shell\AutoRun\command - F:\Imageviewer.exe

    *Newly Created Service* - CATCHME
    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-06-14 11:19:22
    Windows 5.1.2600 Service Pack 2 FAT NTAPI

    Balayage processus cachés ...

    Balayage caché autostart entries ...

    Balayage des fichiers cachés ...

    Scan terminé avec succès
    Les fichiers cachés: 0

    **************************************************************************
    .
    Temps d'accomplissement: 2008-06-14 11:19:49
    ComboFix-quarantined-files.txt 2008-06-14 09:19:48
    ComboFix2.txt 2008-06-09 19:39:24

    Pre-Run: 25,603,768,320 octets libres
    Post-Run: 26,703,298,560 octets libres

    239 --- E O F --- 2008-06-11 19:14:46

    Re,

    Copie (Ctrl+C) le texte se situant dans le cadre ci-dessous :

    File::
    C:\WINDOWS\system32\nnnljjjk.dll_old

    Folder::
    C:\FOUND.052
    C:\FOUND.051
    C:\FOUND.050
    C:\FOUND.049
    C:\FOUND.048
    C:\Documents and Settings\caroline amory\Application Data\WinButler\WinButler.exe
    C:\Documents and Settings\caroline amory\Application Data\Microsoft

    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01A10E80-F95B-48F2-B82F-2B2AE3122ADA}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{02959035-BFB0-4A4F-B3C9-597740D1A1E3}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{AB14E64A-56DE-0425-FF4D-7FA2969B4C95}]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "WinButler"=-
    "SfKg6wIPu"=-
    "Acmw"=-
    "Gbu"=-
    "SpybotSD TeaTimer"=-
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXPGXNH]
    [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0089C4A]


    Ouvre le Bloc-Notes puis colle (Ctrl+V) le texte précedemment copié.
    Sauvegarde ce fichier sous le nom de CFScript.txt.

    Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :


    Cela va relancer Combofix, tape sur 1 puis valide. Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.
    [#ff0000]NOTE : S'il n'y a pas de rédémarrage, poste quand même les rapports demandés.[/#f]
    Lassé par la pub ? Créez un compte
    Tom's guide dans le monde