Pb virus :Analyse findykill et Hijack this

sambou911 Messages postés 18 Statut Membre -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour,
Bonjour a tous

J'ai un gros probleme avec mes deux ordi en reseaux...
Tout d'abord il faut savoir que je n'ai pas d'antivirus (oui je sais tres malin...)

Depuis quelques jours il y a une succession de pannes!!!!
Ca a commencé par ma connection a internet qui se deconnectait et se reconnecait spontanement toutes les 10 min. Puis la connection apparaissait bonne et l'ordinateur ne diagnostiquait pas de problème mais au bout de qq min de connection la page internet restait blanche sans message d'erreur mais sans acces a aucun site...
Maintenant de plus en plus de programmes ne marchent plus : BS player, Spybot, et meme L'appercu de photo!
J'ai telecharger tant bien que mal (en desactivant et en reactivant ma connection toutes les 5 min) Avast, l'installation se lance l'interface de l'assistant s'affiche 1 seconde puis s'efface sans que j'ai le temps de cliquer sur suivant!!!
A l'heure d'aujourd'hui je ne peux pas rester connecté a internet plus de 5 min ensuite il faut que je desactive/reactive ma connection pour avoir 5 min de plus ect...

Mon MODE SANS ECHEC NE MARCHE PAS !!! puisque mon ordi s'etteint avans le lancement du mode sans echec...

Je ne sais pas quoi faire j'ai peur de perdre petit a petit toutes mes données...
Merci d'avance

Voici les rapports deja effectués:

----------------- FindyKill V4.709 ------------------

* User : laura - ACER-29569F1E48
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 10/12/08 par Chiquitine29
* Recherche effectuée à 12:43:24 le 18/12/2008
* Windows XP - Internet Explorer 6.0.2900.5512

((((((((((((((((( *** Recherche *** ))))))))))))))))))

--------------- [ Processus actifs ] ----------------

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\drivers\SYSTMON.EXE
C:\acer\epm\epm-dm.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxtray.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\D-Link\Bluetooth Software\BTTray.exe
C:\DOCUME~1\laura\LOCALS~1\Temp\27034.exe
C:\DOCUME~1\laura\LOCALS~1\Temp\28274.exe

--------------- [ Fichiers/Dossiers infectieux ] ----------------

»»»» Presence des fichiers dans C:

»»»» Presence des fichiers dans C:\WINDOWS

»»»» Presence des fichiers dans C:\WINDOWS\Prefetch

Found ! - C:\WINDOWS\prefetch\742.EXE-14C51122.pf
Found ! - C:\WINDOWS\prefetch\129.EXE-28C05F99.pf
Found ! - C:\WINDOWS\prefetch\452.EXE-190CC5F8.pf
Found ! - C:\WINDOWS\prefetch\44552.EXE-2A57CA60.pf
Found ! - C:\WINDOWS\prefetch\49864.EXE-03494FE4.pf
Found ! - C:\WINDOWS\prefetch\700.EXE-052F4665.pf
Found ! - C:\WINDOWS\prefetch\399.EXE-30D5E5D7.pf
Found ! - C:\WINDOWS\prefetch\288.EXE-35350111.pf
Found ! - C:\WINDOWS\prefetch\568.EXE-2D93D831.pf
Found ! - C:\WINDOWS\prefetch\27034.EXE-31970A2D.pf
Found ! - C:\WINDOWS\prefetch\28274.EXE-3560FBFD.pf

»»»» Presence des fichiers dans C:\WINDOWS\system32

»»»» Presence des fichiers dans C:\WINDOWS\system32\config\systemprofile\AppData\Roaming

»»»» Presence des fichiers dans C:\WINDOWS\system32\drivers

»»»» Presence des fichiers dans C:\Documents and Settings\laura\Application Data

»»»» Presence des fichiers dans C:\DOCUME~1\laura\LOCALS~1\Temp

»»»» Presence des fichiers dans C:\Documents and Settings\laura\Local Settings\Temporary Internet Files\Content.IE5

Found ! [11/03/2008 14:52] - C:\Documents and Settings\laura\Local Settings\Temporary Internet Files\Content.IE5\GF9L23AN\D92A21CE69B64231FD1D638952DFF8[1].jpg
Found ! [18/02/2008 20:03] - C:\Documents and Settings\laura\Local Settings\Temporary Internet Files\Content.IE5\P4RWSE3Q\D979F4F0E464E1DE74AC69445B64AF[1].jpg

--------------- [ Registre / Startup ] ----------------

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
Windows Video Drivers=C:\RECYCLER\S-1-5-21-2554790503-3335217910-174153591-5315\winlogon.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
epm-dm=c:\acer\epm\epm-dm.exe
WOOWATCH=C:\PROGRA~1\WANADOO\Watch.exe
SynTPLpr=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
SunJavaUpdateSched="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
RTHDCPL=RTHDCPL.EXE
PHIME2002ASync=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
Persistence=C:\WINDOWS\system32\igfxpers.exe
PCMService="C:\Program Files\Acer\Acer Arcade\PCMService.exe"
MSPY2002=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
Logitech Hardware Abstraction Layer=KHALMNPR.EXE
LaunchApp=Alaunch
iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
IMJPMIG8.1="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
IgfxTray=C:\WINDOWS\system32\igfxtray.exe
HotKeysCmds=C:\WINDOWS\system32\hkcmd.exe
High Definition Audio Property Page Shortcut=HDAShCut.exe
eRecoveryService=C:\Program Files\Acer\eRecovery\Monitor.exe
ePowerManagement=C:\Acer\ePM\ePM.exe boot
AzMixerSel=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
Alcmtr=ALCMTR.EXE
QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
MFServices="C:\Program Files\Companion Suite IH\MFServices.exe" -n
MFPrintServer="C:\Program Files\Companion Suite IH\MFPrintServer.exe"
OneTouch Monitor=C:\PROGRA~1\COMPAN~2\ONETOU~3.EXE
SYSTMON.EXE=C:\WINDOWS\system32\drivers\SYSTMON.EXE
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
Installed=1
NoChange=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1

[HKEY_CURRENT_USER\software\local appwizard-generated applications\iRiver Manager Internet Audio Player]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\Launch Tool]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\Logitech Secure Encryption Wizard]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\MFPrintServer]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\MMDiag]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\PPLinks]

--------------- [ Registre / Clés infectieuses ] ----------------

--------------- [ Etat / Services ] ----------------

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

- sans echec non fonctionnel !!

Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

- sans echec non fonctionnel !!

+- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

Ndisuio - Type de démarrage = 3

EapHost - Type de démarrage = 3

Ip6Fw - Type de démarrage = 3

SharedAccess - Type de démarrage = 2

wuauserv - Type de démarrage = 2

/!\ wscsvc - Type de démarrage = 4

--------------- [ Recherche dans supports amovibles] ----------------

+- Informations :

C: - Lecteur fixe

D: - Lecteur fixe

E: - Lecteur de CD-ROM

+- presence des fichiers :

--------------- [ Registre / Mountpoint2 ] ----------------

-> Not found !

------------------- ! Fin du rapport ! --------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:07:34, on 20/12/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\CyberLink\Shared Files\RichVideo.exe
C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
C:\WINDOWS\system32\drivers\SYSTMON.EXE
C:\acer\epm\epm-dm.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Acer\Acer Arcade\PCMService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Acer\eRecovery\Monitor.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\D-Link\Bluetooth Software\BTTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://portail.free.fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
F2 - REG:system.ini: Shell=Explorer.exe %windir%\system32\drivers\SYSTMON.EXE
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: (no name) - {B529F6A4-DF0A-4CDE-A8EF-0AFFD4C1CA86} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [epm-dm] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MFServices] "C:\Program Files\Companion Suite IH\MFServices.exe" -n
O4 - HKLM\..\Run: [MFPrintServer] "C:\Program Files\Companion Suite IH\MFPrintServer.exe"
O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\COMPAN~2\ONETOU~3.EXE
O4 - HKLM\..\Run: [SYSTMON.EXE] C:\WINDOWS\system32\drivers\SYSTMON.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Windows Video Drivers] C:\RECYCLER\S-1-5-21-2554790503-3335217910-174153591-5315\winlogon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
O4 - Startup: RC.exe.lnk = C:\Program Files\DTV\DVB-T CardBus\RC.exe
O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\D-Link\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=https://portail.free.fr/
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/ [...] NPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NNServ - Unknown owner - C:\Program Files\NewDotNet\nnrun.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: sgbx_device - Unknown owner - C:\WINDOWS\system32\sgbxcoms.exe (file missing)
O24 - Desktop Component 0: (no name) - http://ww11.spots1.hundiesgalleries.com/ [...] pic008.jpg

--
End of file - 10356 bytes

GMER ne trouve pas de modification

PLEASE DONNEZ MOI UNE SOLUTION RAPIDE POUR DESINFECTER MON PC!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
Configuration: Windows XP
Internet Explorer 7.0 sur l'ordi par lequel j'ecris/ mozilla firefox sur les 2 ordi infectés

23 réponses

  • 1
  • 2
  1. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    slt effectivement pas d'antivirus c'est pas bien...

    pour reparer le mode sans echec ici:
    http://www.assistepc.com/forum/reparer-le-mode-sans-echec-de-windows-vt867.html

    et dis nous si le mode sans echec remarche

    _______________

    sinon

    vide ta corbeille puis

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    --> Double clic sur le raccourci FindyKill sur ton bureau

    --> Au menu principal,choisi l option 2 (Suppression)

    /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

    /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

    -------> ensuite post le rapport FindyKill.txt

    Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
    Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

    __________________

    Télécharge ici :

    http://images.malwareremoval.com/random/RSIT.exe

    random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Clique Continue à l'écran Disclaimer.

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt (<<qui sera affiché)
    ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

    NB : Les rapports sont sauvegardés dans le dossier C:\rsit
    0
  2. sambou911 Messages postés 18 Statut Membre
     
    Merci!
    Alors réparation mode sans échec avec la première solution 0 mais j'ai pas reéssayer depuis la supression des fichiers infectés parce que je sais pas comment ca se passe un fois qu'il est lancé...
    Sinon g deja l'impression que ma connection internet respire un peu mieux, meme beaucoup mieux!!...

    Petite question est ce que je peux me servir de findykill sur mon autre ordi qui était en reseaux avec celui dont je t'ai envoyé les rapports qui a exactement les memes symptomes ?

    Voici les rapports:

    ----------------- FindyKill V4.709 ------------------

    * User : laura - ACER-29569F1E48
    * executed from : C:\Program Files\FindyKill
    * Update on 10/12/08 par Chiquitine29
    * Start at 20:48:34 the 20/12/2008
    * Windows XP - Internet Explorer 6.0.2900.5512

    ((((((((((((((( *** deleting *** ))))))))))))))))))

    --------------- [ Active Processes ] ----------------

    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\WINDOWS\system32\logonui.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\userinit.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Acer\eManager\anbmServ.exe
    C:\WINDOWS\system32\WgaTray.exe
    C:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
    C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
    C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\WINDOWS\system32\fxssvc.exe

    --------------- [ Infected files / folders ] ----------------

    »»»» Supression files in C:

    »»»» Supression files in C:\WINDOWS

    »»»» Supression files in C:\WINDOWS\Prefetch

    Deleted ! - C:\WINDOWS\prefetch\742.EXE-14C51122.pf
    Deleted ! - C:\WINDOWS\prefetch\129.EXE-28C05F99.pf
    Deleted ! - C:\WINDOWS\prefetch\452.EXE-190CC5F8.pf
    Deleted ! - C:\WINDOWS\prefetch\44552.EXE-2A57CA60.pf
    Deleted ! - C:\WINDOWS\prefetch\49864.EXE-03494FE4.pf
    Deleted ! - C:\WINDOWS\prefetch\700.EXE-052F4665.pf
    Deleted ! - C:\WINDOWS\prefetch\399.EXE-30D5E5D7.pf
    Deleted ! - C:\WINDOWS\prefetch\288.EXE-35350111.pf
    Deleted ! - C:\WINDOWS\prefetch\568.EXE-2D93D831.pf
    Deleted ! - C:\WINDOWS\prefetch\27034.EXE-31970A2D.pf
    Deleted ! - C:\WINDOWS\prefetch\28274.EXE-3560FBFD.pf

    »»»» Supression files in C:\WINDOWS\system32

    »»»» Supression files in C:\WINDOWS\system32\config\systemprofile\AppData\Roaming

    »»»» Supression files in C:\WINDOWS\system32\drivers

    »»»» Supression files in C:\Documents and Settings\laura\Application Data

    »»»» Supression files in C:\DOCUME~1\laura\LOCALS~1\Temp

    »»»» Supression files in C:\Documents and Settings\laura\Local Settings\Temporary Internet Files\Content.IE5

    Deleted ! - C:\Documents and Settings\laura\Local Settings\Temporary Internet Files\Content.IE5\GF9L23AN\D92A21CE69B64231FD1D638952DFF8[1].jpg
    Deleted ! - C:\Documents and Settings\laura\Local Settings\Temporary Internet Files\Content.IE5\P4RWSE3Q\D979F4F0E464E1DE74AC69445B64AF[1].jpg
    Deleted ! - C:\Documents and Settings\laura\Local Settings\Application Data\Microsoft\Media Player\Cache d'images\LocalMLS\{569A6DEC-E49C-4C95-BA4B-3808B64EF40C}.jpg
    Deleted ! - C:\Documents and Settings\laura\Local Settings\Application Data\Microsoft\Media Player\Cache d'images\LocalMLS\{1FA798E4-BB64-4012-A8EC-0096CED41CAE}.jpg
    Deleted ! - C:\Documents and Settings\laura\Local Settings\Application Data\Microsoft\Media Player\Cache d'images\LocalMLS\{F41DBF49-0C68-4FC4-9E20-D3640DB6423E}.jpg
    Deleted ! - C:\Documents and Settings\laura\Local Settings\Application Data\Microsoft\Media Player\Cache d'images\LocalMLS\{B640E33B-FFEB-49AE-9F6E-C536D603DB28}.jpg

    --------------- [ Registry / Infected keys ] ----------------

    --------------- [ States / Restarting of services ] ----------------

    +- Safe boot mode restored !

    +- Services : [ Auto=2 / Request=3 / Disable=4 ]

    Ndisuio - Type of startup = 3

    EapHost - Type of startup = 2

    Ip6Fw - Type of startup = 2

    SharedAccess - Type of startup = 2

    wuauserv - Type of startup = 2

    wscsvc - Type of startup = 2

    --------------- [ Cleaning removable drives ] ----------------

    +- Informations :

    C: - Lecteur fixe

    D: - Lecteur fixe

    F: - Lecteur amovible

    G: - Lecteur amovible

    H: - Lecteur amovible

    +- deleting files :

    Deleted ! - F:\autorun.inf
    Deleted ! - G:\autorun.inf
    Deleted ! - H:\autorun.inf

    --------------- [ Registry / Mountpoint2 ] ----------------

    -> Not found !

    --------------- [ Searching Cracks / Keygen ] ----------------

    C:\Documents and Settings\laura\Recent\Nero.Burning.Rom.Reloaded.v7.8.5.0.Incl.Keygen-FFF.lnk
    C:\Documents and Settings\laura\Mes documents\Ma musique\iTunes\iTunes Music\Vitalic\Unknown Album\the horrorist - Crackers.mp3
    C:\Documents and Settings\laura\Mes documents\Ma musique\iTunes\iTunes Music\Tchaikovsky\Nutcracker Suite
    C:\Documents and Settings\laura\Mes documents\Ma musique\iTunes\iTunes Music\Tchaikovsky\Nutcracker Suite\Russian Dance.mp3

    ---------------- ! End of report ! ------------------

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by laura at 2008-12-20 20:54:33
    Microsoft Windows XP Édition familiale Service Pack 3
    System drive C: has 6 GB (17%) free of 36 GB
    Total RAM: 1014 MB (60% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:54:38, on 20/12/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Acer\eManager\anbmServ.exe
    C:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
    C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
    C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLService.exe
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\System32\svchost.exe
    C:\DOCUME~1\laura\LOCALS~1\Temp\30fff.exe
    C:\DOCUME~1\laura\LOCALS~1\Temp\322ac.exe
    C:\DOCUME~1\laura\LOCALS~1\Temp\3327b.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\laura\Bureau\RSIT.exe
    C:\Program Files\Trend Micro\HijackThis\laura.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://portail.free.fr/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    F2 - REG:system.ini: Shell=Explorer.exe %windir%\system32\drivers\SYSTMON.EXE
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
    O3 - Toolbar: (no name) - {B529F6A4-DF0A-4CDE-A8EF-0AFFD4C1CA86} - (no file)
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
    O4 - HKLM\..\Run: [epm-dm] c:\acer\epm\epm-dm.exe
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe"
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [LaunchApp] Alaunch
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [eRecoveryService] C:\Program Files\Acer\eRecovery\Monitor.exe
    O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MFServices] "C:\Program Files\Companion Suite IH\MFServices.exe" -n
    O4 - HKLM\..\Run: [MFPrintServer] "C:\Program Files\Companion Suite IH\MFPrintServer.exe"
    O4 - HKLM\..\Run: [OneTouch Monitor] C:\PROGRA~1\COMPAN~2\ONETOU~3.EXE
    O4 - HKLM\..\Run: [SYSTMON.EXE] C:\WINDOWS\system32\drivers\SYSTMON.EXE
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [Windows Video Drivers] C:\RECYCLER\S-1-5-21-2554790503-3335217910-174153591-5315\winlogon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [^SetupICWDesktop] (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] (User 'Default user')
    O4 - Startup: RC.exe.lnk = C:\Program Files\DTV\DVB-T CardBus\RC.exe
    O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
    O4 - Global Startup: BTTray.lnk = ?
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\D-Link\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\D-Link\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O14 - IERESET.INF: START_PAGE_URL=https://portail.free.fr/
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.mail.live.com/mail/w1/resources/MSNPUpld.cab
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
    O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\D-Link\Bluetooth Software\bin\btwdins.exe
    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe
    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe
    O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe
    O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NNServ - Unknown owner - C:\Program Files\NewDotNet\nnrun.exe (file missing)
    O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
    O23 - Service: sgbx_device - Unknown owner - C:\WINDOWS\system32\sgbxcoms.exe (file missing)
    O24 - Desktop Component 0: (no name) - http://spots1.hundiesgalleries.com/pigtailsroundasses/pictures/courtney/images/pic008.jpg
    0
  3. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    télécharge OTMoveIt
    http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

    double-clique sur OTMoveIt.exe pour le lancer.
    copie la liste qui se trouve en citation ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
    (attention bien mettre :files)

    :files
    C:\DOCUME~1\laura\LOCALS~1\Temp\30fff.exe
    C:\DOCUME~1\laura\LOCALS~1\Temp\322ac.exe
    C:\DOCUME~1\laura\LOCALS~1\Temp\3327b.exe
    C:\RECYCLER\S-1-5-21-2554790503-3335217910-174153591-5315\winlogon.exe
    :commands
    [purity]
    [emptytemp]
    [start explorer]

    clique sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    clique sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

    ______________________

    scan avec
    MalwareByte's Anti-Malware après mise a jour, en mode normal, fais un scan rapide et vire ce qui est trouvé et colle le rapport

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    ____________________________

    colle le rapport d'un scan en ligne
    avec un des suivants:

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Panda en ligne :
    http://pandasoftware.fr

    Kaspersky en ligne
    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    0
    1. sambou911 Messages postés 18 Statut Membre
       
      Voici deja le premier:

      ========== FILES ==========
      C:\DOCUME~1\laura\LOCALS~1\Temp\30fff.exe moved successfully.
      C:\DOCUME~1\laura\LOCALS~1\Temp\322ac.exe moved successfully.
      C:\DOCUME~1\laura\LOCALS~1\Temp\3327b.exe moved successfully.
      File/Folder C:\RECYCLER\S-1-5-21-2554790503-3335217910-174153591-5315\wi­nlogon.exe not found.
      ========== COMMANDS ==========
      File delete failed. C:\DOCUME~1\laura\LOCALS~1\Temp\etilqs_jhHnifHyJy3UoaHBNA5X scheduled to be deleted on reboot.
      User's Temp folder emptied.
      User's Temporary Internet Files folder emptied.
      User's Internet Explorer cache folder emptied.
      Local Service Temp folder emptied.
      File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
      Local Service Temporary Internet Files folder emptied.
      File delete failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be deleted on reboot.
      File delete failed. C:\WINDOWS\temp\sqlite_fXtzg2AghQJIgrN scheduled to be deleted on reboot.
      Windows Temp folder emptied.
      Java cache emptied.
      File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\XUL.mfl scheduled to be deleted on reboot.
      File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
      FireFox cache emptied.
      Temp folders emptied.
      Explorer started successfully

      OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12202008_211143

      Files moved on Reboot...
      File C:\DOCUME~1\laura\LOCALS~1\Temp\etilqs_jhHnifHyJy3UoaHBNA5X not found!
      File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
      C:\WINDOWS\temp\CLML_AGENT_LOG1.txt moved successfully.
      File C:\WINDOWS\temp\sqlite_fXtzg2AghQJIgrN not found!
      C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_MAP_ moved successfully.
      C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_001_ moved successfully.
      C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_002_ moved successfully.
      C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_003_ moved successfully.
      C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\XUL.mfl moved successfully.
      C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\urlclassifier3.sqlite moved successfully.
      0
    2. sambou911 Messages postés 18 Statut Membre
       
      Voila le rapport Malwarebyte's:
      Il y a 7 éléments en quarantaine j'en fais quoi?

      Malwarebytes' Anti-Malware 1.31
      Version de la base de données: 1456
      Windows 5.1.2600 Service Pack 3

      20/12/2008 22:07:24
      mbam-log-2008-12-20 (22-07-24).txt

      Type de recherche: Examen complet (C:\|D:\|)
      Eléments examinés: 92117
      Temps écoulé: 25 minute(s), 40 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 3
      Valeur(s) du Registre infectée(s): 1
      Elément(s) de données du Registre infecté(s): 1
      Dossier(s) infecté(s): 1
      Fichier(s) infecté(s): 2

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f919fbd3-a96b-4679-af26-f551439bb5fd} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b64f4a7c-97c9-11da-8bde-f66bad1e3f3a} (Rogue.WinAntivirus) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\WUSN.1 (Adware.WhenUSave) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\windows video drivers (Trojan.Agent) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

      Dossier(s) infecté(s):
      C:\Program Files\Save (Adware.WhenUSave) -> Quarantined and deleted successfully.

      Fichier(s) infecté(s):
      C:\Program Files\Save\ACM.dll (Adware.WhenUSave) -> Quarantined and deleted successfully.
      C:\RECYCLER\S-1-5-21-2554790503-3335217910-174153591-5315\winlogon.exe (Trojan.Agent) -> Delete on reboot.
      0
    3. sambou911 Messages postés 18 Statut Membre
       
      Par contre la connection recommence a beuguer et je peux pas rester sur internet trop longtemps je crois que j'arriverais pas a faire le scan en ligne... en plus j'ai mozilla et pas internet explorer
      0
    4. sambou911 Messages postés 18 Statut Membre
       
      Derniere chose (desolée) j'ai pas fu faire le scan de Malwarebyte's en mode sans echec...
      0
  4. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    télécharge combofix (par sUBs) ici :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    et enregistre le sur le bureau.

    déconnecte toi d'internet et ferme toutes tes applications.

    désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

    double-clique sur combofix.exe et suis les instructions

    à la fin, il va produire un rapport C:\ComboFix.txt

    réactive ton parefeu, ton antivirus, la garde de ton antispyware

    copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

    Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

    Tu as un tutoriel complet ici :

    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

    ______________________

    vire avast: si present comme ceci: https://www.avast.com/fr-fr/uninstall-utility

    _______________________

    mets antivir et colle un rapport avec:

    https://www.malekal.com/avira-free-security-antivirus-gratuit/
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. sambou911 Messages postés 18 Statut Membre
     
    ComboFix 08-12-20.03 - laura 2008-12-21 9:54:54.1 - [color=red][b]FAT32[/b][/color]x86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.1.1036.18.1014.622 [GMT 1:00]
    Lancé depuis: c:\documents and settings\laura\Bureau\ComboFix.exe
    Commutateurs utilisés :: c:\documents and settings\laura\Bureau\WinXP_FR_PER_BF.EXE
    * Un nouveau point de restauration a été créé
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\autorun.ini
    c:\windows\system32\drivers\npf.sys
    c:\windows\system32\packet.dll
    c:\windows\system32\pthreadVC.dll
    c:\windows\system32\rnaph.dll
    c:\windows\system32\wpcap.dll

    .
    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_NNSERV
    -------\Legacy_NPF
    -------\Service_NNServ
    -------\Service_NPF

    ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-21 au 2008-12-21 ))))))))))))))))))))))))))))))))))))
    .

    2008-12-20 21:51 . 2008-12-20 21:51 9,773 --a------ C:\9j6n1v4y8n8.exe
    2008-12-20 21:34 . 2008-12-20 21:34 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
    2008-12-20 21:34 . 2008-12-20 21:34 <REP> d-------- c:\documents and settings\laura\Application Data\Malwarebytes
    2008-12-20 21:34 . 2008-12-20 21:34 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
    2008-12-20 21:34 . 2008-12-03 19:52 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
    2008-12-20 21:34 . 2008-12-03 19:52 15,504 --a------ c:\windows\system32\drivers\mbam.sys
    2008-12-20 21:10 . 2008-12-20 21:10 <REP> d-------- C:\_OTMoveIt
    2008-12-20 20:54 . 2008-12-20 20:54 <REP> d-------- C:\rsit
    2008-12-20 14:09 . 2008-11-06 02:03 <REP> d-------- C:\SDFix
    2008-12-20 10:19 . 2008-12-20 10:54 64,557 --a------ C:\d9j6n1v4y8n8.exe
    2008-12-20 08:07 . 2008-12-20 08:07 <REP> d-------- c:\program files\Trend Micro
    2008-12-19 14:14 . 2008-12-19 14:14 250 --a------ c:\windows\gmer.ini
    2008-12-18 12:42 . 2008-12-18 12:42 <REP> d-------- c:\program files\FindyKill
    2008-12-15 11:18 . 2008-12-18 13:28 60,973 --a------ C:\c6u7b7y6z8p2.exe
    2008-12-15 11:03 . 2008-12-15 11:03 219,648 -r-hs---- c:\windows\system32\drivers\SYSTMON.EXE
    2008-12-14 23:03 . 2008-12-14 23:03 54,156 --ah----- c:\windows\QTFont.qfn
    2008-12-14 23:03 . 2008-12-14 23:03 1,409 --a------ c:\windows\QTFont.for
    2008-11-21 16:40 . 2008-11-21 16:40 <REP> d-------- c:\windows\system32\Samsung_USB_Drivers
    2008-11-21 16:40 . 2005-08-30 17:59 94,000 --a------ c:\windows\system32\drivers\ss_mdm.sys
    2008-11-21 16:40 . 2005-08-30 17:57 58,320 --a------ c:\windows\system32\drivers\ss_bus.sys
    2008-11-21 16:40 . 2005-08-30 17:58 8,304 --a------ c:\windows\system32\drivers\ss_mdfl.sys
    2008-11-21 16:40 . 2005-08-30 17:58 6,144 --a------ c:\windows\system32\drivers\ss_cmnt.sys
    2008-11-21 16:40 . 2005-08-30 17:58 6,144 --a------ c:\windows\system32\drivers\ss_cm.sys
    2008-11-21 16:40 . 2005-08-30 17:57 5,808 --a------ c:\windows\system32\drivers\ss_whnt.sys
    2008-11-21 16:40 . 2005-08-30 17:57 5,808 --a------ c:\windows\system32\drivers\ss_wh.sys
    2008-11-21 16:40 . 2005-08-28 20:51 766 --a------ c:\windows\system32\Uninstall.ico
    2008-11-21 16:39 . 2008-11-21 16:40 <REP> d-------- c:\program files\Samsung

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
    2008-10-24 11:21 455,296 ------w c:\windows\system32\dllcache\mrxsmb.sys
    2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
    2008-10-23 12:36 286,720 ------w c:\windows\system32\dllcache\gdi32.dll
    2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
    2008-10-16 13:13 202,776 ----a-w c:\windows\system32\dllcache\wuweb.dll
    2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
    2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\dllcache\wuaueng.dll
    2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
    2008-10-16 13:12 561,688 ----a-w c:\windows\system32\dllcache\wuapi.dll
    2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
    2008-10-16 13:12 323,608 ----a-w c:\windows\system32\dllcache\wucltui.dll
    2008-10-16 13:09 92,696 ----a-w c:\windows\system32\dllcache\cdm.dll
    2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
    2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
    2008-10-16 13:09 51,224 ----a-w c:\windows\system32\dllcache\wuauclt.exe
    2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
    2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
    2008-10-16 13:08 34,328 ----a-w c:\windows\system32\dllcache\wups.dll
    2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
    2008-10-16 13:06 208,744 ----a-w c:\windows\system32\muweb.dll
    2008-10-15 17:35 337,408 ------w c:\windows\system32\dllcache\netapi32.dll
    2008-10-03 10:03 247,326 ----a-w c:\windows\system32\strmdll.dll
    2008-10-03 10:03 247,326 ----a-w c:\windows\system32\dllcache\strmdll.dll
    2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
    2008-06-18 15:09 6,042 ----a-w c:\documents and settings\laura\Application Data\wklnhst.dat
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-17 68856]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "LaunchApp"="Alaunch" [X]
    "epm-dm"="c:\acer\epm\epm-dm.exe" [2005-08-11 258048]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-08 155648]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-08 745472]
    "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
    "PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
    "PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 455168]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2005-06-07 172032]
    "PCMService"="c:\program files\Acer\Acer Arcade\PCMService.exe" [2005-08-11 200704]
    "MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 116736]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2005-06-24 335872]
    "IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 266240]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-06-07 151552]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-06-07 135168]
    "eRecoveryService"="c:\program files\Acer\eRecovery\Monitor.exe" [2005-08-18 409600]
    "ePowerManagement"="c:\acer\ePM\ePM.exe" [2005-03-15 2951168]
    "AzMixerSel"="c:\program files\Realtek\InstallShield\AzMixerSel.exe" [2005-06-11 110592]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2006-09-01 339968]
    "SYSTMON.EXE"="c:\windows\system32\drivers\SYSTMON.EXE" [2008-12-15 219648]
    "RTHDCPL"="RTHDCPL.EXE" [2005-08-09 c:\windows\RTHDCPL.EXE]
    "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 c:\windows\system32\HdAShCut.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "DisableTaskMgr"= 1 (0x1)
    "DisableRegistryTools"= 1 (0x1)

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
    "DisableTaskMgr"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Shell"="Explorer.exe %windir%\\system32\\drivers\\SYSTMON.EXE"
    "SFCDisable"=dword:ffffff9d

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "msacm.l3acm"= l3codecp.acm
    "msacm.mkdmp3enc"= c:\progra~1\Acer\ACERAR~1\Kernel\Burner\MKDMP3Enc.ACM
    "vidc.DIV3"= DivXc32.dll
    "vidc.DIV4"= DivXc32f.dll
    "msacm.divxa32"= DivXa32.acm

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    --------- 2008-04-14 04:34 1752576 c:\program files\Messenger\msmsgs.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "FTRTSVC"=2 (0x2)

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001
    "AntiVirusOverride"=dword:00000001
    "FirewallOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Acer\\Acer Arcade\\PCMService.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
    "c:\\WINDOWS\\system32\\wscntfy.exe"=
    "c:\\WINDOWS\\Alaunch.exe"=
    "c:\\Program Files\\Adobe\\Acrobat 7.0\\Reader\\reader_sl.exe"=
    "c:\\WINDOWS\\system32\\wuauclt.exe"=
    "c:\\WINDOWS\\system32\\hkcmd.exe"=
    "c:\\Program Files\\D-Link\\Bluetooth Software\\BTTray.exe"=
    "c:\\WINDOWS\\ALCMTR.EXE"=
    "c:\\Program Files\\Media Player Classic\\mplayerc.exe"=
    "c:\\Program Files\\iTunes\\iTunesHelper.exe"=
    "c:\\Program Files\\Acer\\eRecovery\\Monitor.exe"=
    "c:\\WINDOWS\\system32\\IME\\PINTLGNT\\ImScInst.exe"=
    "c:\\Program Files\\Google\\GoogleToolbarNotifier\\GoogleToolbarNotifier.exe"=
    "c:\\acer\\epm\\epm-dm.exe"=
    "c:\\WINDOWS\\system32\\cleanmgr.exe"=
    "c:\\WINDOWS\\system32\\cmd.exe"=
    "c:\\WINDOWS\\system32\\drivers\\SYSTMON.EXE"=
    "c:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"=
    "c:\\ComboFix\\NirCmd.cfexe"=
    "c:\\DOCUME~1\\laura\\LOCALS~1\\Temp\\18a39.exe"=
    "c:\\DOCUME~1\\laura\\LOCALS~1\\Temp\\20555.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009

    R2 EpmPsd;Acer EPM Power Scheme Driver;\??\c:\windows\system32\drivers\epm-psd.sys [2005-11-27 4096]
    R2 EpmShd;Acer EPM System Hardware Driver;\??\c:\windows\system32\drivers\epm-shd.sys [2005-11-27 78208]
    R2 osaio;osaio;\??\c:\windows\system32\drivers\osaio.sys [2005-11-27 7296]
    R2 osanbm;osanbm;\??\c:\windows\system32\drivers\osanbm.sys [2005-11-27 4010]
    R3 WMI_MFC_TPSHOKER_80;WMI_MFC_TPSHOKER_80;\??\c:\windows\system32\drivers\qhpkpn.sys []
    S3 ids00026;ids00026;\??\c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00026.sys []
    S3 ids00118;ids00118;\??\c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00118.sys []
    S3 ids0014f;ids0014f;\??\c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids0014f.sys []
    S3 ids0015d;ids0015d;\??\c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids0015d.sys []
    S3 ids00180;ids00180;\??\c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00180.sys []
    S3 ids0018a;ids0018a;\??\c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids0018a.sys []
    S3 ids00196;ids00196;\??\c:\documents and settings\All Users\Application Data\Kaspersky Anti-Virus Personal\5.0\bases\ids00196.sys []
    S3 sgbx_device;sgbx_device;c:\windows\system32\sgbxcoms.exe -service []
    S3 WDM_Capture_220A;DVB-T TV Receiver;c:\windows\system32\Drivers\WDM_Capture_220A.sys [2007-02-09 18432]
    S3 WDM_Loader_220A;DVB-T TV Loader;c:\windows\system32\Drivers\WDM_Loader_220A.sys [2007-02-09 15488]
    S3 WlanUIG;Sagem 802.11g Wireless LAN USB Adapter Driver;c:\windows\system32\DRIVERS\WlanUIG.sys [2006-01-31 379456]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{788d54ca-3ea9-11dd-be53-0013ce69f481}]
    \Shell\AutoRun\command - F:\travel&work.exe
    \Shell\Shell00\Command - F:\travel&work.exe
    .
    Contenu du dossier 'Tâches planifiées'

    2007-09-15 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-10-10 17:13]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    Toolbar-{B529F6A4-DF0A-4CDE-A8EF-0AFFD4C1CA86} - (no file)
    WebBrowser-{B529F6A4-DF0A-4CDE-A8EF-0AFFD4C1CA86} - (no file)
    HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - c:\program files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
    HKLM-Run-WOOWATCH - c:\progra~1\WANADOO\Watch.exe
    HKLM-Run-MFServices - c:\program files\Companion Suite IH\MFServices.exe
    HKLM-Run-MFPrintServer - c:\program files\Companion Suite IH\MFPrintServer.exe
    HKLM-Run-OneTouch Monitor - c:\progra~1\COMPAN~2\ONETOU~3.EXE
    HKLM-Run-Logitech Hardware Abstraction Layer - KHALMNPR.EXE
    HKU-Default-RunOnce-^SetupICWDesktop - (no file)
    MSConfigStartUp-Google Desktop Search - c:\program files\Google\Google Desktop Search\GoogleDesktop.exe
    MSConfigStartUp-Livecom - c:\progra~1\LIVECOM\APPLIC~1\CommunicationAgent\CommunicationAgent.exe
    MSConfigStartUp-MsnMsgr - c:\program files\MSN Messenger\MsnMsgr.Exe
    MSConfigStartUp-WOOKIT - c:\progra~1\WANADOO\Shell.exe

    .
    ------- Examen supplémentaire -------
    .
    uSearch Page = hxxp://www.google.com
    uStart Page = about:blank
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uSearch Bar = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    IE: Envoyer au périphérique &Bluetooth... - c:\program files\D-Link\Bluetooth Software\btsendto_ie_ctx.htm
    FF - ProfilePath - c:\documents and settings\laura\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\
    FF - prefs.js: browser.startup.homepage - hxxp://fr.www.mozilla.com/fr/firefox/3.0.1/firstrun/|https://www.google.fr/?client=firefox-a&rls=org.mozilla:fr:official&gws_rd=ssl
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-21 09:59:10
    Windows 5.1.2600 Service Pack 3 FAT NTAPI

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\program files\INTEL\WIRELESS\BIN\EVTENG.EXE
    c:\program files\INTEL\WIRELESS\BIN\S24EVMON.EXE
    c:\acer\EMANAGER\ANBMSERV.EXE
    c:\program files\D-LINK\BLUETOOTH SOFTWARE\BIN\BTWDINS.EXE
    c:\program files\ACER\ACER ARCADE\KERNEL\TV\CLCAPSVC.EXE
    c:\program files\ACER\ACER ARCADE\KERNEL\CLML_NTSERVICE\CLMLSERVER.EXE
    c:\program files\ACER\ACER ARCADE\KERNEL\CLML_NTSERVICE\CLMLSERVICE.EXE
    c:\program files\INTEL\WIRELESS\BIN\REGSRVC.EXE
    c:\program files\CYBERLINK\SHARED FILES\RICHVIDEO.EXE
    c:\program files\ACER\ACER ARCADE\KERNEL\TV\CLSCHED.EXE
    c:\program files\IPOD\BIN\IPODSERVICE.EXE
    c:\program files\D-LINK\BLUETOOTH SOFTWARE\BTTRAY.EXE
    c:\program files\ADOBE\ACROBAT 7.0\READER\READER_SL.EXE
    c:\docume~1\laura\LOCALS~1\Temp\18a39.exe
    c:\docume~1\laura\LOCALS~1\Temp\20555.exe
    .
    **************************************************************************
    .
    Heure de fin: 2008-12-21 10:01:14 - La machine a redémarré
    ComboFix-quarantined-files.txt 2008-12-21 09:01:12

    Avant-CF: 6 436 913 152 octets libres
    Après-CF: 6,355,615,744 octets libres

    WinXP_FR_PER_BF.EXE
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

    262 --- E O F --- 2008-12-14 22:07:02
    0
  7. sambou911 Messages postés 18 Statut Membre
     
    Je craque!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
    Y a de plus en plus de programmes qui marchent pas je peu meme plus acceder a mes documents!
    Mon ordi me dis que antivir ne peut pas s'installer parc$e que iertutil est introuvable...!!!!!
    0
  8. sambou911 Messages postés 18 Statut Membre
     
    J'ai telecherger iertutil.dll et mai ntenant quand je clique sue l'icone antivir il se passe rien....
    0
  9. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    télécharge OTMoveIt
    http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

    double-clique sur OTMoveIt.exe pour le lancer.
    copie la liste qui se trouve en citation ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
    (attention bien mettre :files)

    :processus
    explorer.exe
    :files
    C:\d9j6n1v4y8n8.exe
    C:\9j6n1v4y8n8.exe
    C:\c6u7b7y6z8p2.exe
    c:\\DOCUME~1\\laura\\LOCALS~1\\Temp\\18a39.exe
    c:\\DOCUME~1\\laura\\LOCALS~1\\Temp\\20555.exe
    c:\docume~1\laura\LOCALS~1\Temp\18a39.exe
    c:\docume~1\laura\LOCALS~1\Temp\20555.exe
    :commands
    [purity]
    [emptytemp]
    [start explorer]

    clique sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    clique sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

    __________________

    finit de virer les traces de kaspersky: car c'est peut etre a cause de ces traces qu'il y a un souci pour mettre un antivirus

    http://grandpublic.kaspersky.fr/index.php?ShowID=257

    __________________

    Telecharge UsbFix sur ton bureau
    http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

    --> Lance l installation avec les parametres par default

    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

    --> Double clic sur le raccourci UsbFix sur ton bureau

    --> Le pc va redémarer

    -->Apres redémarrage post le rapport UsbFix.txt

    Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
    Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides

    ___________________

    colle le rapport d'un scan en ligne
    avec un des suivants:

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Panda en ligne :
    http://pandasoftware.fr

    Kaspersky en ligne
    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
    0
  10. sambou911 Messages postés 18 Statut Membre
     
    ========== FILES ==========
    C:\DOCUME~1\laura\LOCALS~1\Temp\30fff.exe moved successfully.
    C:\DOCUME~1\laura\LOCALS~1\Temp\322ac.exe moved successfully.
    C:\DOCUME~1\laura\LOCALS~1\Temp\3327b.exe moved successfully.
    File/Folder C:\RECYCLER\S-1-5-21-2554790503-3335217910-174153591-5315\wi­nlogon.exe not found.
    ========== COMMANDS ==========
    File delete failed. C:\DOCUME~1\laura\LOCALS~1\Temp\etilqs_jhHnifHyJy3UoaHBNA5X scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
    Local Service Temporary Internet Files folder emptied.
    File delete failed. C:\WINDOWS\temp\CLML_AGENT_LOG1.txt scheduled to be deleted on reboot.
    File delete failed. C:\WINDOWS\temp\sqlite_fXtzg2AghQJIgrN scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    Java cache emptied.
    File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\XUL.mfl scheduled to be deleted on reboot.
    File delete failed. C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
    FireFox cache emptied.
    Temp folders emptied.
    Explorer started successfully

    OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12202008_211143

    Files moved on Reboot...
    File C:\DOCUME~1\laura\LOCALS~1\Temp\etilqs_jhHnifHyJy3UoaHBNA5X not found!
    File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
    C:\WINDOWS\temp\CLML_AGENT_LOG1.txt moved successfully.
    File C:\WINDOWS\temp\sqlite_fXtzg2AghQJIgrN not found!
    C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_MAP_ moved successfully.
    C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_001_ moved successfully.
    C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_002_ moved successfully.
    C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\Cache\_CACHE_003_ moved successfully.
    C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\XUL.mfl moved successfully.
    C:\Documents and Settings\laura\Local Settings\Application Data\Mozilla\Firefox\Profiles\gazis8v9.default\urlclassifier3.sqlite moved successfully.

    J'arrive pas a acceder a la page web pour desinstaller Kaspersky depuis mon ordi infecté!
    0
  11. sambou911 Messages postés 18 Statut Membre
     
    Quand je double clic sur ubsfix ca redemarre pas ca mre demande si je veux 1-nettoyer, 2-vacciner, 3-desintaler ou Q-quitter
    0
  12. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    passe a la suite

    si impossible de faire le scan en ligne on verra
    0
  13. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    fais nettoyer avec usbfix
    0
  14. sambou911 Messages postés 18 Statut Membre
     
    c'est la catastrophe!! j'ai voulu installer internet explorer pour pouvoir faire le scan en ligne et ducoup j'ai desintaller mozilla et maintenant internet rame tellement que je peux plus acceder arien !!!!!!!
    0
  15. sambou911 Messages postés 18 Statut Membre
     
    j'ai reinstalle firefox mais je crois que j'arriverai pas a faire la scan en ligne...
    0
  16. sambou911 Messages postés 18 Statut Membre
     
    j'arrive pas a reccupérer le rapport d'usbfix
    0
  17. sambou911 Messages postés 18 Statut Membre
     
    Je sais pas si c'est ca?

    Changelog UsbFix établit le 2 decembre 2008
    outils créé par Chiquitine29 , aide aux mises a jours -> Chimay8

    >>>>>>in "ProgramFiles"<<<<<<<<<

    Internet Explorer\Connection Wizard\icwconn1\rada
    Internet Explorer\Connection Wizard\icwconn1\rade
    Internet Explorer\Connection Wizard\icwconn1\radf
    Internet Explorer\Connection Wizard\icwconn1\rad5
    Internet Explorer\Connection Wizard\icwconn1\rad0
    Internet Explorer\Connection Wizard\icwconn1\rad9
    Internet Explorer\Connection Wizard\icwconn1\rad4
    Internet Explorer\Connection Wizard\icwconn1\rad1
    Internet Explorer\Connection Wizard\icwconn1
    Movie Maker\explorer.exe
    Internet Explorer\explorer.exe

    >>>>>>in "Windows"<<<<<<<<<

    autorun.inf
    autorun.exe
    autorun.vbs
    autorun.reg
    autorun.ini
    autorun.fcb
    autorun.bat
    autorun.com
    AdobeR.exe
    Alecks.vbs
    bittorrent.exe
    cmd32.exe
    CwbRmDir.bat
    Fonts\Fonts.exe
    FS6519.dll.vbs
    funny.exe
    GMOGLFEO.exe
    hiqalowo.inf
    icapy.scr
    ilezyvu.bin
    Lany.vbs
    lumy.exe
    manulopa.reg
    MS32DLL.dll.vbs
    MyMP3.vbs
    nar.vbs
    osok.inf
    osotilasiq.pif
    oxafa.com
    qobo.dat
    rundll32.vbe
    sleep.vbe
    SysRes.vbs
    takice.lib
    tusoha.exe
    unahafiwik.exe
    waol.exe
    waziqepehi.ban
    WillPolo.vbs
    Win32DLL.vbs
    win.vbe
    window.exe
    wyzeha.com
    xcopy.exe
    yjilu.inf
    ylacupyb.dll

    RECYCLER\systems.com

    temp\039.tmp

    >>>>>>in "Windows\system32"<<<<<<<<<

    agucuri.vbs
    ahr.exe
    Alecks.vbs
    antinul.vbe
    amvo.exe
    amvo0.dll
    amvo1.dll
    amvo2.dll
    autorun.bat
    Autorun.com
    autorun.exe
    autorun.fcb
    autorun.inf
    autorun.ini
    autorun.reg
    autorun.vbs
    Autoruns.exe
    avpo.exe
    avpo0.dll
    avpo1.dll
    Bitkvo.exe
    Bitkv0.dll
    Bitkv1.dll
    cftmonn.exe
    Christina.jpg
    Christina.vbs
    ckvo.exe
    ckvo0.dll
    ckvo1.dll
    ckvo2.dll
    cradle_of_filth.vbe
    delself.bat
    FS6519.dll.vbs
    GMOGLFEO.exe
    icf.exe.exe
    ie.exe
    jvvo.exe
    jvvo0.dll
    jvvo1.dll
    jvvo2.dll
    jvvo3.dll
    j3ewro.exe
    jwedsfdo0.dll
    jwedsfdo1.dll
    jwedsfdo2.dll
    jwedsfdo3.dll
    jxnraqjxg.exe
    kavo.exe
    kamsoft.exe
    kav0.dll
    kav1.dll
    kav2.dll
    kav3.dll
    kavo0.dll
    kavo1.dll
    kavo2.dll
    kavo3.dll
    kdkfm.exe
    KEYBOARD.exe
    keygen.exe
    kulitut.bat
    kulitut.vbs
    kxvo.exe
    kxvo0.dll
    kxvo1.dll
    kxvo2.dll
    kxvo3.dll
    lExplore.exe
    loader.exe
    logoneui.exe
    LOVE-LETTER-FOR-YOU.HTM
    LOVE-LETTER-FOR-YOU.TXT.vbs
    msfun80.exe
    msime82.exe
    MSKernel32.vbs
    ne0kS.dll.wsf
    ne0kS.exe
    OeApi.vbs
    pubnet.vbs
    rs32net.exe
    SemiAntiVirus.vbs
    Sexy Girls.scr
    SpiderH.bmp
    SpiderH.jpeg
    SpiderH.vbs
    sys.vbs
    Syso.vbs
    SysRes.vbs
    syx.exe
    taso.exe
    tavo.exe
    tavo0.dll
    tavo1.dll
    tavo2.dll
    tavo3.dll
    temp1.exe
    temp2.exe
    temp?.exe
    text.txt
    Ecran.exe
    THe Girls
    tmp.reg
    tmp.txt
    t.txt
    vb@dock.vbs
    vl@dock.vbs
    Win32.vbs
    winudp64.exe

    dllcache\Default.exe

    >>>>>>in "Windows\system32\drivers"<<<<<<<<<

    ._Sanaa style-1 les formes.exe
    0hct8ybw.exe
    1ere partie du projet modifier.exe
    abdelali lahrach.exe
    Analyse transactionnelle.exe
    AutoRun.exe
    Bernoulli01215.exe"
    Cahiers français Quels modes de financement pour les entreprises - La Documentation française.exe
    Copie de Devoir I.exe
    e-ticket Juba Paris.exe
    fdfp2.exe
    fihi ghizlane Rapport de stage.exe
    graphic.exe
    intel.exe
    isew32.exe
    kheireddine.exe
    le_cadeau_du_sud(1).exe
    LEADERSHIP SKILLS FINAL.exe
    lettre de motivation.exe
    MSDS.exe
    Note.exe
    PREMIER CHAPITRE modifié.exe
    Raila Odinga.exe
    Rapport NADIA.exe
    spectro_masse1.exe
    td de reacteur.exe
    these-223.exe
    xyw9tmdj.exe

    >>>>>>in "Documents and Settings"<<<<<<<<<

    tazebama.dl_
    hook.dl_

    >>>>>>in "appdata"<<<<<<<<<

    fetomiv.vbs
    gumugy.vbs
    jicapikase.vbs
    mobyhikaja.vbs
    nebohozi.com
    orimuwy.exe
    sidymyvig.vbs
    tazebama\tazebama.log
    tazebama\zPharaoh.dat
    tazebama

    >>>>>>in "Temp files"<<<<<<<<<

    1.reg
    2.dll
    6257890.exe
    fq9.dll
    help.exe
    help1.rar
    inst.exe
    system.dll
    w2e.sys
    winhqqo.exe
    wintoift.exe
    xhjb.dll
    xxx6042.exe
    zb5ok.dll

    >>>>>>in "All Drives"<<<<<<<<<

    ._autorun.inf
    autorun.inf
    autorun.ini
    autorun.reg
    autorun.bat
    autorun.vbs
    autorun2.inf
    autosys.exe
    00hoeav.com
    096.bat
    0gjn3yw.exe
    0qx0sc6.bat
    0tmhoc.cmd
    0u.cmd
    0w.com
    0wk2.cmd
    108i.cmd
    1aq1obb.bat
    1bbvq96y.com
    1dg.exe
    1i.com
    1nkbd8h.bat
    1rfw8hjr.com
    1u0o8bnq.cmd
    1weicxa.com
    1XXEC.exe
    22xo.exe
    2ifetri.cmd
    2y8la.exe
    30ed3.exe
    33gmhso.bat
    39lpji.com
    3o.exe
    3wcxx91.cmd
    3xXx31.exe
    4vzjaw3o.sys
    62oop0ak.bat
    68.exe
    6tkoyhx.cmd
    6x8be16.cmd
    8e9gmih.bat
    8ng8w.com
    93vx0c.com
    9yqusig.bat
    22wcb21o.exe
    31n3b2h.exe
    39lpji.com
    80avp08.com
    82r9.cmd
    83fgj.com
    83l3v.cmd
    8df.exe >
    8h3hh3m.exe
    8tss2gwq.bat
    90imhpnc.exe
    92j11sm.com
    9es.com
    a1.bat
    a9.com
    abk.bat
    activexdebugger32.exe
    Administrateur_Fichiers.exe
    admp.exe
    adobeR.exe
    Akon.exe
    Alecks.vbs
    antihost.exe
    antinul.vbe
    aoutfq.exe
    ar.exe
    Atisetup.exe
    auto.exe
    autorum.exe
    AutoRun\Demo.exe
    autorun.exe
    autorun.pif
    autoruns.exe
    AutoScr.exe
    ay8p6v3.cmd
    Ayame.exe
    b3b9u.com
    bicsxk03.com
    bittorrent.exe
    bndafai.exe
    bo1dhu.bat
    bobm.exe
    boot.exe
    bootin.exe
    bplrl98.cmd
    buis.exe
    bwpncb6.com
    bxuup9r.bat c18vk.exe
    c9.com
    c9hehpa.bat
    camp.exe
    cayfq2.cmd
    cd8idoyl.com
    cdr.exe
    ceb6eu98.bat
    cekbru.pif
    clear.bat
    ClickMe.exe
    cftmonn.exe
    cfv90h.com
    Christina.vbs
    cjq.exe
    commands.txt
    comment.htt
    copetttt.com
    copy.exe
    cradle_of_filth.vbe
    cqdis.cmd
    cvqkuk.exe
    d3bn0j.exe
    ddyikr.cmd
    delautorun.bat
    DFD34719171.bat
    DFD34719375.bat
    DFD34719609.bat
    DFD34723328.bat
    DFD34723375.bat
    DFD34723781.bat
    DFD34724390.bat
    DFD34719609.bat
    DFD34724531.bat
    DFD34724656.bat
    DFD34725125.bat
    DFD34725218.bat
    DFD34726312.bat
    DFD34724390.bat
    DFD34726328.bat
    DFD34729609.bat
    DFD34730531.bat
    DFD34730937.bat
    DFD34734937.bat
    DFD34739859.bat
    DFD34741421.bat
    DFD34741734.bat
    DFD34741843.bat
    DFD*.bat
    dhv2u8.cmd
    DPFMate.exe
    dstart.exe
    dtqlv.exe
    dynrn6e.cmd
    e898.com
    e9ehn1m8.com
    eb9ehyh.exe
    Ecran.exe
    ek.com
    ekf6dbg0.com
    ekugb3.bat
    erdeIect.com
    esta ig.vbs
    ev60a2.cmd
    explorer.exe
    exqmmle.exe
    f0.cmd
    f2ir.com
    fe.bat
    ffojc.com
    fi.cmd
    FLIPART.EXE
    folder.exe
    Folder.htt
    fooool.exe
    Form5.exe
    forSV.exe
    FS6519.dll.vbs
    fucker.vbs
    fun.xls.exe
    g2p3s.exe
    g2pfnid.com
    g83816.com
    gdmae.bmp
    Ghost.pif
    gkyzcijfb.exe
    GMOGLFEO.exe
    gqsk.bat
    graphic.exe
    gsxlexd.cmd
    gxlxknou.exe
    gy.cmd
    h0s2.bat h2.com
    hfhludy.exe
    hgu.bat
    hni.cmd
    host.exe
    hsomklg.exe
    hxt9.bat
    i0.cmd
    i8.cmd
    ie.exe
    igxv.cmd
    ij.bat
    ilpg9ejd.com
    info.exe
    infrom.exe
    ino6.com
    install.exe
    intel.exe
    intro.exe
    ipy.cmd
    iq0ecwcj.cmd
    lsass.exe
    itsduel.exe
    iwjj.com
    j4c8t8b5l3a6.exe
    j8q8d.cmd
    jbfqv8j.cmd
    jdhc2x2.com
    jdwx.exe
    jfjsipw.exe
    jfvkcsy.bat
    jiwsxh39.exe
    JJJ.exe
    Jojo.exe
    jwwgtuh.exe
    jxnraqjxg.exe
    jxpiinstall.exe
    k6wkwon2.exe
    ka1nk.bat
    kaq86asx.bat
    kayira.bat
    kbqbptn.exe
    kdkfm.exe
    kdy.cmd
    kfmyoc.pif
    khbph.exe
    killVBS.vbs
    kk3.bat
    KM.exe
    kmd.exe
    kn6jhgc.cmd
    kqnns.exe
    kqsr.exe
    krg62.cmd
    kulitut.bat
    kulitut.vbs
    kxax.cmd
    l2f.cmd
    l9dwu8.bat
    lExplore.exe
    lgcadwx.bat
    lgrncie.bat
    lky.exe
    ln9.exe
    lo.exe
    loader.exe
    logoneui.exe
    Long.exe
    LOVE.PIF
    ltljrg.exe
    lumy.exe
    lurjlnps.exe
    lvxvo1xg.cmd
    m1t8ta.com
    m9j.com
    mail.exe
    manulopa.reg
    mcxa.exe
    Menu.exe
    mgjpcfdg.cm
    mnl6on3.com
    mp.bat
    mp.cmd
    mp.com
    Movie1.exe
    mrsne.bat
    MS-DOS.com
    MS32DLL.dll.vbs
    MSd040.vbs
    MSdC64.vbs
    MSdFB7.vbs
    MSd141.vbs
    MSd191.vbs
    MSd49A.vbs
    MSdE78.vbs
    MSd*.vbs
    mshta.exe
    MSKernel32.vbs
    muniu.exe
    MyMP3.vbs
    n1detect.com
    n2de.cmd
    n6j.com
    n6j6pc0.com
    n6t1h.cmd
    nansy ajram.vbs
    nar.vbs
    ne0kS.exe
    nemesis.exe
    nemesis.inf
    nfdmg.com
    nideiect.com
    niu.exe
    njibyekk.com
    nl.com
    nncu6kk.com
    NoLimit.exe
    np.exe
    nq0cq.cmd
    nqvarn.pif
    nriljal.exe
    ntde1ect.com
    ntdelect.com
    nq.bat
    nq0cq.cmd
    nqgcd.com
    nsv.bat
    nw0t1l0d.exe
    o2yf0w.bat
    o9o2u.bat
    o6opnro.bat
    OeApi.vbs
    oegbi.exe
    ogcikeq.com
    oka3yrf.bat
    oq.cmd
    oskkofa.exe
    osotilasiq.pif
    osy3.sys
    otyh.cmd
    oufddh.exe
    oxafa.com
    p3r1ud.exe
    p83gjy.exe
    p9.exe
    pa39xth.cmd
    pagefile.pif
    pbwkwj.com
    pefbutr.exe
    pkxfkrki.bat
    ph.com
    phgr1j.bat
    phim_nguoi_lon.exe
    pnc.exe
    prhyper.exe
    psqrhqn.exe
    pxka.exe
    q3v.com
    q83iwmgf.bat
    q8sywiva.cmd
    qcwpung.exe
    qd.cmd
    qjfl.exe
    qkarc.exe
    qquq.bat
    qqzjnhuoi.exe
    qpe6.com
    qobo.dat
    qrkugxtw.exe
    qxbx9blb.com
    r1y1.bat
    r2nl.com
    r6r.exe
    r813.bat
    Raila Odinga.exe
    Raila Odinga.gif
    ranvrgn.exe
    ravmon.exe
    ravmon.log
    ReadMe.exe
    RecInfo\RecInfo.exe
    Recycle.exe
    Recycled\ctfmon.exe
    RECYCLED\INFO.exe
    Recycled.exe
    RECYCLER\Lock Folder.exe
    RECYCLER\RECYCLER.exe
    RECYCLER\*.exe
    regxpcom.exe
    resycled\boot.com
    resycled\ctfmon.exe
    revo.exe
    rggbw.exe
    rjiybg.exe
    rn.exe
    rombkaewl.exe
    rosftpm.exe
    rqq2v.bat
    rs.cmd
    rt.exe
    Run.exe
    runaut~1\autorun.pif
    RunDll32.exe
    rxukgcm.exe
    s38k.exe
    sal.xls.exe
    sasyg1y8.com
    script.bat
    scriptlo.txt
    scvhosts.exe
    sdcvhost.exe
    SemiAntiVirus.vbs
    smkjd.cmd
    smss.exe
    semo2x.exe
    spq.bat
    serivces.exe
    server.exe
    server.inf
    Sex City.jpg.wsf
    sowar.vbs
    SpiderH.vbs
    sq.com
    sqlserv.exe
    SSVICHOSST.exe
    stwi.com
    svch0st.exe
    scvhosts.exe
    svdioajm.cmd
    sxs.exe
    sydp.exe
    sys.vbs
    Syso.vbs
    SysRes.vbs
    system.exe
    system32.exe
    systems.com
    systems.exe
    t82e2v.cmd
    TAE7ESLP.exe
    taipingtianguov1.1.exe
    takice.lib
    tel.xls.exe
    temp.bat
    temp.exe
    temp.temp
    temp1.exe
    temp2.exe
    test.exe
    testfile.bat
    testflo.bat
    tfk8.exe
    The_Cars.vbs
    THe Girls
    tknapl.exe
    tknn6.bat
    tmf3w3g0.com
    TMMDW8LP.exe
    Toy.exe
    tusoha.exe
    tyktjfww.exe
    u18vxqle.com
    u6k.cmd
    u9dyi.exe
    udnnnvq.exe
    UFO.exe
    ufuaugwq.exe
    uis.com
    uis.exe
    um.cmd
    un9.cmd
    unahafiwik.exe
    UnplugDrive.exe
    uorys.cmd
    update.exe
    uqhqx1.cmd
    usdeiect.com
    userinit.exe
    utdetect.com
    uxdeiect.com
    u?de?ect.com
    v2h3.exe
    v3pif.bat
    VB6FR.DLL
    vb@dock.vbs
    vfpkkbq.exe
    vksucydrh.exe
    vl@dock.vbs
    vmhr.bat
    vmyphd.bat
    vva0hc0p.cmd
    vxl.exe
    w0o.com
    w0owgn.bat
    w32sys.exe
    w3dn9f.bat
    waziqepehi.ban
    wa6.vbs
    Wallpaper.vbs
    WallpaperMEHDI.vbs
    wfhth.exe
    whi.com
    WillPolo.vbs
    WINDOWS.EXE
    Windows.scr
    winfile.exe
    winglogon.exe
    winrun.vbs
    winstall.exe
    wjlfhtfm.cmd
    wol.exe
    wsctf.exe
    wtbcccq.exe
    x0.cmd
    XAdeIect.com
    xcopy.exe
    xfoolavp.com
    xih9.cmd
    xj.bat
    xk2n.bat
    xlk9.com
    xlu8a8sy.exe
    xmnm2.cmd
    xn1i9x.com
    xnynrnh.exe
    xo8wr9.exe
    xp19.com
    xpbkh.com
    xqf.com
    xvlyb.exe
    xyhav.pif
    y82td3td.com
    ybj8df.exe
    yew.bat
    yg.cmd
    yjilu.inf
    ylacupyb.dl
    ylr.exe
    yjkjfuo.cmd
    yjvmtaa.exe
    ynfs9ks.cmd
    yssjnngm.cmd
    yvmkdwn.exe
    zPharaoh.exe
    0.cmd
    1.cmd
    2.cmd
    3.cmd
    4.cmd
    5.cmd
    6.cmd
    7.cmd
    8.cmd
    9.cmd
    0.bat
    1.bat
    2.bat
    3.bat
    4.bat
    5.bat
    6.bat
    7.bat
    8.bat
    9.bat
    0.exe
    1.exe
    2.exe
    3.exe
    4.exe
    5.exe
    6.exe
    7.exe
    8.exe
    9.exe
    0.com
    1.com
    2.com
    3.com
    4.com
    5.com
    6.com
    7.com
    8.com
    9.com
    0.vbs
    1.vbs
    2.vbs
    3.vbs
    4.vbs
    5.vbs
    6.vbs
    7.vbs
    8.vbs
    9.vbs
    a.com
    b.com
    c.com
    d.com
    e.com
    f.com
    g.com
    h.com
    i.com
    j.com
    k.com
    l.com
    m.com
    n.com
    o.com
    p.com
    q.com
    r.com
    s.com
    t.com
    u.com
    v.com
    w.com
    x.com
    y.com
    z.com
    a.bat
    b.bat
    c.bat
    d.bat
    e.bat
    f.bat
    g.bat
    h.bat
    i.bat
    j.bat
    k.bat
    l.bat
    m.bat
    n.bat
    o.bat
    p.bat
    q.bat
    r.bat
    s.bat
    t.bat
    u.bat
    v.bat
    w.bat
    x.bat
    y.bat
    z.bat
    a.cmd
    b.cmd
    c.cmd
    d.cmd
    e.cmd
    f.cmd
    g.cmd
    h.cmd
    i.cmd
    j.cmd
    k.cmd
    l.cmd
    m.cmd
    n.cmd
    o.cmd
    p.cmd
    q.cmd
    r.cmd
    s.cmd
    t.cmd
    u.cmd
    v.cmd
    w.cmd
    x.cmd
    y.cmd
    z.cmd
    a.exe
    b.exe
    c.exe
    d.exe
    e.exe
    f.exe
    g.exe
    h.exe
    i.exe
    j.exe
    k.exe
    l.exe
    m.exe
    n.exe
    o.exe
    p.exe
    q.exe
    r.exe
    s.exe
    t.exe
    u.exe
    v.exe
    w.exe
    x.exe
    y.exe
    z.exe
    a.vbs
    b.vbs
    c.vbs
    d.vbs
    e.vbs
    f.vbs
    g.vbs
    h.vbs
    i.vbs
    j.vbs
    k.vbs
    l.vbs
    m.vbs
    n.vbs
    o.vbs
    p.vbs
    q.vbs
    r.vbs
    s.vbs
    t.vbs
    u.vbs
    v.vbs
    w.vbs
    x.vbs
    y.vbs
    z.vbs
    *.dll.vbs

    >>Dossiers :

    AutoRun
    autorun.inf
    fsc.tmp
    RecInfo
    Recycled\Recycled
    Recycler\Recycler
    resycled
    runaut~1
    sdlflzoip

    >>>>>>"Registry"<<<<<<<<<

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    "Window Title"=-
    "Start Page"=-
    "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\MAIN]
    "Start Page"="https://www.msn.com/fr-fr"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "fucker"=-
    "SysDir"=-
    "ms32dll"=-
    "cftmonn"=-
    "Lany"=-
    "Zip"=-
    "RavAV"=-
    "cmd32"=-
    "Install.exe"=-
    "FIXEDFON.FON"=-
    "MS-RAD0"=-
    "MS-RAD1"=-
    "MS-RAD2"=-
    "MS-RAD3"=-
    "MS-RAD4"=-
    "MS-RAD5"=-
    "MS-RAD6"=-
    "MS-RAD7"=-
    "MS-RAD8"=-
    "MS-RAD9"=-
    "MS-RADA"=-
    "MS-RADB"=-
    "MS-RADC"=-
    "MS-RADD"=-
    "MS-RADE"=-
    "MS-RADF"=-
    "MS-RADG"=-
    "MS-RADH"=-
    "MS-RADI"=-
    "MS-RADJ"=-
    "MS-RADK"=-
    "MS-RADL"=-
    "MS-RADM"=-
    "MS-RADN"=-
    "MS-RADO"=-
    "MS-RADP"=-
    "MS-RADQ"=-
    "MS-RADR"=-
    "MS-RADS"=-
    "MS-RADT"=-
    "MS-RADU"=-
    "MS-RADV"=-
    "MS-RADW"=-
    "MS-RADX"=-
    "MS-RADY"=-
    "MS-RADZ"=-
    " "=-
    "winrun.dll"=-
    "loader.exe"=-
    "recinfo49"=-
    "System"=-
    "System Updater Machine"=-
    "SpiderH"=-
    "winudp64.exe"=-
    "System12"=-
    "System64"=-
    "IMJPMIG8.2"=-
    "CARPService"=-
    "039.tmp"=-
    "userd"=-
    "nar"=-
    "MSKernel32"=-
    "WillPolo"=-
    "MyMP3"=-
    "FS6519"=-
    "Windows\SysRes.vbs"=-
    "SysRes"=-
    "Raila Odinga"=-
    "reginit"=-
    "lnternet Update"=-
    "GMOGLFEO"=-
    "WintelUpdate"=-
    "Pubnet"=-
    "antihost"=-

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices]
    "System Updater Machine"=-
    "Win32DLL"=-
    "lnternet Update"=-

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    " "=-

    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RavAV]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "kamsoft"=-
    "amva"=-
    "kava"=-
    "tava"=-
    "avpa"=-
    "internet_explorer"=-
    "anti-virus 2007"=-
    "Mp3 player"=-
    "kxvo"=-
    "EXPLORER.EXE"=-
    "wsctf.exe"=-
    "loader.exe"=-
    "jvvo"=-
    "taso"=-
    "Avg_AntiHost"=-
    "jvsoft"=-
    "tasoft"=-
    "SpiderH"=-
    "MsServer"=-
    "MSFox"=-
    "msn"=-
    "????r"=-
    "Windows Update"=-
    "Microsoft Debug Manager"=-
    "protect_autorun"=-
    "Le Petit Robert Hyperappel"=-
    "firewall 2008"=-
    " "=-

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    " "=-

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run]
    "test"=-
    "Msn"=-
    "MsnHost"=-
    "MsnLoad"=-
    "MsnConvert"=-
    "MsnMessendger"=-
    "sys"=-

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "DefaultUserName"=-
    "LegalNoticeCaption"=-
    "LegalNoticeText"=-

    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\NoChangingWallPaper]

    -------------------------------------------------------------------------------------------------------------

    Mises a jours du 5 decembre 2008

    >>>>>>in "All Drives"<<<<<<<<<

    6xdgw26.com
    6xig.com
    8386nac.com
    8e.com
    8u.com
    8uot.exe
    arun.exe
    asneg.com
    bpu.exe
    br1e.com
    cdwfql2v.com
    ceqfqp.bat
    cm0.com
    d1y36.com
    dh66ln.cmd
    dpu1.exe
    dyr2j6mv.exe
    ermvu8.cmd
    fblfnthuh.exe
    fn20.exe
    fufb6tq3.cmd
    g2o1n.exe
    gx.com h3hi1k3.exe
    i8.com
    ivcvknr.bat
    jv.exe
    kernel32.dll.vbs
    kg2v.com
    klp8j6i.com
    ktnquo.exe
    l1.cmd
    lp3c.bat
    m0g8sqx.cmd
    m6dqm2vd.exe
    m8wafly.com
    m9as2c.cmd
    MicrosoftPowerPoint.exe
    MSd30D.vbs
    msnmsgr_plus.exe
    ncyrf.bat
    ntdeIect.com
    ntnq.exe
    ntphyy.com
    NTsys.exe
    o6pq1n8.com
    okhr.exe
    ous.exe
    ox.cmd
    p1f6b.exe
    program.exe
    qeoc6sj.exe
    qwultj1.bat
    rcukd.cmd
    rdsfk.com
    rjx0.exe
    rqb0v2ot.bat
    scene.exe
    Server082.exe
    tigi.cmd
    uh31.exe
    uwlmj.com
    uxkktr.cmd
    vd91t29.exe
    w2qagd.com
    welcome.exe
    WindowsXP.exe
    winsys3.exe
    ypjq1.cmd

    .MGT_reg32.dll.vbs
    achitasin.dll.vbs
    autoupdate.dll.vbs
    bat32.txt
    happy.vbs
    ie.vbs
    killgodzilla.vbs
    maskrider.dll.vbs
    maskrider2001.vbs
    msiexec.dll.vbs
    MsUpdate.sys.vbs
    nohack.vbs
    RUNDLL64.dll.vbs
    setup.dll.vbs
    VBRuntime32.dll.vbs
    viva.dll.vbs
    Win32.dll.vbs
    winconfig.dll.vbs
    xepet.html
    xepet.txt

    >>>>>>in "Windows"<<<<<<<<<

    .MGT_reg32.dll.vbs
    achitasin.dll.vbs
    autoupdate.dll.vbs
    bat32.txt
    boot.ini
    happy.vbs
    ie.vbs
    killgodzilla.vbs
    maskrider.dll.vbs
    maskrider2001.vbs
    msiexec.dll.vbs
    MsUpdate.sys.vbs
    nohack.vbs
    RUNDLL64.dll.vbs
    setup.dll.vbs
    VBRuntime32.dll.vbs
    viva.dll.vbs
    Win32.dll.vbs
    winconfig.dll.vbs
    xepet.html
    xepet.txt

    >>>>>>in "Windows\system32"<<<<<<<<<

    kdyul.exe
    gasretyw0.dll
    gasretyw1.dll
    gasretyw2.dll
    gasretyw3.dll
    DC4491.DLL

    >>>>>>"Registry"<<<<<<<<<

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Winboot"=-

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "UC"=-
    "r4n694-24y"=-
    "kernel32"=-
    "MSConfigs"=-
    "Microsoft"=-
    "MGT_reg"=-
    "Winboot"=-
    "Winamp"=-
    "Macromedia"=-
    "WINFIX"=-
    "winconfig"=-
    "Achitasin"=-
    "mcafee"=-
    "wscript32dll"=-
    "Batch32"=-
    "maskrider"=-
    "autoupdate"=-
    "KILLMS32DLL"=-
    "WinExpress"=-
    "WinDebugger"=-
    "C:\WINDOWS\system32\kdyul.exe"=-

    mises a jours du 6 Décembre 2008

    >>>>>>in "All Drives"<<<<<<<<<

    lgrncie.bat
    info.bat
    iqosrtk.bat
    0oyl662q.cmd
    eb.bat
    New Folder.exe
    Setup_ver1.1779.2.exe
    Setup_ver*.exe

    >>>>>>in "Windows"<<<<<<<<<

    SSVICHOSST.exe

    >>>>>>in "Windows\system32"<<<<<<<<<

    SSVICHOSST.exe
    kdxkt.exe
    kdjay.exe
    kdwzh.exe
    msiconf.exe

    >>>>>>"Registry"<<<<<<<<<

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
    "MsUpdate"=-
    "C:\WINDOWS\system32\kdxkt.exe"=-
    "C:\WINDOWS\system32\kdjay.exe"=-
    "C:\WINDOWS\system32\kdwzh.exe"=-

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
    "msiexec.exe"=-
    "Yahoo Messengger"=-

    mises a jours du 11 Décembre 2008

    >>>>>>in "All Drives"<<<<<<<<<

    Secret.exe
    hupxj.bat
    fphj6j31.bat
    shell.exe
    Installer.exe
    fvbk.exe
    snaoc9i.exe
    bt8vuaw.com
    wjlc.exe
    6fnlpetp.exe
    g8rruyw.exe
    o1.com
    yannh.cmd
    1t6yxlxx.cmd
    2h60k.cmd
    3rl3lqbq.bat
    ewatr.cmd
    Maradona.exe
    iw.bat
    m2nl.bat
    ov.cmd
    pnt.com
    t1ypkh.exe
    grgarevn.inf
    microsvn.inf
    refsanvn.inf
    Zidan vs Tito.exe
    desktop.exe
    omsirutnarg.exe
    Alisa.exe
    blazzers.exe
    burimi.exe
    nfd.exe
    repppp.exe
    wax.exe
    wny.exe
    msv2008.exe
    GETBOOTD.BAT
    tbm9.bat
    08dgu.com

    >>>>>>in "Windows\system32"<<<<<<<<<

    vamsoft.exe
    vbsdfe0.dll
    vbsdfe1.dll
    vbsdfe2.dll
    vbsdfe3.dll
    syx.exe

    >>>>>>"Registry"<<<<<<<<<

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
    "Host Process for Windows Services"=-
    "Advanced DHTML Enable"=-

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\runServices]
    "Host Process for Windows Services"=-

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
    "Runonce"=-
    "vamsoft"=-

    mises a jours du 17 Décembre 2008

    >>>>>>in "Windows"<<<<<<<<<

    pagefile.sys.vbs
    backinf.tab
    session.exe
    startup.vbs
    KAT.vbs
    explorar.vbs

    help\destrukto.vbs
    inf\destrukto.vbs
    registration\destrukto.vbs

    >>>>>>in "Windows\system32"<<<<<<<<<

    filekan.exe
    socksa.exe
    KAT.vbs
    destrukto.vbs
    security.vbs
    explorar.vbs
    destrukto.html

    >>>>>>in "Windows\system32\drivers"<<<<<<<<<

    Memoire Jeff EYEGHE.exe

    >>>>>>in "All Drives"<<<<<<<<<

    .\Recycled\Driveinfo.exe
    m9ma.exe
    JIM.exe
    iri.exe
    lol.exe
    mpsn.exe
    pagefile.sys.vbs
    al.xls.exe
    MDM.EXE
    RavManE.exe
    iexp1ore.exe
    msvcr71.dll
    BSserver
    FileKan.exe
    ASocksrv.exe
    algsrv.exe
    BACKINF.TAB
    ufdata2000.log
    twunk32.exe
    windhcp.ocx
    algssl.exe
    msfir80.exe
    msime80.exe
    destrukto.vbs
    Xsfr.exe
    Zser.exe
    THUMBS.DB.COM
    KAT.vbs
    startup.vbs
    THUMBS.DB
    MrHelloween.scr
    mig2.exe
    Perso_Stress.exe
    msfun80.exe
    IMJPMIG8.2
    msime82.exe
    IMJPMIG8.1
    algsrvs.exe
    pr2.exe
    sdfgh.exe
    p1y2.cmd h3.bat
    session.exe
    explorar.vbs
    security.vbs

    >>>>>>"Registry"<<<<<<<<<

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "MSRegInfo"=-
    "ASocksrv"=-
    "Startup"=-
    "Explorer"=-

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "BSserver"=-
    0
  18. sambou911 Messages postés 18 Statut Membre
     
    et j'arrive pas a me connecter a la page pour le scan en ligne.........
    0
  19. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    non c'est pas cela le rapport usbfix refais et colle le rapport
    0
  20. sambou911 Messages postés 18 Statut Membre
     
    j'ai relancer usbfix aucun rapport n'est apparu, desole
    0
  • 1
  • 2