PC infecte: TR/crypt.zpack.gen

requyem -  
 TR/Crypt.FKM.Gen -
Bonjour,

mon PC portable est affecte par un virus detecte par Avira comme etant TR/crypt.zpack.gen, avec plein de fichiers caches dans systeme32 dont el nom commence par ovfsth (y'sa des .tmp, des .dll et du .sys). J'ai vu pas mal de sujets sur ce virus entre autres sur ce forum, mais j'ai un gros probleme supplementaire (peut etre lie, je ne sais pas): mon ordi voit le reseau local et internet, mais je ne peut pas m'y connecter (ma page internet s'ouvre et reste vide, et avec winSCP il y a une erreur de reseau inconnue). Je ne peux donc pas telecharger de logiciels anti virus ou autre (j'ai essaye de copier le .exe de spybot sur un CD, mais au lancement de l'installation sur mon PC il veut acceder a internet pour telecharger d'autres fichiers dont il a besoin pour s'installer, et donc ca ne marche pas). quelqu'un aurait une idee de quoi faire s'il vous plait? (sachant que j'aimerais ne pas tout formater, je n'ai malheureusement pas de backup recent - j'etais sur le point d'en faire un quand c'est arrive).
Configuration: PC: toshiba, windows XP professionnal, navigateur: firefox

5 réponses

  1. Utilisateur anonyme
     
    Salut ,

    Télécharge random's system information tool (RSIT) et sauvegarde-le sur le Bureau.

    Double-clique sur RSIT.exe afin de lancer RSIT.

    Lis le contenu de l'écran Disclaimer puis clique sur Continue (si tu acceptes les conditions).

    Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

    Poste le contenu de log.txt
    0
    1. gladiateur
       
      Logfile of random's system information tool 1.06 (written by random/random)
      Run by BERESSA at 2009-10-12 08:53:27
      Microsoft Windows XP Professionnel Service Pack 2
      System drive C: has 24 GB (32%) free of 75 GB
      Total RAM: 511 MB (36% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 08:53:29, on 12/10/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\soundman.exe
      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Documents and Settings\BERESSA.UNICORNI-6B5B43\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
      C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
      C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Internet Download Manager\IEMonitor.exe
      C:\Program Files\Internet Download Manager\IDMan.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\BERESSA.UNICORNI-6B5B43\Mes documents\Downloads\Programs\RSIT.exe
      C:\Program Files\trend micro\BERESSA.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.dz/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll (file missing)
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O4 - HKLM\..\Run: [SoundMan] soundman.exe
      O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [PopRock] C:\DOCUME~1\BERESS~1.UNI\LOCALS~1\Temp\b.exe
      O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
      O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\BERESSA.UNICORNI-6B5B43\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
      O4 - Global Startup: BlueSoleil.lnk = ?
      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files\Internet Download Manager\IEExt.htm
      O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
      O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O17 - HKLM\System\CCS\Services\Tcpip\..\{9A81A723-694F-4FA0-BAE2-223831FA67E8}: NameServer = 41.221.20.4 193.251.169.165
      O20 - AppInit_DLLs: C:\WINDOWS\System32\icardie32.dll
      O20 - Winlogon Notify: f891d965670 - C:\WINDOWS\System32\icardie32.dll
      O23 - Service: Avira Pare-feu (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe
      O23 - Service: Avira AntiVir MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avmailc.exe
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Avira AntiVir WebGuard (AntiVirWebService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE
      O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
      O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      0
  2. requyem
     
    Bonjour,

    je ne peux pas faire ceci, parce que si je peux copier des donnees d'ailleur sur mon ordi via CD, je ne peux rien en sortir, parce qu'il ne veut pas se connecter au net, et ne reconnais pas mes cles USB ni ne veux graver de CD.
    0
    1. requyem
       
      Bonjour,

      je peux finalement graver de CDs (ca devait etre un probleme avec le CD en fait), donc voici le log de malbytes antimalware que j'ai fait peu de temps apres le premier post (meme si lui ne m'a pas detecte du tout les trucs detectes par avira):
      Malwarebytes' Anti-Malware 1.36
      Database version: 1945
      Windows 5.1.2600 Service Pack 2

      29/04/2009 12:39:25
      mbam-log-2009-04-29 (12-39-18).txt

      Scan type: Full Scan (C:\|)
      Objects scanned: 308823
      Time elapsed: 52 minute(s), 46 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 6
      Registry Keys Infected: 17
      Registry Values Infected: 12
      Registry Data Items Infected: 10
      Folders Infected: 6
      Files Infected: 29

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      C:\WINDOWS\system32\posuyele.dll (Trojan.Vundo.H) -> No action taken.
      c:\WINDOWS\system32\guhegesi.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\tepusiga.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\toluboli.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\gurabimi.dll (Trojan.Vundo.H) -> No action taken.
      C:\WINDOWS\system32\autochk.dll (Trojan.FakeAlert) -> No action taken.

      Registry Keys Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c70d6f11-735b-4ecd-aceb-8074b113f42b} (Trojan.Vundo.H) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{c70d6f11-735b-4ecd-aceb-8074b113f42b} (Trojan.Vundo.H) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{b2ba40a2-74f0-42bd-f434-12345a2c8953} (Trojan.Zlob.H) -> No action taken.
      HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c70d6f11-735b-4ecd-aceb-8074b113f42b} (Trojan.Vundo.H) -> No action taken.
      HKEY_CLASSES_ROOT\bhonew.bho (Trojan.FakeAlert) -> No action taken.
      HKEY_CLASSES_ROOT\bhonew.bho.1 (Trojan.FakeAlert) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{4937d5d1-2039-409a-bd83-fec9b39b2356} (Trojan.BHO) -> No action taken.
      HKEY_CLASSES_ROOT\Interface\{caf9d798-c659-4b9b-8e19-ee27c3d04ee7} (Trojan.BHO) -> No action taken.
      HKEY_CLASSES_ROOT\Typelib\{15c7d7ad-a87a-4c0d-9d8b-637fcd3488ef} (Trojan.BHO) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f65e955e-26c0-42ff-8ee2-443a05ea286a} (Trojan.FakeAlert) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{6fd31ed6-7c94-4bbc-8e95-f927f4d3a949} (Adware.180Solutions) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\xpreapp (Malware.Trace) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Bind (Malware.Trace) -> No action taken.

      Registry Values Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\c8fe6a81 (Trojan.Vundo.H) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpmcbcd591d (Trojan.Vundo.H) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\zimupetopi (Trojan.Vundo.H) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{b2ba40a2-74f0-42bd-f434-12345a2c8953} (Trojan.Zlob.H) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autochk (Trojan.Agent) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autochk (Trojan.Agent) -> No action taken.
      HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\autochk (Trojan.Agent) -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Framework Windows (Trojan.FakeAlert) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\diagnostic manager (Trojan.Downloader) -> No action taken.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\amva (Spyware.OnlineGames) -> No action taken.

      Registry Data Items Infected:
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\guhegesi.dll -> No action taken.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\tepusiga.dll -> No action taken.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tepusiga.dll

      j'ai a priori retire tous les trucs ci dessus.

      voici aussi le log de hijackthis - pas RSIT, parce que lui ne veut pas s'installer sur mon pc, il a surement besoin du net...
      Logfile of Trend Micro HijackThis v2.0.2

      Scan saved at 18:00:58, on 07/05/2009

      Platform: Windows XP SP2 (WinNT 5.01.2600)

      MSIE: Internet Explorer v7.00 (7.00.6000.16827)

      Boot mode: Normal



      Running processes:

      C:\WINDOWS\System32\smss.exe

      C:\WINDOWS\system32\winlogon.exe

      C:\WINDOWS\system32\services.exe

      C:\WINDOWS\system32\lsass.exe

      C:\WINDOWS\system32\svchost.exe

      C:\WINDOWS\System32\svchost.exe

      C:\WINDOWS\system32\svchost.exe

      C:\WINDOWS\system32\spoolsv.exe

      C:\Program Files\Avira\AntiVir Desktop\sched.exe

      C:\WINDOWS\system32\agrsmsvc.exe

      C:\Program Files\Avira\AntiVir Desktop\avguard.exe

      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

      C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe

      C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

      C:\WINDOWS\system32\CTsvcCDA.exe

      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

      C:\Program Files\Java\jre6\bin\jqs.exe

      C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

      C:\WINDOWS\System32\svchost.exe

      C:\WINDOWS\System32\svchost.exe

      C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe

      c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe

      C:\WINDOWS\system32\ThpSrv.exe

      C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe

      C:\WINDOWS\system32\TODDSrv.exe

      c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe

      C:\WINDOWS\Explorer.EXE

      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe

      C:\WINDOWS\RTHDCPL.EXE

      C:\WINDOWS\system32\ctfmon.exe

      C:\WINDOWS\system32\00THotkey.exe

      C:\Program Files\Apoint2K\Apoint.exe

      C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe

      C:\WINDOWS\system32\TPSMain.exe

      C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE

      C:\Program Files\TOSHIBA\TME3\TMEEJME.EXE

      C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe

      C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe

      C:\Program Files\TOSHIBA\TAudEffect\TAudEff.exe

      C:\WINDOWS\system32\TPSBattM.exe

      C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe

      C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\ddwmon.exe

      C:\Program Files\Apoint2K\Apntex.exe

      C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe

      C:\WINDOWS\system32\thpsrv.exe

      C:\WINDOWS\system32\igfxtray.exe

      C:\WINDOWS\system32\hkcmd.exe

      C:\Program Files\Protector Suite QL\psqltray.exe

      C:\WINDOWS\system32\igfxpers.exe

      C:\WINDOWS\system32\igfxsrvc.exe

      C:\WINDOWS\system32\TFNF5.exe

      C:\Program Files\TOSHIBA\DualPointUtility\TEDTray.exe

      C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

      C:\WINDOWS\system32\igfxext.exe

      C:\Program Files\Java\jre6\bin\jusched.exe

      C:\Program Files\iTunes\iTunesHelper.exe

      C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

      C:\Program Files\Sunbelt Software\CounterSpy\SBAMTray.exe

      C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

      C:\Program Files\Skype\Phone\Skype.exe

      C:\Program Files\Messenger\msmsgs.exe

      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

      C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe

      C:\Program Files\iPod\bin\iPodService.exe

      C:\Program Files\Skype\Plugin Manager\skypePM.exe

      C:\Program Files\iTunes\iTunes.exe

      C:\Program Files\Microsoft Office\Office12\POWERPNT.EXE

      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\hpmup081.bin

      C:\WINDOWS\system32\rundll32.exe

      C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe

      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe



      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.com/en

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.com/en

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.orange.com/en

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp

      R3 - URLSearchHook: (no name) - {4FBACD73-F67C-42AE-B46A-03960AFE3DFB} - C:\PROGRA~1\ORANGE~1\TOOLBA~2.DLL

      O2 - BHO: (no name) - {B2BA40A2-74F0-42BD-F434-12345A2C8953} - (no file)

      O3 - Toolbar: Orange Toolbar - {E97B5F2E-CA8E-4D34-BDA3-44EEC4ED2B12} - C:\Program Files\Orange Toolbar UK\ToolbarContainer192.dll

      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll

      O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"

      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

      O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe

      O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe

      O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

      O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe

      O4 - HKLM\..\Run: [TPSODDCtl] TPSODDCtl.exe

      O4 - HKLM\..\Run: [TPSMain] TPSMain.exe

      O4 - HKLM\..\Run: [TMERzCtl.EXE] C:\Program Files\TOSHIBA\TME3\TMERzCtl.EXE /Service

      O4 - HKLM\..\Run: [TMESRV.EXE] C:\Program Files\TOSHIBA\TME3\TMESRV31.EXE /Logon

      O4 - HKLM\..\Run: [TOSDCR] TOSDCR.EXE

      O4 - HKLM\..\Run: [TosHKCW.exe] "C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe"

      O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe

      O4 - HKLM\..\Run: [TAudEffect] C:\Program Files\TOSHIBA\TAudEffect\TAudEff.exe /run

      O4 - HKLM\..\Run: [TFncKy] TFncKy.exe

      O4 - HKLM\..\Run: [DDWMon] C:\Program Files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe

      O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup

      O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup

      O4 - HKLM\..\Run: [ThpSrv] C:\WINDOWS\system32\thpsrv /logon

      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe

      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe

      O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe

      O4 - HKLM\..\Run: [TFNF5] TFNF5.exe

      O4 - HKLM\..\Run: [DpUtil] C:\Program Files\TOSHIBA\DualPointUtility\TEDTray.exe

      O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"

      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

      O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe

      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

      O4 - HKLM\..\Run: [CTCheck] C:\Program Files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe

      O4 - HKLM\..\Run: [prnet] "C:\WINDOWS\system32\prnet.tmp"

      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

      O4 - HKLM\..\Run: [SBAMTray] C:\Program Files\Sunbelt Software\CounterSpy\SBAMTray.exe

      O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

      O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"

      O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount

      O4 - HKCU\..\Run: [prnet] "C:\WINDOWS\system32\prnet.tmp"

      O4 - HKUS\S-1-5-19\..\Run: [zimupetopi] Rundll32.exe "C:\WINDOWS\system32\gurabimi.dll",s (User 'LOCAL SERVICE')

      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

      O4 - HKUS\S-1-5-18\..\Run: [] C:\WINDOWS\TEMP\w642vo.exe (User 'SYSTEM')

      O4 - HKUS\S-1-5-18\..\Run: [Windows Resurections] C:\WINDOWS\TEMP\w642vo.exe (User 'SYSTEM')

      O4 - HKUS\S-1-5-18\..\Run: [Diagnostic Manager] C:\WINDOWS\TEMP\1894691652.exe (User 'SYSTEM')

      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

      O10 - Broken Internet access because of LSP provider 'c:\windows\temp\ntdll64.dll' missing

      O14 - IERESET.INF: START_PAGE_URL=https://www.orange.com/en

      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

      O20 - AppInit_DLLs:

      O20 - Winlogon Notify: TosBtNP - C:\WINDOWS\SYSTEM32\TosBtNP.dll

      O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\WINDOWS\system32\agrsmsvc.exe

      O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

      O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

      O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

      O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe

      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe

      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe

      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

      O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

      O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)

      O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe

      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

      O23 - Service: CounterSpy Antispyware (SBAMSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBAMSvc.exe

      O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe

      O23 - Service: TOSHIBA HDD Protection (Thpsrv) - TOSHIBA Corporation - C:\WINDOWS\system32\ThpSrv.exe

      O23 - Service: Tmesrv3 (Tmesrv) - TOSHIBA - C:\Program Files\TOSHIBA\TME3\Tmesrv31.exe

      O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\WINDOWS\system32\TODDSrv.exe

      O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe


      0
  3. Utilisateur anonyme
     
    Télécharge combofix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    -> Double clique sur combofix.exe.
    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

    Avant d'utiliser ComboFix :

    -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

    -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

    Une fois fait, sur ton bureau double-clic sur Combofix.exe.

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

    -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
    0
  4. requyem
     
    Bonjour,

    merci pour le conseil combofix, cela semble avoir marche, puisque je peux de nouveau me connecter a internet (et le scan d'avira en cours n'a rien detecte pour le moment, alors qu'il detectait le virus assez tot avant). enfin, bref, voila le log de combofix:

    ComboFix 09-05-07.06 - requyem 08/05/2009 10:39.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2039.1630 [GMT 1:00]
    Running from: c:\documents and settings\requyem\Desktop\ComboFix.exe
    AV: AntiVir Desktop *On-access scanning disabled* (Outdated)
    * Resident AV is active

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\ak1.exe
    c:\windows\system32\biologon.dll
    c:\windows\system32\config\systemprofile\protect.dll
    c:\windows\system32\drivers\ovfsthrteonsvvayvysjajajbjdmopwdjesbiv.sys
    c:\windows\system32\lmppcsetup.exe
    c:\windows\system32\ovfsthdwffkkddrqxnqtcpfbngqfshsvapfyoy.dat
    c:\windows\system32\ovfsthmhccrawmrctmynautfyvntfbmqotyvdj.dll
    c:\windows\system32\ovfsthmlqjnpdcikuyxmgmnbenhtskdnfyiajt.dll
    c:\windows\system32\ovfsthmsapfowykmcqykpfjgauqayvrxdwjhdw.dll
    c:\windows\system32\ovfsthxidngoedjymxhvitaiwbytqfgojpvuxy.dat
    c:\windows\system32\pifufoyo.dll
    c:\windows\system32\prnet.tmp
    c:\windows\system32\test.ttt
    c:\windows\system32\uniq.tll

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Service_ovfsthlvoqmnwoentmpvptuuobrmretujklymj

    ((((((((((((((((((((((((( Files Created from 2009-04-08 to 2009-05-08 )))))))))))))))))))))))))))))))
    .

    2009-05-08 09:47 . 2009-05-08 09:47 -------- d-----w C:\63c36f294fc90360d23885b0
    2009-05-08 09:47 . 2009-05-08 09:47 -------- d-----w C:\f1926c767dbf791a570b
    2009-04-30 12:05 . 2009-04-30 12:05 -------- d-----w c:\program files\Trend Micro
    2009-04-30 11:59 . 2009-04-30 11:59 -------- d-----w c:\documents and settings\requyem\Application Data\Sunbelt
    2009-04-30 11:59 . 2009-04-30 11:59 -------- d-----w c:\documents and settings\All Users\Application Data\Sunbelt
    2009-04-30 11:59 . 2009-04-30 11:59 -------- d-----w c:\program files\Sunbelt Software
    2009-04-29 13:25 . 2009-04-29 13:25 -------- d-----w c:\program files\CCleaner
    2009-04-29 10:34 . 2009-04-29 10:34 -------- d-----w c:\documents and settings\requyem\Application Data\Malwarebytes
    2009-04-29 10:34 . 2009-04-06 14:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
    2009-04-29 10:34 . 2009-04-06 14:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
    2009-04-29 10:34 . 2009-04-29 10:34 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
    2009-04-29 10:34 . 2009-04-29 11:39 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
    2009-04-27 22:05 . 2009-02-13 10:31 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
    2009-04-15 16:44 . 2009-03-06 14:00 284160 -c----w c:\windows\system32\dllcache\pdh.dll
    2009-04-15 16:44 . 2005-07-26 04:20 60416 -c----w c:\windows\system32\dllcache\colbact.dll
    2009-04-15 16:44 . 2009-02-06 09:54 35328 -c----w c:\windows\system32\dllcache\sc.exe
    2009-04-15 16:44 . 2009-02-09 10:01 401408 -c----w c:\windows\system32\dllcache\rpcss.dll
    2009-04-15 16:44 . 2009-02-06 10:22 110592 -c----w c:\windows\system32\dllcache\services.exe
    2009-04-15 16:44 . 2009-02-09 10:01 473088 -c----w c:\windows\system32\dllcache\fastprox.dll
    2009-04-15 16:44 . 2009-02-06 09:41 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
    2009-04-15 16:44 . 2009-02-09 10:01 617984 -c----w c:\windows\system32\dllcache\advapi32.dll
    2009-04-15 16:44 . 2009-02-09 10:01 715264 -c----w c:\windows\system32\dllcache\ntdll.dll
    2009-04-15 16:41 . 2008-04-21 10:02 215552 -c----w c:\windows\system32\dllcache\wordpad.exe

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-04-27 22:05 . 2008-07-24 09:52 -------- d-----w c:\program files\Avira
    2009-04-26 20:39 . 2007-05-31 16:20 -------- d-----w c:\program files\Microsoft SQL Server
    2009-04-20 11:38 . 2008-06-27 18:51 90920 ----a-w c:\documents and settings\requyem\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2009-03-29 14:46 . 2009-03-29 14:46 -------- d-----w c:\program files\Alcohol Soft
    2009-03-29 14:41 . 2009-03-29 14:41 716272 ----a-w c:\windows\system32\drivers\sptd.sys
    2009-03-17 12:26 . 2009-03-17 12:26 65320 ----a-w c:\windows\system32\sbbd.exe
    2009-03-06 14:00 . 2007-05-30 08:13 284160 ----a-w c:\windows\system32\pdh.dll
    2009-03-03 00:18 . 2007-05-30 08:13 826368 ----a-w c:\windows\system32\wininet.dll
    2009-02-20 18:09 . 2007-05-30 08:13 78336 ----a-w c:\windows\system32\ieencode.dll
    2009-02-09 10:19 . 2007-05-30 08:13 1846272 ----a-w c:\windows\system32\win32k.sys
    2009-02-09 10:01 . 2007-05-30 08:13 401408 ----a-w c:\windows\system32\rpcss.dll
    2009-02-09 10:01 . 2007-05-30 08:13 728576 ----a-w c:\windows\system32\lsasrv.dll
    2009-02-09 10:01 . 2007-05-30 08:12 617984 ----a-w c:\windows\system32\advapi32.dll
    2009-02-09 10:01 . 2007-05-30 08:13 715264 ----a-w c:\windows\system32\ntdll.dll
    2008-09-26 12:52 . 2008-09-26 12:52 1271557 ----a-w c:\program files\wrar371fr.exe
    2008-07-28 15:29 . 2008-07-28 15:13 9501920 ----a-w c:\program files\vlc-0.8.6i-win32.exe
    2009-01-27 16:19 . 2009-01-27 16:19 48640 --sha-w c:\windows\system32\benopezu.dll.tmp
    2009-01-27 16:19 . 2009-01-27 16:19 48640 --sha-w c:\windows\system32\simejufa.dll.tmp
    2009-01-27 16:19 . 2009-01-27 16:19 48640 --sha-w c:\windows\system32\terozepu.dll.tmp
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2005-04-11 65536]
    "Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-06-03 21718312]
    "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-07-25 68856]
    "CTSyncU.exe"="c:\program files\Creative\Sync Manager Unicode\CTSyncU.exe" [2007-07-17 868352]
    "AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 52\axcmd.exe" [2008-03-20 216520]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ThpSrv"="c:\windows\system32\thpsrv" [X]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-02-12 174872]
    "00THotkey"="c:\windows\system32\[u]0/u0THotkey.exe" [2006-08-07 11:58 253952]
    "Apoint"="c:\program files\Apoint2K\Apoint.exe" [2004-03-24 196608]
    "SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2007-05-11 143360]
    "TMERzCtl.EXE"="c:\program files\TOSHIBA\TME3\TMERzCtl.EXE" [2006-09-04 90112]
    "TMESRV.EXE"="c:\program files\TOSHIBA\TME3\TMESRV31.EXE" [2006-03-06 114688]
    "TosHKCW.exe"="c:\program files\TOSHIBA\Wireless Hotkey\TosHKCW.exe" [2005-05-17 49152]
    "TAudEffect"="c:\program files\TOSHIBA\TAudEffect\TAudEff.exe" [2006-08-09 344144]
    "DDWMon"="c:\program files\TOSHIBA\TOSHIBA Direct Disc Writer\\ddwmon.exe" [2007-04-26 495616]
    "PSQLLauncher"="c:\program files\Protector Suite QL\launcher.exe" [2006-05-05 30208]
    "topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-04-02 577536]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-04-09 138008]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-04-09 162584]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2007-04-09 138008]
    "DpUtil"="c:\program files\TOSHIBA\DualPointUtility\TEDTray.exe" [2005-08-05 155648]
    "Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-07 136600]
    "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
    "CTCheck"="c:\program files\Creative\Creative ZEN\ZEN Media Explorer\CTCheck.exe" [2007-11-06 397312]
    "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
    "SBAMTray"="c:\program files\Sunbelt Software\CounterSpy\SBAMTray.exe" [2009-03-17 681256]
    "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2007-03-13 16125440]
    "000StTHK"="000StTHK.exe" - c:\windows\system32\[u]0/u00StTHK.exe [2001-06-23 03:28 24576]
    "TPSODDCtl"="TPSODDCtl.exe" - c:\windows\system32\TPSODDCtl.exe [2007-04-18 102400]
    "TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2007-04-18 299008]
    "TOSDCR"="TOSDCR.EXE" - c:\windows\system32\TOSDCR.exe [2005-12-12 57344]
    "NDSTray.exe"="NDSTray.exe" [BU]
    "TFncKy"="TFncKy.exe" [BU]
    "TFNF5"="TFNF5.exe" - c:\windows\system32\TFNF5.exe [2006-04-11 622592]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]
    "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    "NoSetActiveDesktop"= 1 (0x1)
    "NoActiveDesktopChanges"= 1 (0x1)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
    2006-05-05 16:48 40448 ----a-w c:\windows\system32\psqlpwd.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\TosBtNP]
    2006-07-22 02:54 65536 ----a-w c:\windows\system32\TosBtNP.dll

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Notification Packages REG_MULTI_SZ scecli psqlpwd

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
    "c:\\Program Files\\Cyanide\\Chaos-League\\ChaosLeague.exe"=
    "c:\\Program Files\\Cyanide\\GameCenter\\GameCenter.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=
    "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
    "c:\\Program Files\\mIRC\\mirc.exe"=

    R0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\drivers\thpdrv.sys [27/04/2007 10:19 21120]
    R0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\drivers\Thpevm.sys [09/03/2007 15:23 6528]
    R1 TMEI3E;TMEI3E;c:\windows\system32\drivers\TMEI3E.sys [30/05/2007 16:23 5888]
    R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [27/04/2009 23:05 108289]
    R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service;c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [11/01/2008 17:50 30312]
    R2 FdRedir;FdRedir;c:\program files\Common Files\Protector Suite QL\Drivers\FdRedir.sys [05/05/2006 18:00 13568]
    R2 FileDisk2;FileDisk Protector Kernel Driver;c:\program files\Common Files\Protector Suite QL\Drivers\filedisk.sys [05/05/2006 17:59 33024]
    R2 SBAMSvc;CounterSpy Antispyware;c:\program files\Sunbelt Software\CounterSpy\SBAMSvc.exe [17/03/2009 13:26 894248]
    R2 smihlp;SMI helper driver;c:\program files\Protector Suite QL\smihlp.sys [05/05/2006 17:33 3456]
    R2 tdudf;TOSHIBA UDF File System Driver;c:\windows\system32\drivers\tdudf.sys [26/03/2007 12:22 105856]
    R2 Tmesrv;Tmesrv3;c:\program files\TOSHIBA\TME3\TMESRV31.exe [30/05/2007 16:23 114688]
    R2 trudf;TOSHIBA DVD-RAM UDF File System Driver;c:\windows\system32\drivers\trudf.sys [19/02/2007 12:15 134016]
    R3 IFXTPM;IFXTPM;c:\windows\system32\drivers\ifxtpm.sys [31/05/2007 16:10 35968]
    R3 TEchoCan;Toshiba Audio Effect;c:\windows\system32\drivers\TEchoCan.sys [30/05/2007 16:26 435072]
    S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [14/04/2006 10:07 28933976]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
    \Shell\AutoRun\command - E:\pa39xth.cmd
    \Shell\explore\Command - E:\pa39xth.cmd
    \Shell\open\Command - E:\pa39xth.cmd

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0d9fd163-54f5-11dd-90d1-001f3c29a196}]
    \Shell\AutoRun\command - E:\pa39xth.cmd
    \Shell\explore\Command - E:\pa39xth.cmd
    \Shell\open\Command - E:\pa39xth.cmd

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{17f74a2a-62bd-11dd-90ed-001f3c29a196}]
    \Shell\AutoRun\command - E:\pa39xth.cmd
    \Shell\explore\Command - E:\pa39xth.cmd
    \Shell\open\Command - E:\pa39xth.cmd

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9e9b3e82-63e0-11dd-90ef-001f3c29a196}]
    \Shell\AutoRun\command - start.exe
    \Shell\iledefrance\command - start.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c26bcd46-444e-11dd-90b1-001f3c29a196}]
    \Shell\AutoRun\command - E:\pa39xth.cmd
    \Shell\explore\Command - E:\pa39xth.cmd
    \Shell\open\Command - E:\pa39xth.cmd
    .
    - - - - ORPHANS REMOVED - - - -

    BHO-{B2BA40A2-74F0-42BD-F434-12345A2C8953} - (no file)
    HKCU-Run-prnet - c:\windows\system32\prnet.tmp
    HKLM-Run-prnet - c:\windows\system32\prnet.tmp
    HKU-Default-Run-Windows Resurections - c:\windows\TEMP\w642vo.exe
    HKU-Default-Run-Diagnostic Manager - c:\windows\TEMP\1894691652.exe

    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.orange.co.uk
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Settings,ProxyOverride = <local>;*.local
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    FF - ProfilePath - c:\documents and settings\requyem\Application Data\Mozilla\Firefox\Profiles\5xtfzg3m.default\
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.fr/
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-05-08 10:49
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(968)
    c:\windows\system32\psqlpwd.dll
    c:\program files\Protector Suite QL\infra.dll
    c:\program files\Protector Suite QL\homefus2.dll
    c:\program files\Protector Suite QL\homepass.dll
    c:\program files\Protector Suite QL\bio.dll
    c:\program files\Protector Suite QL\remote.dll
    c:\program files\Protector Suite QL\crypto.dll
    c:\program files\Protector Suite QL\biokmd.dll
    c:\program files\Protector Suite QL\basegui.dll
    c:\program files\Protector Suite QL\mysafe.dll

    - - - - - - - > 'lsass.exe'(1024)
    c:\windows\system32\psqlpwd.dll
    c:\program files\Protector Suite QL\infra.dll
    c:\program files\Protector Suite QL\homefus2.dll

    - - - - - - - > 'explorer.exe'(4156)
    c:\progra~1\WINDOW~2\wmpband.dll
    c:\windows\system32\mshtml.dll
    c:\program files\TOSHIBA\TME3\TMEEJMD.DLL
    c:\windows\system32\WPDShServiceObj.dll
    c:\program files\Protector Suite QL\mysafe.dll
    c:\program files\Protector Suite QL\infra.dll
    c:\program files\WinSCP\DragExt.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    c:\windows\system32\TPwrCfg.DLL
    c:\windows\system32\TPwrReg.dll
    c:\windows\system32\TPSTrace.DLL
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\windows\system32\agrsmsvc.exe
    c:\program files\Avira\AntiVir Desktop\avguard.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe
    c:\windows\system32\CTSVCCDA.EXE
    c:\program files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\program files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
    c:\windows\system32\ThpSrv.exe
    c:\windows\system32\TODDSrv.exe
    c:\program files\TOSHIBA\Bluetooth Toshiba Stack\TosBtSrv.exe
    c:\windows\system32\wscntfy.exe
    c:\program files\TOSHIBA\TME3\TMEEJME.exe
    c:\program files\TOSHIBA\ConfigFree\NDSTray.exe
    c:\program files\TOSHIBA\TOSHIBA Direct Disc Writer\DDWMon.exe
    c:\windows\system32\ThpSrv.exe
    c:\windows\system32\TPSBattM.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\Protector Suite QL\psqltray.exe
    c:\windows\system32\igfxext.exe
    c:\program files\Apoint2K\ApntEx.exe
    c:\program files\iPod\bin\iPodService.exe
    c:\windows\system32\msiexec.exe
    c:\program files\Skype\Plugin Manager\skypePM.exe
    c:\windows\system32\msdtc.exe
    c:\windows\system32\dllhost.exe
    .
    **************************************************************************
    .
    Completion time: 2009-05-08 10:56 - machine was rebooted
    ComboFix-quarantined-files.txt 2009-05-08 09:56

    Pre-Run: 17,491,509,248 bytes free
    Post-Run: 18,289,913,856 bytes free

    287 --- E O F --- 2009-05-08 09:52

    par contre ca semble m'avoir reinstalle internet explorer (ou en tout cas j'ai maintenant une icone internet explorer sur le bureau que je n'avais pas avant), c'est normal?
    0
    1. requyem
       
      il semble finalement que ca ne soit pas tout resolu, parce que avira a en fait detecte des trucs, voici son log:



      Avira AntiVir Personal
      Report file date: 08 May 2009 11:02

      Scanning for 1383776 virus strains and unwanted programs.

      Licensee : Avira AntiVir Personal - FREE Antivirus
      Serial number : 0000149996-ADJIE-0000001
      Platform : Windows XP
      Windows version : (Service Pack 2) [5.1.2600]
      Boot mode : Normally booted
      Username : SYSTEM
      Computer name : FGENETLAPTOP

      Version information:
      BUILD.DAT : 9.0.0.394 17962 Bytes 4/17/2009 11:20:00
      AVSCAN.EXE : 9.0.3.5 466689 Bytes 5/8/2009 10:01:18
      AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 09:58:24
      LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 10:35:49
      LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 09:58:52
      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 11:30:36
      ANTIVIR1.VDF : 7.1.2.12 3336192 Bytes 2/11/2009 19:33:26
      ANTIVIR2.VDF : 7.1.3.137 1810944 Bytes 4/30/2009 10:01:18
      ANTIVIR3.VDF : 7.1.3.173 173056 Bytes 5/8/2009 10:01:18
      Engineversion : 8.2.0.160
      AEVDF.DLL : 8.1.1.1 106868 Bytes 5/8/2009 10:01:18
      AESCRIPT.DLL : 8.1.1.79 385403 Bytes 5/8/2009 10:01:18
      AESCN.DLL : 8.1.1.10 127348 Bytes 5/8/2009 10:01:18
      AERDL.DLL : 8.1.1.3 438645 Bytes 10/29/2008 17:24:41
      AEPACK.DLL : 8.1.3.14 397685 Bytes 5/8/2009 10:01:18
      AEOFFICE.DLL : 8.1.0.36 196987 Bytes 2/26/2009 19:01:56
      AEHEUR.DLL : 8.1.0.122 1737080 Bytes 5/8/2009 10:01:18
      AEHELP.DLL : 8.1.2.2 119158 Bytes 2/26/2009 19:01:56
      AEGEN.DLL : 8.1.1.39 348532 Bytes 5/8/2009 10:01:18
      AEEMU.DLL : 8.1.0.9 393588 Bytes 10/9/2008 13:32:40
      AECORE.DLL : 8.1.6.9 176500 Bytes 5/8/2009 10:01:18
      AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 13:32:40
      AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:59
      AVPREF.DLL : 9.0.0.1 43777 Bytes 12/5/2008 09:32:15
      AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 13:34:28
      AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 09:32:09
      AVARKT.DLL : 9.0.0.3 292609 Bytes 5/8/2009 10:01:18
      AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 09:37:08
      SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 14:03:49
      SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 07:21:33
      NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 09:32:10
      RCIMAGE.DLL : 9.0.0.21 2438401 Bytes 2/9/2009 10:45:45
      RCTEXT.DLL : 9.0.37.0 86785 Bytes 5/8/2009 10:01:18

      Configuration settings for the scan:
      Jobname.............................: Complete system scan
      Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
      Logging.............................: low
      Primary action......................: interactive
      Secondary action....................: ignore
      Scan master boot sector.............: on
      Scan boot sector....................: on
      Boot sectors........................: C:,
      Process scan........................: on
      Scan registry.......................: on
      Search for rootkits.................: on
      Integrity checking of system files..: off
      Scan all files......................: All files
      Scan archives.......................: on
      Recursion depth.....................: 20
      Smart extensions....................: on
      Macro heuristic.....................: on
      File heuristic......................: medium

      Start of the scan: 08 May 2009 11:02

      Starting search for hidden objects.
      '65498' objects were checked, '0' hidden objects were found.

      The scan of running processes will be started
      Scan process 'WINWORD.EXE' - '1' Module(s) have been scanned
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'AcroRd32.exe' - '1' Module(s) have been scanned
      Scan process 'firefox.exe' - '1' Module(s) have been scanned
      Scan process 'notepad.exe' - '1' Module(s) have been scanned
      Scan process 'explorer.exe' - '1' Module(s) have been scanned
      Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
      Scan process 'dllhost.exe' - '1' Module(s) have been scanned
      Scan process 'msdtc.exe' - '1' Module(s) have been scanned
      Scan process 'skypePM.exe' - '1' Module(s) have been scanned
      Scan process 'iPodService.exe' - '1' Module(s) have been scanned
      Scan process 'ApntEx.exe' - '1' Module(s) have been scanned
      Scan process 'CTSyncU.exe' - '1' Module(s) have been scanned
      Scan process 'GoogleToolbarNotifier.exe' - '1' Module(s) have been scanned
      Scan process 'msmsgs.exe' - '1' Module(s) have been scanned
      Scan process 'Skype.exe' - '1' Module(s) have been scanned
      Scan process 'TOSCDSPD.exe' - '1' Module(s) have been scanned
      Scan process 'igfxext.exe' - '1' Module(s) have been scanned
      Scan process 'SBAMTray.exe' - '1' Module(s) have been scanned
      Scan process 'psqltray.exe' - '1' Module(s) have been scanned
      Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
      Scan process 'igfxsrvc.exe' - '1' Module(s) have been scanned
      Scan process 'jusched.exe' - '1' Module(s) have been scanned
      Scan process 'PIFSvc.exe' - '1' Module(s) have been scanned
      Scan process 'TEDTray.exe' - '1' Module(s) have been scanned
      Scan process 'TFNF5.exe' - '1' Module(s) have been scanned
      Scan process 'igfxpers.exe' - '1' Module(s) have been scanned
      Scan process 'hkcmd.exe' - '1' Module(s) have been scanned
      Scan process 'igfxtray.exe' - '1' Module(s) have been scanned
      Scan process 'TPSBattM.exe' - '1' Module(s) have been scanned
      Scan process 'ThpSrv.exe' - '1' Module(s) have been scanned
      Scan process 'TOPI.exe' - '1' Module(s) have been scanned
      Scan process 'DDWMon.exe' - '1' Module(s) have been scanned
      Scan process 'TAudEff.exe' - '1' Module(s) have been scanned
      Scan process 'NDSTray.exe' - '1' Module(s) have been scanned
      Scan process 'TosHKCW.exe' - '1' Module(s) have been scanned
      Scan process 'TMEEJME.exe' - '1' Module(s) have been scanned
      Scan process 'TMERzCtl.exe' - '1' Module(s) have been scanned
      Scan process 'TPSMain.exe' - '1' Module(s) have been scanned
      Scan process 'SmoothView.exe' - '1' Module(s) have been scanned
      Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
      Scan process 'Apoint.exe' - '1' Module(s) have been scanned
      Scan process '00THotkey.exe' - '1' Module(s) have been scanned
      Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
      Scan process 'IAAnotif.exe' - '1' Module(s) have been scanned
      Scan process 'alg.exe' - '1' Module(s) have been scanned
      Scan process 'TosBtSrv.exe' - '1' Module(s) have been scanned
      Scan process 'TODDSrv.exe' - '1' Module(s) have been scanned
      Scan process 'TMESRV31.exe' - '1' Module(s) have been scanned
      Scan process 'ThpSrv.exe' - '1' Module(s) have been scanned
      Scan process 'StarWindServiceAE.exe' - '1' Module(s) have been scanned
      Scan process 'sqlwriter.exe' - '1' Module(s) have been scanned
      Scan process 'SBAMSvc.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'PIFSvc.exe' - '1' Module(s) have been scanned
      Scan process 'jqs.exe' - '1' Module(s) have been scanned
      Scan process 'IAANTmon.exe' - '1' Module(s) have been scanned
      Scan process 'CTSVCCDA.EXE' - '1' Module(s) have been scanned
      Scan process 'CFSvcs.exe' - '1' Module(s) have been scanned
      Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
      Scan process 'BcmSqlStartupSvc.exe' - '1' Module(s) have been scanned
      Scan process 'AluSchedulerSvc.exe' - '1' Module(s) have been scanned
      Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned
      Scan process 'agrsmsvc.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'lsass.exe' - '1' Module(s) have been scanned
      Scan process 'services.exe' - '1' Module(s) have been scanned
      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'smss.exe' - '1' Module(s) have been scanned
      82 processes with 82 modules were scanned

      Starting master boot sector scan:
      Master boot sector HD0
      [INFO] No virus was found!

      Start scanning boot sectors:
      Boot sector 'C:\'
      [INFO] No virus was found!

      Starting to scan executable files (registry).
      The registry was scanned ( '71' files ).


      Starting the file scan:

      Begin scan in 'C:\' <H07685ENP01>
      C:\hiberfil.sys
      [WARNING] The file could not be opened!
      [NOTE] This file is a Windows system file.
      [NOTE] This file cannot be opened for scanning.
      C:\pagefile.sys
      [WARNING] The file could not be opened!
      [NOTE] This file is a Windows system file.
      [NOTE] This file cannot be opened for scanning.
      C:\Qoobox\Quarantine\C\WINDOWS\system32\ak1.exe.vir
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      C:\Qoobox\Quarantine\C\WINDOWS\system32\lmppcsetup.exe.vir
      [DETECTION] Is the TR/Drop.Agent.amnc Trojan
      C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthmhccrawmrctmynautfyvntfbmqotyvdj.dll.vir
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthmlqjnpdcikuyxmgmnbenhtskdnfyiajt.dll.vir
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthmsapfowykmcqykpfjgauqayvrxdwjhdw.dll.vir
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      C:\Qoobox\Quarantine\C\WINDOWS\system32\pifufoyo.dll.vir
      [DETECTION] Is the TR/Vundo.Gen Trojan
      C:\Qoobox\Quarantine\C\WINDOWS\system32\prnet.tmp.vir
      [DETECTION] Is the TR/Click.VB.cvs Trojan
      C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\protect.dll.vir
      [DETECTION] Is the TR/Crypt.IL Trojan
      C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ovfsthrteonsvvayvysjajajbjdmopwdjesbiv.sys.vir
      [DETECTION] Is the TR/Dropper.Gen Trojan
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020315.sys
      [DETECTION] Is the TR/Dropper.Gen Trojan
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020316.dll
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020317.dll
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020318.dll
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020335.exe
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020336.dll
      [DETECTION] Is the TR/Crypt.IL Trojan
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020337.exe
      [DETECTION] Is the TR/Drop.Agent.amnc Trojan
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020340.dll
      [DETECTION] Is the TR/Vundo.Gen Trojan
      C:\WINDOWS\system32\benopezu.dll.tmp
      [DETECTION] Is the TR/Vundo.48640AJ.4 Trojan
      C:\WINDOWS\system32\simejufa.dll.tmp
      [DETECTION] Is the TR/Vundo.48640AJ.4 Trojan
      C:\WINDOWS\system32\terozepu.dll.tmp
      [DETECTION] Is the TR/Vundo.48640AJ.4 Trojan
      C:\WINDOWS\system32\drivers\sptd.sys
      [WARNING] The file could not be opened!

      Beginning disinfection:
      C:\Qoobox\Quarantine\C\WINDOWS\system32\ak1.exe.vir
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      [NOTE] The file was moved to '4a3521e8.qua'!
      C:\Qoobox\Quarantine\C\WINDOWS\system32\lmppcsetup.exe.vir
      [DETECTION] Is the TR/Drop.Agent.amnc Trojan
      [NOTE] The file was moved to '4a7421ea.qua'!
      C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthmhccrawmrctmynautfyvntfbmqotyvdj.dll.vir
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      [NOTE] The file was moved to '4a6a21f3.qua'!
      C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthmlqjnpdcikuyxmgmnbenhtskdnfyiajt.dll.vir
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      [NOTE] The file was moved to '49c2a884.qua'!
      C:\Qoobox\Quarantine\C\WINDOWS\system32\ovfsthmsapfowykmcqykpfjgauqayvrxdwjhdw.dll.vir
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      [NOTE] The file was moved to '4be60c4c.qua'!
      C:\Qoobox\Quarantine\C\WINDOWS\system32\pifufoyo.dll.vir
      [DETECTION] Is the TR/Vundo.Gen Trojan
      [NOTE] The file was moved to '4a6a21e6.qua'!
      C:\Qoobox\Quarantine\C\WINDOWS\system32\prnet.tmp.vir
      [DETECTION] Is the TR/Click.VB.cvs Trojan
      [NOTE] The file was moved to '4a7221ef.qua'!
      C:\Qoobox\Quarantine\C\WINDOWS\system32\config\systemprofile\protect.dll.vir
      [DETECTION] Is the TR/Crypt.IL Trojan
      [NOTE] The file was moved to '4a7321f0.qua'!
      C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ovfsthrteonsvvayvysjajajbjdmopwdjesbiv.sys.vir
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '4a6a21f4.qua'!
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020315.sys
      [DETECTION] Is the TR/Dropper.Gen Trojan
      [NOTE] The file was moved to '4a3421ae.qua'!
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020316.dll
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      [NOTE] The file was moved to '4bb32f3f.qua'!
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020317.dll
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      [NOTE] The file was moved to '4b4d68af.qua'!
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020318.dll
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      [NOTE] The file was moved to '4902d837.qua'!
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020335.exe
      [DETECTION] Is the TR/Crypt.ZPACK.Gen Trojan
      [NOTE] The file was moved to '490c20cf.qua'!
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020336.dll
      [DETECTION] Is the TR/Crypt.IL Trojan
      [NOTE] The file was moved to '490d2887.qua'!
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020337.exe
      [DETECTION] Is the TR/Drop.Agent.amnc Trojan
      [NOTE] The file was moved to '490e315f.qua'!
      C:\System Volume Information\_restore{057EF1DB-699E-460E-A182-554DABF78B4D}\RP243\A0020340.dll
      [DETECTION] Is the TR/Vundo.Gen Trojan
      [NOTE] The file was moved to '490f3917.qua'!
      C:\WINDOWS\system32\benopezu.dll.tmp
      [DETECTION] Is the TR/Vundo.48640AJ.4 Trojan
      [NOTE] The file was moved to '4a7221e3.qua'!
      C:\WINDOWS\system32\simejufa.dll.tmp
      [DETECTION] Is the TR/Vundo.48640AJ.4 Trojan
      [NOTE] The file was moved to '4a7121e7.qua'!
      C:\WINDOWS\system32\terozepu.dll.tmp
      [DETECTION] Is the TR/Vundo.48640AJ.4 Trojan
      [NOTE] The file was moved to '4a7621e3.qua'!


      End of the scan: 08 May 2009 13:11
      Used time: 1:47:03 Hour(s)

      The scan has been done completely.

      19753 Scanned directories
      744016 Files were scanned
      20 Viruses and/or unwanted programs were found
      0 Files were classified as suspicious
      0 files were deleted
      0 Viruses and unwanted programs were repaired
      20 Files were moved to quarantine
      0 Files were renamed
      3 Files cannot be scanned
      743993 Files not concerned
      13124 Archives were scanned
      3 Warnings
      22 Notes
      65498 Objects were scanned with rootkit scan
      0 Hidden objects were found
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. TR/Crypt.FKM.Gen
     
    ayudennme a eliminar este viruz TR/Crypt.FKM.Gen
    0