Virus windowsclick ...
pedrodu69
Messages postés
279
Statut
Membre
-
kduc -
kduc -
Bonjour,
J'ai le virus windowsclick sur mon ordi , j'ai vu d'autre post sur ce sujet mais tous avec des manips différentes. J'ai fait un rapport avec hijackthis que je vous donne pour m'aider. Je vous remerci d'avance pour votre aide!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:54:40, on 07/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\windows\system32\PnkBstrB.exe
C:\windows\system32\svchost.exe
C:\windows\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Documents and Settings\Games\Bureau\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - (no file)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
O20 - AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd.dll,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrB - Unknown owner - C:\windows\system32\PnkBstrB.exe
J'ai le virus windowsclick sur mon ordi , j'ai vu d'autre post sur ce sujet mais tous avec des manips différentes. J'ai fait un rapport avec hijackthis que je vous donne pour m'aider. Je vous remerci d'avance pour votre aide!
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:54:40, on 07/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\windows\system32\PnkBstrB.exe
C:\windows\system32\svchost.exe
C:\windows\Explorer.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Internet Explorer\Iexplore.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\Documents and Settings\Games\Bureau\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - (no file)
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
O20 - AppInit_DLLs: c:\progra~1\kasper~1\kasper~1\mzvkbd.dll,c:\progra~1\kasper~1\kasper~1\mzvkbd3.dll,c:\progra~1\kasper~1\kasper~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrB - Unknown owner - C:\windows\system32\PnkBstrB.exe
A voir également:
- Virus windowsclick ...
- Virus mcafee - Accueil - Piratage
- Virus facebook demande d'amis - Accueil - Facebook
- Virus informatique - Guide
- Panda anti virus gratuit - Télécharger - Antivirus & Antimalwares
- Undisclosed-recipients virus - Guide
37 réponses
Sa y est fini :) :) :) :)
tiens le rapport , j'ai tout supprimer!
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2392
Windows 5.1.2600 Service Pack 2
08/07/2009 17:52:13
mbam-log-2009-07-08 (17-52-05).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 198836
Temps écoulé: 52 minute(s), 48 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 20
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309436.sys (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309437.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309438.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309439.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309440.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309441.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309442.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310223.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310651.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310652.dll (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETjvbddiye.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETtsaekvvm.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACegpavyvkhbwbouu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACgeacugexfcnoddu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACjkkebdykuciixds.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACqjnkrdlsewnirrn.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACviumqgwylftplpy.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACvxmsjohubltrhyi.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\drivers\UACqpoakjbutaybivv.sys.vir (Trojan.TDSS) -> No action taken.
d:\téléchargement\logiciels\rar_password_cracker_v4.12\rpc.exe (Trojan.Dropper) -> No action taken.
tiens le rapport , j'ai tout supprimer!
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2392
Windows 5.1.2600 Service Pack 2
08/07/2009 17:52:13
mbam-log-2009-07-08 (17-52-05).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 198836
Temps écoulé: 52 minute(s), 48 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 20
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309436.sys (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309437.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309438.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309439.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309440.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309441.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309442.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310223.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310651.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310652.dll (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETjvbddiye.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETtsaekvvm.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACegpavyvkhbwbouu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACgeacugexfcnoddu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACjkkebdykuciixds.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACqjnkrdlsewnirrn.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACviumqgwylftplpy.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACvxmsjohubltrhyi.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\drivers\UACqpoakjbutaybivv.sys.vir (Trojan.TDSS) -> No action taken.
d:\téléchargement\logiciels\rar_password_cracker_v4.12\rpc.exe (Trojan.Dropper) -> No action taken.
Finis , tout supprimé , niquel!!!
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2392
Windows 5.1.2600 Service Pack 2
08/07/2009 17:52:13
mbam-log-2009-07-08 (17-52-05).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 198836
Temps écoulé: 52 minute(s), 48 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 20
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309436.sys (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309437.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309438.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309439.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309440.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309441.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309442.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310223.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310651.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310652.dll (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETjvbddiye.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETtsaekvvm.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACegpavyvkhbwbouu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACgeacugexfcnoddu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACjkkebdykuciixds.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACqjnkrdlsewnirrn.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACviumqgwylftplpy.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACvxmsjohubltrhyi.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\drivers\UACqpoakjbutaybivv.sys.vir (Trojan.TDSS) -> No action taken.
d:\téléchargement\logiciels\rar_password_cracker_v4.12\rpc.exe (Trojan.Dropper) -> No action taken.
PS : MERCI !! JSPR QUE TOUT EST BON OU D'AUTRE CHOSE A FAIRE ??? CORDIALEMENT
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2392
Windows 5.1.2600 Service Pack 2
08/07/2009 17:52:13
mbam-log-2009-07-08 (17-52-05).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 198836
Temps écoulé: 52 minute(s), 48 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 20
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309436.sys (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309437.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309438.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309439.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309440.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309441.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309442.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310223.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310651.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310652.dll (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETjvbddiye.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETtsaekvvm.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACegpavyvkhbwbouu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACgeacugexfcnoddu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACjkkebdykuciixds.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACqjnkrdlsewnirrn.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACviumqgwylftplpy.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACvxmsjohubltrhyi.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\drivers\UACqpoakjbutaybivv.sys.vir (Trojan.TDSS) -> No action taken.
d:\téléchargement\logiciels\rar_password_cracker_v4.12\rpc.exe (Trojan.Dropper) -> No action taken.
PS : MERCI !! JSPR QUE TOUT EST BON OU D'AUTRE CHOSE A FAIRE ??? CORDIALEMENT
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Finis , tout supprimé , niquel!!!
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2392
Windows 5.1.2600 Service Pack 2
08/07/2009 17:52:13
mbam-log-2009-07-08 (17-52-05).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 198836
Temps écoulé: 52 minute(s), 48 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 20
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309436.sys (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309437.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309438.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309439.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309440.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309441.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309442.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310223.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310651.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310652.dll (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETjvbddiye.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETtsaekvvm.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACegpavyvkhbwbouu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACgeacugexfcnoddu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACjkkebdykuciixds.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACqjnkrdlsewnirrn.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACviumqgwylftplpy.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACvxmsjohubltrhyi.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\drivers\UACqpoakjbutaybivv.sys.vir (Trojan.TDSS) -> No action taken.
d:\téléchargement\logiciels\rar_password_cracker_v4.12\rpc.exe (Trojan.Dropper) -> No action taken.
PS : MERCI !! JSPR QUE TOUT EST BON OU D'AUTRE CHOSE A FAIRE ??? CORDIALEMENT
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2392
Windows 5.1.2600 Service Pack 2
08/07/2009 17:52:13
mbam-log-2009-07-08 (17-52-05).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 198836
Temps écoulé: 52 minute(s), 48 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 20
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309436.sys (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309437.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309438.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309439.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309440.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309441.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309442.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310223.exe (Trojan.Dropper) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310651.dll (Trojan.TDSS) -> No action taken.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310652.dll (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETjvbddiye.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\SKYNETtsaekvvm.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACegpavyvkhbwbouu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACgeacugexfcnoddu.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACjkkebdykuciixds.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACqjnkrdlsewnirrn.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACviumqgwylftplpy.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\UACvxmsjohubltrhyi.dll.vir (Trojan.TDSS) -> No action taken.
c:\Qoobox\quarantine\C\windows\system32\drivers\UACqpoakjbutaybivv.sys.vir (Trojan.TDSS) -> No action taken.
d:\téléchargement\logiciels\rar_password_cracker_v4.12\rpc.exe (Trojan.Dropper) -> No action taken.
PS : MERCI !! JSPR QUE TOUT EST BON OU D'AUTRE CHOSE A FAIRE ??? CORDIALEMENT
Alors , le log :
Logfile of random's system information tool 1.06 (written by random/random)
Run by Games at 2009-07-08 18:10:16
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 66 GB (85%) free of 78 GB
Total RAM: 1024 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:10:21, on 08/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\PnkBstrB.exe
C:\windows\system32\svchost.exe
C:\windows\Explorer.EXE
C:\windows\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Games\Bureau\RSIT.exe
C:\Documents and Settings\Games\Bureau\Games.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrB - Unknown owner - C:\windows\system32\PnkBstrB.exe
Logfile of random's system information tool 1.06 (written by random/random)
Run by Games at 2009-07-08 18:10:16
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 66 GB (85%) free of 78 GB
Total RAM: 1024 MB (61% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:10:21, on 08/07/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\PnkBstrB.exe
C:\windows\system32\svchost.exe
C:\windows\Explorer.EXE
C:\windows\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Games\Bureau\RSIT.exe
C:\Documents and Settings\Games\Bureau\Games.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O3 - Toolbar: SYSTRAN Toolbar - {95daa571-4def-4a6d-97d8-98a346672a24} - mscoree.dll (file missing)
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: &Virtual keyboard - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: URLs c&heck - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'c:\program files\bonjour\mdnsnsp.dll' missing
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - https://driveragent.com/files/driveragent.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\windows\system32\nvsvc32.exe
O23 - Service: PnkBstrB - Unknown owner - C:\windows\system32\PnkBstrB.exe
Mais je viens d'en faire un ! J'ai tout supprimer ! SUR ET CERTAIN!
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2392
Windows 5.1.2600 Service Pack 2
08/07/2009 17:53:48
mbam-log-2009-07-08 (17-53-48).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 198836
Temps écoulé: 52 minute(s), 48 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 20
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309436.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309437.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309438.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309439.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309440.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309441.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309442.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310223.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310651.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310652.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\SKYNETjvbddiye.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\SKYNETtsaekvvm.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACegpavyvkhbwbouu.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACgeacugexfcnoddu.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACjkkebdykuciixds.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACqjnkrdlsewnirrn.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACviumqgwylftplpy.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACvxmsjohubltrhyi.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\drivers\UACqpoakjbutaybivv.sys.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
d:\téléchargement\logiciels\rar_password_cracker_v4.12\rpc.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
Malwarebytes' Anti-Malware 1.38
Version de la base de données: 2392
Windows 5.1.2600 Service Pack 2
08/07/2009 17:53:48
mbam-log-2009-07-08 (17-53-48).txt
Type de recherche: Examen complet (C:\|D:\|)
Eléments examinés: 198836
Temps écoulé: 52 minute(s), 48 second(s)
Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 20
Processus mémoire infecté(s):
(Aucun élément nuisible détecté)
Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)
Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)
Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)
Dossier(s) infecté(s):
(Aucun élément nuisible détecté)
Fichier(s) infecté(s):
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309436.sys (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309437.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309438.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309439.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309440.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309441.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0309442.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310223.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310651.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\system volume information\_restore{3af69682-42a0-42f2-88a1-e941249be9fc}\RP417\A0310652.dll (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\SKYNETjvbddiye.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\SKYNETtsaekvvm.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACegpavyvkhbwbouu.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACgeacugexfcnoddu.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACjkkebdykuciixds.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACqjnkrdlsewnirrn.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACviumqgwylftplpy.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\UACvxmsjohubltrhyi.dll.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
c:\Qoobox\quarantine\C\windows\system32\drivers\UACqpoakjbutaybivv.sys.vir (Trojan.TDSS) -> Quarantined and deleted successfully.
d:\téléchargement\logiciels\rar_password_cracker_v4.12\rpc.exe (Trojan.Dropper) -> Quarantined and deleted successfully.