Trojan

Bonjour,

depuis quelques jours, à chaque démarrage de mon PC portable, il m'affiche ceci: alerte avast, un cheval de troie a été détecté: son nom:" html skin trim " et aussi " egcmgaup.tmp" .
Aprés quelques recherches sur divers forum, j'ai modifié les options de dossiers, ainsi j'ai pu avoir accés ax fichiers cachés et j'ai retrouvé le fichier egcmgaup.exe >> le problème, c'est que je ne peux pas le supprimer ("pas l'autorisation").
Etait-ce la bonne méthode, quelqu'un pourrait-il me donner la solution, m'aider à en finir avec ce trojan.
Merci d'avance.

17 réponses

  1. Avec avasst tu doit le metre en quarantaine et ensuite le supprimer
    1
    1. Démarre en mode sans echec et normalement tu pourras supprimer les fichiers.
      Sinon il existe un logiciel qui peut forcer la suppression de certains fichiers malheureusement je ne me rappelle plus du nom du soft.

      Bonne chance
      1
      1. Contributeur sécurité
        salut,

        skin trim,c'est magic.control

        pour vérifier

        - Télécharge TrendMicro™ HijackThis™ de Merijn(prog de diagnostic) sur ton bureau.
        - Cette version est sans installateur! ( Zip à décompresser )
        - Enregistre le sur ton bureau.

        -A l'installation,
        ****Place le dans son répertoire par défaut, c'est à dire : C:\program files***

        Important : Sous Vista, clic droit sur le fichier Hijackthis.exe ou sur le raccourci, Propriétés, Onglet Compatibilité, cocher :
        "Exécuter ce programme en tant qu'administrateur"

        installer hijackthis correctement:
        https://forums.cnetfrance.fr

        *** Ferme toute les fenêtres ouvertes , et déconnecte toi du web***

        - Double-clique dessus
        - Génère un rapport en suivant ces indications :
        - Exécute le et clique sur "Do a scan and save log file".
        - Le rapport s'ouvre sur le Bloc-Note.
        - Colle le rapport ici, pour cela :
        - Menu Edition / Selectionner Tout
        - Menu Edition / copier
        - Ici dans un nouveau message : clic droit / coller
        - ** ne pas fixer de lignes sans notre avis **
        Aide : N'hésite pas à consulter l'aide HiJackThis de Malekal_morte
        En image
        0
        1. sauf erreur de ma part, voici le rapport:

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:52:35, on 08/07/2009
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v7.00 (7.00.6001.18248)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\ASUS\ASUS Live Update\ALU.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
          C:\Program Files\ASUS\ATK Media\DMedia.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Windows\System32\ASUSTPE.exe
          C:\Windows\ASScrPro.exe
          C:\Program Files\PowerForPhone\PowerForPhone.exe
          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
          C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
          C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Users\EwenMaïna\AppData\Local\egcgmga.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\WinZip\WZQKPICK.EXE
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
          C:\Windows\System32\mobsync.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
          C:\Windows\system32\wuauclt.exe
          C:\Users\EwenMaïna\Desktop\HiJackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.asus.com/fr/
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
          O1 - Hosts: ::1 localhost
          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
          O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Ask Search Assistant BHO - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
          O2 - BHO: Megaupload Toolbar - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
          O2 - BHO: Mega Manager IE Click Monitor - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O2 - BHO: Ask Toolbar BHO - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
          O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
          O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
          O3 - Toolbar: Ask Toolbar - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
          O3 - Toolbar: Megaupload Toolbar - {A057A204-BACC-4D26-C39E-35F1D2A32EC8} - C:\PROGRA~1\MEGAUP~2\MEGAUP~1.DLL
          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
          O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
          O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [ASUSTPE] C:\Windows\system32\ASUSTPE.exe
          O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe
          O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
          O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone.exe
          O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
          O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
          O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
          O4 - HKLM\..\Run: [Emjysoft-Anti-Spam] C:\Program Files\Emjysoft\Antispam\antispam.exe
          O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
          O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
          O4 - HKCU\..\Run: [egcgmga] "c:\users\ewenmaïna\appdata\local\egcgmga.exe" egcgmga
          O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\SHOCKW~1\SWHELP~1.EXE -Update -1100465 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506; MEGAUPLOAD 3.0)" -"https://www.miniclip.com/games/golf-ace-hawaii/en/"
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
          O8 - Extra context menu item: Liens de téléchargement avec Mega Manager... - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
          O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
          O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
          O13 - Gopher Prefix:
          O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
          O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - http://javadl-esd.sun.com/update/1.5.0/jinstall-1_5_0_09-windows-i586.cab
          O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
          O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
          O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
          O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
          O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
          O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
          O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
          O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
          O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
          O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
          O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
          O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
          0
          1. Contributeur sécurité
            et donc voici notre ami skin trim/navipromo/magic.control
            O4 - HKCU\..\Run: [egcgmga] "c:\users\ewenmaïna\appdata\local\egcgmga.exe" egcgmga

            sur ce tu as d'autres trucs néfastes

            on commence par lui

            /!\IMPORTANT/!\
            Désactive l'UAC (User Account Control ou Contrôle de Compte Utilisateur) le temps de la désinfection,tu le réactiveras après ta désinfection:
            • Va dans Panneau de Configuration puis Comptes d'Utilisateurs.
            • Clique sur "Activer" ou "désactiver" le contrôle des comptes utilisateurs.
            • Décoche la case "Utiliser le contrôle des comptes utilisateurs pour vous aider à protéger votre ordinateur".
            • Clique sur OK pour enregistrer la modification et redémarre ton PC lorsque cela t'est demandé.

            aide en cas de problèmes

            ensuite

            Télécharge Navilog1.exe de il mafioso

            Note : Si, lors du téléchargement, ton Antivirus fais une alerte, ignore-là, un composant de Navilog1 est détecté par certains AntiVirus comme étant un Malware .
            Ce n'en est nullement un !


            * Choisis Enregistrer sous.... et enregistre-le sur ton bureau.
            * Sous XP, double clique sur navilog1.exe pour lancer l'installation.
            **Sous VISTA, fais un clic droit dessus et dans le menu contextuel choisis "Exécuter en tant qu'administrateur".
            tuto pour vista

            Une fois l'installation terminée, fais un clic droit sur le raccourci Navilog1
            présent sur ton bureau et choisis "Exécuter en tant qu'administrateur".
            (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

            Laisse-toi guider. Au menu principal, choisis 1 et valide.

            * Patiente jusqu'au message :
            ***Analyse Termine le.....***
            * Appuie sur une touche comme demandé, le bloc-note va s'ouvrir.
            * Copie/colle l'intégralité du rapport dans ta réponse.
            Referme le bloc-note.

            * Le rapport est en outre sauvegardé à la racine du disque C:\ (fixnavi.txt)

            Copie/colle le ici dans ta prochaine réponse stp.
            0
            1. aprés plusieurs péripéties, voici le rapport:

              Fix Navipromo version 4.0.0 commencé le 09/07/2009 à 18:05:55,17

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Postez ce rapport sur le forum pour le faire analyser !!!

              Outil exécuté depuis C:\Program Files\navilog1

              Mise à jour le 19.06.2009 à 20h00 par IL-MAFIOSO

              Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
              X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2330 @ 1.60GHz )
              BIOS : Default System BIOS
              USER : EwenMaïna ( Administrator )
              BOOT : Normal boot

              Antivirus : Norton Internet Security 2007 (Activated)
              Firewall : Norton Internet Security 2007 (Not Activated)

              C:\ (Local Disk) - NTFS - Total:84 Go (Free:41 Go)
              D:\ (Local Disk) - NTFS - Total:56 Go (Free:40 Go)
              E:\ (CD or DVD)
              F:\ (USB)

              Recherche exécutée en mode normal

              Nettoyage exécuté au redémarrage de l'ordinateur

              C:\Program Files\Live-Player supprimé !
              c:\progra~2\micros~1\windows\startm~1\programs\Live-Player supprimé !
              C:\Users\EwenMa‹na\AppData\Roaming\Live-Player supprimé !
              C:\Windows\prefetch\egcgmga*.pf supprimé !
              C:\Users\EwenMa‹na\AppData\Local\egcgmga.exe supprimé !
              C:\Users\EwenMa‹na\AppData\Local\egcgmga.dat supprimé !
              C:\Users\EwenMa‹na\AppData\Local\egcgmga_nav.dat supprimé !
              C:\Users\EwenMa‹na\AppData\Local\egcgmga_navps.dat supprimé !

              Nettoyage contenu C:\Windows\Temp effectué !
              Nettoyage contenu C:\Users\EWENMA~1\AppData\Local\Temp effectué !

              *** Sauvegarde du Registre vers dossier Safebackup ***

              sauvegarde du Registre réalisée avec succès !

              *** Nettoyage Registre ***

              Nettoyage Registre Ok
              0
              1. Plusieurs interrogations concernant mon PC (si tu peux me répondre, merci):

                Tu dis qu'il n'y à pas que ce trojan sur ma machine> est-ce pour cela que depuis un bon moment, il rame énormément? et pourra-t'on tout éradiquer?

                J'ai voulu télécharger un logiciel antispam (en fait je souhaitait quelque chose contre les pop-up, car depuis peu on est envahi de fenêtres de pubs, dès que l'on se connecte au web), je ne l'ai finalement jamais installé, mais à chaque démarrage il me propose de l'installer> Comment l'enlever de l'ordinateur?

                Quelle(s) solution(s) pour qu'un cheval de troie ne revienne à nouveau perturber le fonctionnement du micro, et éviter d'autres désagréments du même genre?
                0
                1. Contributeur sécurité
                  re,

                  oui tu as encore un adware que tu as installé de ton plein gré avec une toolbar inutile

                  on est envahi de fenêtres de pubs,

                  normal,c'est a ça que sert notre ami skin trim/navipromo!!

                  Télécharge Toolbar-S&D (Eric_71, Angeldark, Sham_Rock et XmichouX) sur ton Bureau.
                  https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                  en cas de problêmes,tu as un tuto
                  Tutorial Toolbar S&D

                  * Lance l'installation du programme en exécutant le fichier téléchargé.
                  * Double-clique sur le raccourci de Toolbar-S&D.
                  * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis valide avec la touche "Entrée".
                  * Choisis l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                  * Poste le rapport généré. (C:\TB.txt)
                  0
                  1. Voilà:

                    -----------\\ ToolBar S&D 1.2.8 XP/Vista

                    Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                    X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2330 @ 1.60GHz )
                    BIOS : Default System BIOS
                    USER : EwenMaïna ( Administrator )
                    BOOT : Normal boot
                    Antivirus : Norton Internet Security 2007 (Activated)
                    Firewall : Norton Internet Security 2007 (Not Activated)
                    C:\ (Local Disk) - NTFS - Total:84 Go (Free:42 Go)
                    D:\ (Local Disk) - NTFS - Total:56 Go (Free:40 Go)
                    E:\ (CD or DVD)
                    F:\ (USB)

                    "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                    Option : [1] ( 09/07/2009|21:43 )

                    [ UAC => 0 ]

                    -----------\\ Recherche de Fichiers / Dossiers ...

                    C:\Program Files\AskTBar
                    C:\Program Files\AskTBar\bar
                    C:\Program Files\AskTBar\PopSwatr
                    C:\Program Files\AskTBar\SrchAstt
                    C:\Program Files\AskTBar\bar\1.bin
                    C:\Program Files\AskTBar\bar\Cache
                    C:\Program Files\AskTBar\bar\History
                    C:\Program Files\AskTBar\bar\Settings
                    C:\Program Files\AskTBar\bar\1.bin\A5POPSWT.DLL
                    C:\Program Files\AskTBar\bar\1.bin\ASKTBAR.DLL
                    C:\Program Files\AskTBar\bar\Cache\000D5516
                    C:\Program Files\AskTBar\bar\Cache\000D5842
                    C:\Program Files\AskTBar\bar\Cache\000D5AB3.bin
                    C:\Program Files\AskTBar\bar\Cache\000D5D72.bin
                    C:\Program Files\AskTBar\bar\Cache\000D5F37.bin
                    C:\Program Files\AskTBar\bar\Cache\000D610C.bin
                    C:\Program Files\AskTBar\bar\Cache\000D634E.bin
                    C:\Program Files\AskTBar\bar\Cache\000D6533.bin
                    C:\Program Files\AskTBar\bar\Cache\000D6755.bin
                    C:\Program Files\AskTBar\bar\Cache\files.ini
                    C:\Program Files\AskTBar\bar\History\search2
                    C:\Program Files\AskTBar\bar\Settings\prevcfg2.htm
                    C:\Program Files\AskTBar\PopSwatr\History
                    C:\Program Files\AskTBar\PopSwatr\History\notallow
                    C:\Program Files\AskTBar\SrchAstt\1.bin
                    C:\Program Files\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL

                    -----------\\ [..\Internet Explorer\Main]

                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                    "Local Page"="C:\\Windows\\system32\\blank.htm"
                    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Start Page"="https://www.google.com/?gws_rd=ssl"
                    "Url"="https://www.msn.com/fr-fr/actualite/"

                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                    "Start Page"="http://www.ustart.org"
                    "Default_Page_URL"="https://www.asus.com/fr/"
                    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                    --------------------\\ Recherche d'autres infections

                    --------------------\\ Cracks & Keygens ..

                    C:\Users\EWENMA~1\Desktop\Restorer 2000 Pro v2 0 Crack
                    C:\Users\EWENMA~1\Desktop\Restorer 2000 Pro v2 0 Crack\crack.txt
                    C:\Users\EWENMA~1\Desktop\Restorer 2000 Pro v2 0 Crack\r2k_wnt.int
                    C:\Users\EWENMA~1\Desktop\Restorer 2000 Pro v2 0 Crack\Restorer 2000 Pro v2.0.exe

                    [ UAC => 1 ]

                    1 - "C:\ToolBar SD\TB_1.txt" - 09/07/2009|21:43 - Option : [1]

                    -----------\\ Fin du rapport a 21:43:45,60
                    0
                    1. Contributeur sécurité
                      bien,

                      Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".
                      *** Ne ferme pas la fenêtre lors de la suppression ***
                      Un rapport sera créé, poste son contenu ici.

                      ensuite

                      comme tu as des cracks,on va faire une p'tite recherche sur bagle

                      Télécharge FindyKill de Chiquitine29

                      Fais un clic droit sur le lien, enregistrer sous .....sur le bureau

                      http://sd-1.archive-host.com/membres/up/127028005715545653/FindyKill.exe

                      Installe le par défaut dans "Progam files"

                      Entre dans le dossier FindyKill

                      double clique sur "FindyKill.exe" (si ça fonctionne pas essaye "executer en tant qu'administrateur")

                      choisis l'option 1 (recherche)

                      un rapport va s'ouvrir, poste le dans ta prochaine réponse s-t-p

                      Note : le rapport FindyKill.txt est sauvegardé à la racine du disque

                      tutorial: https://www.malekal.com/tutorial-findykill/
                      0
                      1. Voilà pour la première opération:

                        -----------\\ ToolBar S&D 1.2.8 XP/Vista

                        Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                        X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2330 @ 1.60GHz )
                        BIOS : Default System BIOS
                        USER : EwenMaïna ( Administrator )
                        BOOT : Normal boot
                        Antivirus : Norton Internet Security 2007 (Activated)
                        Firewall : Norton Internet Security 2007 (Not Activated)
                        C:\ (Local Disk) - NTFS - Total:84 Go (Free:42 Go)
                        D:\ (Local Disk) - NTFS - Total:56 Go (Free:40 Go)
                        E:\ (CD or DVD)
                        F:\ (USB)

                        "C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
                        Option : [2] ( 09/07/2009|22:29 )

                        [ UAC => 1 ]

                        -----------\\ SUPPRESSION

                        Supprime! - C:\Program Files\AskTBar\bar
                        Supprime! - C:\Program Files\AskTBar\PopSwatr
                        Supprime! - C:\Program Files\AskTBar\SrchAstt
                        Supprime! - C:\Program Files\AskTBar

                        -----------\\ Recherche de Fichiers / Dossiers ...

                        -----------\\ [..\Internet Explorer\Main]

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                        "Local Page"="C:\\Windows\\system32\\blank.htm"
                        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                        "Start Page"="https://www.google.com/?gws_rd=ssl"
                        "Url"="https://www.msn.com/fr-fr/actualite/"

                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                        "Start Page"="https://www.msn.com/fr-fr/"
                        "Default_Page_URL"="https://www.asus.com/fr/"
                        "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                        "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                        --------------------\\ Recherche d'autres infections

                        --------------------\\ Cracks & Keygens ..

                        C:\Users\EWENMA~1\Desktop\Restorer 2000 Pro v2 0 Crack
                        C:\Users\EWENMA~1\Desktop\Restorer 2000 Pro v2 0 Crack\crack.txt
                        C:\Users\EWENMA~1\Desktop\Restorer 2000 Pro v2 0 Crack\r2k_wnt.int
                        C:\Users\EWENMA~1\Desktop\Restorer 2000 Pro v2 0 Crack\Restorer 2000 Pro v2.0.exe

                        [ UAC => 1 ]

                        1 - "C:\ToolBar SD\TB_1.txt" - 09/07/2009|21:43 - Option : [1]
                        2 - "C:\ToolBar SD\TB_2.txt" - 09/07/2009|22:31 - Option : [2]

                        -----------\\ Fin du rapport a 22:31:06,81
                        0
                        1. Voici le rapport Findykill:

                          ############################## | FindyKill V6.004 |

                          # User : EwenMaïna (Administrateurs) # PC-DE-EWENMAINA
                          # Update on 08/07/09 by Chiquitine29 & C_XX
                          # Start at: 22:57:00 | 09/07/2009
                          # Website : http://pagesperso-orange.fr/NosTools/index.html

                          # Intel(R) Pentium(R) Dual CPU T2330 @ 1.60GHz
                          # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                          # Internet Explorer 7.0.6001.18000
                          # Windows Firewall Status : Disabled
                          # AV : avast! antivirus 4.8.1229 [VPS 090709-0] 4.8.1229 [ Enabled | Updated ]
                          # AV : Norton Internet Security 2007 [ Enabled | (!) Outdated ]
                          # FW : Norton Internet Security[ (!) Disabled ]2007

                          # C:\ # Disque fixe local # 84,74 Go (42,12 Go free) [VistaOS] # NTFS
                          # D:\ # Disque fixe local # 56,49 Go (40,38 Go free) [DATA] # NTFS
                          # E:\ # Disque CD-ROM
                          # F:\ # Disque amovible

                          ############################## | Processus actifs |

                          C:\Windows\System32\smss.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\wininit.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\services.exe
                          C:\Windows\system32\winlogon.exe
                          C:\Windows\system32\lsass.exe
                          C:\Windows\system32\lsm.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\Ati2evxx.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\SLsvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\Ati2evxx.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
                          C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Program Files\ATK Hotkey\Hcontrol.exe
                          C:\Program Files\ATKOSD2\ATKOSD2.exe
                          C:\Program Files\Wireless Console 2\wcourier.exe
                          C:\Program Files\P4G\BatteryLife.exe
                          C:\Windows\System32\spoolsv.exe
                          C:\Program Files\ASUS\Splendid\ACMON.exe
                          C:\Windows\RtHDVCpl.exe
                          C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                          C:\Program Files\ASUS\ATK Media\DMedia.exe
                          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          C:\Windows\System32\ASUSTPE.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\ASScrPro.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Program Files\PowerForPhone\PowerForPhone.exe
                          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                          C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                          C:\Program Files\ATK Hotkey\ATKOSD.exe
                          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                          C:\Windows\System32\ACEngSvr.exe
                          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                          C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                          C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                          C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\ATK Hotkey\KBFiltr.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                          C:\Windows\ehome\ehtray.exe
                          C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\WinZip\WZQKPICK.EXE
                          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                          C:\Windows\ehome\ehmsas.exe
                          C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                          C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\StkCSrv.exe
                          C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\SearchIndexer.exe
                          C:\Windows\system32\WUDFHost.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\SearchProtocolHost.exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\Windows\system32\wbem\wmiprvse.exe
                          C:\Program Files\Windows Media Player\wmpnetwk.exe
                          C:\Windows\system32\wbem\wmiprvse.exe
                          C:\Windows\system32\conime.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

                          ################## | Registre Startup |

                          HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
                          HKCU_Main: "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                          HKCU_Main: "Start Page"="https://www.google.com/?gws_rd=ssl"
                          HKCU_Main: "Secondary Start Pages"=hex(7):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,\
                          HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
                          HKLM_logon: "LegalNoticeCaption"=""
                          HKLM_logon: "LegalNoticeText"=""
                          HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
                          HKLM_Run: RtHDVCpl=RtHDVCpl.exe
                          HKLM_Run: SMSERIAL=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                          HKLM_Run: ATKMEDIA=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                          HKLM_Run: SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                          HKLM_Run: ASUSTPE=C:\Windows\system32\ASUSTPE.exe
                          HKLM_Run: ASUS Camera ScreenSaver=C:\Windows\ASScrProlog.exe
                          HKLM_Run: ASUS Screen Saver Protector=C:\Windows\ASScrPro.exe
                          HKLM_Run: PowerForPhone=C:\Program Files\PowerForPhone\PowerForPhone.exe
                          HKLM_Run: ccApp="C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                          HKLM_Run: Symantec PIF AlertEng="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                          HKLM_Run: avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          HKLM_Run: TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                          HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          HKLM_Run: HP Software Update=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                          HKLM_Run: NeroFilterCheck=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                          HKLM_Run: hpqSRMon=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                          HKLM_Run: ArcSoft Connection Service=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                          HKLM_Run: Emjysoft-Anti-Spam=C:\Program Files\Emjysoft\Antispam\antispam.exe
                          HKLM_Run: GrooveMonitor="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                          HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                          HKCU_Run: Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                          HKCU_Run: StartCCC=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                          HKCU_Run: MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                          HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          HKCU_Run: LightScribe Control Panel=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                          HKCU_Run: ehTray.exe=C:\Windows\ehome\ehTray.exe
                          HKCU_Run: TomTomHOME.exe="C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
                          HKCU_Run: WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe

                          ################## | Fichiers # Dossiers infectieux |

                          ################## | C:\Users\EwenMa‹na\Temporary Internet Files |

                          ################## | All Drives ... |

                          ################## | Registre # Clés Run infectieuses |

                          Présent ! HKLM\software\microsoft\security center "UacDisableNotify" ( 0x1 )

                          ################## | Registre # Mountpoints2 |

                          HKCU\...\Explorer\MountPoints2\G\Shell\AutoRun\Command
                          HKCU\...\Explorer\MountPoints2\{e09736f3-d995-11dd-90c2-001fc61f4728}\Shell\AutoRun\Command
                          HKCU\...\Explorer\MountPoints2\{e550a89e-0f43-11de-b8a9-001fc61f4728}\Shell\AutoRun\Command

                          ################## | Etat / Services / Informations |

                          # Affichage des fichiers cachés : OK

                          # Mode sans echec : OK

                          # Uac : OK

                          # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                          # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
                          # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
                          # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
                          # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                          # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                          # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                          ################## | Cracks / Keygens / Serials |
                          0
                          1. Contributeur sécurité
                            re,

                            Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d'avoir été infectées sans les ouvrir
                            réouvre Findykill,

                            choisis cette fois ci l'option 2 (suppression)

                            il y aura 1 redémarrage, laisse travailler l'outils jusqu'a l'apparition du message "nettoyage effectué"

                            un rapport va s'ouvrir, poste le dans ta prochaine réponse s-t-p

                            Note : le rapport FindyKill.txt est sauvegardé à la racine du disque
                            Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valides

                            0
                            1. J'ai comme l'impression qu'il s'agit du même rapport, non?

                              ############################## | FindyKill V6.004 |

                              # User : EwenMaïna (Administrateurs) # PC-DE-EWENMAINA
                              # Update on 08/07/09 by Chiquitine29 & C_XX
                              # Start at: 22:57:00 | 09/07/2009
                              # Website : http://pagesperso-orange.fr/NosTools/index.html

                              # Intel(R) Pentium(R) Dual CPU T2330 @ 1.60GHz
                              # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                              # Internet Explorer 7.0.6001.18000
                              # Windows Firewall Status : Disabled
                              # AV : avast! antivirus 4.8.1229 [VPS 090709-0] 4.8.1229 [ Enabled | Updated ]
                              # AV : Norton Internet Security 2007 [ Enabled | (!) Outdated ]
                              # FW : Norton Internet Security[ (!) Disabled ]2007

                              # C:\ # Disque fixe local # 84,74 Go (42,12 Go free) [VistaOS] # NTFS
                              # D:\ # Disque fixe local # 56,49 Go (40,38 Go free) [DATA] # NTFS
                              # E:\ # Disque CD-ROM
                              # F:\ # Disque amovible

                              ############################## | Processus actifs |

                              C:\Windows\System32\smss.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\wininit.exe
                              C:\Windows\system32\csrss.exe
                              C:\Windows\system32\services.exe
                              C:\Windows\system32\winlogon.exe
                              C:\Windows\system32\lsass.exe
                              C:\Windows\system32\lsm.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\Ati2evxx.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\SLsvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\system32\Ati2evxx.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                              C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
                              C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Program Files\ATK Hotkey\Hcontrol.exe
                              C:\Program Files\ATKOSD2\ATKOSD2.exe
                              C:\Program Files\Wireless Console 2\wcourier.exe
                              C:\Program Files\P4G\BatteryLife.exe
                              C:\Windows\System32\spoolsv.exe
                              C:\Program Files\ASUS\Splendid\ACMON.exe
                              C:\Windows\RtHDVCpl.exe
                              C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                              C:\Program Files\ASUS\ATK Media\DMedia.exe
                              C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              C:\Windows\System32\ASUSTPE.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\ASScrPro.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Program Files\PowerForPhone\PowerForPhone.exe
                              C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                              C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                              C:\Program Files\ATK Hotkey\ATKOSD.exe
                              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                              C:\Windows\System32\ACEngSvr.exe
                              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                              C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                              C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                              C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\ATK Hotkey\KBFiltr.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
                              C:\Windows\ehome\ehtray.exe
                              C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\WinZip\WZQKPICK.EXE
                              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
                              C:\Windows\ehome\ehmsas.exe
                              C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
                              C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\svchost.exe
                              C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
                              C:\Windows\system32\svchost.exe
                              C:\Windows\System32\StkCSrv.exe
                              C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                              C:\Windows\System32\svchost.exe
                              C:\Windows\system32\SearchIndexer.exe
                              C:\Windows\system32\WUDFHost.exe
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\SearchProtocolHost.exe
                              C:\Windows\system32\SearchFilterHost.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\Windows\system32\wbem\wmiprvse.exe
                              C:\Program Files\Windows Media Player\wmpnetwk.exe
                              C:\Windows\system32\wbem\wmiprvse.exe
                              C:\Windows\system32\conime.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe

                              ################## | Registre Startup |

                              HKCU_Main: "Local Page"="C:\\Windows\\system32\\blank.htm"
                              HKCU_Main: "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                              HKCU_Main: "Start Page"="https://www.google.com/?gws_rd=ssl"
                              HKCU_Main: "Secondary Start Pages"=hex(7):68,00,74,00,74,00,70,00,3a,00,2f,00,2f,00,77,00,\
                              HKLM_logon: "Userinit"="C:\\Windows\\system32\\userinit.exe,"
                              HKLM_logon: "LegalNoticeCaption"=""
                              HKLM_logon: "LegalNoticeText"=""
                              HKLM_Run: Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              HKLM_Run: RtHDVCpl=RtHDVCpl.exe
                              HKLM_Run: SMSERIAL=C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
                              HKLM_Run: ATKMEDIA=C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
                              HKLM_Run: SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                              HKLM_Run: ASUSTPE=C:\Windows\system32\ASUSTPE.exe
                              HKLM_Run: ASUS Camera ScreenSaver=C:\Windows\ASScrProlog.exe
                              HKLM_Run: ASUS Screen Saver Protector=C:\Windows\ASScrPro.exe
                              HKLM_Run: PowerForPhone=C:\Program Files\PowerForPhone\PowerForPhone.exe
                              HKLM_Run: ccApp="C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                              HKLM_Run: Symantec PIF AlertEng="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                              HKLM_Run: avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              HKLM_Run: TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                              HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              HKLM_Run: HP Software Update=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              HKLM_Run: NeroFilterCheck=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
                              HKLM_Run: hpqSRMon=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                              HKLM_Run: ArcSoft Connection Service=C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
                              HKLM_Run: Emjysoft-Anti-Spam=C:\Program Files\Emjysoft\Antispam\antispam.exe
                              HKLM_Run: GrooveMonitor="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                              HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                              HKCU_Run: Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              HKCU_Run: StartCCC=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
                              HKCU_Run: MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              HKCU_Run: swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              HKCU_Run: LightScribe Control Panel=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
                              HKCU_Run: ehTray.exe=C:\Windows\ehome\ehTray.exe
                              HKCU_Run: TomTomHOME.exe="C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
                              HKCU_Run: WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe

                              ################## | Fichiers # Dossiers infectieux |

                              ################## | C:\Users\EwenMa‹na\Temporary Internet Files |

                              ################## | All Drives ... |

                              ################## | Registre # Clés Run infectieuses |

                              Présent ! HKLM\software\microsoft\security center "UacDisableNotify" ( 0x1 )

                              ################## | Registre # Mountpoints2 |

                              HKCU\...\Explorer\MountPoints2\G\Shell\AutoRun\Command
                              HKCU\...\Explorer\MountPoints2\{e09736f3-d995-11dd-90c2-001fc61f4728}\Shell\AutoRun\Command
                              HKCU\...\Explorer\MountPoints2\{e550a89e-0f43-11de-b8a9-001fc61f4728}\Shell\AutoRun\Command

                              ################## | Etat / Services / Informations |

                              # Affichage des fichiers cachés : OK

                              # Mode sans echec : OK

                              # Uac : OK

                              # Ndisuio -> Start = 3 ( Good = 3 | Bad = 4 )
                              # EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
                              # Wlansvc -> Start = 2 ( Good = 2 | Bad = 4 )
                              # (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
                              # windefend -> Start = 2 ( Good = 2 | Bad = 4 )
                              # wuauserv -> Start = 2 ( Good = 2 | Bad = 4 )
                              # wscsvc -> Start = 2 ( Good = 2 | Bad = 4 )

                              ################## | Cracks / Keygens / Serials |
                              0
                              1. Contributeur sécurité
                                ah bah oui!

                                t'as fais l'option 2?
                                0
                                1. Salut, j'ai refait la procédure compléte (il est probable que le premier nettoyage avec mon disque externe n'ait pas été fait correctement) et posté le rapport. Qu'en est-il de la suite à donner à tout çà????

                                  Par contre, on voit déjà le mieux pour le surf sur internet!!!!
                                  0
                              2. Salut, après un long week-end de repos, me voici de nouveau parti à l'attaque:
                                Cette fois-ci, ce devrait être le bon rapport:

                                ############################## | FindyKill V6.004 |

                                # User : EwenMaïna (Administrateurs) # PC-DE-EWENMAINA
                                # Update on 08/07/09 by Chiquitine29 & C_XX
                                # Start at: 09:38:57 | 15/07/2009
                                # Website : http://pagesperso-orange.fr/NosTools/index.html

                                # Intel(R) Pentium(R) Dual CPU T2330 @ 1.60GHz
                                # Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
                                # Internet Explorer 7.0.6001.18000
                                # Windows Firewall Status : Disabled
                                # AV : avast! antivirus 4.8.1229 [VPS 090710-0] 4.8.1229 [ Enabled | Updated ]
                                # AV : Norton Internet Security 2007 [ Enabled | (!) Outdated ]
                                # FW : Norton Internet Security[ (!) Disabled ]2007

                                # C:\ # Disque fixe local # 84,74 Go (41,46 Go free) [VistaOS] # NTFS
                                # D:\ # Disque fixe local # 56,49 Go (40,38 Go free) [DATA] # NTFS
                                # E:\ # Disque CD-ROM
                                # F:\ # Disque amovible
                                # G:\ # Disque fixe local # 465,64 Go (378,08 Go free) [My Book] # FAT32
                                # H:\ # Disque amovible # 1,91 Go (1,45 Go free) # FAT

                                ############################## | Processus actifs |

                                C:\Windows\System32\smss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\wininit.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\services.exe
                                C:\Windows\system32\lsass.exe
                                C:\Windows\system32\lsm.exe
                                C:\Windows\system32\winlogon.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\Ati2evxx.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\SLsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\Ati2evxx.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
                                C:\Program Files\ATK Hotkey\ASLDRSrv.exe
                                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                C:\Windows\System32\spoolsv.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
                                C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\StkCSrv.exe
                                C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\SearchIndexer.exe
                                C:\Windows\system32\WUDFHost.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Program Files\ASUS\ASUS Live Update\ALU.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\ATK Hotkey\Hcontrol.exe
                                C:\Program Files\ATKOSD2\ATKOSD2.exe
                                C:\Program Files\Wireless Console 2\wcourier.exe
                                C:\Program Files\P4G\BatteryLife.exe
                                C:\Program Files\ASUS\Splendid\ACMON.exe
                                C:\Windows\System32\ACEngSvr.exe
                                C:\Program Files\ATK Hotkey\ATKOSD.exe
                                C:\Program Files\ATK Hotkey\KBFiltr.exe
                                C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                C:\Windows\system32\wbem\wmiprvse.exe
                                C:\Windows\system32\PresentationSettings.exe
                                C:\Windows\system32\runonce.exe
                                C:\Windows\system32\conime.exe
                                C:\Windows\system32\wbem\wmiprvse.exe

                                ################## | Fichiers # Dossiers infectieux |

                                ################## | C:\Users\EwenMa‹na\Temporary Internet Files |

                                ################## | All Drives ... |

                                Supprimé ! G:\Setup.exe
                                Supprimé ! G:\autorun.inf

                                ################## | Autres ... |

                                ################## | Registre # Clés Run infectieuses |

                                # HKLM\software\microsoft\security center "UacDisableNotify" # -> Reset sucessfully !

                                ################## | Registre # Mountpoints2 |

                                Supprimé ! HKCU\...\Explorer\MountPoints2\G\Shell\AutoRun\Command
                                Supprimé ! HKCU\...\Explorer\MountPoints2\{e09736f3-d995-11dd-90c2-001fc61f4728}\Shell\AutoRun\Command
                                Supprimé ! HKCU\...\Explorer\MountPoints2\{e550a89e-0f43-11de-b8a9-001fc61f4728}\Shell\AutoRun\Command

                                ################## | Listing des fichiers présent |

                                [18/09/2006 23:43|--a------|24] - C:\autoexec.bat
                                [19/01/2008 09:45|-rahs----|333203] - C:\bootmgr
                                [09/07/2009 18:26|--a------|1653] - C:\cleannavi.txt
                                [18/09/2006 23:43|--a------|10] - C:\config.sys
                                [30/07/2007 18:55|-rah-----|524288] - C:\F5RL.ROM
                                [15/07/2009 10:09|--a------|4511] - C:\FindyKill.txt
                                [09/07/2009 22:59|--a------|9019] - C:\FindyKill1.txt
                                [?|?|?] - C:\hiberfil.sys
                                [?|?|?] - C:\pagefile.sys
                                [12/04/2009 00:40|--ah-----|268] - C:\sqmdata00.sqm
                                [12/04/2009 00:40|--ah-----|244] - C:\sqmnoopt00.sqm
                                [09/07/2009 22:31|--a------|2205] - C:\TB.txt
                                [24/11/2008 23:30|--a------|1942016] - D:\bellion 2.MSWMM
                                [09/11/2008 21:40|--a------|1942528] - D:\bellion.MSWMM
                                [22/01/2009 22:27|---hs----|83] - D:\desktop.ini
                                [12/08/2008 11:40|--a------|650] - D:\Sample Videos.lnk
                                [02/11/2008 11:30|--a------|154624] - D:\stef.MSWMM
                                [31/03/2008 12:57|--a------|87] - G:\Install.ini
                                [15/07/2009 09:23|--a------|78] - G:\Install.log
                                [29/05/2008 22:08|--a------|291417] - H:\Instructions_0806.pdf
                                [29/05/2009 10:07|--a------|24064] - H:\stickers.doc
                                [26/05/2009 16:29|--a------|32256] - H:\DP.doc
                                [10/06/2009 14:24|--a------|32992] - H:\groupe district.pdf
                                [21/06/2009 13:17|--a------|29184] - H:\discours.doc
                                [03/07/2009 08:12|--a------|32256] - H:\discours modifi‚.doc
                                [29/06/2009 12:43|--a------|4078061] - H:\lampe basse consommation.wmv
                                [16/05/2006 20:49|--a------|2319274] - H:\Chez maman.wmv
                                [30/12/2008 15:12|--a------|1079691] - H:\anniversaires famille2.jpg
                                [30/12/2008 15:10|--a------|1519078] - H:\anniversaires famille1.jpg
                                [20/03/2009 09:54|--a------|10903932] - H:\guide-longeville-2009.pdf
                                0
                                1. Aussi, depuis 5-6 jours j'ai ce message qui s'affiche:
                                  Asus Live Update a cessé de fonctionner
                                  Un pb a fait que le programme a cessé de fonctionner correctement....
                                  0