Trojan ntoskrnl-hook imposible a supprimer

Résolu
Bonjour,
Hier soir sur le pc de mon homme se bloquait quelque minutes apres l'allumage
j'ai donc lancer une recherche antivirus avec McAfee et il a trouver ceci:

"NTOSKRNL-HOOK
cheval de troie
generic rootkit.d!rootkit"

McAfee dit que l'élément est réparé jusque la pas de souci.

Ce matin le bug se reproduit je relance une recherche et le cheval de troie est toujours là

j'aurais besoin d'une solution pour le supprimer de manière definitive
vous remerciant par avance.
Configuration: Windows XP Internet Explorer 7.0

16 réponses

  1. Contributeur sécurité
    salut

    • Télécharge Random's System Information Tool (RSIT) de Random/Random, et enregistre le sur ton Bureau.
    http://images.malwareremoval.com/random/RSIT.exe

    Double clique sur RSIT.exe pour lancer l'outil.
    • Clique sur "Continue" à l'écran Disclaimer.
    • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande) et tu devras accepter la licence.
    • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

    Tutoriel illustré pour t'aider : https://www.androidworld.fr/
    0
    1. alors voila les deux rapport

      celui-ci s'appelle log
      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Alexandre Ribière at 2009-07-15 18:13:09
      Microsoft Windows XP Édition familiale Service Pack 3
      System drive C: has 207 GB (69%) free of 302 GB
      Total RAM: 3070 MB (79% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 18:13:25, on 15/07/2009
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\WINDOWS\system32\ICO.EXE
      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
      C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
      C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
      C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
      C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      C:\Program Files\Winamp\Winampa.exe
      C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
      C:\WINDOWS\system32\Pmxmiced.exe
      C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
      C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Logitech\QuickCam\Quickcam.exe
      C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
      C:\Program Files\McAfee.com\Agent\mcagent.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
      C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
      c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
      C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      C:\Program Files\McAfee\MPF\MPFSrv.exe
      C:\Program Files\McAfee\MSK\MskSrver.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\Pen_Tablet.exe
      C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
      C:\WINDOWS\system32\Pen_Tablet.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\Alexandre Ribière\Bureau\RSIT.exe
      C:\Program Files\trend micro\Alexandre Ribière.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=4080224
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/hws/sb/dell-row/fr/side.html?channel=fr
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/hws/sb/dell-row/fr/side.html?channel=fr
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/hws/sb/dell-row/fr/side.html?channel=fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=4080224
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O1 - Hosts: 94.23.26.222 L2authd.lineage2.com
      O1 - Hosts: 216.107.250.194 nprotect.lineage2.com
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
      O2 - BHO: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
      O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
      O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
      O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O3 - Toolbar: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
      O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
      O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
      O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
      O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
      O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
      O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
      O4 - HKLM\..\Run: [net] "C:\WINDOWS\system32\net.net"
      O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
      O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
      O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
      O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
      O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
      O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
      O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
      O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
      O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
      O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
      O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
      O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe
      O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
      0
      1. Contributeur sécurité
        re

        donc apparament tu es infecté par du Vundo https://www.systemlookup.com/search.php?type=filename&client=malwaresearch-ff&search=net.net

        affiche les dossier caché a l'aide de ceci :
        http://www.commentcamarche.net/faq/sujet 825 afficher les extensions et les fichiers caches sous windows

        puis fait ceci :

        clic ici https://www.virustotal.com/gui/ et clic sur parcourir et va cherche les fichier un par un et fait analyser ces fichiers et poste les rapport en entier avec les NOM DU FICHIER EN ENTETE

        C:\WINDOWS\system32\net.net-up.txt
        C:\WINDOWS\system32\rn.tmp
        C:\WINDOWS\system32\drivers\orviyusientixfvr.sys

        tu fait sa pour les 3 fichiers ci dessus

        et tu connais un genre d'adresse internet avec lineage2.com ??
        0
        1. alors voila

          j'ai passer les deux premiers fichiers que tu m'as dis, pour le troisième je ne l'ai pas trouver

          alors pour le premier il n'a strictement rien trouver

          et pour le second voici ce qu'il m'a trouver:
          Fichier rn.tmp reçu le 2009.07.15 16:51:44 (UTC)
          Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

          Résultat: 10/40 (25%)
          en train de charger les informations du serveur...
          Votre fichier est dans la file d'attente, en position: 1.
          L'heure estimée de démarrage est entre 40 et 57 secondes.
          Ne fermez pas la fenêtre avant la fin de l'analyse.
          L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
          Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
          Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
          les résultats seront affichés au fur et à mesure de leur génération.
          Formaté Impression des résultats Votre fichier a expiré ou n'existe pas.
          Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.
          Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée. Email:

          Antivirus Version Dernière mise à jour Résultat
          a-squared 4.5.0.24 2009.07.15 -
          AhnLab-V3 5.0.0.2 2009.07.15 -
          AntiVir 7.9.0.215 2009.07.15 TR/Agent.ands.1
          Antiy-AVL 2.0.3.7 2009.07.15 -
          Authentium 5.1.2.4 2009.07.15 -
          Avast 4.8.1335.0 2009.07.14 -
          AVG 8.5.0.387 2009.07.15 Generic14.BSU
          BitDefender 7.2 2009.07.15 Trojan.Agent.ANDS
          CAT-QuickHeal 10.00 2009.07.15 -
          ClamAV 0.94.1 2009.07.15 -
          Comodo 1660 2009.07.15 -
          DrWeb 5.0.0.12182 2009.07.15 -
          eSafe 7.0.17.0 2009.07.15 -
          eTrust-Vet 31.6.6616 2009.07.15 -
          F-Prot 4.4.4.56 2009.07.14 -
          Fortinet 3.120.0.0 2009.07.15 -
          GData 19 2009.07.15 Trojan.Agent.ANDS
          Ikarus T3.1.1.64.0 2009.07.15 -
          Jiangmin 11.0.706 2009.07.15 -
          K7AntiVirus 7.10.792 2009.07.14 -
          Kaspersky 7.0.0.125 2009.07.15 -
          McAfee 5676 2009.07.14 -
          McAfee+Artemis 5676 2009.07.14 -
          McAfee-GW-Edition 6.8.5 2009.07.15 Trojan.Agent.ands.1
          Microsoft 1.4803 2009.07.15 -
          NOD32 4246 2009.07.15 -
          Norman 6.01.09 2009.07.15 -
          nProtect 2009.1.8.0 2009.07.15 -
          Panda 10.0.0.14 2009.07.14 -
          PCTools 4.4.2.0 2009.07.15 -
          Prevx 3.0 2009.07.15 Medium Risk Malware
          Rising 21.38.24.00 2009.07.15 -
          Sophos 4.43.0 2009.07.15 Troj/Mdrop-CDV
          Sunbelt 3.2.1858.2 2009.07.15 BehavesLike.Win32.Malware (v)
          Symantec 1.4.4.12 2009.07.15 Trojan Horse
          TheHacker 6.3.4.3.368 2009.07.15 -
          TrendMicro 8.950.0.1094 2009.07.15 TROJ_AGENTT.EG
          VBA32 3.12.10.8 2009.07.15 -
          ViRobot 2009.7.15.1837 2009.07.15 -
          VirusBuster 4.6.5.0 2009.07.15 -
          Information additionnelle
          File size: 1046861 bytes
          MD5...: ea7145bba529a3da45306ff1ec918c14
          SHA1..: ab66c5e34dd5737b0d1919d2ca2f6b76bcb89b56
          SHA256: 4de82762d3e30a29b24c14515a98ddb5506f9854a4663b22c3124cd2af9e645d
          ssdeep: 24576:fGvXPeuF63UitXi6Mer0NT9UdwyQ0gnP:4euFaUitXH0NT9WwyQ

          PEiD..: Armadillo v1.71
          TrID..: File type identification
          Win32 Executable Generic (42.3%)
          Win32 Dynamic Link Library (generic) (37.6%)
          Generic Win/DOS Executable (9.9%)
          DOS Executable Generic (9.9%)
          VXD Driver (0.1%)
          PEInfo: PE Structure information

          ( base data )
          entrypointaddress.: 0x12f2
          timedatestamp.....: 0x4a5733cc (Fri Jul 10 12:27:56 2009)
          machinetype.......: 0x14c (I386)

          ( 7 sections )
          name viradd virsiz rawdsiz ntrpy md5
          .text 0x1000 0x4703c 0x1aa00 8.00 ae9fea690f515e5d3af10bfceacc8b67
          .data 0x49000 0x90e4 0x4200 7.99 a809edcd5985ea7e8b13355df9f94169
          .rdata 0x53000 0x1187e0 0xc8800 8.00 cabeb48e39a8488a2f7bc471ead39968
          .bss 0x16c000 0x6b88 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
          .idata 0x173000 0xff4 0x800 7.34 b40b294bbae9c753d57676554f185d1a
          .rsrc 0x174000 0x6788 0x6800 3.73 bd25e22eefd12afeb45a74926bdec5ac
          .adata 0x17b000 0x1caa0 0x11000 8.00 5cf7cf614febe1cce51b119ecba4fda2

          ( 4 imports )
          > kernel32.dll: GetModuleHandleA, ExitProcess, HeapDestroy, RtlUnwind, CloseHandle
          > user32.dll: wsprintfA, CreateWindowExA, CharLowerBuffA, SetWindowLongA
          > advapi32.dll: RegCreateKeyA, RegOpenKeyA, RegEnumKeyA, RegQueryValueA
          > ole32.dll: CoRegisterClassObject, CoCreateInstanceEx, CoMarshalInterface

          ( 0 exports )

          PDFiD.: -
          RDS...: NSRL Reference Data Set
          -
          Prevx info: <a href='http://info.prevx.com/aboutprogramtext.asp?PX5=A8300E574DC52633F9FE0FCACBF4AB00A228603A' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=A8300E574DC52633F9FE0FCACBF4AB00A228603A</a>

          et pour ce qui de lineage2.com oui je connais c'est un jeux online
          si tu me donne l'adresse complete je pourrais savoir le quel c'est

          et maintenant je fait quoi ?
          0
      2. Contributeur sécurité
        re

        tu connais ces adresses pour ton jeux :

        O1 - Hosts: 94.23.26.222 L2authd.lineage2.com
        O1 - Hosts: 216.107.250.194 nprotect.lineage2.com

        Fait un scan en ligne avec internet explorer ici et poste le rapport en ENTIER avec les lignes
        http://www.bitdefender.fr/scan_fr/scan8/ie.html

        puis

        * Télécharge Malwarebytes
        http://www.commentcamarche.net/telecharger/telecharger 34055379 malwarebytes
        * Fais la mise à jour du logiciel (elle se fait normalement à l'installation)
        * Lance une analyse complète en cliquant sur "Exécuter un examen rapide"
        * Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"
        * Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"
        * Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"
        * Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

        * Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée

        ensuite redemarre ton PC et poste nouveau LOG.txt de RSIT
        0
        1. donc pour les deux adresse oui je les connais ce sont les hosts du serveur sur lequel je joue

          et ensuite probleme pour le scan en ligne ca se bloque sur la mise a jour

          on fait quoi ?
          0
          1. Contributeur sécurité
            salut

            Passe a malwarebyte et oublie pas de supprimer ce qu'il trouve puis après retente le scan en ligne
            0
            1. salut,

              je viens donc de télécharger malwarebyte
              et au moment de l'executer j'ai un petit sablier a coté de ma souris
              il reste quelque seconde voir une minute puis il disparait et puis plus rien
              j'ai tenté plusieurs fois impossible de l'installer

              je sais plus quoi faire la
              0
              1. Contributeur sécurité
                ok, l'infection te bloque l'installation de logiciel de securité

                telecharge combofix sur ton BUREAU et pas ailleurs en CLIC DROIT sur le lien et choisit"enregistré la cible sous"
                CHANGE le nom pour contrer l'infection appel le CF et enregistre sur ton bureau
                http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                Deconnecte toi d'internet et debranche le cable ou la wifi
                DESACTIVE ton antivirus et antispyware et toutes tes defences

                puis lance le et ne touche + a rien meme pas a la souris et poste le rapport à la fin
                0
                1. bonsoir,

                  en effet ca a marché pour combofix
                  voici le fichier log
                  je t'attend pour la suite

                  ComboFix 09-07-14.08 - Alexandre Ribière 16/07/2009 22:01.1.2 - NTFSx86
                  Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.3070.2699 [GMT 2:00]
                  Running from: c:\documents and settings\Alexandre Ribière\Bureau\CF.exe
                  AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
                  FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}

                  WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
                  .

                  ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  c:\windows\system32\drivers\UACclqerpjbaxtptornp.sys
                  c:\windows\system32\net.net
                  c:\windows\system32\UACckldihrlcoxbarmvl.dll
                  c:\windows\system32\UACfdqolwevptdvsdgpu.db
                  c:\windows\system32\uacinit.dll
                  c:\windows\system32\UACiqvnmbfaaugqekeyd.dll
                  c:\windows\system32\UACrwwxiloowyltgkebk.dll
                  c:\windows\system32\UACsdlvptrojunpwirlk.log
                  c:\windows\system32\UACtjesuiumimxfmsrrv.dat
                  c:\windows\system32\UACunsxowmnepqbkethj.dll
                  c:\windows\system32\UACwpuwmtkyxufxuwnsf.dll
                  c:\windows\system32\UACxsmgerpubuvumxxya.dll
                  D:\install.exe

                  .
                  ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                  .

                  -------\Service_UACd.sys

                  ((((((((((((((((((((((((( Files Created from 2009-06-16 to 2009-07-16 )))))))))))))))))))))))))))))))
                  .

                  2009-07-15 20:56 . 2009-07-15 20:56 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache
                  2009-07-15 18:27 . 2009-07-15 18:51 -------- d-----w- c:\windows\BDOSCAN8
                  2009-07-15 16:13 . 2009-07-15 16:13 -------- d-----w- C:\rsit
                  2009-07-15 16:13 . 2009-07-15 16:13 -------- d-----w- c:\program files\trend micro
                  2009-07-15 01:04 . 2009-07-15 01:04 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
                  2009-07-14 23:49 . 2009-06-02 10:12 102912 ------w- c:\windows\system32\dllcache\iecompat.dll
                  2009-07-14 23:49 . 2009-07-14 23:49 -------- d-----w- c:\windows\ie8updates
                  2009-07-14 23:47 . 2009-04-30 21:16 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
                  2009-07-14 23:47 . 2009-04-30 21:16 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
                  2009-07-14 23:45 . 2009-07-14 23:47 -------- dc-h--w- c:\windows\ie8
                  2009-07-14 23:36 . 2009-07-14 23:36 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
                  2009-07-14 23:32 . 2009-07-14 23:32 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\SiteAdvisor
                  2009-07-14 23:29 . 2009-05-13 21:25 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
                  2009-07-14 23:29 . 2009-05-13 21:25 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
                  2009-07-14 23:29 . 2009-05-13 21:25 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
                  2009-07-14 23:29 . 2009-04-09 12:23 120136 ----a-w- c:\windows\system32\drivers\Mpfp.sys
                  2009-07-14 23:29 . 2009-07-14 23:29 -------- d-----w- c:\program files\Fichiers communs\McAfee
                  2009-07-14 23:28 . 2009-07-14 23:29 -------- d-----w- c:\program files\McAfee.com
                  2009-07-14 23:28 . 2009-07-15 01:04 -------- d-----w- c:\program files\McAfee
                  2009-07-14 23:24 . 2009-05-13 21:24 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
                  2009-07-14 22:37 . 2009-07-14 22:37 -------- d-----w- c:\program files\CCleaner
                  2009-06-20 20:02 . 2009-06-20 20:04 -------- d-----w- c:\program files\Mumble

                  .
                  (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  2009-07-14 23:35 . 2008-02-24 12:28 -------- d-----w- c:\docume~1\ALLUSE~1\APPLIC~1\McAfee
                  2009-07-14 21:36 . 2009-07-14 21:36 1046861 ----a-w- c:\windows\system32\rn.tmp
                  2009-06-16 14:40 . 2004-08-20 10:24 119808 ----a-w- c:\windows\system32\t2embed.dll
                  2009-06-16 14:40 . 2004-08-20 10:23 81920 ----a-w- c:\windows\system32\fontsub.dll
                  2009-06-13 13:10 . 2008-11-17 14:32 -------- d-----w- c:\program files\Lineage II
                  2009-06-11 09:17 . 2008-02-24 12:25 -------- d-----w- c:\program files\Microsoft Works
                  2009-06-03 19:10 . 2004-08-20 10:24 1297408 ----a-w- c:\windows\system32\quartz.dll
                  2009-05-29 14:29 . 2009-01-02 00:14 -------- d-----w- c:\program files\Gravity
                  2009-05-29 14:29 . 2008-02-24 12:24 -------- d--h--w- c:\program files\InstallShield Installation Information
                  2009-05-13 21:25 . 2009-05-13 21:25 214024 ----a-w- c:\windows\system32\drivers\mfehidk.sys
                  2009-05-13 05:04 . 2004-08-20 10:24 915456 ----a-w- c:\windows\system32\wininet.dll
                  2009-05-07 15:33 . 2004-08-20 10:23 348672 ----a-w- c:\windows\system32\localspl.dll
                  2009-04-19 19:50 . 2004-08-20 10:24 1847296 ----a-w- c:\windows\system32\win32k.sys
                  .

                  ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                  .
                  .
                  *Note* empty entries & legit default entries are not shown
                  REGEDIT4

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
                  "{2ba521ac-b9b9-4433-ba45-dba2f02cba5a}"= "c:\program files\speed-bit\tbspee.dll" [2007-07-31 1391640]

                  [HKEY_CLASSES_ROOT\clsid\{2ba521ac-b9b9-4433-ba45-dba2f02cba5a}]

                  [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2ba521ac-b9b9-4433-ba45-dba2f02cba5a}]
                  2007-07-31 15:33 1391640 ----a-w- c:\program files\speed-bit\tbspee.dll

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
                  "{2ba521ac-b9b9-4433-ba45-dba2f02cba5a}"= "c:\program files\speed-bit\tbspee.dll" [2007-07-31 1391640]

                  [HKEY_CLASSES_ROOT\clsid\{2ba521ac-b9b9-4433-ba45-dba2f02cba5a}]

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
                  "{2BA521AC-B9B9-4433-BA45-DBA2F02CBA5A}"= "c:\program files\speed-bit\tbspee.dll" [2007-07-31 1391640]

                  [HKEY_CLASSES_ROOT\clsid\{2ba521ac-b9b9-4433-ba45-dba2f02cba5a}]

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
                  "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-02-24 68856]
                  "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-20 136600]
                  "ATICCC"="c:\program files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-09-25 90112]
                  "ISUSPM Startup"="c:\program files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856]
                  "ISUSScheduler"="c:\program files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
                  "RoxWatchTray"="c:\program files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2006-11-05 221184]
                  "RoxioDragToDisc"="c:\program files\Roxio\Drag-to-Disc\DrgToDsc.exe" [2006-08-17 1116920]
                  "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2006-10-20 118784]
                  "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-02-24 1838592]
                  "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2007-05-24 17920]
                  "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384]
                  "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-07-16 142104]
                  "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-07-16 162584]
                  "Persistence"="c:\windows\system32\igfxpers.exe" [2007-07-16 138008]
                  "WinampAgent"="c:\program files\Winamp\Winampa.exe" [2003-04-02 12288]
                  "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-12-22 241664]
                  "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
                  "HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2004-02-18 49152]
                  "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 5.0\apdproxy.exe" [2006-09-14 61440]
                  "LogitechCommunicationsManager"="c:\program files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe" [2007-10-25 563984]
                  "LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2007-10-25 2178832]
                  "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
                  "EEventManager"="c:\program files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2006-10-12 102400]
                  "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-05-01 645328]
                  "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2007-07-16 16132608]
                  "PMX Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2006-11-08 49152]

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                  c:\docume~1\ALLUSE~1\MENUD~1\PROGRA~1\DMARR~1\
                  Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
                  @=""

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
                  @=""

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
                  "DisableMonitoring"=dword:00000001

                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
                  "DisableMonitoring"=dword:00000001

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                  "EnableFirewall"= 0 (0x0)

                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                  "%windir%\\system32\\sessmgr.exe"=
                  "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
                  "c:\\Program Files\\Messenger\\msmsgs.exe"=
                  "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                  "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                  "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
                  "c:\\Program Files\\Fichiers communs\\McAfee\\MNA\\McNASvc.exe"=

                  R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [15/07/2009 01:32 206112]
                  R2 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [08/08/2008 19:01 1373480]
                  R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [24/02/2008 14:03 84992]
                  R3 pmxmouse;PMXMOUSE;c:\windows\system32\drivers\pmxmouse.sys [27/02/2008 10:42 18432]
                  R3 pmxusblf;PMXUSBLF;c:\windows\system32\drivers\pmxusblf.sys [27/02/2008 10:42 14336]

                  [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
                  "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
                  .
                  - - - - ORPHANS REMOVED - - - -

                  HKLM-Run-net - c:\windows\system32\net.net

                  .
                  ------- Supplementary Scan -------
                  .
                  uStart Page = hxxp://www.google.fr/
                  IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
                  IE: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                  DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - hxxp://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                  .

                  **************************************************************************

                  catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                  Rootkit scan 2009-07-16 22:11
                  Windows 5.1.2600 Service Pack 3 NTFS

                  scanning hidden processes ...

                  scanning hidden autostart entries ...

                  scanning hidden files ...

                  scan completed successfully
                  hidden files: 0

                  **************************************************************************
                  .
                  --------------------- DLLs Loaded Under Running Processes ---------------------

                  - - - - - - - > 'explorer.exe'(7400)
                  c:\program files\Fichiers communs\Logishrd\LVMVFM\LVPrcInj.dll
                  c:\program files\McAfee\SiteAdvisor\saHook.dll
                  c:\windows\system32\webcheck.dll
                  c:\windows\system32\eappprxy.dll
                  c:\windows\system32\pmxscrll.dll
                  c:\windows\system32\PMXCOMM.dll
                  c:\windows\system32\PMXHOOKS.dll
                  .
                  ------------------------ Other Running Processes ------------------------
                  .
                  c:\windows\system32\ati2evxx.exe
                  c:\program files\Fichiers communs\logishrd\LVMVFM\LVPrcSrv.exe
                  c:\program files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
                  c:\program files\Java\jre6\bin\jqs.exe
                  c:\program files\Fichiers communs\logishrd\LVCOMSER\LVComSer.exe
                  c:\windows\system32\wdfmgr.exe
                  c:\windows\system32\WTablet\Pen_TabletUser.exe
                  c:\program files\ATI Technologies\ATI.ACE\CLI.exe
                  c:\windows\system32\pmxmiced.exe
                  c:\program files\Fichiers communs\logishrd\LQCVFX\COCIManager.exe
                  c:\program files\ATI Technologies\ATI.ACE\CLI.exe
                  c:\windows\system32\wbem\wmiapsrv.exe
                  c:\windows\system32\wscntfy.exe
                  c:\program files\Fichiers communs\logishrd\LVCOMSER\LVComSer.exe
                  c:\program files\Fichiers communs\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                  .
                  **************************************************************************
                  .
                  Completion time: 2009-07-16 22:15 - machine was rebooted
                  ComboFix-quarantined-files.txt 2009-07-16 20:15

                  Pre-Run: 216 732 819 456 octets libres
                  Post-Run: 216 946 573 312 octets libres

                  198 --- E O F --- 2009-07-15 17:44
                  0
                  1. Contributeur sécurité
                    bonjour,

                    arrive tu a faire le poste 5 maintenant

                    c'est le scan en ligne + malwarebyte et poste les rapports en entier en supprimant tout ce qui est trouvés
                    0
                    1. bonjour,

                      donc voila le rapport du scan en ligne de bit defender

                      BitDefender Online Scanner - Rapport virus en temps réel

                      Généré à: Fri, Jul 17, 2009 - 10:30:41

                      --------------------------------------------------------------------------------

                      Info d'analyse

                      Fichiers scannés
                      15504

                      Infectés Fichiers
                      0

                      Virus Détectés

                      Aucun virus trouvé.

                      --------------------------------------------------------------------------------

                      Ce sommaire du processus d'analyse sera utilisé par les laboratoires Antivirus BitDefender pour créer des statistiques agréguées sur l'activité des virus dans le monde.
                      0
                      1. ensuite voici celui de malware

                        Malwarebytes' Anti-Malware 1.39
                        Version de la base de données: 2447
                        Windows 5.1.2600 Service Pack 3

                        17/07/2009 10:44:41
                        mbam-log-2009-07-17 (10-44-40).txt

                        Type de recherche: Examen rapide
                        Eléments examinés: 92997
                        Temps écoulé: 7 minute(s), 21 second(s)

                        Processus mémoire infecté(s): 0
                        Module(s) mémoire infecté(s): 0
                        Clé(s) du Registre infectée(s): 0
                        Valeur(s) du Registre infectée(s): 0
                        Elément(s) de données du Registre infecté(s): 0
                        Dossier(s) infecté(s): 0
                        Fichier(s) infecté(s): 1

                        Processus mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Module(s) mémoire infecté(s):
                        (Aucun élément nuisible détecté)

                        Clé(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Valeur(s) du Registre infectée(s):
                        (Aucun élément nuisible détecté)

                        Elément(s) de données du Registre infecté(s):
                        (Aucun élément nuisible détecté)

                        Dossier(s) infecté(s):
                        (Aucun élément nuisible détecté)

                        Fichier(s) infecté(s):
                        c:\WINDOWS\system32\rn.tmp (Trojan.Downloader) -> Quarantined
                        0
                        1. et pour finir le log de RSIT

                          je t'attends pour la suite des evenements

                          Logfile of random's system information tool 1.06 (written by random/random)
                          Run by Alexandre Ribière at 2009-07-17 10:49:20
                          Microsoft Windows XP Édition familiale Service Pack 3
                          System drive C: has 207 GB (69%) free of 302 GB
                          Total RAM: 3070 MB (81% free)

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 10:49:34, on 17/07/2009
                          Platform: Windows XP SP3 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\Ati2evxx.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\Program Files\Java\jre6\bin\jusched.exe
                          C:\WINDOWS\RTHDCPL.EXE
                          C:\WINDOWS\system32\ICO.EXE
                          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                          C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                          C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
                          C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
                          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                          C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
                          C:\WINDOWS\system32\Pmxmiced.exe
                          C:\Program Files\Winamp\Winampa.exe
                          C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                          C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
                          C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                          C:\Program Files\Logitech\QuickCam\Quickcam.exe
                          C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
                          C:\Program Files\McAfee.com\Agent\mcagent.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\Messenger\msmsgs.exe
                          C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
                          C:\Program Files\Java\jre6\bin\jqs.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                          C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
                          C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                          c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
                          c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
                          C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                          C:\Program Files\McAfee\MPF\MPFSrv.exe
                          C:\Program Files\McAfee\MSK\MskSrver.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\system32\Pen_Tablet.exe
                          C:\WINDOWS\system32\WTablet\Pen_TabletUser.exe
                          C:\WINDOWS\system32\Pen_Tablet.exe
                          C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                          C:\WINDOWS\system32\wbem\wmiapsrv.exe
                          C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                          C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\Documents and Settings\Alexandre Ribière\Bureau\RSIT.exe
                          C:\Program Files\trend micro\Alexandre Ribière.exe
                          C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=4080224
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
                          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                          O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                          O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\mskapbho.dll
                          O2 - BHO: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
                          O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                          O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
                          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.15642\swg.dll
                          O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
                          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                          O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
                          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                          O2 - BHO: JQSIEStartDetectorImpl Class - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                          O3 - Toolbar: speed-bit Toolbar - {2ba521ac-b9b9-4433-ba45-dba2f02cba5a} - C:\Program Files\speed-bit\tbspee.dll
                          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                          O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                          O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                          O4 - HKLM\..\Run: [PMX Daemon] ICO.EXE
                          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
                          O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
                          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                          O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                          O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
                          O4 - HKLM\..\Run: [PDVDDXSrv] "C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
                          O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                          O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe
                          O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                          O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                          O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                          O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                          O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
                          O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                          O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
                          O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
                          O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
                          O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                          O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [EEventManager] C:\Program Files\EPSON\Creativity Suite\Event Manager\EEventManager.exe
                          O4 - HKLM\..\Run: [mcagent_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                          O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                          O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
                          O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
                          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                          O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                          O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                          O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                          O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                          O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                          O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
                          O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
                          O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mna\mcnasvc.exe
                          O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
                          O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
                          O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
                          O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
                          O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
                          O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
                          O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                          O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Fichiers communs\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                          O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Fichiers communs\SureThing Shared\stllssvr.exe
                          O23 - Service: TabletServicePen - Wacom Technology, Corp. - C:\WINDOWS\system32\Pen_Tablet.exe
                          0
                          1. Contributeur sécurité
                            salut

                            lance ce fichier C:\Program Files\trend micro\Alexandre Ribière.exe

                            choisit do a scan only et coche les cases a gauche des lignes :

                            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                            O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                            O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
                            O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                            O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                            O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

                            puis clic sur fix checked

                            ensuite si tu as + de probleme fait la suite :

                            Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

                            * Télécharge Toolscleaner sur ton Bureau

                            http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
                            * Double-clique sur ToolsCleaner2.exe et laisse le travailler
                            * Clique sur Recherche et laisse le scan se terminer.
                            * Clique sur Suppression pour finaliser.
                            * Tu peux, si tu le souhaites, te servir des Options facultatives.
                            * Clique sur Quitter, pour que le rapport puisse se créer.
                            * Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta prochaine réponse

                            puis

                            on peut aussi verfier la vulnerabilité de windows et aussi d'autre produits

                            -
                            Soit par le biais de ce site internet il faut installer l'active X puis
                            clic start scan et le site montre d'une croix rouge les faille de
                            sécurité pour quelques produits important installé sur le PC comme
                            java, IE, windows, flashplayer, adobe...les + importantes
                            https://www.flexera.com/products/operations/software-vulnerability-management.html

                            -
                            Soit on peut aussi passer par un logiciel a installer qui scan le PC et
                            affiche TOUTES les mises a jour des logiciels et produits installé sur
                            le PC
                            https://filehippo.com/windows/tuning-utilities/

                            si tu ne l'as pas utilise CCleaner comme expliquer ici :
                            https://www.malekal.com/tutoriel-ccleaner/ mais quand tu l'installe DECOCHE la toolbar

                            et ensuite va dans : option/avancé et decoche la premiere ligne puis nettoie ton registre et tes fichiers temporaire plusieurs fois jusqu'a trouver 0erreur

                            puis purge ta restauration avec sa http://www.commentcamarche.net/faq/sujet 5097 virus system volume information
                            puis creer un point de restauration sain avec sa http://www.commentcamarche.net/faq/sujet 740 windows points de restauration

                            et enfin met ton sujet en résolu ;)

                            P.S : meme si tu paye Mcaffe il est trés loin d'etre un bon antivirus, je te conseillerai beaucoup plus en GRATUIT antivir ou AVG
                            0
                            1. bonsoir
                              voici donc le rapport que tu m'as dit de posté

                              ensuite un énorme merci pour ton aide
                              et pour conclure je ne pense pas qu'il soit tres utile pour le moment d'aller plus avant dans la protection du pc de mon homme ( qui te remerci également )

                              par contre si tu peux me renseigner sur un moyen de faire une image de son pc pour a l'avenir regler ce genre de souci je suis preneur

                              [ Rapport ToolsCleaner version 2.3.7 (par A.Rothstein & dj QUIOU) ]

                              --> Recherche:

                              C:\Combofix.txt: trouvé !
                              C:\Qoobox: trouvé !
                              C:\Rsit: trouvé !
                              C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe: trouvé !
                              C:\Documents and Settings\Alexandre Ribière\Bureau\Rsit.exe: trouvé !
                              C:\Program Files\trend micro\HijackThis.exe: trouvé !
                              C:\Program Files\trend micro\hijackthis.log: trouvé !

                              ---------------------------------
                              --> Suppression:

                              C:\Documents and Settings\Administrateur\Bureau\ComboFix.exe: supprimé !
                              C:\Program Files\trend micro\HijackThis.exe: supprimé !
                              C:\Combofix.txt: supprimé !
                              C:\Documents and Settings\Alexandre Ribière\Bureau\Rsit.exe: supprimé !
                              C:\Program Files\trend micro\hijackthis.log: supprimé !
                              C:\Qoobox: supprimé !
                              C:\Rsit: supprimé !

                              encore merci à toi
                              0
                              1. Contributeur sécurité
                                re

                                de rien ;)

                                tu as dit "pour conclure je ne pense pas qu'il soit tres utile pour le moment d'aller plus avant dans la protection du pc de mon homme"
                                tu parle de ce qui suit après toolcleaner si c'est le cas :

                                fait les mise a jour avec les 2 outils que je t'ai prioposé après toolcleaner ce n'est pas des logiciel de securité c'est pour maintenir ton systeme a jour et eviter les faille de securité qui t'infecte

                                CCleaner c'est obligatoire de l'avoir c'est un "reparateur" de registre qui allege le PC pour un fonctionnement plus rapide, passe le plusieurs fois jusqu' a trouver 0erreur ton PC te remerciera

                                ensuite pour faire une image comme tu dit :

                                c'est marqué a la fin avec les liens d'aide, c'est a dire que tu dois purger ta restauration pour effacer les point de sauvegarde de restaurations syetme qui sont eventuellement infecté puis tu en crée un autre nouveau avec le niom que tu souhaite et ta configuration actuel

                                Fait tout ce que jté mit c'est trés important au passage garde bien malwarebyte et CCleaner qui sont trés utile

                                sinon jté pas demandé mais a stu encore des problemes ?
                                0