Comment désenregister un malware?

Bonjour, j'ai un grave problème avec Ibiss( wtoolsb) J'ai beau l'aenrayer avec des antispys en mode sans échec et en désactivant ma restauration du système, rien ne fonctionne. Je refais un autre scan 10 secondes après et le m^me problème est réapparu. J'ai lu sur un site anglais qu'il faut que désenregistre le produit en allant dans exécuter et puis taper cmd. Mais le reste, je ne comprends pas quoi faire par la suite, je ne sais pas exactement quoi taper pour avoir accès aux programmes que je désire désenregistrer.

Merci à l'avance.

12 réponses

  1. salut jp040780

    telecharge hijackthis:
    http://www.merijn.org/files/hijackthis.zip
    Dezippe le dans un dossier prévu a cet effet.
    Par exemple C:\hijackthis
    lance le puis:
    clic sur "do a system scan and save logfile"
    fais un copier coller du log entier sur le forum.

    a+
    0
    1. Logfile of HijackThis v1.99.0
      Scan saved at 16:46:02, on 02/04/2005
      Platform: Windows XP (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 (6.00.2600.0000)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\SYSTEM32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\HP\HP Software Update\HPWuSchd.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-ca\msnappau.exe
      C:\WINDOWS\System32\rundll32.exe
      C:\WINDOWS\System32\rundll32.exe
      C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
      C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
      C:\WINDOWS\System32\looe.exe
      C:\WINDOWS\System32\l?ass.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\WINDOWS\System32\drivers\CDAC11BA.EXE
      C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
      C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
      C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\WINDOWS\System32\devldr32.exe
      C:\WINDOWS\System32\wuauclt.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Real\RealPlayer\RealPlay.exe
      C:\Documents and Settings\Jean Pascal\Bureau\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll (file missing)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: AddressBar Class - {1474CE44-8057-4AE3-8F3E-ED37C7C63D8A} - C:\WINDOWS\system32\iasad.dll
      O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
      O2 - BHO: (no name) - {B515FA5C-1DCF-654B-99DF-4181E9B65FE3} - C:\WINDOWS\System32\lphepenu.dll
      O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll
      O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
      O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
      O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
      O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-ca\msnappau.exe"
      O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
      O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
      O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
      O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
      O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
      O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\FICHIE~1\WinTools\WToolsA.exe
      O4 - HKCU\..\Run: [Pcam] C:\WINDOWS\System32\looe.exe
      O4 - HKCU\..\Run: [Nikxn] C:\WINDOWS\System32\l?ass.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
      O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
      O15 - Trusted IP range: (HKLM)
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cab
      O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/05ad58539e7aa1271417/netzip/RdxIE601.cab
      O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
      O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
      O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{13F5B916-8623-4B12-92C1-26757A9F186F}: NameServer = 206.47.244.79 206.47.244.101
      O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
      O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:\WINDOWS\System32\dmadmin.exe
      O23 - Service: Journal des événements - Unknown - C:\WINDOWS\system32\services.exe
      O23 - Service: Service COM de gravage de CD IMAPI - Unknown - C:\WINDOWS\System32\imapi.exe
      O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
      O23 - Service: DDE réseau - Unknown - C:\WINDOWS\system32\netdde.exe
      O23 - Service: DSDM DDE réseau - Unknown - C:\WINDOWS\system32\netdde.exe
      O23 - Service: Panda Firewall Service - Unknown - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
      O23 - Service: Panda anti-virus service - Unknown - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
      O23 - Service: Plug-and-Play - Unknown - C:\WINDOWS\system32\services.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
      O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance - Unknown - C:\WINDOWS\system32\sessmgr.exe
      O23 - Service: RIO Mass Storage C - Digital Networks North America, Inc. - C:\WINDOWS\System32\RioMSC.exe
      O23 - Service: Prise en charge des cartes à puces - Unknown - C:\WINDOWS\System32\SCardSvr.exe
      O23 - Service: Carte à puce - Unknown - C:\WINDOWS\System32\SCardSvr.exe
      O23 - Service: Journaux et alertes de performance - Unknown - C:\WINDOWS\system32\smlogsvc.exe
      O23 - Service: Cliché instantané de volume - Unknown - C:\WINDOWS\System32\vssvc.exe
      O23 - Service: Carte de performance WMI - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe
      0
      1. Contributeur sécurité
        salut
        imprime ceci pour ne rien oublier et tous faire
        tous faire dans l ordre imperativement
        -------------------------
        tous da bord telecharge ces programmes si tu ne les a pas et met les a jour mais ne les utilise pas encore
        adaware (1)
        spyboot (2)
        (ici) http://pageperso.aol.fr/balltrap34/page%20virus.htm

        et aussi celui ci
        Télécharger cet uninstaller:
        http://www.purityscan.com/uninstall.html
        execute le et redemarre
        ----------------

        demarre en mode sans echec
        mode sans echec pour cela tu tapote la touche f8
        des le debut de l allumage du pc sans t arreter
        une fenetre vas souvrir tute deplace avec les fleches du clavier sur demarreren mode sans echec
        une fois sur le bureau il ni auras pas toutes les couleurs et autres c est normal.si f8 ne marche pas utilise la touche f5
        -------------------------
        desactive ta restauration systeme
        pour ça tu fais clic droit sur poste de travail
        propriété tu clique sur onglet restauration système
        tu coche la case désactiver la restauration et applique
        ------------

        assure toi de ceci
        Affiche tous les fichiers et dossiers :
        cliquer sur démarrer/panneau de configuration/option des dossiers/affichage
        Cocher afficher les dossiers cacher

        Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

        Décocher masquer les extensions dont le type est connu
        Puis fais «Ok» pour valider les changements.

        Et appliquer
        ----------------------
        vide tes fichiers temps et tempory internet file sur tous les utilisateur
        utilise ceci pour le faire
        http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

        --------------------
        relance hijack coche ces lignes et ensuite clik sur fix
        R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll (file missing)
        O2 - BHO: AddressBar Class - {1474CE44-8057-4AE3-8F3E-ED37C7C63D8A} - C:\WINDOWS\system32\iasad.dll
        O2 - BHO: (no name) - {B515FA5C-1DCF-654B-99DF-4181E9B65FE3} - C:\WINDOWS\System32\lphepenu.dll
        O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
        O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
        O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\FICHIE~1\WinTools\WToolsA.exe
        O4 - HKCU\..\Run: [Pcam] C:\WINDOWS\System32\looe.exe
        O4 - HKCU\..\Run: [Nikxn] C:\WINDOWS\System32\l?ass.exe
        O15 - Trusted IP range: (HKLM)
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cab
        O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/05ad58539e7aa1271417/netzip/RdxIE601.cab
        O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
        O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
        O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab

        ----------------------
        recherche et suppr ceci
        attention seulement les fichiers
        C:\PROGRA~1\Toolbar\toolbar.dll
        C:\WINDOWS\system32\iasad.dll
        C:\WINDOWS\System32\lphepenu.dll
        C:\PROGRA~1\FICHIE~1\WinTools\WToolsA.exe
        C:\WINDOWS\System32\looe.exe
        C:\WINDOWS\System32\l?ass.exe

        ---------------
        passe adaware et vire tous se qu il trouve
        ----------
        passe spy boot et vire tous se qu il trouvent
        -------------
        tu vide ta poubelle et tu redemarre en mode normal et refait un hijack

        --
        0
        1. Merci beaucoup pour tes conseils, je vais essayer!
          0
          1. Salut

            Télécharge ces 2 antispywares (gratuits)

            - Spybot S&D:
            http://telechargement.zebulon.fr/79-Spybot---Search-&-Destroy.html
            l'aide:
            http://www.zebulon.fr/articles/spybot_1.php
            http://assiste.free.fr/p/internet_utilitaires/spybot_search_destroy.php#ssd_02

            - Ad-aware:
            http://www.lavasoftusa.com/french/support/download/
            l'aide:
            http://www.ordi-netfr.org/tutorialadaware.php

            Bien lire l'aide, et mettre à jours avant de les utiliser.

            -> Rend visible les fichiers cachés et systeme
            panneau de configuration > options des dossiers > onglet affichage
            cocher " afficher les fichiers et dossiers cachés "
            décocher " masquer les extentions des fichiers dont le type est connu
            décocher " masquer les fichiers protégés du système"

            -> désactive la restauration systéme
            Clic droit sur poste de travail > propriétés > onglet restauration système
            puis cocher "désactiver la restauration système".

            Puis:
            - Redémarre en mode sans échec en appuyant sur la touche F8 au démarrage de ton PC (apres l'ecran du bios)

            ---------------------------------------------

            Vérifie si ce ou ces procéssus apparaissent dans le gestionnaire des taches.(CTRL+ALT+SUPPR)
            S'ils sont présent: clic droit dessus puis clic sur "terminer le processus"

            l?ass.exe <= attention ne confond pas avec lsass.exe qui lui est ok
            looe.exe

            Lance hijackthis et Fixe:
            (cocher au début de chaques lignes valider avec fix checked)

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll (file missing)
            O2 - BHO: AddressBar Class - {1474CE44-8057-4AE3-8F3E-ED37C7C63D8A} - C:\WINDOWS\system32\iasad.dll
            O2 - BHO: (no name) - {B515FA5C-1DCF-654B-99DF-4181E9B65FE3} - C:\WINDOWS\System32\lphepenu.dll
            O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
            O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
            O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\FICHIE~1\WinTools\WToolsA.exe
            O4 - HKCU\..\Run: [Pcam] C:\WINDOWS\System32\looe.exe
            O4 - HKCU\..\Run: [Nikxn] C:\WINDOWS\System32\l?ass.exe
            O15 - Trusted IP range: (HKLM)
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by23fd.bay23.hotmail.msn.com/resources/MsnPUpld.cab
            O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/05ad58539e7aa1271417/netzip/RdxIE601.cab
            O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
            O16 - DPF: {CE69F98F-2AF3-4306-BAC6-A79070EDA1B4} (Zylom Loader Object) - http://eu.download.games.yahoo.com/zylom/activex/zylomloader.cab
            O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab

            Rechercher et supprimer si présent:

            C:\WINDOWS\system32\iasad.dll
            C:\WINDOWS\System32\lphepenu.dll
            C:\WINDOWS\System32\looe.exe
            C:\WINDOWS\System32\l?ass.exe
            C:\WINDOWS\System32\E6F1873B.DLL
            C:\WINDOWS\System32\D3D869D4.dll
            C:\PROGRAM FILES\FICHIER COMMUNS\WinTools <= tout le dossier
            C:\PROGRAM FILES\Toolbar <= tout le dossier

            Ensuite:

            Fais un nettoyage des fichiers temps...etc avec ce programme:
            http://pageperso.aol.fr/Balltrap34/CleanUp312.exe

            ou manuellement:

            Supprimer tout les fichiers à l'intérieur des dossiers suivants:

            * C:\Temp
            * C:\Windows (ou WinNT)\Temp
            * C:\WINDOWS\Prefetch <= sauf le fichier layout.ini
            * C:\Documents and Settings\tous les utilisateurs\Local Settings\Temp
            * C:\Documents and Settings\tous les utilisateurs \Cookies
            * Vider la corbeille !

            Nettoyage du disque:
            Démarrer > Tous les programmes > accessoires > outils système > nettoyage du disque
            cocher:
            - fichiers et programmes téléchargés
            - fichiers internet temporaires
            - corbeille
            - fichier temporaires
            valider ok

            -----------------------------

            Profite d'être en mode sans echecs pour lancer le scan de ad-aware, spybot... et supprime tout ce qu'ils trouvent.

            ensuite fais un scan AV ici:
            http://www.ravantivirus.com/scan/
            Clic sur "To continue without subscribing click here" et attends quelques minutes.
            Lorsque "Ready" est affiché dans "status", coche la case "Autoclean" puis clic sur "Scan my PC".
            A la fin de l'analyse, copier/coller le rapport ici + un nouveau log hijackthis

            Ne pas oublier après les manips de recocher " masquer les fichiers protégés du système" dans les options des dossiers
            0
            1. Contributeur sécurité
              grilled moe
              0
              1. bahh... c'est normal, le balltrap ca affute les reflexes lol

                a+
                0
                1. Contributeur sécurité
                  lol pas vrai cette annee j ai pas tirer (depuis debut 2004)
                  0
                  1. voici l'analyse de rav antivirus

                    Scan started at 03/04/2005 03:19:02

                    Scanning memory...
                    Scanning boot sectors...
                    Scanning files...
                    C:\WINDOWS\ntwb32.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\addtt32.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\atlfe32.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\sysdd.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\javabr32.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\ntxj.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\appfc.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\sdkvt.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\addsa.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\apiuc.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\sdkeh.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\javazt32.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\mfcfs32.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\sysjo.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\netwu.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\winbh32.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\sdkrl32.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\d3wu32.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\apppt.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\mfctq.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\iepc.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\TFTP1376 - Worm:Win32/Dabber.C.dam#2 -> Infected
                    C:\WINDOWS\system32\ipex32.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\ntdu.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\iptl.exe - TrojanDownloader:Win32/Agent.EZ -> Infected
                    C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\CTEFGPIV\0006_regular[1].cab->istactivex.dll - TrojanDownloader:Win32/Istbar.GH.dll -> Infected
                    C:\Program Files\Internet Explorer\xgcqxwyy.exe - TrojanDownloader:Win32/WinShow.AL -> Infected

                    VOici avec hijack

                    Logfile of HijackThis v1.99.0
                    Scan saved at 13:12:55, on 03/04/2005
                    Platform: Windows XP (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 (6.00.2600.0000)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\SYSTEM32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\HP\HP Software Update\HPWuSchd.exe
                    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
                    C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-ca\msnappau.exe
                    C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE
                    C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                    C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
                    C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Panda Software\Panda Antivirus Platinum\AVENGINE.EXE
                    C:\Program Files\Panda Software\Panda Antivirus Platinum\pavProxy.exe
                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                    C:\WINDOWS\System32\wuauclt.exe
                    C:\WINDOWS\System32\devldr32.exe
                    C:\Program Files\Cakewalk\SONAR 3 Producer Edition\SONARPDR.EXE
                    C:\Documents and Settings\Jean Pascal\Bureau\HijackThis.exe

                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll (file missing)
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
                    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.4000.1001\en-ca\msntb.dll (file missing)
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                    O4 - HKLM\..\Run: [Look 'n' Stop] "C:\Program Files\Soft4Ever\looknstop\looknstop.exe" -auto
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
                    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
                    O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-ca\msnappau.exe"
                    O4 - HKLM\..\Run: [SCANINICIO] "C:\Program Files\Panda Software\Panda Antivirus Platinum\Inicio.exe"
                    O4 - HKLM\..\Run: [APVXDWIN] "C:\Program Files\Panda Software\Panda Antivirus Platinum\APVXDWIN.EXE" /s
                    O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                    O15 - Trusted IP range: (HKLM)
                    O16 - DPF: {A3009861-330C-4E10-822B-39D16EC8829D} (CRAVOnline Object) - http://www.ravantivirus.com/scan/ravonline.cab
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{13F5B916-8623-4B12-92C1-26757A9F186F}: NameServer = 206.47.244.79 206.47.244.101
                    O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll
                    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
                    O23 - Service: Service d'administration du Gestionnaire de disque logique - Unknown - C:\WINDOWS\System32\dmadmin.exe
                    O23 - Service: Journal des événements - Unknown - C:\WINDOWS\system32\services.exe
                    O23 - Service: Service COM de gravage de CD IMAPI - Unknown - C:\WINDOWS\System32\imapi.exe
                    O23 - Service: Partage de Bureau à distance NetMeeting - Unknown - C:\WINDOWS\System32\mnmsrvc.exe
                    O23 - Service: DDE réseau - Unknown - C:\WINDOWS\system32\netdde.exe
                    O23 - Service: DSDM DDE réseau - Unknown - C:\WINDOWS\system32\netdde.exe
                    O23 - Service: Panda Firewall Service - Unknown - C:\Program Files\Panda Software\Panda Antivirus Platinum\Firewall\PavFires.exe
                    O23 - Service: Panda anti-virus service - Unknown - C:\Program Files\Panda Software\Panda Antivirus Platinum\pavsrv51.exe
                    O23 - Service: Plug-and-Play - Unknown - C:\WINDOWS\system32\services.exe
                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                    O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance - Unknown - C:\WINDOWS\system32\sessmgr.exe
                    O23 - Service: RIO Mass Storage C - Digital Networks North America, Inc. - C:\WINDOWS\System32\RioMSC.exe
                    O23 - Service: Prise en charge des cartes à puces - Unknown - C:\WINDOWS\System32\SCardSvr.exe
                    O23 - Service: Carte à puce - Unknown - C:\WINDOWS\System32\SCardSvr.exe
                    O23 - Service: Journaux et alertes de performance - Unknown - C:\WINDOWS\system32\smlogsvc.exe
                    O23 - Service: Cliché instantané de volume - Unknown - C:\WINDOWS\System32\vssvc.exe
                    O23 - Service: Carte de performance WMI - Unknown - C:\WINDOWS\System32\wbem\wmiapsrv.exe

                    0
                    1. Contributeur sécurité
                      redemarre en mode sans echec recherche et suppr les fichiers

                      C:\WINDOWS\ntwb32.exe
                      C:\WINDOWS\atlfe32.exe
                      C:\WINDOWS\sysdd.exe
                      C:\WINDOWS\javabr32.exe
                      C:\WINDOWS\ntxj.exe
                      C:\WINDOWS\appfc.exe
                      C:\WINDOWS\sdkvt.exe
                      C:\WINDOWS\addsa.exe
                      C:\WINDOWS\apiuc.exe
                      C:\WINDOWS\javazt32.exe
                      C:\WINDOWS\system32\mfcfs32.exe
                      C:\WINDOWS\system32\sysjo.exe
                      C:\WINDOWS\system32\netwu.exe
                      C:\WINDOWS\system32\winbh32.exe
                      C:\WINDOWS\system32\sdkrl32.exe
                      C:\WINDOWS\system32\d3wu32.exe
                      C:\WINDOWS\system32\apppt.exe - TrojanDownloader:Win32/Agent.EZ
                      C:\WINDOWS\system32\mfctq.exe
                      C:\WINDOWS\system32\iepc.exe
                      C:\WINDOWS\system32\TFTP1376
                      C:\WINDOWS\system32\ipex32.exe
                      C:\WINDOWS\system32\ntdu.exe
                      C:\WINDOWS\system32\iptl.exe
                      C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\CTEFGPIV\0006_regular[1].cab->istactivex.dll
                      C:\Program Files\Internet Explorer\xgcqxwyy.exe

                      la redemarre et refait un scan rav
                      0
                      1. salut balltrap, jp040780

                        et apres desinfection, un p'tit tour ici s'impose:
                        http://v5.windowsupdate.microsoft.com
                        sinon ca risque de pas servir à grand chose...

                        Platform: Windows XP (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 (6.00.2600.0000)

                        a+
                        0
                        1. Contributeur sécurité
                          bien vu moe c est vrai
                          0