C:\windows\system32\rutasaka.dll

Bonjour,

Lorsque j'allume mon pc, j'ai 3 messages d'erreurs differents dans 3 fenetres qui s'ouvre me disant qu'il y a une erreur de chargement de :

- c:\windows\system32\rutasaka.dll
- c:\windows\system32\yatodimi.dll
- c:\windows\system32\jijejeju.dll

Je n'y connais rien, est-ce grave?

Merci d'avance
Configuration: Windows XP
Firefox 3.0.11

31 réponses

Résumé de la discussion

Au démarrage, trois messages d’erreur indiquent des échecs de chargement de DLL dans C:\Windows\System32 (rutasaka.dll, yatodimi.dll, jijejeju.dll), suggérant une infection potentielle sur Windows XP inquié­tante. La meilleure réponse préconise d’utiliser l’outil Random’s System Information Tool (RSIT) et HijackThis pour diagnostiquer l’infection et obtenir des rapports log et info à partager pour nettoyage. D’autres réponses recommandent MBAM en quarantaine, puis un nouveau RSIT et l’utilisation d’OTM pour supprimer des fichiers suspects et réinitialiser le système afin de sécuriser le poste. Les rapports montrent des éléments d’injection et des entrées suspectes dans le registre et les liaisons de démarrage, ce qui renforce la nécessité d’un nettoyage approfondi.

Bobot (l’IA à votre service)
  1. Modérateur
    Bonjour,

    C'est une infection Vundo.

    --> Télécharge Random's System Information Tool (RSIT) (par random/random) sur ton Bureau.

    --> Double-clique sur RSIT.exe afin de lancer le programme.
    (Sous Vista, il faut cliquer droit sur RSIT.exe et choisir Exécuter en tant qu'administrateur)

    --> Clique sur Continue à l'écran Disclaimer.

    --> Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

    --> Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront. Poste le contenu de log.txt (c'est celui qui apparaît à l'écran) ainsi que de info.txt (que tu verras dans la barre des tâches).

    Note : les rapports sont sauvegardés dans le dossier C:\rsit.
    1
    1. Cela peut il etre en rapport aec un probleme de connexion internet? Parce que, impossible de me connecter sur la freebox?
      0
      1. Modérateur
        Oui, c'est possible.
        0
        1. C'est justement le problème alors, je ne peux pas faire ces demarches car je n'arrie pas a me connecter sur internet.

          J'ai un probleme de IP : 0.0.0.0
          0
          1. Modérateur
            Tu utilises un autre PC donc ?

            Le PC infecté est connecté en wifi ou par câble ?
            0
            1. j'ai reussi a me connecter, pour combien de temps je sais pas. voici les rapports :

              log :

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by alex at 2009-08-30 21:54:04
              Microsoft Windows XP Professionnel Service Pack 2
              System drive C: has 42 GB (84%) free of 50 GB
              Total RAM: 1023 MB (50% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:54:16, on 30/08/2009
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\Ati2evxx.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\Program Files\Alwil Software\Avast4\ashDisp.exe
              C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
              C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
              C:\WINDOWS\RTHDCPL.EXE
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\WINDOWS\system32\rundll32.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\WINDOWS\lclock.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Hercules\WiFi Station pour Livebox\WifiStationLB.exe
              C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Documents and Settings\alex\Bureau\RSIT.exe
              C:\Program Files\trend micro\alex.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://melanthios-ana.com/zcvisitor/1624d318-3614-11eb-87b9-12a1ab6c324d/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=47f83760-f118-11ea-9bc8-0ac2bbf4ada7
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
              R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://melanthios-ana.com/zcvisitor/1624d318-3614-11eb-87b9-12a1ab6c324d/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=47f83760-f118-11ea-9bc8-0ac2bbf4ada7
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: (no name) - {7126baa2-3157-42b4-8fa4-e1903ea009d6} - C:\WINDOWS\system32\yederoda.dll (file missing)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
              O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [CPM5378aaef] Rundll32.exe "c:\windows\system32\rutasaka.dll",a
              O4 - HKLM\..\Run: [504b9973] rundll32.exe "C:\WINDOWS\system32\jijejeju.dll",b
              O4 - HKLM\..\Run: [pedovayizo] Rundll32.exe "C:\WINDOWS\system32\yatodimi.dll",s
              O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
              O4 - HKLM\..\RunOnce: [wextract_cleanup1] rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\alex\LOCALS~1\Temp\IXP000.TMP\"
              O4 - HKLM\..\RunOnce: [nabtsfec0] rundll32.exe streamci,StreamingDeviceSetup {07DAD662-22F1-11d1-A9F4-00C04FBBDE8F},GLOBAL,{07DAD660-22F1-11d1-A9F4-00C04FBBDE8F},C:\WINDOWS\INF\nabtsfec.inf,NABTSFEC.Interface.Install
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [LClock] lclock.exe
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-20\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\S-1-5-18\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - HKUS\.DEFAULT\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'Default user')
              O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
              O4 - Global Startup: WiFi Station pour Livebox.lnk = ?
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office10\EXCEL.EXE/3000
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
              O20 - AppInit_DLLs: C:\WINDOWS\system32\rezakaju.dll c:\windows\system32\rutasaka.dll
              O21 - SSODL: SSODL - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\rutasaka.dll (file missing)
              O22 - SharedTaskScheduler: STS - {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - c:\windows\system32\rutasaka.dll (file missing)
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              0
              1. Modérateur
                ---> Télécharge Malwarebytes' Anti-Malware (MBAM) sur ton Bureau.
                ---> Double-clique sur le fichier téléchargé pour lancer le processus d'installation.
                ---> Dans l'onglet Mise à jour, clique sur le bouton Recherche de mise à jour : si le pare-feu demande l'autorisation à MBAM de se connecter à Internet, accepte.
                ---> Une fois la mise à jour terminée, rends-toi dans l'onglet Recherche.
                ---> Sélectionne Exécuter un examen rapide.
                ---> Clique sur Rechercher. L'analyse démarre.

                A la fin de l'analyse, un message s'affiche :

                L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.

                ---> Clique sur OK pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
                ---> Ferme tes navigateurs.
                Si des malwares ont été détectés, clique sur Afficher les résultats.
                ---> Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre infectés et en mettre une copie dans la quarantaine.
                ---> MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport dans ta prochaine réponse.
                0
                1. Malwarebytes' Anti-Malware 1.40
                  Version de la base de données: 2719
                  Windows 5.1.2600 Service Pack 2

                  30/08/2009 22:26:31
                  mbam-log-2009-08-30 (22-26-31).txt

                  Type de recherche: Examen rapide
                  Eléments examinés: 90119
                  Temps écoulé: 6 minute(s), 38 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 0
                  Clé(s) du Registre infectée(s): 6
                  Valeur(s) du Registre infectée(s): 6
                  Elément(s) de données du Registre infecté(s): 1
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 6

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Clé(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7126baa2-3157-42b4-8fa4-e1903ea009d6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{7126baa2-3157-42b4-8fa4-e1903ea009d6} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm5378aaef (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\504b9973 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pedovayizo (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.BHO) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.BHO) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.

                  Elément(s) de données du Registre infecté(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  C:\WINDOWS\system32\yukojuni.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\inujokuy.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\pebapehe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\govegomu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\trz6.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\trz7.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.
                  0
                  1. Modérateur
                    --> Relance MBAM, va dans Quarantaine et supprime tout.

                    --> Refais un scan RSIT et poste le rapport log.
                    0
                    1. Malwarebytes' Anti-Malware 1.40
                      Version de la base de données: 2719
                      Windows 5.1.2600 Service Pack 2

                      30/08/2009 22:42:39
                      mbam-log-2009-08-30 (22-42-39).txt

                      Type de recherche: Examen rapide
                      Eléments examinés: 90242
                      Temps écoulé: 6 minute(s), 14 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 0
                      Valeur(s) du Registre infectée(s): 0
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 0

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Valeur(s) du Registre infectée(s):
                      (Aucun élément nuisible détecté)

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      (Aucun élément nuisible détecté)
                      0
                      1. exact desolée.

                        Logfile of random's system information tool 1.06 (written by random/random)
                        Run by alex at 2009-08-30 22:45:44
                        Microsoft Windows XP Professionnel Service Pack 2
                        System drive C: has 42 GB (84%) free of 50 GB
                        Total RAM: 1023 MB (30% free)

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 22:45:45, on 30/08/2009
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                        C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
                        C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
                        C:\WINDOWS\RTHDCPL.EXE
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                        C:\WINDOWS\system32\rundll32.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\WINDOWS\lclock.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\Program Files\Hercules\WiFi Station pour Livebox\WifiStationLB.exe
                        C:\Program Files\MessengerDiscovery\MessengerDiscovery Live.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\WINDOWS\system32\Ms14.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Windows Live\Contacts\wlcomm.exe
                        C:\Documents and Settings\alex\Bureau\RSIT.exe
                        C:\Program Files\trend micro\alex.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://melanthios-ana.com/zcvisitor/1624d318-3614-11eb-87b9-12a1ab6c324d/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=47f83760-f118-11ea-9bc8-0ac2bbf4ada7
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/toolbar/ie8/sidebar.html
                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://melanthios-ana.com/zcvisitor/1624d318-3614-11eb-87b9-12a1ab6c324d/72092e88-2c53-401c-b988-51ef43ce1034?campaignid=47f83760-f118-11ea-9bc8-0ac2bbf4ada7
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                        O4 - HKLM\..\Run: [avast!] "C:\Program Files\Alwil Software\Avast4\ashDisp.exe"
                        O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
                        O4 - HKLM\..\RunOnce: [wextract_cleanup1] rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\DOCUME~1\alex\LOCALS~1\Temp\IXP000.TMP\"
                        O4 - HKLM\..\RunOnce: [nabtsfec0] rundll32.exe streamci,StreamingDeviceSetup {07DAD662-22F1-11d1-A9F4-00C04FBBDE8F},GLOBAL,{07DAD660-22F1-11d1-A9F4-00C04FBBDE8F},C:\WINDOWS\INF\nabtsfec.inf,NABTSFEC.Interface.Install
                        O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                        O4 - HKLM\..\RunOnce: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [LClock] lclock.exe
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-19\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-20\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\S-1-5-18\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O4 - HKUS\.DEFAULT\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'Default user')
                        O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                        O4 - Global Startup: WiFi Station pour Livebox.lnk = ?
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office10\EXCEL.EXE/3000
                        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
                        O20 - AppInit_DLLs: C:\WINDOWS\system32\rezakaju.dll c:\windows\system32\rutasaka.dll
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        O23 - Service: Component Services1 (ComServices1) - Unknown owner - C:\WINDOWS\System32\com\ComServices.exe
                        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                        0
                        1. Modérateur
                          --> Fais analyser ce fichier : C:\WINDOWS\System32\com\ComServices.exe

                          --> Sur VirusTotal et poste le lien de l'analyse.
                          0
                          1. http://www.virustotal.com/fr/analisis/1cdef246dddbe9dc0f9ef7cab4566da5b7aa72a5365f3e03cf427f40e807c0c9-1251666037
                            0
                            1. Modérateur
                              1/

                              --> Démarre Spybot, clique sur Mode, coche Mode avancé.
                              --> A gauche, clique sur Outils, puis sur Résident.
                              --> Décoche la case devant Résident "TeaTimer" :
                              http://sd-1.archive-host.com/membres/up/3288717712384394/TeaTimer.jpg
                              --> Quitte Spybot.

                              2/

                              ---> Télécharge OTM (OldTimer) sur ton Bureau.

                              ---> Double-clique sur OTM.exe afin de le lancer.

                              ---> Copie (Ctrl+C) le texte suivant ci-dessous :

                              :processes
                              explorer.exe

                              :services
                              ComServices1

                              :reg
                              [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
                              "wextract_cleanup1"=-
                              "nabtsfec0"=-
                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                              "AppInit_DLLS"=""
                              [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
                              "Notification Packages"=hex(7):73,00,63,00,65,00,63,00,6c,00,69,00,00,00,00,00

                              :files
                              C:\WINDOWS\system32\qhodemjf.txt
                              C:\WINDOWS\system32\Ms14.exe
                              C:\WINDOWS\System32\com

                              :commands
                              [purity]
                              [emptytemp]
                              [zipfiles]
                              [reboot]

                              ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                              ---> Clique maintenant sur le bouton MoveIt! puis ferme OTM.

                              Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                              Accepte en cliquant sur YES.

                              ---> Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\
                              Le nom du rapport correspond au moment de sa création : date_heure.log
                              0
                              1. je commence à etre perdue, je le trouve où Spybot?
                                0
                                1. Modérateur
                                  Regarde dans Menu Démarrer > Tous les programmes.
                                  0
                                  1. All processes killed
                                    ========== PROCESSES ==========
                                    No active process named explorer.exe was found!
                                    ========== SERVICES/DRIVERS ==========

                                    Service\Driver ComServices1 deleted successfully.
                                    ========== REGISTRY ==========
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
                                    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
                                    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\wextract_cleanup1 deleted successfully.
                                    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce\\nabtsfec0 deleted successfully.
                                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLS"|"" /E : value set successfully!
                                    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"Notification Packages"|hex(7):73,00,63,00,65,00,63,00,6c,00,69,00,00,00,00,00 /E : value set successfully!
                                    ========== FILES ==========
                                    C:\WINDOWS\system32\qhodemjf.txt moved successfully.
                                    C:\WINDOWS\system32\Ms14.exe moved successfully.
                                    C:\WINDOWS\System32\Com moved successfully.
                                    ========== COMMANDS ==========

                                    [EMPTYTEMP]

                                    User: alex
                                    File delete failed. C:\Documents and Settings\alex\Local Settings\Temp\~DFC1C9.tmp scheduled to be deleted on reboot.
                                    ->Temp folder emptied: 45705311 bytes
                                    ->Temporary Internet Files folder emptied: 556708191 bytes
                                    ->Java cache emptied: 8547694 bytes
                                    ->FireFox cache emptied: 99219186 bytes
                                    ->Google Chrome cache emptied: 6053089 bytes

                                    User: All Users

                                    User: Default User
                                    ->Temp folder emptied: 0 bytes
                                    ->Temporary Internet Files folder emptied: 33170 bytes

                                    User: LocalService
                                    ->Temp folder emptied: 0 bytes
                                    ->Temporary Internet Files folder emptied: 33170 bytes

                                    User: NetworkService
                                    ->Temp folder emptied: 0 bytes
                                    ->Temporary Internet Files folder emptied: 33170 bytes

                                    %systemdrive% .tmp files removed: 0 bytes
                                    %systemroot% .tmp files removed: 2114013 bytes
                                    %systemroot%\System32 .tmp files removed: 4371456 bytes
                                    File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                                    File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_590.dat scheduled to be deleted on reboot.
                                    Windows Temp folder emptied: 522838 bytes
                                    RecycleBin emptied: 101972210 bytes

                                    Total Files Cleaned = 787,08 mb

                                    OTM by OldTimer - Version 3.0.0.6 log created on 08302009_233658

                                    Files moved on Reboot...
                                    C:\Documents and Settings\alex\Local Settings\Temp\~DFC1C9.tmp moved successfully.
                                    File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
                                    C:\WINDOWS\temp\Perflib_Perfdata_590.dat moved successfully.

                                    Registry entries deleted on Reboot...
                                    0
                                    • 1
                                    • 2