Demande d'analyse rapport hijack this

Bonjour,

depuis quelques mois mon ordi subit des ralntissements, utilisation de l'uc incompréhensible, deconnexion d'internet intempestives et apparemment quelqu'un se connecte d'un autre poste sur mon compte msn.
Apres avoir fait plusieurs analyses avec antivir, malwarebytes, adaware, spybot, ccleaner, asquared ainsi que 2 analyses en ligne avec trend micro et bit defender aucun virus n'a été trouvé; etant donné que je ne suis pas calé en informatique je poste mon rapport hijackthis si jamais quelqu'un y trouve quelquechose d'anormal merci de m'aider. Cordialement.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:41:15, on 31/10/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir Desktop\sched.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
c:\program files\avira\antivir desktop\avcenter.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Propriétaire\Mes documents\GenProc\GenProc\outil\Propriétaire_GenProc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.cherche.us/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww12.cherche.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qfr10.hpwis.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.missim.org/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: (no name) - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O9 - Extra button: FreshDownload - {30885858-3B60-459E-97DD-343DDC54EE34} - C:\Program Files\FreshDevices\FreshDownload\fd.exe (file missing)
O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O15 - Trusted Zone: *.chat-land.org
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.extrafilm.fr/ImageUploader5.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LVSrvLauncher - Labtec Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe

--
End of file - 7706 bytes
Configuration: Windows XP Internet Explorer 8.0

11 réponses

  1. Bonsoir guillom49

    Hijack ne montre rien d'anormal...

    Fais ceci stp:

    Télécharge RSIT (de random/random) sur le bureau :

    - Double clique sur RSIT.exe qui est sur le bureau
    - Clique sur "Continue" dans la fenêtre
    - RSIT téléchargera HijackThis si il n’est pas présent où détecté, alors il faudra accepter la licence
    - Poste le contenu de log.txt plus info.txt (réduit ds la barre de taches) à la fin de l’analyse .

    Les rapports sont dans le dossier ici C:\rsit
    a+

    0
    1. Merci je ne m'attendais pas a une reponse si rapide, je fais ca tout de suite.
      0
      1. j'ai suivi tes instructions voila les 2 rapports:

        Logfile of random's system information tool 1.06 (written by random/random)
        Run by Propriétaire at 2009-10-31 23:05:03
        Microsoft Windows XP Édition familiale Service Pack 3
        System drive C: has 73 GB (66%) free of 111 GB
        Total RAM: 511 MB (38% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 23:05:32, on 31/10/2009
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v8.00 (8.00.6001.18702)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Avira\AntiVir Desktop\sched.exe
        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        C:\Program Files\Java\jre6\bin\jqs.exe
        C:\WINDOWS\System32\nvsvc32.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\WINDOWS\system32\cmd.exe
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Program Files\Internet Explorer\IEXPLORE.EXE
        C:\Documents and Settings\Propriétaire\Bureau\RSIT.exe
        C:\Program Files\trend micro\Propriétaire.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.cherche.us/keyword/%s
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww12.cherche.us
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qfr10.hpwis.com/
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.missim.org/
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
        O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
        O3 - Toolbar: (no name) - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - (no file)
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
        O9 - Extra button: FreshDownload - {30885858-3B60-459E-97DD-343DDC54EE34} - C:\Program Files\FreshDevices\FreshDownload\fd.exe (file missing)
        O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
        O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
        O15 - Trusted Zone: *.chat-land.org
        O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
        O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
        O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
        O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
        O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.extrafilm.fr/ImageUploader5.cab
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
        O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
        O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
        O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
        O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
        O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
        O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
        O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
        O23 - Service: LVSrvLauncher - Labtec Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        0
        1. Ok,

          Ton pc montre une infection liée aux supports amovibles...
          ==> Fais ceci:
          • Télécharge et installe USBFIX

          http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe­

          (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptibles d'avoir été infectés sans les ouvrir

          • Double clic sur le raccourci UsbFix présent sur ton bureau .

          • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

          • Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

          • Laisse travailler l'outil.

          • Ensuite post le rapport UsbFix.txt qui apparaitra.

          • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

          • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          a+
          0
          1. Ok merci pour la rapidité et l'éfficacité, j'utilise une clef usb qui se balade de pc en pc mais je ne l'ai pas avec moi la donc je ferai ca dans les 2 jours si ya rien d'autre a faire sans le support amovible. si ce n'est pas grave je suis rassuré je me demandais si on piratai pas l'ordi a distance. merci encore a+
            0
            1. Je ne sais pas si ca a un quelconque interet mais jai fait tourner usbfix sans le support amovible connecté, voici le rapport:

              ############################## | UsbFix V6.046 |

              User : Propriétaire (Administrateurs) # CHANTAL
              Update on 29/10/2009 by Chiquitine29, C_XX & Chimay8
              Start at: 23:36:50 | 31/10/2009
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              Intel(R) Pentium(R) 4 CPU 2.80GHz
              Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
              Internet Explorer 8.0.6001.18702
              Windows Firewall Status : Enabled

              A:\ -> Lecteur de disquettes 3 ½ pouces
              C:\ -> Disque fixe local # 108,27 Go (71,11 Go free) [PRESARIO] # NTFS
              D:\ -> Disque fixe local # 3,5 Go (715,04 Mo free) [PRESARIO_RP] # FAT32
              E:\ -> Disque CD-ROM
              F:\ -> Disque CD-ROM

              ############################## | Processus actifs |

              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\WINDOWS\System32\nvsvc32.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\WINDOWS\explorer.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Windows Live\Contacts\wlcomm.exe
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\WINDOWS\system32\NOTEPAD.EXE
              C:\WINDOWS\system32\NOTEPAD.EXE
              C:\Program Files\Internet Explorer\IEXPLORE.EXE
              C:\Program Files\Outlook Express\msimn.exe
              C:\Program Files\OpenOffice.org 3\program\soffice.exe
              C:\Program Files\OpenOffice.org 3\program\soffice.bin
              C:\WINDOWS\system32\wbem\wmiprvse.exe

              ################## | Fichiers # Dossiers infectieux |

              D:\autorun.inf.vir

              ################## | Registre # Clés Run infectieuses |

              [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
              [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
              [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

              ################## | Registre # Mountpoints2 |

              HKCU\..\..\Explorer\MountPoints2\{1bc4fc50-0be8-11de-a85c-000c76ebdcc7}
              Shell\AutoRun\command =G:\husyu8n.exe
              Shell\open\Command =G:\husyu8n.exe

              HKCU\..\..\Explorer\MountPoints2\{4a6c00a7-a730-11dd-a80a-000c76ebdcc7}
              Shell\Auto\command =AdobeR.exe e
              Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL AdobeR.exe e

              HKCU\..\..\Explorer\MountPoints2\{87942566-d085-11dd-a833-000c76ebdcc7}
              Shell\AutoRun\command =G:\husyu8n.exe
              Shell\open\Command =G:\husyu8n.exe

              HKCU\..\..\Explorer\MountPoints2\{97a7bdc6-25c2-11dd-a7b6-000c76ebdcc7}
              Shell\AutoRun\command =C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe pagefile.sys.vbs

              ################## | Suspect | https://www.virustotal.com/gui/ |

              ################## | Cracks / Keygens / Serials |

              ################## | ! Fin du rapport # UsbFix V6.046 ! |
              0
              1. OK c'est bien....mais il faudra le refaire avec ta clé banchée quand tu l'auras

                • Double clic sur le raccourci UsbFix présent sur ton bureau

                • Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

                • Au second menu Choisis l'option " 2 " ( Suppression ) et tape sur [entrée]

                • Ton bureau disparaitra et le pc redémarrera .

                • Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                • Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

                • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                a+
                0
                1. l'analyse a bloqué a 80% sur nettoyage des fichiers temporaires j'ai du fermer la session et revenir il y a quand meme eu un rapport de généré le voila:

                  ############################## | UsbFix V6.046 |

                  User : Propriétaire (Administrateurs) # CHANTAL
                  Update on 29/10/2009 by Chiquitine29, C_XX & Chimay8
                  Start at: 00:00:19 | 01/11/2009
                  Website : http://pagesperso-orange.fr/NosTools/index.html
                  Contact : FindyKill.Contact@gmail.com

                  Intel(R) Pentium(R) 4 CPU 2.80GHz
                  Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
                  Internet Explorer 8.0.6001.18702
                  Windows Firewall Status : Enabled

                  A:\ -> Lecteur de disquettes 3 ½ pouces
                  C:\ -> Disque fixe local # 108,27 Go (71,15 Go free) [PRESARIO] # NTFS
                  D:\ -> Disque fixe local # 3,5 Go (715,04 Mo free) [PRESARIO_RP] # FAT32
                  E:\ -> Disque CD-ROM
                  F:\ -> Disque CD-ROM

                  ############################## | Processus actifs |

                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\csrss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  C:\Program Files\Java\jre6\bin\jqs.exe
                  C:\WINDOWS\System32\nvsvc32.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\WINDOWS\System32\alg.exe
                  C:\WINDOWS\system32\wbem\wmiprvse.exe

                  ################## | Fichiers # Dossiers infectieux |

                  Supprimé ! D:\autorun.inf.vir

                  ################## | Registre # Clés Run infectieuses |

                  Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"
                  Supprimé ! [HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"
                  Supprimé ! [HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDrives"

                  ################## | Registre # Mountpoints2 |

                  Supprimé ! HKCU\...\Explorer\MountPoints2\{1bc4fc50-0be8-11de-a85c-000c76ebdcc7}\Shell\AutoRun\Command
                  Supprimé ! HKCU\...\Explorer\MountPoints2\{4a6c00a7-a730-11dd-a80a-000c76ebdcc7}\Shell\Auto\Command
                  Supprimé ! HKCU\...\Explorer\MountPoints2\{87942566-d085-11dd-a833-000c76ebdcc7}\Shell\AutoRun\Command
                  Supprimé ! HKCU\...\Explorer\MountPoints2\{97a7bdc6-25c2-11dd-a7b6-000c76ebdcc7}\Shell\AutoRun\Command
                  0
                  1. Effectivement le rapport n'est pas complet.
                    Fais un nouveau RSIT pour contole...
                    Tu n'auras que le logtxt cette fois,c'est normal...

                    a+
                    0
                    1. ok voila le rapport.

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by Propriétaire at 2009-11-01 00:47:22
                      Microsoft Windows XP Édition familiale Service Pack 3
                      System drive C: has 73 GB (66%) free of 111 GB
                      Total RAM: 511 MB (19% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 00:47:50, on 01/11/2009
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      C:\Program Files\Java\jre6\bin\jqs.exe
                      C:\WINDOWS\System32\nvsvc32.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\internet explorer\iexplore.exe
                      C:\Program Files\internet explorer\iexplore.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                      C:\Documents and Settings\Propriétaire\Bureau\RSIT.exe
                      C:\Program Files\trend micro\Propriétaire.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.cherche.us/keyword/%s
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-qfr10.hpwis.com/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
                      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                      O3 - Toolbar: (no name) - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - (no file)
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                      O9 - Extra button: FreshDownload - {30885858-3B60-459E-97DD-343DDC54EE34} - C:\Program Files\FreshDevices\FreshDownload\fd.exe (file missing)
                      O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                      O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                      O15 - Trusted Zone: *.chat-land.org
                      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                      O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
                      O16 - DPF: {2357B3CF-7F8D-4451-8D81-FD6097610AEE} - http://activex.camfrogweb.com/advanced/2.0.2.20/cfweb_activex.camfrogweb.com-advanced-2.0.2.20_instmodule.exe
                      O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                      O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.extrafilm.fr/ImageUploader5.cab
                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
                      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase9563.cab
                      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/webplayer/stage6/windows/AutoDLDivXWebPlayerInstaller.cab
                      O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
                      O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
                      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
                      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                      O23 - Service: LVSrvLauncher - Labtec Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
                      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                      0
                  2. Ok....

                    - Désinstalles les traces de Norton qui restent sur le pc:
                    http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

                    - Pour desinstaller les outils utilisés

                    Telecharge ToolsCleaner2--> http://pc-system.fr/
                    -Une fois téléchargé, installe-le et lance-le
                    -Clique sur Recherche et laisse le scan se terminer
                    -Clique sur SUPPRESSION
                    -Clique sur Quitter pour que le rapport puisse se créer
                    -Poste moi le rapport se trouvant ici--> C:\TCleaner.txt

                    a+
                    0
                    1. Ok norton est bien desinstallé et voici le rapport de tools cleaner; merci de refaire une santé a mon pc si ya d'autres manip a faire je suis preneur.

                      [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

                      --> Recherche:

                      C:\VundoFix.txt: trouvé !
                      C:\Combofix.txt: trouvé !
                      C:\rapport_clean.txt: trouvé !
                      C:\UsbFix.txt: trouvé !
                      C:\Vundofix backups: trouvé !
                      C:\GenProc: trouvé !
                      C:\Qoobox: trouvé !
                      C:\UsbFix: trouvé !
                      C:\Rsit: trouvé !
                      C:\ComboFix(2)\Combofix.txt: trouvé !
                      C:\Documents and Settings\Propriétaire\Bureau\UsbFix.exe: trouvé !
                      C:\Documents and Settings\Propriétaire\Bureau\Rsit.exe: trouvé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc.zip: trouvé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc: trouvé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc\GenProc: trouvé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc\GenProc\Genproc.exe: trouvé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc\GenProc\outil\hijackthis.log: trouvé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc\GenProc\outil\mbr.exe: trouvé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc\GenProc\Page\GenProc[*].html: trouvé !
                      C:\Documents and Settings\Propriétaire\Recent\UsbFix.lnk: trouvé !
                      C:\GenProc\Page\GenProc[*].html: trouvé !
                      C:\Program Files\trend micro\HijackThis.exe: trouvé !
                      C:\Program Files\trend micro\hijackthis.log: trouvé !
                      C:\Qoobox\Quarantine\catchme.log: trouvé !

                      ---------------------------------
                      --> Suppression:

                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc.zip: supprimé !
                      C:\Program Files\trend micro\HijackThis.exe: supprimé !
                      C:\VundoFix.txt: supprimé !
                      C:\Combofix.txt: supprimé !
                      C:\rapport_clean.txt: supprimé !
                      C:\UsbFix.txt: supprimé !
                      C:\ComboFix(2)\Combofix.txt: supprimé !
                      C:\Documents and Settings\Propriétaire\Bureau\UsbFix.exe: supprimé !
                      C:\Documents and Settings\Propriétaire\Bureau\Rsit.exe: supprimé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc\GenProc\Genproc.exe: supprimé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc\GenProc\outil\hijackthis.log: supprimé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc\GenProc\outil\mbr.exe: supprimé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
                      C:\Documents and Settings\Propriétaire\Recent\UsbFix.lnk: supprimé !
                      C:\GenProc\Page\GenProc[*].html: ERREUR DE SUPPRESSION !!
                      C:\Program Files\trend micro\hijackthis.log: supprimé !
                      C:\Qoobox\Quarantine\catchme.log: supprimé !
                      C:\Vundofix backups: supprimé !
                      C:\GenProc: supprimé !
                      C:\Qoobox: supprimé !
                      C:\UsbFix: supprimé !
                      C:\Rsit: supprimé !
                      C:\Documents and Settings\Propriétaire\Mes documents\GenProc: supprimé !
                      0
                  3. Re

                    Surtout n'oublies pas de désinfecter ta clé usb acec usbfix (option2)
                    car sinon tu réinfecteras ton pc illico !

                    pour finir:

                    >Télécharge HiJackThis : https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/
                    - Lance le programme, puis sélectionne < do a system only >
                    - Et coche (fixe) les lignes suivantes:
                    Tuto : si problème : http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

                    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                    O3 - Toolbar: (no name) - {ED0E8CA5-42FB-4B18-997B-769E0408E79D} - (no file)
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
                    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe

                    Appuies ensuite sur FIX CHECKED

                    Comment se comporte le pc ?

                    A+

                    0
                    1. je viens de faire le scan hijack this a part la ligne 023 qui était absente tout est fixé, le pc marche nickel pour le moment, je penserais a faire la manip kan je connecte un support amovible.
                      c'est la premiere fois que je faisais appel a ce genre de forum, merci de faire partager vos compétences.

                      Cordialement.
                      0