Besoin d'aide : Ordinateur Infecter?

Résolu
Bonjour,
Déjà je vous remercie de bien vouloir m'aider :=)
Voilà je vais vous exposer mon problème :
Hier une personne a branché sa clé pour me donner un programme tout bête j'ai accepté. Mais j'avais oublié de l'analyser... -_-"
Puis mon anti-virus (Kaspersky] 2010) a signaler que j'avais des virus (cheval de Troie) Affolé car je ne pouvais plus entrer dans mon disque dur et mon disque dur contenant tout mes données. Alors j'ai fait n'importe quoi même la restauration de mon système (j'ai pas formater)
Donc après j'ai fait n'importe quoi comme je le disait en haut et j'ai même désactiver l'autorun.inf de mon disque dur (car je ne pouvais plus l'accéder) Alors sa avait marché mais curieux j'ai voulu savoir pourquoi sa marcher donc après cela j'ai remis donc autorun.inf

Bon maintenant enfin avant de poster ce sujet j'ai donc fait un scan avec hijackThis Voilà le résultat mais je ne pense pas avoir bien fait le scan..

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:04:34, on 25/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\VM_STI.EXE
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Philips\Philips SPC210NC Webcam\TrayMin210.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
C:\WINDOWS\System32\NOTEPAD.EXE
C:\Documents and Settings\Bryan\Mes documents\Téléchargements\HiJackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC210NC Webcam
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\Bryan\Mes documents\Téléchargements\HijackThis.exe /startupscan
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: TrayMin210.exe.lnk = ?
O8 - Extra context menu item: Ajouter à l'Anti-bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Clavier &virtuel - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Analyse des &liens - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe

--
End of file - 4881 bytes

Je vous remercie de bien m'avoir écouter (enfin lu ^^) et je vous remerci d'avance pour ceux ou celle qui voudrions bien m'aider..

Cordialement Trollman

edit: C'est la 1er fois que je poste ici si il y a des trucs a revoir ou a ne plus faire quand je poste un sujet dite le moi... Merci
Configuration: Windows XP
Firefox 3.5.5

57 réponses

Résumé de la discussion

Une suspicion d'infection est apparue après qu'une clé USB a été connectée et qu'un cheval de Troie a été détecté par l'antivirus, suivie de mesures risquées comme des restaurations système et désactivation d'AutoRun. Des outils comme HijackThis peuvent ne pas révéler ce type d'infection lié aux supports externes; des solutions recommandées consistent à utiliser RSIT ou UsbFix et à partager les rapports pour diagnostic. Selon les échanges, il est conseillé de télécharger des outils spécialisés, d'analyser les rapports générés et d'éviter les manipulations qui pourraient réinfecter l'ordinateur ou compromettre les données sensibles. En cas d'infection par USB, la priorité est de préserver les données et de tester les périphériques sur un ordinateur isolé avant toute réémission de programmes.

Bobot (l’IA à votre service)
  1. non desolé tu n'as pas fait tes preuves en tant que helpeur et je ne peux me permettre de divulguer ces infos à n'importe qui
    4
    1. Contributeur sécurité
      attention post 2 il y avait infections par support usb

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{158f9655-d913-11de-84ae-00248cebd982}]
      shell\AutoRun\command - F:\i9bwjpqc.exe
      shell\open\command - F:\i9bwjpqc.exe

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{158f9656-d913-11de-84ae-00248cebd982}]
      shell\AutoRun\command - G:\i9bwjpqc.exe
      shell\open\command - G:\i9bwjpqc.exe

      sans traitement des cles usb, cela va réinfecter le pc formaté..!
      3
      1. Bonjour trollman

        HijackThis ne montre pas ce genre d'infection

        - Télécharge Random's System Information Tool (RSIT) de Random / Random
        http://images.malwareremoval.com/random/RSIT.exe et sauvegarde-le sur ton Bureau,

        - Double-clique sur [b]RSIT.exe[/b] pour lancer le programme

        - Clique sur [b]continuer[/b] sur l'écran Disclaimer,

        [b]NOTE[/b]
        Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

        - L'analyse terminée, deux fichiers texte s'ouvriront.

        - Poste le contenu de[b] log.txt[/b] (<<qui sera affiché) ainsi que de [b]info.txt[/b] (<<qui sera réduit dans la Barre des Tâches).

        Note : Tu peux aussi retrouver les deux rapports dans le dossier C:\Rsit
        1
        1. Salut ,

          Tes disque G et F sont infectés :

          • Télécharge UsbFix sur ton bureau .

          (!) Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

          • Double clic sur "UsbFix.exe" présent sur ton bureau .

          • Choisis l' option F pour français et et tape sur [entrée] .

          • choisis l'option 2 ( Suppression ) et tape sur [entrée].

          • Ton bureau disparaitra et le pc redémarrera .

          • Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

          Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

          • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

          ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
          1
          1. Re , non la clé est propre , le pc aussi

            → Ferme toutes les applications en cours, puis télécharge ToolsCleaner2 sur ton Bureau.

            → Double clique sur ToolsCleaner2.exe
            → Clique sur .Recherche
            → puis sur Suppression quand la liste est trouvée.
            → Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

            (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

            Note : ton bureau RISQUE de disparaître, c'est normal. S'il n'apparaît pas à la fin du scan, fais la manip suivante :

            CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
            Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

            Tape explorer.exe et valide. Cela fera re-apparaître le Bureau
            1
            1. Good mais l'écran na pas disparu mais j'ai pas trouver de rapport non lus x)

              Mais j'ai eu sa dans le logiciels

              C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Bureau\HijackThis.exe: supprimé !
              C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Recent\HijackThis.lnk: supprimé !
              C:\UsbFix.txt: supprimé !
              C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Bureau\hijackthis.log: supprimé !
              C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Bureau\UsbFix.exe: supprimé !
              C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Bureau\Rsit.exe: supprimé !
              C:\UsbFix: supprimé !
              C:\Rsit: supprimé !
              1
              1. Logfile of random's system information tool 1.06 (written by random/random)
                Run by Bryan at 2009-11-25 12:48:32
                Microsoft Windows XP Édition familiale Service Pack 3
                System drive C: has 321 GB (93%) free of 343 GB
                Total RAM: 2038 MB (66% free)

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 12:48:39, on 25/11/2009
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\igfxtray.exe
                C:\WINDOWS\system32\hkcmd.exe
                C:\WINDOWS\system32\igfxpers.exe
                C:\WINDOWS\system32\igfxsrvc.exe
                C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\VM_STI.EXE
                C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Philips\Philips SPC210NC Webcam\TrayMin210.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtblfs.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Documents and Settings\Bryan\Mes documents\Téléchargements\RSIT.exe
                C:\Documents and Settings\Bryan\Mes documents\Téléchargements\Bryan.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: link filter bho - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
                O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
                O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC210NC Webcam
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
                O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\Bryan\Mes documents\Téléchargements\HijackThis.exe /startupscan
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - Global Startup: TrayMin210.exe.lnk = ?
                O8 - Extra context menu item: Ajouter à l'Anti-bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                O9 - Extra button: Clavier &virtuel - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                O9 - Extra button: Analyse des &liens - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\klwtbbho.dll
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
                O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
                O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                0
                1. Voilà j'ai formaté Mon ordinateur mais j'ai pu constater que il rester certain donné donc j'ai refait un autre test voilà le résultat

                  Avec Hijackthis
                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 14:19:14, on 25/11/2009
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                  Boot mode: Normal

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\wscntfy.exe
                  C:\WINDOWS\system32\igfxtray.exe
                  C:\WINDOWS\system32\hkcmd.exe
                  C:\WINDOWS\system32\igfxsrvc.exe
                  C:\WINDOWS\system32\igfxpers.exe
                  C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Philips\Philips SPC210NC Webcam\TrayMin210.exe
                  C:\WINDOWS\system32\msiexec.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                  C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Bureau\RSIT.exe
                  C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Bureau\HiJackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
                  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
                  O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
                  O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.exe Philips SPC 210NC PC Camera
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                  O4 - HKLM\..\RunOnce: [WMC_RebootCheck] C:\WINDOWS\inf\unregmp2.exe /FixUps
                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                  O4 - HKCU\..\RunOnce: [MPlayer2_FixUp] C:\WINDOWS\inf\unregmp2.exe /Fixups
                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                  O4 - Global Startup: TrayMin210.exe.lnk = C:\Program Files\Philips\Philips SPC210NC Webcam\TrayMin210.exe
                  O8 - Extra context menu item: Ajouter à l'Anti-bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
                  O9 - Extra button: Clavier &virtuel - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\WINDOWS\system32\shdocvw.dll
                  O9 - Extra button: Analyse des &liens - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\WINDOWS\system32\shdocvw.dll
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
                  O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                  0
                  1. RE, après reformatage ?
                    REfait un scan RSIT et poste le
                    0
                    1. wow merci aprés formatage voilà le résultat

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by Bryan at 2009-11-26 07:48:37
                      Microsoft Windows XP Édition familiale Service Pack 2
                      System drive C: has 316 GB (92%) free of 343 GB
                      Total RAM: 2038 MB (76% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 07:48:41, on 26/11/2009
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\igfxtray.exe
                      C:\WINDOWS\system32\hkcmd.exe
                      C:\WINDOWS\system32\igfxsrvc.exe
                      C:\WINDOWS\system32\igfxpers.exe
                      C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
                      C:\WINDOWS\VM_STI.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Philips\Philips SPC210NC Webcam\TrayMin210.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\Mozilla Firefox\firefox.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\wscntfy.exe
                      C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Bureau\RSIT.exe
                      C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Bureau\Bryan.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
                      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
                      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
                      O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.exe Philips SPC 210NC PC Camera
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - Global Startup: TrayMin210.exe.lnk = C:\Program Files\Philips\Philips SPC210NC Webcam\TrayMin210.exe
                      O8 - Extra context menu item: Ajouter à l'Anti-bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
                      O9 - Extra button: Clavier &virtuel - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\WINDOWS\system32\shdocvw.dll
                      O9 - Extra button: Analyse des &liens - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\WINDOWS\system32\shdocvw.dll
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll
                      O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
                      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                      0
                      1. Merci voilà

                        ############################## | UsbFix V6.057 |

                        User : Bryan (Administrateurs) # BRYAN-2A110C14D
                        Update on 25/11/2009 by Chiquitine29, C_XX & Chimay8
                        Start at: 11:40:00 | 26/11/2009
                        Website : http://pagesperso-orange.fr/NosTools/index.html
                        Contact : FindyKill.Contact@gmail.com

                        Intel(R) Pentium(R) Dual CPU E2200 @ 2.20GHz
                        Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 2
                        Internet Explorer 6.0.2900.2180
                        Windows Firewall Status : Disabled
                        AV : Kaspersky Internet Security 9.0.0.459 [ (!) Disabled | Updated ]
                        FW : Kaspersky Internet Security[ (!) Disabled ]9.0.0.459

                        A:\ -> Lecteur de disquettes 3 ½ pouces
                        C:\ -> Disque fixe local # 335,35 Go (306,29 Go free) # NTFS
                        D:\ -> Disque CD-ROM
                        E:\ -> Disque fixe local # 596,17 Go (321,95 Go free) # NTFS
                        F:\ -> Disque amovible # 1,85 Go (532,29 Mo free) # FAT32

                        ############################## | Processus actifs |

                        C:\WINDOWS\System32\smss.exe 900
                        C:\WINDOWS\system32\csrss.exe 960
                        C:\WINDOWS\system32\winlogon.exe 984
                        C:\WINDOWS\system32\services.exe 1028
                        C:\WINDOWS\system32\lsass.exe 1040
                        C:\WINDOWS\system32\svchost.exe 1212
                        C:\WINDOWS\system32\svchost.exe 1300
                        C:\WINDOWS\System32\svchost.exe 1424
                        C:\WINDOWS\system32\svchost.exe 1568
                        C:\WINDOWS\system32\svchost.exe 1680
                        C:\WINDOWS\system32\spoolsv.exe 1880
                        C:\WINDOWS\Explorer.EXE 224
                        C:\WINDOWS\system32\wdfmgr.exe 608
                        C:\WINDOWS\system32\wuauclt.exe 1656
                        C:\WINDOWS\system32\wscntfy.exe 132
                        C:\WINDOWS\System32\alg.exe 1632
                        C:\WINDOWS\system32\wbem\wmiprvse.exe 2040

                        ################## | Fichiers # Dossiers infectieux |

                        ################## | Registre # Clés infectieuses |

                        ################## | Registre # Mountpoints2 |

                        ################## | Listing des fichiers présent |

                        [25/11/2009 16:10|-rahs----|0] C:\$bootdrive$
                        [25/11/2009 16:10|-rahs----|0] C:\$dwnlvldrive$
                        [25/11/2009 16:10|-rahs----|0] C:\$lsdrive$
                        [20/11/2009 21:26|--a------|0] C:\AUTOEXEC.BAT
                        [25/11/2009 20:09|---hs----|216] C:\boot.ini
                        [05/08/2004 16:00|-rahs----|4952] C:\Bootfont.bin
                        [02/11/2006 13:53|-rahs----|438840] C:\bootmgr
                        [25/11/2009 16:18|-ra-s----|8192] C:\BOOTSECT.BAK
                        [20/11/2009 21:26|--a------|0] C:\CONFIG.SYS
                        [20/11/2009 21:26|-rahs----|0] C:\IO.SYS
                        [20/11/2009 21:26|-rahs----|0] C:\MSDOS.SYS
                        [05/08/2004 16:00|-rahs----|47564] C:\NTDETECT.COM
                        [22/11/2009 16:05|-rahs----|252240] C:\ntldr
                        [?|?|?] C:\pagefile.sys
                        [26/11/2009 11:42|--a------|2424] C:\UsbFix.txt
                        [18/11/2009 07:41|--a------|734400512] F:\2012(exclu 2009 by Trollman).avi
                        [22/11/2009 11:44|--a------|699041510] F:\Pandorum.R5.up.by.radiant.avi

                        ################## | Vaccination |

                        # C:\autorun.inf -> Dossier créé par UsbFix.
                        # E:\autorun.inf -> Dossier créé par UsbFix.
                        # F:\autorun.inf -> Dossier créé par UsbFix.

                        ################## | Suspect | https://www.virustotal.com/gui/ |

                        ################## | Cracks / Keygens / Serials |

                        ################## | ! Fin du rapport # UsbFix V6.057 ! |
                        0
                        1. RE, dommage d'être passé par un formatage pour quand même en arriver à passer le tool de chiquitine29 (que je salue au passage)
                          0
                          1. Oué mais Le virus en question fesait planter mon ordinateur et mon anti-virus ne pouvais rien faire -_-"
                            Et pis mon ordinateur vient de redémarrer tout seul o0
                            J'ai fait une analyse avec le log RSIT

                            Logfile of random's system information tool 1.06 (written by random/random)
                            Run by Bryan at 2009-11-26 18:15:36
                            Microsoft Windows XP Édition familiale Service Pack 2
                            System drive C: has 317 GB (92%) free of 343 GB
                            Total RAM: 2038 MB (71% free)

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 18:15:39, on 26/11/2009
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\WINDOWS\system32\igfxtray.exe
                            C:\WINDOWS\system32\hkcmd.exe
                            C:\WINDOWS\system32\igfxpers.exe
                            C:\WINDOWS\system32\igfxsrvc.exe
                            C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe
                            C:\WINDOWS\VM_STI.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Philips\Philips SPC210NC Webcam\TrayMin210.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\taskmgr.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Bureau\RSIT.exe
                            C:\Documents and Settings\Bryan.BRYAN-2A110C14D\Bureau\Bryan.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ievkbd.dll
                            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                            O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
                            O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
                            O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
                            O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\HDADeck\HDeck.exe 1
                            O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe"
                            O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE Philips SPC210NC Webcam
                            O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                            O4 - Global Startup: TrayMin210.exe.lnk = C:\Program Files\Philips\Philips SPC210NC Webcam\TrayMin210.exe
                            O8 - Extra context menu item: Ajouter à l'Anti-bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\ie_banner_deny.htm
                            O9 - Extra button: Clavier &virtuel - {4248FE82-7FCB-46AC-B270-339F08212110} - C:\WINDOWS\system32\shdocvw.dll
                            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                            O9 - Extra button: Analyse des &liens - {CCF151D8-D089-449F-A5A4-D9909053F20F} - C:\WINDOWS\system32\shdocvw.dll
                            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                            O23 - Service: Kaspersky Internet Security (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2010\avp.exe
                            O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                            0
                            1. salut a tous ce windows est un windows xp titanium donc illégitime
                              0
                              1. o0 pourquoi dit tu que mon windows xp es illégitime?
                                Ce n'est pas un titanium
                                Mais c'est quoi un titanium? xD
                                0
                                • 1
                                • 2
                                • 3