Trojan-Dropper:W32/BHO.EYN

TOMY TOM -  
eZula Messages postés 3509 Statut Contributeur -
Bonjour,c est ma premier sur un forum.j ai un probleme avec un virus. mon anti virus f secure me dit que j ai un virus.il me le nettoie avec succes et me fait redemarrer le pc.apres plusieurs utilisation il me resignal le meme virus mes ne peux pas le nettoyer car il a changer de mon.
sur f secure,j ai fait un scane et me trouve un virus .mais des qu il me le nettoie le pc redemarre tout seul sans que le procede de netoyage soit fini et le virus et tjrs la.je l ai fait plusieurs fois et le meme resultat.
je ne sais que faire surtout que je suis novice en informatique.
quelle q un pourrait il m aider s il vous plait. merci
Configuration: Windows Vista Internet Explorer 7.0

6 réponses

  1. eZula Messages postés 3509 Statut Contributeur 392
     
    Bonjour,

    télécharge GenProc http://www.genproc.com/GenProc.exe

    double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre
    0
  2. TOMY TOM
     
    je te renvois un mail car je ne sais pas si tu as recu le premier.encore merci. Rapport GenProc 2.655 [2] - 04/12/2009 à 21:59:35
    @ Windows VISTA Service Pack 2 - HP-Pavilion - Mode normal
    @ Internet Explorer 8.0.6001.18828 [Navigateur par défaut]

    GenProc n'a détecté aucune infection caractéristique et suggère de suivre la procédure suivante :

    Poste un rapport Nod32 https://www.eset.com/ (il faut utiliser Internet Explorer)
    - coche toutes les cases à chaque fois, et lorsque c'est terminé, colle le rapport :
    C:\Program Files\EsetOnlineScanner\log.txt

    ~~~~ INFORMATION COMPLEMENTAIRE ~~~~

    Rapport de ZHPDiag v1.24.35 par Nicolas Coolman
    Run by tom at 04/12/2009 22:01:42
    Web site : http://www.premiumorange.com/zeb-help-process/zhpdiag.html
    Platform : Windows Vista (TM) Home Premium (6.0.6002) Service Pack 2
    MSIE: Internet Explorer v8.0.6001.18828

    Boot mode: Normal (Normal boot)
    Total RAM: 1981 MB (45% free)
    System drive C: has 42 GB (18%) free of 225 GB

    ---\\
    C:\Program Files\Windows Defender\MSASCui.exe
    c:\hp\support\hpsysdrv.exe
    C:\HP\KBD\KbdStub.EXE
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\SFR\Pack Sécurité\FSGUI\TNBUtil.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    C:\Program Files\www.codecpack.net\Codec Pack Suite\WinCheck.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Program Files\Hercules\Dualpix HD\XtrCtrl.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Windows\SMINST\launcher.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\SFR\Media Center\MediaCenter.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Windows\ehome\ehTray.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
    C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\SLsvc.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\SearchIndexer.exe

    ---\\
    F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,
    F2 - REG:system.ini: Shell=explorer.exe

    ---\\
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.sfr.fr/fr/adsl-neufbox.jsp

    ---\\
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm

    ---\\
    R3 - URLSearchHook: Microsoft Url Search Hook - {CFBFAE00-17A6-11D0-99CB-00C04FD64497} - C:\Windows\system32\ieframe.dll

    ---\\
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\RazaWebHook32.dll
    O2 - BHO: Aide à la navigation SFR - {0F6E720A-1A6B-40E1-A294-1D4D19F156C8} - C:\Program Files\Neuf\Kit\SFRNavErrorHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll

    ---\\
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

    ---\\
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
    O4 - HKLM\..\Run: [OsdMaestro] C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [F-Secure Manager] C:\Program Files\SFR\Pack Sécurité\Common\FSM32.EXE" /splash
    O4 - HKLM\..\Run: [F-Secure TNB] C:\Program Files\SFR\Pack Sécurité\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    O4 - HKLM\..\Run: [WinCheck] C:\Program Files\www.codecpack.net\Codec Pack Suite\WinCheck.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Adobe ARM] C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    O4 - HKLM\..\Run: [CamserviceHD] C:\Program Files\Hercules\Dualpix HD\XtrCtrl.exe /startup
    O4 - HKLM\..\Run: [QuickTime Task] C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [Neuf Media Center] C:\Program Files\SFR\Media Center\MediaCenter.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKLM\..\policies\Explorer: [BindDirectlyToPropertySetStorage] Data=0
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem
    O4 - HKUS\S-1-5-20\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
    O4 - Global Startup: HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: WinCheck.lnk - C:\Windows\Installer\{1B1D61FB-B1E4-4166-8941-FC86B3FD9227}\_CC76CA812AE64A7457880C.exe
    O4 - Global Startup: OneNote 2007 - Capture d'écran et lancement.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE

    ---\\
    O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\RazaWebHook32.dll/3000
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000

    ---\\
    O9 - Extra button: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll,201
    O9 - Extra button: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll,103
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFBARH.ICO

    ---\\
    O10 - WLSP:\000000000001\Winsock LSP File - C:\Windows\system32\NLAapi.dll
    O10 - WLSP:\000000000002\Winsock LSP File - C:\Windows\system32\napinsp.dll
    O10 - WLSP:\000000000003\Winsock LSP File - C:\Windows\system32\pnrpnsp.dll
    O10 - WLSP:\000000000004\Winsock LSP File - C:\Windows\system32\pnrpnsp.dll
    O10 - WLSP:\000000000005\Winsock LSP File - C:\Windows\system32\mswsock.dll
    O10 - WLSP:\000000000006\Winsock LSP File - C:\Windows\system32\winrnr.dll

    ---\\
    O16 - DPF: {22492231-AEF0-49FC-9180-CE8969AB1273} (F-Secure Online Scanner Launcher) - http://download.sp.f-secure.com/ols/f-secure-rtm/resources/fslauncher.cab

    ---\\
    O18 - Handler: cdl - {3dd53d40-7b8b-11D0-b013-00aa0059ce02} - C:\Windows\system32\urlmon.dll
    O18 - Handler: dvd - {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\msvidctl.dll
    O18 - Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Handler: mhtml - {05300401-BCBC-11d0-85E3-00C04FD85AB4} - C:\Windows\system32\inetcomm.dll
    O18 - Handler: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
    O18 - Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll
    O18 - Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
    O18 - Handler: tv - {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\msvidctl.dll
    O18 - Handler: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
    O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

    ---\\
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\System32\webcheck.dll

    ---\\
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - %SystemRoot%\system32\browseui.dll

    ---\\
    O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - C:\Program Files\SFR\Pack Sécurité\Anti-Virus\fsgk32st.exe
    O23 - Service: F-Secure Management Agent (FSMA) - C:\Program Files\SFR\Pack Sécurité\Common\FSMA32.EXE
    O23 - Service: Service Google Update (gupdate1ca1208dbc17ed0) (gupdate1ca1208dbc17ed0) - C:\Program Files\Google\Update\GoogleUpdate.exe" /svc
    O23 - Service: Google Software Updater (gusvc) - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - C:\Windows\system32\nvvsvc.exe
    O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - C:\Windows\system32\SLsvc.exe
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - C:\Windows\System32\spoolsv.exe
    O23 - Service: @%systemroot%\system32\SearchIndexer.exe,-103 (WSearch) - C:\Windows\system32\SearchIndexer.exe /Embedding

    ---\\
    O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Google Software Updater.job
    O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    O39 - APT:Automatic Planified Task - C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    O39 - APT:Automatic Planified Task - C:\Windows\Tasks\Scheduled scanning task.job
    O39 - APT:Automatic Planified Task - C:\Windows\Tasks\User_Feed_Synchronization-{AEFD2492-BB23-471C-BB1E-41A46511F0E4}.job

    ---\\
    O41 - Driver: Ancilliary Function Driver for Winsock (AFD) - C:\Windows\system32\drivers\afd.sys
    O41 - Driver: Pilote de CD-ROM (cdrom) - C:\WINDOWS\system32\DRIVERS\cdrom.sys
    O41 - Driver: @%systemroot%\system32\drivers\dfsc.sys,-101 (DfsC) - C:\WINDOWS\System32\Drivers\dfsc.sys
    O41 - Driver: F-Secure HIPS Driver (F-Secure HIPS) - C:\Program Files\SFR\Pack Sécurité\HIPS\drivers\fshs.sys
    O41 - Driver: F-Secure Email Scanning Driver (FSES) - C:\WINDOWS\System32\drivers\fses.sys
    O41 - Driver: F-Secure Firewall Driver (FSFW) - C:\WINDOWS\System32\drivers\fsdfw.sys
    O41 - Driver: F-Secure Vista Support Driver (fsvista) - C:\Program Files\SFR\Pack Sécurité\Anti-Virus\minifilter\fsvista.sys
    O41 - Driver: Pilote pour clavier i8042 et souris sur port PS/2 (i8042prt) - C:\WINDOWS\system32\DRIVERS\i8042prt.sys
    O41 - Driver: Pilote de la classe Clavier (kbdclass) - C:\WINDOWS\system32\DRIVERS\kbdclass.sys
    O41 - Driver: Pilote de la classe Souris (mouclass) - C:\WINDOWS\system32\DRIVERS\mouclass.sys
    O41 - Driver: NetBIOS Interface (NetBIOS) - C:\WINDOWS\system32\DRIVERS\netbios.sys
    O41 - Driver: NETBT (netbt) - C:\WINDOWS\System32\DRIVERS\netbt.sys
    O41 - Driver: NSI proxy service (nsiproxy) - C:\WINDOWS\system32\drivers\nsiproxy.sys
    O41 - Driver: @%SystemRoot%\System32\drivers\pacer.sys,-101 (PSched) - C:\WINDOWS\system32\DRIVERS\pacer.sys
    O41 - Driver: Remote Access Auto Connection Driver (RasAcd) - C:\WINDOWS\System32\DRIVERS\rasacd.sys
    O41 - Driver: Redirected Buffering Sub Sysytem (rdbss) - C:\WINDOWS\system32\DRIVERS\rdbss.sys
    O41 - Driver: RDPCDD (RDPCDD) - C:\WINDOWS\System32\DRIVERS\RDPCDD.sys
    O41 - Driver: RDP Encoder Mirror Driver (RDPENCDD) - C:\WINDOWS\system32\drivers\rdpencdd.sys
    O41 - Driver: @%SystemRoot%\system32\tcpipcfg.dll,-50005 (Smb) - C:\WINDOWS\system32\DRIVERS\smb.sys
    O41 - Driver: @%SystemRoot%\system32\tcpipcfg.dll,-50004 (tdx) - C:\WINDOWS\system32\DRIVERS\tdx.sys
    O41 - Driver: Pilote de périphérique terminal (TermDD) - C:\WINDOWS\system32\DRIVERS\termdd.sys
    O41 - Driver: (no object) (VgaSave) - C:\Windows\System32\drivers\vga.sys
    O41 - Driver: Remote Access IPv6 ARP Driver (Wanarpv6) - C:\WINDOWS\system32\DRIVERS\wanarp.sys

    ---\\
    O42 - Logiciel: 32 Bit HP CIO Components Installer
    O42 - Logiciel: Activation Assistant for the 2007 Microsoft Office suites
    O42 - Logiciel: Adobe Flash Player 10 ActiveX
    O42 - Logiciel: Adobe Flash Player 9 ActiveX
    O42 - Logiciel: Adobe Reader 8.1.7 - Français
    O42 - Logiciel: Apple Application Support
    O42 - Logiciel: Apple Software Update
    O42 - Logiciel: Archiveur WinRAR
    O42 - Logiciel: Assistant de connexion Windows Live
    O42 - Logiciel: Codec Pack Suite
    O42 - Logiciel: Galerie de photos Windows Live
    O42 - Logiciel: Google Toolbar for Internet Explorer
    O42 - Logiciel: Google Update Helper
    O42 - Logiciel: Google Earth
    O42 - Logiciel: HP Customer Experience Enhancements
    O42 - Logiciel: HP Customer Feedback
    O42 - Logiciel: HP Customer Participation Program 8.0
    O42 - Logiciel: HP Easy Setup - Frontend
    O42 - Logiciel: HP Imaging Device Functions 8.0
    O42 - Logiciel: HP OCR Software 8.0
    O42 - Logiciel: HP On-Screen Cap/Num/Scroll Lock Indicator
    O42 - Logiciel: HP Photosmart Essential
    O42 - Logiciel: HP Photosmart Essential 2.0
    O42 - Logiciel: HP Photosmart.All-In-One Driver Software 8.0 .A
    O42 - Logiciel: HP Picasso Media Center Add-In
    O42 - Logiciel: HP Product Assistant
    O42 - Logiciel: HP Solution Center 8.0
    O42 - Logiciel: HP Update
    O42 - Logiciel: HPSSupply
    O42 - Logiciel: Hercules Dualpix HD
    O42 - Logiciel: Hercules Webcam Station Evolution
    O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    O42 - Logiciel: Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    O42 - Logiciel: Installation Windows Live
    O42 - Logiciel: Junk Mail filter update
    O42 - Logiciel: MSVCRT
    O42 - Logiciel: MSXML 4.0 SP2 (KB954430)
    O42 - Logiciel: MSXML 4.0 SP2 (KB973688)
    O42 - Logiciel: Microsoft .NET Framework 3.5 Language Pack SP1 - fra
    O42 - Logiciel: Microsoft .NET Framework 3.5 SP1
    O42 - Logiciel: Microsoft Choice Guard
    O42 - Logiciel: Microsoft Office 2007 Service Pack 2 (SP2)
    O42 - Logiciel: Microsoft Office Excel MUI (French) 2007
    O42 - Logiciel: Microsoft Office Home and Student 2007
    O42 - Logiciel: Microsoft Office Live Add-in 1.3
    O42 - Logiciel: Microsoft Office OneNote MUI (French) 2007
    O42 - Logiciel: Microsoft Office PowerPoint MUI (French) 2007
    O42 - Logiciel: Microsoft Office Proof (Arabic) 2007
    O42 - Logiciel: Microsoft Office Proof (Dutch) 2007
    O42 - Logiciel: Microsoft Office Proof (English) 2007
    O42 - Logiciel: Microsoft Office Proof (French) 2007
    O42 - Logiciel: Microsoft Office Proof (German) 2007
    O42 - Logiciel: Microsoft Office Proof (Spanish) 2007
    O42 - Logiciel: Microsoft Office Proofing (French) 2007
    O42 - Logiciel: Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
    O42 - Logiciel: Microsoft Office Shared MUI (French) 2007
    O42 - Logiciel: Microsoft Office Word MUI (French) 2007
    O42 - Logiciel: Microsoft SQL Server 2005 Compact Edition [ENU]
    O42 - Logiciel: Microsoft Silverlight
    O42 - Logiciel: Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    O42 - Logiciel: Microsoft Visual C++ 2005 Redistributable
    O42 - Logiciel: Microsoft Works
    O42 - Logiciel: Module linguistique Microsoft .NET Framework 3.5 SP1- fra
    O42 - Logiciel: NVIDIA Drivers
    O42 - Logiciel: Navman NavDesk 2008
    O42 - Logiciel: Outil de téléchargement Windows Live
    O42 - Logiciel: Outils de diagnostic du matériel
    O42 - Logiciel: Pack sécurité
    O42 - Logiciel: Python 2.4.3
    O42 - Logiciel: QuickTime
    O42 - Logiciel: Realtek High Definition Audio Driver
    O42 - Logiciel: Roxio Activation Module
    O42 - Logiciel: Roxio Creator Audio
    O42 - Logiciel: Roxio Creator Basic v9
    O42 - Logiciel: Roxio Creator Copy
    O42 - Logiciel: Roxio Creator Data
    O42 - Logiciel: Roxio Creator EasyArchive
    O42 - Logiciel: Roxio Creator Tools
    O42 - Logiciel: Roxio Express Labeler 3
    O42 - Logiciel: Roxio MyDVD Basic v9
    O42 - Logiciel: SFR - Kit de connexion
    O42 - Logiciel: SFR - Media Center
    O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB969559)
    O42 - Logiciel: Security Update for 2007 Microsoft Office System (KB973704)
    O42 - Logiciel: Security Update for CAPICOM (KB931906)
    O42 - Logiciel: Security Update for Microsoft Office Excel 2007 (KB973593)
    O42 - Logiciel: Security Update for Microsoft Office PowerPoint 2007 (KB957789)
    O42 - Logiciel: Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
    O42 - Logiciel: Security Update for Microsoft Office system 2007 (972581)
    O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB969613)
    O42 - Logiciel: Security Update for Microsoft Office system 2007 (KB974234)
    O42 - Logiciel: Shareaza 2.5.0.0
    O42 - Logiciel: Solution de clavier multimédia amélioré
    O42 - Logiciel: Spybot - Search & Destroy
    O42 - Logiciel: Update for 2007 Microsoft Office System (KB967642)
    O42 - Logiciel: Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    O42 - Logiciel: Update for Microsoft Office Word 2007 (KB974561)
    O42 - Logiciel: VLC media player 1.0.3
    O42 - Logiciel: Vista Codec Package
    O42 - Logiciel: Windows Live Call
    O42 - Logiciel: Windows Live Communications Platform
    O42 - Logiciel: Windows Live FolderShare
    O42 - Logiciel: Windows Live Mail
    O42 - Logiciel: Windows Live Messenger
    O42 - Logiciel: Windows Live Movie Maker
    O42 - Logiciel: Windows Live Writer
    O42 - Logiciel: muvee autoProducer 6.0

    ---\\
    O44 - LFC:Last File Created 04/12/2009 - 20:10:19 ---A- C:\Windows\PFRO.log
    O44 - LFC:Last File Created 04/12/2009 - 20:10:24 -S-A- C:\Windows\bootstat.dat
    O44 - LFC:Last File Created 04/12/2009 - 20:10:50 ---A- C:\Windows\FSSTM.LOG
    O44 - LFC:Last File Created 04/12/2009 - 20:15:51 ---A- C:\Windows\WindowsUpdate.log
    O44 - LFC:Last File Created 05/11/2009 - 18:36:22 ---A- C:\Windows\System32\mrt.exe
    O44 - LFC:Last File Created 10/11/2009 - 23:08:24 ---A- C:\Windows\System32\QuickTime.qts
    O44 - LFC:Last File Created 10/11/2009 - 23:08:24 ---A- C:\Windows\System32\QuickTimeVR.qtx
    O44 - LFC:Last File Created 12/11/2009 - 09:38:30 ---A- C:\Windows\System32\FNTCACHE.DAT
    O44 - LFC:Last File Created 18/11/2009 - 11:55:55 --HA- C:\Windows\System32\drivers\Msft_User_WpdFs_01_07_00.Wdf
    O44 - LFC:Last File Created 22/11/2009 - 10:45:50 ---A- C:\Windows\setupact.log
    O44 - LFC:Last File Created 26/11/2009 - 08:17:31 ---A- C:\Windows\msxml4-KB973688-enu.LOG
    O44 - LFC:Last File Created 28/11/2009 - 21:02:55 ---A- C:\Windows\System32\PerfStringBackup.INI
    O44 - LFC:Last File Created 28/11/2009 - 21:02:55 ---A- C:\Windows\System32\perfc009.dat
    O44 - LFC:Last File Created 28/11/2009 - 21:02:55 ---A- C:\Windows\System32\perfc00C.dat
    O44 - LFC:Last File Created 28/11/2009 - 21:02:55 ---A- C:\Windows\System32\perfh009.dat
    O44 - LFC:Last File Created 28/11/2009 - 21:02:55 ---A- C:\Windows\System32\perfh00C.dat
    O44 - LFC:Last File Created 29/11/2009 - 10:16:41 ---A- C:\Windows\DirectX.log

    ---\\
    O51 - MPSK:{6f0153bf-6d4d-11de-9ca7-001bb9ddf20b}\Shell\AutoRun\command - wd_windows_tools\WDSetup.exe

    ---\\
    O63 - Logiciel: HijackThis 2.0.2
    O63 - Logiciel: GenProc

    End of the scan: 314 lines

    ----------------------------------------------------------------------
    Sites officiels GenProc : www.alt-shift-return.org et www.genproc.com
    ----------------------------------------------------------------------

    ~~ Fin à 22:03:19 ~~
    0
  3. eZula Messages postés 3509 Statut Contributeur 392
     
    Quelle est exactement la localisation de ce virus ?
    0
    1. TOMY TOM
       
      je ne sais pas?je suis en traint de faire un scan avec le lien du rapport que tu ma fait faire.je te donne des nouvelle des que c est fini j ai encore 70 pour cent a faire.pour info f secure me dit que c est dans le systeme.je ne sais pas si c est sa que tu me demande
      0
  4. eZula Messages postés 3509 Statut Contributeur 392
     
    oui mais si tu peux précise où exactement, par exemple C:\windows\malware.exe
    0
    1. TOMY TOM
       
      le scan que je fait actuellement avec ESET me dit menace detecte:win32/packed.autoit.gen application
      0
    2. TOMY TOM
       
      et 2 iemes fichiers infectes:win32/adware.rk.ab application
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. TOMY TOM
     
    je ne sais pas si tu est encore là.je vais laisser finir le scane de ESET car je ne suis meme pas a 50 pour cent et j ai deja 5 fichier infectes avec cheval de troie en prime.merci pour ton aide cela ma bien servi.je vais te donner des nouvelles sur la reussite ou non.un grand merci.

    a bientot.
    0
  7. eZula Messages postés 3509 Statut Contributeur 392
     
    quand ce sera terminé, poste le rapport demandé
    0