Gros probleme trojan mebroot.mr

Résolu
Bonjour,

Avant j'avais kaspersky comme antivirus, apres un formatage il y a quelques semaines, j'ai decidé d'utiliser nod32... Depuis que je l'ai il me dit que je suis infectée par le trojan mebroot.mbr et dans le journal il y a ecrit ca :
02/01/2010 23:26:20 Analyseur au démarrage secteur d'amorçage secteur MBR de 1. disque physique Win32/Mebroot.mbr cheval de troie erreur pendant le nettoyage - opération indisponible pour ce type d'objet 204DECF850AE43F\Administrateur.

Impossible de nettoyer ou de supprimer... J'ai tenté le machin GMER et le rapport le voila :

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-01-02 17:15:28
Windows 5.1.2600 Service Pack 3
Running: v1f1rrge.exe; Driver: C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\pwpdyfoc.sys

---- Kernel code sections - GMER 1.0.15 ----

.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xF6BFA360, 0x3541AF, 0xE8000020]

---- User code sections - GMER 1.0.15 ----

.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] kernel32.dll!LoadResource 7C80A045 7 Bytes JMP 28001E20 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] kernel32.dll!FindResourceExW 7C80AD18 7 Bytes JMP 28001C60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] kernel32.dll!FindResourceW 7C80BC5E 7 Bytes JMP 28001BE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] kernel32.dll!SizeofResource 7C80BCF9 7 Bytes JMP 28001EE0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] kernel32.dll!FindResourceA 7C80BF19 7 Bytes JMP 28001CF0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] kernel32.dll!LockResource 7C80CD27 5 Bytes JMP 28001F50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] kernel32.dll!CreateEventA 7C83089D 5 Bytes JMP 28001840 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] kernel32.dll!FindResourceExA 7C835F90 7 Bytes JMP 28001D80 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] ADVAPI32.dll!CryptDeriveKey 77DB9FDD 7 Bytes JMP 28001000 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] ADVAPI32.dll!CryptDecrypt 77DBA109 7 Bytes JMP 28001060 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] USER32.dll!GetWindowLongW 7E3988A6 7 Bytes JMP 28006A70 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] USER32.dll!PeekMessageW 7E39929B 5 Bytes JMP 28004630 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] USER32.dll!SetWindowPlacement 7E39DE46 5 Bytes JMP 28005E10 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] USER32.dll!CreateDialogParamW 7E39EA3B 5 Bytes JMP 28006090 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] USER32.dll!LoadImageW 7E3A7B97 5 Bytes JMP 280066E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] USER32.dll!CreateWindowExW 7E3AD0A3 5 Bytes JMP 28003C60 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] USER32.dll!SetWindowRgn 7E3AE528 7 Bytes JMP 28005F50 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] USER32.dll!LoadIconW 7E3AE8BC 5 Bytes JMP 280068D0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] USER32.dll!MessageBoxIndirectW 7E3E64D5 5 Bytes JMP 28006280 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] USER32.dll!TrackPopupMenuEx 7E3ECF62 5 Bytes JMP 28004F10 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] WS2_32.dll!closesocket 719F3E2B 5 Bytes JMP 2800B8C0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] WS2_32.dll!send 719F4C27 5 Bytes JMP 2800B4A0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] WS2_32.dll!WSARecv 719F4CB5 5 Bytes JMP 2800B280 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] WS2_32.dll!recv 719F676F 5 Bytes JMP 2800B0E0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] WS2_32.dll!WSASend 719F68FA 5 Bytes JMP 2800B680 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] SHELL32.dll!Shell_NotifyIconW 7CA3A57E 5 Bytes JMP 280033B0 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] ole32.dll!CoInitializeEx 774BEF7B 5 Bytes JMP 28002260 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] ole32.dll!CoCreateInstance 774C057E 5 Bytes JMP 28002600 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] ole32.dll!CoRegisterClassObject 774D7E90 5 Bytes JMP 28002360 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] WININET.dll!InternetCloseHandle 4408DA49 5 Bytes JMP 2800A240 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] WININET.dll!HttpOpenRequestA 44094331 5 Bytes JMP 28009F00 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] WININET.dll!InternetReadFile 4409ABA4 5 Bytes JMP 2800A090 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\Windows Live\Messenger\msnmsgr.exe[1988] WININET.dll!HttpSendRequestA 4409CD28 5 Bytes JMP 2800A170 C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll (Messenger Plus! Live Add-On/Yuna Software)
.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1996] kernel32.dll!SetUnhandledExceptionFilter 7C8449FD 4 Bytes [C2, 04, 00, 00]

---- Devices - GMER 1.0.15 ----

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys

---- EOF - GMER 1.0.15 ----


Alors je n'y connais rien mais visiblement ya rien dans ce truc la qui dit que je suis infectée non?
Du coup j'ai tenté le mbrfix.exe mais ca ne donne rien... juste une fenetre dos qui se barre et puis le pc commence a planter, il met trois plombes a redemarrer et me rend dingue...

Quelqu'un saurait-il m'aider?
Merci d'avance!
Configuration: Windows XP
Firefox 3.0.16

27 réponses

Résumé de la discussion

Un utilisateur Windows XP relate qu'après le passage d'un antivirus à ESET NOD32, le système signale le cheval de Troie Win32/Mebroot.mbr dans le MBR et le nettoyage échoue. Le récit décrit GMER avec des sections kernel évoquant un rootkit, et l'impossibilité de nettoyer l'objet via MBRfix, tout en mentionnant des ralentissements et des redémarrages. Plusieurs contributeurs proposent des pistes comme mettre à jour les mises à jour de sécurité via IE, relancer RSIT et vérifier HijackThis et le fichier Hosts. Une nuance utile : ces outils servent surtout à diagnostiquer et préparer une remediation, sans garantie d'une solution unique dans ce contexte.

Bobot (l’IA à votre service)
  1. Dans windows xp si vous avez la version légale il y a un anti-virus formidable facile à utiliser, parfait pour les amateurs de chatroom et totalement gratuit...jamais rien prit avec celui-ci alors que avast version gratuite pouvait laisser passer de temps en temps
    0
    1. Je serai toi change d'antivirus deja car nod32 c'est pas cool !!!

      Deja la peut etre tu arivera a le vire , mais surement que le mec a mis la fonction de sont trojan en persistance !!

      Donc tu va impeut galere allor si tu s'est ou est place le virus fais un scan avec Window defender il va le trouver et le suprimer !!

      A oui j'ai oublier je te conseille Avira comme antivirus et Comodo comme un firewall

      Voila dit moi si sa marche !!
      0
      1. Contributeur sécurité
        bonjour

        je ne suis pas un pro de ce genre de bestiole...

        mais essaies de faire ceci (sans garanti)

        /!\ Il faut impérativement désactiver tous tes logiciels de protection pour utiliser ce programme/!\

        * Télécharge mbr.exe de Gmer ici : http://www2.gmer.net/mbr/mbr.exe et enregistre le fichier sur le Bureau.

        * Désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)

        * Double clique sur mbr.exe

        * Un rapport sera généré : mbr.log

        * En cas d'infection, ce message "MBR rootkit code detected" va apparaitre.

        * Pour supprimer le rootkit aller dans le menu Démarrer=> Exécuter et tapez la commande en gras:
        "%userprofile%\Bureau\mbr" -f

        * (veuillez à bien respecter les guillemets)

        * Dans le mbr.log cette ligne apparaitra "original MBR restored successfully !"

        * Réactive tes protections .Poste ce rapport et supprime le ensuite.

        o Pour vérifier désactive tes protections et coupe la connexion. (Antivirus et antispywares, HIPS et autre résident)
        o Relance mbr.exe
        o Réactive tes protections.
        o Le nouveau mbr.log devrait être celui-ci :
        o Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
        o device: opened successfully
        user: MBR read successfully
        kernel: MBR read successfully
        user & kernel MBR OK

        0
        1. je suis bien infectée ... la je suis en mode sans echec sinon je n'arrivais pas a lancer le mbr.exe ...
          donc il dit :

          Stealth MBR rootkit/Mebroot/Sinoval detector 0.3.7 by Gmer, http://www.gmer.net

          device : opened successfully
          user: MBR read successfully
          kernel : MBR read successfully
          user & kernel MBR OK
          copy of MBR has been found in sector 0x044ED9D3
          malicious code sector 0x044ED9D6 !
          PE file found in sector at 0x044ED9EC !

          J'ai tenté la commade "%userprofile%\Bureau\mbr" -f mais ca me dit que mbr n'est pas une application valide...
          Que puis-je faire?

          0
          1. Contributeur sécurité
            ok

            on va faire ca dans l'ordre...

            • Télécharge Random's System Information Tool (RSIT) de Random/Random.

            http://images.malwareremoval.com/random/RSIT.exe

            • Enregistre le sur ton Bureau.

            • Double clique sur RSIT.exe pour lancer l'outil.

            • Clique sur "Continue" à l'écran Disclaimer.

            • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

            et tu devras accepter la licence.

            • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

            Les rapports se trouvent à cet endroit:
            C:\rsit\info.txt
            C:\rsit\log.txt

            0
            1. voici le log.txt (par contre, rsit a eut l'air de planter et quand g fait une fin de tache, les deux raaports sont apparus alors j'espere qu'ils sont complets...)

              log.txt :

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by Administrateur at 2010-01-03 12:47:36
              Microsoft Windows XP Professionnel Service Pack 3
              System drive C: has 26 GB (74%) free of 35 GB
              Total RAM: 1023 MB (63% free)

              ======Registry dump======

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
              Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
              Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-12-28 41760]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E5A1691B-D188-4419-AD02-90002030B8EE}]
              FlashFXP Helper for Internet Explorer - C:\PROGRA~1\FlashFXP\IEFlash.dll [2008-06-16 191096]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
              JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-12-28 73728]

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
              "nwiz"=nwiz.exe /install []
              "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-01-16 13680640]
              "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-01-16 86016]
              "egui"=C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe [2008-03-13 1443072]
              "EasyTuneV"=C:\Program Files\Gigabyte\ET5\ETcall.exe [2007-04-26 24576]
              "Raccourci vers la page des propriétés de High Definition Audio"=HDAShCut.exe []
              "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-12-28 149280]
              "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-11-25 81000]

              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
              "TaskSwitchXP"=C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe [2006-08-04 62976]
              "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-08-24 15360]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
              C:\WINDOWS\system32\WgaLogon.dll [2008-08-24 200064]

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
              WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\wpdshserviceobj.dll [2008-08-24 133632]

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
              "dontdisplaylastusername"=0
              "legalnoticecaption"=
              "legalnoticetext"=
              "shutdownwithoutlogon"=1
              "undockwithoutlogon"=1

              [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
              "NoDriveTypeAutoRun"=145
              "NoSMHelp"=1

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
              "HonorAutoRunSetting"=

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
              "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
              "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
              "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
              "C:\Program Files\ma-config.com\maconfservice.exe"="C:\Program Files\ma-config.com\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
              "C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"
              "C:\Program Files\Java\jre6\bin\java.exe"="C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java(TM) Platform SE binary"

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
              "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
              "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
              "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live FolderShare"
              "C:\Program Files\FlashFXP\FlashFXP.exe"="C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3"

              ======List of files/folders created in the last 1 months======

              2010-01-03 12:44:33 ----D---- C:\Program Files\trend micro
              2010-01-03 12:44:32 ----D---- C:\rsit
              2010-01-03 00:16:29 ----A---- C:\WINDOWS\system32\MSVCR71.dll
              2010-01-03 00:16:29 ----A---- C:\WINDOWS\system32\MSVCP71.dll
              2010-01-03 00:16:29 ----A---- C:\WINDOWS\system32\MFC71.dll
              2010-01-03 00:16:29 ----A---- C:\WINDOWS\system32\aswBoot.exe
              2010-01-03 00:16:27 ----D---- C:\Program Files\Alwil Software
              2010-01-01 14:32:38 ----D---- C:\Documents and Settings\Administrateur\Application Data\vlc
              2010-01-01 14:32:10 ----D---- C:\Program Files\VideoLAN
              2010-01-01 02:25:22 ----D---- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
              2010-01-01 02:25:12 ----D---- C:\Program Files\Messenger Plus! Live
              2009-12-31 21:18:25 ----D---- C:\Program Files\FlashFXP
              2009-12-31 21:18:24 ----D---- C:\Documents and Settings\All Users\Application Data\FlashFXP
              2009-12-29 14:48:50 ----D---- C:\WINDOWS\Sun
              2009-12-28 18:20:42 ----A---- C:\WINDOWS\system32\javaws.exe
              2009-12-28 18:20:42 ----A---- C:\WINDOWS\system32\javaw.exe
              2009-12-28 18:20:42 ----A---- C:\WINDOWS\system32\deploytk.dll
              2009-12-28 18:20:41 ----A---- C:\WINDOWS\system32\java.exe
              2009-12-28 18:20:29 ----D---- C:\Program Files\Java
              2009-12-28 18:19:45 ----D---- C:\Documents and Settings\Administrateur\Application Data\Sun
              2009-12-19 21:41:32 ----A---- C:\MbrFix.exe
              2009-12-19 21:39:58 ----A---- C:\WINDOWS\ntbtlog.txt
              2009-12-17 19:03:08 ----A---- C:\WINDOWS\system32\sfman32.dll
              2009-12-17 19:03:08 ----A---- C:\WINDOWS\system32\sblfx.dll
              2009-12-17 19:03:07 ----A---- C:\WINDOWS\system32\devldr32.exe
              2009-12-17 19:03:07 ----A---- C:\WINDOWS\system32\devcon32.dll
              2009-12-17 19:03:07 ----A---- C:\WINDOWS\system32\ctwdm32.dll
              2009-12-17 17:46:32 ----D---- C:\WINDOWS\system32\XPSViewer
              2009-12-17 17:46:29 ----D---- C:\Program Files\MSBuild
              2009-12-17 17:46:27 ----D---- C:\WINDOWS\system32\en-US
              2009-12-17 17:46:23 ----D---- C:\Program Files\Reference Assemblies
              2009-12-17 17:46:06 ----N---- C:\WINDOWS\system32\spmsg.dll
              2009-12-17 17:46:06 ----A---- C:\WINDOWS\system32\spupdsvc.exe
              2009-12-17 17:46:03 ----N---- C:\WINDOWS\system32\prntvpt.dll
              2009-12-17 17:46:02 ----N---- C:\WINDOWS\system32\xpssvcs.dll
              2009-12-17 17:46:02 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
              2009-12-17 17:46:02 ----D---- C:\508b8f6ee74c525945
              2009-12-17 16:36:07 ----A---- C:\WINDOWS\system32\HdAudRes.dll
              2009-12-17 16:35:14 ----A---- C:\WINDOWS\system32\HdAProp.dll
              2009-12-17 16:33:51 ----SHD---- C:\RECYCLER
              2009-12-17 15:34:28 ----D---- C:\Program Files\Gigabyte
              2009-12-17 15:34:23 ----A---- C:\WINDOWS\IsUninst.exe
              2009-12-17 14:57:35 ----D---- C:\pnp
              2009-12-17 14:26:19 ----D---- C:\WINDOWS\8AAB4176A747493AA42CB63CFADFD8E3.TMP
              2009-12-17 14:25:46 ----D---- C:\WINDOWS\nview
              2009-12-17 13:39:07 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
              2009-12-17 13:30:09 ----A---- C:\WINDOWS\system32\muweb.dll
              2009-12-17 13:30:09 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
              2009-12-17 13:30:09 ----A---- C:\WINDOWS\system32\mucltui.dll

              ======List of files/folders modified in the last 1 months======

              2010-01-03 12:44:33 ----D---- C:\Program Files
              2010-01-03 12:40:49 ----D---- C:\Program Files\Mozilla Firefox
              2010-01-03 12:37:25 ----D---- C:\WINDOWS\Temp
              2010-01-03 00:24:26 ----D---- C:\WINDOWS\system32\config
              2010-01-03 00:17:18 ----A---- C:\WINDOWS\SchedLgU.Txt
              2010-01-03 00:16:58 ----D---- C:\WINDOWS\system32\drivers
              2010-01-03 00:16:56 ----D---- C:\WINDOWS\system32
              2010-01-01 14:43:22 ----D---- C:\WINDOWS\system32\CatRoot2
              2009-12-30 11:10:28 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
              2009-12-29 14:48:50 ----D---- C:\WINDOWS
              2009-12-29 14:26:20 ----SHD---- C:\WINDOWS\Installer
              2009-12-29 14:26:20 ----D---- C:\Program Files\ma-config.com
              2009-12-29 14:26:20 ----D---- C:\Documents and Settings\All Users\Application Data\ma-config.com
              2009-12-17 19:13:52 ----D---- C:\WINDOWS\Microsoft.NET
              2009-12-17 19:13:44 ----RSD---- C:\WINDOWS\assembly
              2009-12-17 19:04:51 ----D---- C:\WINDOWS\security
              2009-12-17 17:53:08 ----D---- C:\WINDOWS\inf
              2009-12-17 17:49:32 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
              2009-12-17 17:49:20 ----D---- C:\WINDOWS\WinSxS
              2009-12-17 17:46:26 ----RSD---- C:\WINDOWS\Fonts
              2009-12-17 17:46:11 ----D---- C:\WINDOWS\system32\spool
              2009-12-17 17:46:09 ----D---- C:\WINDOWS\system32\dllcache
              2009-12-17 17:46:05 ----D---- C:\WINDOWS\system32\CatRoot
              2009-12-17 17:40:33 ----D---- C:\WINDOWS\SoftwareDistribution
              2009-12-17 14:30:45 ----D---- C:\WINDOWS\Help
              2009-12-17 14:26:13 ----D---- C:\Program Files\Fichiers communs\Wise Installation Wizard
              2009-12-17 14:23:52 ----D---- C:\NVIDIA

              ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

              R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-11-25 48560]
              R1 epfwtdir;epfwtdir; C:\WINDOWS\system32\DRIVERS\epfwtdir.sys [2008-03-13 33800]
              R3 rtl8139;Pilote NT de carte Realtek PCI Fast Ethernet à base RTL8139(A/B/C); C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2008-04-13 20992]
              R3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-08-24 32128]
              R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
              R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
              R3 usbuhci;Pilote miniport de contrôleur hôte universel USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
              S1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-11-25 27408]
              S1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-11-25 114768]
              S1 easdrv;easdrv; C:\WINDOWS\system32\DRIVERS\easdrv.sys [2008-03-13 29704]
              S1 intelppm;Pilote de processeur Intel; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 40576]
              S2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-11-25 20560]
              S2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-11-25 94160]
              S2 eamon;EAMON; C:\WINDOWS\system32\DRIVERS\eamon.sys [2008-03-13 40456]
              S3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
              S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-11-25 23120]
              S3 CCDECODE;Décodeur sous-titre fermé; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
              S3 ctljystk;Creative SBLive! Port de jeux; C:\WINDOWS\system32\DRIVERS\ctljystk.sys [2001-08-17 3712]
              S3 driverhardwarev2;driverhardwarev2; \??\C:\Program Files\ma-config.com\Drivers\driverhardwarev2.sys []
              S3 emu10k;Creative SB Live! (WDM); C:\WINDOWS\system32\drivers\emu10k1m.sys [2001-08-17 283904]
              S3 emu10k1;Pilote du Gestionnaire d'interface Creative (WDM); C:\WINDOWS\system32\drivers\ctlfacem.sys [2001-08-17 6912]
              S3 ET5Drv;ET5Drv; \??\C:\WINDOWS\system32\Drivers\ET5Drv.sys []
              S3 HdAudAddService;Pilote de fonction Microsoft UAA pour Service High Definition Audio; C:\WINDOWS\system32\drivers\HdAudio.sys [2008-08-24 145920]
              S3 HDAudBus;Pilote de bus Microsoft UAA pour High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-08-24 144384]
              S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys []
              S3 NABTSFEC;Codec NABTS/FEC VBI; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
              S3 NdisIP;Connection TV/vidéo Microsoft; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
              S3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
              S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-01-16 6305120]
              S3 sfman;Pilote du Gestionnaire SoundFont Creative (WDM); C:\WINDOWS\system32\drivers\sfmanm.sys [2001-08-17 36480]
              S3 SLIP;Détrameur décalage BDA; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
              S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
              S3 usbaudio;Pilote USB audio (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
              S3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
              S3 usbvideo;Périphérique vidéo USB (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-13 121984]
              S3 WSTCODEC;Codec Teletext standard; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
              S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2008-08-24 77568]
              S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2008-08-24 82944]
              S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

              ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

              S2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-11-25 18752]
              S2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-11-25 138680]
              S2 ekrn;Eset Service; C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe [2008-03-13 472320]
              S2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-12-28 153376]
              S2 NOD32FiXTemDono;Eset Nod32 Boot; C:\WINDOWS\system32\regedt32.exe [2008-08-24 29696]
              S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-01-16 163908]
              S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
              S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-11-25 254040]
              S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-11-25 352920]
              S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
              S3 EhttpSrv;Eset HTTP Server; C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe [2008-03-13 19200]
              S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
              S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
              S3 maconfservice;Ma-Config Service; C:\Program Files\ma-config.com\maconfservice.exe [2009-12-17 243056]
              S3 WMPNetworkSvc;Service Partage réseau du Lecteur Windows Media; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-11-03 918016]
              S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-08-24 14336]
              S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]

              -----------------EOF-----------------
              0
              1. et voici info.txt :

                info.txt logfile of random's system information tool 1.06 2010-01-03 12:45:11

                ======Uninstall list======

                -->MsiExec /X{B83FC356-B7C0-441F-8A4D-D71E088E7974}
                Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
                Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
                Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
                Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
                avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
                EasyTune5-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Gigabyte\ET5\Uninst.isu" -c"C:\Program Files\Gigabyte\ET5\uninstdrv.dll"
                ESET NOD32 Antivirus-->MsiExec.exe /I{855AF172-B32E-4A74-AC95-E798DD784ABC}
                FlashFXP v3-->"C:\Program Files\FlashFXP\Uninstall.exe" "C:\Program Files\FlashFXP\install.log" -u
                Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
                HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
                Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
                Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
                Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
                Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
                Java(TM) 6 Update 17-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216017FF}
                Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
                Ma-Config.com-->MsiExec.exe /X{18754BA4-4F0C-4E6E-888B-9496AFA05F43}
                Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
                Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
                Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
                Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
                Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
                Microsoft .NET Framework 3.5 SP1-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
                Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
                Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
                Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
                Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
                Module de prise en charge linguistique de Microsoft .NET Framework 2.0 - FRA-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0 Language Pack - FRA\install.exe
                Mozilla Firefox (3.0.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                Mozilla Thunderbird (2.0.0.14)-->C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
                MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
                Nero 8 Lite 8.3.2.1-->"C:\Program Files\Nero\unins000.exe"
                NOD32 v3.0.642 FiX1.2 by TemDono (31 days remaining forever up -->"C:\Program Files\ESET\ESET NOD32 Antivirus\unins000.exe"
                NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
                NVIDIA PhysX-->MsiExec.exe /X{B83FC356-B7C0-441F-8A4D-D71E088E7974}
                Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
                Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
                TaskSwitchXP-->C:\Program Files\TaskSwitchXP\uninst.exe
                VideoLAN VLC media player 0.8.6c-->C:\Program Files\VideoLAN\VLC\uninstall.exe
                Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
                Windows Live Communications Platform-->MsiExec.exe /I{ED00D08A-3C5F-488D-93A0-A04F21F23956}
                Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
                Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
                Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
                Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

                ======Hosts File======

                127.0.0.1 localhost
                127.0.0.1 ad.a8.net
                127.0.0.1 asy.a8ww.net
                127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
                127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
                127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
                127.0.0.1 phpadsnew.abac.com
                127.0.0.1 a.abnad.net
                127.0.0.1 b.abnad.net
                127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]

                ======Security center information======

                AV: avast! antivirus 4.8.1368 [VPS 100102-1]
                AV: ESET NOD32 Antivirus 3.0

                ======System event log======

                Computer Name: 204DECF850AE43F
                Event Code: 6011
                Message: Le nom NetBIOS et le nom de l'hôte DNS de cet ordinateur ont été modifiés de MACHINENAME vers 204DECF850AE43F.

                Record Number: 5
                Source Name: EventLog
                Time Written: 20091118163707.000000+060
                Event Type: Informations
                User:

                Computer Name: MACHINENAME
                Event Code: 2
                Message: Pendant la validation de \Device\Serial0 en tant que port série, une FIFO a été détectée. La FIFO sera utilisée.

                Record Number: 4
                Source Name: Serial
                Time Written: 20091118173110.000000+060
                Event Type: Informations
                User:

                Computer Name: MACHINENAME
                Event Code: 2
                Message: Pendant la validation de \Device\Serial1 en tant que port série, une FIFO a été détectée. La FIFO sera utilisée.

                Record Number: 3
                Source Name: Serial
                Time Written: 20091118173110.000000+060
                Event Type: Informations
                User:

                Computer Name: MACHINENAME
                Event Code: 6005
                Message: Le service d'Enregistrement d'événement a démarré.

                Record Number: 2
                Source Name: EventLog
                Time Written: 20091118173048.000000+060
                Event Type: Informations
                User:

                Computer Name: MACHINENAME
                Event Code: 6009
                Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 3 Multiprocessor Free.

                Record Number: 1
                Source Name: EventLog
                Time Written: 20091118173048.000000+060
                Event Type: Informations
                User:

                =====Application event log=====

                Computer Name: 204DECF850AE43F
                Event Code: 1000
                Message: Les compteurs de performances pour le service MSDTC (MSDTC) ont été chargés.
                Les données d'enregistrement contiennent les nouvelles valeurs d'index
                assignées à ce service.

                Record Number: 5
                Source Name: LoadPerf
                Time Written: 20091118163849.000000+060
                Event Type: Informations
                User:

                Computer Name: 204DECF850AE43F
                Event Code: 1000
                Message: Les compteurs de performances pour le service TermService (Services Terminal Server) ont été chargés.
                Les données d'enregistrement contiennent les nouvelles valeurs d'index
                assignées à ce service.

                Record Number: 4
                Source Name: LoadPerf
                Time Written: 20091118163847.000000+060
                Event Type: Informations
                User:

                Computer Name: 204DECF850AE43F
                Event Code: 1000
                Message: Les compteurs de performances pour le service RemoteAccess (Routage et accès distant) ont été chargés.
                Les données d'enregistrement contiennent les nouvelles valeurs d'index
                assignées à ce service.

                Record Number: 3
                Source Name: LoadPerf
                Time Written: 20091118163748.000000+060
                Event Type: Informations
                User:

                Computer Name: 204DECF850AE43F
                Event Code: 1000
                Message: Les compteurs de performances pour le service PSched (PSched) ont été chargés.
                Les données d'enregistrement contiennent les nouvelles valeurs d'index
                assignées à ce service.

                Record Number: 2
                Source Name: LoadPerf
                Time Written: 20091118163732.000000+060
                Event Type: Informations
                User:

                Computer Name: 204DECF850AE43F
                Event Code: 1000
                Message: Les compteurs de performances pour le service RSVP (QoS RSVP) ont été chargés.
                Les données d'enregistrement contiennent les nouvelles valeurs d'index
                assignées à ce service.

                Record Number: 1
                Source Name: LoadPerf
                Time Written: 20091118163713.000000+060
                Event Type: Informations
                User:

                ======Environment variables======

                "ComSpec"=%SystemRoot%\system32\cmd.exe
                "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
                "windir"=%SystemRoot%
                "FP_NO_HOST_CHECK"=NO
                "OS"=Windows_NT
                "PROCESSOR_ARCHITECTURE"=x86
                "PROCESSOR_LEVEL"=15
                "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 4 Stepping 1, GenuineIntel
                "PROCESSOR_REVISION"=0401
                "NUMBER_OF_PROCESSORS"=2
                "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
                "TEMP"=%SystemRoot%\TEMP
                "TMP"=%SystemRoot%\TEMP
                "SAFEBOOT_OPTION"=NETWORK

                -----------------EOF-----------------
                0
                1. ya un autre souci depuis hier soir, alors je sais pas si ca vient de l'installation d'avast mais je ne peux plus lancer windows en mode normal car il plnate au bout de 30 secondes apres etre arrivé sur le bureau... du coup je suis en mode ss echec... ca vient du virus ou d'avast a votre avis?
                  0
                  1. Je crois sa doit venir du virus sa doit etre une fonction .bat qui te fait planter l'ordi au bout de 30 seconde !!
                    Mais je suis pas sur je suis pas devant ton ecrant !!

                    Si on ne s'est jamais tu arive a retourner sans que sa plante fait un scan tout de suite avec avast !!

                    Au pire si tu a les CD de reinstalation sa te serai utile *
                    0
                    1. Contributeur sécurité
                      ok

                      me manque une partie du rapport

                      mais d'apres ce que je vois ca ne sent pas bon

                      évites d'utiliser trop ton pc

                      et fais ceci

                      ▶ Téléchargez Dr.Web CureIt! sur ton Bureau :
                      ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe

                      ▶ Double-cliquez sur drweb-cureit.exe et cliquez sur Commencer le scan.
                      ▶ Ce scan rapide permet l'analyse des processus chargés en mémoire; s'il trouve des processus infectés, cliquez sur le bouton Oui pour Tout à l'invite.
                      ▶ Lorsque le scan rapide est terminé, cliquez sur Options > Changer la configuration.
                      ▶ Choisissez l'onglet Scanner, et décochez Analyse heuristique.
                      ▶ De retour à la fenêtre principale : choisissez Analyse complète.
                      ▶ Cliquez la flèche verte sur la droite et le scan débutera. Une publicité apparaît quelquefois, fermez-la.
                      ▶ Cliquez Oui pour Tout si un fichier est détecté.
                      ▶ A la fin du scan, si des infections sont trouvées, cliquez sur Tout sélectionner, puis sur Désinfecter. Si la désinfection est impossible, cliquez sur Quarantaine.
                      ▶ Au menu principal de l'outil, en haut à gauche, cliquez sur le menu Fichier et choisissez Enregistrer le rapport.
                      ▶ Sauvegardez le rapport sur votre Bureau. Ce dernier se nommera DrWeb.csv.
                      ▶ Fermez Dr.Web CureIt!
                      ▶ Redémarrez votre ordinateur (très important) car certains fichiers peuvent être déplacés/réparés au redémarrage.
                      ▶ Postez (Copiez/Collez) le contenu du rapport de l'outil Dr.Web dans un bloc note

                      Ensuite :

                      ▶ Rendez-vous à cette adresse d'hébergement gratuit : http://www.cijoint.fr/
                      ▶ Cliquez sur parcourir, chercher rapport DrWeb.txt puis sur cliquez ici pour déposer le fichier
                      ▶ Une fois le lien crée, faite un clique droit dessus et copier l'adresse du lien pour venir le coller dans votre réponse

                      0
                      1. ok donc voici le lien ou est le rapport...

                        http://www.cijoint.fr/cjlink.php?file=cj201001/cijDGa2j88.txt
                        0
                        1. bon j'ai desinstallé avast car c'etait lui qui me fesait planter le pc... c deja un petit pas...
                          0
                          1. Contributeur sécurité
                            E:\Save Disk dur\Mes progs\Divers;Win32.Virut.56;Désinfecté.

                            c'est ce qu'il y a de pire sur le marcher

                            telecharges hijackthis

                            https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/

                            L’exécuter puis sur "Do a system scan and save a logfile" (cf. démo)
                            faire un copier-coller du log entier sur le forum

                            Démo : (Merci a Balltrap34 pour cette réalisation)
                            http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
                            0
                            1. merci beaucoup pour votre aide ;) ! Voici le rapport :

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 12:08:03, on 04/01/2010
                              Platform: Windows XP SP3 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.20861)
                              Boot mode: Safe mode with network support

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\Program Files\trend micro\HijackThis\HijackThis.exe
                              C:\WINDOWS\system32\taskmgr.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Ultimate Edition
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
                              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
                              O4 - HKLM\..\Run: [EasyTuneV] C:\Program Files\Gigabyte\ET5\ETcall.exe
                              O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAShCut.exe
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKCU\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKUS\S-1-5-19\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE RÉSEAU')
                              O4 - HKUS\S-1-5-18\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'SYSTEM')
                              O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SYSTEM')
                              O4 - HKUS\.DEFAULT\..\Run: [TaskSwitchXP] C:\Program Files\TaskSwitchXP\TaskSwitchXP.exe (User 'Default user')
                              O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'Default user')
                              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                              O14 - IERESET.INF: START_PAGE_URL=https://www.google.fr/?gws_rd=ssl
                              O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
                              O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
                              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                              0
                              1. Contributeur sécurité
                                Téléchargez MalwareByte's Anti-Malware

                                http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                                . Enregistres le sur le bureau
                                . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
                                . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
                                . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
                                . Une fois la mise à jour terminé
                                . Rend-toi dans l'onglet, Recherche
                                . Sélectionnes Exécuter un examen complet
                                . Cliques sur Rechercher
                                . Le scan démarre.
                                . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
                                . Cliques sur Ok pour poursuivre.
                                . Si des malwares ont été détectés, clique sur Afficher les résultats
                                . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
                                . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
                                . Rends toi dans l'onglet rapport/log
                                . Tu cliques dessus pour l'afficher, une fois affiché
                                . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
                                . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
                                . tu cliques droit dans le cadre de la reponse et coller

                                Si tu as besoin d'aide regarde ces tutoriels :
                                Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam
                                0
                                1. voila :

                                  Malwarebytes' Anti-Malware 1.43
                                  Version de la base de données: 3491
                                  Windows 5.1.2600 Service Pack 3 (Safe Mode)
                                  Internet Explorer 7.0.5730.13

                                  04/01/2010 12:54:38
                                  mbam-log-2010-01-04 (12-54-38).txt

                                  Type de recherche: Examen complet (C:\|E:\|)
                                  Eléments examinés: 176730
                                  Temps écoulé: 13 minute(s), 1 second(s)

                                  Processus mémoire infecté(s): 0
                                  Module(s) mémoire infecté(s): 0
                                  Clé(s) du Registre infectée(s): 0
                                  Valeur(s) du Registre infectée(s): 0
                                  Elément(s) de données du Registre infecté(s): 2
                                  Dossier(s) infecté(s): 0
                                  Fichier(s) infecté(s): 2

                                  Processus mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Module(s) mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Clé(s) du Registre infectée(s):
                                  (Aucun élément nuisible détecté)

                                  Valeur(s) du Registre infectée(s):
                                  (Aucun élément nuisible détecté)

                                  Elément(s) de données du Registre infecté(s):
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoSMHelp (Hijack.Help) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                                  Dossier(s) infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Fichier(s) infecté(s):
                                  E:\RECYCLER\S-1-5-21-789336058-287218729-1644491937-500\Dc3.1284\nfoviewer.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                  E:\Save Disk dur\Mes progs\Divers\FlashFXP_v3.7.4.1284\nfoviewer.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                  0
                                  1. Contributeur sécurité
                                    ok

                                    comment ce comporte le pc ?

                                    0
                                    1. bonjour à vous 2
                                      ======Hosts File======

                                      127.0.0.1 localhost
                                      127.0.0.1 ad.a8.net
                                      127.0.0.1 asy.a8ww.net
                                      127.0.0.1 www.abx4.com #[Adware.ABXToolbar]
                                      127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
                                      127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
                                      127.0.0.1 phpadsnew.abac.com
                                      127.0.0.1 a.abnad.net
                                      127.0.0.1 b.abnad.net
                                      127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]


                                      Hijackthis exécuté en mode sans échec, c'est normal ?
                                      0
                                  2. et bien, depuis que j'ai fait tout ce que vous aviez dit, Nod 32 ne me dis plus rien et mon pc a l'air de tourner normalement... y a t-il un moyen sur et certain de savoir si mon pc est desinfecté du mebroot? Et y a t-il encore quelque chose a faire ou cela vous semble ok?
                                    0
                                    1. Contributeur sécurité
                                      pour le savoir

                                      relances RSIT et postes juste le rapport log
                                      0
                                      • 1
                                      • 2