HEEEEEELP!!! Trojan et spyware...

Résolu/Fermé
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010 - 21 juil. 2010 à 18:02
 Utilisateur anonyme - 2 août 2010 à 17:10
Bonjour,



HELP, trojan et spyware

Bonjour,


Depuis quelques temps, mon ordi bipe à tout va, via antivir qui signale un "trojan zwangi je ne sais plus quoi", ainsi qu'un "spyware.gen 2 ".
J'ai navigué sur le site et ai déjà effectué quelques actions mais je ne suis pas sure qu'elles aideront... Je ne suis pas super calée, alors un grand MERCI à ceux qui prendront le temps de me lire et de m'aider s'ils le peuvent...

J'ai déjà désinstallé pleins de programmes que je n'utilisais pas (et qui étaient ptet bien responsables de pleins de pop up intempestives, autre souci... Mais il m'en reste une que je n'arrive pas à faire dégager définitivement, une hotbar wether quelque chose).
Ensuite, j'ai lancé c cleaner et hijackthis (dont je poste le bilan ci dessous). Et puis, comme j'ai tout pompé au forum, j'ai installé malwarebytes qui me fait mon analyse en ce moment.
Pourriez vous m'indiquer si je vais dans la bonne direction et ce que je dois faire de mon bilan ci dessous?
Merci beaucoup,

Anne, désespérée

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:26:58, on 21/07/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18928)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Goto Software\Vaderetro_mgr.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\Users\MORNAS\AppData\Local\ukbhdlb.exe
C:\Program Files\Panasonic\VideoCamSuite\VideoCamSuiteAutoStart.exe
C:\Program Files\GigaTribe\gigatribe.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Orange HSS\Launcher\Launcher.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\Orange HSS\connectivity\connectivitymanager.exe
C:\Program Files\Orange HSS\systray\systrayapp.exe
C:\Program Files\Orange HSS\Deskboard\deskboard.exe
C:\Program Files\Orange HSS\connectivity\CoreCom\CoreCom.exe
C:\Program Files\Orange HSS\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\Program Files\Orange HSS\browser\browser.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Users\MORNAS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9VYPMSB8\HiJackThis[1].exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2405727
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: ShoppingReport2 - {258C9770-1713-4021-8D7E-1F184A2BD754} - C:\Program Files\ShoppingReport2\Bin\2.7.12\ShoppingReport.dll (file missing)
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Skytel] Skytel.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [VadeRetro Outlook] C:\Program Files\Goto Software\Vade Retro\VrMoRegister.exe -s
O4 - HKLM\..\Run: [VRManager] C:\Program Files\Common Files\Goto Software\Vaderetro_Mgr.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [HotbarSA] "C:\Program Files\Hotbar\bin\11.0.175.0\HotbarSA.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [mcwqa] "c:\users\mornas\appdata\local\mcwqa.exe" mcwqa
O4 - HKCU\..\Run: [EPSON SX100 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIEDE.EXE /FU "C:\Windows\TEMP\E_SE4FD.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe"
O4 - HKCU\..\Run: [WeatherDPA] "C:\Program Files\Hotbar\bin\11.0.175.0\Weather.exe" -auto
O4 - HKCU\..\Run: [ukbhdlb] "c:\users\mornas\appdata\local\ukbhdlb.exe" ukbhdlb
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: GigaTribe.lnk = C:\Program Files\GigaTribe\gigatribe.exe
O4 - Global Startup: Exécution automatique de VideoCam Suite 1.0.lnk = ?
O4 - Global Startup: OFFICE One Startup v7.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: ShopperReports - Compare product prices - {DB38E21A-0133-419d-92AD-ECDFD5244D6D} - C:\Program Files\ShoppingReport2\Bin\2.7.12\ShoppingReport.dll (file missing)
O9 - Extra button: ShopperReports - Compare travel rates - {EB620C54-E229-4942-87CE-E717109FC8C6} - C:\Program Files\ShoppingReport2\Bin\2.7.12\ShoppingReport.dll (file missing)
O13 - Gopher Prefix:
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de délivrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
O16 - DPF: {B79A53C0-1DAC-4636-BACE-FD086A7A79BF} (AdSignerLCContrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerVistaADP-1.1.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {EDFCB7CB-942C-4822-AF14-F0B687409848} (Image Uploader Control) - http://www.mypix.com/importer/ImageUploader4.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: BarDiscover Service - Unknown owner - C:\ProgramData\BarDiscover\bardiscover133.exe (file missing)
O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\System32\bgsvcgen.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: Syntek AVStream USB2.0 WebCam Service (StkSSrv) - Syntek America Inc. - C:\Windows\System32\StkCSrv.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
A voir également:

58 réponses

Utilisateur anonyme
23 juil. 2010 à 00:12
hello refais un scan OTL stp
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
23 juil. 2010 à 21:09
Coucou

Voilà les 2 derniers bilans:
http://www.cijoint.fr/cjlink.php?file=cj201007/cijEQa2PMT.txt

http://www.cijoint.fr/cjlink.php?file=cj201007/cijoloUHzf.txt

Par contre, j'ai cette fenêtre qui s'ouvre toutes les 10 secondes maintenant:
"cette page contient un risque de sécurité non spécifié, voulez vous continuer?", schant que antivir et pare feu sont désactivés...
0
Utilisateur anonyme
23 juil. 2010 à 22:07
* Télécharge ici : USBFIX sur ton bureau



/!\ Désactive provisoirement et seulement le temps de l'utilisation d'USBFIX, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."


sur l'icône Usbfix située sur ton Bureau.
Sur la page, clique sur le bouton :

« Recherche »

/!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

- puis clique sur OK
- Laisse travailler l'outil.
- Poste le rapport qui apparaît à la fin.
le rapport se trouve sur C:\ UsbFix.txt



Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
24 juil. 2010 à 08:55
Bonjour bonjour,

Voilà le rapport, nous branchons juste l'appareil photo et l'imprimante:

############################## | UsbFix 7.017 | [Recherche]

Utilisateur: MORNAS (Administrateur) # PC-DE-MORNAS [ASUSTeK Computer Inc. F5R]
Mis à jour le 22/07/10 par El Desaparecido / C_XX
Lancé à 08:49:08 | 24/07/2010
Site Web: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com

CPU: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
CPU 2: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18928

Pare-feu Windows: Désactivé /!\
RAM -> 1919 Mo
C:\ (%systemdrive%) -> Disque fixe # 75 Go (18 Go libre(s) - 24%) [VistaOS] # NTFS
D:\ -> Disque fixe # 67 Go (64 Go libre(s) - 96%) [DATA] # NTFS
E:\ -> Disque amovible # 488 Mo (283 Mo libre(s) - 58%) [] # FAT
F:\ -> CD-ROM
G:\ -> Disque amovible # 2 Go (2 Go libre(s) - 100%) [] # FAT

################## | Éléments infectieux |

Présent! C:\Users\MORNAS\AppData\Roaming\mdbu.bin

################## | Registre |


################## | Mountpoints2 |

HKCU\.\.\.\.\Explorer\MountPoints2\{13b8da04-8c83-11dd-a984-001e8c61438b}
Shell\AutoRun\Command = I:\LaunchU3.exe -a

HKCU\.\.\.\.\Explorer\MountPoints2\{4d4e8c8c-a86f-11dd-8d0c-001e8c61438b}
Shell\AutoRun\Command = .\run\autorun.exe
Shell\open\Command = .\run\autorun.exe

HKCU\.\.\.\.\Explorer\MountPoints2\{6d49dfd7-0505-11df-b74c-001e8c61438b}
Shell\AutoRun\Command = G:\InstallTomTomHOME.exe


################## | Vaccin |

(!) Cet ordinateur n'est pas vacciné!

################## | E.O.F |
0
Shad || x || Messages postés 323 Date d'inscription dimanche 11 juillet 2010 Statut Membre Dernière intervention 29 juillet 2010 32
Modifié par Shad || x || le 24/07/2010 à 12:04
Salut,

désolé de l'incruste ^^

juste pour faire avancer gen-hackman, enfin..surtout toi nanou ^^


Relance USBFix.exe par clic-droit "exécuter en tant qu'administrateur"

* Clique sur Suppression.
* Une fenêtre te demandera de bancher tous les périphériques externes (clés USB, lecteurs MP3, disques durs externes, etc ...). Branche le matériel puis clique sur OK pour poursuivre.
* Le bureau va disparaitre et ne sera plus accessible tout le temps du scan, c'est normal. Patiente le temps du nettoyage sans l'interrompre.
* A la fin, un rapport va être généré (C:\USBFix.txt).
* Envoie l'intégralité de son contenu dans ta prochaine réponse.
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
24 juil. 2010 à 13:14
Kikou

Y'a pas de souci, merci de t'intéresser à mon pauvre cas!
Voilà le bilan demandé:

############################## | UsbFix 7.017 | [Suppression]

Utilisateur: MORNAS (Administrateur) # PC-DE-MORNAS [ASUSTeK Computer Inc. F5R]
Mis à jour le 22/07/10 par El Desaparecido / C_XX
Lancé à 13:04:28 | 24/07/2010
Site Web: http://pagesperso-orange.fr/NosTools/index.html
Contact: FindyKill.Contact@gmail.com

CPU: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
CPU 2: Intel(R) Core(TM) Duo CPU T2250 @ 1.73GHz
Microsoft® Windows Vista(TM) Édition Familiale Premium (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18928

Pare-feu Windows: Désactivé /!\
RAM -> 1919 Mo
C:\ (%systemdrive%) -> Disque fixe # 75 Go (17 Go libre(s) - 23%) [VistaOS] # NTFS
D:\ -> Disque fixe # 67 Go (64 Go libre(s) - 96%) [DATA] # NTFS
E:\ -> Disque amovible # 488 Mo (283 Mo libre(s) - 58%) [] # FAT
F:\ -> CD-ROM
G:\ -> Disque amovible # 2 Go (2 Go libre(s) - 100%) [] # FAT

################## | Éléments infectieux |

Supprimé! C:\Users\MORNAS\AppData\Roaming\mdbu.bin

################## | Registre |


################## | Mountpoints2 |

Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{13b8da04-8c83-11dd-a984-001e8c61438b}
Supprimé! HKCU\.\.\.\.\Explorer\MountPoints2\{4d4e8c8c-a86f-11dd-8d0c-001e8c61438b}

################## | Listing |

[24/07/2010 - 13:09:44 | SHD ] C:\$RECYCLE.BIN
[21/07/2010 - 06:31:42 | A | 112761] C:\aaw7boot.log
[21/07/2010 - 18:24:57 | A | 10903] C:\Ad-Report-CLEAN[1].txt
[14/12/2007 - 01:58:39 | D ] C:\ADOBE
[22/07/2010 - 19:43:47 | A | 4] C:\autoexec.bat
[24/10/2009 - 11:40:21 | SHD ] C:\Boot
[11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
[18/04/2007 - 11:26:27 | RAS | 8192] C:\BOOTSECT.BAK
[04/04/2007 - 06:01:54 | A | 19] C:\CA13.txt
[18/09/2006 - 23:43:37 | A | 10] C:\config.sys
[14/12/2007 - 03:37:03 | A | 18891] C:\devlist.txt
[02/11/2006 - 15:02:03 | SHD ] C:\Documents and Settings
[21/12/2007 - 20:02:46 | RH | 524288] C:\F5R.BIN
[04/06/2007 - 11:49:55 | RAH | 524288] C:\F5R.ROM
[18/10/2007 - 04:46:33 | A | 16] C:\F5R_Vista.40
[14/12/2007 - 03:33:42 | A | 9] C:\Finish.log
[23/06/2008 - 09:09:40 | SHD ] C:\found.000
[24/07/2010 - 12:50:12 | ASH | 2012471296] C:\hiberfil.sys
[04/01/2010 - 12:26:46 | RASH | 0] C:\IO.SYS
[22/07/2010 - 19:17:57 | D ] C:\Kill'em
[22/07/2010 - 16:55:28 | A | 24803] C:\List'em.txt
[06/08/2008 - 15:47:15 | D ] C:\MC_TMP
[04/01/2010 - 12:26:46 | RASH | 0] C:\MSDOS.SYS
[14/12/2007 - 01:12:55 | RHD ] C:\MSOCache
[07/08/2007 - 23:43:02 | A | 15] C:\NERO.LOG
[14/12/2007 - 01:54:23 | D ] C:\NIS
[17/05/2007 - 05:35:24 | A | 15] C:\NIS2007_A.TXT
[16/03/2007 - 01:18:45 | A | 25] C:\OFFICE2007_A.TXT
[24/07/2010 - 12:50:08 | ASH | 2326269952] C:\pagefile.sys
[13/12/2007 - 12:22:35 | A | 105] C:\Pass.txt
[28/09/2007 - 01:56:05 | A | 947] C:\Patch.LOG
[21/06/2008 - 23:18:25 | D ] C:\PerfLogs
[13/12/2007 - 11:40:06 | D ] C:\Preload
[22/07/2010 - 15:11:09 | RD ] C:\Program Files
[21/07/2010 - 18:24:42 | HD ] C:\ProgramData
[24/05/2007 - 00:43:40 | A | 17] C:\READER_A.TXT
[14/12/2007 - 03:07:11 | A | 420] C:\RHDSetup.log
[01/02/2008 - 16:03:23 | A | 159] C:\Setup.log
[27/04/2008 - 11:09:08 | D ] C:\SPDISK
[16/05/2006 - 02:22:24 | A | 5] C:\Store.LOG
[24/07/2010 - 09:56:19 | SHD ] C:\System Volume Information
[24/07/2010 - 13:09:44 | D ] C:\UsbFix
[24/07/2010 - 13:04:29 | A | 3353] C:\UsbFix.txt
[04/01/2009 - 17:53:38 | RD ] C:\Users
[14/09/2007 - 01:06:04 | A | 23] C:\V53.TXT
[21/07/2010 - 07:37:44 | D ] C:\Windows
[24/07/2010 - 13:05:25 | SHD ] D:\$RECYCLE.BIN
[13/04/2008 - 13:07:26 | D ] D:\FILM
[14/12/2007 - 01:04:46 | SHD ] D:\System Volume Information
[11/05/2006 - 20:30:46 | D ] E:\DCIM
[11/05/2006 - 20:31:16 | D ] E:\MISC
[20/04/2008 - 16:50:42 | AH | 512] E:\NIKON001.DSC

################## | Vaccin |

C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
D:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
E:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)

################## | Upload |

Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC-DE-MORNAS.zip
https://www.ionos.fr/?affiliate_id=77097
Merci de votre contribution.

################## | E.O.F |
0
Shad || x || Messages postés 323 Date d'inscription dimanche 11 juillet 2010 Statut Membre Dernière intervention 29 juillet 2010 32
24 juil. 2010 à 13:35
Ok ;)


Il devrait revenir...je n'en doute pas ^^

Juste un truc avant qu'il continue:

Sur un PC: UN SEUL ANTIVIRUS !

Garde Antivir et vire le reste.
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
24 juil. 2010 à 13:45
euh... j'en aurais donc plusieurs en route en mm temps? C'est vrai que j'en ai essayé quelques uns mais je pensais n'avoir gardé actif que antivir.

Tant qu'on en cause, que conseillerais tu en protection mis à part antivir du coup?

Promis, je fais du ménage dans les antivirus...
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
24 juil. 2010 à 13:54
Alors du coup, j'ai, si je vois bien:

- norton
-hijack this
-malwarebytes
-adaware
-otl
-usbfix
- c cleaner
- avira
-kill them

Koi je garde, koi je vire? Et ceux qu'on garde, comment les utilise -t -on?

Idem, pour tous les rapports d'analyse, est ce que dois les garder? J'en ai dans des dossiers et sur le bureau...
0
Shad || x || Messages postés 323 Date d'inscription dimanche 11 juillet 2010 Statut Membre Dernière intervention 29 juillet 2010 32
24 juil. 2010 à 14:01
Pour ce qui est de malwarebytes, hijackthis, ad-remover, usbfix, otl...tout ça ce sont des outils d'analyse et de suppression. Tu n'a pas à y toucher pour le moment ils seront tous supprimés une fois la désinfection terminée.

Garde ccleaner

Vire norton: http://service1.symantec.com/support/inter/tsgeninfointl.nsf/fr_docid/20050414110429924?OpenDocument&seg=hm&lg=fr&ct=fr

Et il y a encore un bout d'avast, vire le également: https://www.avast.com/fr-fr/uninstall-utility
0
petite entracte lol ^^

▶ Relance List&Kill'em(soit en clic droit "executer en tant que......" pour vista/7),avec le raccourci sur ton bureau.

mais cette fois-ci :

▶ choisis l'option ADD KEY

un document texte va s'ouvrir à l'apparition de : Text Please

▶copie/colle le texte en gras ci-dessous :

"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "UacDisableNotify" /t REG_DWORD /d "0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "InternetSettingsDisableNotify" /t REG_DWORD /d "0"
"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "AutoUpdateDisableNotify" /t REG_DWORD /d "0"



ensuite onglet "Fichier" clic sur enregistrer , puis ferme ce bloc notes

Laisse travailler l'outil

à la fin un rapport s'ouvre ,

▶ poste le resultat
?G3?-?@¢??@?(TM)©®?
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
24 juil. 2010 à 14:15
Hey salut salut!

Pas de souci t'as ben raison de te reposer et de faire autre chose!

Ok je fais tout ca...
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
24 juil. 2010 à 14:18
et voilou, l'était rapide cuici:

¤¤¤¤¤¤¤¤¤¤ Keys :

Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "UacDisableNotify" /t REG_DWORD /d "0"
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "InternetSettingsDisableNotify" /t REG_DWORD /d "0"
Added : HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center" /v "AutoUpdateDisableNotify" /t REG_DWORD /d "0"
0
Utilisateur anonyme
24 juil. 2010 à 14:22
ok refais OTL stp
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
24 juil. 2010 à 14:48
Re coucou

http://www.cijoint.fr/cjlink.php?file=cj201007/cijHJR1wkF.txt

http://www.cijoint.fr/cjlink.php?file=cj201007/cijzwmN1z2.txt

Voiloù
0
si tu as XP => double clique
si tu as Vista ou windows 7 => clic droit "executer en tant que...."


sur OTL.exe pour le lancer.


▶Copie la liste qui se trouve en gras ci-dessous,

▶ colle-la dans la zone sous "Personnalisation" :


:processes
explorer.exe
iexplore.exe
firefox.exe
msnmsgr.exe
Teatimer.exe

:OTL
PRC - [2007/01/09 23:59:32 | 000,108,648 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
PRC - [2007/01/05 02:19:28 | 000,047,712 | ---- | M] (Symantec Corporation) -- C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
SRV - [2008/10/09 14:47:42 | 001,079,176 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsSvc.exe -- (sdCoreService)
SRV - [2008/06/13 17:29:14 | 000,356,920 | ---- | M] (PC Tools) [On_Demand | Stopped] -- C:\Program Files\Spyware Doctor\pctsAuxs.exe -- (sdAuxService)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Show Norton Toolbar) - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll (Symantec Corporation)
O3 - HKU\S-1-5-21-1273562678-3384725392-186920749-1000\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - No CLSID value found.
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab (Reg Error: Key error.)
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:DFC5A2B2

:Reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run]
"iTunesHelper"=-
"QuickTime Task"=-
"Symantec PIF AlertEng"=-
"TkBellExe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer]
"NoDriveTypeAutoRun"=145

:commands
[emptytemp]
[start explorer]
[reboot]


▶ Clique sur "Correction" pour lancer la suppression.


▶ Poste le rapport qui logiquement s'ouvrira tout seul en fin de travail appres le redemarrage.

?G3?-?@¢??@?(TM)©®?
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
24 juil. 2010 à 15:28
Voilà

All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
No active process named iexplore.exe was found!
No active process named firefox.exe was found!
Process msnmsgr.exe killed successfully!
No active process named Teatimer.exe was found!
========== OTL ==========
No active process named ccSvcHst.exe was found!
No active process named AppSvc32.exe was found!
Service sdCoreService stopped successfully!
Service sdCoreService deleted successfully!
C:\Program Files\Spyware Doctor\pctsSvc.exe moved successfully.
Service sdAuxService stopped successfully!
Service sdAuxService deleted successfully!
C:\Program Files\Spyware Doctor\pctsAuxs.exe moved successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1E8A6170-7264-4D0F-BEAE-D42A53123C75}\ not found.
File C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{90222687-F593-4738-B738-FBEE9C7B26DF} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{90222687-F593-4738-B738-FBEE9C7B26DF}\ deleted successfully.
File C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll not found.
Registry value HKEY_USERS\S-1-5-21-1273562678-3384725392-186920749-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-0000-0000-0000-000000000000} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-0000-0000-0000-000000000000}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\Windows\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\iTunesHelper deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\QuickTime Task deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\Symantec PIF AlertEng not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\run\\TkBellExe deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\"NoDriveTypeAutoRun"|145 /E : value set successfully!
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: Default User

User: MORNAS
->Temp folder emptied: 48263258 bytes
->Temporary Internet Files folder emptied: 53993923 bytes
->Java cache emptied: 4002903 bytes
->FireFox cache emptied: 12474 bytes
->Flash cache emptied: 1967625 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 103,00 mb


OTL by OldTimer - Version 3.2.9.1 log created on 07242010_152324

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
0
Utilisateur anonyme
24 juil. 2010 à 15:51
vire les restes de norton avec cet outil :

Télécharge et exécute le Norton Removal Tool.

ensuite :

fais un scan avec antivir et poste le rapport
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
24 juil. 2010 à 16:37
Coucou

Je l'ai fait à l'instant suite au mess de Shad, il m'avait posté un lien pour désinstaller. Je te poste le rapport antivir ce soir, corvée courses, tu me dis si je dois le refaire et que tout n'est pas parti?
0
Utilisateur anonyme
24 juil. 2010 à 16:37
oiui c'est bon j'avais zappé ce passage

à te lire
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
24 juil. 2010 à 19:29
De retour, antivir me sort un message: "scan has detected viruses or unwante prog.
Il me demande si je repair ou cancel all.
On retrouve là dedans mes "adspy gen2" ainsi que "TR/BHO zwangi " avec différents chiffres. Une ptite quinzaine en tout dans la liste.
Koi je fais?
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
25 juil. 2010 à 08:27
Salut salut,
Voilà le bilan antivir

Avira AntiVir Personal
Report file date: samedi 24 juillet 2010 15:57

Scanning for 2566895 virus strains and unwanted programs.

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows Vista
Windows version : (Service Pack 2) [6.0.6002]
Boot mode : Normally booted
Username : SYSTEM
Computer name : PC-DE-MORNAS

Version information:
BUILD.DAT : 9.0.0.422 21701 Bytes 09/03/2010 10:29:00
AVSCAN.EXE : 9.0.3.10 466689 Bytes 13/10/2009 10:26:33
AVSCAN.DLL : 9.0.3.0 40705 Bytes 27/02/2009 09:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 20/02/2009 10:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 27/02/2009 09:58:52
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 06:35:52
VBASE001.VDF : 7.10.1.0 1372672 Bytes 19/11/2009 17:52:28
VBASE002.VDF : 7.10.3.1 3143680 Bytes 20/01/2010 20:10:12
VBASE003.VDF : 7.10.3.75 996864 Bytes 26/01/2010 18:45:48
VBASE004.VDF : 7.10.4.203 1579008 Bytes 05/03/2010 15:08:46
VBASE005.VDF : 7.10.6.82 2494464 Bytes 15/04/2010 18:20:25
VBASE006.VDF : 7.10.7.218 2294784 Bytes 02/06/2010 20:02:39
VBASE007.VDF : 7.10.9.165 4840960 Bytes 23/07/2010 18:41:30
VBASE008.VDF : 7.10.9.166 2048 Bytes 23/07/2010 18:41:30
VBASE009.VDF : 7.10.9.167 2048 Bytes 23/07/2010 18:41:31
VBASE010.VDF : 7.10.9.168 2048 Bytes 23/07/2010 18:41:32
VBASE011.VDF : 7.10.9.169 2048 Bytes 23/07/2010 18:41:33
VBASE012.VDF : 7.10.9.170 2048 Bytes 23/07/2010 18:41:33
VBASE013.VDF : 7.10.9.171 2048 Bytes 23/07/2010 18:41:35
VBASE014.VDF : 7.10.9.172 2048 Bytes 23/07/2010 18:41:35
VBASE015.VDF : 7.10.9.173 2048 Bytes 23/07/2010 18:41:35
VBASE016.VDF : 7.10.9.174 2048 Bytes 23/07/2010 18:41:35
VBASE017.VDF : 7.10.9.175 2048 Bytes 23/07/2010 18:41:35
VBASE018.VDF : 7.10.9.176 2048 Bytes 23/07/2010 18:41:35
VBASE019.VDF : 7.10.9.177 2048 Bytes 23/07/2010 18:41:36
VBASE020.VDF : 7.10.9.178 2048 Bytes 23/07/2010 18:41:36
VBASE021.VDF : 7.10.9.179 2048 Bytes 23/07/2010 18:41:39
VBASE022.VDF : 7.10.9.180 2048 Bytes 23/07/2010 18:41:39
VBASE023.VDF : 7.10.9.181 2048 Bytes 23/07/2010 18:41:39
VBASE024.VDF : 7.10.9.182 2048 Bytes 23/07/2010 18:41:39
VBASE025.VDF : 7.10.9.183 2048 Bytes 23/07/2010 18:41:39
VBASE026.VDF : 7.10.9.184 2048 Bytes 23/07/2010 18:41:39
VBASE027.VDF : 7.10.9.185 2048 Bytes 23/07/2010 18:41:39
VBASE028.VDF : 7.10.9.186 2048 Bytes 23/07/2010 18:41:39
VBASE029.VDF : 7.10.9.187 2048 Bytes 23/07/2010 18:41:39
VBASE030.VDF : 7.10.9.188 2048 Bytes 23/07/2010 18:41:40
VBASE031.VDF : 7.10.9.193 68608 Bytes 23/07/2010 18:41:42
Engineversion : 8.2.4.26
AEVDF.DLL : 8.1.2.0 106868 Bytes 23/04/2010 19:20:12
AESCRIPT.DLL : 8.1.3.41 1364346 Bytes 20/07/2010 18:18:03
AESCN.DLL : 8.1.6.1 127347 Bytes 12/05/2010 17:05:45
AESBX.DLL : 8.1.3.1 254324 Bytes 23/04/2010 19:20:12
AERDL.DLL : 8.1.8.2 614772 Bytes 20/07/2010 18:17:44
AEPACK.DLL : 8.2.3.2 471414 Bytes 20/07/2010 18:17:29
AEOFFICE.DLL : 8.1.1.8 201081 Bytes 21/07/2010 18:15:56
AEHEUR.DLL : 8.1.2.6 2793846 Bytes 20/07/2010 18:17:18
AEHELP.DLL : 8.1.13.2 242039 Bytes 20/07/2010 18:16:30
AEGEN.DLL : 8.1.3.17 385396 Bytes 21/07/2010 18:15:55
AEEMU.DLL : 8.1.2.0 393588 Bytes 23/04/2010 19:20:11
AECORE.DLL : 8.1.16.2 192887 Bytes 20/07/2010 18:16:19
AEBB.DLL : 8.1.1.0 53618 Bytes 23/04/2010 19:20:11
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 07:47:59
AVPREF.DLL : 9.0.3.0 44289 Bytes 26/08/2009 14:14:02
AVREP.DLL : 8.0.0.7 159784 Bytes 18/02/2010 17:46:55
AVREG.DLL : 9.0.0.0 36609 Bytes 05/12/2008 09:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 24/03/2009 14:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 30/01/2009 09:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 28/01/2009 14:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 02/02/2009 07:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 05/12/2008 09:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 15/05/2009 14:39:58
RCTEXT.DLL : 9.0.73.0 86785 Bytes 13/10/2009 11:25:47

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium
Deviating risk categories...........: +APPL,+GAME,+JOKE,+PCK,+PFS,+SPR,

Start of the scan: samedi 24 juillet 2010 15:57

Starting search for hidden objects.
'115406' objects were checked, '0' hidden objects were found.

The scan of running processes will be started
Scan process 'SearchFilterHost.exe' - '1' Module(s) have been scanned
Scan process 'SearchProtocolHost.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'Browser.exe' - '1' Module(s) have been scanned
Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
Scan process 'FTCOMModule.exe' - '1' Module(s) have been scanned
Scan process 'OraConfigRecover.exe' - '1' Module(s) have been scanned
Scan process 'CoreCom.exe' - '1' Module(s) have been scanned
Scan process 'Deskboard.exe' - '1' Module(s) have been scanned
Scan process 'SystrayApp.exe' - '1' Module(s) have been scanned
Scan process 'ConnectivityManager.exe' - '1' Module(s) have been scanned
Scan process 'AlertModule.exe' - '1' Module(s) have been scanned
Scan process 'Launcher.exe' - '1' Module(s) have been scanned
Scan process 'CCC.exe' - '1' Module(s) have been scanned
Scan process 'VideoCamSuiteAutoStart.exe' - '1' Module(s) have been scanned
Scan process 'MOM.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'LightScribeControlPanel.exe' - '1' Module(s) have been scanned
Scan process 'sidebar.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned
Scan process 'WLIDSVCM.EXE' - '1' Module(s) have been scanned
Scan process 'notepad.exe' - '1' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
Scan process 'WLIDSVC.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'StkCSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SeaPort.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
Scan process 'FTRTSVC.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
Scan process 'bgsvcgen.exe' - '1' Module(s) have been scanned
Scan process 'ATKOSD.exe' - '1' Module(s) have been scanned
Scan process 'ACEngSvr.exe' - '1' Module(s) have been scanned
Scan process 'ACMON.exe' - '1' Module(s) have been scanned
Scan process 'BatteryLife.exe' - '1' Module(s) have been scanned
Scan process 'wcourier.exe' - '1' Module(s) have been scanned
Scan process 'HControl.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'ALU.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'dwm.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'ASLDRSrv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'audiodg.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
74 processes with 74 modules were scanned
0
nanou.o Messages postés 64 Date d'inscription mercredi 21 juillet 2010 Statut Membre Dernière intervention 13 novembre 2010
25 juil. 2010 à 08:28
Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '49' files ).


Starting the file scan:

Begin scan in 'C:\' <VistaOS>
C:\hiberfil.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.dll.vir
[DETECTION] Is the TR/BHO.Zwangi.642 Trojan
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.exe.vir
[DETECTION] Is the TR/BHO.Zwangi.517 Trojan
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\HotbarSADF.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Srv.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Weather.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\WeSkin.VIR.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\firefox\extensions\plugins\npclntax_HotbarSA.dll.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
C:\Users\MORNAS\AppData\Local\qcufaj.VIR
[DETECTION] Contains virus patterns of Adware ADWARE/Adware.Gen2
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7UDZT58W\upgrade[1].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/BHO.Zwangi.626 Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Is the TR/GerVar.598016.DP Trojan
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.618 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[1].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/BHO.Zwangi.621 Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Is the TR/BHO.Zwangi.627 Trojan
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.640 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[2].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/GerVar.669904 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G1HNZ4X7\upgrade[2].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/BHO.Zwangi.578 Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Is the TR/BHO.Zwangi.642 Trojan
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.517 Trojan
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[1].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Contains recognition pattern of the DR/Zwangi.aal dropper
--> [UnknownDir]/bardiscover.dll
[DETECTION] Contains virus patterns of Adware ADWARE/Zwangi.aal
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[2].cab
[0] Archive type: CAB (Microsoft)
--> upgrade.exe
[DETECTION] Is the TR/Drop.TMR Trojan
--> [UnknownDir]/bardiscover.dll
[DETECTION] Contains virus patterns of Adware ADWARE/Agent.NEE
--> [UnknownDir]/bardiscover.exe
[DETECTION] Is the TR/BHO.Zwangi.619 Trojan
Begin scan in 'D:\' <DATA>

Beginning disinfection:
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.dll.vir
[DETECTION] Is the TR/BHO.Zwangi.642 Trojan
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\bardiscover\bardiscover.exe.vir
[DETECTION] Is the TR/BHO.Zwangi.517 Trojan
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\HotbarSADF.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Srv.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\Weather.exe.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\WeSkin.VIR.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Program Files\Ad-Remover\Quarantine\C\Program Files\Hotbar\bin\11.0.175.0\firefox\extensions\plugins\npclntax_HotbarSA.dll.vir
[DETECTION] Contains recognition pattern of the ADSPY/AdSpy.Gen2 adware or spyware
[WARNING] The file was ignored!
C:\Users\MORNAS\AppData\Local\qcufaj.VIR
[DETECTION] Contains virus patterns of Adware ADWARE/Adware.Gen2
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7UDZT58W\upgrade[1].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[1].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DHW1NJQC\upgrade[2].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G1HNZ4X7\upgrade[2].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[1].cab
[WARNING] The file was ignored!
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LOOHBLFU\upgrade[2].cab
[WARNING] The file was ignored!


End of the scan: samedi 24 juillet 2010 23:18
Used time: 1:53:23 Hour(s)

The scan has been done completely.

27563 Scanned directories
446720 Files were scanned
23 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
2 Files cannot be scanned
446695 Files not concerned
4776 Archives were scanned
16 Warnings
2 Notes
115406 Objects were scanned with rootkit scan
0 Hidden objects were found
0