Antivirus software alert (virus)

Goosi Messages postés 21 Statut Membre -  
fred08700 Messages postés 3633 Statut Contributeur sécurité -
Bonjour, mon pc, depuis lundi soir est infecté par un virus. Ce virus m'empêche d'accéder à tous programmes prétendant qu'ils sont infectés ( je ne peux même pas régler le volume pour dire ). J'ai essayer de le supprimer par différents moyens vu sur des forums mais il persiste. J'arrive à accéder à mes programmes durant 2min juste après avoir allumé mon pc ( je suis sous xp ) ce qui m'a permis d'effectuer un scan malwarebytes, j'ai supprimé les menaces pourtant le virus persiste.
Je désespère vraiment :(
Merci d'avance !

30 réponses

  • 1
  • 2
Résumé de la discussion

Un ordinateur sous Windows XP est frappé par un virus qui bloque l'accès à la plupart des programmes et empêche le réglage du volume, malgré des tentatives de suppression et un scan. Plusieurs outils de nettoyage ont été utilisés, comme ZHPFix, ZHPDiag et Ad-Remover, et des éléments du registre ont été supprimés; Malwarebytes a détecté et isolé de nombreuses infections, notamment Backdoor.Refpron et Worm.VBNA. En parallèle, l'accès à Internet reste problématique malgré la détection et la suppression d'infections, suggérant une persistance potentielle de composants malveillants nécessitant une neutralisation plus approfondie. Des rapports mentionnent des fichiers et clés système infectés, ainsi que des actions ciblant des programmes indésirables; Des conseils soulignent l'usage de scans en mode sans échec et de nettoyeurs.

Bobot (l'IA à votre service)
  1. fred08700 Messages postés 3633 Statut Contributeur sécurité 550
     
    salut

    fait ce scan de diagnostique

    ● Télécharges ZHPDiag ( de Nicolas coolman ).

    ● Double clique sur le fichier d'installation, puis installes le avec les paramètres par défaut ( N'oublies pas de cocher " Créer une icône sur le bureau " )

    ● Lances ZHPDiag en double cliquant sur l'icône présente sur ton bureau

    ● Cliques sur la loupe en haut à gauche, puis laisse l'outil scanner.

    ● Une fois le scan terminé, cliques sur l'icône en forme de disquette et enregistres le fichier sur ton bureau.

    ● Rends toi sur http://www.cijoint.fr/

    ● Cliques sur " Parcourir " dans la partie " Joindre un fichier[...] "

    ● Séléctionnes le rapport ZHPdiag.txt qui se trouve sur ton bureau

    ● Cliques ensuite sur " Créer le lien cjoint " et copie/colle le dans ton prochain message
    0
  2. Goosi Messages postés 21 Statut Membre
     
    Voila le lien : http://www.cijoint.fr/cjlink.php?file=cj201007/cijmVe7EHI.txt
    Merci de votre aide. Que dois je faire maintenant ?
    0
  3. fred08700 Messages postés 3633 Statut Contributeur sécurité 550
     
    re

    Tu es très infecté , on va déja s'occuper du rogue

    Les rogues sont des faux anti-spywares.Il sont seulement créés pour faire de l'argent.Ils se répandent à travers des infections virales ou via des popups de pubs ou d'alerte lorsque vous surfez.Les rogues peuvent aussi s'installer à votre insu. : lors de téléchargement et ouverte de cracks via des sites ou sur des réseaux P2P ou via des failles de sécurités lorsque vous surfez sur des sites douteux.
    Lorsque vous êtes infecté, le faux anti-spyware se met en route automatiquement et vous détecte des menaces imaginaires, seulement pour vous nettoyer ces infections imaginaires, vous devez payer la version commerciale.
    En règle général, ces infections sont accompagnées de fausses alertes indiquant que vous êtes infecté, soit en modifiant votre fond d'écran, soit via une icônes d'alerte souvent à côté de l'horloge.
    Ils prennent généralement la place de l'antivirus dans le centre de sécurité.
    Ces alertes vous harcèlent afin de vous faire acheter la version "commerciale".


    Télécharger rkill depuis l'un des liens ci-dessous:

    https://download.bleepingcomputer.com/grinler/rkill.exe
    https://download.bleepingcomputer.com/grinler/rkill.scr
    https://download.bleepingcomputer.com/grinler/rkill.com

    * Si vous avez un message qui signale que Rkill est un indésirable, ignorez la et lancez de nouveau Rkill après désactivation du logiciel le considérant comme néfaste.

    Une bref fenêtre noire indiquera que l'installation s'est bien déroulée

    N.B: ne pas redémarrer le pc après avoir fait Rkil sans quoi l'infection pourrait se réactiver

    puis :

    ● Télécharges Malwarebytes

    ● Tu auras un tutoriel à ta disposition pour l'installer et l'utiliser correctement.

    ● Fais la mise à jour du logiciel (elle se fait normalement à l'installation)

    ● Lance une analyse complète en cliquant sur "Exécuter un examen complet"

    ● Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"

    L'analyse peut durer un bon moment.....

    ● Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"

    ● Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"

    ● Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

    ● Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC... Faites le en cliquant sur "oui" à la question posée

    Les créateurs d'infections utilisent les emplacements des fichiers système pour hébérger les infections, d'où les fichiers . dll ou exe dans ces series d'infections.
    MABM est très régulièrement mis à jour pour ne pas supprimer les fichiers légitimes de windows, donc pas de craintes de ce côté là.

    0
  4. Goosi Messages postés 21 Statut Membre
     
    Voila j'ai téléchargé rkill, depuis le virus ne s'est pas manifesté, j'espère que c'est bon signe. J'ai lancé l'analyse Malwarebytes je poste le rapport dès que celle ci sera terminée.
    Merci encore
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Goosi Messages postés 21 Statut Membre
     
    Le rapport :

    Malwarebytes' Anti-Malware 1.44
    Version de la base de données: 3510
    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    23/07/2010 01:09:17
    mbam-log-2010-07-23 (01-09-17).txt

    Type de recherche: Examen complet (C:\|)
    Eléments examinés: 189784
    Temps écoulé: 1 hour(s), 23 minute(s), 46 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 1

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)
    0
    1. Goosi Messages postés 21 Statut Membre
       
      Le virus est toujours présent :(
      0
  7. fred08700 Messages postés 3633 Statut Contributeur sécurité 550
     
    bonjour

    Malwarebytes n'est pas à jour

    Recommences RKILL et relances malwarebytes ( Et mets malwarebytes à jour ==> onglets mises à jour)

    et poste le rapport
    0
  8. Goosi Messages postés 21 Statut Membre
     
    Le rapport malwarebytes :

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Version de la base de données: 4340

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    23/07/2010 14:38:22
    mbam-log-2010-07-23 (14-38-22).txt

    Type d'examen: Examen complet (C:\|)
    Elément(s) analysé(s): 198039
    Temps écoulé: 1 heure(s), 28 minute(s), 46 seconde(s)

    Processus mémoire infecté(s): 2
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 20
    Valeur(s) du Registre infectée(s): 7
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 5
    Fichier(s) infecté(s): 15

    Processus mémoire infecté(s):
    C:\WINDOWS\system32\dfttuyo.exe (Backdoor.Refpron) -> No action taken.
    C:\WINDOWS\system32\dfttuyox.exe (Worm.VBNA) -> No action taken.

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> No action taken.
    HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> No action taken.
    HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> No action taken.
    HKEY_CLASSES_ROOT\CLSID\{91d20868-0d8a-4b9e-9ee9-6ff70cc87c24} (Adware.BHO) -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{91d20868-0d8a-4b9e-9ee9-6ff70cc87c24} (Adware.BHO) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91d20868-0d8a-4b9e-9ee9-6ff70cc87c24} (Adware.BHO) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Trojan.DownLoader) -> No action taken.
    HKEY_CLASSES_ROOT\adgj.aghlp (Adware.EZLife) -> No action taken.
    HKEY_CLASSES_ROOT\adgj.aghlp.1 (Adware.EZLife) -> No action taken.
    HKEY_CLASSES_ROOT\adshothlpr.adshothlpr (Adware.Adrotator) -> No action taken.
    HKEY_CLASSES_ROOT\adshothlpr.adshothlpr.1.0 (Adware.Adrotator) -> No action taken.
    HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Sky-Banners (Adware.Adrotator) -> No action taken.
    HKEY_CURRENT_USER\Software\Street-Ads (Adware.Adrotator) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\avsuite (Rogue.AntivirusSuite) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallMTF1011$ (Adware.Adrotator) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> No action taken.
    HKEY_CURRENT_USER\Software\AVSolution (Trojan.Agent) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\AVSolution (Trojan.Agent) -> No action taken.

    Valeur(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dfttuyo (Backdoor.Refpron) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dfttuyox (Worm.VBNA) -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rfvglqun (Trojan.Dropper) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rfvglqun (Trojan.Dropper) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mchk (Trojan.Adware) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sta (Trojan.Agent.Gen) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\tcyz46 (Trojan.Agent) -> No action taken.

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    C:\Documents and Settings\lameiras\Application Data\Sky-Banners (Adware.Adrotator) -> No action taken.
    C:\Documents and Settings\lameiras\Application Data\Sky-Banners\skb (Adware.Adrotator) -> No action taken.
    C:\Documents and Settings\lameiras\Application Data\Street-Ads (Adware.Adrotator) -> No action taken.
    C:\Documents and Settings\lameiras\Application Data\Street-Ads\sta (Adware.Adrotator) -> No action taken.
    C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> No action taken.

    Fichier(s) infecté(s):
    C:\WINDOWS\system32\dfttuyo.exe (Backdoor.Refpron) -> No action taken.
    C:\WINDOWS\system32\dfttuyox.exe (Worm.VBNA) -> No action taken.
    C:\Documents and Settings\lameiras\Local Settings\Application Data\fwxxolyjc\fmsxwnmtssd.exe (Trojan.Dropper) -> No action taken.
    C:\WINDOWS\system32\crnwp.exe (Trojan.Adware) -> No action taken.
    C:\Documents and Settings\lameiras\Local Settings\Temp\uhedyvt.exe (Adware.BHO) -> No action taken.
    C:\Documents and Settings\lameiras\Local Settings\Temp\lu3r3twe5.exe (Worm.VBNA) -> No action taken.
    C:\Documents and Settings\lameiras\Local Settings\Temp\rropyvnl.exe (Trojan.Dropper) -> No action taken.
    C:\WINDOWS\system32\lrnwp.dll (Adware.BHO) -> No action taken.
    C:\WINDOWS\temp\ltcq.tmp\setup.exe (Trojan.DownLoader) -> No action taken.
    C:\WINDOWS\$NtUninstallMTF1011$\apUninstall.exe (Adware.Adrotator) -> No action taken.
    C:\WINDOWS\$NtUninstallMTF1011$\zrpt.xml (Adware.Adrotator) -> No action taken.
    C:\Documents and Settings\lameiras\Local Settings\Temp\l84alx.exe (Trojan.Agent) -> No action taken.
    C:\WINDOWS\system32\comsats.sys (Trojan.Agent) -> No action taken.
    C:\WINDOWS\system32\service.sys (Rootkit.Agent) -> No action taken.
    C:\WINDOWS\system32\updata.exe (Trojan.Agent) -> No action taken.

    Plus de trace du virus :) par contre je n'arrive pas à accéder à internet pourtant je suis bien connecté au réseau...?
    0
  9. Goosi Messages postés 21 Statut Membre
     
    Le rapport malwarebytes :

    Malwarebytes' Anti-Malware 1.46
    www.malwarebytes.org

    Version de la base de données: 4340

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    23/07/2010 14:38:22
    mbam-log-2010-07-23 (14-38-22).txt

    Type d'examen: Examen complet (C:\|)
    Elément(s) analysé(s): 198039
    Temps écoulé: 1 heure(s), 28 minute(s), 46 seconde(s)

    Processus mémoire infecté(s): 2
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 20
    Valeur(s) du Registre infectée(s): 7
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 5
    Fichier(s) infecté(s): 15

    Processus mémoire infecté(s):
    C:\WINDOWS\system32\dfttuyo.exe (Backdoor.Refpron) -> No action taken.
    C:\WINDOWS\system32\dfttuyox.exe (Worm.VBNA) -> No action taken.

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> No action taken.
    HKEY_CLASSES_ROOT\AppID\{38061edc-40bb-4618-a8da-e56353347e6d} (Adware.EZlife) -> No action taken.
    HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> No action taken.
    HKEY_CLASSES_ROOT\CLSID\{91d20868-0d8a-4b9e-9ee9-6ff70cc87c24} (Adware.BHO) -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{91d20868-0d8a-4b9e-9ee9-6ff70cc87c24} (Adware.BHO) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{91d20868-0d8a-4b9e-9ee9-6ff70cc87c24} (Adware.BHO) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setup.exe (Trojan.DownLoader) -> No action taken.
    HKEY_CLASSES_ROOT\adgj.aghlp (Adware.EZLife) -> No action taken.
    HKEY_CLASSES_ROOT\adgj.aghlp.1 (Adware.EZLife) -> No action taken.
    HKEY_CLASSES_ROOT\adshothlpr.adshothlpr (Adware.Adrotator) -> No action taken.
    HKEY_CLASSES_ROOT\adshothlpr.adshothlpr.1.0 (Adware.Adrotator) -> No action taken.
    HKEY_CURRENT_USER\Software\avsuite (Rogue.AntivirusSuite) -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Sky-Banners (Adware.Adrotator) -> No action taken.
    HKEY_CURRENT_USER\Software\Street-Ads (Adware.Adrotator) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\avsuite (Rogue.AntivirusSuite) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallMTF1011$ (Adware.Adrotator) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> No action taken.
    HKEY_CURRENT_USER\Software\AVSolution (Trojan.Agent) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\AVSolution (Trojan.Agent) -> No action taken.

    Valeur(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dfttuyo (Backdoor.Refpron) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\dfttuyox (Worm.VBNA) -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rfvglqun (Trojan.Dropper) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rfvglqun (Trojan.Dropper) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mchk (Trojan.Adware) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sta (Trojan.Agent.Gen) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\tcyz46 (Trojan.Agent) -> No action taken.

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    C:\Documents and Settings\lameiras\Application Data\Sky-Banners (Adware.Adrotator) -> No action taken.
    C:\Documents and Settings\lameiras\Application Data\Sky-Banners\skb (Adware.Adrotator) -> No action taken.
    C:\Documents and Settings\lameiras\Application Data\Street-Ads (Adware.Adrotator) -> No action taken.
    C:\Documents and Settings\lameiras\Application Data\Street-Ads\sta (Adware.Adrotator) -> No action taken.
    C:\WINDOWS\$NtUninstallMTF1011$ (Adware.Adrotator) -> No action taken.

    Fichier(s) infecté(s):
    C:\WINDOWS\system32\dfttuyo.exe (Backdoor.Refpron) -> No action taken.
    C:\WINDOWS\system32\dfttuyox.exe (Worm.VBNA) -> No action taken.
    C:\Documents and Settings\lameiras\Local Settings\Application Data\fwxxolyjc\fmsxwnmtssd.exe (Trojan.Dropper) -> No action taken.
    C:\WINDOWS\system32\crnwp.exe (Trojan.Adware) -> No action taken.
    C:\Documents and Settings\lameiras\Local Settings\Temp\uhedyvt.exe (Adware.BHO) -> No action taken.
    C:\Documents and Settings\lameiras\Local Settings\Temp\lu3r3twe5.exe (Worm.VBNA) -> No action taken.
    C:\Documents and Settings\lameiras\Local Settings\Temp\rropyvnl.exe (Trojan.Dropper) -> No action taken.
    C:\WINDOWS\system32\lrnwp.dll (Adware.BHO) -> No action taken.
    C:\WINDOWS\temp\ltcq.tmp\setup.exe (Trojan.DownLoader) -> No action taken.
    C:\WINDOWS\$NtUninstallMTF1011$\apUninstall.exe (Adware.Adrotator) -> No action taken.
    C:\WINDOWS\$NtUninstallMTF1011$\zrpt.xml (Adware.Adrotator) -> No action taken.
    C:\Documents and Settings\lameiras\Local Settings\Temp\l84alx.exe (Trojan.Agent) -> No action taken.
    C:\WINDOWS\system32\comsats.sys (Trojan.Agent) -> No action taken.
    C:\WINDOWS\system32\service.sys (Rootkit.Agent) -> No action taken.
    C:\WINDOWS\system32\updata.exe (Trojan.Agent) -> No action taken.

    Plus de trace du virus :) par contre je n'arrive pas à accéder à internet pourtant je suis bien connecté au réseau...?
    0
  10. fred08700 Messages postés 3633 Statut Contributeur sécurité 550
     
    salut

    Tu n'as pas suivi le tuto -)
    No action taken. ==> malwarebytes n'a pas entrepris d'actions.

    Relances malwarebytes , quarantaine , Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"

    refais un scan ZHPdiag
    0
  11. Goosi Messages postés 21 Statut Membre
     
    Ah...
    J'ai tout supprimé et j'ai refait un scan, je redémarre mon pc maintenant ?
    0
  12. fred08700 Messages postés 3633 Statut Contributeur sécurité 550
     
    redémarres et refais un scan ZHPdiag (poste le rapport)
    0
  13. Goosi Messages postés 21 Statut Membre
     
    Bonjour, voici la rapport ZHPdiag

    http://www.cijoint.fr/cjlink.php?file=cj201007/cijdROcedC.txt
    0
  14. fred08700 Messages postés 3633 Statut Contributeur sécurité 550
     
    salut

    Encore beaucoup de boulot

    Tu as avast et norton en antivirus : Supprimes-en un des deux
    https://www.commentcamarche.net/faq/7367-desinstaller-proprement-liens-et-astuces

    -----------------------------------------
    * Téléchargez TDSSKiller sur votre bureau

    https://support.kaspersky.com/downloads/utils/tdsskiller.zip

    * Créez un nouveau dossier sur votre bureau puis décompressez l'archive dedans
    * Lancez le programme en cliquant sur TDSSKiller.exe, l'analyse se fait automatiquement, si l'infection est détectée, des éléments cachés (= hidden) seront alors affichés.

    Cochez les et cliquez sur "Delete/Repair Selected".

    * Un message peut ensuite apparaitre demandant de redémarrer le pc (reboot)pour finir le nettoyage. taper "Y" pour redémarrer le PC ("close all programs and choose Y to restart").

    0
  15. Goosi Messages postés 21 Statut Membre
     
    J'ai supprimé Avast et télécharger TDSSKiller mais l'analyse ne s'est pas fait automatiquement j'ai donc cliqué sur start scan; on me demande " select action for found objects, je clique sur continue ?
    0
  16. fred08700 Messages postés 3633 Statut Contributeur sécurité 550
     
    si l'infection est détectée, des éléments cachés (= hidden) seront alors affichés.

    Cochez les et cliquez sur "Delete/Repair Selected".

    Un message peut ensuite apparaitre demandant de redémarrer le pc (reboot)pour finir le nettoyage. taper "Y" pour redémarrer le PC ("close all programs and choose Y to restart").
    0
  17. fred08700 Messages postés 3633 Statut Contributeur sécurité 550
     
    doublon

    Chaque difficulté rencontrée doit être l'occasion d'un nouveau progrès.

    [Pierre de Coubertin]
    0
  18. Goosi Messages postés 21 Statut Membre
     
    J'ai supprimé les infections, j'ai refait un scan il n'y a plus d'infection maitenant
    0
  19. fred08700 Messages postés 3633 Statut Contributeur sécurité 550
     
    /!\Avertissement :
    Ce logiciel n'est à utiliser que prescrit par un helper qualifié et formé à l'outil.
    Ne pas utiliser en dehors de ce cas de figure : dangereux!


    ● Télécharges ComboFix à partir de ce lien et enregistres le sur ton bureau :
    https://forum.pcastuces.com/combofix_renomme_au_telechargement-f31s22.htm
    ou ici :
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    A lire
    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

    Avant d'utiliser ComboFix :

    Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

    ● Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent gêner fortement la procédure de recherche et de nettoyage de l'outil.

    Une fois fait, sur ton bureau double-clic sur Combofix.exe.

    /!\Utilisateur de Vista : Clique droit sur le logo de Combofix, « exécuter en tant qu'administrateur »

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    /!\INSTALLES LA CONSOLE DE RÉCUPÉRATION

    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes. ==> risque de plantage

    - En fin de scan il est possible que ComboFix ait besoin de redémarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

    ● Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    ● Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.
    0
  20. Goosi Messages postés 21 Statut Membre
     
    Combofix est en train de scanner mais je crois que la console de récupération n'a pas été installée car cela nécessitait une connexion internet mais je n'ai pas réussi à la réactiver
    0
  21. Goosi Messages postés 21 Statut Membre
     
    ComboFix 10-07-21.01 - lameiras 24/07/2010 20:34:21.1.2 - x86
    Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.1015.468 [GMT 2:00]
    Lancé depuis: c:\documents and settings\lameiras\Bureau\ComboFix.exe
    AV: Norton Internet Security *On-access scanning disabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
    FW: Norton Internet Security *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

    AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!
    .
    Les fichiers ci-dessous ont été désactivés pendant l'exécution:
    c:\windows\system32\locasol.dll

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\system32\dfttuyo.txt
    c:\windows\system32\driVERs\hbwxdv.sys
    c:\windows\system32\drivers\sbzydrbc.sys
    c:\windows\system32\drivers\txuqmlmy.sys
    c:\windows\system32\egypack.dll
    c:\windows\system32\Install.txt
    c:\windows\system32\jdjmhmn.dll
    c:\windows\system32\kcagykr.dll
    c:\windows\system32\mswyxtnd.dll
    c:\windows\Temp\scsE.tmp
    c:\windows\Temp\scsF.tmp
    c:\windows\xpsp1hfm.log

    .
    ((((((((((((((((((((((((((((((((((((((( Pilotes/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_SBZYDRBC
    -------\Legacy_XGMSTWBA
    -------\Service_sbzydrbc
    -------\Service_xgmstwba
    -------\Legacy_hbwxdv
    -------\Service_hbwxdv

    ((((((((((((((((((((((((((((( Fichiers créés du 2010-06-24 au 2010-07-24 ))))))))))))))))))))))))))))))))))))
    .

    2010-07-23 11:36 . 2010-07-23 11:36 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
    2010-07-23 11:04 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-07-23 11:03 . 2010-07-23 11:04 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-07-23 11:03 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-07-22 11:22 . 2010-07-22 11:22 -------- d-----w- c:\documents and settings\Administrateur\Application Data\Malwarebytes
    2010-07-22 11:22 . 2010-07-22 11:22 -------- d-sh--w- c:\documents and settings\Administrateur\IETldCache
    2010-07-21 21:06 . 2010-07-21 21:06 -------- d-----w- c:\windows\system32\wbem\Repository
    2010-07-21 20:14 . 2010-07-23 21:10 -------- d-----w- c:\program files\ZHPDiag
    2010-07-21 13:44 . 2010-07-21 13:44 -------- d-----r- c:\documents and settings\NetworkService\Favoris
    2010-07-20 22:16 . 2010-07-23 12:38 -------- d-----w- c:\documents and settings\lameiras\Local Settings\Application Data\fwxxolyjc
    2010-07-20 22:16 . 2010-07-20 22:16 -------- d-----w- c:\documents and settings\lameiras\Application Data\AD0E5148A2AA1DD94B83B69814763C19
    2010-07-14 15:26 . 2010-06-14 14:31 744448 ------w- c:\windows\system32\dllcache\helpsvc.exe
    2010-07-11 20:06 . 2010-07-11 20:07 2605008 ----a-w- c:\documents and settings\lameiras\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\fpupdateax\fpupdateax.exe

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-07-24 11:32 . 2008-04-15 12:00 12032 ----a-w- c:\windows\system32\drivers\acpiec.sys
    2010-07-24 11:21 . 2010-03-24 13:28 -------- d-----w- c:\program files\Alwil Software
    2010-07-16 21:35 . 2010-03-19 21:25 -------- d-----w- c:\documents and settings\lameiras\Application Data\MessengerDiscovery 2
    2010-06-30 11:13 . 2010-06-04 19:42 -------- d-----w- c:\program files\Messenger_Plus_Live_France
    2010-06-25 21:36 . 2010-03-24 16:09 -------- d-----w- c:\program files\Enigma Software Group
    2010-06-23 10:50 . 2008-06-25 17:59 84964 ----a-w- c:\windows\system32\perfc00C.dat
    2010-06-23 10:50 . 2008-06-25 17:59 510980 ----a-w- c:\windows\system32\perfh00C.dat
    2010-06-20 11:31 . 2010-01-04 23:15 1 ----a-w- c:\documents and settings\lameiras\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2010-06-17 13:01 . 2010-06-04 22:12 -------- d-----w- c:\program files\gPotato.eu
    2010-06-14 14:31 . 2010-07-14 15:26 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
    2010-06-05 09:05 . 2009-05-10 14:55 -------- d-----w- c:\program files\Microsoft Silverlight
    2010-06-04 22:01 . 2010-06-04 22:01 -------- d-----w- c:\program files\Neffy
    2010-06-04 19:42 . 2010-06-04 19:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Messenger Plus!
    2010-06-04 19:42 . 2010-06-04 19:42 -------- d-----w- c:\program files\Conduit
    2010-06-04 19:41 . 2010-06-04 19:41 -------- d-----w- c:\program files\Messenger Plus! Live
    2010-06-03 15:09 . 2010-06-03 14:48 -------- d-----w- c:\documents and settings\lameiras\Application Data\imeshmediabartb
    2010-06-03 14:48 . 2010-06-03 14:47 -------- d-----w- c:\program files\iMesh Applications
    2010-06-03 14:47 . 2010-06-03 14:47 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{E2F7B169-4020-4ADB-BA78-74FE9AC42BC2}
    2010-06-03 14:47 . 2010-06-03 14:47 -------- d-----w- c:\documents and settings\All Users\Application Data\iMesh
    2010-05-28 18:01 . 2010-05-28 18:01 40960 ----a-w- c:\windows\system32\locasol.dll
    2010-05-27 21:04 . 2010-05-27 21:04 -------- d-----w- c:\program files\MSXML 4.0
    2010-05-27 16:44 . 2010-06-03 14:47 3330324 -c--a-w- c:\documents and settings\All Users\Application Data\{E2F7B169-4020-4ADB-BA78-74FE9AC42BC2}\iMesh_V10_fr_Setup.exe
    2010-05-26 20:20 . 2010-05-26 20:20 -------- d-----w- c:\program files\Samsung
    2010-05-26 20:20 . 2009-05-10 14:39 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-05-26 12:42 . 2010-05-26 12:42 503808 ----a-w- c:\documents and settings\lameiras\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-104fdc5b-n\msvcp71.dll
    2010-05-26 12:42 . 2010-05-26 12:42 348160 ----a-w- c:\documents and settings\lameiras\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-104fdc5b-n\msvcr71.dll
    2010-05-26 12:42 . 2010-05-26 12:42 499712 ----a-w- c:\documents and settings\lameiras\Application Data\Sun\Java\Deployment\cache\6.0\46\f84c6ae-104fdc5b-n\jmc.dll
    2010-05-16 16:08 . 2010-07-22 11:21 38784 ----a-w- c:\documents and settings\Administrateur\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2010-05-16 16:08 . 2010-05-16 16:53 38784 ----a-w- c:\documents and settings\lameiras\Application Data\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
    2010-05-06 10:33 . 2010-06-11 13:57 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-05-02 08:08 . 2010-05-02 08:08 1851392 ----a-w- c:\windows\system32\win32k.sys
    2010-04-29 09:47 . 2010-04-29 09:47 499712 ----a-w- c:\windows\system32\msvcp71.dll
    2010-04-06 17:42 . 2010-04-06 17:42 3054586 ----a-w- c:\program files\XnView-win-fr.exe
    2010-03-24 13:05 . 2010-03-24 13:04 585584 ----a-w- c:\program files\AutoDetectPkg.exe
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{59994074-c06d-4a75-9768-49e5a8c21264}"= "c:\program files\Messenger_Plus_Live_France\tbMes1.dll" [2010-06-30 2734688]

    [HKEY_CLASSES_ROOT\clsid\{59994074-c06d-4a75-9768-49e5a8c21264}]

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{474597C5-AB09-49d6-A4D5-2E8D7341384E}]
    2010-05-27 15:02 392072 ----a-w- c:\program files\iMesh Applications\MediaBar\DataMngr\IEBHO.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{59994074-c06d-4a75-9768-49e5a8c21264}]
    2010-06-30 11:13 2734688 ----a-w- c:\program files\Messenger_Plus_Live_France\tbMes1.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}]
    2009-11-20 17:34 87472 ----a-w- c:\program files\iMesh Applications\MediaBar\ToolBar\iMeshMediaBarDx.dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{ABB49B3B-AB7D-4ED0-9135-93FD5AA4F69F}"= "c:\program files\iMesh Applications\MediaBar\ToolBar\iMeshMediaBarDx.dll" [2009-11-20 87472]
    "{59994074-c06d-4a75-9768-49e5a8c21264}"= "c:\program files\Messenger_Plus_Live_France\tbMes1.dll" [2010-06-30 2734688]

    [HKEY_CLASSES_ROOT\clsid\{abb49b3b-ab7d-4ed0-9135-93fd5aa4f69f}]

    [HKEY_CLASSES_ROOT\clsid\{59994074-c06d-4a75-9768-49e5a8c21264}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
    "{59994074-C06D-4A75-9768-49E5A8C21264}"= "c:\program files\Messenger_Plus_Live_France\tbMes1.dll" [2010-06-30 2734688]

    [HKEY_CLASSES_ROOT\clsid\{59994074-c06d-4a75-9768-49e5a8c21264}]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-05-18 39408]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ccApp"="-" [X]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
    "SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2009-03-30 483428]
    "AESTFltr"="c:\windows\system32\AESTFltr.exe" [2009-02-18 737280]
    "HP BTW Detect Program"="c:\program files\HP\HPBTWD.exe" [2009-03-30 319488]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-01-16 1418536]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-12-03 35184]
    "Syncables"="c:\program files\syncables\syncables desktop\Syncables.exe" [2009-04-01 173360]
    "Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-02-06 224616]
    "hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2010-01-04 149280]
    "DataMngr"="c:\progra~1\IMESHA~1\MediaBar\DataMngr\DataMngrUI.exe" [2010-05-27 796592]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

    c:\documents and settings\lameiras\Menu D'marrer\Programmes\D'marrage\
    OpenOffice.org 3.1.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2009-8-18 384000]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
    @="FSFilter Activity Monitor"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001
    "FirewallOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)
    "DisableNotifications"= 1 (0x1)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "%windir%\\system32\\sessmgr.exe"=
    "c:\\Program Files\\Fichiers communs\\AOL\\Loader\\aolload.exe"=
    "c:\\Program Files\\syncables\\syncables desktop\\jre\\bin\\javaw.exe"=
    "c:\\Program Files\\Messenger\\msmsgs.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
    "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
    "c:\\Program Files\\iMesh Applications\\iMesh\\iMesh.exe"=

    R0 SahdIa32;HDD Filter Driver;c:\windows\system32\drivers\SahdIa32.sys [10/05/2009 16:44 21488]
    R0 SaibIa32;Volume Filter Driver;c:\windows\system32\drivers\SaibIa32.sys [10/05/2009 16:44 15856]
    R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1008000.029\SymEFA.sys [04/02/2010 20:31 310320]
    R0 SysCow;SysCow;c:\windows\system32\drivers\syscow32x.sys [24/09/2008 22:09 103792]
    R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1008000.029\BHDrvx86.sys [04/02/2010 20:31 259632]
    R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1008000.029\cchpx86.sys [04/02/2010 20:30 482432]
    R1 SaibVd32;Virtual Disk Driver;c:\windows\system32\drivers\SaibVd32.sys [10/05/2009 16:44 25584]
    R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269;Roxio SAIB Service;c:\program files\Roxio\BackOnTrack\Disaster Recovery\SaibSVC.exe [11/12/2008 22:46 125424]
    R2 BOTService;BOTService;c:\program files\Roxio\BackOnTrack\Instant Restore\BOTService.exe [19/03/2009 12:04 203248]
    R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [04/02/2010 20:30 117640]
    R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [10/05/2009 16:39 113664]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [25/12/2009 12:53 102448]
    R3 L1c;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [02/03/2009 23:03 38912]
    S1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100218.001\IDSXpx86.sys [20/02/2010 00:20 329592]
    S2 gupdate;Service Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [18/05/2010 09:02 135664]
    S3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des -service --> c:\windows\system32\GameMon.des -service [?]
    S3 RSUSBSTOR;RTS5121.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTS5121.sys --> c:\windows\system32\Drivers\RTS5121.sys [?]
    S3 Rts516xIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys --> c:\windows\system32\DRIVERS\Rts516xIR.sys [?]

    --- Autres Services/Pilotes en mémoire ---

    *NewlyCreated* - SBZYDRBC
    *Deregistered* - sbzydrbc
    *Deregistered* - SymEvent
    .
    Contenu du dossier 'Tâches planifiées'

    2010-07-24 c:\windows\Tasks\BackOnTrack Instant Restore Idle.job
    - c:\program files\Roxio\BackOnTrack\Instant Restore\RstIdle.exe [2009-03-19 10:05]

    2010-07-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-18 07:01]

    2010-07-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-05-18 07:01]
    .
    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://www.google.fr/
    uInternet Settings,ProxyServer = http=127.0.0.1:5643
    uInternet Settings,ProxyOverride = <local>
    IE: &Recherche AOL Toolbar - c:\documents and settings\All Users\Application Data\AOL\ieToolbar\resources\fr-FR\local\search.html
    IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_89D8574934B26AC4.dll/cmsidewiki.html
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    WebBrowser-{604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - (no file)
    HKLM-Run-rmnzhp - c:\windows\system32\mswyxtnd.dll
    SafeBoot-klmdb.sys

    **************************************************************************
    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés:

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Norton Internet Security]
    "ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.8.0.41\diMaster.dll\" /prefetch:1"

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\ccEvtMgr]
    "ImagePath"="-"

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\npggsvc]
    "ImagePath"="c:\windows\system32\GameMon.des -service"

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SAVRT]
    "ImagePath"="-"

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SNDSrvc]
    "ImagePath"="-"

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SYMTDI]
    "ImagePath"="-"
    .
    --------------------- CLES DE REGISTRE BLOQUEES ---------------------

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe,-101"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
    "Enabled"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
    @="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10h_ActiveX.exe"

    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker4"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"

    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------

    - - - - - - - > 'explorer.exe'(360)
    c:\windows\system32\eappprxy.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Autres processus actifs ------------------------
    .
    c:\program files\idt\wdm\STacSV.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\windows\system32\wbem\wmiapsrv.exe
    c:\windows\system32\igfxsrvc.exe
    c:\program files\syncables\syncables desktop\jre\bin\javaw.exe
    c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
    c:\program files\syncables\syncables desktop\MigoMapi.exe
    c:\program files\OpenOffice.org 3\program\soffice.exe
    c:\program files\OpenOffice.org 3\program\soffice.bin
    c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
    c:\program files\Roxio\BackOnTrack\Instant Restore\UINotification.exe
    .
    **************************************************************************
    .
    Heure de fin: 2010-07-24 20:58:31 - La machine a redémarré
    ComboFix-quarantined-files.txt 2010-07-24 18:58

    Avant-CF: 142 421 807 104 octets libres
    Après-CF: 143 147 024 384 octets libres

    - - End Of File - - 33200DAE16D14BAEB5C29082FC598728
    0
  • 1
  • 2