Rapport Hijackthis.

Résolu
racaille -  
moment de grace Messages postés 30049 Statut Contributeur sécurité -
Bonjour,

Quelqu'un pourrait-il me dire s'il y a quelque chose qui cloche ? voici :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:04:15, on 06/10/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18943)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\CheckPoint\ZAForceField\ForceField.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Yahoo!\Common\YMailAdvisor.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\IObit\IObit Security 360\is360tray.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\OfferBox\OfferBox.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Users\ronel\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Preserve
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.emachines.com/rdr.aspx?b=ACEW&l=040c&s=2&o=vb32&d=0309&m=e625
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.emachines.com/rdr.aspx?b=ACEW&l=040c&s=2&o=vb32&d=0309&m=e625
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: Softonic_France Toolbar - {4daac69c-cba7-45e2-9bc8-1044483d3352} - C:\Program Files\Softonic_France\tbSof0.dll
R3 - URLSearchHook: interdescargas-FR Toolbar - {31c322dc-5878-452e-a2d8-c4aab9973c9a} - C:\Program Files\interdescargas-FR\tbint1.dll
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
R3 - URLSearchHook: GameYard Toolbar - {b27200ad-1137-430c-bbaf-593defb7373b} - C:\Program Files\GameYard\tbGam1.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: interdescargas-FR Toolbar - {31c322dc-5878-452e-a2d8-c4aab9973c9a} - C:\Program Files\interdescargas-FR\tbint1.dll
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: Softonic_France Toolbar - {4daac69c-cba7-45e2-9bc8-1044483d3352} - C:\Program Files\Softonic_France\tbSof0.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: ZoneAlarm Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.5126.1836\swg.dll
O2 - BHO: GameYard Toolbar - {b27200ad-1137-430c-bbaf-593defb7373b} - C:\Program Files\GameYard\tbGam1.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: Interest recogniser for Moovida (powered by Spointer) - {E2A7BD67-0EAF-497f-B05B-748D7BF3C421} - C:\Program Files\Fluendo\Moovida\spointer\extensions\moovida_air_ie.dll
O2 - BHO: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\pdfforge Toolbar\SearchSettings.dll
O2 - BHO: myBabylon English4 Toolbar - {fc600575-3013-4e8e-941c-4b00dafce730} - C:\Program Files\myBabylon_English4\tbmyB1.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: myBabylon English4 Toolbar - {fc600575-3013-4e8e-941c-4b00dafce730} - C:\Program Files\myBabylon_English4\tbmyB1.dll
O3 - Toolbar: interdescargas-FR Toolbar - {31c322dc-5878-452e-a2d8-c4aab9973c9a} - C:\Program Files\interdescargas-FR\tbint1.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Softonic_France Toolbar - {4daac69c-cba7-45e2-9bc8-1044483d3352} - C:\Program Files\Softonic_France\tbSof0.dll
O3 - Toolbar: GameYard Toolbar - {b27200ad-1137-430c-bbaf-593defb7373b} - C:\Program Files\GameYard\tbGam1.dll
O3 - Toolbar: ZoneAlarm Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\eMachines\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [YMailAdvisor] "C:\Program Files\Yahoo!\Common\YMailAdvisor.exe"
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\pdfforge Toolbar\SearchSettings.exe
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ISW] "C:\Program Files\CheckPoint\ZAForceField\ForceField.exe" /icon="hidden"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [IObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Coach Cérébral Vol.2 OLR] C:\PROGRA~1\BVRPSO~1\COACHC~1.2\BVRPOlr.exe /Coach Cérébral Vol.2
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Pando Media Booster] C:\Program Files\Pando Networks\Media Booster\PMB.exe
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [OfferBox] C:\Program Files\OfferBox\OfferBox.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\system32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -"Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0; GTB6; FunWebProducts; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.5.30729; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.0.30729; FDM)" -"http://www.jouerjeux.net/jeux/Crank_307.html"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Users\ronel\AppData\Roaming\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O4 - Startup: OneNote 2007 - Capture d'écran et lancement.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5FE4A54D-5177-4E7F-A6C1-FBE0F48CF366}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{C523A511-4DC8-408D-9FC1-F32A4D5CF48F}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CS1\Services\Tcpip\..\{5FE4A54D-5177-4E7F-A6C1-FBE0F48CF366}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CS2\Services\Tcpip\..\{5FE4A54D-5177-4E7F-A6C1-FBE0F48CF366}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CS3\Services\Tcpip\..\{5FE4A54D-5177-4E7F-A6C1-FBE0F48CF366}: NameServer = 156.154.70.22,156.154.71.22
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files\Application Updater\ApplicationUpdater.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe
O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: Canon Inkjet Printer/Scanner/Fax Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe
O23 - Service: ZoneAlarm Toolbar IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: IviRegMgr - InterVideo - C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe


Merci.




45 réponses

racaille
 
Alors alors ???
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
alors...je t'ai oublié

Relance List_Kill'em(soit en clic droit pour vista/7),avec le raccourci sur ton bureau.
mais cette fois-ci :

choisis l'option CLEAN


laisse travailler l'outil.

en fin de scan la fenetre se ferme , et tu as un rapport du nom de Kill'em.txt sur ton bureau ,

colle le contenu dans ta reponse



0
Utilisateur anonyme
 
hello moi j'ai un doute sur ces fichiers ^^

[18/05/2007 - 15:20:14 | SH | 16384] E:\pvqelelo.exeynzklnwo.exe
[18/05/2007 - 15:20:14 | SH | 16384] E:\AdobeR.exe enjfduihk.exe
[18/05/2007 - 15:20:14 | SH | 16384] E:\njfduihk.exepalrcnmk.exe
[18/05/2007 - 15:20:14 | SH | 16384] E:\AdobeR.exe eskwglyer.exe
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
j'ai beau chercher quelque chose de futé à te répondre pour avoir le dernier mot...je trouve pas

bien vu...encore une fois
0
racaille
 
Bizarre...Je lance l'outil et l'invité de commande apparaît puis disparaît immédiatement et pas de rapport du nom de Kill'em.txt à l'arrivée.
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
tu as bien désactivé tes protections et fais clic droit "executer en tant qu'administrateur"
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
racaille
 
Voici, en faite je n'avais pas exécuté le programme depuis mon bureau :

¤¤¤¤¤¤¤¤¤¤ Kill'em by g3n-h@ckm@n 2.1.0.9 ¤¤¤¤¤¤¤¤¤¤

User : ronel (Administrateurs)
Update on 04/10/2010 by g3n-h@ckm@n ::::: 21.00
Start at: 21:34:18 | 07/10/2010

AMD Athlon(tm) Processor TF-20
Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-bit) # Service Pack 2
Internet Explorer 8.0.6001.18943
Windows Firewall Status : Enabled

C:\ -> Disque fixe local | 136,04 Go (64,29 Go free) [OS] | NTFS
D:\ -> Disque CD-ROM | 51,89 Mo (0 Mo free) [Coach Cer. Vol.2] | CDFS

¤¤¤¤¤¤¤¤¤¤ Files/folders :

Quarantined & Deleted !! : C:\ProgramData\Valusoft
Quarantined & Deleted !! : C:\Program Files\Anti Trojan Elite

Quarantined & Deleted !! : C:\Windows\Temp\GUR4CB8.tmp
Quarantined & Deleted !! : C:\Windows\Temp\ZLT04ba7.TMP
Quarantined & Deleted !! : C:\Windows\Temp\ZLT06c13.TMP
Quarantined & Deleted !! : C:\Users\ronel\AppData\Local\d3d9caps.dat
Quarantined & Deleted !! : C:\Users\ronel\AppData\Local\GDIPFONTCACHEV1.DAT
Quarantined & Deleted !! : C:\Users\ronel\AppData\Local\kgdawz.exe
Quarantined & Deleted !! : C:\Users\ronel\LOCAL Settings\Temp\RtkBtMnt.exe
Quarantined & Deleted !! : C:\Users\ronel\LOCAL Settings\Temp\SearchWithGoogleUpdate.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$I0WECUX.jpg
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$I148WX0.png
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$I2PFW49.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$I50N44C.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$I5VWS0W.fm
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$I6QAX8S.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$I6ZSGE1.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$I7RFFDY.gif
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IAWA7M5.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IBKR4QU.png
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IC7UKON.png
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$ICS334W.jpg
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IDU3RVP.tac
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IE733F9.jpg
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IEGY09C.wps
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IEKJ9TZ.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IEKV77U.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IELBNBW.tac
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IEQFJRP.fm
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IEVJPU9.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IFDV20K.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IH3KDRN.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$II94EN7.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IIEGCJX.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IJC2UOY.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IJL8CJS.fm
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IJXG5TB.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IKJXXJV
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IKTEBQY.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IL6DHZR.LNK
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IM9GR9A.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IN74CGF
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$INO4ICK.png
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$INT559A.jpg
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IOZMXE6.png
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IPW3CF3.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IQAAWKS.ps
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IQDMEOB.jpg
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IQX4PPW.png
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IR2JFXF.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IRY9Z9Y.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$ISCCO0T.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$ISN5LK9.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$ISP5R7B.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$ISQTK62.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IT9GI6Z.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IU9TK69.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IUCRIEK.jpg
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IVK3JXY.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IXSKVSU.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IXU9PK1.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IXYLZQV.zip
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IZF6IU6.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$IZRQVGM.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$R2PFW49.Txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$R50N44C.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$R6ZSGE1.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$REVJPU9.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RFDV20K.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RIEGCJX.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RJC2UOY.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RJXG5TB.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RKTEBQY.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RL6DHZR.LNK
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RM9GR9A.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RN74CGF
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RPW3CF3.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RQAAWKS.ps
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RR2JFXF.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RSCCO0T.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RSP5R7B.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RT9GI6Z.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RU9TK69.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RXSKVSU.lnk
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RXU9PK1.exe
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RXYLZQV.zip
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RZF6IU6.txt
Deleted !! : C:\$Recycle.bin\S-1-5-21-213074631-1232468087-63800457-1000\$RZZWDNE.BAK

¤¤¤¤¤¤¤¤¤¤ Hosts ¤¤¤¤¤¤¤¤¤¤


¤¤¤¤¤¤¤¤¤¤ Registry ¤¤¤¤¤¤¤¤¤¤

Deleted : "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask

Toolbar"
Deleted : HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
Deleted : HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{83ff80f4-8c74-4b80-b5ba-c8ddd434e5c4}
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\741B4ADF27276464790022C965AB6DA8
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\76DA9915C36F3D742951F63351CF5C97
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\7DE196B10195F5647A2B21B761F3DE01
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\9B0B0584E80456A4FB98DA3973B1EB3F
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\9D4F5849367142E4685ED8C25E44C5ED
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\A5875B04372C19545BEB90D4D606C472
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\A876D9E80B896EC44A8620248CC79296
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\A89F1E0FE544529429C8BF82FE74CE39
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\B66FFAB725B92594C986DE826A867888
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\C9667115F6A9CE340B31B63B680FF26F
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\EFB70E89C3D6D354596520DE424F89D6
Deleted : HKLM\software\microsoft\windows\currentversion\installer\userdata\S-1-5-18

\Components\F49A213B5069AC348994D03F81B56C19

¤¤¤¤¤¤¤¤¤¤ Internet Explorer ¤¤¤¤¤¤¤¤¤¤

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.msn.com/fr-fr/?ocid=iehp
Local Page = C:\WINDOWS\system32\blank.htm
Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
Start Page = https://www.google.com/?gws_rd=ssl
Local Page = C:\WINDOWS\system32\blank.htm
Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

¤¤¤¤¤¤¤¤¤¤ Security Center ¤¤¤¤¤¤¤¤¤¤

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
cval = 1 ()
FirstRunDisabled = 1 ()
AntiVirusDisableNotify = 0 (0x0)
FirewallDisableNotify = 0 (0x0)
UpdatesDisableNotify = 0 (0x0)
AntiVirusOverride = 0 (0x0)
FirewallOverride = 0 (0x0)

¤¤¤¤¤¤¤¤¤¤ Services ¤¤¤¤¤¤¤¤¤¤

Ndisuio : Start = 3
EapHost : Start = 2
Wlansvc : Start = 2
SharedAccess : Start = 2
windefend : Start = 2
wuauserv : Start = 2
wscsvc : Start = 2

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
Disk Cleaned
anti-ver blaster : OK
Prefetch cleaned
¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

FEATURE_BROWSER_EMULATION | svchost :
====================================


Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net

device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll storport.sys ahcix86s.sys
kernel: MBR read successfully
user & kernel MBR OK




¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
0
racaille
 
Merci gen-hackman aussi, au passage :).
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
0
racaille
 
############################## | UsbFix 7.027 | [Recherche]

Utilisateur: ronel (Administrateur) # PC-DE-RONEL [eMachines eMachines E625]
Mis à jour le 28/09/10 par El Desaparecido / C_XX
Lancé à 22:48:05 | 07/10/2010
Site Web: http://www.teamxscript.org
Contact: FindyKill.Contact@gmail.com

CPU: AMD Athlon(tm) Processor TF-20
Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18943

RAM -> 2813 Mo
C:\ (%systemdrive%) -> Disque fixe # 136 Go (67 Go libre(s) - 49%) [OS] # NTFS
D:\ -> CD-ROM
E:\ -> Disque amovible # 116 Mo (116 Mo libre(s) - 100%) [] # FAT

################## | Éléments infectieux |


Présent! D:\Autorun.inf

################## | Registre |


################## | Mountpoints2 |


################## | Vaccin |

C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
E:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)

################## | E.O.F |
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
regarde sur E si ces fichiers sont toujours présents

E:\pvqelelo.exeynzklnwo.exe
E:\AdobeR.exe enjfduihk.exe
E:\njfduihk.exepalrcnmk.exe
E:\AdobeR.exe eskwglyer.exe
0
racaille
 
Non rien.
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
tu veux dire qu'ils n'y sont pas ?
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
relance usbfix et fais listing stp

poste le rapport
0
racaille
 
############################## | UsbFix 7.027 | [Listing]

Utilisateur: ronel (Administrateur) # PC-DE-RONEL [eMachines eMachines E625]
Mis à jour le 28/09/10 par El Desaparecido / C_XX
Lancé à 04:52:34 | 08/10/2010
Site Web: http://www.teamxscript.org
Contact: FindyKill.Contact@gmail.com

CPU: AMD Athlon(tm) Processor TF-20
Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18943

Pare-feu Windows: Activé
RAM -> 2813 Mo
C:\ (%systemdrive%) -> Disque fixe # 136 Go (65 Go libre(s) - 48%) [OS] # NTFS
D:\ -> CD-ROM
E:\ -> Disque amovible # 116 Mo (116 Mo libre(s) - 100%) [] # FAT

################## | Listing |

[03/10/2010 - 18:50:31 | SHD ] C:\$Recycle.Bin
[27/06/2010 - 03:46:45 | D ] C:\3902e40f947d05251705
[11/08/2010 - 21:45:53 | D ] C:\84f0ea2d1c3db568a832ba2e16
[30/08/2009 - 13:15:19 | HD ] C:\ACER
[30/08/2009 - 13:14:15 | HD ] C:\ACERSW
[06/10/2010 - 06:27:42 | A | 11697] C:\Ad-Report-CLEAN[1].txt
[06/10/2010 - 06:48:21 | A | 2913] C:\Ad-Report-CLEAN[2].txt
[06/10/2010 - 09:14:34 | A | 2459] C:\Ad-Report-SCAN[1].txt
[07/10/2010 - 22:22:53 | A | 4] C:\autoexec.bat
[07/10/2010 - 01:05:40 | RASHD ] C:\Autorun.inf
[28/03/2009 - 00:45:25 | AD ] C:\book
[28/10/2009 - 22:12:12 | SHD ] C:\Boot
[11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
[11/02/2010 - 00:13:31 | D ] C:\BraCa Soft
[06/10/2010 - 06:37:37 | SHD ] C:\Config.Msi
[18/09/2006 - 23:43:37 | A | 10] C:\config.sys
[18/07/2010 - 18:04:09 | D ] C:\Data
[02/11/2006 - 14:59:44 | SHD ] C:\Documents and Settings
[13/07/2010 - 17:43:26 | D ] C:\Downloads
[07/10/2010 - 22:58:20 | ASH | 2950807552] C:\hiberfil.sys
[30/06/2010 - 08:39:41 | RASH | 0] C:\IO.SYS
[07/10/2010 - 21:34:19 | D ] C:\Kill'em
[07/10/2010 - 21:34:18 | A | 54683] C:\List'em.txt
[30/06/2010 - 08:39:41 | RASH | 0] C:\MSDOS.SYS
[03/03/2009 - 15:19:20 | RHD ] C:\MSOCache
[28/07/2010 - 23:06:08 | AD ] C:\Navilog1
[07/10/2010 - 22:58:18 | ASH | 3264610304] C:\pagefile.sys
[21/01/2008 - 04:43:50 | D ] C:\PerfLogs
[07/10/2010 - 21:34:39 | RD ] C:\Program Files
[08/10/2010 - 01:27:55 | AHD ] C:\ProgramData
[14/02/2010 - 20:49:18 | D ] C:\Securitoo
[08/10/2010 - 03:23:24 | SHD ] C:\System Volume Information
[13/07/2010 - 14:43:45 | D ] C:\temp
[05/10/2010 - 01:48:20 | D ] C:\TTF Assistant
[05/08/2010 - 16:07:02 | A | 369704] C:\TTF Assistant(2).rar
[07/10/2010 - 22:52:23 | D ] C:\UsbFix
[08/10/2010 - 04:52:34 | A | 2495] C:\UsbFix.txt
[07/10/2010 - 01:05:44 | A | 685454] C:\UsbFix_Upload_Me_PC-DE-RONEL.zip
[13/11/2009 - 07:53:28 | RD ] C:\Users
[21/07/2010 - 10:42:16 | HD ] C:\VritualRoot
[07/10/2010 - 07:50:22 | D ] C:\Windows
[07/10/2010 - 00:39:09 | A | 33902] C:\ZHPExportRegistry-07-10-2010-00-39-09.txt
[07/10/2010 - 06:51:53 | A | 1564] C:\ZHPExportRegistry-07-10-2010-06-51-53.txt
[10/03/2008 - 18:51:18 | R | 91] D:\Autorun.inf
[10/03/2008 - 12:19:50 | R | 2382] D:\Happy_CoachCerebralvol2.ico
[10/03/2008 - 18:44:15 | D ] D:\Reg
[10/03/2008 - 12:19:36 | R | 24] D:\debut.ls
[10/03/2008 - 12:19:44 | R | 111292] D:\happy_cd.exe
[10/03/2008 - 12:19:52 | R | 265] D:\readme.txt
[10/03/2008 - 12:51:37 | R | 50568941] D:\setup.exe
[07/10/2010 - 01:05:42 | RASHD ] E:\Autorun.inf
[18/05/2007 - 15:20:14 | SH | 16384] E:\pvqelelo.exeynzklnwo.exe
[18/05/2007 - 15:20:14 | SH | 16384] E:\AdobeR.exe enjfduihk.exe
[18/05/2007 - 15:20:14 | SH | 16384] E:\njfduihk.exepalrcnmk.exe
[18/05/2007 - 15:20:14 | SH | 16384] E:\AdobeR.exe eskwglyer.exe

################## | E.O.F |
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
ok

desinstalle usbfix et retélécharge le il a été mis à jour pour cela

http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
ou
https://www.ionos.fr/?affiliate_id=77097

fais l'option RECHERCHE stp
0
racaille
 
Voici voici :

############################## | UsbFix 7.029 | [Recherche]

Utilisateur: ronel (Administrateur) # PC-DE-RONEL [eMachines eMachines E625]
Mis à jour le 07/10/10 par El Desaparecido / C_XX
Lancé à 05:12:17 | 08/10/2010
Site Web: http://www.teamxscript.org
Contact: eldesaparecido@arx-services.com

CPU: AMD Athlon(tm) Processor TF-20
Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18943

Pare-feu Windows: Activé
RAM -> 2813 Mo
C:\ (%systemdrive%) -> Disque fixe # 136 Go (68 Go libre(s) - 50%) [OS] # NTFS
D:\ -> CD-ROM
E:\ -> Disque amovible # 116 Mo (116 Mo libre(s) - 100%) [] # FAT

################## | Éléments infectieux |


Présent! D:\Autorun.inf
Présent! E:\pvqelelo.exeynzklnwo.exe
Présent! E:\AdobeR.exe enjfduihk.exe
Présent! E:\njfduihk.exepalrcnmk.exe
Présent! E:\AdobeR.exe eskwglyer.exe

################## | Registre |


################## | Mountpoints2 |


################## | Vaccin |

C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
E:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)

################## | E.O.F |
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
ok

relances le

option SUPPRESSION
poste le rapport stp
0
racaille
 
############################## | UsbFix 7.029 | [Suppression]

Utilisateur: ronel (Administrateur) # PC-DE-RONEL [eMachines eMachines E625]
Mis à jour le 07/10/10 par El Desaparecido / C_XX
Lancé à 05:36:52 | 08/10/2010
Site Web: http://www.teamxscript.org
Contact: eldesaparecido@arx-services.com

CPU: AMD Athlon(tm) Processor TF-20
Microsoft® Windows Vista(TM) Édition Familiale Basique (6.0.6002 32-Bit) # Service Pack 2
Internet Explorer 8.0.6001.18943

Pare-feu Windows: Désactivé /!\
RAM -> 2813 Mo
C:\ (%systemdrive%) -> Disque fixe # 136 Go (67 Go libre(s) - 49%) [OS] # NTFS
D:\ -> CD-ROM
E:\ -> Disque amovible # 116 Mo (116 Mo libre(s) - 100%) [] # FAT

################## | Éléments infectieux |


Non supprimé ! D:\Autorun.inf
Supprimé! C:\$RECYCLE.BIN\S-1-5-18
Supprimé! C:\$RECYCLE.BIN\S-1-5-20
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-1514550121-240313202-2036960856-500
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-213074631-1232468087-63800457-1000
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-213074631-1232468087-63800457-500
Supprimé! C:\$RECYCLE.BIN\S-1-5-21-213074631-1232468087-63800457-501
Supprimé! E:\pvqelelo.exeynzklnwo.exe
Supprimé! E:\AdobeR.exe enjfduihk.exe
Supprimé! E:\njfduihk.exepalrcnmk.exe
Supprimé! E:\AdobeR.exe eskwglyer.exe

################## | Registre |


################## | Mountpoints2 |


################## | Listing |

[08/10/2010 - 05:39:23 | SHD ] C:\$Recycle.Bin
[27/06/2010 - 03:46:45 | D ] C:\3902e40f947d05251705
[11/08/2010 - 21:45:53 | D ] C:\84f0ea2d1c3db568a832ba2e16
[30/08/2009 - 13:15:19 | D ] C:\ACER
[30/08/2009 - 13:14:15 | D ] C:\ACERSW
[06/10/2010 - 06:27:42 | N | 11697] C:\Ad-Report-CLEAN[1].txt
[06/10/2010 - 06:48:21 | N | 2913] C:\Ad-Report-CLEAN[2].txt
[06/10/2010 - 09:14:34 | N | 2459] C:\Ad-Report-SCAN[1].txt
[07/10/2010 - 22:22:53 | N | 4] C:\autoexec.bat
[07/10/2010 - 01:05:40 | RASHD ] C:\Autorun.inf
[28/03/2009 - 00:45:25 | D ] C:\book
[28/10/2009 - 22:12:12 | D ] C:\Boot
[11/04/2009 - 08:36:36 | RASH | 333257] C:\bootmgr
[11/02/2010 - 00:13:31 | D ] C:\BraCa Soft
[08/10/2010 - 05:07:56 | D ] C:\Config.Msi
[18/09/2006 - 23:43:37 | N | 10] C:\config.sys
[18/07/2010 - 18:04:09 | D ] C:\Data
[02/11/2006 - 14:59:44 | SHD ] C:\Documents and Settings
[13/07/2010 - 17:43:26 | D ] C:\Downloads
[07/10/2010 - 22:58:20 | ASH | 2950807552] C:\hiberfil.sys
[30/06/2010 - 08:39:41 | N | 0] C:\IO.SYS
[07/10/2010 - 21:34:19 | D ] C:\Kill'em
[07/10/2010 - 21:34:18 | N | 54683] C:\List'em.txt
[30/06/2010 - 08:39:41 | N | 0] C:\MSDOS.SYS
[03/03/2009 - 15:19:20 | RHD ] C:\MSOCache
[28/07/2010 - 23:06:08 | D ] C:\Navilog1
[07/10/2010 - 22:58:18 | ASH | 3264610304] C:\pagefile.sys
[21/01/2008 - 04:43:50 | D ] C:\PerfLogs
[07/10/2010 - 21:34:39 | RD ] C:\Program Files
[08/10/2010 - 01:27:55 | AHD ] C:\ProgramData
[14/02/2010 - 20:49:18 | D ] C:\Securitoo
[08/10/2010 - 04:59:36 | SHD ] C:\System Volume Information
[13/07/2010 - 14:43:45 | D ] C:\temp
[05/10/2010 - 01:48:20 | D ] C:\TTF Assistant
[05/08/2010 - 16:07:02 | N | 369704] C:\TTF Assistant(2).rar
[08/10/2010 - 05:39:23 | D ] C:\UsbFix
[08/10/2010 - 05:37:08 | A | 3166] C:\UsbFix.txt
[07/10/2010 - 01:05:44 | N | 685454] C:\UsbFix_Upload_Me_PC-DE-RONEL.zip
[13/11/2009 - 07:53:28 | D ] C:\Users
[21/07/2010 - 10:42:16 | D ] C:\VritualRoot
[07/10/2010 - 07:50:22 | D ] C:\Windows
[07/10/2010 - 00:39:09 | N | 33902] C:\ZHPExportRegistry-07-10-2010-00-39-09.txt
[07/10/2010 - 06:51:53 | N | 1564] C:\ZHPExportRegistry-07-10-2010-06-51-53.txt
[10/03/2008 - 18:51:18 | R | 91] D:\Autorun.inf
[10/03/2008 - 12:19:50 | R | 2382] D:\Happy_CoachCerebralvol2.ico
[10/03/2008 - 18:44:15 | D ] D:\Reg
[10/03/2008 - 12:19:36 | R | 24] D:\debut.ls
[10/03/2008 - 12:19:44 | R | 111292] D:\happy_cd.exe
[10/03/2008 - 12:19:52 | R | 265] D:\readme.txt
[10/03/2008 - 12:51:37 | R | 50568941] D:\setup.exe
[07/10/2010 - 01:05:42 | RASHD ] E:\Autorun.inf

################## | Vaccin |

E:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)

################## | Upload |

Veuillez envoyer le fichier: C:\UsbFix_Upload_Me_PC-DE-RONEL.zip
https://www.ionos.fr/?affiliate_id=77097
Merci de votre contribution.

################## | E.O.F |
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
parfait

comment va le pc ?

Fais un nouveau rapport ZHPdiag stp

Rend toi sur Cjoint : http://www.cijoint.fr/

Clique sur "Parcourir " dans la partie " Joindre un fichier[...] "

Sélectionne le rapport ZHPdiag.txt qui se trouve sur ton bureau

Clique ensuite sur "Cliquez ici pour déposer le fichier " et copie/colle le lien dans ton prochain message

0
racaille
 
Assez fluide dans les chargements. Et le rapport :

http://www.cijoint.fr/cjlink.php?file=cj201010/cijrqvi4Sh.txt
0
Utilisateur anonyme
 
Hello racaille :)

Peux tu envoyer ce fichier : C:\UsbFix_Upload_Me_PC-DE-RONEL.zip

Ici : https://www.ionos.fr/?affiliate_id=77097

Ca me permettra d'analyser ton infection ;)

Par avance merci .

0
racaille
 
C'est fait.
0
Utilisateur anonyme
 
Merci racaille :)

Bonne suite ;)
0
moment de grace Messages postés 30049 Statut Contributeur sécurité 2 274
 
ok

pour finir


1)

* Lancez Adobe Reader
* Cliquez sur Edition --> Préférences --> JavaScript
* Décochez "Activer Acrobat JavaScript"
* Validez

....................

2)
IMPORTANT

Purger la restauration systeme vista
https://www.commentcamarche.net/faq/13214-vista-desactiver-reactiver-la-restauration-systeme-de-vista

.................

3)

Télécharge DelFix sur ton bureau.

http://sd-1.archive-host.com/membres/up/17959594961240255/DelFix.exe

1. Lance le, tape 2 puis valide en appuyant sur [Entrée]

2. Patiente pendant le scan jusqu'à l'ouverture du rapport.

3. Copie/Colle le contenu du rapport dans ta prochaine réponse.

Note : Le rapport se trouve également sous C:\DelFixSearch

....................

Recommandations pour l'avenir

Tu es la meilleure protection pour ton pc que tout autre antivirus, si tu admets un minimum de rigueur dans son utilisation...Les virus sont vigilants et pénètrent ta machine par toutes les portes que tu laisseras ouvertes...
- logiciels non à jour (windows, internet explorer, java, adobe reader etc)
- installation de toolbar
- fréquentation de sites piégés
- P2P
- Application de cracks
- Supports usb

Pour t'aider dans cette tâche, voici quelques pistes

Pour naviguer sur internet plus en sécurité et à l'abri des publicités, je te conseille vivement d'installer et d'utiliser le navigateur firefox
http://www.mozilla-europe.org/fr/firefox/

Une fois que c'est fait, lances le et installe l'extension de sécurité adblock plus
pour bloquer les publicités
http://www.clubic.com/telecharger-fiche45912-adblock-plus.html

............................

WOT - Extension pour ton navigateur internet :
Voici une extension à télécharger qui te permettra, en faisant tes recherches sur google, de savoir si le site proposé lors de tes recherches est un site de confiance ou un site à éviter car il pourrait infecter ton PC :
Pour Firefox : https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/
Pour internet explorer : https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp

........................

Pour éviter une infection toolbar, il faut tout lire attentivement lorsque tu installes un programme gratuit, et décocher tous les programmes additionnels qui sont proposés, en particulier les barres d'outils !

..........................

Vaccines tes disques amovibles à l'aide de USBFix (de Chiquitine29 et C_XX)
http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
Au menu principal, choisis l'option 3 (Vaccination).
............................

garder Malwarebytes et faire un examen de temps en temps ton PC, avec mise à jour avant chaque scan
.......................

Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
https://www.commentcamarche.net/telecharger/utilitaires/5647-ccleaner/

* Lance-le.(clic droit "en tant qu'administrateur" pour Vista) Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs tant de fois qu il en trouve a l analyse

..........................
utilitaire pour défragmenter , utilises pour ce faire Defraggler https://www.clubic.com/telecharger-fiche44314-defraggler.html

........................
A lire pour mieux comprendre l'environnement qui t'entoure
http://assiste.com.free.fr/p/abc/a/zombies_et_botnets.html
https://www.malekal.com/fichiers/projetantimalwares/ProjetAntiMalware-courte.pdf

http://www.libellules.ch/...






0