Log hijackthis suite à infection nombreuses

Bernard -  
 Bernard -
Bonjour à tous,

Seb08 m'a conseillé de mettre le log hijackthis sur le forum, suite à infection par un ver. Ewido a découvert plusieurs virus, 35000 fichiers infectés, mais impossible de copier/coller le rapport qu'il m'a demandé. Merci de me dire ce qu'il faut faire maintenant.

Bravo pour l'aide apportée aux néophytes comme moi ! C'est vraiment sympa cet altruisme. Bernard

Logfile of HijackThis v1.99.1
Scan saved at 17:51:15, on 11/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe
C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\keyhook.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\adirss.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\HP_PRO~1\LOCALS~1\Temp\Rar$EX00.718\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [adir] C:\WINDOWS\system32\adirss.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [AutoTBar] AUTOTBAR.EXE
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
O9 - Extra button: Messager Wanadoo - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
O9 - Extra 'Tools' menuitem: Messager Wanadoo - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O15 - Trusted Zone: www.contentdiscount.info
O15 - Trusted Zone: www.extremeaccess.info
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe

10 réponses

  1. Utilisateur anonyme
     
    Salut,

    clique sur démarrer, rechercher et supprime ces fichiers:

    adirss.exe
    ALCXMNTR.EXE

    **Si un fichier persiste lors de la suppression fait ceci:
    -Redemarres ton pc, dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaitre choisis "mode sans echec" attends un peu.. puis vas supprimer les fichiers/dossiers qui persistaient, vides ta corbeille et redemarres normalement

    Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2(en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
    Une fois qu'il a terminé colle le rapport ici stp

    _Online Scanner
    _Kaspersky Online Scanner
    _My Computer

    https://www.kaspersky.fr/downloads
    0
    1. Bernard
       
      Salut Boulepate62,

      J'ai fait ce que tu m'as dit pour supprimer adirss.exe et ALCXMNT.EXE (sauf 2 logiciels ALCXMNTR créés en 2004 et sept 2006, ne sachant pas s'il fallait les éjecter). Puis ai analysé par un scan online Kaspersky, mais impossible de copier le rapport. Ca bogue à chaque fois. L'ai sauvegardé dans mes fichiers, mais très très lent à ouvrir. 7 virus et 96 fichiers infectés trouvés.

      Si je peux le mettre sur le forum, je le ferais. En tout cas, merci, et il y a nadine24 qui a des problèmes.
      S'il y a d'autres moyens...
      0
      1. Utilisateur anonyme > Bernard
         
        Salut Bernard

        ça fait beaucoup de fichiers infectés tout ça !

        Tu fais ce scanne en ligne il supprimera les virus qu'il trouvera

        Fait ce scan anti-virus en ligne avec Internet Explorer, accepte l'active X; la barre anti-popup du SP2 (en haut) va se mettre à clignoter, clic dessus et choisis "accepter l'active X" pour faire fonctionner le scan anti-virus.
        Une fois qu'il a terminé colle le rapport ici stp

        https://www.bitdefender.com/toolbox/


        Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked"

        O15 - Trusted Zone.....
        O15 - Trusted Zone....
        0
      2. Bernard > Utilisateur anonyme
         
        Salut Boulepate62,

        Merci et ci-après le rapport. Je poursuis les autres manoeuvres.

        BitDefender Online Scanner



        Scan report generated at: Mon, Nov 13, 2006 - 08:21:38





        Scan path: C:\;D:\;E:\;F:\;G:\;H:\;I:\;J:\;







        Statistics

        Time
        01:30:00

        Files
        629393

        Folders
        14594

        Boot Sectors
        3

        Archives
        16060

        Packed Files
        60159




        Results

        Identified Viruses
        8

        Infected Files
        94

        Suspect Files
        0

        Warnings
        0

        Disinfected
        30

        Deleted Files
        64




        Engines Info

        Virus Definitions
        315836

        Engine build
        AVCORE v1.0 (build 2355) (i386) (Sep 25 2006 13:46:24)

        Scan plugins
        13

        Archive plugins
        38

        Unpack plugins
        6

        E-mail plugins
        6

        System plugins
        1




        Scan Settings

        First Action
        Disinfect

        Second Action
        Delete

        Heuristics
        Yes

        Enable Warnings
        Yes

        Scanned Extensions
        *;

        Exclude Extensions


        Scan Emails
        Yes

        Scan Archives
        Yes

        Scan Packed
        Yes

        Scan Files
        Yes

        Scan Boot
        Yes




        Scanned File
        Status

        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\TD998\AMCap.lnk=>C:\WINDOWS\amcap.exe
        Infected with: Win32.Mixor.A@mm

        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\TD998\AMCap.lnk=>C:\WINDOWS\amcap.exe
        Disinfected

        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\TD998\AMCap.lnk
        Updated

        C:\explorer1.exe
        Infected with: Trojan.Downloader.Femad.C

        C:\explorer1.exe
        Disinfection failed

        C:\explorer1.exe
        Deleted

        C:\Program Files\Alwil Software\Avast4\DATA\moved\aom.exe.vir
        Infected with: Win32.Mixor.A@mm

        C:\Program Files\Alwil Software\Avast4\DATA\moved\aom.exe.vir
        Disinfection failed

        C:\Program Files\Alwil Software\Avast4\DATA\moved\aom.exe.vir
        Deleted

        C:\Program Files\Alwil Software\Avast4\DATA\moved\firefox.exe.vir
        Infected with: Win32.Mixor.A@mm

        C:\Program Files\Alwil Software\Avast4\DATA\moved\firefox.exe.vir
        Disinfected

        C:\Program Files\Hitman Pro\packages\cwshredder.exe
        Infected with: Win32.Mixor.A@mm

        C:\Program Files\Hitman Pro\packages\cwshredder.exe
        Disinfected

        C:\Program Files\HP\Digital Imaging\bin\hpdns_01.exe
        Infected with: Win32.Mixor.A@mm

        C:\Program Files\HP\Digital Imaging\bin\hpdns_01.exe
        Disinfected

        C:\Program Files\HP\Digital Imaging\bin\hpdstb01.exe
        Infected with: Win32.Mixor.A@mm

        C:\Program Files\HP\Digital Imaging\bin\hpdstb01.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030617.exe
        Infected with: Worm.Glowa.M

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030617.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030617.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030618.exe
        Infected with: Worm.Glowa.G

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030618.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030618.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030619.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030619.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030619.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030620.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030620.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030620.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030621.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030621.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030621.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030622.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030622.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030622.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030623.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030623.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030623.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030624.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030624.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030624.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030625.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030625.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030625.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030626.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030626.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030626.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030627.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030627.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030627.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030628.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030628.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030628.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030629.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030629.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030629.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030630.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030630.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030630.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030631.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030631.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030631.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030632.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030632.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030632.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030633.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030633.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030633.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030634.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030634.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030634.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030635.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030635.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030635.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030636.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030636.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030636.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030637.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030637.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030637.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030638.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030638.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030638.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030639.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030639.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030639.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030640.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030640.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030640.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030641.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030641.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030641.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030642.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030642.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030642.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030643.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030643.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030643.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030644.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030644.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030644.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030645.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030645.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030645.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030646.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030646.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030646.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030647.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030647.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030647.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030648.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030648.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030648.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030649.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030649.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030649.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030650.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030650.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030650.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030651.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030651.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030651.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030652.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030652.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030652.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030653.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030653.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030653.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030654.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030654.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030654.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030655.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030655.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030655.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030656.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030656.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030656.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030657.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030657.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030657.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030658.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030658.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030658.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030659.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030659.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030659.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030660.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030660.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030660.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030661.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030661.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030661.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030662.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030662.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030662.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030663.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030663.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030663.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030664.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030664.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030664.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030665.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030665.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030665.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030666.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030666.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030666.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030667.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030667.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030667.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030668.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030668.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030668.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030669.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030669.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030669.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030670.exe
        Infected with: Win32.Worm.Nuwar.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030670.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030670.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030671.exe
        Infected with: Trojan.Downloader.Mohbpork.A

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030671.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030671.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030672.exe
        Infected with: Trojan.Downloader.Mohbpork.A

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030672.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030672.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030673.exe
        Infected with: Trojan.Downloader.Mohbpork.A

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030673.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030673.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030674.exe
        Infected with: MemScan:Trojan.Agent.QB

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030674.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030674.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030753.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030753.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030837.EXE
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030837.EXE
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030919.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030919.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030919.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030922.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030922.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030954.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030954.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030957.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030957.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030985.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030985.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030987.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030987.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030989.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0030989.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031010.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031010.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031011.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031011.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031012.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031012.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031013.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031013.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031014.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031014.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031015.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031015.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031016.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031016.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031017.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031017.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031018.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031018.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031019.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0031019.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032171.dll
        Infected with: Trojan.Agent.WN

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032171.dll
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032171.dll
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032185.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032185.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032186.exe
        Infected with: Trojan.Downloader.Femad.C

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032186.exe
        Disinfection failed

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032186.exe
        Deleted

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032187.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032187.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032188.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032188.exe
        Disinfected

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032189.exe
        Infected with: Win32.Mixor.A@mm

        C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP111\A0032189.exe
        Disinfected

        C:\WINDOWS\CleanDev.exe
        Infected with: Win32.Mixor.A@mm

        C:\WINDOWS\CleanDev.exe
        Disinfected

        C:\WINDOWS\ov519cap.exe
        Infected with: Win32.Mixor.A@mm

        C:\WINDOWS\ov519cap.exe
        Disinfected

        C:\WINDOWS\system32\__delete_on_reboot__a_d_i_r_._d_l_l_
        Infected with: Trojan.Agent.WN

        C:\WINDOWS\system32\__delete_on_reboot__a_d_i_r_._d_l_l_
        Disinfection failed

        C:\WINDOWS\system32\__delete_on_reboot__a_d_i_r_._d_l_l_
        Deleted

        C:\WINDOWS\vidcap32.exe
        Infected with: Win32.Mixor.A@mm

        C:\WINDOWS\vidcap32.exe
        Disinfected
        0
  2. Utilisateur anonyme
     
    Re,

    Télécharge SmitfraudFix (enregistre le sur le "bureau")
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip

    décompresse SmitfraudFix
    Lance le fichier SmitfraudFix ou SmitfraudFix.cmd et choisis l option 1 copie le rapport ici stp

    et

    fait un clique droit sur hijackthis choisis "renommer" marque: abcde.exe puis "ok"

    et envoit nous un nouveau rapport hijackthis stp
    0
  3. Bernard
     
    Salut Boulepate,

    Ci-joint le rapport de SmitfraudFix, suivi d'un nouveau log hijackthis.

    Merci.

    SmitFraudFix v2.121

    Rapport fait à 4:12:37,20, 14/11/2006
    Executé à partir de C:\Documents and Settings\HP_Propri‚taire\Bureau\SmitfraudFix\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Fix executé en mode normal

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Propri‚taire

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Propri‚taire\Application Data

    »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

    C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url PRESENT !
    C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url PRESENT !

    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_PRO~1\Favoris

    »»»»»»»»»»»»»»»»»»»»»»»» Bureau

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

    »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="Ma page d'accueil"

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""

    »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

    »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin

    Logfile of HijackThis v1.99.1
    Scan saved at 04:21:04, on 14/11/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\System32\FTRTSVC.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\wbem\wmiapsrv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\windows\system\hpsysdrv.exe
    C:\WINDOWS\system32\hphmon06.exe
    C:\HP\KBD\KBD.EXE
    C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe
    C:\Program Files\InterVideo\Common\Bin\WinRemote.exe
    C:\WINDOWS\system32\keyhook.exe
    C:\WINDOWS\AGRSMMSG.exe
    C:\WINDOWS\ALCXMNTR.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\WINDOWS\system32\rundll32.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\abcde.exe.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
    O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
    O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
    O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
    O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
    O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
    O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
    O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\Wanadoo\CnxMon.exe
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [adir] C:\WINDOWS\system32\adirss.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [AutoTBar] AUTOTBAR.EXE
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
    O9 - Extra button: Messager Wanadoo - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
    O9 - Extra 'Tools' menuitem: Messager Wanadoo - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
    O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
    O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
    O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
    O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe (file missing)
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: RpcService - Unknown owner - C:\WINDOWS\SYSTEM32\EXPLORE.EXE (file missing)
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
    0
  4. Utilisateur anonyme
     
    Salut Bernard

    rien ne sera supprimé sauf si indiqué !

    Relance HijackThis, choisis "do a scan only" coche la case devant les lignes ci-dessous et clic en bas sur "fix checked"

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/...
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/...
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/...
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/...
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/...
    O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
    O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [Home Theater SchSvr] "C:\Program Files\Fichiers communs\InterVideo\SchSvr\SchSvr.exe"
    O4 - HKLM\..\Run: [WINREMOTE] "C:\Program Files\InterVideo\Common\Bin\WinRemote.exe"
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
    O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
    O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
    O20 - Winlogon Notify: rpcc - C:\WINDOWS\system32\rpcc.dll
    O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll

    Clic sur "demarrer", "executer", tape: services.msc ,cherche dans la liste ces lignes, fais un clic droit dessus choisis "propriétés" et régle les sur "désactivé"

    France Telecom Routing Table Service
    InstallDriver Table Manager
    NVIDIA Display Driver Service
    RpcService

    Telecharges Killbox:
    http://www.killbox.net/downloads/KillBox.exe

    Doubles clique sur killbox.exe (Pocket Killbox)

    - coches: delete on reboot
    dans la barre vide entre ceci: (exactement)

    C:\WINDOWS\system32\rpcc.dll

    - cliques sur le rond rouge avec la croix blanche
    - une fenetre va apparaitre pour confirmation cliques sur YES
    - une seconde fenetre te demande si tu veux redemarrer cliques sur NO

    Ensuite à nouveau dans la barre vide tu réentres ceci:

    C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll

    - cliques sur la croix rouge
    - une fenetre va apparaitre pour confirmation cliques sur YES
    - une seconde fenetre te demande si tu veux redemarrer cliques sur YES

    Laisse le pc redemarrer s'il ne redémarre pas de lui même alors fait le.

    Clic sur démarrer, poste de travail, C:, program files et supprime ce dossier:

    MSN Apps

    Clique sur démarrer, rechercher et supprime ces fichiers si encore présent, qu'importe la date

    ALCXMNTR.EXE
    adirss.exe
    taskdir.exe

    **Si un fichier persiste lors de la suppression fait ceci:
    -Redemarres ton pc, dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaitre choisis "mode sans echec" attends un peu.. puis vas supprimer les fichiers/dossiers qui persistaient, vides ta corbeille et redemarres normalement

    Ensuite:

    Redémarres le PC en mode sans échec : tu tapotes sur la touche F8 de ton clavier (ou F5 ) et tu choisis le mode sans échec)

    - Ouvre le dossier "SmitfraudFix" et double clic sur "Smitfraudfix.cmd", choisit l 'option 2 et tu réponds oui à tout.

    Enregistre le rapport puis Copie/colle le rapport sur le forum stp.

    Fait ce nettoyage: (à faire réguliérement)

    ¤Telecharges et installes ceci:
    CCleaner:
    Ccleaner

    dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
    Les sauvegardes que tu aura faites tu pourra les supprimer si ton ordinateur n'a plus de problémes

    ¤Relance Ccleaner, vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"

    Si tu as besoin d'aide pour Ccleaner, regarde ce tutoriel:
    http://www.tutopat.com/viewtopic.php?t=305

    Puis dis moi les logiciels anti-spywares que tu as stp

    A++
    0
    1. Bernard
       
      Salut boulepate62,

      J'ai fait ce que tu m'as indiqué,même si entre les différentes opérations mes grands gamins ont pas mal surfé. Résulat, j'ai un autre virus. Mais bon, je vais essayer de l'éliminer. Je te copie le dernier rapport de smitfraudfix. En tout cas, encore mille fois merci de ton aide précieuse. Si je peux te rendre la pareille dans d'autres domaines.... Bernard. A+++

      SmitFraudFix v2.121

      Rapport fait à 21:35:15,70, 15/11/2006
      Executé à partir de C:\Documents and Settings\HP_Propri‚taire\Bureau\SmitfraudFix\SmitfraudFix
      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
      Fix executé en mode sans echec

      »»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll

      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus


      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

      GenericRenosFix by S!Ri


      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

      C:\WINDOWS\blank.mht supprimé
      C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url supprimé
      C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url supprimé

      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires


      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

      Nettoyage terminé.

      »»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix
      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

      SrchSTS.exe by S!Ri
      Search SharedTaskScheduler's .dll


      »»»»»»»»»»»»»»»»»»»»»»»» Fin
      0
    2. Bernard
       
      Oups, j'ai oublié de te donner les spyware que j'ai:

      Ewido (c'est toi qui me l'as indiqué)
      Spyboot
      Ad aware
      Ad watch SE Professional
      Hitman pro (plusieurs spyware)
      Avast (bouclier anti-virus)

      Voila, je crois que c'est tout...

      Tchao et merci. Bernard
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Utilisateur anonyme
     
    Salut Bernard

    ok, c'est bon pour smitfraudfix tu peux le supprimer.

    Peux tu remettres un rapport hijackthis stp
    0
    1. Bernard
       
      Salut Boulepate62,

      log hijackthis suit. A +++. Bernard

      Logfile of HijackThis v1.99.1
      Scan saved at 06:42:21, on 16/11/2006
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
      C:\Program Files\ewido anti-spyware 4.0\guard.exe
      C:\WINDOWS\system32\svchost.exe
      c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\Explorer.EXE
      C:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\hphmon06.exe
      C:\HP\KBD\KBD.EXE
      C:\WINDOWS\system32\keyhook.exe
      C:\WINDOWS\AGRSMMSG.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\ewido anti-spyware 4.0\ewido.exe
      C:\WINDOWS\system32\spoolsvv.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\SAGEM WiFi manager\WLANUTL.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\abcde.exe.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
      O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
      O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
      O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
      O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
      O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [AutoTBar] AUTOTBAR.EXE
      O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
      O4 - HKLM\..\Run: [spoolsvv] C:\WINDOWS\system32\spoolsvv.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: Utilitaire réseau pour SAGEM Wi-Fi 11g USB adapter.lnk = ?
      O9 - Extra button: Messager Wanadoo - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
      O9 - Extra 'Tools' menuitem: Messager Wanadoo - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\PROGRA~1\WANADO~1\Wanadoo Messager.exe (file missing)
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
      O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
      O12 - Plugin for .mpg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: winsys2freg - C:\Documents and Settings\All Users\Documents\Settings\winsys2f.dll
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
      O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
      O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
      O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - c:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
      0
  7. Utilisateur anonyme
     
    Salut Bernard,

    fait ça:

    Pour afficher tous les dossiers et fichiers cachés;

    Clic sur "démarrer", "panneau de configuration", "outils" ,"option des dossiers", "affichage"
    "
    Coche:
    ¤ afficher les fichiers et dossiers cachés

    Décoche la case:
    ¤ masquer les fichiers protégés du système d'exploitation (recommandé)
    ¤ masquer les extensions dont le type est connu

    Clic sur "appliquer" puis "ok"

    _______
    Clic sur démarrer, poste de travail, C:, documents and settings, all users, documents, settings, et supprime ce fichier:

    winsys2f.dll

    Clic sur démarrer, rechercher, cherche et supprime ce processus:

    spoolsvv.exe < attention, à l'orthographe

    **Si un fichier persiste lors de la suppression fait ceci:
    -Redemarres ton pc, dès l'allumage de celui-ci tapote la touche F8 (ou F5 si F8 ne fonctionne pas), à l'écran qui va apparaitre choisis "mode sans echec" attends un peu.. puis vas supprimer les fichiers/dossiers qui persistaient, vides ta corbeille et redemarres normalement

    Désactive le pare-feu de Windows(SP2) il ne sert à rien puis installe celui ci pour plus de sécurité

    Kerio: (pare-feu, qui reste gratuit après la periode d'essai!)
    Kerio
    -tutoriel: pour configurer et comprendre l'utilisation de Kerio
    https://kerio.probb.fr/
    http://www.infos-du-net.com/telecharger/Firewall-Kerio-Personal,0301-390.html

    0
  8. Bernard
     
    Bonsoir Boulepate62,

    Impossible de désactiver le pare-feu windows, l'accès est impossible pour une raison inconnue. Impossible aussi de supprimer le fichier winsys2f.dll, même en mode sans échec.
    Je n'ai donc pas téléchargé Kério.

    Voilà l'ami. A+++ Bernard
    0
  9. Utilisateur anonyme
     
    Salut Bernanrd

    télécharge et installe ce logiciel
    Dès que c'est fait retourne sur le fichier qui persisté à la suppression puis tu fera un clique droit dessus et tu choisira "unlocker" puis supprimer" au redémarrage ça devrait fonctionné

    Ensuite; (ferme ton navigateur web avant de faire la manip)

    telecharge ça:
    http://download.bleepingcomputer.com/sUBs/combofix.exe

    appuyes sur "Y" pour continuer

    Attends quelques minutes..un rapport va s'ouvrir enregistre son contenu, puis copie et colle le sur ici stp
    0
    1. Bernard
       
      Salut Boulepate62,
      Bien reçu, mais il doit manquer le lien pour le 1er logiciel que tu me dis de télécharger. Enfin, je crois...
      A bientôt
      Bernard
      0
  10. Utilisateur anonyme
     
    0
    1. Bernard
       
      Salut Boulepate62,

      C'est bon, ai pu supprimer le fichier, merci. Voici le log Combofix. Bon courage et A++.

      HP_Propri‚taire - 06-11-18 10:49:08.28 Service Pack 2
      ComboFix 06.11.9 - Running from: "C:\Documents and Settings\HP_Propri‚taire\Bureau"

      (((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


      C:\Documents and Settings\All Users\Documents\Settings


      ((((((((((((((((((((((((((((((( Files Created from 2006-10-17 to 2006-11-17 ))))))))))))))))))))))))))))))))))


      2006-11-17 09:45 28,672 --------- C:\WINDOWS\system32\verclsid.exe
      2006-11-15 08:14 50,000 --ah----- C:\WINDOWS\system32\5E2198.dll
      2006-11-15 08:14 50,000 --ah----- C:\WINDOWS\system32\5D98E0.dll
      2006-11-15 08:06 50,000 --ah----- C:\WINDOWS\system32\56588D.dll
      2006-11-15 07:59 50,000 --ah----- C:\WINDOWS\system32\50878A.dll
      2006-11-15 07:58 50,000 --ah----- C:\WINDOWS\system32\4F7455.dll
      2006-11-15 07:57 50,000 --ah----- C:\WINDOWS\system32\4E36E3.dll
      2006-11-15 07:56 50,000 --ah----- C:\WINDOWS\system32\4D9573.dll
      2006-11-15 07:55 50,000 --ah----- C:\WINDOWS\system32\4CBECA.dll
      2006-11-14 11:59 34,914 -rahs---- C:\WINDOWS\system32\spoolsvv.exe
      2006-11-14 04:12 3,134 --a------ C:\WINDOWS\system32\tmp.reg
      2006-11-14 04:10 53,248 --a------ C:\WINDOWS\system32\Process.exe
      2006-11-14 04:10 40,960 --a------ C:\WINDOWS\system32\swsc.exe
      2006-11-14 04:10 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
      2006-11-14 04:10 135,168 --a------ C:\WINDOWS\system32\swreg.exe
      2006-11-13 18:25 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
      2006-11-13 18:21 18,200 --a------ C:\WINDOWS\system32\wups2.dll
      2006-11-09 11:06 14,686 --a------ C:\WINDOWS\system32\w.exe
      2006-11-07 04:33 90,112 --a------ C:\WINDOWS\system32\AVASTSS.scr
      2006-11-07 04:33 87,424 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
      2006-11-07 04:33 85,952 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
      2006-11-07 04:33 666,240 --a------ C:\WINDOWS\system32\aswBoot.exe
      2006-11-07 04:33 36,176 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
      2006-11-07 04:33 24,560 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
      2006-11-07 04:33 16,352 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
      2006-11-06 13:07 51,072 --a------ C:\WINDOWS\system32\drivers\ikhlayer.sys
      2006-11-06 13:07 30,592 --a------ C:\WINDOWS\system32\drivers\ikhfile.sys
      2006-11-05 16:06 60,489 --a------ C:\WINDOWS\system32\image1.gif.exe
      2006-11-05 16:06 5,705 --a------ C:\WINDOWS\system32\se.exe.exe
      2006-11-04 14:17 1,245,696 --a------ C:\WINDOWS\system32\msxml4.dll
      2006-11-02 21:06 40,960 --a------ C:\WINDOWS\system32\ov519ext.dll
      2006-11-02 21:06 25,211 --a------ C:\WINDOWS\system32\drivers\ov519cmd.sys
      2006-11-02 21:06 174,530 --a------ C:\WINDOWS\system32\drivers\ov519vid.sys
      2006-11-02 21:06 16,426 --a------ C:\WINDOWS\system32\ov519usd.dll
      2006-10-30 09:16 31,744 --a------ C:\WINDOWS\system32\drivers\ZDPSp50a64.sys
      2006-10-30 09:16 29,184 --a------ C:\WINDOWS\system32\drivers\BRGSp50a64.sys
      2006-10-30 09:16 20,608 --a------ C:\WINDOWS\system32\drivers\BRGSp50.sys
      2006-10-30 09:16 17,664 --a------ C:\WINDOWS\system32\drivers\ZDPSp50.sys
      2006-10-30 09:14 493,440 --a------ C:\WINDOWS\system32\drivers\WlanBZ64.SYS
      2006-10-30 09:14 402,432 --a------ C:\WINDOWS\system32\drivers\WlanBZXP.sys
      2006-10-25 23:41 38,229 --------- C:\WINDOWS\system32\drivers\StMp3Rec.sys
      2006-10-21 18:27 114,688 --a------ C:\WINDOWS\system32\WLANUTL.dll
      2006-10-20 18:23 94,208 --a------ C:\WINDOWS\system32\W32n50.dll
      2006-10-20 18:23 40,960 --a------ C:\WINDOWS\system32\FTRTSVC.exe
      2006-10-20 18:23 36,864 --a------ C:\WINDOWS\system32\IfHelper.dll
      2006-10-20 18:23 16,128 --------- C:\WINDOWS\system32\PCANDIS5.SYS


      (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


      2006-11-18 10:46 -------- d-------- C:\Program Files\Unlocker
      2006-11-18 10:44 195645 --a------ C:\Program Files\unlocker_unlocker_1.8.5_francais_20237.exe
      2006-11-18 09:10 -------- d-------- C:\Program Files\Mozilla Firefox
      2006-11-17 17:11 -------- d-------- C:\Program Files\ewido anti-spyware 4.0
      2006-11-17 12:59 -------- d-------- C:\Program Files\Messenger
      2006-11-17 12:54 -------- d-------- C:\Program Files\MSXML 4.0
      2006-11-17 12:52 -------- d-------- C:\Program Files\Internet Explorer
      2006-11-17 12:49 -------- d-------- C:\Program Files\Outlook Express
      2006-11-17 12:49 -------- d-------- C:\Program Files\Fichiers communs\System
      2006-11-16 23:09 -------- d-------- C:\Program Files\Windows Media Player
      2006-11-16 21:44 -------- d-------- C:\Program Files\Microsoft Works
      2006-11-16 06:42 6575 --a------ C:\Program Files\hijackthis.log
      2006-11-15 21:45 -------- d-------- C:\Program Files\CCleaner
      2006-11-15 21:44 1496208 --a------ C:\Program Files\ccsetup134.exe
      2006-11-15 21:10 -------- d-------- C:\Program Files\backups
      2006-11-15 05:52 92672 --a------ C:\Program Files\KillBox.exe
      2006-11-13 08:10 307200 --a------ C:\WINDOWS\vidcap32.exe
      2006-11-13 08:05 135168 --a------ C:\WINDOWS\ov519cap.exe
      2006-11-13 07:54 40960 --a------ C:\WINDOWS\CleanDev.exe
      2006-11-13 06:59 32528 --a------ C:\WINDOWS\amcap.exe
      2006-11-11 18:20 5711904 --a------ C:\Program Files\firefox-2.0.exe
      2006-11-11 17:52 215697 --a------ C:\Program Files\hijackthis.zip
      2006-11-11 14:34 -------- d-------- C:\Program Files\MSN Messenger
      2006-11-11 13:45 -------- d-------- C:\Program Files\vmntoolbar
      2006-11-11 13:45 -------- d-------- C:\Program Files\Fake Webcam
      2006-11-11 13:42 -------- d-------- C:\Program Files\Wanadoo
      2006-11-11 13:42 -------- d-------- C:\Program Files\Spyware Doctor
      2006-11-11 13:42 -------- d-------- C:\Program Files\Sonic RecordNow!
      2006-11-11 13:42 -------- d-------- C:\Program Files\SAGEM WiFi manager
      2006-11-11 13:42 -------- d-------- C:\Program Files\RegCleaner
      2006-11-11 13:42 -------- d-------- C:\Program Files\QuickTime
      2006-11-11 13:42 -------- d-------- C:\Program Files\PhotoFiltre
      2006-11-11 13:42 -------- d-------- C:\Program Files\mtp-target
      2006-11-11 13:42 -------- d-------- C:\Program Files\iTunes
      2006-11-11 13:42 -------- d-------- C:\Program Files\eMule
      2006-11-11 13:41 -------- d-a------ C:\Program Files\PC-Doctor for Windows
      2006-11-11 13:41 -------- d-------- C:\Program Files\PhotoDeluxe BE 1.0 TO
      2006-11-11 13:41 -------- d-------- C:\Program Files\Microsoft Picture It! 9
      2006-11-11 13:40 -------- d-------- C:\Program Files\MSN Reaper
      2006-11-11 13:40 -------- d-------- C:\Program Files\MessengerPlus! 3
      2006-11-11 13:40 -------- d-------- C:\Program Files\Messenger Plus! Live
      2006-11-11 13:40 -------- d-------- C:\Program Files\K-Lite Codec Pack
      2006-11-11 13:40 -------- d-------- C:\Program Files\Hitman Pro
      2006-11-11 13:39 -------- d-------- C:\Program Files\Help and Support Additions
      2006-11-11 13:38 -------- d-------- C:\Program Files\Fichiers communs\snpstd
      2006-11-11 13:38 -------- d-------- C:\Program Files\Easy Internet signup
      2006-11-11 13:38 -------- d-------- C:\Program Files\CamStudio
      2006-11-11 13:38 -------- d-------- C:\Program Files\AC3Filter
      2006-11-11 13:38 -------- d-------- C:\Program Files\12Planet Instant Communication Server v3.0.0
      2006-11-11 13:37 -------- d-------- C:\Documents and Settings\HP_Propri‚taire\Application Data\MSNInstaller
      2006-11-11 10:03 6020448 --a------ C:\Program Files\ewido-setup_4.0.0.172c.exe
      2006-11-10 17:08 5711904 --a------ C:\Program Files\Firefox Setup 2.0.exe
      2006-11-09 22:53 908 --a------ C:\Program Files\aswclnr.log
      2006-11-09 22:23 403072 --a------ C:\Program Files\aswclnr.exe
      2006-11-07 04:33 -------- d-------- C:\Program Files\Alwil Software
      2006-11-07 04:27 12220440 --a------ C:\Program Files\avast_avast_4.7.892_francais_anglais_11113.exe
      2006-11-06 21:15 -------- d-------- C:\Documents and Settings\HP_Propri‚taire\Application Data\Webroot
      2006-11-06 21:15 -------- d-------- C:\Documents and Settings\HP_Propri‚taire\Application Data\PC Tools
      2006-11-06 07:49 -------- d-------- C:\Program Files\MSN Toolbar
      2006-11-05 13:02 -------- d-------- C:\Program Files\DivX
      2006-10-31 12:28 258 --a------ C:\Documents and Settings\HP_Propri‚taire\Application Data\wklnhst.dat
      2006-10-30 09:16 -------- d--h----- C:\Program Files\InstallShield Installation Information
      2006-10-30 09:15 -------- d-------- C:\Program Files\SAGEM
      2006-10-24 16:55 -------- d---s---- C:\Documents and Settings\HP_Propri‚taire\Application Data\Microsoft
      2006-10-21 14:38 -------- d-------- C:\Program Files\Thomson
      2006-10-20 17:59 -------- d-------- C:\Program Files\Securitoo
      2006-10-15 19:01 -------- d-------- C:\Program Files\Microsoft Office
      2006-10-15 18:57 -------- d-------- C:\Program Files\Microsoft Works Suite 2004
      2006-10-13 13:36 145920 --a------ C:\WINDOWS\system32\nwprovau.dll
      2006-10-07 18:48 163644 --a------ C:\WINDOWS\system32\drivers\secdrv.sys
      2006-10-01 06:10 0 --a------ C:\ja.exe
      2006-09-21 01:54 -------- d-------- C:\Documents and Settings\HP_Propri‚taire\Application Data\Macromedia
      2006-09-20 21:53 -------- d-------- C:\Documents and Settings\HP_Propri‚taire\Application Data\Mozilla
      2006-09-20 21:41 -------- d-------- C:\Program Files\Fichiers communs\Symantec Shared
      2006-09-20 21:40 -------- d-------- C:\Program Files\Symantec
      2006-09-20 21:28 -------- d-------- C:\Documents and Settings\HP_Propri‚taire\Application Data\Motive
      2006-09-20 19:41 -------- d-------- C:\Documents and Settings\HP_Propri‚taire\Application Data\Help
      2006-09-20 18:39 -------- d-------- C:\Program Files\WinRAR
      2006-09-20 18:17 -------- d-------- C:\Program Files\Diskeeper Corporation
      2006-09-20 18:17 -------- d-------- C:\Documents and Settings\HP_Propri‚taire\Application Data\Leadertech
      2006-09-20 18:16 -------- d-------- C:\Program Files\Lavasoft
      2006-09-20 18:16 -------- d-------- C:\Documents and Settings\HP_Propri‚taire\Application Data\Lavasoft
      2006-09-20 17:33 -------- d-------- C:\Documents and Settings\HP_Propri‚taire\Application Data\vlc
      2006-09-20 05:04 -------- d-------- C:\Program Files\Windows NT
      2006-09-20 05:04 -------- d-------- C:\Program Files\NetMeeting
      2006-09-18 00:41 -------- d-------- C:\Program Files\Google
      2006-09-13 06:03 1084416 --a------ C:\WINDOWS\system32\msxml3.dll
      2006-08-25 16:51 617472 --a------ C:\WINDOWS\system32\comctl32.dll
      2006-08-21 13:26 16896 --a------ C:\WINDOWS\system32\fltlib.dll
      2006-08-21 10:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe
      2006-08-17 13:29 728576 --a------ C:\WINDOWS\system32\lsasrv.dll
      2006-08-17 13:29 132096 --a------ C:\WINDOWS\system32\wkssvc.dll


      (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

      *Note* empty entries are not shown

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
      "hpsysdrv"="c:\\windows\\system\\hpsysdrv.exe"
      "HPHUPD06"="c:\\Program Files\\HP\\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\\hphupd06.exe"
      "HPHmon06"="C:\\WINDOWS\\system32\\hphmon06.exe"
      "KBD"="C:\\HP\\KBD\\KBD.EXE"
      "Recguard"="C:\\WINDOWS\\SMINST\\RECGUARD.EXE"
      "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
      "SiS Windows KeyHook"="C:\\WINDOWS\\system32\\keyhook.exe"
      "AGRSMMSG"="AGRSMMSG.exe"
      "PS2"="C:\\WINDOWS\\system32\\ps2.exe"
      "iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
      "avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
      "AutoTBar"="AUTOTBAR.EXE"
      "!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
      "spoolsvv"="C:\\WINDOWS\\system32\\spoolsvv.exe"
      "UnlockerAssistant"="\"C:\\Program Files\\Unlocker\\UnlockerAssistant.exe\""

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
      "Installed"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
      "Installed"="1"
      "NoChange"="1"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
      "Installed"="1"

      [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
      "DeskHtmlVersion"=dword:00000110
      "DeskHtmlMinorVersion"=dword:00000005
      "Settings"=dword:00000001
      "GeneralFlags"=dword:00000000

      [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
      "Spyware Doctor"=""

      [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
      "Spyware Doctor"=""

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
      "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pré-chargeur Browseui"
      "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Démon de cache des catégories de composant"

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
      "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
      "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
      "NoDriveTypeAutoRun"=hex:95,00,00,00

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
      "dontdisplaylastusername"=dword:00000000
      "legalnoticecaption"=""
      "legalnoticetext"=""
      "shutdownwithoutlogon"=dword:00000001
      "undockwithoutlogon"=dword:00000001

      [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
      "NoDriveTypeAutoRun"=dword:00000091

      [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
      "NoDriveTypeAutoRun"=dword:00000091

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
      "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
      "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
      "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
      "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

      HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winsys2freg

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
      "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


      Contents of the 'Scheduled Tasks' folder
      C:\WINDOWS\tasks\AD539ED591B81581.job
      C:\WINDOWS\tasks\Symantec NetDetect.job

      Completion time: 06-11-18 10:50:57.62
      C:\ComboFix.txt ... 06-11-18 10:50
      0
  11. Utilisateur anonyme
     
    Salut Bernard,

    merci, pour le rapport

    Clique sur démarrer, poste de travail, C:, Windows, system32(dossier) cherche et supprime ces processus:

    spoolsvv.exe
    w.exe
    image1.gif.exe
    se.exe.exe
    IfHelper.dll

    Il reste des fichiers suspect, je reviendrais vers toi plus tard dans la journèe car la j'ai sommeil, n'hésite pas à me faire un petit bilan de ton PC me dire comment il se porte ;-)

    Bonne jounèe, à toute à l'heure
    0
    1. Bernard
       
      Rebonjour Boulepate62,

      Ai effectué les opérations indiquées. Le PC se porte mieux. Pas de fichiers au démarrage et plus de virus indiqué par avast. Par contre, toujours impossible d'ouvrir le dossier pare-feu windows, et de réinstaller les outils works (word excel ect..).

      Merci beaucoup et...Bonne nuit ! Bernard.
      0
    2. Bernard
       
      Ah oui, j'ai oublié aussi un logiciel qui se met en route à l'ouverture des sessions AOI Software windows. On doit annuler car il ne trouve pas d'emplacement. Je ne sais pas à quoi il sert...

      Tchao et bon réveil...
      0
    3. Bernard
       
      Salut Boulepate62,

      En fait c'est AiO Software. Sinon, il y a 4 ou 5 mois, l'ordi s'est planté pour cause de virus : il s'allumait mais s'éteignait aussitôt. Un copain m'a tout réinstallé, Je ne sais pas comment il a fait, car je n'ai jamais pu faire de DVD de réinstallation, car il boguait à mi-chemin systématiquement chaque fois que j'ai tenté de créer ce DVD. Voilà, tu sais tout.

      Amicalement, Bernard.
      0