Infectée par trojan downloader
Résolu
kristell
Messages postés
5
Date d'inscription
Statut
Membre
Dernière intervention
-
Lyonnais92 Messages postés 25159 Date d'inscription Statut Contributeur sécurité Dernière intervention -
Lyonnais92 Messages postés 25159 Date d'inscription Statut Contributeur sécurité Dernière intervention -
Bonjour,
J'ai un problème avec le virus Trojan sur mon ordinateur .mon antivirus Antivir le détecte mais ne peut pas le déplacer ou le désinfecter.
je suis sous windows XP.
j'ai fait un scan avec Hijack This et il me préconise de le soumettre a quelqu'un qui s'y connait bien en informatique. J'ai également fait un scan avec Smitfraudfix. Quelqu'un pourrait il m'aider s'il vous plait. Je vous remercie d'avance. Voici les rapportsde Hijackthis et de smitfraudfix:
Logfile of HijackThis v1.99.1
Scan saved at 14:28:37, on 03/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\windows\system32\svchosts.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\msasvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\windows\system32\slserv.exe
C:\windows\system32\svchost.exe
C:\windows\system32\rundll32.exe
C:\windows\dsrss.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\windows\system32\rundll32.exe
C:\Program Files\Fichiers communs\{182AD39E-0A76-1036-1022-040409280021}\Update.exe
C:\windows\TEMP\win1B.tmp.exe
C:\windows\system32\udial.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MessengerSkinner\MessengerSkinner.exe
C:\windows\system32\ctpmon.exe
C:\windows\system32\ctpmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\windows\system32\udial.exe
C:\windows\system32\udial.exe
C:\windows\system32\udial.exe
C:\windows\system32\udial.exe
C:\Program Files\PeDevice\PeDev.exe
C:\windows\system32\udial.exe
C:\Program Files\a-squared Free\a2free.exe
C:\windows\system32\udial.exe
C:\windows\system32\udial.exe
C:\windows\system32\udial.exe
C:\windows\explorer.exe
C:\Program Files\AVPersonal\AVWIN.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\windows\system32\udial.exe
C:\Documents and Settings\GUEVEL\Bureau\HijackThis.exe
C:\windows\system32\ctpmon.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [rmploknjmi] c:\windows\system32\rmploknjmi.exe rmploknjmi
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NI.UWAS6V_0001_N91M2208] "C:\documents and settings\guevel\application data\winantispyware2006freeinstall_fr[1].exe" -nag
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [gfmabch.dll] C:\windows\system32\rundll32.exe "C:\Documents and Settings\GUEVEL\Local Settings\Application Data\gfmabch.dll",qnpqijg
O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
O4 - HKLM\..\Run: [IE Redir] C:\windows\ieredir.exe
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [WinAntiSpyware 2006 Free] "C:\Program Files\WinAntiSpyware 2006 Free\was6.exe" /min
O4 - HKLM\..\Run: [uwas6cw] "C:\Program Files\WinAntiSpyware 2006 Free\uwas6cw.exe" -c
O4 - HKLM\..\Run: [eotbzve.dll] C:\windows\system32\rundll32.exe C:\windows\system32\eotbzve.dll,ucmwbn
O4 - HKLM\..\Run: [{182AD39E-0A76-1036-1022-040409280021}] "C:\Program Files\Fichiers communs\{182AD39E-0A76-1036-1022-040409280021}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [syswin] C:\windows\TEMP\win1B.tmp.exe
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\windows\system32\dkoeipbw.dll",setvm
O4 - HKLM\..\Run: [UDial] C:\windows\system32/udial.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [messengerskinner] C:\Program Files\MessengerSkinner\MessengerSkinner.exe
O4 - HKCU\..\Run: [ctpmon] ctpmon.exe
O4 - Global Startup: .protected
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Suchen - res://C:\windows\system32\Suchspur.dll/Suchspur.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\windows\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {A4F64D63-3576-4754-8DD5-4D0A49345FD5} - (no file) (HKCU)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: COM+ Messages - Unknown owner - C:\windows\system32\svchosts.exe" -e mc-110-12-0000272 (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\windows\system32\msasvc.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\windows\SYSTEM32\slserv.exe
SmitFraudFix v2.138
Rapport fait à 16:32:09,50, 03/02/2007
Executé à partir de C:\Documents and Settings\GUEVEL\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows
C:\windows\.protected PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\system32
C:\windows\system32\ctpmon.exe PRESENT !
C:\windows\system32\RegistryCleanerSetup.exe PRESENT !
C:\windows\system32\svchosts.exe PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\GUEVEL
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\GUEVEL\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\DMARRA~1\.protected PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GUEVEL\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
huy32 détecté, utilisez un scanner de Rootkit
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
J'ai un problème avec le virus Trojan sur mon ordinateur .mon antivirus Antivir le détecte mais ne peut pas le déplacer ou le désinfecter.
je suis sous windows XP.
j'ai fait un scan avec Hijack This et il me préconise de le soumettre a quelqu'un qui s'y connait bien en informatique. J'ai également fait un scan avec Smitfraudfix. Quelqu'un pourrait il m'aider s'il vous plait. Je vous remercie d'avance. Voici les rapportsde Hijackthis et de smitfraudfix:
Logfile of HijackThis v1.99.1
Scan saved at 14:28:37, on 03/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\windows\system32\svchosts.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\msasvc.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\windows\system32\slserv.exe
C:\windows\system32\svchost.exe
C:\windows\system32\rundll32.exe
C:\windows\dsrss.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\windows\system32\rundll32.exe
C:\Program Files\Fichiers communs\{182AD39E-0A76-1036-1022-040409280021}\Update.exe
C:\windows\TEMP\win1B.tmp.exe
C:\windows\system32\udial.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MessengerSkinner\MessengerSkinner.exe
C:\windows\system32\ctpmon.exe
C:\windows\system32\ctpmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\windows\system32\udial.exe
C:\windows\system32\udial.exe
C:\windows\system32\udial.exe
C:\windows\system32\udial.exe
C:\Program Files\PeDevice\PeDev.exe
C:\windows\system32\udial.exe
C:\Program Files\a-squared Free\a2free.exe
C:\windows\system32\udial.exe
C:\windows\system32\udial.exe
C:\windows\system32\udial.exe
C:\windows\explorer.exe
C:\Program Files\AVPersonal\AVWIN.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\windows\system32\udial.exe
C:\Documents and Settings\GUEVEL\Bureau\HijackThis.exe
C:\windows\system32\ctpmon.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [rmploknjmi] c:\windows\system32\rmploknjmi.exe rmploknjmi
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NI.UWAS6V_0001_N91M2208] "C:\documents and settings\guevel\application data\winantispyware2006freeinstall_fr[1].exe" -nag
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [gfmabch.dll] C:\windows\system32\rundll32.exe "C:\Documents and Settings\GUEVEL\Local Settings\Application Data\gfmabch.dll",qnpqijg
O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
O4 - HKLM\..\Run: [IE Redir] C:\windows\ieredir.exe
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [WinAntiSpyware 2006 Free] "C:\Program Files\WinAntiSpyware 2006 Free\was6.exe" /min
O4 - HKLM\..\Run: [uwas6cw] "C:\Program Files\WinAntiSpyware 2006 Free\uwas6cw.exe" -c
O4 - HKLM\..\Run: [eotbzve.dll] C:\windows\system32\rundll32.exe C:\windows\system32\eotbzve.dll,ucmwbn
O4 - HKLM\..\Run: [{182AD39E-0A76-1036-1022-040409280021}] "C:\Program Files\Fichiers communs\{182AD39E-0A76-1036-1022-040409280021}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [syswin] C:\windows\TEMP\win1B.tmp.exe
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\windows\system32\dkoeipbw.dll",setvm
O4 - HKLM\..\Run: [UDial] C:\windows\system32/udial.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [messengerskinner] C:\Program Files\MessengerSkinner\MessengerSkinner.exe
O4 - HKCU\..\Run: [ctpmon] ctpmon.exe
O4 - Global Startup: .protected
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Suchen - res://C:\windows\system32\Suchspur.dll/Suchspur.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\windows\system32\shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {A4F64D63-3576-4754-8DD5-4D0A49345FD5} - (no file) (HKCU)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: Boonty Games - Unknown owner - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe (file missing)
O23 - Service: COM+ Messages - Unknown owner - C:\windows\system32\svchosts.exe" -e mc-110-12-0000272 (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: Microsoft authenticate service (MsaSvc) - Unknown owner - C:\windows\system32\msasvc.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\windows\SYSTEM32\slserv.exe
SmitFraudFix v2.138
Rapport fait à 16:32:09,50, 03/02/2007
Executé à partir de C:\Documents and Settings\GUEVEL\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows
C:\windows\.protected PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\system32
C:\windows\system32\ctpmon.exe PRESENT !
C:\windows\system32\RegistryCleanerSetup.exe PRESENT !
C:\windows\system32\svchosts.exe PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\GUEVEL
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\GUEVEL\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\DMARRA~1\.protected PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GUEVEL\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="Ma page d'accueil"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
huy32 détecté, utilisez un scanner de Rootkit
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
A voir également:
- Infectée par trojan downloader
- Downloader for pc - Télécharger - Téléchargement & Transfert
- Freemake video downloader - Télécharger - Téléchargement & Transfert
- Telecharger youtube downloader - Télécharger - Conversion & Codecs
- Flash video downloader - Télécharger - Téléchargement & Transfert
- Trojan remover - Télécharger - Antivirus & Antimalwares
41 réponses
Re,
toujours là !
Relance Hijackthis.
Choisis do a scan only.
Coche la case devant ces lignes :
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\nmfoeqbr.dll (file missing)
O9 - Extra button: (no name) - {A4F64D63-3576-4754-8DD5-4D0A49345FD5} - (no file) (HKCU)
Ferme toutes les fenêtres et clique sur fix cjhecked.
Ferme et réouvre HijackThis.
Choisis the misc tools section.
et delete a file on reboot.
Trouve ce fichier
C:\windows\system32\pmnmjkk.dll
et tu clique sur ouvrir.
Quand il te deamnde si tu veux rebooter, tu reponds non et tu reclique sur delete a file on reboot.
Tu cherches C:\windows\system32\jkhhf.dll puis Ouvrir.
Maintenant tu réponds oui à la question du reboot.
Tu redémarres normalement et tu mets un nouveau log HijackThis.
@+
toujours là !
Relance Hijackthis.
Choisis do a scan only.
Coche la case devant ces lignes :
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\nmfoeqbr.dll (file missing)
O9 - Extra button: (no name) - {A4F64D63-3576-4754-8DD5-4D0A49345FD5} - (no file) (HKCU)
Ferme toutes les fenêtres et clique sur fix cjhecked.
Ferme et réouvre HijackThis.
Choisis the misc tools section.
et delete a file on reboot.
Trouve ce fichier
C:\windows\system32\pmnmjkk.dll
et tu clique sur ouvrir.
Quand il te deamnde si tu veux rebooter, tu reponds non et tu reclique sur delete a file on reboot.
Tu cherches C:\windows\system32\jkhhf.dll puis Ouvrir.
Maintenant tu réponds oui à la question du reboot.
Tu redémarres normalement et tu mets un nouveau log HijackThis.
@+
Re,
Tu réouivres HijackThis,
tu choisis do a scan only.
Tu coches la case devant ces lignes :
O2 - BHO: (no name) - {0DFDAA04-D717-47B6-821F-0E7D91007B0F} - C:\windows\system32\jkhhf.dll
O2 - BHO: (no name) - {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} - C:\windows\system32\pmnmjkk.dll
O9 - Extra button: (no name) - {A4F64D63-3576-4754-8DD5-4D0A49345FD5} - (no file) (HKCU)
O20 - Winlogon Notify: jkhhf - C:\windows\system32\jkhhf.dll
O20 - Winlogon Notify: pmnmjkk - C:\windows\SYSTEM32\pmnmjkk.dll
Tu fermes toutes les fenêtres actives et tu cliques sur fix checked.
Tu fermes HijackThis.
Tu réouvres vundofix.
Scan puis remove. Tu acceptes tous les redémarrages. Tu postes le log.
Tu mets un noveau log HijackThis.
Au reboot de vundofix, attends un moment. J'ai l'impression que le fix n'est pas terminé. J'ai l'impression qu'il recommence à examiner les fichiers. Si tu regardes les cas précédents, tu verras qu'il change la liste à chaque itération. Laisse le faire 'jusqu'au bout'.
@+
Tu réouivres HijackThis,
tu choisis do a scan only.
Tu coches la case devant ces lignes :
O2 - BHO: (no name) - {0DFDAA04-D717-47B6-821F-0E7D91007B0F} - C:\windows\system32\jkhhf.dll
O2 - BHO: (no name) - {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} - C:\windows\system32\pmnmjkk.dll
O9 - Extra button: (no name) - {A4F64D63-3576-4754-8DD5-4D0A49345FD5} - (no file) (HKCU)
O20 - Winlogon Notify: jkhhf - C:\windows\system32\jkhhf.dll
O20 - Winlogon Notify: pmnmjkk - C:\windows\SYSTEM32\pmnmjkk.dll
Tu fermes toutes les fenêtres actives et tu cliques sur fix checked.
Tu fermes HijackThis.
Tu réouvres vundofix.
Scan puis remove. Tu acceptes tous les redémarrages. Tu postes le log.
Tu mets un noveau log HijackThis.
Au reboot de vundofix, attends un moment. J'ai l'impression que le fix n'est pas terminé. J'ai l'impression qu'il recommence à examiner les fichiers. Si tu regardes les cas précédents, tu verras qu'il change la liste à chaque itération. Laisse le faire 'jusqu'au bout'.
@+
Bonjour,
je suis pris cet après midi.
Alors, pour avancer, si la situation n'a pas évoluée, c'est à dire si les lignes 02 et 020 sont encore là (s'il y a file missing, elles n'y sont plus), tu fais tout cela :
1) Tu supprimes tous les fix utilisés (et leurs fichiers, log associés). Tu regardes si il y a une procédure de désinstallation (via panneau de configuration,Ajout/suppression de programmes). Sinon, tu supprimes en passant par l'explorateur.
SmitfraudFix
Blacklight
Vundofix
Navifix et les associés
Combofix
Rustbfix
escan antivirus toolkit (C:\Kaspersky)
Clean.zip et fichiers associés
2) Tu retélécharges combofix (voir post 11) , tu l'exécutes, tu postes le log.
3) tu retélécharges Smitfraud fix, tu l'exécutes, tu postes le log
4) Tu retélécharges Navifix (voir post 7) , décompression, exécution choix 1, tu postes le log,
5) tu retélécharges Clean.zip (post 25) , décompression, exécution, tu postes le log.
6) Spybot mis à jour, exécution, destruction de tout ce qu'il trouve, vaccination.
7) mise à jour de AVG antispy, exécution,nettoyage, tu postes le log
@+
je suis pris cet après midi.
Alors, pour avancer, si la situation n'a pas évoluée, c'est à dire si les lignes 02 et 020 sont encore là (s'il y a file missing, elles n'y sont plus), tu fais tout cela :
1) Tu supprimes tous les fix utilisés (et leurs fichiers, log associés). Tu regardes si il y a une procédure de désinstallation (via panneau de configuration,Ajout/suppression de programmes). Sinon, tu supprimes en passant par l'explorateur.
SmitfraudFix
Blacklight
Vundofix
Navifix et les associés
Combofix
Rustbfix
escan antivirus toolkit (C:\Kaspersky)
Clean.zip et fichiers associés
2) Tu retélécharges combofix (voir post 11) , tu l'exécutes, tu postes le log.
3) tu retélécharges Smitfraud fix, tu l'exécutes, tu postes le log
4) Tu retélécharges Navifix (voir post 7) , décompression, exécution choix 1, tu postes le log,
5) tu retélécharges Clean.zip (post 25) , décompression, exécution, tu postes le log.
6) Spybot mis à jour, exécution, destruction de tout ce qu'il trouve, vaccination.
7) mise à jour de AVG antispy, exécution,nettoyage, tu postes le log
@+
bonsoir,
les lignes 02 et 20 étaient toujours là j'ai donc suivi le post 39
voici tous les rapports
a+
"GUEVEL" - 07-02-07 21:01:15 Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Program Files\Mozilla Firefox"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\GUEVEL
C:\qoobox\purity\DOCUME~1\GUEVEL\Application Data
C:\qoobox\purity\DOCUME~1\GUEVEL\Application Data\from.txt
C:\qoobox\purity\DOCUME~1\GUEVEL\Application Data\YSTEM3~1
C:\qoobox\purity\WINDOWS\ASKS~1
C:\qoobox\purity\WINDOWS\FNTS~1
C:\qoobox\purity\WINDOWS\system32\ECURIT~1
C:\qoobox\purity\WINDOWS\system32\MCROSO~1
((((((((((((((((((((((((((((((( Files Created from 2007-01-07 to 2007-02-07 ))))))))))))))))))))))))))))))))))
2007-02-07 17:19 118,804 --a------ C:\WINDOWS\system32\whefqcch.dll
2007-02-07 05:33 76,412 --a------ C:\WINDOWS\system32\bgxpcxow.dll
2007-02-06 13:20 <REP> d-------- C:\Program Files\MSN Messenger
2007-02-06 05:33 76,412 --a------ C:\WINDOWS\system32\tcwleyec.dll
2007-02-05 22:06 <REP> d-------- C:\Downloads
2007-02-05 22:06 <REP> d-------- C:\Bases
2007-02-05 12:52 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-02-05 05:52 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-05 05:52 <REP> d-------- C:\Program Files\Grisoft
2007-02-05 01:02 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-02-05 01:01 42,920 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2007-02-05 01:01 <REP> d-------- C:\WINDOWS\system32\ZoneLabs
2007-02-05 01:00 <REP> d-------- C:\WINDOWS\Internet Logs
2007-02-04 16:27 <REP> d-------- C:\Program Files\Kerio
2007-02-03 16:32 3,648 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-03 15:26 <REP> d-------- C:\WINDOWS\Sun
2007-02-03 15:26 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Sun
2007-02-03 13:40 <REP> d-------- C:\Program Files\Yahoo!
2007-02-02 17:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Talkback
2007-02-02 14:19 94,720 --a------ C:\WINDOWS\system32\xaygtbc.dll
2007-02-02 14:13 <REP> d-------- C:\Program Files\a-squared Free
2007-02-02 12:38 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-02-02 12:38 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2007-02-02 12:38 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2007-02-02 02:22 <REP> d--h----- C:\Program Files\Fichiers communs\Uninstall Information
2007-02-02 02:20 95,232 --a------ C:\WINDOWS\system32\uguzrcf.dll
2007-02-01 19:51 277,234 --------- C:\WINDOWS\system32\jkhhf.dll
2007-02-01 19:45 22,591 --------- C:\WINDOWS\system32\pmnmjkk.dll
2007-02-01 13:48 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-02-01 13:14 <REP> d-------- C:\DOCUME~1\GUEVEL\Contacts
2007-02-01 13:12 434,252 --a------ C:\WINDOWS\system32\Msvcrtd.dll
2007-02-01 13:11 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-02-01 12:13 95,232 --a------ C:\WINDOWS\system32\gaunhre.dll
2007-02-01 02:11 <REP> d-------- C:\DOCUME~1\GUEVEL\Mes documents
2007-01-31 23:51 <REP> d-------- C:\Program Files\PeDevice
2007-01-31 13:22 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Trymedia
2007-01-30 17:34 <REP> d-------- C:\Program Files\Java
2007-01-30 17:33 <REP> d-------- C:\Program Files\Fichiers communs\Java
2007-01-30 15:05 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\SecondLife
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\PlayFirst
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\PlayFirst
2007-01-30 02:48 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-01-24 13:56 <REP> d-------- C:\Program Files\Real
2007-01-24 13:56 <REP> d-------- C:\Program Files\Fichiers communs\Real
2007-01-24 13:56 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Real
2007-01-24 13:28 <REP> d-------- C:\Program Files\MSN Apps
2007-01-22 22:26 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-01-19 15:43 <REP> d-------- C:\Program Files\MSXML 4.0
2007-01-19 12:53 51,056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-19 10:32 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-01-19 10:32 <REP> d-------- C:\WINDOWS\system32\PreInstall
2007-01-19 10:12 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Lavasoft
2007-01-19 01:30 0 --a------ C:\WINDOWS\nsreg.dat
2007-01-18 17:26 <REP> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-01-18 17:20 3,757 --a------ C:\WINDOWS\mozver.dat
2007-01-18 17:20 <REP> d-------- C:\Program Files\Mozilla Firefox
2007-01-18 16:53 <REP> d-------- C:\Program Files\Lavasoft
2007-01-18 14:29 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Google
2007-01-18 14:28 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google
2007-01-18 14:14 <REP> d-------- C:\Program Files\Google
2007-01-18 14:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google Updater
2007-01-18 12:57 <REP> d---s---- C:\DOCUME~1\GUEVEL\UserData
2007-01-18 12:17 <REP> d--hs---- C:\WINDOWS\ftpcache
2007-01-18 12:17 <REP> d-------- C:\Program Files\Free
2007-01-11 14:15 53,248 -ra------ C:\WINDOWS\system32\NeroCo.dll
2007-01-11 14:15 1,658,880 --------- C:\WINDOWS\UNNeroBurnRights.exe
2007-01-11 14:08 99,568 --------- C:\WINDOWS\system32\drivers\incdfs.sys
2007-01-11 14:08 9,561 --------- C:\WINDOWS\system32\drivers\incdrec.sys
2007-01-11 14:08 27,664 --------- C:\WINDOWS\system32\drivers\incdpass.sys
2007-01-11 14:08 1,769,472 --------- C:\WINDOWS\NuNinst.exe
2007-01-11 14:08 <REP> d-------- C:\WINDOWS\InCD
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-06 01:08 -------- d---s---- C:\DOCUME~1\GUEVEL\Application Data\microsoft
2007-02-05 12:38 -------- d-------- C:\Program Files\avpersonal
2007-02-02 00:25 -------- d-------- C:\Program Files\ahead
2007-02-01 13:18 3665 --a------ C:\WINDOWS\urls.dat
2007-02-01 13:18 17896 --a------ C:\WINDOWS\htmlcode.dat
2007-01-31 12:10 -------- d--h----- C:\Program Files\installshield installation information
2007-01-31 12:10 -------- d-------- C:\Program Files\epson
2007-01-31 10:27 -------- d-------- C:\Program Files\quicktime
2007-01-28 11:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobeum
2007-01-20 01:56 48616 --a--c--- C:\WINDOWS\system32\perfc00c.dat
2007-01-20 01:56 367658 --a--c--- C:\WINDOWS\system32\perfh00c.dat
2007-01-19 15:46 -------- d-------- C:\Program Files\messenger
2007-01-19 01:30 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\mozilla
2007-01-18 15:20 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\macromedia
2007-01-18 12:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobe
2007-01-11 15:12 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\ahead
2006-12-07 17:02 2174976 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"regkeyname"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"NeroFilterCheck"="C:\\windows\\system32\\NeroCheck.exe"
"AVGCtrl"="C:\\Program Files\\AVPersonal\\AVGNT.EXE /min"
"iKeyWorks"="C:\\PROGRA~1\\A4Tech\\Keyboard\\Ikeymain.exe"
"EPSON Stylus Photo RX420 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9CE.EXE /P31 \"EPSON Stylus Photo RX420 Series\" /O6 \"USB001\" /M \"Stylus Photo RX420\""
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"AVSCHED32"="C:\\Program Files\\AVPersonal\\AVSCHED32.EXE /min"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"DllRunning"="rundll32.exe \"C:\\windows\\system32\\whefqcch.dll\",setvm"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhhf
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmjkk
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6359eeb0-4e50-11db-82f0-001109630ca1}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL 4x3_LIEVIN_BIS.PDF
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-07 21:05:41
SmitFraudFix v2.140
Rapport fait à 21:06:59,37, 07/02/2007
Executé à partir de C:\Documents and Settings\GUEVEL\Bureau\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\GUEVEL
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\GUEVEL\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GUEVEL\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
"LoadAppInit_DLLs"=dword:00000001
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Search Navipromo version 1.0.3 commencé le 07/02/2007 à 21:09:16,51
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Poster ce rapport sur le forum pour le faire analyser !!!
!!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!
Fix lancé depuis C:\Documents and Settings\GUEVEL\Bureau\navilog1
Mise a jour le 01.02.2007 a 21h00 by IL-MAFIOSO
Executé en mode normal
*** Recherche Programmes installes ***
*** Recherche dossiers dans C:\windows ***
*** Recherche dossiers dans C:\Program Files ***
*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***
*** Recherche dossiers dans C:\Documents and Settings\GUEVEL\Application Data ***
*** Recherche avec BlackLight Engine/F-secure ***
BlackLight Engine est un produit de F-secure, pour + d'infos :
https://www.f-secure.com/en
F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
======================================
Copyright 2005-2006 F-Secure Corporation. All rights reserved.
This is a beta version. It will expire on 1st of April, 2007.
Version information: 2.2.1055.
[+] Started on 02/07/07 at 21:09:20.
[+] Initializing ...
[+] Starting scan, press Ctrl-C to abort.
[+] Scanning for hidden items ........................................
[+] Scan complete.
[+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
[+] Exited on 02/07/07 at 21:12:34 (return code = 0).
*** Recherche fichiers ***
*** Recherche cles registre ***
Recharche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
Recharche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]
Recherche Clé Magic Control
*** Module de recherche complémentaire ***
(recherche fichiers spécifiques)
*** Analyse Terminé le 07/02/2007 à 21:14:26,28 ***
Rapport clean par Malekal_morte - http://www.malekal.com
Option 1, executee le 07/02/2007 a 21:18:07,57
*** Recherche de fichiers sur C:
*** Recherche des fichiers dans C:\windows\
*** Recherche des fichiers dans C:\windows\system32
C:\windows\system32\mcrh.tmp FOUND
C:\windows\system32\SpoonUninstall.exe FOUND
"C:\Program Files\PeDevice\" FOUND
*** Fin du rapport !
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 22:21:40 07/02/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{2C7AF1E4-B2BC-4175-A4AF-DF9EB1EDFECC}\RP330\A0117616.dll -> Adware.Virtumonde : Nettoyé.
C:\System Volume Information\_restore{2C7AF1E4-B2BC-4175-A4AF-DF9EB1EDFECC}\RP330\A0117618.dll -> Adware.Virtumonde : Nettoyé.
C:\WINDOWS\system32\pmnmjkk.dll -> Adware.Virtumonde : Nettoyé.
:mozilla.39:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.40:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.42:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.43:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.44:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@247realmedia[1].txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.145:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.164:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.58:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.8:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.122:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.123:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.131:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.132:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.133:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.134:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.9:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.62:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.124:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.125:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.126:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.7:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.15:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.105:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.106:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.107:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.108:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.71:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.109:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.110:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.111:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.112:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@questionmarket[2].txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.118:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.119:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.61:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.11:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.12:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.13:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.53:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
Fin du rapport
les lignes 02 et 20 étaient toujours là j'ai donc suivi le post 39
voici tous les rapports
a+
"GUEVEL" - 07-02-07 21:01:15 Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Program Files\Mozilla Firefox"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~
Folders Quarantined:
C:\qoobox\purity\DOCUME~1
C:\qoobox\purity\DOCUME~1\GUEVEL
C:\qoobox\purity\DOCUME~1\GUEVEL\Application Data
C:\qoobox\purity\DOCUME~1\GUEVEL\Application Data\from.txt
C:\qoobox\purity\DOCUME~1\GUEVEL\Application Data\YSTEM3~1
C:\qoobox\purity\WINDOWS\ASKS~1
C:\qoobox\purity\WINDOWS\FNTS~1
C:\qoobox\purity\WINDOWS\system32\ECURIT~1
C:\qoobox\purity\WINDOWS\system32\MCROSO~1
((((((((((((((((((((((((((((((( Files Created from 2007-01-07 to 2007-02-07 ))))))))))))))))))))))))))))))))))
2007-02-07 17:19 118,804 --a------ C:\WINDOWS\system32\whefqcch.dll
2007-02-07 05:33 76,412 --a------ C:\WINDOWS\system32\bgxpcxow.dll
2007-02-06 13:20 <REP> d-------- C:\Program Files\MSN Messenger
2007-02-06 05:33 76,412 --a------ C:\WINDOWS\system32\tcwleyec.dll
2007-02-05 22:06 <REP> d-------- C:\Downloads
2007-02-05 22:06 <REP> d-------- C:\Bases
2007-02-05 12:52 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-02-05 05:52 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-05 05:52 <REP> d-------- C:\Program Files\Grisoft
2007-02-05 01:02 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-02-05 01:01 42,920 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2007-02-05 01:01 <REP> d-------- C:\WINDOWS\system32\ZoneLabs
2007-02-05 01:00 <REP> d-------- C:\WINDOWS\Internet Logs
2007-02-04 16:27 <REP> d-------- C:\Program Files\Kerio
2007-02-03 16:32 3,648 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-03 15:26 <REP> d-------- C:\WINDOWS\Sun
2007-02-03 15:26 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Sun
2007-02-03 13:40 <REP> d-------- C:\Program Files\Yahoo!
2007-02-02 17:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Talkback
2007-02-02 14:19 94,720 --a------ C:\WINDOWS\system32\xaygtbc.dll
2007-02-02 14:13 <REP> d-------- C:\Program Files\a-squared Free
2007-02-02 12:38 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-02-02 12:38 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2007-02-02 12:38 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2007-02-02 02:22 <REP> d--h----- C:\Program Files\Fichiers communs\Uninstall Information
2007-02-02 02:20 95,232 --a------ C:\WINDOWS\system32\uguzrcf.dll
2007-02-01 19:51 277,234 --------- C:\WINDOWS\system32\jkhhf.dll
2007-02-01 19:45 22,591 --------- C:\WINDOWS\system32\pmnmjkk.dll
2007-02-01 13:48 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-02-01 13:14 <REP> d-------- C:\DOCUME~1\GUEVEL\Contacts
2007-02-01 13:12 434,252 --a------ C:\WINDOWS\system32\Msvcrtd.dll
2007-02-01 13:11 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-02-01 12:13 95,232 --a------ C:\WINDOWS\system32\gaunhre.dll
2007-02-01 02:11 <REP> d-------- C:\DOCUME~1\GUEVEL\Mes documents
2007-01-31 23:51 <REP> d-------- C:\Program Files\PeDevice
2007-01-31 13:22 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Trymedia
2007-01-30 17:34 <REP> d-------- C:\Program Files\Java
2007-01-30 17:33 <REP> d-------- C:\Program Files\Fichiers communs\Java
2007-01-30 15:05 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\SecondLife
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\PlayFirst
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\PlayFirst
2007-01-30 02:48 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-01-24 13:56 <REP> d-------- C:\Program Files\Real
2007-01-24 13:56 <REP> d-------- C:\Program Files\Fichiers communs\Real
2007-01-24 13:56 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Real
2007-01-24 13:28 <REP> d-------- C:\Program Files\MSN Apps
2007-01-22 22:26 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-01-19 15:43 <REP> d-------- C:\Program Files\MSXML 4.0
2007-01-19 12:53 51,056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-19 10:32 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-01-19 10:32 <REP> d-------- C:\WINDOWS\system32\PreInstall
2007-01-19 10:12 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Lavasoft
2007-01-19 01:30 0 --a------ C:\WINDOWS\nsreg.dat
2007-01-18 17:26 <REP> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-01-18 17:20 3,757 --a------ C:\WINDOWS\mozver.dat
2007-01-18 17:20 <REP> d-------- C:\Program Files\Mozilla Firefox
2007-01-18 16:53 <REP> d-------- C:\Program Files\Lavasoft
2007-01-18 14:29 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Google
2007-01-18 14:28 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google
2007-01-18 14:14 <REP> d-------- C:\Program Files\Google
2007-01-18 14:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google Updater
2007-01-18 12:57 <REP> d---s---- C:\DOCUME~1\GUEVEL\UserData
2007-01-18 12:17 <REP> d--hs---- C:\WINDOWS\ftpcache
2007-01-18 12:17 <REP> d-------- C:\Program Files\Free
2007-01-11 14:15 53,248 -ra------ C:\WINDOWS\system32\NeroCo.dll
2007-01-11 14:15 1,658,880 --------- C:\WINDOWS\UNNeroBurnRights.exe
2007-01-11 14:08 99,568 --------- C:\WINDOWS\system32\drivers\incdfs.sys
2007-01-11 14:08 9,561 --------- C:\WINDOWS\system32\drivers\incdrec.sys
2007-01-11 14:08 27,664 --------- C:\WINDOWS\system32\drivers\incdpass.sys
2007-01-11 14:08 1,769,472 --------- C:\WINDOWS\NuNinst.exe
2007-01-11 14:08 <REP> d-------- C:\WINDOWS\InCD
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-06 01:08 -------- d---s---- C:\DOCUME~1\GUEVEL\Application Data\microsoft
2007-02-05 12:38 -------- d-------- C:\Program Files\avpersonal
2007-02-02 00:25 -------- d-------- C:\Program Files\ahead
2007-02-01 13:18 3665 --a------ C:\WINDOWS\urls.dat
2007-02-01 13:18 17896 --a------ C:\WINDOWS\htmlcode.dat
2007-01-31 12:10 -------- d--h----- C:\Program Files\installshield installation information
2007-01-31 12:10 -------- d-------- C:\Program Files\epson
2007-01-31 10:27 -------- d-------- C:\Program Files\quicktime
2007-01-28 11:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobeum
2007-01-20 01:56 48616 --a--c--- C:\WINDOWS\system32\perfc00c.dat
2007-01-20 01:56 367658 --a--c--- C:\WINDOWS\system32\perfh00c.dat
2007-01-19 15:46 -------- d-------- C:\Program Files\messenger
2007-01-19 01:30 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\mozilla
2007-01-18 15:20 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\macromedia
2007-01-18 12:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobe
2007-01-11 15:12 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\ahead
2006-12-07 17:02 2174976 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"regkeyname"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"NeroFilterCheck"="C:\\windows\\system32\\NeroCheck.exe"
"AVGCtrl"="C:\\Program Files\\AVPersonal\\AVGNT.EXE /min"
"iKeyWorks"="C:\\PROGRA~1\\A4Tech\\Keyboard\\Ikeymain.exe"
"EPSON Stylus Photo RX420 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9CE.EXE /P31 \"EPSON Stylus Photo RX420 Series\" /O6 \"USB001\" /M \"Stylus Photo RX420\""
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"AVSCHED32"="C:\\Program Files\\AVPersonal\\AVSCHED32.EXE /min"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"DllRunning"="rundll32.exe \"C:\\windows\\system32\\whefqcch.dll\",setvm"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhhf
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmjkk
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6359eeb0-4e50-11db-82f0-001109630ca1}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL 4x3_LIEVIN_BIS.PDF
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-07 21:05:41
SmitFraudFix v2.140
Rapport fait à 21:06:59,37, 07/02/2007
Executé à partir de C:\Documents and Settings\GUEVEL\Bureau\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\windows\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\GUEVEL
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\GUEVEL\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GUEVEL\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
"LoadAppInit_DLLs"=dword:00000001
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»»»»»»»»»»»»»»»»»»»» Fin
Search Navipromo version 1.0.3 commencé le 07/02/2007 à 21:09:16,51
!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Poster ce rapport sur le forum pour le faire analyser !!!
!!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!
Fix lancé depuis C:\Documents and Settings\GUEVEL\Bureau\navilog1
Mise a jour le 01.02.2007 a 21h00 by IL-MAFIOSO
Executé en mode normal
*** Recherche Programmes installes ***
*** Recherche dossiers dans C:\windows ***
*** Recherche dossiers dans C:\Program Files ***
*** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***
*** Recherche dossiers dans C:\Documents and Settings\GUEVEL\Application Data ***
*** Recherche avec BlackLight Engine/F-secure ***
BlackLight Engine est un produit de F-secure, pour + d'infos :
https://www.f-secure.com/en
F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
======================================
Copyright 2005-2006 F-Secure Corporation. All rights reserved.
This is a beta version. It will expire on 1st of April, 2007.
Version information: 2.2.1055.
[+] Started on 02/07/07 at 21:09:20.
[+] Initializing ...
[+] Starting scan, press Ctrl-C to abort.
[+] Scanning for hidden items ........................................
[+] Scan complete.
[+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
[+] Exited on 02/07/07 at 21:12:34 (return code = 0).
*** Recherche fichiers ***
*** Recherche cles registre ***
Recharche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]
Recharche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]
Recherche Clé Magic Control
*** Module de recherche complémentaire ***
(recherche fichiers spécifiques)
*** Analyse Terminé le 07/02/2007 à 21:14:26,28 ***
Rapport clean par Malekal_morte - http://www.malekal.com
Option 1, executee le 07/02/2007 a 21:18:07,57
*** Recherche de fichiers sur C:
*** Recherche des fichiers dans C:\windows\
*** Recherche des fichiers dans C:\windows\system32
C:\windows\system32\mcrh.tmp FOUND
C:\windows\system32\SpoonUninstall.exe FOUND
"C:\Program Files\PeDevice\" FOUND
*** Fin du rapport !
---------------------------------------------------------
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 22:21:40 07/02/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{2C7AF1E4-B2BC-4175-A4AF-DF9EB1EDFECC}\RP330\A0117616.dll -> Adware.Virtumonde : Nettoyé.
C:\System Volume Information\_restore{2C7AF1E4-B2BC-4175-A4AF-DF9EB1EDFECC}\RP330\A0117618.dll -> Adware.Virtumonde : Nettoyé.
C:\WINDOWS\system32\pmnmjkk.dll -> Adware.Virtumonde : Nettoyé.
:mozilla.39:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.40:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.42:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.43:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.44:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@247realmedia[1].txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.145:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.164:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.58:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.8:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.122:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.123:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.131:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.132:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.133:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.134:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.9:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.62:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.124:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.125:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
:mozilla.126:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Comclick : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Nettoyé.
:mozilla.7:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.15:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.105:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.106:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.107:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.108:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.71:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.109:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.110:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.111:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.112:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@questionmarket[2].txt -> TrackingCookie.Questionmarket : Nettoyé.
:mozilla.118:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.119:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Sitestat : Nettoyé.
:mozilla.61:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.11:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.12:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.13:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.53:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
Fin du rapport
Bonsoir,
je ne sais pas quelle heure il est chez toi.
Redémarre ton PC en mode sans échec :
Double-clic sur clean. Cela va ouvrir une fenêtre noire.
Un menu va apparaître, choisis l'option 2 en appuyant sur la touche 2 de ton clavier.
Clean va travailler.
Un rapport va etre généré, envoie le moi dans ta prochaine réponse .
redémarre en mode normal.
remets un log HikackThis.
@+
je ne sais pas quelle heure il est chez toi.
Redémarre ton PC en mode sans échec :
Double-clic sur clean. Cela va ouvrir une fenêtre noire.
Un menu va apparaître, choisis l'option 2 en appuyant sur la touche 2 de ton clavier.
Clean va travailler.
Un rapport va etre généré, envoie le moi dans ta prochaine réponse .
redémarre en mode normal.
remets un log HikackThis.
@+
salut
ben chez moi l'heure s'écrit 10111h100111 et ça s'énonce 23h39
voici les 2 rapports
à+
Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Option 2, executee le 07/02/2007 a 23:35:59,89
Microsoft Windows XP [version 5.1.2600]
*** Suppression de fichiers sur C:
*** Suppression des fichiers dans C:\windows\
*** Suppression des fichiers dans C:\windows\system32
tentative de suppression de C:\windows\system32\mcrh.tmp
tentative de suppression de C:\windows\system32\SpoonUninstall.exe
tentative de suppression de "C:\Program Files\PeDevice\"
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
Logfile of HijackThis v1.99.1
Scan saved at 23:45:02, on 07/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\windows\system32\svchost.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\GUEVEL\Bureau\Hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
ben chez moi l'heure s'écrit 10111h100111 et ça s'énonce 23h39
voici les 2 rapports
à+
Script execute en mode sans echec
Rapport clean par Malekal_morte - http://www.malekal.com
Option 2, executee le 07/02/2007 a 23:35:59,89
Microsoft Windows XP [version 5.1.2600]
*** Suppression de fichiers sur C:
*** Suppression des fichiers dans C:\windows\
*** Suppression des fichiers dans C:\windows\system32
tentative de suppression de C:\windows\system32\mcrh.tmp
tentative de suppression de C:\windows\system32\SpoonUninstall.exe
tentative de suppression de "C:\Program Files\PeDevice\"
*** Suppression des clefs du registre effectuee..
*** Fin du rapport !
Logfile of HijackThis v1.99.1
Scan saved at 23:45:02, on 07/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\windows\system32\svchost.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\GUEVEL\Bureau\Hijackthis.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Re,
ben chez moi l'heure s'écrit 10111h100111 et ça s'énonce 23h39 GMT mdr.
Supprime ce dossier : C:\qoobox.
Tu as poussé le zèle jusqu'à détruire HijackThis.exe et le retélécharger.
Renomme le à nouveau Vundoscan.exe
Peux tu vérifier si Cleanzip a bien fonctionné en cherchant, par l'explorateur Windows les fichiers et dossiers cités ( C:\windows\system32\mcrh.tmp , C:\windows\system32\SpoonUninstall.exe, C:\Program Files\PeDevice).
Si oui, tu retélécharges VundoFix.
Tu le lances (double clic) puis scan, puis remove.
Tu postes le rapport avec un nouveau rapport HijackThis.
Si non, tu postes seulement un rapport HijackThis.
Je n'ai pas été assez attentif aux posts 25 et 28 sur Cleanzip (il fonctionne comme SmitfraudFix, option 1 en mode normal pour scanner, option 2 en mode sans échec pour éradiquer).
@+
ben chez moi l'heure s'écrit 10111h100111 et ça s'énonce 23h39 GMT mdr.
Supprime ce dossier : C:\qoobox.
Tu as poussé le zèle jusqu'à détruire HijackThis.exe et le retélécharger.
Renomme le à nouveau Vundoscan.exe
Peux tu vérifier si Cleanzip a bien fonctionné en cherchant, par l'explorateur Windows les fichiers et dossiers cités ( C:\windows\system32\mcrh.tmp , C:\windows\system32\SpoonUninstall.exe, C:\Program Files\PeDevice).
Si oui, tu retélécharges VundoFix.
Tu le lances (double clic) puis scan, puis remove.
Tu postes le rapport avec un nouveau rapport HijackThis.
Si non, tu postes seulement un rapport HijackThis.
Je n'ai pas été assez attentif aux posts 25 et 28 sur Cleanzip (il fonctionne comme SmitfraudFix, option 1 en mode normal pour scanner, option 2 en mode sans échec pour éradiquer).
@+
salut
je n'ai pas trouvé ces dossiers...donc voici le rapport hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 00:42:11, on 08/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\windows\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Adobe\Adobe Illustrator CS2\Support Files\Contents\Windows\Illustrator.exe
C:\DOCUME~1\GUEVEL\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\DOCUME~1\GUEVEL\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {09863B72-5ECD-4934-B5E5-4A572C935A2F} - C:\windows\system32\jkhhf.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} - C:\windows\system32\pmnmjkk.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: jkhhf - C:\windows\system32\jkhhf.dll
O20 - Winlogon Notify: pmnmjkk - C:\windows\SYSTEM32\pmnmjkk.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
je n'ai pas trouvé ces dossiers...donc voici le rapport hijackthis
Logfile of HijackThis v1.99.1
Scan saved at 00:42:11, on 08/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\windows\system32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Adobe\Adobe Illustrator CS2\Support Files\Contents\Windows\Illustrator.exe
C:\DOCUME~1\GUEVEL\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
C:\DOCUME~1\GUEVEL\LOCALS~1\Temp\Adobelm_Cleanup.0001
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {09863B72-5ECD-4934-B5E5-4A572C935A2F} - C:\windows\system32\jkhhf.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} - C:\windows\system32\pmnmjkk.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: jkhhf - C:\windows\system32\jkhhf.dll
O20 - Winlogon Notify: pmnmjkk - C:\windows\SYSTEM32\pmnmjkk.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Re,
Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
http://www.atribune.org/ccount/click.php?id=4
Double-clique VundoFix.exe afin de le lancer.
Clique sur le bouton Scan for Vundo.
Lorsque le scan est complété, clique sur le bouton Remove Vundo.
Une invite te demandera si tu veux supprimer les fichiers, clique YES
Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
Démarre ton PC à nouveau.
Post le log Vundofix avec un nouveau log HijackThis.
@+
Télécharge VundoFix.exe (par Atribune) sur ton Bureau.
http://www.atribune.org/ccount/click.php?id=4
Double-clique VundoFix.exe afin de le lancer.
Clique sur le bouton Scan for Vundo.
Lorsque le scan est complété, clique sur le bouton Remove Vundo.
Une invite te demandera si tu veux supprimer les fichiers, clique YES
Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers.
Tu verras une invite qui t'annonce que ton PC va s'éteindre ("shutdown") ; clique OK
Démarre ton PC à nouveau.
Post le log Vundofix avec un nouveau log HijackThis.
@+
Salut
voici les 2 scans
VundoFix V6.3.5
Checking Java version...
Scan started at 00:51:04 08/02/2007
Listing files found while scanning....
C:\windows\system32\fhhkj.ini
C:\windows\system32\hccqfehw.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\pmnmjkk.dll
C:\windows\system32\whefqcch.dll
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\hccqfehw.ini
C:\windows\system32\hccqfehw.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Attempting to delete C:\windows\system32\whefqcch.dll
C:\windows\system32\whefqcch.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Logfile of HijackThis v1.99.1
Scan saved at 01:28:16, on 08/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} - C:\windows\system32\pmnmjkk.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {A5B13795-07A4-4DFF-8157-708B3BDF7DD2} - C:\windows\system32\jkhhf.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: jkhhf - C:\windows\system32\jkhhf.dll
O20 - Winlogon Notify: pmnmjkk - C:\windows\SYSTEM32\pmnmjkk.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
voici les 2 scans
VundoFix V6.3.5
Checking Java version...
Scan started at 00:51:04 08/02/2007
Listing files found while scanning....
C:\windows\system32\fhhkj.ini
C:\windows\system32\hccqfehw.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\pmnmjkk.dll
C:\windows\system32\whefqcch.dll
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\hccqfehw.ini
C:\windows\system32\hccqfehw.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Attempting to delete C:\windows\system32\whefqcch.dll
C:\windows\system32\whefqcch.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Logfile of HijackThis v1.99.1
Scan saved at 01:28:16, on 08/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\spoolsv.exe
C:\windows\Explorer.EXE
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} - C:\windows\system32\pmnmjkk.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {A5B13795-07A4-4DFF-8157-708B3BDF7DD2} - C:\windows\system32\jkhhf.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: jkhhf - C:\windows\system32\jkhhf.dll
O20 - Winlogon Notify: pmnmjkk - C:\windows\SYSTEM32\pmnmjkk.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Bonjour,
Rends toi sur ce site :
http://www.virustotal.com/xhtml/virustotal_en.html
Clique sur parcourir et cherche ce fichier : C:\WINDOWS\system32\gaunhre.dll
Clique sur send.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Télécharge Killbox (Option^Explicit) http://www.downloads.subratam.org/KillBox.zip
(Tu trouveras une démo ici :
http://mickael.barroux.free.fr/securite/killbox.html et une autre là : http://pageperso.aol.fr/balltrap34/killbox.htm)
- Clique sur KillBox Download Link pour le télécharger
-- Décompresse le sur le bureau
- Clique sur Démarrer exécuter tape notepad puis clique sur Ok
- Sélectionne le texte en citation et fais en un copier coller dans le blocnote (notepad)
C:\WINDOWS\system32\whefqcch.dll
C:\WINDOWS\system32\bgxpcxow.dll
C:\WINDOWS\system32\tcwleyec.dll
C:\WINDOWS\system32\zllictbl.dat
C:\WINDOWS\system32\xaygtbc.dll
C:\WINDOWS\system32\uguzrcf.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\gaunhre.dll
* Dans le bloc notes sur le menu en haut clique sur Edition >>> Sélectionner tout puis Edition >>> Copier
* Ouvre Killbox
-- Coche la case [X] "Delete on next reboot"
-- Clique sur le menu File puis sur Paste from Clipboard
* Clique sur la croix blanche sur fond rouge
-- au message "All listed files will be deleted on next reboot" clique sur OUI
-- Au message "Files will be removed on next reboot, Do you want to reboot now ?" clique sur OUI
-- Redémarre ton ordinateur en mode sans échec s'il ne le fait pas automatiquement
* Aprés son redémarrage supprime le dossier C:\!Killbox
Vide la corbeille et les quarantaines.
Relance Vundofix, scan puis remove.
Redémarre en mode normal.
Poste le rapport de Killbox, le rapport de VUndofix et un nouveau rapport HijackThis.
Si Vundofix n'a pas pu tuer tous les fichiers, relance Combofix et poste le rapport.
@+
Rends toi sur ce site :
http://www.virustotal.com/xhtml/virustotal_en.html
Clique sur parcourir et cherche ce fichier : C:\WINDOWS\system32\gaunhre.dll
Clique sur send.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Télécharge Killbox (Option^Explicit) http://www.downloads.subratam.org/KillBox.zip
(Tu trouveras une démo ici :
http://mickael.barroux.free.fr/securite/killbox.html et une autre là : http://pageperso.aol.fr/balltrap34/killbox.htm)
- Clique sur KillBox Download Link pour le télécharger
-- Décompresse le sur le bureau
- Clique sur Démarrer exécuter tape notepad puis clique sur Ok
- Sélectionne le texte en citation et fais en un copier coller dans le blocnote (notepad)
C:\WINDOWS\system32\whefqcch.dll
C:\WINDOWS\system32\bgxpcxow.dll
C:\WINDOWS\system32\tcwleyec.dll
C:\WINDOWS\system32\zllictbl.dat
C:\WINDOWS\system32\xaygtbc.dll
C:\WINDOWS\system32\uguzrcf.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\gaunhre.dll
* Dans le bloc notes sur le menu en haut clique sur Edition >>> Sélectionner tout puis Edition >>> Copier
* Ouvre Killbox
-- Coche la case [X] "Delete on next reboot"
-- Clique sur le menu File puis sur Paste from Clipboard
* Clique sur la croix blanche sur fond rouge
-- au message "All listed files will be deleted on next reboot" clique sur OUI
-- Au message "Files will be removed on next reboot, Do you want to reboot now ?" clique sur OUI
-- Redémarre ton ordinateur en mode sans échec s'il ne le fait pas automatiquement
* Aprés son redémarrage supprime le dossier C:\!Killbox
Vide la corbeille et les quarantaines.
Relance Vundofix, scan puis remove.
Redémarre en mode normal.
Poste le rapport de Killbox, le rapport de VUndofix et un nouveau rapport HijackThis.
Si Vundofix n'a pas pu tuer tous les fichiers, relance Combofix et poste le rapport.
@+
salut
voici les rapports
j'ai relancé combofix à la fin car je crois que vundofix n'arrive pas à venir à bout de C:\windows\system32\jkhhf.dll et C:\windows\system32\pmnmjkk.dl
je l'ai relancé +sieurs fois, j'ai essayé aussi en faisant add files mais rien y fait.
à+
Complete scanning result of "gaunhre.dll", received in VirusTotal at 02.08.2007, 13:10:34 (CET).
Antivirus Version Update Result
AntiVir 7.3.1.34 02.08.2007 TR/Crypt.XPACK.Gen
Authentium 4.93.8 02.07.2007 Possibly a new variant of W32/new-malware!Maximus
Avast 4.7.936.0 02.07.2007 no virus found
AVG 386 02.07.2007 no virus found
BitDefender 7.2 02.08.2007 Trojan.Obfus.Gen
CAT-QuickHeal 9.00 02.07.2007 no virus found
ClamAV devel-20060426 02.08.2007 no virus found
DrWeb 4.33 02.08.2007 Trojan.DownLoader.based
eSafe 7.0.14.0 02.08.2007 suspicious Trojan/Worm
eTrust-InoculateIT 30.4.3378 02.08.2007 no virus found
eTrust-Vet 30.4.3378 02.08.2007 no virus found
Ewido 4.0 02.07.2007 no virus found
Fortinet 2.85.0.0 02.08.2007 suspicious
F-Prot 4.2.1.29 02.07.2007 W32/new-malware!Maximus
F-Secure 6.70.13030.0 02.08.2007 W32/Malware
Ikarus T3.1.0.31 02.08.2007 Trojan-Downloader.Win32.Busky.gen
Kaspersky 4.0.2.24 02.08.2007 no virus found
McAfee 4958 02.07.2007 Downloader-AXI.gen
Microsoft 1.2101 02.08.2007 Trojan:Win32/Busky.gen
NOD32v2 2045 02.08.2007 a variant of Win32/TrojanDownloader.Busky.AZ
Norman 5.80.02 02.07.2007 W32/Malware
Panda 9.0.0.4 02.08.2007 Suspicious file
Prevx1 V2 02.08.2007 no virus found
Sophos 4.13.0 02.08.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.08.2007 Trojan.Busky
TheHacker 6.1.6.053 02.07.2007 no virus found
UNA 1.83 02.07.2007 no virus found
VBA32 3.11.2 02.07.2007 no virus found
VirusBuster 4.3.19:9 02.07.2007 Trojan.DL.Obfusc.Gen3
Aditional Information
File size: 95232 bytes
MD5: 840e31a35bb9d69227a3e56d73c3a180
SHA1: a84b73cd1ac64ef2d4a4f1328482c7d5e881368c
packers: UPX
packers: UPX
packers: UPX, embedded
norman sandbox: [ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Decompressing UPX.
* File length: 95232 bytes.
[ Changes to filesystem ]
* Creates file C:WINDOWSSYSTEM32gaunhre.dll.
* Creates file C:WINDOWSSYSTEM32 qgrrwk.dll.
[ Changes to registry ]
* Creates key "HKLMSoftwareAdwareDisableKey4".
* Sets value "default"="1166912096" in key "HKLMSoftwareAdwareDisableKey4".
* Creates key "HKCUSoftwareAdwareDisableKey4".
* Sets value "default"="1166912096" in key "HKCUSoftwareAdwareDisableKey4".
* Deletes value "e7d22331.exe" in key "HKCUSoftwareMicrosoftWindowsCurrentVersionRun".
* Deletes value "e7d22331.exe" in key "HKLMSoftwareMicrosoftWindowsCurrentVersionRun".
* Creates value "gaunhre.dll"="C:WINDOWS undll32.exe C:WINDOWSSYSTEM32gaunhre.dll,gshxpzc" in key "HKLMSoftwareMicrosoftWindowsCurrentVersionRun".
* Creates key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
* Sets value "default"="C:WINDOWSSYSTEM32 qgrrwk.dll" in key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
* Sets value "ThreadingModel"="Apartment" in key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
[ Process/window information ]
* Creates a mutex a4d22331.
* Enumerates running processes.
* Will automatically restart after boot (I'll be back...).
VundoFix V6.3.5
Checking Java version...
Scan started at 13:36:09 08/02/2007
Listing files found while scanning....
C:\windows\system32\fhhkj.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\pmnmjkk.dll
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Logfile of HijackThis v1.99.1
Scan saved at 14:00:55, on 08/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} - C:\windows\system32\pmnmjkk.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {A691EB64-4E4C-459A-B644-BF428E54624A} - C:\windows\system32\jkhhf.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: jkhhf - C:\windows\system32\jkhhf.dll
O20 - Winlogon Notify: pmnmjkk - C:\windows\SYSTEM32\pmnmjkk.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
"GUEVEL" - 07-02-08 14:02:03 Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Documents and Settings\GUEVEL\Bureau"
((((((((((((((((((((((((((((((( Files Created from 2007-01-08 to 2007-02-08 ))))))))))))))))))))))))))))))))))
2007-02-08 00:51 <REP> d-------- C:\VundoFix Backups
2007-02-07 21:08 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-02-06 13:20 <REP> d-------- C:\Program Files\MSN Messenger
2007-02-06 05:33 76,412 --a------ C:\WINDOWS\system32\tcwleyec.dll
2007-02-05 22:06 <REP> d-------- C:\Downloads
2007-02-05 22:06 <REP> d-------- C:\Bases
2007-02-05 05:52 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-05 05:52 <REP> d-------- C:\Program Files\Grisoft
2007-02-05 01:02 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-02-05 01:01 42,920 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2007-02-05 01:01 <REP> d-------- C:\WINDOWS\system32\ZoneLabs
2007-02-05 01:00 <REP> d-------- C:\WINDOWS\Internet Logs
2007-02-04 16:27 <REP> d-------- C:\Program Files\Kerio
2007-02-03 16:32 3,094 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-03 15:26 <REP> d-------- C:\WINDOWS\Sun
2007-02-03 15:26 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Sun
2007-02-03 13:40 <REP> d-------- C:\Program Files\Yahoo!
2007-02-02 17:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Talkback
2007-02-02 14:19 94,720 --a------ C:\WINDOWS\system32\xaygtbc.dll
2007-02-02 14:13 <REP> d-------- C:\Program Files\a-squared Free
2007-02-02 12:38 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-02-02 12:38 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2007-02-02 12:38 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2007-02-02 02:22 <REP> d--h----- C:\Program Files\Fichiers communs\Uninstall Information
2007-02-02 02:20 95,232 --a------ C:\WINDOWS\system32\uguzrcf.dll
2007-02-01 19:51 277,234 --------- C:\WINDOWS\system32\jkhhf.dll
2007-02-01 19:45 22,591 --------- C:\WINDOWS\system32\pmnmjkk.dll
2007-02-01 13:48 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-02-01 13:14 <REP> d-------- C:\DOCUME~1\GUEVEL\Contacts
2007-02-01 13:12 434,252 --a------ C:\WINDOWS\system32\Msvcrtd.dll
2007-02-01 13:11 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-02-01 12:13 95,232 --a------ C:\WINDOWS\system32\gaunhre.dll
2007-02-01 02:11 <REP> d-------- C:\DOCUME~1\GUEVEL\Mes documents
2007-01-31 13:22 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Trymedia
2007-01-30 17:34 <REP> d-------- C:\Program Files\Java
2007-01-30 17:33 <REP> d-------- C:\Program Files\Fichiers communs\Java
2007-01-30 15:05 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\SecondLife
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\PlayFirst
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\PlayFirst
2007-01-30 02:48 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-01-24 13:56 <REP> d-------- C:\Program Files\Real
2007-01-24 13:56 <REP> d-------- C:\Program Files\Fichiers communs\Real
2007-01-24 13:56 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Real
2007-01-24 13:28 <REP> d-------- C:\Program Files\MSN Apps
2007-01-22 22:26 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-01-19 15:43 <REP> d-------- C:\Program Files\MSXML 4.0
2007-01-19 12:53 51,056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-19 10:32 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-01-19 10:32 <REP> d-------- C:\WINDOWS\system32\PreInstall
2007-01-19 10:12 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Lavasoft
2007-01-19 01:30 0 --a------ C:\WINDOWS\nsreg.dat
2007-01-18 17:26 <REP> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-01-18 17:20 3,757 --a------ C:\WINDOWS\mozver.dat
2007-01-18 17:20 <REP> d-------- C:\Program Files\Mozilla Firefox
2007-01-18 16:53 <REP> d-------- C:\Program Files\Lavasoft
2007-01-18 14:29 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Google
2007-01-18 14:28 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google
2007-01-18 14:14 <REP> d-------- C:\Program Files\Google
2007-01-18 14:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google Updater
2007-01-18 12:57 <REP> d---s---- C:\DOCUME~1\GUEVEL\UserData
2007-01-18 12:17 <REP> d--hs---- C:\WINDOWS\ftpcache
2007-01-18 12:17 <REP> d-------- C:\Program Files\Free
2007-01-11 14:15 53,248 -ra------ C:\WINDOWS\system32\NeroCo.dll
2007-01-11 14:15 1,658,880 --------- C:\WINDOWS\UNNeroBurnRights.exe
2007-01-11 14:08 99,568 --------- C:\WINDOWS\system32\drivers\incdfs.sys
2007-01-11 14:08 9,561 --------- C:\WINDOWS\system32\drivers\incdrec.sys
2007-01-11 14:08 27,664 --------- C:\WINDOWS\system32\drivers\incdpass.sys
2007-01-11 14:08 1,769,472 --------- C:\WINDOWS\NuNinst.exe
2007-01-11 14:08 <REP> d-------- C:\WINDOWS\InCD
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-08 09:41 -------- d-------- C:\Program Files\avpersonal
2007-02-06 01:08 -------- d---s---- C:\DOCUME~1\GUEVEL\Application Data\microsoft
2007-02-02 00:25 -------- d-------- C:\Program Files\ahead
2007-02-01 13:18 3665 --a------ C:\WINDOWS\urls.dat
2007-02-01 13:18 17896 --a------ C:\WINDOWS\htmlcode.dat
2007-01-31 12:10 -------- d--h----- C:\Program Files\installshield installation information
2007-01-31 12:10 -------- d-------- C:\Program Files\epson
2007-01-31 10:27 -------- d-------- C:\Program Files\quicktime
2007-01-28 11:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobeum
2007-01-20 01:56 48616 --a--c--- C:\WINDOWS\system32\perfc00c.dat
2007-01-20 01:56 367658 --a--c--- C:\WINDOWS\system32\perfh00c.dat
2007-01-19 15:46 -------- d-------- C:\Program Files\messenger
2007-01-19 01:30 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\mozilla
2007-01-18 15:20 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\macromedia
2007-01-18 12:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobe
2007-01-11 15:12 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\ahead
2006-12-07 17:02 2174976 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"regkeyname"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"NeroFilterCheck"="C:\\windows\\system32\\NeroCheck.exe"
"AVGCtrl"="C:\\Program Files\\AVPersonal\\AVGNT.EXE /min"
"iKeyWorks"="C:\\PROGRA~1\\A4Tech\\Keyboard\\Ikeymain.exe"
"EPSON Stylus Photo RX420 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9CE.EXE /P31 \"EPSON Stylus Photo RX420 Series\" /O6 \"USB001\" /M \"Stylus Photo RX420\""
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"AVSCHED32"="C:\\Program Files\\AVPersonal\\AVSCHED32.EXE /min"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhhf
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmjkk
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6359eeb0-4e50-11db-82f0-001109630ca1}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL 4x3_LIEVIN_BIS.PDF
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-08 14:09:47
C:\ComboFix2.txt ... 07-02-07 21:05
voici les rapports
j'ai relancé combofix à la fin car je crois que vundofix n'arrive pas à venir à bout de C:\windows\system32\jkhhf.dll et C:\windows\system32\pmnmjkk.dl
je l'ai relancé +sieurs fois, j'ai essayé aussi en faisant add files mais rien y fait.
à+
Complete scanning result of "gaunhre.dll", received in VirusTotal at 02.08.2007, 13:10:34 (CET).
Antivirus Version Update Result
AntiVir 7.3.1.34 02.08.2007 TR/Crypt.XPACK.Gen
Authentium 4.93.8 02.07.2007 Possibly a new variant of W32/new-malware!Maximus
Avast 4.7.936.0 02.07.2007 no virus found
AVG 386 02.07.2007 no virus found
BitDefender 7.2 02.08.2007 Trojan.Obfus.Gen
CAT-QuickHeal 9.00 02.07.2007 no virus found
ClamAV devel-20060426 02.08.2007 no virus found
DrWeb 4.33 02.08.2007 Trojan.DownLoader.based
eSafe 7.0.14.0 02.08.2007 suspicious Trojan/Worm
eTrust-InoculateIT 30.4.3378 02.08.2007 no virus found
eTrust-Vet 30.4.3378 02.08.2007 no virus found
Ewido 4.0 02.07.2007 no virus found
Fortinet 2.85.0.0 02.08.2007 suspicious
F-Prot 4.2.1.29 02.07.2007 W32/new-malware!Maximus
F-Secure 6.70.13030.0 02.08.2007 W32/Malware
Ikarus T3.1.0.31 02.08.2007 Trojan-Downloader.Win32.Busky.gen
Kaspersky 4.0.2.24 02.08.2007 no virus found
McAfee 4958 02.07.2007 Downloader-AXI.gen
Microsoft 1.2101 02.08.2007 Trojan:Win32/Busky.gen
NOD32v2 2045 02.08.2007 a variant of Win32/TrojanDownloader.Busky.AZ
Norman 5.80.02 02.07.2007 W32/Malware
Panda 9.0.0.4 02.08.2007 Suspicious file
Prevx1 V2 02.08.2007 no virus found
Sophos 4.13.0 02.08.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.08.2007 Trojan.Busky
TheHacker 6.1.6.053 02.07.2007 no virus found
UNA 1.83 02.07.2007 no virus found
VBA32 3.11.2 02.07.2007 no virus found
VirusBuster 4.3.19:9 02.07.2007 Trojan.DL.Obfusc.Gen3
Aditional Information
File size: 95232 bytes
MD5: 840e31a35bb9d69227a3e56d73c3a180
SHA1: a84b73cd1ac64ef2d4a4f1328482c7d5e881368c
packers: UPX
packers: UPX
packers: UPX, embedded
norman sandbox: [ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Decompressing UPX.
* File length: 95232 bytes.
[ Changes to filesystem ]
* Creates file C:WINDOWSSYSTEM32gaunhre.dll.
* Creates file C:WINDOWSSYSTEM32 qgrrwk.dll.
[ Changes to registry ]
* Creates key "HKLMSoftwareAdwareDisableKey4".
* Sets value "default"="1166912096" in key "HKLMSoftwareAdwareDisableKey4".
* Creates key "HKCUSoftwareAdwareDisableKey4".
* Sets value "default"="1166912096" in key "HKCUSoftwareAdwareDisableKey4".
* Deletes value "e7d22331.exe" in key "HKCUSoftwareMicrosoftWindowsCurrentVersionRun".
* Deletes value "e7d22331.exe" in key "HKLMSoftwareMicrosoftWindowsCurrentVersionRun".
* Creates value "gaunhre.dll"="C:WINDOWS undll32.exe C:WINDOWSSYSTEM32gaunhre.dll,gshxpzc" in key "HKLMSoftwareMicrosoftWindowsCurrentVersionRun".
* Creates key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
* Sets value "default"="C:WINDOWSSYSTEM32 qgrrwk.dll" in key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
* Sets value "ThreadingModel"="Apartment" in key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
[ Process/window information ]
* Creates a mutex a4d22331.
* Enumerates running processes.
* Will automatically restart after boot (I'll be back...).
VundoFix V6.3.5
Checking Java version...
Scan started at 13:36:09 08/02/2007
Listing files found while scanning....
C:\windows\system32\fhhkj.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\pmnmjkk.dll
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Logfile of HijackThis v1.99.1
Scan saved at 14:00:55, on 08/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Adobe\Photoshop 7.0\Photoshop.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} - C:\windows\system32\pmnmjkk.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {A691EB64-4E4C-459A-B644-BF428E54624A} - C:\windows\system32\jkhhf.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: jkhhf - C:\windows\system32\jkhhf.dll
O20 - Winlogon Notify: pmnmjkk - C:\windows\SYSTEM32\pmnmjkk.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
"GUEVEL" - 07-02-08 14:02:03 Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Documents and Settings\GUEVEL\Bureau"
((((((((((((((((((((((((((((((( Files Created from 2007-01-08 to 2007-02-08 ))))))))))))))))))))))))))))))))))
2007-02-08 00:51 <REP> d-------- C:\VundoFix Backups
2007-02-07 21:08 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-02-06 13:20 <REP> d-------- C:\Program Files\MSN Messenger
2007-02-06 05:33 76,412 --a------ C:\WINDOWS\system32\tcwleyec.dll
2007-02-05 22:06 <REP> d-------- C:\Downloads
2007-02-05 22:06 <REP> d-------- C:\Bases
2007-02-05 05:52 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-05 05:52 <REP> d-------- C:\Program Files\Grisoft
2007-02-05 01:02 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-02-05 01:01 42,920 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2007-02-05 01:01 <REP> d-------- C:\WINDOWS\system32\ZoneLabs
2007-02-05 01:00 <REP> d-------- C:\WINDOWS\Internet Logs
2007-02-04 16:27 <REP> d-------- C:\Program Files\Kerio
2007-02-03 16:32 3,094 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-03 15:26 <REP> d-------- C:\WINDOWS\Sun
2007-02-03 15:26 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Sun
2007-02-03 13:40 <REP> d-------- C:\Program Files\Yahoo!
2007-02-02 17:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Talkback
2007-02-02 14:19 94,720 --a------ C:\WINDOWS\system32\xaygtbc.dll
2007-02-02 14:13 <REP> d-------- C:\Program Files\a-squared Free
2007-02-02 12:38 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-02-02 12:38 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2007-02-02 12:38 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2007-02-02 02:22 <REP> d--h----- C:\Program Files\Fichiers communs\Uninstall Information
2007-02-02 02:20 95,232 --a------ C:\WINDOWS\system32\uguzrcf.dll
2007-02-01 19:51 277,234 --------- C:\WINDOWS\system32\jkhhf.dll
2007-02-01 19:45 22,591 --------- C:\WINDOWS\system32\pmnmjkk.dll
2007-02-01 13:48 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-02-01 13:14 <REP> d-------- C:\DOCUME~1\GUEVEL\Contacts
2007-02-01 13:12 434,252 --a------ C:\WINDOWS\system32\Msvcrtd.dll
2007-02-01 13:11 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-02-01 12:13 95,232 --a------ C:\WINDOWS\system32\gaunhre.dll
2007-02-01 02:11 <REP> d-------- C:\DOCUME~1\GUEVEL\Mes documents
2007-01-31 13:22 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Trymedia
2007-01-30 17:34 <REP> d-------- C:\Program Files\Java
2007-01-30 17:33 <REP> d-------- C:\Program Files\Fichiers communs\Java
2007-01-30 15:05 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\SecondLife
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\PlayFirst
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\PlayFirst
2007-01-30 02:48 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-01-24 13:56 <REP> d-------- C:\Program Files\Real
2007-01-24 13:56 <REP> d-------- C:\Program Files\Fichiers communs\Real
2007-01-24 13:56 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Real
2007-01-24 13:28 <REP> d-------- C:\Program Files\MSN Apps
2007-01-22 22:26 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-01-19 15:43 <REP> d-------- C:\Program Files\MSXML 4.0
2007-01-19 12:53 51,056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-19 10:32 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-01-19 10:32 <REP> d-------- C:\WINDOWS\system32\PreInstall
2007-01-19 10:12 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Lavasoft
2007-01-19 01:30 0 --a------ C:\WINDOWS\nsreg.dat
2007-01-18 17:26 <REP> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-01-18 17:20 3,757 --a------ C:\WINDOWS\mozver.dat
2007-01-18 17:20 <REP> d-------- C:\Program Files\Mozilla Firefox
2007-01-18 16:53 <REP> d-------- C:\Program Files\Lavasoft
2007-01-18 14:29 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Google
2007-01-18 14:28 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google
2007-01-18 14:14 <REP> d-------- C:\Program Files\Google
2007-01-18 14:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google Updater
2007-01-18 12:57 <REP> d---s---- C:\DOCUME~1\GUEVEL\UserData
2007-01-18 12:17 <REP> d--hs---- C:\WINDOWS\ftpcache
2007-01-18 12:17 <REP> d-------- C:\Program Files\Free
2007-01-11 14:15 53,248 -ra------ C:\WINDOWS\system32\NeroCo.dll
2007-01-11 14:15 1,658,880 --------- C:\WINDOWS\UNNeroBurnRights.exe
2007-01-11 14:08 99,568 --------- C:\WINDOWS\system32\drivers\incdfs.sys
2007-01-11 14:08 9,561 --------- C:\WINDOWS\system32\drivers\incdrec.sys
2007-01-11 14:08 27,664 --------- C:\WINDOWS\system32\drivers\incdpass.sys
2007-01-11 14:08 1,769,472 --------- C:\WINDOWS\NuNinst.exe
2007-01-11 14:08 <REP> d-------- C:\WINDOWS\InCD
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-08 09:41 -------- d-------- C:\Program Files\avpersonal
2007-02-06 01:08 -------- d---s---- C:\DOCUME~1\GUEVEL\Application Data\microsoft
2007-02-02 00:25 -------- d-------- C:\Program Files\ahead
2007-02-01 13:18 3665 --a------ C:\WINDOWS\urls.dat
2007-02-01 13:18 17896 --a------ C:\WINDOWS\htmlcode.dat
2007-01-31 12:10 -------- d--h----- C:\Program Files\installshield installation information
2007-01-31 12:10 -------- d-------- C:\Program Files\epson
2007-01-31 10:27 -------- d-------- C:\Program Files\quicktime
2007-01-28 11:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobeum
2007-01-20 01:56 48616 --a--c--- C:\WINDOWS\system32\perfc00c.dat
2007-01-20 01:56 367658 --a--c--- C:\WINDOWS\system32\perfh00c.dat
2007-01-19 15:46 -------- d-------- C:\Program Files\messenger
2007-01-19 01:30 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\mozilla
2007-01-18 15:20 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\macromedia
2007-01-18 12:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobe
2007-01-11 15:12 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\ahead
2006-12-07 17:02 2174976 --a------ C:\WINDOWS\system32\wmvcore.dll
2006-11-08 06:07 679424 --a------ C:\WINDOWS\system32\inetcomm.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"regkeyname"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"NeroFilterCheck"="C:\\windows\\system32\\NeroCheck.exe"
"AVGCtrl"="C:\\Program Files\\AVPersonal\\AVGNT.EXE /min"
"iKeyWorks"="C:\\PROGRA~1\\A4Tech\\Keyboard\\Ikeymain.exe"
"EPSON Stylus Photo RX420 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9CE.EXE /P31 \"EPSON Stylus Photo RX420 Series\" /O6 \"USB001\" /M \"Stylus Photo RX420\""
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"AVSCHED32"="C:\\Program Files\\AVPersonal\\AVSCHED32.EXE /min"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkhhf
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnmjkk
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6359eeb0-4e50-11db-82f0-001109630ca1}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL 4x3_LIEVIN_BIS.PDF
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-08 14:09:47
C:\ComboFix2.txt ... 07-02-07 21:05
Bonjour,
1) Je ne vois pas le log de Pocket Killbox.
2) D'où vient ceci :
packers: UPX
packers: UPX
packers: UPX, embedded
norman sandbox: [ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Decompressing UPX.
* File length: 95232 bytes.
[ Changes to filesystem ]
* Creates file C:WINDOWSSYSTEM32gaunhre.dll.
* Creates file C:WINDOWSSYSTEM32 qgrrwk.dll.
[ Changes to registry ]
* Creates key "HKLMSoftwareAdwareDisableKey4".
* Sets value "default"="1166912096" in key "HKLMSoftwareAdwareDisableKey4".
* Creates key "HKCUSoftwareAdwareDisableKey4".
* Sets value "default"="1166912096" in key "HKCUSoftwareAdwareDisableKey4".
* Deletes value "e7d22331.exe" in key "HKCUSoftwareMicrosoftWindowsCurrentVersionRun".
* Deletes value "e7d22331.exe" in key "HKLMSoftwareMicrosoftWindowsCurrentVersionRun".
* Creates value "gaunhre.dll"="C:WINDOWS undll32.exe C:WINDOWSSYSTEM32gaunhre.dll,gshxpzc" in key "HKLMSoftwareMicrosoftWindowsCurrentVersionRun".
* Creates key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
* Sets value "default"="C:WINDOWSSYSTEM32 qgrrwk.dll" in key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
* Sets value "ThreadingModel"="Apartment" in key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
[ Process/window information ]
* Creates a mutex a4d22331.
* Enumerates running processes.
* Will automatically restart after boot (I'll be back...).
Tu as certainement trouvé des informations vitales sur le mécanisme de réinfection. Mais j'ai besoin d'en savoir plus pour m'en servir.
3) Peux tu trouver le nom complet de undll32.exe et le soumettre aussi à Virustotal en fournissant le rapport.
4) J'avais aussi 2 questions sur des fichiers qui sont sans réponse. Merci.
@+
1) Je ne vois pas le log de Pocket Killbox.
2) D'où vient ceci :
packers: UPX
packers: UPX
packers: UPX, embedded
norman sandbox: [ General information ]
* **IMPORTANT: PLEASE SEND THE SCANNED FILE TO: ANALYSIS@NORMAN.NO - REMEMBER TO ENCRYPT IT (E.G. ZIP WITH PASSWORD)**.
* Decompressing UPX.
* File length: 95232 bytes.
[ Changes to filesystem ]
* Creates file C:WINDOWSSYSTEM32gaunhre.dll.
* Creates file C:WINDOWSSYSTEM32 qgrrwk.dll.
[ Changes to registry ]
* Creates key "HKLMSoftwareAdwareDisableKey4".
* Sets value "default"="1166912096" in key "HKLMSoftwareAdwareDisableKey4".
* Creates key "HKCUSoftwareAdwareDisableKey4".
* Sets value "default"="1166912096" in key "HKCUSoftwareAdwareDisableKey4".
* Deletes value "e7d22331.exe" in key "HKCUSoftwareMicrosoftWindowsCurrentVersionRun".
* Deletes value "e7d22331.exe" in key "HKLMSoftwareMicrosoftWindowsCurrentVersionRun".
* Creates value "gaunhre.dll"="C:WINDOWS undll32.exe C:WINDOWSSYSTEM32gaunhre.dll,gshxpzc" in key "HKLMSoftwareMicrosoftWindowsCurrentVersionRun".
* Creates key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
* Sets value "default"="C:WINDOWSSYSTEM32 qgrrwk.dll" in key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
* Sets value "ThreadingModel"="Apartment" in key "HKCRCLSID{33D72701-74C4-8352-1C1F-00B72AF60CDD}InprocServer32".
[ Process/window information ]
* Creates a mutex a4d22331.
* Enumerates running processes.
* Will automatically restart after boot (I'll be back...).
Tu as certainement trouvé des informations vitales sur le mécanisme de réinfection. Mais j'ai besoin d'en savoir plus pour m'en servir.
3) Peux tu trouver le nom complet de undll32.exe et le soumettre aussi à Virustotal en fournissant le rapport.
4) J'avais aussi 2 questions sur des fichiers qui sont sans réponse. Merci.
@+
Salut,
alors Packers...etc ça vient du scan de virus total
je n'ai pas de fichier qui s'appelle undll32. exe, j'ai seulement rundll32.exe donc je l'ai scanné avec virustotal si jamais c'était celui là...
Sinon, voici le log de killbox
à+
Pocket Killbox version 2.0.0.648
Running on Windows XP as GUEVEL(Administrator)
was started @ jeudi, février 08, 2007, 4:25 PM
# 1 [Delete on Reboot]
Path = C:\WINDOWS\system32\tcwleyec.dll
I Rebooted @ 4:26:55 PM
Killbox Closed(Exit) @ 4:27:20 PM
et le scan de virus total
Complete scanning result of "rundll32.exe", received in VirusTotal at 02.08.2007, 16:41:44 (CET).
Antivirus Version Update Result
AntiVir 7.3.1.34 02.08.2007 no virus found
Authentium 4.93.8 02.07.2007 no virus found
Avast 4.7.936.0 02.08.2007 no virus found
AVG 386 02.08.2007 no virus found
BitDefender 7.2 02.08.2007 no virus found
CAT-QuickHeal 9.00 02.08.2007 no virus found
ClamAV devel-20060426 02.08.2007 no virus found
DrWeb 4.33 02.08.2007 no virus found
eSafe 7.0.14.0 02.08.2007 no virus found
eTrust-InoculateIT 30.4.3378 02.08.2007 no virus found
eTrust-Vet 30.4.3378 02.08.2007 no virus found
Ewido 4.0 02.07.2007 no virus found
Fortinet 2.85.0.0 02.08.2007 no virus found
F-Prot 4.2.1.29 02.07.2007 no virus found
F-Secure 6.70.13030.0 02.08.2007 no virus found
Ikarus T3.1.0.31 02.08.2007 no virus found
Kaspersky 4.0.2.24 02.08.2007 no virus found
McAfee 4958 02.07.2007 no virus found
Microsoft 1.2101 02.08.2007 no virus found
NOD32v2 2045 02.08.2007 no virus found
Norman 5.80.02 02.08.2007 no virus found
Panda 9.0.0.4 02.08.2007 no virus found
Prevx1 V2 02.08.2007 no virus found
Sophos 4.13.0 02.08.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.08.2007 no virus found
TheHacker 6.1.6.053 02.07.2007 no virus found
UNA 1.83 02.07.2007 no virus found
VBA32 3.11.2 02.07.2007 no virus found
VirusBuster 4.3.19:9 02.08.2007 no virus found
Aditional Information
File size: 33792 bytes
MD5: f5402cd47b7389ddc21f92119a906eee
SHA1: 23755a333f5eb21a89a8ff12cd28201acf122b1f
_______________________________
alors Packers...etc ça vient du scan de virus total
je n'ai pas de fichier qui s'appelle undll32. exe, j'ai seulement rundll32.exe donc je l'ai scanné avec virustotal si jamais c'était celui là...
Sinon, voici le log de killbox
à+
Pocket Killbox version 2.0.0.648
Running on Windows XP as GUEVEL(Administrator)
was started @ jeudi, février 08, 2007, 4:25 PM
# 1 [Delete on Reboot]
Path = C:\WINDOWS\system32\tcwleyec.dll
I Rebooted @ 4:26:55 PM
Killbox Closed(Exit) @ 4:27:20 PM
et le scan de virus total
Complete scanning result of "rundll32.exe", received in VirusTotal at 02.08.2007, 16:41:44 (CET).
Antivirus Version Update Result
AntiVir 7.3.1.34 02.08.2007 no virus found
Authentium 4.93.8 02.07.2007 no virus found
Avast 4.7.936.0 02.08.2007 no virus found
AVG 386 02.08.2007 no virus found
BitDefender 7.2 02.08.2007 no virus found
CAT-QuickHeal 9.00 02.08.2007 no virus found
ClamAV devel-20060426 02.08.2007 no virus found
DrWeb 4.33 02.08.2007 no virus found
eSafe 7.0.14.0 02.08.2007 no virus found
eTrust-InoculateIT 30.4.3378 02.08.2007 no virus found
eTrust-Vet 30.4.3378 02.08.2007 no virus found
Ewido 4.0 02.07.2007 no virus found
Fortinet 2.85.0.0 02.08.2007 no virus found
F-Prot 4.2.1.29 02.07.2007 no virus found
F-Secure 6.70.13030.0 02.08.2007 no virus found
Ikarus T3.1.0.31 02.08.2007 no virus found
Kaspersky 4.0.2.24 02.08.2007 no virus found
McAfee 4958 02.07.2007 no virus found
Microsoft 1.2101 02.08.2007 no virus found
NOD32v2 2045 02.08.2007 no virus found
Norman 5.80.02 02.08.2007 no virus found
Panda 9.0.0.4 02.08.2007 no virus found
Prevx1 V2 02.08.2007 no virus found
Sophos 4.13.0 02.08.2007 no virus found
Sunbelt 2.2.907.0 02.02.2007 no virus found
Symantec 10 02.08.2007 no virus found
TheHacker 6.1.6.053 02.07.2007 no virus found
UNA 1.83 02.07.2007 no virus found
VBA32 3.11.2 02.07.2007 no virus found
VirusBuster 4.3.19:9 02.08.2007 no virus found
Aditional Information
File size: 33792 bytes
MD5: f5402cd47b7389ddc21f92119a906eee
SHA1: 23755a333f5eb21a89a8ff12cd28201acf122b1f
_______________________________
Re,
1) j'examine ce qui vient de Virustotal.
Est ce que, par l'explorateur Windows, tu trouves les fichiers non détruits par Killbox ?
C:\WINDOWS\system32\whefqcch.dll
C:\WINDOWS\system32\bgxpcxow.dll
C:\WINDOWS\system32\zllictbl.dat
C:\WINDOWS\system32\xaygtbc.dll
C:\WINDOWS\system32\uguzrcf.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\gaunhre.dll
2) Pour Vundofix, quand l'ordi reboote, Vundofix se ré ouvre ? Tu cliques sur Scan Vundo, puis remove Vundo ? Fais cette opération autant de fois que nécessaire (10 s'il le faut).
Décris moi exactement comment ça se passe avec Vundofix.
@+
1) j'examine ce qui vient de Virustotal.
Est ce que, par l'explorateur Windows, tu trouves les fichiers non détruits par Killbox ?
C:\WINDOWS\system32\whefqcch.dll
C:\WINDOWS\system32\bgxpcxow.dll
C:\WINDOWS\system32\zllictbl.dat
C:\WINDOWS\system32\xaygtbc.dll
C:\WINDOWS\system32\uguzrcf.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\gaunhre.dll
2) Pour Vundofix, quand l'ordi reboote, Vundofix se ré ouvre ? Tu cliques sur Scan Vundo, puis remove Vundo ? Fais cette opération autant de fois que nécessaire (10 s'il le faut).
Décris moi exactement comment ça se passe avec Vundofix.
@+
salut,
explorateur windows a trouvé
C:\WINDOWS\system32\xaygtbc.dll
C:\WINDOWS\system32\uguzrcf.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\gaunhre.dll
Sinon Vundofix me fait la même chose à chaque fois :
je lance le scan et il affiche
C:\Program files\VSAdd-in\VSAdd-in.dll
C:\WINDOWS\system32\aiqsjwtf.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\fhhf.dll
après je fais remove vundo, l'ordi redémarre
vundo affiche
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\fhhf.dll
je refais remove vundo, l'ordi s'éteind et redémarre encore et vundo n'affiche plus rien dans la case blanche
je fais donc remove vundo et il m'explique qu'il n'y a plus rien et qu'il va s'arrêter. Le bureau s'affiche, je relance vundofix, puis scan for vundo et il m'affiche la même chose :
C:\Program files\VSAdd-in\VSAdd-in.dll
C:\WINDOWS\system32\aiqsjwtf.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\fhhf.dll
dc ça redémarre etc etc
voilà...
VundoFix V6.3.5
Checking Java version...
Scan started at 13:49:42 08/02/2007
Listing files found while scanning....
C:\windows\system32\fhhkj.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\pmnmjkk.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\gaunhre.dll
C:\WINDOWS\system32\gaunhre.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\pmnmjkk.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\uguzrcf.dll
C:\WINDOWS\system32\uguzrcf.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\xaygtbc.dll
C:\WINDOWS\system32\xaygtbc.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\pmnmjkk.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
VundoFix V6.3.5
Checking Java version...
Scan started at 18:00:42 08/02/2007
Listing files found while scanning....
C:\Program Files\VSAdd-in\VSAdd-in.dll
C:\windows\system32\aiqsjwtf.dll
C:\windows\system32\fhhkj.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\lshbritb.exe
C:\windows\system32\oxvvhpqq.ini
C:\windows\system32\pmnmjkk.dll
C:\windows\system32\qqphvvxo.dll
Beginning removal...
Attempting to delete C:\windows\system32\aiqsjwtf.dll
C:\windows\system32\aiqsjwtf.dll Has been deleted!
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\lshbritb.exe
C:\windows\system32\lshbritb.exe Has been deleted!
Attempting to delete C:\windows\system32\oxvvhpqq.ini
C:\windows\system32\oxvvhpqq.ini Has been deleted!
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Attempting to delete C:\windows\system32\qqphvvxo.dll
C:\windows\system32\qqphvvxo.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
explorateur windows a trouvé
C:\WINDOWS\system32\xaygtbc.dll
C:\WINDOWS\system32\uguzrcf.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\gaunhre.dll
Sinon Vundofix me fait la même chose à chaque fois :
je lance le scan et il affiche
C:\Program files\VSAdd-in\VSAdd-in.dll
C:\WINDOWS\system32\aiqsjwtf.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\fhhf.dll
après je fais remove vundo, l'ordi redémarre
vundo affiche
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\fhhf.dll
je refais remove vundo, l'ordi s'éteind et redémarre encore et vundo n'affiche plus rien dans la case blanche
je fais donc remove vundo et il m'explique qu'il n'y a plus rien et qu'il va s'arrêter. Le bureau s'affiche, je relance vundofix, puis scan for vundo et il m'affiche la même chose :
C:\Program files\VSAdd-in\VSAdd-in.dll
C:\WINDOWS\system32\aiqsjwtf.dll
C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\fhhf.dll
dc ça redémarre etc etc
voilà...
VundoFix V6.3.5
Checking Java version...
Scan started at 13:49:42 08/02/2007
Listing files found while scanning....
C:\windows\system32\fhhkj.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\pmnmjkk.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\gaunhre.dll
C:\WINDOWS\system32\gaunhre.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\jkhhf.dll
C:\WINDOWS\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\pmnmjkk.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\uguzrcf.dll
C:\WINDOWS\system32\uguzrcf.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\xaygtbc.dll
C:\WINDOWS\system32\xaygtbc.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\pmnmjkk.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\pmnmjkk.dll
C:\WINDOWS\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
VundoFix V6.3.5
Checking Java version...
Scan started at 18:00:42 08/02/2007
Listing files found while scanning....
C:\Program Files\VSAdd-in\VSAdd-in.dll
C:\windows\system32\aiqsjwtf.dll
C:\windows\system32\fhhkj.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\lshbritb.exe
C:\windows\system32\oxvvhpqq.ini
C:\windows\system32\pmnmjkk.dll
C:\windows\system32\qqphvvxo.dll
Beginning removal...
Attempting to delete C:\windows\system32\aiqsjwtf.dll
C:\windows\system32\aiqsjwtf.dll Has been deleted!
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\lshbritb.exe
C:\windows\system32\lshbritb.exe Has been deleted!
Attempting to delete C:\windows\system32\oxvvhpqq.ini
C:\windows\system32\oxvvhpqq.ini Has been deleted!
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Attempting to delete C:\windows\system32\qqphvvxo.dll
C:\windows\system32\qqphvvxo.dll Has been deleted!
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Bonsoir,
essaye de faire comme ça vaec vundofix :
tu le lances, tu fais scan, puis remove.
Il redémarre, affiche ce qu'il veut; Tu fais SCAN à nouveau et pas remove directement. A la fin du scan, tu fais remove.
Tu recommences tant quelque chose change (dans la liste qu'il affiche au reboot).
Quand plus rien ne change, essaye de faire un clic droit dans la zone blanche et d'y coller les nom des fichiers restants puis close puis remove.
Tu me tiens au courant.
@+
essaye de faire comme ça vaec vundofix :
tu le lances, tu fais scan, puis remove.
Il redémarre, affiche ce qu'il veut; Tu fais SCAN à nouveau et pas remove directement. A la fin du scan, tu fais remove.
Tu recommences tant quelque chose change (dans la liste qu'il affiche au reboot).
Quand plus rien ne change, essaye de faire un clic droit dans la zone blanche et d'y coller les nom des fichiers restants puis close puis remove.
Tu me tiens au courant.
@+
bonjour,
j'ai "vundofixé" plusieurs fois, mais c toujours la même chose.
Il ne vient pas à bout de ces dossiers
C:\windows\system32\fhhkj.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\pmnmjkk.dll
Il ne les détruit jamais (par contre en ce qui concerne ma patience, il a réussi...)
donc je te mets juste la fin du rapports car c la même chose sur plusieurs pages :
à+
VundoFix V6.3.5
Checking Java version...
Scan started at 14:16:14 09/02/2007
Listing files found while scanning....
C:\windows\system32\aiqsjwtf.dll
C:\windows\system32\fhhkj.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\pmnmjkk.dll
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
j'ai "vundofixé" plusieurs fois, mais c toujours la même chose.
Il ne vient pas à bout de ces dossiers
C:\windows\system32\fhhkj.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\pmnmjkk.dll
Il ne les détruit jamais (par contre en ce qui concerne ma patience, il a réussi...)
donc je te mets juste la fin du rapports car c la même chose sur plusieurs pages :
à+
VundoFix V6.3.5
Checking Java version...
Scan started at 14:16:14 09/02/2007
Listing files found while scanning....
C:\windows\system32\aiqsjwtf.dll
C:\windows\system32\fhhkj.ini
C:\windows\system32\jkhhf.dll
C:\windows\system32\pmnmjkk.dll
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\fhhkj.ini
C:\windows\system32\fhhkj.ini Has been deleted!
Attempting to delete C:\windows\system32\jkhhf.dll
C:\windows\system32\jkhhf.dll Could not be deleted.
Attempting to delete C:\windows\system32\pmnmjkk.dll
C:\windows\system32\pmnmjkk.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Bonjour,
J'ai co,nsulté des helpers plus confirmés et qui m'ont donné de nouvelles voies.
A) Télécharge VirtumundoBegone sur le bureau:
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
Double clique ensuite sur VirtumundoBeGone.exe et suis les instructions.
Une fois terminé, redémarre et tu posteras le rapport VBG.TXT créé sur le bureau dans ta prochaine réponse avec un nouveau rapport HijackThis.
Ne t'inquiète pas si tu vois un message Ecran bleu "Erreur fatale", c'est normal et attendu
B)
1)Télécharge Brute Force Uninstaller (de Merijn):
http://www.merijn.org/files/bfu.zip
Créé un nouveau dossier directement sur le C:\ et nomme-le BFU. Décompresse le fichier téléchargé dans ce nouveau dossier (C:\BFU)
2) Ouvre le Bloc-note et copie-colle les lignes en gras ci-dessous :
DllUnregister %SYSDIR%\whefqcch.dll|1
DllUnregister %SYSDIR%\bgxpcxow.dll|1
DllUnregister %SYSDIR%\tcwleyec.dll|1
DllUnregister %SYSDIR%\xaygtbc.dll|1
DllUnregister %SYSDIR%\uguzrcf.dll|1
DllUnregister %SYSDIR%\pmnmjkk.dll|1
DllUnregister %SYSDIR%\jkhhf.dll|1
DllUnregister %SYSDIR%\gaunhre.dll|1
FileDelete %SYSDIR%\whefqcch.dll
FileDelete %SYSDIR%\bgxpcxow.dll
FileDelete %SYSDIR%\tcwleyec.dll
FileDelete %SYSDIR%\zllictbl.dat
FileDelete %SYSDIR%\xaygtbc.dll
FileDelete %SYSDIR%\uguzrcf.dll
FileDelete %SYSDIR%\pmnmjkk.dll
FileDelete %SYSDIR%\jkhhf.dll
FileDelete %SYSDIR%\gaunhre.dll
SystemEmptyTempFolder
SystemEmptyRecycleBin
Sauvegarde dans le dossier créé (C:\BFU) (Nom du fichier : "Fixme.bfu " -sans inclure les guillemets- ; Type : Tous les fichiers).
Redémarre en mode Sans Échec : au redémarrage, tapote immédiatement la touche F8; tu verras un écran avec choix de démarrages apparaître. Utilisant les flèches du clavier, choisis "Mode Sans Échec" et valide avec "Entrée". Choisis ton compte usuel, et non Administrateur.
Démarre le "Brute Force Uninstaller" en double-cliquant BFU.exe (du dossier C:\BFU)
- Clique sur le petit dossier jaune, à la droite de la boîte scrïptline to execute, et double-clique sur :
Fixme.bfu
- Dans la boîte "scrïptline to execute", tu devrais maintenant voir ceci : C:\BFU\Fixme.bfu
Clique sur Execute et laisse-le faire son travail.
Attendre que Complete scrïpt execution apparaîsse et clique sur OK.
Clique Exit pour fermer le programme BFU.
Redémarre normalement.
Tu postes le rapport de BFu, celui de Virtumondobegone et un nouveau log HijackThis
@+
J'ai co,nsulté des helpers plus confirmés et qui m'ont donné de nouvelles voies.
A) Télécharge VirtumundoBegone sur le bureau:
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
Double clique ensuite sur VirtumundoBeGone.exe et suis les instructions.
Une fois terminé, redémarre et tu posteras le rapport VBG.TXT créé sur le bureau dans ta prochaine réponse avec un nouveau rapport HijackThis.
Ne t'inquiète pas si tu vois un message Ecran bleu "Erreur fatale", c'est normal et attendu
B)
1)Télécharge Brute Force Uninstaller (de Merijn):
http://www.merijn.org/files/bfu.zip
Créé un nouveau dossier directement sur le C:\ et nomme-le BFU. Décompresse le fichier téléchargé dans ce nouveau dossier (C:\BFU)
2) Ouvre le Bloc-note et copie-colle les lignes en gras ci-dessous :
DllUnregister %SYSDIR%\whefqcch.dll|1
DllUnregister %SYSDIR%\bgxpcxow.dll|1
DllUnregister %SYSDIR%\tcwleyec.dll|1
DllUnregister %SYSDIR%\xaygtbc.dll|1
DllUnregister %SYSDIR%\uguzrcf.dll|1
DllUnregister %SYSDIR%\pmnmjkk.dll|1
DllUnregister %SYSDIR%\jkhhf.dll|1
DllUnregister %SYSDIR%\gaunhre.dll|1
FileDelete %SYSDIR%\whefqcch.dll
FileDelete %SYSDIR%\bgxpcxow.dll
FileDelete %SYSDIR%\tcwleyec.dll
FileDelete %SYSDIR%\zllictbl.dat
FileDelete %SYSDIR%\xaygtbc.dll
FileDelete %SYSDIR%\uguzrcf.dll
FileDelete %SYSDIR%\pmnmjkk.dll
FileDelete %SYSDIR%\jkhhf.dll
FileDelete %SYSDIR%\gaunhre.dll
SystemEmptyTempFolder
SystemEmptyRecycleBin
Sauvegarde dans le dossier créé (C:\BFU) (Nom du fichier : "Fixme.bfu " -sans inclure les guillemets- ; Type : Tous les fichiers).
Redémarre en mode Sans Échec : au redémarrage, tapote immédiatement la touche F8; tu verras un écran avec choix de démarrages apparaître. Utilisant les flèches du clavier, choisis "Mode Sans Échec" et valide avec "Entrée". Choisis ton compte usuel, et non Administrateur.
Démarre le "Brute Force Uninstaller" en double-cliquant BFU.exe (du dossier C:\BFU)
- Clique sur le petit dossier jaune, à la droite de la boîte scrïptline to execute, et double-clique sur :
Fixme.bfu
- Dans la boîte "scrïptline to execute", tu devrais maintenant voir ceci : C:\BFU\Fixme.bfu
Clique sur Execute et laisse-le faire son travail.
Attendre que Complete scrïpt execution apparaîsse et clique sur OK.
Clique Exit pour fermer le programme BFU.
Redémarre normalement.
Tu postes le rapport de BFu, celui de Virtumondobegone et un nouveau log HijackThis
@+
Bonjour,
voici tous les rapports
à+
[02/10/2007, 13:25:19] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\GUEVEL\Bureau\VirtumundoBeGone.exe" )
[02/10/2007, 13:25:24] - Detected System Information:
[02/10/2007, 13:25:24] - Windows Version: 5.1.2600, Service Pack 2
[02/10/2007, 13:25:24] - Current Username: GUEVEL (Admin)
[02/10/2007, 13:25:24] - Windows is in NORMAL mode.
[02/10/2007, 13:25:24] - Searching for Browser Helper Objects:
[02/10/2007, 13:25:24] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/10/2007, 13:25:24] - BHO 2: {233E2BC1-76EA-40DA-B200-571545F46404} ()
[02/10/2007, 13:25:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:24] - Checking for HKLM\...\Winlogon\Notify\jkhhf
[02/10/2007, 13:25:24] - Found: HKLM\...\Winlogon\Notify\jkhhf - This is probably Virtumundo.
[02/10/2007, 13:25:24] - Assigning {233E2BC1-76EA-40DA-B200-571545F46404} MSEvents Object
[02/10/2007, 13:25:24] - BHO list has been changed! Starting over...
[02/10/2007, 13:25:24] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/10/2007, 13:25:24] - BHO 2: {233E2BC1-76EA-40DA-B200-571545F46404} (MSEvents Object)
[02/10/2007, 13:25:24] - ALERT: Found MSEvents Object!
[02/10/2007, 13:25:24] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[02/10/2007, 13:25:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:24] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[02/10/2007, 13:25:24] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[02/10/2007, 13:25:24] - BHO 4: {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} ()
[02/10/2007, 13:25:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:24] - Checking for HKLM\...\Winlogon\Notify\aiqsjwtf
[02/10/2007, 13:25:24] - Key not found: HKLM\...\Winlogon\Notify\aiqsjwtf, continuing.
[02/10/2007, 13:25:25] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/10/2007, 13:25:25] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/10/2007, 13:25:25] - BHO 7: {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} ()
[02/10/2007, 13:25:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:25] - Checking for HKLM\...\Winlogon\Notify\pmnmjkk
[02/10/2007, 13:25:25] - Found: HKLM\...\Winlogon\Notify\pmnmjkk - This is probably Virtumundo.
[02/10/2007, 13:25:25] - Assigning {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} MSEvents Object
[02/10/2007, 13:25:25] - BHO list has been changed! Starting over...
[02/10/2007, 13:25:25] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/10/2007, 13:25:25] - BHO 2: {233E2BC1-76EA-40DA-B200-571545F46404} (MSEvents Object)
[02/10/2007, 13:25:25] - ALERT: Found MSEvents Object!
[02/10/2007, 13:25:25] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[02/10/2007, 13:25:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:25] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[02/10/2007, 13:25:25] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[02/10/2007, 13:25:25] - BHO 4: {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} ()
[02/10/2007, 13:25:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:25] - Checking for HKLM\...\Winlogon\Notify\aiqsjwtf
[02/10/2007, 13:25:25] - Key not found: HKLM\...\Winlogon\Notify\aiqsjwtf, continuing.
[02/10/2007, 13:25:25] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/10/2007, 13:25:25] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/10/2007, 13:25:25] - BHO 7: {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} (MSEvents Object)
[02/10/2007, 13:25:25] - ALERT: Found MSEvents Object!
[02/10/2007, 13:25:25] - BHO 8: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} (ST)
[02/10/2007, 13:25:25] - BHO 9: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[02/10/2007, 13:25:25] - BHO 10: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (MSNToolBandBHO)
[02/10/2007, 13:25:25] - BHO 11: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[02/10/2007, 13:25:25] - Finished Searching Browser Helper Objects
[02/10/2007, 13:25:25] - *** Detected MSEvents Object
[02/10/2007, 13:25:25] - Trying to remove MSEvents Object...
[02/10/2007, 13:25:26] - Terminating Process: IEXPLORE.EXE
[02/10/2007, 13:25:27] - Terminating Process: RUNDLL32.EXE
[02/10/2007, 13:25:27] - Disabling Automatic Shell Restart
[02/10/2007, 13:25:27] - Terminating Process: EXPLORER.EXE
[02/10/2007, 13:25:27] - Suspending the NT Session Manager System Service
[02/10/2007, 13:25:27] - Terminating Windows NT Logon/Logoff Manager
[02/10/2007, 13:25:28] - Re-enabling Automatic Shell Restart
[02/10/2007, 13:25:28] - File to disable: C:\windows\system32\jkhhf.dll
[02/10/2007, 13:25:28] - Renaming C:\windows\system32\jkhhf.dll -> C:\windows\system32\jkhhf.dll.vir
[02/10/2007, 13:25:28] - File successfully renamed!
[02/10/2007, 13:25:28] - Removing HKLM\...\Browser Helper Objects\{233E2BC1-76EA-40DA-B200-571545F46404}
[02/10/2007, 13:25:28] - Removing HKCR\CLSID\{233E2BC1-76EA-40DA-B200-571545F46404}
[02/10/2007, 13:25:28] - Adding Kill Bit for ActiveX for GUID: {233E2BC1-76EA-40DA-B200-571545F46404}
[02/10/2007, 13:25:28] - Deleting ATLEvents/MSEvents Registry entries
[02/10/2007, 13:25:28] - Removing HKLM\...\Winlogon\Notify\jkhhf
[02/10/2007, 13:25:28] - Searching for Browser Helper Objects:
[02/10/2007, 13:25:28] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/10/2007, 13:25:28] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[02/10/2007, 13:25:28] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:28] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[02/10/2007, 13:25:28] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[02/10/2007, 13:25:29] - BHO 3: {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} ()
[02/10/2007, 13:25:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:29] - Checking for HKLM\...\Winlogon\Notify\aiqsjwtf
[02/10/2007, 13:25:29] - Key not found: HKLM\...\Winlogon\Notify\aiqsjwtf, continuing.
[02/10/2007, 13:25:29] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/10/2007, 13:25:29] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/10/2007, 13:25:29] - BHO 6: {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} (MSEvents Object)
[02/10/2007, 13:25:29] - ALERT: Found MSEvents Object!
[02/10/2007, 13:25:29] - BHO 7: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} (ST)
[02/10/2007, 13:25:29] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[02/10/2007, 13:25:29] - BHO 9: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (MSNToolBandBHO)
[02/10/2007, 13:25:29] - BHO 10: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[02/10/2007, 13:25:29] - Finished Searching Browser Helper Objects
[02/10/2007, 13:25:29] - *** Detected MSEvents Object
[02/10/2007, 13:25:29] - Trying to remove MSEvents Object...
[02/10/2007, 13:25:30] - Terminating Process: IEXPLORE.EXE
[02/10/2007, 13:25:30] - Terminating Process: RUNDLL32.EXE
[02/10/2007, 13:25:30] - Disabling Automatic Shell Restart
[02/10/2007, 13:25:31] - Terminating Process: EXPLORER.EXE
[02/10/2007, 13:25:31] - Suspending the NT Session Manager System Service
[02/10/2007, 13:25:31] - Terminating Windows NT Logon/Logoff Manager
[02/10/2007, 13:25:31] - Re-enabling Automatic Shell Restart
[02/10/2007, 13:25:31] - File to disable: C:\windows\system32\pmnmjkk.dll
[02/10/2007, 13:25:31] - Renaming C:\windows\system32\pmnmjkk.dll -> C:\windows\system32\pmnmjkk.dll.vir
[02/10/2007, 13:25:31] - File successfully renamed!
[02/10/2007, 13:25:31] - Removing HKLM\...\Browser Helper Objects\{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}
[02/10/2007, 13:25:31] - Removing HKCR\CLSID\{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}
[02/10/2007, 13:25:31] - Adding Kill Bit for ActiveX for GUID: {90382AD7-4298-47E0-BC0F-14ACCFF44D2C}
[02/10/2007, 13:25:31] - Deleting ATLEvents/MSEvents Registry entries
[02/10/2007, 13:25:31] - Removing HKLM\...\Winlogon\Notify\pmnmjkk
[02/10/2007, 13:25:32] - Searching for Browser Helper Objects:
[02/10/2007, 13:25:32] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/10/2007, 13:25:32] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[02/10/2007, 13:25:32] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:32] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[02/10/2007, 13:25:32] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[02/10/2007, 13:25:32] - BHO 3: {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} ()
[02/10/2007, 13:25:32] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:32] - Checking for HKLM\...\Winlogon\Notify\aiqsjwtf
[02/10/2007, 13:25:32] - Key not found: HKLM\...\Winlogon\Notify\aiqsjwtf, continuing.
[02/10/2007, 13:25:32] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/10/2007, 13:25:32] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/10/2007, 13:25:32] - BHO 6: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} (ST)
[02/10/2007, 13:25:32] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[02/10/2007, 13:25:32] - BHO 8: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (MSNToolBandBHO)
[02/10/2007, 13:25:32] - BHO 9: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[02/10/2007, 13:25:32] - Finished Searching Browser Helper Objects
[02/10/2007, 13:25:32] - Finishing up...
[02/10/2007, 13:25:32] - A restart is needed.
[02/10/2007, 13:25:35] - Attempting to Restart via STOP error (Blue Screen!)
Logfile of HijackThis v1.99.1
Scan saved at 13:29:19, on 10/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\aiqsjwtf.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\windows\system32\sacxdvuq.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
BFU v1.00.9
Windows XP SP2 (WinNT 5.01.2600 SP2)
Script started at 13:52:46, on 10/02/2007
Failed: DllUnregister C:\windows\system32\whefqcch.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\bgxpcxow.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\tcwleyec.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\xaygtbc.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\uguzrcf.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\pmnmjkk.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\jkhhf.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\gaunhre.dll|1 (file not found)
Failed: FileDelete C:\DOCUME~1\GUEVEL\LOCALS~1\Temp\~DF1434.tmp (operation failed)
Script completed.
Logfile of HijackThis v1.99.1
Scan saved at 13:58:03, on 10/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\windows\system32\NOTEPAD.EXE
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\aiqsjwtf.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\windows\system32\sacxdvuq.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
voici tous les rapports
à+
[02/10/2007, 13:25:19] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\GUEVEL\Bureau\VirtumundoBeGone.exe" )
[02/10/2007, 13:25:24] - Detected System Information:
[02/10/2007, 13:25:24] - Windows Version: 5.1.2600, Service Pack 2
[02/10/2007, 13:25:24] - Current Username: GUEVEL (Admin)
[02/10/2007, 13:25:24] - Windows is in NORMAL mode.
[02/10/2007, 13:25:24] - Searching for Browser Helper Objects:
[02/10/2007, 13:25:24] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/10/2007, 13:25:24] - BHO 2: {233E2BC1-76EA-40DA-B200-571545F46404} ()
[02/10/2007, 13:25:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:24] - Checking for HKLM\...\Winlogon\Notify\jkhhf
[02/10/2007, 13:25:24] - Found: HKLM\...\Winlogon\Notify\jkhhf - This is probably Virtumundo.
[02/10/2007, 13:25:24] - Assigning {233E2BC1-76EA-40DA-B200-571545F46404} MSEvents Object
[02/10/2007, 13:25:24] - BHO list has been changed! Starting over...
[02/10/2007, 13:25:24] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/10/2007, 13:25:24] - BHO 2: {233E2BC1-76EA-40DA-B200-571545F46404} (MSEvents Object)
[02/10/2007, 13:25:24] - ALERT: Found MSEvents Object!
[02/10/2007, 13:25:24] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[02/10/2007, 13:25:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:24] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[02/10/2007, 13:25:24] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[02/10/2007, 13:25:24] - BHO 4: {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} ()
[02/10/2007, 13:25:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:24] - Checking for HKLM\...\Winlogon\Notify\aiqsjwtf
[02/10/2007, 13:25:24] - Key not found: HKLM\...\Winlogon\Notify\aiqsjwtf, continuing.
[02/10/2007, 13:25:25] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/10/2007, 13:25:25] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/10/2007, 13:25:25] - BHO 7: {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} ()
[02/10/2007, 13:25:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:25] - Checking for HKLM\...\Winlogon\Notify\pmnmjkk
[02/10/2007, 13:25:25] - Found: HKLM\...\Winlogon\Notify\pmnmjkk - This is probably Virtumundo.
[02/10/2007, 13:25:25] - Assigning {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} MSEvents Object
[02/10/2007, 13:25:25] - BHO list has been changed! Starting over...
[02/10/2007, 13:25:25] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/10/2007, 13:25:25] - BHO 2: {233E2BC1-76EA-40DA-B200-571545F46404} (MSEvents Object)
[02/10/2007, 13:25:25] - ALERT: Found MSEvents Object!
[02/10/2007, 13:25:25] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[02/10/2007, 13:25:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:25] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[02/10/2007, 13:25:25] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[02/10/2007, 13:25:25] - BHO 4: {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} ()
[02/10/2007, 13:25:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:25] - Checking for HKLM\...\Winlogon\Notify\aiqsjwtf
[02/10/2007, 13:25:25] - Key not found: HKLM\...\Winlogon\Notify\aiqsjwtf, continuing.
[02/10/2007, 13:25:25] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/10/2007, 13:25:25] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/10/2007, 13:25:25] - BHO 7: {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} (MSEvents Object)
[02/10/2007, 13:25:25] - ALERT: Found MSEvents Object!
[02/10/2007, 13:25:25] - BHO 8: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} (ST)
[02/10/2007, 13:25:25] - BHO 9: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[02/10/2007, 13:25:25] - BHO 10: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (MSNToolBandBHO)
[02/10/2007, 13:25:25] - BHO 11: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[02/10/2007, 13:25:25] - Finished Searching Browser Helper Objects
[02/10/2007, 13:25:25] - *** Detected MSEvents Object
[02/10/2007, 13:25:25] - Trying to remove MSEvents Object...
[02/10/2007, 13:25:26] - Terminating Process: IEXPLORE.EXE
[02/10/2007, 13:25:27] - Terminating Process: RUNDLL32.EXE
[02/10/2007, 13:25:27] - Disabling Automatic Shell Restart
[02/10/2007, 13:25:27] - Terminating Process: EXPLORER.EXE
[02/10/2007, 13:25:27] - Suspending the NT Session Manager System Service
[02/10/2007, 13:25:27] - Terminating Windows NT Logon/Logoff Manager
[02/10/2007, 13:25:28] - Re-enabling Automatic Shell Restart
[02/10/2007, 13:25:28] - File to disable: C:\windows\system32\jkhhf.dll
[02/10/2007, 13:25:28] - Renaming C:\windows\system32\jkhhf.dll -> C:\windows\system32\jkhhf.dll.vir
[02/10/2007, 13:25:28] - File successfully renamed!
[02/10/2007, 13:25:28] - Removing HKLM\...\Browser Helper Objects\{233E2BC1-76EA-40DA-B200-571545F46404}
[02/10/2007, 13:25:28] - Removing HKCR\CLSID\{233E2BC1-76EA-40DA-B200-571545F46404}
[02/10/2007, 13:25:28] - Adding Kill Bit for ActiveX for GUID: {233E2BC1-76EA-40DA-B200-571545F46404}
[02/10/2007, 13:25:28] - Deleting ATLEvents/MSEvents Registry entries
[02/10/2007, 13:25:28] - Removing HKLM\...\Winlogon\Notify\jkhhf
[02/10/2007, 13:25:28] - Searching for Browser Helper Objects:
[02/10/2007, 13:25:28] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/10/2007, 13:25:28] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[02/10/2007, 13:25:28] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:28] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[02/10/2007, 13:25:28] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[02/10/2007, 13:25:29] - BHO 3: {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} ()
[02/10/2007, 13:25:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:29] - Checking for HKLM\...\Winlogon\Notify\aiqsjwtf
[02/10/2007, 13:25:29] - Key not found: HKLM\...\Winlogon\Notify\aiqsjwtf, continuing.
[02/10/2007, 13:25:29] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/10/2007, 13:25:29] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/10/2007, 13:25:29] - BHO 6: {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} (MSEvents Object)
[02/10/2007, 13:25:29] - ALERT: Found MSEvents Object!
[02/10/2007, 13:25:29] - BHO 7: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} (ST)
[02/10/2007, 13:25:29] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[02/10/2007, 13:25:29] - BHO 9: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (MSNToolBandBHO)
[02/10/2007, 13:25:29] - BHO 10: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[02/10/2007, 13:25:29] - Finished Searching Browser Helper Objects
[02/10/2007, 13:25:29] - *** Detected MSEvents Object
[02/10/2007, 13:25:29] - Trying to remove MSEvents Object...
[02/10/2007, 13:25:30] - Terminating Process: IEXPLORE.EXE
[02/10/2007, 13:25:30] - Terminating Process: RUNDLL32.EXE
[02/10/2007, 13:25:30] - Disabling Automatic Shell Restart
[02/10/2007, 13:25:31] - Terminating Process: EXPLORER.EXE
[02/10/2007, 13:25:31] - Suspending the NT Session Manager System Service
[02/10/2007, 13:25:31] - Terminating Windows NT Logon/Logoff Manager
[02/10/2007, 13:25:31] - Re-enabling Automatic Shell Restart
[02/10/2007, 13:25:31] - File to disable: C:\windows\system32\pmnmjkk.dll
[02/10/2007, 13:25:31] - Renaming C:\windows\system32\pmnmjkk.dll -> C:\windows\system32\pmnmjkk.dll.vir
[02/10/2007, 13:25:31] - File successfully renamed!
[02/10/2007, 13:25:31] - Removing HKLM\...\Browser Helper Objects\{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}
[02/10/2007, 13:25:31] - Removing HKCR\CLSID\{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}
[02/10/2007, 13:25:31] - Adding Kill Bit for ActiveX for GUID: {90382AD7-4298-47E0-BC0F-14ACCFF44D2C}
[02/10/2007, 13:25:31] - Deleting ATLEvents/MSEvents Registry entries
[02/10/2007, 13:25:31] - Removing HKLM\...\Winlogon\Notify\pmnmjkk
[02/10/2007, 13:25:32] - Searching for Browser Helper Objects:
[02/10/2007, 13:25:32] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/10/2007, 13:25:32] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[02/10/2007, 13:25:32] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:32] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[02/10/2007, 13:25:32] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[02/10/2007, 13:25:32] - BHO 3: {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} ()
[02/10/2007, 13:25:32] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/10/2007, 13:25:32] - Checking for HKLM\...\Winlogon\Notify\aiqsjwtf
[02/10/2007, 13:25:32] - Key not found: HKLM\...\Winlogon\Notify\aiqsjwtf, continuing.
[02/10/2007, 13:25:32] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/10/2007, 13:25:32] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/10/2007, 13:25:32] - BHO 6: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} (ST)
[02/10/2007, 13:25:32] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[02/10/2007, 13:25:32] - BHO 8: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (MSNToolBandBHO)
[02/10/2007, 13:25:32] - BHO 9: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[02/10/2007, 13:25:32] - Finished Searching Browser Helper Objects
[02/10/2007, 13:25:32] - Finishing up...
[02/10/2007, 13:25:32] - A restart is needed.
[02/10/2007, 13:25:35] - Attempting to Restart via STOP error (Blue Screen!)
Logfile of HijackThis v1.99.1
Scan saved at 13:29:19, on 10/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\aiqsjwtf.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\windows\system32\sacxdvuq.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
BFU v1.00.9
Windows XP SP2 (WinNT 5.01.2600 SP2)
Script started at 13:52:46, on 10/02/2007
Failed: DllUnregister C:\windows\system32\whefqcch.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\bgxpcxow.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\tcwleyec.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\xaygtbc.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\uguzrcf.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\pmnmjkk.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\jkhhf.dll|1 (file not found)
Failed: DllUnregister C:\windows\system32\gaunhre.dll|1 (file not found)
Failed: FileDelete C:\DOCUME~1\GUEVEL\LOCALS~1\Temp\~DF1434.tmp (operation failed)
Script completed.
Logfile of HijackThis v1.99.1
Scan saved at 13:58:03, on 10/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\windows\system32\NOTEPAD.EXE
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\aiqsjwtf.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\windows\system32\sacxdvuq.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Bonjour,
il semble que Vitumondobegone a réussi là où Vundofix a échoué.
Pour vérifier, peux tu rechercher si jkhhf et pmnmjkk sont encore dans l'ordi (fais rechercher dans tous les disques dur les noms ci-dessus).
Redémarre l'ordi,
relance combofix
poste le log de combofix avec un nouveau log hijackthis.
@+
il semble que Vitumondobegone a réussi là où Vundofix a échoué.
Pour vérifier, peux tu rechercher si jkhhf et pmnmjkk sont encore dans l'ordi (fais rechercher dans tous les disques dur les noms ci-dessus).
Redémarre l'ordi,
relance combofix
poste le log de combofix avec un nouveau log hijackthis.
@+
salut,
avec la recherche mon ordi a trouvé:
C:\VundoFixBackups\jkhhf.dll.bad
C:\VundoFixBackups\jkhhf.dll.bad
C:\WINDOWS\system32\jkhhf.dll.vir
C:\WINDOWS\system32\pmnmjkk.dll.vir
et voici les rapports combo et hijack :
à+
"GUEVEL" - 07-02-10 15:04:32 Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Documents and Settings\GUEVEL\Bureau"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\GUEVEL\Application Data\SearchToolbarCorp
((((((((((((((((((((((((((((((( Files Created from 2007-01-10 to 2007-02-10 ))))))))))))))))))))))))))))))))))
2007-02-10 13:54 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-02-10 13:31 <REP> d-------- C:\BFU
2007-02-10 11:20 118,804 --a------ C:\WINDOWS\system32\sacxdvuq.dll
2007-02-08 00:51 <REP> d-------- C:\VundoFix Backups
2007-02-07 21:08 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-02-06 13:20 <REP> d-------- C:\Program Files\MSN Messenger
2007-02-05 22:06 <REP> d-------- C:\Downloads
2007-02-05 22:06 <REP> d-------- C:\Bases
2007-02-05 05:52 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-05 05:52 <REP> d-------- C:\Program Files\Grisoft
2007-02-05 01:01 42,920 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2007-02-05 01:01 <REP> d-------- C:\WINDOWS\system32\ZoneLabs
2007-02-05 01:00 <REP> d-------- C:\WINDOWS\Internet Logs
2007-02-04 16:27 <REP> d-------- C:\Program Files\Kerio
2007-02-03 16:32 3,094 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-03 15:26 <REP> d-------- C:\WINDOWS\Sun
2007-02-03 15:26 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Sun
2007-02-03 13:40 <REP> d-------- C:\Program Files\Yahoo!
2007-02-02 17:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Talkback
2007-02-02 14:13 <REP> d-------- C:\Program Files\a-squared Free
2007-02-02 12:38 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-02-02 12:38 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2007-02-02 12:38 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2007-02-02 02:22 <REP> d--h----- C:\Program Files\Fichiers communs\Uninstall Information
2007-02-01 19:51 277,234 --a------ C:\WINDOWS\system32\jkhhf.dll.vir
2007-02-01 19:45 22,591 --a------ C:\WINDOWS\system32\pmnmjkk.dll.vir
2007-02-01 13:48 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-02-01 13:14 <REP> d-------- C:\DOCUME~1\GUEVEL\Contacts
2007-02-01 13:12 434,252 --a------ C:\WINDOWS\system32\Msvcrtd.dll
2007-02-01 13:11 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-02-01 02:11 <REP> d-------- C:\DOCUME~1\GUEVEL\Mes documents
2007-01-31 13:22 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Trymedia
2007-01-30 17:34 <REP> d-------- C:\Program Files\Java
2007-01-30 17:33 <REP> d-------- C:\Program Files\Fichiers communs\Java
2007-01-30 15:05 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\SecondLife
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\PlayFirst
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\PlayFirst
2007-01-30 02:48 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-01-24 13:56 <REP> d-------- C:\Program Files\Real
2007-01-24 13:56 <REP> d-------- C:\Program Files\Fichiers communs\Real
2007-01-24 13:56 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Real
2007-01-24 13:28 <REP> d-------- C:\Program Files\MSN Apps
2007-01-22 22:26 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-01-19 15:43 <REP> d-------- C:\Program Files\MSXML 4.0
2007-01-19 12:53 51,056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-19 10:32 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-01-19 10:32 <REP> d-------- C:\WINDOWS\system32\PreInstall
2007-01-19 10:12 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Lavasoft
2007-01-19 01:30 0 --a------ C:\WINDOWS\nsreg.dat
2007-01-18 17:26 <REP> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-01-18 17:20 3,757 --a------ C:\WINDOWS\mozver.dat
2007-01-18 17:20 <REP> d-------- C:\Program Files\Mozilla Firefox
2007-01-18 16:53 <REP> d-------- C:\Program Files\Lavasoft
2007-01-18 14:29 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Google
2007-01-18 14:28 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google
2007-01-18 14:14 <REP> d-------- C:\Program Files\Google
2007-01-18 14:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google Updater
2007-01-18 12:57 <REP> d---s---- C:\DOCUME~1\GUEVEL\UserData
2007-01-18 12:17 <REP> d--hs---- C:\WINDOWS\ftpcache
2007-01-18 12:17 <REP> d-------- C:\Program Files\Free
2007-01-11 14:15 53,248 -ra------ C:\WINDOWS\system32\NeroCo.dll
2007-01-11 14:15 1,658,880 --------- C:\WINDOWS\UNNeroBurnRights.exe
2007-01-11 14:08 99,568 --------- C:\WINDOWS\system32\drivers\incdfs.sys
2007-01-11 14:08 9,561 --------- C:\WINDOWS\system32\drivers\incdrec.sys
2007-01-11 14:08 27,664 --------- C:\WINDOWS\system32\drivers\incdpass.sys
2007-01-11 14:08 1,769,472 --------- C:\WINDOWS\NuNinst.exe
2007-01-11 14:08 <REP> d-------- C:\WINDOWS\InCD
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-08 09:41 -------- d-------- C:\Program Files\avpersonal
2007-02-06 01:08 -------- d---s---- C:\DOCUME~1\GUEVEL\Application Data\microsoft
2007-02-02 00:25 -------- d-------- C:\Program Files\ahead
2007-02-01 13:18 3665 --a------ C:\WINDOWS\urls.dat
2007-02-01 13:18 17896 --a------ C:\WINDOWS\htmlcode.dat
2007-01-31 12:10 -------- d--h----- C:\Program Files\installshield installation information
2007-01-31 12:10 -------- d-------- C:\Program Files\epson
2007-01-31 10:27 -------- d-------- C:\Program Files\quicktime
2007-01-28 11:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobeum
2007-01-20 01:56 48616 --a--c--- C:\WINDOWS\system32\perfc00c.dat
2007-01-20 01:56 367658 --a--c--- C:\WINDOWS\system32\perfh00c.dat
2007-01-19 15:46 -------- d-------- C:\Program Files\messenger
2007-01-19 01:30 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\mozilla
2007-01-18 15:20 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\macromedia
2007-01-18 12:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobe
2007-01-11 15:12 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\ahead
2006-12-07 17:02 2174976 --a------ C:\WINDOWS\system32\wmvcore.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"regkeyname"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"NeroFilterCheck"="C:\\windows\\system32\\NeroCheck.exe"
"AVGCtrl"="C:\\Program Files\\AVPersonal\\AVGNT.EXE /min"
"iKeyWorks"="C:\\PROGRA~1\\A4Tech\\Keyboard\\Ikeymain.exe"
"EPSON Stylus Photo RX420 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9CE.EXE /P31 \"EPSON Stylus Photo RX420 Series\" /O6 \"USB001\" /M \"Stylus Photo RX420\""
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"AVSCHED32"="C:\\Program Files\\AVPersonal\\AVSCHED32.EXE /min"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"DllRunning"="rundll32.exe \"C:\\windows\\system32\\sacxdvuq.dll\",setvm"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6359eeb0-4e50-11db-82f0-001109630ca1}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL 4x3_LIEVIN_BIS.PDF
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-10 15:06:41
Logfile of HijackThis v1.99.1
Scan saved at 15:07:01, on 10/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\NOTEPAD.EXE
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\aiqsjwtf.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\windows\system32\sacxdvuq.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
avec la recherche mon ordi a trouvé:
C:\VundoFixBackups\jkhhf.dll.bad
C:\VundoFixBackups\jkhhf.dll.bad
C:\WINDOWS\system32\jkhhf.dll.vir
C:\WINDOWS\system32\pmnmjkk.dll.vir
et voici les rapports combo et hijack :
à+
"GUEVEL" - 07-02-10 15:04:32 Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Documents and Settings\GUEVEL\Bureau"
(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\DOCUME~1\GUEVEL\Application Data\SearchToolbarCorp
((((((((((((((((((((((((((((((( Files Created from 2007-01-10 to 2007-02-10 ))))))))))))))))))))))))))))))))))
2007-02-10 13:54 4,212 ---h----- C:\WINDOWS\system32\zllictbl.dat
2007-02-10 13:31 <REP> d-------- C:\BFU
2007-02-10 11:20 118,804 --a------ C:\WINDOWS\system32\sacxdvuq.dll
2007-02-08 00:51 <REP> d-------- C:\VundoFix Backups
2007-02-07 21:08 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-02-06 13:20 <REP> d-------- C:\Program Files\MSN Messenger
2007-02-05 22:06 <REP> d-------- C:\Downloads
2007-02-05 22:06 <REP> d-------- C:\Bases
2007-02-05 05:52 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-02-05 05:52 <REP> d-------- C:\Program Files\Grisoft
2007-02-05 01:01 42,920 --a------ C:\WINDOWS\system32\vsutil_loc040c.dll
2007-02-05 01:01 <REP> d-------- C:\WINDOWS\system32\ZoneLabs
2007-02-05 01:00 <REP> d-------- C:\WINDOWS\Internet Logs
2007-02-04 16:27 <REP> d-------- C:\Program Files\Kerio
2007-02-03 16:32 3,094 --a------ C:\WINDOWS\system32\tmp.reg
2007-02-03 15:26 <REP> d-------- C:\WINDOWS\Sun
2007-02-03 15:26 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Sun
2007-02-03 13:40 <REP> d-------- C:\Program Files\Yahoo!
2007-02-02 17:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Talkback
2007-02-02 14:13 <REP> d-------- C:\Program Files\a-squared Free
2007-02-02 12:38 512,688 --a------ C:\WINDOWS\system32\XceedCry.dll
2007-02-02 12:38 423,784 --a------ C:\WINDOWS\system32\XceedBkp.dll
2007-02-02 12:38 101,888 --a------ C:\WINDOWS\system32\VB6STKIT.DLL
2007-02-02 02:22 <REP> d--h----- C:\Program Files\Fichiers communs\Uninstall Information
2007-02-01 19:51 277,234 --a------ C:\WINDOWS\system32\jkhhf.dll.vir
2007-02-01 19:45 22,591 --a------ C:\WINDOWS\system32\pmnmjkk.dll.vir
2007-02-01 13:48 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-02-01 13:14 <REP> d-------- C:\DOCUME~1\GUEVEL\Contacts
2007-02-01 13:12 434,252 --a------ C:\WINDOWS\system32\Msvcrtd.dll
2007-02-01 13:11 <REP> d----c--- C:\WINDOWS\system32\DRVSTORE
2007-02-01 02:11 <REP> d-------- C:\DOCUME~1\GUEVEL\Mes documents
2007-01-31 13:22 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Trymedia
2007-01-30 17:34 <REP> d-------- C:\Program Files\Java
2007-01-30 17:33 <REP> d-------- C:\Program Files\Fichiers communs\Java
2007-01-30 15:05 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\SecondLife
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\PlayFirst
2007-01-30 12:13 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\PlayFirst
2007-01-30 02:48 1,060,864 --a------ C:\WINDOWS\system32\mfc71.dll
2007-01-24 13:56 <REP> d-------- C:\Program Files\Real
2007-01-24 13:56 <REP> d-------- C:\Program Files\Fichiers communs\Real
2007-01-24 13:56 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Real
2007-01-24 13:28 <REP> d-------- C:\Program Files\MSN Apps
2007-01-22 22:26 262,144 --a------ C:\DOCUME~1\ALLUSE~1\ntuser.dat
2007-01-19 15:43 <REP> d-------- C:\Program Files\MSXML 4.0
2007-01-19 12:53 51,056 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-01-19 10:32 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2007-01-19 10:32 <REP> d-------- C:\WINDOWS\system32\PreInstall
2007-01-19 10:12 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Lavasoft
2007-01-19 01:30 0 --a------ C:\WINDOWS\nsreg.dat
2007-01-18 17:26 <REP> d-------- C:\WINDOWS\system32\SoftwareDistribution
2007-01-18 17:20 3,757 --a------ C:\WINDOWS\mozver.dat
2007-01-18 17:20 <REP> d-------- C:\Program Files\Mozilla Firefox
2007-01-18 16:53 <REP> d-------- C:\Program Files\Lavasoft
2007-01-18 14:29 <REP> d-------- C:\DOCUME~1\GUEVEL\Application Data\Google
2007-01-18 14:28 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google
2007-01-18 14:14 <REP> d-------- C:\Program Files\Google
2007-01-18 14:14 <REP> d-------- C:\DOCUME~1\ALLUSE~1\Application Data\Google Updater
2007-01-18 12:57 <REP> d---s---- C:\DOCUME~1\GUEVEL\UserData
2007-01-18 12:17 <REP> d--hs---- C:\WINDOWS\ftpcache
2007-01-18 12:17 <REP> d-------- C:\Program Files\Free
2007-01-11 14:15 53,248 -ra------ C:\WINDOWS\system32\NeroCo.dll
2007-01-11 14:15 1,658,880 --------- C:\WINDOWS\UNNeroBurnRights.exe
2007-01-11 14:08 99,568 --------- C:\WINDOWS\system32\drivers\incdfs.sys
2007-01-11 14:08 9,561 --------- C:\WINDOWS\system32\drivers\incdrec.sys
2007-01-11 14:08 27,664 --------- C:\WINDOWS\system32\drivers\incdpass.sys
2007-01-11 14:08 1,769,472 --------- C:\WINDOWS\NuNinst.exe
2007-01-11 14:08 <REP> d-------- C:\WINDOWS\InCD
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-02-08 09:41 -------- d-------- C:\Program Files\avpersonal
2007-02-06 01:08 -------- d---s---- C:\DOCUME~1\GUEVEL\Application Data\microsoft
2007-02-02 00:25 -------- d-------- C:\Program Files\ahead
2007-02-01 13:18 3665 --a------ C:\WINDOWS\urls.dat
2007-02-01 13:18 17896 --a------ C:\WINDOWS\htmlcode.dat
2007-01-31 12:10 -------- d--h----- C:\Program Files\installshield installation information
2007-01-31 12:10 -------- d-------- C:\Program Files\epson
2007-01-31 10:27 -------- d-------- C:\Program Files\quicktime
2007-01-28 11:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobeum
2007-01-20 01:56 48616 --a--c--- C:\WINDOWS\system32\perfc00c.dat
2007-01-20 01:56 367658 --a--c--- C:\WINDOWS\system32\perfh00c.dat
2007-01-19 15:46 -------- d-------- C:\Program Files\messenger
2007-01-19 01:30 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\mozilla
2007-01-18 15:20 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\macromedia
2007-01-18 12:26 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\adobe
2007-01-11 15:12 -------- d-------- C:\DOCUME~1\GUEVEL\Application Data\ahead
2006-12-07 17:02 2174976 --a------ C:\WINDOWS\system32\wmvcore.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\windows\\system32\\ctfmon.exe"
"NBJ"="\"C:\\Program Files\\Ahead\\Nero BackItUp\\NBJ.exe\""
"swg"="C:\\Program Files\\Google\\GoogleToolbarNotifier\\1.2.1128.5462\\GoogleToolbarNotifier.exe"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"regkeyname"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"NeroFilterCheck"="C:\\windows\\system32\\NeroCheck.exe"
"AVGCtrl"="C:\\Program Files\\AVPersonal\\AVGNT.EXE /min"
"iKeyWorks"="C:\\PROGRA~1\\A4Tech\\Keyboard\\Ikeymain.exe"
"EPSON Stylus Photo RX420 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9CE.EXE /P31 \"EPSON Stylus Photo RX420 Series\" /O6 \"USB001\" /M \"Stylus Photo RX420\""
"InCD"="C:\\Program Files\\Ahead\\InCD\\InCD.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"AVSCHED32"="C:\\Program Files\\AVPersonal\\AVSCHED32.EXE /min"
"Zone Labs Client"="\"C:\\Program Files\\Zone Labs\\ZoneAlarm\\zlclient.exe\""
"Google Desktop Search"="\"C:\\Program Files\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"DllRunning"="rundll32.exe \"C:\\windows\\system32\\sacxdvuq.dll\",setvm"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex]
@=""
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"appinit_dlls"="C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{90382AD7-4298-47E0-BC0F-14ACCFF44D2C}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6359eeb0-4e50-11db-82f0-001109630ca1}]
Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL 4x3_LIEVIN_BIS.PDF
********************************************************************
catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net
scanning hidden processes ...
scanning hidden services ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
********************************************************************
Completion time: 07-02-10 15:06:41
Logfile of HijackThis v1.99.1
Scan saved at 15:07:01, on 10/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\NOTEPAD.EXE
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\aiqsjwtf.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\windows\system32\sacxdvuq.dll",setvm
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Bonjour,
je crois qu'il n'en reste plus qu'un !
Comme j'aime bien savoir à qui j'ai affaire,
Rends toi sur ce site :
http://www.virustotal.com/xhtml/virustotal_en.html
Clique sur parcourir et cherche ce fichier : C:\windows\system32\sacxdvuq.dll
Clique sur send.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Tu relances AVG antispy (voir post 9 si nécessaire). Tu postes le log, après avoir appliqué les actions.
@+
je crois qu'il n'en reste plus qu'un !
Comme j'aime bien savoir à qui j'ai affaire,
Rends toi sur ce site :
http://www.virustotal.com/xhtml/virustotal_en.html
Clique sur parcourir et cherche ce fichier : C:\windows\system32\sacxdvuq.dll
Clique sur send.
Un rapport va s'élaborer ligne à ligne.
Attends la fin. Il doit comprendre la taille du fichier envoyé.
Sauvegarde le rapport avec le bloc-note.
Copie le dans ta réponse.
Tu relances AVG antispy (voir post 9 si nécessaire). Tu postes le log, après avoir appliqué les actions.
@+
Salut,
voici les 2 rapports que tu voulais
à+
Complete scanning result of "sacxdvuq.dll_", received in VirusTotal at 02.10.2007, 17:54:09 (CET).
Antivirus Version Update Result
AntiVir 7.3.1.36 02.09.2007 ADSPY/Virtumonde.FT
Authentium 4.93.8 02.09.2007 no virus found
Avast 4.7.936.0 02.10.2007 Win32:Adware-gen.
AVG 386 02.09.2007 Adware Generic.SKU
BitDefender 7.2 02.10.2007 Trojan.Virtumod.EB
CAT-QuickHeal 9.00 02.09.2007 AdWare.Virtumonde.ft (Not a Virus)
ClamAV devel-20060426 02.10.2007 no virus found
DrWeb 4.33 02.10.2007 Trojan.Virtumod
eSafe 7.0.14.0 02.09.2007 no virus found
eTrust-Vet 30.4.3384 02.10.2007 Win32/Vundo.BY
Ewido 4.0 02.10.2007 no virus found
Fortinet 2.85.0.0 02.10.2007 suspicious
F-Prot 4.2.1.29 02.09.2007 no virus found
F-Secure 6.70.13030.0 02.10.2007 no virus found
Ikarus T3.1.0.31 02.10.2007 not-a-virus:AdWare.Win32.Virtumonde.ft
Kaspersky 4.0.2.24 02.10.2007 not-a-virus:AdWare.Win32.Virtumonde.ft
McAfee 4960 02.09.2007 Vundo.dll
Microsoft 1.2204 02.10.2007 no virus found
NOD32v2 2050 02.10.2007 Win32/Adware.Virtumonde.FT
Norman 5.80.02 02.09.2007 W32/Virtumonde.TM
Panda 9.0.0.4 02.10.2007 Spyware/Virtumonde
Prevx1 V2 02.10.2007 no virus found
Sophos 4.13.0 02.08.2007 no virus found
Sunbelt 2.2.907.0 02.09.2007 VIPRE.Suspicious
Symantec 10 02.10.2007 Trojan.Vundo
TheHacker 6.1.6.055 02.09.2007 Adware/Virtumonde.ft
UNA 1.83 02.09.2007 Adware.Virtumonde.E6F3
VBA32 3.11.2 02.09.2007 Adware.Virtumonde
VirusBuster 4.3.19:9 02.10.2007 Adware.Virtumonde.BL
Aditional Information
File size: 118804 bytes
MD5: 0767a8d5ac036425d43e74f29847cc7e
SHA1: fc951a74a7e8a5239ada35b628dce98531f3937f
packers: UPX
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 18:43:08 10/02/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{2C7AF1E4-B2BC-4175-A4AF-DF9EB1EDFECC}\RP331\A0118294.dll -> Adware.Virtumonde : Nettoyé.
C:\WINDOWS\system32\pmnmjkk.dll.vir -> Adware.Virtumonde : Nettoyé.
:mozilla.14:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.17:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.18:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.38:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.205:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.206:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.43:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.44:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.45:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.46:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.180:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.181:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.31:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.207:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.117:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.118:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.119:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.77:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.74:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.115:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.116:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.54:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.55:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.56:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.57:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.198:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.146:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.147:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.148:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.19:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.20:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.21:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.22:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.23:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.24:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.32:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.33:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.34:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.168:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Spylog : Nettoyé.
:mozilla.72:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.73:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.122:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.123:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.124:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.178:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.172:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.173:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
Fin du rapport
voici les 2 rapports que tu voulais
à+
Complete scanning result of "sacxdvuq.dll_", received in VirusTotal at 02.10.2007, 17:54:09 (CET).
Antivirus Version Update Result
AntiVir 7.3.1.36 02.09.2007 ADSPY/Virtumonde.FT
Authentium 4.93.8 02.09.2007 no virus found
Avast 4.7.936.0 02.10.2007 Win32:Adware-gen.
AVG 386 02.09.2007 Adware Generic.SKU
BitDefender 7.2 02.10.2007 Trojan.Virtumod.EB
CAT-QuickHeal 9.00 02.09.2007 AdWare.Virtumonde.ft (Not a Virus)
ClamAV devel-20060426 02.10.2007 no virus found
DrWeb 4.33 02.10.2007 Trojan.Virtumod
eSafe 7.0.14.0 02.09.2007 no virus found
eTrust-Vet 30.4.3384 02.10.2007 Win32/Vundo.BY
Ewido 4.0 02.10.2007 no virus found
Fortinet 2.85.0.0 02.10.2007 suspicious
F-Prot 4.2.1.29 02.09.2007 no virus found
F-Secure 6.70.13030.0 02.10.2007 no virus found
Ikarus T3.1.0.31 02.10.2007 not-a-virus:AdWare.Win32.Virtumonde.ft
Kaspersky 4.0.2.24 02.10.2007 not-a-virus:AdWare.Win32.Virtumonde.ft
McAfee 4960 02.09.2007 Vundo.dll
Microsoft 1.2204 02.10.2007 no virus found
NOD32v2 2050 02.10.2007 Win32/Adware.Virtumonde.FT
Norman 5.80.02 02.09.2007 W32/Virtumonde.TM
Panda 9.0.0.4 02.10.2007 Spyware/Virtumonde
Prevx1 V2 02.10.2007 no virus found
Sophos 4.13.0 02.08.2007 no virus found
Sunbelt 2.2.907.0 02.09.2007 VIPRE.Suspicious
Symantec 10 02.10.2007 Trojan.Vundo
TheHacker 6.1.6.055 02.09.2007 Adware/Virtumonde.ft
UNA 1.83 02.09.2007 Adware.Virtumonde.E6F3
VBA32 3.11.2 02.09.2007 Adware.Virtumonde
VirusBuster 4.3.19:9 02.10.2007 Adware.Virtumonde.BL
Aditional Information
File size: 118804 bytes
MD5: 0767a8d5ac036425d43e74f29847cc7e
SHA1: fc951a74a7e8a5239ada35b628dce98531f3937f
packers: UPX
Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics.
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 18:43:08 10/02/2007
+ Résultat de l'analyse:
C:\System Volume Information\_restore{2C7AF1E4-B2BC-4175-A4AF-DF9EB1EDFECC}\RP331\A0118294.dll -> Adware.Virtumonde : Nettoyé.
C:\WINDOWS\system32\pmnmjkk.dll.vir -> Adware.Virtumonde : Nettoyé.
:mozilla.14:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.17:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.18:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.247realmedia : Nettoyé.
:mozilla.38:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.2o7 : Nettoyé.
:mozilla.205:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.206:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adtech : Nettoyé.
:mozilla.43:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.44:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.45:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.46:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Advertising : Nettoyé.
:mozilla.180:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.181:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Adviva : Nettoyé.
:mozilla.31:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Atdmt : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
:mozilla.207:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Bluestreak : Nettoyé.
:mozilla.117:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.118:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.119:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Casalemedia : Nettoyé.
:mozilla.77:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Doubleclick : Nettoyé.
:mozilla.74:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Estat : Nettoyé.
:mozilla.115:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.116:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Fastclick : Nettoyé.
:mozilla.54:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.55:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.56:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.57:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Hitbox : Nettoyé.
:mozilla.198:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Mediaplex : Nettoyé.
:mozilla.146:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.147:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.148:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Pointroll : Nettoyé.
:mozilla.19:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.20:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.21:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.22:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.23:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.24:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Serving-sys : Nettoyé.
:mozilla.32:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.33:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.34:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Smartadserver : Nettoyé.
:mozilla.168:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Spylog : Nettoyé.
:mozilla.72:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.73:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Statcounter : Nettoyé.
:mozilla.122:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.123:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.124:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Tradedoubler : Nettoyé.
:mozilla.178:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Weborama : Nettoyé.
C:\Documents and Settings\GUEVEL\Cookies\guevel@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.
:mozilla.172:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
:mozilla.173:C:\Documents and Settings\GUEVEL\Application Data\Mozilla\Firefox\Profiles\l4lfh3h0.default\cookies.txt -> TrackingCookie.Yieldmanager : Nettoyé.
Fin du rapport
Re,
relance Vundofix et poste le log.
Mets aussi un nouveau rapport Hijackthis;
@+
relance Vundofix et poste le log.
Mets aussi un nouveau rapport Hijackthis;
@+
bonjour,
voici les rapports vundofix et hijack
à+
C:\windows\system32\aiqsjwtf.dll
C:\windows\system32\quvdxcas.ini
C:\windows\system32\sacxdvuq.dll
Beginning removal...
Attempting to delete C:\windows\system32\quvdxcas.ini
C:\windows\system32\quvdxcas.ini Has been deleted!
Attempting to delete C:\windows\system32\sacxdvuq.dll
C:\windows\system32\sacxdvuq.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\sacxdvuq.dll
C:\windows\system32\sacxdvuq.dll Has been deleted!
Performing Repairs to the registry.
Done!
Logfile of HijackThis v1.99.1
Scan saved at 15:35:08, on 11/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\windows\system32\rundll32.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\windows\system32\wuauclt.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\aiqsjwtf.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
voici les rapports vundofix et hijack
à+
C:\windows\system32\aiqsjwtf.dll
C:\windows\system32\quvdxcas.ini
C:\windows\system32\sacxdvuq.dll
Beginning removal...
Attempting to delete C:\windows\system32\quvdxcas.ini
C:\windows\system32\quvdxcas.ini Has been deleted!
Attempting to delete C:\windows\system32\sacxdvuq.dll
C:\windows\system32\sacxdvuq.dll Could not be deleted.
Performing Repairs to the registry.
Done!
Beginning removal...
Attempting to delete C:\windows\system32\sacxdvuq.dll
C:\windows\system32\sacxdvuq.dll Has been deleted!
Performing Repairs to the registry.
Done!
Logfile of HijackThis v1.99.1
Scan saved at 15:35:08, on 11/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\windows\system32\rundll32.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\windows\system32\wuauclt.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\aiqsjwtf.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Bonjour,
redémarre l'ordi,
Ouvre HijackThis, choisi do a scan only.
Coche la case devant la ligne :
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\aiqsjwtf.dll (file missing)
Ferme toutes les fenêtres (hormis Hijackthis) et clique sur Fix checked.
Ferme Hijackthis.
Relance HijackThis et poste le log.
@+
redémarre l'ordi,
Ouvre HijackThis, choisi do a scan only.
Coche la case devant la ligne :
O2 - BHO: (no name) - {68D5CF1D-EC5C-4bdd-A9EF-F0E517565D50} - C:\windows\system32\aiqsjwtf.dll (file missing)
Ferme toutes les fenêtres (hormis Hijackthis) et clique sur Fix checked.
Ferme Hijackthis.
Relance HijackThis et poste le log.
@+
salut
voici le log
à+
Logfile of HijackThis v1.99.1
Scan saved at 17:32:21, on 11/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
voici le log
à+
Logfile of HijackThis v1.99.1
Scan saved at 17:32:21, on 11/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\windows\system32\spoolsv.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\Documents and Settings\GUEVEL\Bureau\vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Re,
on attend quand même quelques jours la confirmation de tout ça.
En attendant, on va prendre un point de restauration propre.
Va sur ce lien et exécute désactiver puis réactiver la restauration comme indiqué :
http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20020830101856924 .
Je vais te faire faire un nettoyage final que je te conseille de faire régulièrement (un fois par semaine environ).
Imprime et exécute cette manip dans l’ordre.
#Télécharge et installe ces logiciels (si tu ne les as pas) .
Pour les 3 premiers mets les à jour, comme indiqué dans les démos ou tutos.
Ne les utilises pas tout de suite.
Antispywares et autres :
*Ad-Aware (gratuit)
Téléchargement :
http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/11643.html
Le patch en Français pour Ad-Aware (gratuit) :
http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/25543.html
Tuto :
http://perso.orange.fr/entraide-hijackthis/AdAware/AdAware.htm
*Spybot (gratuit) :
Téléchargement :
http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/26157.html
voir demo d utilisation (merci Balltrap)
http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
* AVG AS
AVG anti spyware
https://www.01net.com/
Met le a jour avant de lancer le scan.
Tuto :
http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html
Nettoyeurs (de fichiers inutiles) et autres :
*Ccleaner (gratuit)
Téléchargement :
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
Tuto :
https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
Lors de l’installation, [décoche] l’option qui t’installerait la barre Yahoo !
========================================
->Affiches tous les fichiers et dossiers :
cliques sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage
[Coche] « afficher les dossiers et fichiers cachés »
[Décoches] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »
[Décoches] « masquer les extensions dont le type est connu »
Puis fais [appliquer] pour valider les changements.
Et [Ok]
=======================================
->Démarre en mode sans échec :
Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec
puis tape « entrée ».
Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
(Si F8 ne marche pas utilise la touche F5).
========================================
->Lance CCleaner.
Suppression des fichiers temporaires
Va dans la section "Options" situé dans la marge gauche. Va dans "Avancé" et décoche
Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
Retourne ensuite dans la section "Nettoyeur"
Fais bien attention de cocher toutes les cases dans la marge gauche (Internet Explorer/Windows Explorer/Système/Avancé)
• Clique sur [Analyse]
• Patiente le temps du scan, qui peut prendre un peu de temps si c'est la première fois.
• Une fois le scan terminé, clique sur [Lancer le Nettoyage]
========================================
->Lance AVG pour un scan complet "Analyse" ->"Paramètres"
Sous la question "Comment réagir ?" :
-> clique sur "Actions recommandées" et choisis "Quarantaines"
-> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"
Si un fichier est infecté en fin d'analyse
->Clique sur "Appliquer toutes les actions "
->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".
->Enregistre ce fichier texte sur ton bureau et [copie/colle le rapport en forum]
========================================
->Passe Ad-Aware et supprime tout ce qu’il trouve + supprime les quarantaines…
========================================
->Passe Spybot et corrige tout ce qu’il trouve + vaccine + supprime les quarantaines…
========================================
->Relance CCleaner.
Suppression des incohérences du registre
• Clique sur l'icône [Erreurs] situés dans la marge à gauche
• Puis clique sur [Analyser les erreurs]
• Patiente pendant que CCleaner scan ton registre.
• Une fois le scan terminé, coche toutes les entrèes qu'il t'aura trouvée.
• Tu peux cliquer ensuite sur [Corriger les erreurs].
Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement.
========================================
->Vide ta Corbeille.
========================================
->Redémarre en mode normal.
Remasque les fichiers protégés du système d'exploitation (mais garde les 2 autres visibles, en particulier les extensions des fichiers doivent toujours rester visibles).
Je voulais te dire que tu t'es bien battue dans cette aventure. Heureusement d'ailleurs, car tu avais un nombre impressionnant d'infections différentes.
Et je n'ai pas été génial. Mais j'ai beaucoup appris.
@+
on attend quand même quelques jours la confirmation de tout ça.
En attendant, on va prendre un point de restauration propre.
Va sur ce lien et exécute désactiver puis réactiver la restauration comme indiqué :
http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20020830101856924 .
Je vais te faire faire un nettoyage final que je te conseille de faire régulièrement (un fois par semaine environ).
Imprime et exécute cette manip dans l’ordre.
#Télécharge et installe ces logiciels (si tu ne les as pas) .
Pour les 3 premiers mets les à jour, comme indiqué dans les démos ou tutos.
Ne les utilises pas tout de suite.
Antispywares et autres :
*Ad-Aware (gratuit)
Téléchargement :
http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/11643.html
Le patch en Français pour Ad-Aware (gratuit) :
http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/25543.html
Tuto :
http://perso.orange.fr/entraide-hijackthis/AdAware/AdAware.htm
*Spybot (gratuit) :
Téléchargement :
http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/26157.html
voir demo d utilisation (merci Balltrap)
http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
* AVG AS
AVG anti spyware
https://www.01net.com/
Met le a jour avant de lancer le scan.
Tuto :
http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html
Nettoyeurs (de fichiers inutiles) et autres :
*Ccleaner (gratuit)
Téléchargement :
https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html
Tuto :
https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
Lors de l’installation, [décoche] l’option qui t’installerait la barre Yahoo !
========================================
->Affiches tous les fichiers et dossiers :
cliques sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage
[Coche] « afficher les dossiers et fichiers cachés »
[Décoches] la case « Masquer les fichiers protégés du système d'exploitation (recommandé) »
[Décoches] « masquer les extensions dont le type est connu »
Puis fais [appliquer] pour valider les changements.
Et [Ok]
=======================================
->Démarre en mode sans échec :
Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec
puis tape « entrée ».
Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
(Si F8 ne marche pas utilise la touche F5).
========================================
->Lance CCleaner.
Suppression des fichiers temporaires
Va dans la section "Options" situé dans la marge gauche. Va dans "Avancé" et décoche
Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures".
Retourne ensuite dans la section "Nettoyeur"
Fais bien attention de cocher toutes les cases dans la marge gauche (Internet Explorer/Windows Explorer/Système/Avancé)
• Clique sur [Analyse]
• Patiente le temps du scan, qui peut prendre un peu de temps si c'est la première fois.
• Une fois le scan terminé, clique sur [Lancer le Nettoyage]
========================================
->Lance AVG pour un scan complet "Analyse" ->"Paramètres"
Sous la question "Comment réagir ?" :
-> clique sur "Actions recommandées" et choisis "Quarantaines"
-> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"
Si un fichier est infecté en fin d'analyse
->Clique sur "Appliquer toutes les actions "
->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".
->Enregistre ce fichier texte sur ton bureau et [copie/colle le rapport en forum]
========================================
->Passe Ad-Aware et supprime tout ce qu’il trouve + supprime les quarantaines…
========================================
->Passe Spybot et corrige tout ce qu’il trouve + vaccine + supprime les quarantaines…
========================================
->Relance CCleaner.
Suppression des incohérences du registre
• Clique sur l'icône [Erreurs] situés dans la marge à gauche
• Puis clique sur [Analyser les erreurs]
• Patiente pendant que CCleaner scan ton registre.
• Une fois le scan terminé, coche toutes les entrèes qu'il t'aura trouvée.
• Tu peux cliquer ensuite sur [Corriger les erreurs].
Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement.
========================================
->Vide ta Corbeille.
========================================
->Redémarre en mode normal.
Remasque les fichiers protégés du système d'exploitation (mais garde les 2 autres visibles, en particulier les extensions des fichiers doivent toujours rester visibles).
Je voulais te dire que tu t'es bien battue dans cette aventure. Heureusement d'ailleurs, car tu avais un nombre impressionnant d'infections différentes.
Et je n'ai pas été génial. Mais j'ai beaucoup appris.
@+
Bonjour,
merci pour le compliment mais je vais continuer à croire que tu as eu un rôle primordial ds la résolution de cette histoire.
et merci encore
voici le rapport AVG
sinon adware et spybot n'ont rien trouvé
à+
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 10:07:59 13/02/2007
+ Résultat de l'analyse:
C:\VundoFix Backups\qqphvvxo.dll.bad -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\VundoFix Backups\sacxdvuq.dll.bad -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
Fin du rapport
merci pour le compliment mais je vais continuer à croire que tu as eu un rôle primordial ds la résolution de cette histoire.
et merci encore
voici le rapport AVG
sinon adware et spybot n'ont rien trouvé
à+
AVG Anti-Spyware - Rapport d'analyse
---------------------------------------------------------
+ Créé à: 10:07:59 13/02/2007
+ Résultat de l'analyse:
C:\VundoFix Backups\qqphvvxo.dll.bad -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
C:\VundoFix Backups\sacxdvuq.dll.bad -> Adware.Virtumonde : Nettoyé et sauvegardé (mise en quarantaine).
Fin du rapport
Logfile of HijackThis v1.99.1
Scan saved at 01:22:25, on 07/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\windows\system32\drivers\KodakCCS.exe
C:\windows\system32\svchost.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\AVPersonal\AVSCHED32.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\MSI\Core Center\CoreCenter.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerTV.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\GUEVEL\Bureau\Vundoscan.exe
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.microsoft.com/en-us/windows?type=Hardware&category=MP3%20%26%20Media%20Players&subcategory=Other%20Media%20Players
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0DFDAA04-D717-47B6-821F-0E7D91007B0F} - C:\windows\system32\jkhhf.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {90382AD7-4298-47E0-BC0F-14ACCFF44D2C} - C:\windows\system32\pmnmjkk.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\windows\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Program Files\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [iKeyWorks] C:\PROGRA~1\A4Tech\Keyboard\Ikeymain.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.EXE /P31 "EPSON Stylus Photo RX420 Series" /O6 "USB001" /M "Stylus Photo RX420"
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [AVSCHED32] C:\Program Files\AVPersonal\AVSCHED32.EXE /min
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
O4 - Global Startup: Kodak software updater.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logiciel Kodak EasyShare.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV Hybrid + FM PCI\AVerQT.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {A4F64D63-3576-4754-8DD5-4D0A49345FD5} - (no file) (HKCU)
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: jkhhf - C:\windows\system32\jkhhf.dll
O20 - Winlogon Notify: pmnmjkk - C:\windows\SYSTEM32\pmnmjkk.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\windows\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\windows\system32\drivers\KodakCCS.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe