`infecte par trojan haxdoor

Résolu
salut

mon antivirus vient de detecter un trojan haxdoor (II et GB), j'ai mis en quarantaine les fichiers infectes sauf que le pc est de plus en plus lent, en plus j'ai de la difficulte a me connecter a internet. aidez moi svp je ne sais plus quoi faire, j'ai lance un scan par Hijackthis, en voici le rapport:

Logfile of HijackThis v1.99.1
Scan saved at 3:34:44 PM, on 18/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\smss.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Alwil Software\Avast4\ashChest.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\BSALAH\LOCALS~1\Temp\Rar$EX00.511\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.files-ftp.com/~unicorni/phpBB2/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: (no name) - {1E6CE4CD-161B-4847-B8BF-E2EF72299D69} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [Microsoft Windows Session Manager Subsystem] C:\WINDOWS\smss.exe
O4 - HKLM\..\Run: [Microsoft Windows Logon Process] C:\WINDOWS\winlogon.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.8472\GoogleToolbarNotifier.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)

merci infiniment d'avance.
Configuration: Windows XP
Internet Explorer 6.0

38 réponses

Résumé de la discussion

Des symptômes d'infection Trojan Haxdoor sur Windows XP SP2 provoquent lenteur du PC et difficultés de connexion Internet, malgré la mise en quarantaine de fichiers détectés par l'antivirus. Plusieurs discussions suggèrent des outils de nettoyage comme l2mfix et haxfix, l'analyse du registre et des exécutables système, et le partage de rapports HijackThis pour identifier les clés malicieuses. Références à des fichiers suspects tels que ufgrbe.sys et utgrbe.sys dans System32, et des recommandations d'utiliser VundoFix pour nettoyer le système et poster les résultats. En cas d'évolution, des mesures évoquées incluent aussi le renommage d'applications HijackThis pour contourner les blocages et la vérification des clés de démarrage, sans conclure sur l'état final du problème.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut

    où est-ce q'il te le detecte ???

    ++
    0
    1. salut green day et merci pour ta reponse

      En fait j'etais sur un site internet de partage peer to peer lorsque avast a detecté les 2 fichiers suivants infectes par le haxdoor : ufgrbe.sys(C:\WINNT\system32) et utgrbe.sys (:\WINNT\system32) . En plus une icone d'execution de logiciel inconnue est apparue sur l'ecran bureau juste apres l'alarme de l'anti virus. (j'y pas touché a cet icone, pourrais je la supprimer sans risque?).
      Je n'ai executé ni telechargé aucun logiciel ou fichier au moment de la detection du trojan (juste naviguation).
      merci encore une fois.
      0
  2. Modérateur
    Salut

    ok, fais les manips de ce lien stp :

    virus methode preliminaire de desinfection version fr

    @+
    0
    1. salut

      je vous remercie d'abord pour votre aide, et je fais suivre les 2 rapports issus de l'analyse complete du systeme avec Bitdefender et hijackthis:

      ****************BitDefender Online Scanner******************

      Scan report generated at: Fri, Feb 23, 2007 - 16:42:28

      Scan path: A:\;C:\;D:\;E:\;

      Statistics

      Time

      01:15:05

      Files

      215209

      Folders

      2904

      Boot Sectors

      3

      Archives

      1888

      Packed Files

      19228

      Results

      Identified Viruses

      14

      Infected Files

      27

      Suspect Files

      0

      Warnings

      0

      Disinfected

      0

      Deleted Files

      23

      Engines Info

      Virus Definitions

      393278

      Engine build

      AVCORE v1.0 (build 2397) (i386) (Feb 8 2007 14:24:08)

      Scan plugins

      14

      Archive plugins

      38

      Unpack plugins

      6

      E-mail plugins

      6

      System plugins

      1

      Scan Settings

      First Action

      Disinfect

      Second Action

      Delete

      Heuristics

      Yes

      Enable Warnings

      Yes

      Scanned Extensions

      *;

      Exclude Extensions

      Scan Emails

      Yes

      Scan Archives

      Yes

      Scan Packed

      Yes

      Scan Files

      Yes

      Scan Boot

      Yes

      Scanned File

      Status

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\6PG3Q5CT\popup[1].php=>(gzip)

      Infected with: Trojan.Clicker.AC

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\6PG3Q5CT\popup[1].php=>(gzip)

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\6PG3Q5CT\popup[1].php=>(gzip)

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\6PG3Q5CT\popup[1].php

      Update failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\7NCGHG90\popup[1].php=>(gzip)

      Infected with: Trojan.Clicker.AC

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\7NCGHG90\popup[1].php=>(gzip)

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\7NCGHG90\popup[1].php=>(gzip)

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\7NCGHG90\popup[1].php

      Update failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\GLQFW9UJ\popup[1].php=>(gzip)

      Infected with: Trojan.Clicker.AC

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\GLQFW9UJ\popup[1].php=>(gzip)

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\GLQFW9UJ\popup[1].php=>(gzip)

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\GLQFW9UJ\popup[1].php

      Update failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\IH5U7A5O\api_mix[1].htm

      Infected with: Generic.XPL.ADODB.5A7DD8E1

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\IH5U7A5O\api_mix[1].htm

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\IH5U7A5O\api_mix[1].htm

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\L8SBX54T\popup[1].php=>(gzip)

      Infected with: Trojan.Clicker.AC

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\L8SBX54T\popup[1].php=>(gzip)

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\L8SBX54T\popup[1].php=>(gzip)

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\L8SBX54T\popup[1].php

      Update failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\L8SBX54T\popup[2].php=>(gzip)

      Infected with: Trojan.Clicker.AC

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\L8SBX54T\popup[2].php=>(gzip)

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\L8SBX54T\popup[2].php=>(gzip)

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\L8SBX54T\popup[2].php

      Update failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\SPY7WLMV\ib15[1].dll

      Infected with: Trojan.Banker.J

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\SPY7WLMV\ib15[1].dll

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\SPY7WLMV\ib15[1].dll

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\W1M7WDMR\popup[1].php=>(gzip)

      Infected with: Trojan.Clicker.AC

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\W1M7WDMR\popup[1].php=>(gzip)

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\W1M7WDMR\popup[1].php=>(gzip)

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\W1M7WDMR\popup[1].php

      Update failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\api_mix[1].htm

      Infected with: Trojan.JS.Downloader.B

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\api_mix[1].htm

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\api_mix[1].htm

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\popup[1].php=>(gzip)

      Infected with: Trojan.Clicker.AC

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\popup[1].php=>(gzip)

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\popup[1].php=>(gzip)

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\popup[1].php

      Update failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\popup[2].php=>(gzip)

      Infected with: Trojan.Clicker.AC

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\popup[2].php=>(gzip)

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\popup[2].php=>(gzip)

      Deleted

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WF6J61AT\popup[2].php

      Update failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WRNZYCXL\s[2]

      Infected with: Trojan.JS.Obsq.C

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WRNZYCXL\s[2]

      Disinfection failed

      C:\Documents and Settings\user\Local Settings\Temporary Internet Files\Content.IE5\WRNZYCXL\s[2]

      Deleted

      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine\fil59CFC621.dat=>(gzip)

      Infected with: Trojan.QHosts.W

      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine\fil59CFC621.dat=>(gzip)

      Disinfection failed

      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine\fil59CFC621.dat=>(gzip)

      Deleted

      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine\fil59CFC621.dat

      Update failed

      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine\filB7EC36A1.dat=>(gzip)

      Infected with: Trojan.QHosts.W

      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine\filB7EC36A1.dat=>(gzip)

      Disinfection failed

      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine\filB7EC36A1.dat=>(gzip)

      Deleted

      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine\filB7EC36A1.dat

      Update failed

      C:\System Volume Information\_restore{38CB3C95-3BA9-40EF-8680-414598429104}\RP18\A0002743.exe

      Infected with: Backdoor.Agent.ABF

      C:\System Volume Information\_restore{38CB3C95-3BA9-40EF-8680-414598429104}\RP18\A0002743.exe

      Disinfection failed

      C:\System Volume Information\_restore{38CB3C95-3BA9-40EF-8680-414598429104}\RP18\A0002743.exe

      Deleted

      C:\System Volume Information\_restore{38CB3C95-3BA9-40EF-8680-414598429104}\RP18\A0003744.exe

      Infected with: Backdoor.Agent.ABF

      C:\System Volume Information\_restore{38CB3C95-3BA9-40EF-8680-414598429104}\RP18\A0003744.exe

      Disinfection failed

      C:\System Volume Information\_restore{38CB3C95-3BA9-40EF-8680-414598429104}\RP18\A0003744.exe

      Deleted

      C:\System Volume Information\_restore{38CB3C95-3BA9-40EF-8680-414598429104}\RP18\A0003864.dll

      Infected with: Trojan.Banker.J

      C:\System Volume Information\_restore{38CB3C95-3BA9-40EF-8680-414598429104}\RP18\A0003864.dll

      Disinfection failed

      C:\System Volume Information\_restore{38CB3C95-3BA9-40EF-8680-414598429104}\RP18\A0003864.dll

      Deleted

      C:\WINDOWS\smss.exe

      Infected with: Trojan.Dropper.Delf.FN

      C:\WINDOWS\smss.exe

      Disinfection failed

      C:\WINDOWS\smss.exe

      Delete failed

      C:\WINDOWS\system32\BFF43D7E.exe

      Infected with: Backdoor.Agent.ABF

      C:\WINDOWS\system32\BFF43D7E.exe

      Disinfection failed

      C:\WINDOWS\system32\BFF43D7E.exe

      Delete failed

      C:\WINDOWS\system32\drivers\etc\Hosts

      Infected with: Generic.Qhost.37E0608F

      C:\WINDOWS\system32\drivers\etc\Hosts

      Disinfection failed

      C:\WINDOWS\system32\drivers\etc\Hosts

      Deleted

      C:\WINDOWS\system32\rqrqq.dll

      Infected with: MemScan:Trojan.Vundo.AF

      C:\WINDOWS\system32\rqrqq.dll

      Disinfection failed

      C:\WINDOWS\system32\rqrqq.dll

      Delete failed

      C:\WINDOWS\system32\tuvuv.dll

      Infected with: MemScan:Trojan.Vundo.AF

      C:\WINDOWS\system32\tuvuv.dll

      Disinfection failed

      C:\WINDOWS\system32\tuvuv.dll

      Deleted

      C:\WINDOWS\system32\upxxqqkd.dll

      Infected with: Trojan.Juan.F

      C:\WINDOWS\system32\upxxqqkd.dll

      Disinfection failed

      C:\WINDOWS\system32\upxxqqkd.dll

      Delete failed

      C:\WINDOWS\system32\xovmnbwv.dll

      Infected with: Trojan.Spy.VBStat.B

      C:\WINDOWS\system32\xovmnbwv.dll

      Deleted

      C:\WINNT\dsrss.exe

      Infected with: Trojan.Proxy.VB.V

      C:\WINNT\dsrss.exe

      Disinfection failed

      C:\WINNT\dsrss.exe

      Deleted

      C:\WINNT\smss.exe

      Infected with: Trojan.Spy.Sters.AN

      C:\WINNT\smss.exe

      Disinfection failed

      C:\WINNT\smss.exe

      Deleted

      C:\WINNT\system32\ib15.dll

      Infected with: Trojan.Banker.J

      C:\WINNT\system32\ib15.dll

      Disinfection failed

      C:\WINNT\system32\ib15.dll

      Deleted

      *****************HIJACKTHIS ********************

      Logfile of HijackThis v1.99.1
      Scan saved at 4:57:37 PM, on 23/02/2007
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\WINDOWS\dsrss.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\WinRAR\WinRAR.exe
      C:\DOCUME~1\BSALAH\LOCALS~1\Temp\Rar$EX00.836\HijackThis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
      O4 - HKLM\..\Run: [Microsoft Windows Logon Process] C:\WINDOWS\winlogon.exe
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
      O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
      O23 - Service: 273856AE - Unknown owner - C:\WINDOWS\system32\273856AE.EXE (file missing)
      O23 - Service: 380E0F8C - Unknown owner - C:\WINDOWS\system32\380E0F8C.EXE (file missing)
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe

      Comment est ce que je dois proceder maintenant?
      merci infiniment.
      0
      1. Modérateur
        Salut

        as tu fais le scan avec avg ???

        suite :

        Téléchargez VundoFix.exe (par Atribune) sur ton Bureau :

        http://www.atribune.org/ccount/click.php?id=4

        *Double-clique VundoFix.exe afin de le lancer.
        * Cochez Run VundoFix as a task.
        * l'outil va se fermer et s'ouvrir à nouveau : cliquez Ok
        * Cliquez sur le bouton Scan for Vundo.
        * Lorsque le scan est complété, cliquez sur le bouton Remove Vundo.
        * Une invite vous demandera supprimer les fichiers, clique YES
        * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
        * le PC va s'éteindre ("shutdown") : clique OK
        * Démarrez votre PC à nouveau
        * Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse.

        avec un nouveau hijack stp

        @+
        0
        1. Bonjour

          veuillez trouver ci-dessous les 2 rapports:

          **************VundoFix V6.3.9**************

          Checking Java version...

          Scan started at 11:56:57 PM 24/02/2007

          Listing files found while scanning....

          VundoFix V6.3.9

          Checking Java version...

          Scan started at 9:00:21 AM 25/02/2007

          Listing files found while scanning....

          C:\WINDOWS\system32\fykasmoy.dll
          C:\WINDOWS\system32\qqrqr.bak1
          C:\WINDOWS\system32\qqrqr.bak2
          C:\WINDOWS\system32\qqrqr.ini
          C:\WINDOWS\system32\rqrqq.dll
          C:\WINDOWS\system32\upxxqqkd.dll

          Beginning removal...

          Attempting to delete C:\WINDOWS\system32\fykasmoy.dll
          C:\WINDOWS\system32\fykasmoy.dll Has been deleted!

          Attempting to delete C:\WINDOWS\system32\qqrqr.bak1
          C:\WINDOWS\system32\qqrqr.bak1 Has been deleted!

          Attempting to delete C:\WINDOWS\system32\qqrqr.bak2
          C:\WINDOWS\system32\qqrqr.bak2 Has been deleted!

          Attempting to delete C:\WINDOWS\system32\qqrqr.ini
          C:\WINDOWS\system32\qqrqr.ini Has been deleted!

          Attempting to delete C:\WINDOWS\system32\rqrqq.dll
          C:\WINDOWS\system32\rqrqq.dll Has been deleted!

          Attempting to delete C:\WINDOWS\system32\upxxqqkd.dll
          C:\WINDOWS\system32\upxxqqkd.dll Has been deleted!

          Performing Repairs to the registry.
          Done!

          *****************HijackThis v1.99.1*****************

          Logfile of HijackThis v1.99.1
          Scan saved at 11:33:07 AM, on 25/02/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\WINDOWS\dsrss.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Messenger\msmsgs.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Azureus\Azureus.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
          C:\Documents and Settings\BSALAH\Bureau\HijackThis.exe

          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
          O4 - HKLM\..\Run: [Microsoft Windows Logon Process] C:\WINDOWS\winlogon.exe
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
          O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
          O23 - Service: 273856AE - Unknown owner - C:\WINDOWS\system32\273856AE.EXE (file missing)
          O23 - Service: 380E0F8C - Unknown owner - C:\WINDOWS\system32\380E0F8C.EXE (file missing)
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
          O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe

          Je note une amelioration, il y a moin de lenteur, d'apres votre analyse des rapports, mon systeme est-t-il completement desinfecté? merci
          0
          1. Modérateur
            Salut

            fais ceci stp :

            clic droit sur l'icone de logiciel hijackthis < renommer < et nomme le CCM.exe

            ensuite reposte un nouveau hijack stp

            ++
            0
            1. salut,

              J'ai effectué l'operation exactement comme demandé et executé hijackthis (CCM.exe) . Voici le rapport:

              Logfile of HijackThis v1.99.1
              Scan saved at 12:48:28 PM, on 25/02/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\Explorer.EXE
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\WINDOWS\dsrss.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Azureus\Azureus.exe
              C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
              C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
              C:\Documents and Settings\BSALAH\Bureau\CCM.exe.exe

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
              O2 - BHO: (no name) - {51BA1D25-C93B-468B-8867-48F8E358D069} - C:\WINDOWS\system32\rqrqq.dll (file missing)
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
              O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
              O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\system32\upxxqqkd.dll (file missing)
              O2 - BHO: (no name) - {E8D45E50-FD87-4F7B-B503-40D7A40F7935} - C:\WINDOWS\system32\qomno.dll
              O2 - BHO: (no name) - {FBC5C777-BAA4-445F-9873-1C1A74364508} - C:\WINDOWS\system32\hggeecy.dll
              O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
              O4 - HKLM\..\Run: [Microsoft Windows Logon Process] C:\WINDOWS\winlogon.exe
              O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
              O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
              O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
              O20 - Winlogon Notify: hggeecy - C:\WINDOWS\SYSTEM32\hggeecy.dll
              O20 - Winlogon Notify: qomno - C:\WINDOWS\system32\qomno.dll
              O23 - Service: 273856AE - Unknown owner - C:\WINDOWS\system32\273856AE.EXE (file missing)
              O23 - Service: 380E0F8C - Unknown owner - C:\WINDOWS\system32\380E0F8C.EXE (file missing)
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
              O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
              O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe

              Merci
              a+
              0
              1. Modérateur
                re

                très bien !

                télécharge l2mfix ici:
                http://www.downloads.subratam.org/l2mfix.exe
                Double-cliquer sur l2mfix.exe pour lancer l'extraction
                Dans le dossier l2mfix, double clic sur l2mfix.bat, appuyer sur n'importe quelle touche puis choisir l'option #1 (et pas autre chose) et valider avec la touche entre.
                Le bloc note va s'ouvrir avec le résultat du scan.copie/colles le rapport ici stp

                ++
                0
                1. salut,
                  Excuse moi car je ne trouve pas l2mfix.bat dans le dossier l2mfix. peux tu stp me montrer lequel dans la liste suivante (c'est le contenu du dossier géneré apres l éxtraction du l2mfix téléchargé):

                  *regfixes (sous dossier : insciption registre)
                  *KEYPRESS (application ms dos)
                  *locate (application ms dos)
                  *pv
                  *second (fichier de commande ms dos)
                  *zip
                  *l2mfix (fichier de commande ms dos)
                  *Ntrights
                  *restart (waresoft software)
                  *strings

                  merci
                  0
                  1. Modérateur
                    celui-ci : *l2mfix (fichier de commande ms dos) ;-)
                    0
                    1. merci beaucoup, voici le rapport:

                      L2MFIX find log 051206
                      These are the registry keys present
                      **********************************************************************************
                      Winlogon/notify:
                      Windows Registry Editor Version 5.00

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                      "Asynchronous"=dword:00000000
                      "Impersonate"=dword:00000000
                      "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
                      6c,00,00,00
                      "Logoff"="ChainWlxLogoffEvent"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                      "Asynchronous"=dword:00000000
                      "Impersonate"=dword:00000000
                      "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
                      6c,00,6c,00,00,00
                      "Logoff"="CryptnetWlxLogoffEvent"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                      "DLLName"="cscdll.dll"
                      "Logon"="WinlogonLogonEvent"
                      "Logoff"="WinlogonLogoffEvent"
                      "ScreenSaver"="WinlogonScreenSaverEvent"
                      "Startup"="WinlogonStartupEvent"
                      "Shutdown"="WinlogonShutdownEvent"
                      "StartShell"="WinlogonStartShellEvent"
                      "Impersonate"=dword:00000000
                      "Asynchronous"=dword:00000001

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\hggeecy]
                      "Asynchronous"=dword:00000001
                      "DllName"="hggeecy.dll"
                      "Impersonate"=dword:00000000
                      "Logon"="Logon"
                      "Logoff"="Logoff"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomno]
                      "Asynchronous"=dword:00000001
                      "DllName"="C:\\WINDOWS\\system32\\qomno.dll"
                      "Impersonate"=dword:00000000
                      "Startup"="SysLogon"
                      "Logoff"="SysLogoff"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                      "DLLName"="wlnotify.dll"
                      "Logon"="SCardStartCertProp"
                      "Logoff"="SCardStopCertProp"
                      "Lock"="SCardSuspendCertProp"
                      "Unlock"="SCardResumeCertProp"
                      "Enabled"=dword:00000001
                      "Impersonate"=dword:00000001
                      "Asynchronous"=dword:00000001

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                      "Asynchronous"=dword:00000000
                      "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                      6c,00,6c,00,00,00
                      "Impersonate"=dword:00000000
                      "StartShell"="SchedStartShell"
                      "Logoff"="SchedEventLogOff"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                      "Logoff"="WLEventLogoff"
                      "Impersonate"=dword:00000000
                      "Asynchronous"=dword:00000001
                      "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
                      6c,00,6c,00,00,00

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                      "DLLName"="WlNotify.dll"
                      "Lock"="SensLockEvent"
                      "Logon"="SensLogonEvent"
                      "Logoff"="SensLogoffEvent"
                      "Safe"=dword:00000001
                      "MaxWait"=dword:00000258
                      "StartScreenSaver"="SensStartScreenSaverEvent"
                      "StopScreenSaver"="SensStopScreenSaverEvent"
                      "Startup"="SensStartupEvent"
                      "Shutdown"="SensShutdownEvent"
                      "StartShell"="SensStartShellEvent"
                      "PostShell"="SensPostShellEvent"
                      "Disconnect"="SensDisconnectEvent"
                      "Reconnect"="SensReconnectEvent"
                      "Unlock"="SensUnlockEvent"
                      "Impersonate"=dword:00000001
                      "Asynchronous"=dword:00000001

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                      "Asynchronous"=dword:00000000
                      "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                      6c,00,6c,00,00,00
                      "Impersonate"=dword:00000000
                      "Logoff"="TSEventLogoff"
                      "Logon"="TSEventLogon"
                      "PostShell"="TSEventPostShell"
                      "Shutdown"="TSEventShutdown"
                      "StartShell"="TSEventStartShell"
                      "Startup"="TSEventStartup"
                      "MaxWait"=dword:00000258
                      "Reconnect"="TSEventReconnect"
                      "Disconnect"="TSEventDisconnect"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                      "DLLName"="wlnotify.dll"
                      "Logon"="RegisterTicketExpiredNotificationEvent"
                      "Logoff"="UnregisterTicketExpiredNotificationEvent"
                      "Impersonate"=dword:00000001
                      "Asynchronous"=dword:00000001

                      **********************************************************************************
                      useragent:
                      Windows Registry Editor Version 5.00

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                      "SV1"=""

                      **********************************************************************************
                      Shell Extension key:
                      Windows Registry Editor Version 5.00

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                      "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
                      "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
                      "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
                      "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
                      "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                      "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
                      "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
                      "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
                      "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
                      "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
                      "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Page de compatibilit‚"
                      "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'environnement"
                      "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
                      "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'environnement pour les objets r‚seau de Microsoft Windows"
                      "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
                      "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
                      "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'environnement de compression de fichiers"
                      "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension de l'environnement d'imprimante Web"
                      "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
                      "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
                      "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
                      "{88895560-9AA2-1069-930E-00AA0030EBC8}"="Extension ic“ne HyperTerminal"
                      "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
                      "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
                      "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
                      "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'environnement pour le partage"
                      "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
                      "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
                      "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
                      "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau"
                      "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Connexions r‚seau"
                      "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="&Scanneurs et appareils photo"
                      "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="&Scanneurs et appareils photo"
                      "{905667aa-acd6-11d2-8080-00805f6596d2}"="&Scanneurs et appareils photo"
                      "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="&Scanneurs et appareils photo"
                      "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="&Scanneurs et appareils photo"
                      "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
                      "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extensions de l'interpr‚teur de commandes pour l'environnement d'ex‚cution de scripts Windows"
                      "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Liaison de donn‚es Microsoft"
                      "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
                      "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
                      "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
                      "{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
                      "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
                      "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Barre des tƒches et menu D‚marrer"
                      "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Rechercher"
                      "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                      "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Aide et support"
                      "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Ex‚cuter..."
                      "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
                      "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="Courrier ‚lectronique"
                      "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Polices"
                      "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Outils d'administration"
                      "{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Page de propri‚t‚s des versions pr‚c‚dentes"
                      "{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Versions pr‚c‚dentes"
                      "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
                      "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
                      "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
                      "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
                      "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
                      "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
                      "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
                      "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
                      "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
                      "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
                      "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
                      "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
                      "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
                      "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
                      "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
                      "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
                      "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
                      "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
                      "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
                      "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
                      "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
                      "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
                      "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
                      "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
                      "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
                      "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
                      "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
                      "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
                      "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
                      "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
                      "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
                      "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
                      "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
                      "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
                      "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
                      "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
                      "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
                      "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
                      "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
                      "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
                      "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                      "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
                      "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
                      "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
                      "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
                      "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
                      "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
                      "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
                      "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
                      "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
                      "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                      "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
                      "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
                      "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
                      "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
                      "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
                      "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
                      "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
                      "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
                      "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
                      "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
                      "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
                      "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
                      "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'applications d'environnement"
                      "{0B124F8F-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
                      "{CFCCC7A0-A282-11D1-9082-006008059382}"="Publication d'application Darwin"
                      "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
                      "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
                      "{00E7B358-F65B-4dcf-83DF-CD026B94BFD4}"="Autoplay for SlideShow"
                      "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="Extracteur de miniatures de fichier + GDI"
                      "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Gestionnaire de miniatures - Informations de r‚sum‚ (DOCFILES)"
                      "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
                      "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
                      "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Assistant Publication de sites Web"
                      "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Commande d'impressions via le Web"
                      "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Objet Assistant de publication Shell"
                      "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Assistant Obtenir une identit‚ Passport"
                      "{7A9D77BD-5403-11d2-8785-2E0420524153}"="Comptes d'utilisateurs"
                      "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
                      "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
                      "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
                      "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
                      "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
                      "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
                      "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
                      "{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
                      "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
                      "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
                      "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
                      "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
                      "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
                      "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
                      "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
                      "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
                      "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
                      "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
                      "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
                      "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
                      "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
                      "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
                      "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
                      "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
                      "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
                      "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
                      "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
                      "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
                      "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
                      "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
                      "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
                      "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
                      "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
                      "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
                      "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
                      "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
                      "{472083B0-C522-11CF-8763-00608CC02F24}"="avast"
                      "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
                      "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
                      "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
                      "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"

                      **********************************************************************************
                      HKEY ROOT CLASSIDS:
                      **********************************************************************************
                      Files Found are not all bad files:

                      C:\WINDOWS\SYSTEM32\
                      hggeecy.dll Fri 2007-02-23 3:28:22 ..... 26 637 26,01 K
                      pncrt.dll Tue 2007-02-20 23:58:20 A.... 278 528 272,00 K
                      pndx5016.dll Tue 2007-02-20 23:58:26 A.... 6 656 6,50 K
                      pndx5032.dll Tue 2007-02-20 23:58:26 A.... 5 632 5,50 K
                      qomno.dll Sun 2007-02-25 9:18:40 ..SH. 281 652 275,05 K
                      rmoc3260.dll Tue 2007-02-20 23:59:32 A.... 185 952 181,59 K

                      6 items found: 6 files (1 H/S), 0 directories.
                      Total of file sizes: 785 057 bytes 766,66 K
                      Locate .tmp files:

                      C:\WINDOWS\SYSTEM32\
                      onmoq.tmp Sun 2007-02-25 14:09:12 A.... 0 0,00 K

                      1 item found: 1 file, 0 directories.
                      Total of file sizes: 0 bytes 0,00 K
                      **********************************************************************************
                      Directory Listing of system files:
                      Le volume dans le lecteur C n'a pas de nom.
                      Le num‚ro de s‚rie du volume est 1CB6-2FA2

                      R‚pertoire de C:\WINDOWS\System32

                      25/02/2007 02:09 PM 788,805 onmoq.ini
                      25/02/2007 09:19 AM 761,573 onmoq.bak1
                      25/02/2007 09:18 AM 281,652 qomno.dll
                      26/01/2007 12:20 AM <REP> Microsoft
                      05/02/2002 03:29 AM 353 vuvut.ini
                      05/02/2002 03:29 AM <REP> dllcache
                      05/02/2002 03:29 AM 26,637 awtqool.dll
                      5 fichier(s) 1,859,020 octets
                      2 R‚p(s) 13,237,653,504 octets libres
                      0
                      1. Modérateur
                        très bien , cette fois ci passe à l'option 2 et poste la rapport ainsi qu'un nouveau hijack stp

                        @+
                        0
                        1. les voila:

                          *************L2mfix 051206*************
                          Creating Account.
                          La commande s'est termin‚e correctement.

                          Adding Administrative privleges.
                          Checking for L2MFix account(0=no 1=yes):
                          1
                          Granting SeDebugPrivilege to L2MFIX ... successful

                          Running From:
                          C:\WINDOWS\system32

                          Killing Processes!
                          Killing 'smss.exe'
                          \SystemRoot\System32\smss.exe (336)
                          Killing 'winlogon.exe'
                          winlogon.exe (420)
                          Killing 'explorer.exe'
                          C:\WINDOWS\Explorer.EXE (1340)
                          Killing 'rundll32.exe'
                          Restoring Sedebugprivilege:
                          Granting SeDebugPrivilege to Administrateurs ... successful

                          Scanning First Pass. Please Wait!

                          First Pass Completed

                          Second Pass Scanning

                          Second pass Completed!

                          Restoring Windows Update Certificates.:

                          The following Is the Current Export of the Winlogon notify key:
                          ****************************************************************************
                          Windows Registry Editor Version 5.00

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
                          "Asynchronous"=dword:00000000
                          "Impersonate"=dword:00000000
                          "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
                          6c,00,00,00
                          "Logoff"="ChainWlxLogoffEvent"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
                          "Asynchronous"=dword:00000000
                          "Impersonate"=dword:00000000
                          "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
                          6c,00,6c,00,00,00
                          "Logoff"="CryptnetWlxLogoffEvent"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
                          "DLLName"="cscdll.dll"
                          "Logon"="WinlogonLogonEvent"
                          "Logoff"="WinlogonLogoffEvent"
                          "ScreenSaver"="WinlogonScreenSaverEvent"
                          "Startup"="WinlogonStartupEvent"
                          "Shutdown"="WinlogonShutdownEvent"
                          "StartShell"="WinlogonStartShellEvent"
                          "Impersonate"=dword:00000000
                          "Asynchronous"=dword:00000001

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\hggeecy]
                          "Asynchronous"=dword:00000001
                          "DllName"="hggeecy.dll"
                          "Impersonate"=dword:00000000
                          "Logon"="Logon"
                          "Logoff"="Logoff"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\qomno]
                          "Asynchronous"=dword:00000001
                          "DllName"="C:\\WINDOWS\\system32\\qomno.dll"
                          "Impersonate"=dword:00000000
                          "Startup"="SysLogon"
                          "Logoff"="SysLogoff"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
                          "DLLName"="wlnotify.dll"
                          "Logon"="SCardStartCertProp"
                          "Logoff"="SCardStopCertProp"
                          "Lock"="SCardSuspendCertProp"
                          "Unlock"="SCardResumeCertProp"
                          "Enabled"=dword:00000001
                          "Impersonate"=dword:00000001
                          "Asynchronous"=dword:00000001

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
                          "Asynchronous"=dword:00000000
                          "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                          6c,00,6c,00,00,00
                          "Impersonate"=dword:00000000
                          "StartShell"="SchedStartShell"
                          "Logoff"="SchedEventLogOff"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
                          "Logoff"="WLEventLogoff"
                          "Impersonate"=dword:00000000
                          "Asynchronous"=dword:00000001
                          "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
                          6c,00,6c,00,00,00

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
                          "DLLName"="WlNotify.dll"
                          "Lock"="SensLockEvent"
                          "Logon"="SensLogonEvent"
                          "Logoff"="SensLogoffEvent"
                          "Safe"=dword:00000001
                          "MaxWait"=dword:00000258
                          "StartScreenSaver"="SensStartScreenSaverEvent"
                          "StopScreenSaver"="SensStopScreenSaverEvent"
                          "Startup"="SensStartupEvent"
                          "Shutdown"="SensShutdownEvent"
                          "StartShell"="SensStartShellEvent"
                          "PostShell"="SensPostShellEvent"
                          "Disconnect"="SensDisconnectEvent"
                          "Reconnect"="SensReconnectEvent"
                          "Unlock"="SensUnlockEvent"
                          "Impersonate"=dword:00000001
                          "Asynchronous"=dword:00000001

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
                          "Asynchronous"=dword:00000000
                          "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
                          6c,00,6c,00,00,00
                          "Impersonate"=dword:00000000
                          "Logoff"="TSEventLogoff"
                          "Logon"="TSEventLogon"
                          "PostShell"="TSEventPostShell"
                          "Shutdown"="TSEventShutdown"
                          "StartShell"="TSEventStartShell"
                          "Startup"="TSEventStartup"
                          "MaxWait"=dword:00000258
                          "Reconnect"="TSEventReconnect"
                          "Disconnect"="TSEventDisconnect"

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
                          "DLLName"="wlnotify.dll"
                          "Logon"="RegisterTicketExpiredNotificationEvent"
                          "Logoff"="UnregisterTicketExpiredNotificationEvent"
                          "Impersonate"=dword:00000001
                          "Asynchronous"=dword:00000001

                          The following are the files found:
                          ****************************************************************************

                          Registry Entries that were Deleted:
                          Please verify that the listing looks ok.
                          If there was something deleted wrongly there are backups in the backreg folder.
                          ****************************************************************************
                          REGEDIT4

                          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
                          REGEDIT4

                          [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
                          "SV1"=""
                          ****************************************************************************
                          Desktop.ini Contents:
                          ****************************************************************************

                          ****************************************************************************
                          Checking for L2MFix account(0=no 1=yes):
                          0
                          Zipping up files for submission:
                          zip warning: name not matched: dlls\*.*

                          zip error: Nothing to do! (backup.zip)
                          adding: backregs/notibac.reg (164 bytes security) (deflated 88%)
                          adding: backregs/shell.reg (164 bytes security) (deflated 73%)

                          *************HijackThis *************

                          Logfile of HijackThis v1.99.1
                          Scan saved at 2:25:20 PM, on 25/02/2007
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\system32\notepad.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\WINDOWS\dsrss.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\wuauclt.exe
                          C:\WINDOWS\system32\NOTEPAD.EXE
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Documents and Settings\BSALAH\Bureau\CCM.exe.exe

                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                          O2 - BHO: (no name) - {0500AE87-BE4A-4748-9596-9C944F478AAD} - C:\WINDOWS\system32\qomno.dll
                          O2 - BHO: (no name) - {51BA1D25-C93B-468B-8867-48F8E358D069} - C:\WINDOWS\system32\rqrqq.dll (file missing)
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                          O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
                          O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\system32\upxxqqkd.dll (file missing)
                          O2 - BHO: (no name) - {FBC5C777-BAA4-445F-9873-1C1A74364508} - C:\WINDOWS\system32\hggeecy.dll (file missing)
                          O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
                          O4 - HKLM\..\Run: [Microsoft Windows Logon Process] C:\WINDOWS\winlogon.exe
                          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
                          O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                          O20 - Winlogon Notify: hggeecy - hggeecy.dll (file missing)
                          O20 - Winlogon Notify: qomno - C:\WINDOWS\system32\qomno.dll
                          O23 - Service: 273856AE - Unknown owner - C:\WINDOWS\system32\273856AE.EXE (file missing)
                          O23 - Service: 380E0F8C - Unknown owner - C:\WINDOWS\system32\380E0F8C.EXE (file missing)
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                          O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe

                          merci
                          0
                          1. Modérateur
                            bien :

                            Télécharge SDFix sur ton bureau

                            http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

                            Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
                            Redémarre ton ordinateur en mode sans échec
                            Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur RunThis.bat pour lancer le script.
                            Appuie sur Y pour commencer le processus de nettoyage.
                            Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                            Appuie sur une touche pour redémarrer le PC.
                            Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                            Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                            Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                            Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                            Enfin, copie/colle le contenu du fic

                            ++
                            0
                            1. oops, j'ai effectué la demarche que tu m'as decrite mais j'ai commis une erreur (je pense) car j'ai arreté l'ordinateur pour le redemarrer en mode normal sans que le processus prenne fin (en fait, la suite a été effectuée en mode normal), dois je refaire l'operation? merci infiniment

                              SDFix: Version 1.68

                              Run by BSALAH - 25/02/2007 @ 14:51:22.55

                              Microsoft Windows XP [version 5.1.2600]

                              Running From: C:\Documents and Settings\BSALAH\Bureau\SDFix

                              Safe Mode:
                              Checking Services:

                              Name:

                              Path:

                              Restoring Windows Registry Entries
                              Restoring Default Hosts File

                              Rebooting...

                              Normal Mode:
                              Checking Files:

                              Below files will be copied to Backups folder then removed:

                              C:\WINDOWS\dsrss.exe - Deleted

                              ADS Check:

                              C:\WINDOWS\system32
                              No streams found.

                              Final Check:

                              Remaining Services:
                              ------------------

                              Remaining Files:
                              ---------------

                              Backups Folder: - C:\DOCUME~1\BSALAH\Bureau\SDFix\backups\backups.zip

                              Checking For Files with Hidden Attributes :

                              C:\WINDOWS\system32\awtqool.dll
                              C:\WINDOWS\system32\qomno.dll
                              C:\Documents and Settings\user\Local Settings\Temp\6106700\BIT12.tmp
                              C:\WINDOWS\system32\onmoq.tmp

                              Add/Remove Programs List:

                              avast! Antivirus
                              AVG Anti-Spyware 7.5
                              Azureus
                              CCleaner (remove only)
                              DVD Shrink 3.2
                              ffdshow [rev 610] [2006-12-01]
                              HijackThis 1.99.1
                              Media Player Classic fr
                              Mozilla Firefox (2.0.0.1)
                              Nero OEM
                              Nero Suite
                              Nero Digital
                              Nero Media Player
                              RealPlayer
                              Adobe Flash Player 9
                              VideoLAN VLC media player 0.8.6a
                              Lecteur Windows Mediaÿ10
                              WinRAR archiver
                              Yahoo! Toolbar
                              Yahoo! Toolbar
                              Google Toolbar for Internet Explorer
                              Rhapsody Player Engine
                              J2SE Runtime Environment 5.0 Update 10
                              LightScribe 1.4.42.1

                              Finished
                              0
                              1. Modérateur
                                re

                                c'est ok !

                                poste un new hijack stp, et precise l'evolution de la situation stp

                                ++
                                0
                                1. Merci infiniment green day. Vous m'avez vraiment rendu un énorme service en me debarassant de ce cauchemar, le systeme maintenant est plus rapide, stable et je n'ai plus d'alertes me disant que mon pc est infecté de virus, spyware, adware ...etc. Commentcamarche.net ca marche vraiment tres tres bien.

                                  Logfile of HijackThis v1.99.1
                                  Scan saved at 3:34:10 PM, on 25/02/2007
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
                                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Messenger\msmsgs.exe
                                  C:\Program Files\Mozilla Firefox\firefox.exe
                                  C:\Program Files\Java\jre1.5.0_10\bin\jucheck.exe
                                  C:\Program Files\Media Player Classic\mplayerc.exe
                                  C:\Documents and Settings\BSALAH\Bureau\CCM.exe.exe

                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                  O2 - BHO: (no name) - {1826B2C4-FB71-4BA9-A029-8D1E8085AE78} - C:\WINDOWS\system32\qomno.dll
                                  O2 - BHO: (no name) - {51BA1D25-C93B-468B-8867-48F8E358D069} - C:\WINDOWS\system32\rqrqq.dll (file missing)
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                                  O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
                                  O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\system32\upxxqqkd.dll (file missing)
                                  O2 - BHO: (no name) - {FBC5C777-BAA4-445F-9873-1C1A74364508} - C:\WINDOWS\system32\hggeecy.dll (file missing)
                                  O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
                                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                  O4 - HKLM\..\Run: [WinSysModule] dsrss.exe
                                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                  O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
                                  O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
                                  O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
                                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                  O20 - Winlogon Notify: hggeecy - hggeecy.dll (file missing)
                                  O20 - Winlogon Notify: qomno - C:\WINDOWS\system32\qomno.dll
                                  O23 - Service: 273856AE - Unknown owner - C:\WINDOWS\system32\273856AE.EXE (file missing)
                                  O23 - Service: 380E0F8C - Unknown owner - C:\WINDOWS\system32\380E0F8C.EXE (file missing)
                                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                  O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                  O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe

                                  Merci pour votre aide et assistance j'en suis tres reconnaissant.
                                  salutations.
                                  0
                                  1. Modérateur
                                    super ! :-)

                                    # Désactiver la Restauration du système

                                    * Cliquez sur le bouton Démarrer.
                                    * Cliquez avec le bouton droit de la souris sur Poste de travail puis cliquez sur Propriétés.
                                    * Dans l'onglet Restauration du système, sélectionnez l'option Désactiver la Restauration du système ou Désactiver la Restauration du système sur tous les lecteurs

                                    ( tu pourras la réactivé à la fin de la manip )

                                    dernier détail :

                                    Relance HijackThis : choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked" :

                                    O2 - BHO: (no name) - {1826B2C4-FB71-4BA9-A029-8D1E8085AE78} - C:\WINDOWS\system32\qomno.dll
                                    O2 - BHO: (no name) - {51BA1D25-C93B-468B-8867-48F8E358D069} - C:\WINDOWS\system32\rqrqq.dll (file missing)

                                    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
                                    O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\system32\upxxqqkd.dll (file missing)
                                    O2 - BHO: (no name) - {FBC5C777-BAA4-445F-9873-1C1A74364508} - C:\WINDOWS\system32\hggeecy.dll (file missing)
                                    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)

                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                    O4 - HKLM\..\Run: [WinSysModule] dsrss.exe

                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

                                    O20 - Winlogon Notify: hggeecy - hggeecy.dll (file missing)
                                    O20 - Winlogon Notify: qomno - C:\WINDOWS\system32\qomno.dll

                                    O23 - Service: 273856AE - Unknown owner - C:\WINDOWS\system32\273856AE.EXE (file missing)
                                    O23 - Service: 380E0F8C - Unknown owner - C:\WINDOWS\system32\380E0F8C.EXE (file missing)

                                    ensuite :

                                    # Affiche les dossiers système et fichiers cachés :
                                    Ouvrir le poste de travail :
                                    - Outils --> Options des dossiers
                                    - Affichage --> zone Paramètres avancés
                                    - Cocher : Afficher le contenu des dossiers système
                                    - Cocher : Afficher les fichiers et dossiers cachés
                                    - Décocher : Masquer les extensions des fichiers dont le type est connu
                                    - Décocher : Masquer les fichiers protégés du système d'exploitation (recommandé)
                                    répondre Oui au message
                                    Clique sur "Appliquer à tous les dossiers"
                                    Clique sur OK

                                    Télécharge Killbox sur ton Bureau :

                                    http://www.downloads.subratam.org/KillBox.exe

                                    Double-clique killbox.exe.

                                    Copie le texte gras ci-bas (sélectionne tout avec ta souris, clic-droit et "Copier") :

                                    C:\WINDOWS\system32\qomno.dll
                                    C:\WINDOWS\system32\rqrqq.dll
                                    C:\WINDOWS\system32\upxxqqkd.dll
                                    C:\WINDOWS\system32\hggeecy.dll
                                    C:\WINDOWS\system32\qomno.dll
                                    C:\WINDOWS\system32\273856AE.EXE
                                    C:\WINDOWS\system32\380E0F8C.EXE


                                    * Sélectionnz "delete on reboot"
                                    * Cliquez sur le menu "File" -> "Past from clip board"
                                    * Cliquez sur All Files
                                    * Cliquez sur la croix rouge et et blanche
                                    * Répondez yes et laisse redémarrer ton pc.
                                    *poste un nouveau blacklight

                                    cf démo : http://mickael.barroux.free.fr/securite/killbox.html

                                    ensuite repasse un coup de ccleaner + cleanup :

                                    * CleanUp40 (qui élimine les fichiers temporaires + cookies : gratuit )
                                    http://pageperso.aol.fr/Balltrap34/CleanUp40.exe

                                    tuto : (merci à Balltrap) http://pageperso.aol.fr/balltrap34/democleanup.htm

                                    installe un parefeu !!!

                                    kerio

                                    tuto : pour configurer et comprendre Kerio
                                    https://www.vulgarisation-informatique.com/kerio.php
                                    http://kerio.probb.fr/Systemesd-exploitation-c1/Logiciels-et-tutoriels-gratuits-tries-par-categorie-f6/Tutoriel-pour-Kerio-4-version-gratuite-t201.htm

                                    et reposte un nouveau hijack pour controler !

                                    @+

                                    La sagesse, c'est d'avoir des rêves suffisamment grands pour ne pas les
                                    perdre de vue lorsqu'on les poursuit. (Oscar Wilde)
                                    0
                                    1. salut

                                      je viens de realiser les manip decrites, la seule difficulté que j'ai rencontrée est qu'il n'etait pas possible de supprimer le fichier C:\WINDOWS\system32\qomno.dll , en fait apres avoir cliqué sur la croix rouge et blanche j'ai recu le message suivant : PendingFileRenameOperations Registry Data has been removed by external process!

                                      voici le rapport :

                                      Logfile of HijackThis v1.99.1
                                      Scan saved at 5:27:10 PM, on 25/02/2007
                                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                                      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
                                      C:\Program Files\Mozilla Firefox\firefox.exe
                                      C:\Documents and Settings\BSALAH\Bureau\CCM.exe.exe

                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.files-ftp.com/~unicorni/phpBB2/index.php
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                                      O2 - BHO: (no name) - {7B05F161-FA52-4F23-8FEE-98B317142BBE} - C:\WINDOWS\system32\qomno.dll
                                      O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\system32\yjwpyrnj.dll
                                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
                                      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                      O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
                                      O14 - IERESET.INF: START_PAGE_URL=http://www.files-ftp.com/~unicorni/phpBB2/index.php
                                      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                      O20 - Winlogon Notify: qomno - C:\WINDOWS\system32\qomno.dll
                                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe

                                      a+
                                      0
                                      • 1
                                      • 2