[Trojan] Infecté par Backdoor.Trojan!! :(

Résolu
Salut!

Ca fais maintenant 1 semaine que Norton m'alerte :

Object Name C:\WINDOWS\System32\aqrubygi.dll
Virus Name Backdoor.Trojan
Action Taken Unable to repair this file.

J'ai essayé plusieurs programmes dont ad-aware, counterspy, AVG, registry mechanic, etc. J'ai aussi téléchargé HighJackThis mais je ne sais évidemment pas quoi faire avec ca... :P

Si y'a un bon samaritain qui s'y connait dans le coin.. aide moi s.v.p!!
Configuration: Windows XP
Internet Explorer 6.0

47 réponses

Résumé de la discussion

Une alerte antivirus signale la présence d'un backdoor Trojan dans le fichier C:\WINDOWS\System32\aqrubygi.dll et des difficultés à réparer ce fichier sous Windows XP avec plusieurs outils. Plusieurs solutions proposées incluent SmitfraudFix, HijackThis et KillBox pour nettoyer les clés de registre et les DLL malveillantes, avec des rapports générés et des étapes à suivre. Des échanges détaillent les difficultés, notamment des fichiers protégés et des messages PendingFileRenameOperations, et recommandent de relancer les outils, de vérifier les processus et de déconnecter puis nettoyer le système. En outre, certains conseils évoquent l'importance de vérifier le navigateur et les extensions et d'empêcher les démarrages non souhaités pour éviter les réinfections.

Bobot (l’IA à votre service)
  1. Modérateur
    Salut

    Télécharge ceci sur ton bureau :

    Lien : hijackthis

    Démo : http://pageperso.aol.fr/balltrap34/demohijack.htm

    Choisir l'option "do a scan and a logfile", et faire un copier/coller du rapport ainsi générer sur le forum.

    ++
    0
    1. Salut et merci :) Voici le logfile:

      Logfile of HijackThis v1.99.1
      Scan saved at 14:50:44, on 2007-03-02
      Platform: Windows XP SP1 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      C:\Program Files\Common Files\Symantec Shared\ccApp.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
      C:\WINDOWS\System32\CTsvcCDA.exe
      C:\Program Files\Norton AntiVirus\navapsvc.exe
      C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\WINDOWS\System32\HPZipm12.exe
      C:\WINDOWS\explorer.exe
      C:\Program Files\iTunes\iTunes.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Documents and Settings\Owner\Desktop\Lo\hijackthis_199\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/saint-lin-laurentides
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: (no name) - {6EDF07CD-9F74-42E8-ABD9-4EDEEBB78656} - C:\WINDOWS\system32\eabaeab.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
      O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
      O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
      O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
      O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
      O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
      O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: hp psc 1000 series.lnk = ?
      O4 - Global Startup: hpoddt01.exe.lnk = ?
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://www.gamespy.com
      O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
      O20 - Winlogon Notify: urnwygvs - C:\WINDOWS\SYSTEM32\eabaeab.dll
      O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
      O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
      O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
      O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
      O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
      O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
      O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
      O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
      O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
      O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
      0
      1. Modérateur
        re

        # Télécharge ceci: (merci a S!RI pour ce petit programme).

        http://siri.urz.free.fr/Fix/SmitfraudFix.zip

        Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1,
        voila a quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php
        il va générer un rapport : copie/colle le sur le poste stp.

        ++
        0
        1. Voici le rapport (je pense):

          Scan done at 15:42:53,06, 2007-03-02
          Run from C:\Documents and Settings\Owner\Desktop\Lo\SmitfraudFix
          OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
          The filesystem type is NTFS
          Fix run in normal mode

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
          "Source"="About:Home"
          "SubscribedURL"="About:Home"
          "FriendlyName"="My Current Home Page"

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32

          »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection

          »»»»»»»»»»»»»»»»»»»»»»»» End
          0
          1. Modérateur
            oui, c'est ça ;-)

            télécharge l2mfix ici:
            http://www.downloads.subratam.org/l2mfix.exe
            Double-cliquer sur l2mfix.exe pour lancer l'extraction
            Dans le dossier l2mfix, double clic sur l2mfix.bat, appuyer sur n'importe quelle touche puis choisir l'option #1 (et pas autre chose) et valider avec la touche entre.
            Le bloc note va s'ouvrir avec le rsultat du scan.copie/colles le rapport ici

            ++
            0
            1. Voila! :D ensuite?

              L2MFIX find log 051206
              These are the registry keys present
              **********************************************************************************
              Winlogon/notify:
              Windows Registry Editor Version 5.00

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
              "Asynchronous"=dword:00000000
              "Impersonate"=dword:00000000
              "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
              6c,00,00,00
              "Logoff"="ChainWlxLogoffEvent"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
              "Asynchronous"=dword:00000000
              "Impersonate"=dword:00000000
              "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
              6c,00,6c,00,00,00
              "Logoff"="CryptnetWlxLogoffEvent"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
              "DLLName"="cscdll.dll"
              "Logon"="WinlogonLogonEvent"
              "Logoff"="WinlogonLogoffEvent"
              "ScreenSaver"="WinlogonScreenSaverEvent"
              "Startup"="WinlogonStartupEvent"
              "Shutdown"="WinlogonShutdownEvent"
              "StartShell"="WinlogonStartShellEvent"
              "Impersonate"=dword:00000000
              "Asynchronous"=dword:00000001

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
              @=""
              "DLLName"="igfxsrvc.dll"
              "Asynchronous"=dword:00000001
              "Impersonate"=dword:00000001
              "Unlock"="WinlogonUnlockEvent"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
              "DLLName"="wlnotify.dll"
              "Logon"="SCardStartCertProp"
              "Logoff"="SCardStopCertProp"
              "Lock"="SCardSuspendCertProp"
              "Unlock"="SCardResumeCertProp"
              "Enabled"=dword:00000001
              "Impersonate"=dword:00000001
              "Asynchronous"=dword:00000001

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Schedule]
              "Asynchronous"=dword:00000000
              "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
              6c,00,6c,00,00,00
              "Impersonate"=dword:00000000
              "StartShell"="SchedStartShell"
              "Logoff"="SchedEventLogOff"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
              "Logoff"="WLEventLogoff"
              "Impersonate"=dword:00000000
              "Asynchronous"=dword:00000001
              "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
              6c,00,6c,00,00,00

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
              "DLLName"="WlNotify.dll"
              "Lock"="SensLockEvent"
              "Logon"="SensLogonEvent"
              "Logoff"="SensLogoffEvent"
              "Safe"=dword:00000001
              "MaxWait"=dword:00000258
              "StartScreenSaver"="SensStartScreenSaverEvent"
              "StopScreenSaver"="SensStopScreenSaverEvent"
              "Startup"="SensStartupEvent"
              "Shutdown"="SensShutdownEvent"
              "StartShell"="SensStartShellEvent"
              "PostShell"="SensPostShellEvent"
              "Disconnect"="SensDisconnectEvent"
              "Reconnect"="SensReconnectEvent"
              "Unlock"="SensUnlockEvent"
              "Impersonate"=dword:00000001
              "Asynchronous"=dword:00000001

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\termsrv]
              "Asynchronous"=dword:00000000
              "DllName"=hex(2):77,00,6c,00,6e,00,6f,00,74,00,69,00,66,00,79,00,2e,00,64,00,\
              6c,00,6c,00,00,00
              "Impersonate"=dword:00000000
              "Logoff"="TSEventLogoff"
              "Logon"="TSEventLogon"
              "PostShell"="TSEventPostShell"
              "Shutdown"="TSEventShutdown"
              "StartShell"="TSEventStartShell"
              "Startup"="TSEventStartup"
              "MaxWait"=dword:00000258
              "Reconnect"="TSEventReconnect"
              "Disconnect"="TSEventDisconnect"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\urnwygvs]
              "Asynchronous"=dword:00000000
              "Impersonate"=dword:00000000
              "DLLName"="eabaeab.dll"
              "Logoff"="WLEventStop"
              "Logon"="WLEventStart"

              [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wlballoon]
              "DLLName"="wlnotify.dll"
              "Logon"="RegisterTicketExpiredNotificationEvent"
              "Logoff"="UnregisterTicketExpiredNotificationEvent"
              "Impersonate"=dword:00000001
              "Asynchronous"=dword:00000001

              **********************************************************************************
              useragent:
              Windows Registry Editor Version 5.00

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]

              **********************************************************************************
              Shell Extension key:
              Windows Registry Editor Version 5.00

              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
              "{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
              "{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
              "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
              "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
              "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
              "{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
              "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
              "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
              "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
              "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
              "{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
              "{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
              "{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
              "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
              "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
              "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
              "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
              "{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
              "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
              "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
              "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
              "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
              "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
              "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
              "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
              "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
              "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
              "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
              "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
              "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
              "{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
              "{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
              "{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
              "{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
              "{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
              "{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
              "{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
              "{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
              "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
              "{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
              "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
              "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
              "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
              "{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
              "{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
              "{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
              "{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
              "{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run..."
              "{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
              "{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
              "{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
              "{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
              "{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
              "{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
              "{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
              "{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
              "{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
              "{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
              "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
              "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
              "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
              "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
              "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
              "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
              "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
              "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
              "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
              "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
              "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
              "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
              "{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
              "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
              "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
              "{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
              "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
              "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
              "{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
              "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
              "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
              "{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
              "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
              "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
              "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
              "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
              "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
              "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
              "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
              "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
              "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
              "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
              "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
              "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
              "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
              "{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
              "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
              "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
              "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
              "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
              "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
              "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
              "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
              "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
              "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
              "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
              "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
              "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
              "{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
              "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
              "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
              "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
              "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
              "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
              "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
              "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
              "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
              "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
              "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
              "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
              "{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
              "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
              "{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
              "{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
              "{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
              "{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
              "{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
              "{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
              "{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
              "{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
              "{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
              "{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
              "{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
              "{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
              "{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
              "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
              "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
              "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
              "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
              "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
              "{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
              "{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
              "{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
              "{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
              "{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
              "{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
              "{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
              "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
              "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
              "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
              "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
              "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
              "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
              "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
              "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
              "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
              "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
              "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
              "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
              "{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
              "{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
              "{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
              "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
              "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
              "{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People..."
              "{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
              "{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
              "{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
              "{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
              "{400CFEE2-39D0-46DC-96DF-E0BB5A4324B3}"="My Logitech Pictures"
              "{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
              "{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
              "{8FF88D21-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.2 Context Menu Shell Extension"
              "{8FF88D25-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.2 DragDrop Shell Extension"
              "{8FF88D27-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.2 Context Menu Shell Extension"
              "{8FF88D23-7BD0-11D1-BFB7-00AA00262A11}"="WinAce Archiver 2.2 Property Sheet Shell Extension"

              **********************************************************************************
              HKEY ROOT CLASSIDS:
              **********************************************************************************
              Files Found are not all bad files:

              C:\WINDOWS\SYSTEM32\
              aqrubygi.dll Sat Feb 3 2007 12:36:10p ..... 38,912 38.00 K
              auteabvk.dll Fri Mar 2 2007 11:29:14a A.... 111,616 109.00 K
              eabaeab.dll Tue Feb 27 2007 4:47:48p A.... 76,800 75.00 K
              idhvhri.dll Fri Dec 29 2006 6:47:00p A.... 61 0.06 K
              wrlogo~1.dll Thu Jan 25 2007 10:00:18p A.... 233,024 227.56 K

              5 items found: 5 files, 0 directories.
              Total of file sizes: 460,413 bytes 449.62 K
              Locate .tmp files:

              No matches found.
              **********************************************************************************
              Directory Listing of system files:
              Volume in drive C has no label.
              Volume Serial Number is 002D-80D6

              Directory of C:\WINDOWS\System32

              2007-03-02 15:53 <DIR> ..
              2007-03-02 15:53 <DIR> .
              2006-11-11 13:10 <DIR> dllcache
              2006-05-16 19:20 <DIR> Microsoft
              0 File(s) 0 bytes
              4 Dir(s) 16ÿ675ÿ627ÿ008 bytes free
              0
          2. Modérateur
            Suite !

            Télécharge Blacklight (de F-Secure) :

            https://europe.f-secure.com/exclude/blacklight/index.shtml

            et sauvegarde le sur ton Bureau.

            Double-clique blbeta.exe et accepte la licence ;clique Scan puis Next

            Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

            Copie et colle le contenu de ce rapport dans ta prochaine réponse

            ++
            0
            1. No hidden items found. :S
              Je t'envoie quand meme le texte:

              03/02/07 16:03:55 [Info]: BlackLight Engine 1.0.55 initialized
              03/02/07 16:03:55 [Info]: OS: 5.1 build 2600 (Service Pack 1)
              03/02/07 16:03:55 [Note]: 7019 4
              03/02/07 16:03:55 [Note]: 7005 0
              03/02/07 16:03:57 [Note]: 7006 0
              03/02/07 16:03:57 [Note]: 7011 3072
              03/02/07 16:03:57 [Note]: 7026 0
              03/02/07 16:03:58 [Note]: 7026 0
              03/02/07 16:04:01 [Note]: FSRAW library version 1.7.1021
              0
          3. Modérateur
            c'est plutôt une bonne chose qu'il n'est rien trouvé ;-)

            fais les manips de ce lien stp :

            virus methode preliminaire de desinfection version fr

            ++
            0
            1. Il faut que je parte au travail :(
              Je reviens ce soir et demain matin si tu n'est pas la!
              Merci bcp encore, a+
              0
              1. De retour!
                Je suis en train de faire la marche à suivre et ccleaner ma auté env. 400mb! Je viens de finir AVG : il n'a rien trouvé. Mais j'avais fait un scan avant-hier :

                C:\WINDOWS\Downloaded Program Files\gsda.dll -> Not-A-Virus.Downloader.Win32.SpyGame : Ignored.
                C:\Documents and Settings\Owner\Cookies\owner@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
                C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
                C:\Documents and Settings\Owner\Cookies\owner@com[1].txt -> TrackingCookie.Com : Cleaned.
                C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
                C:\WINDOWS\system32\sdwdaaaa.exe -> Trojan.BHO.u : Cleaned with backup (quarantined).

                J'envoie le reste dans pas long..
                0
                1. Apres 1 heure d'attente, voici le log de BitDefender :

                  Scanned File
                  Status

                  C:\Documents and Settings\Owner\Desktop\l2mfix.exe
                  Infected with: Trojan.Shutdown.Q

                  C:\Documents and Settings\Owner\Desktop\l2mfix.exe
                  Disinfection failed

                  C:\Documents and Settings\Owner\Desktop\l2mfix.exe
                  Deleted

                  C:\Program Files\Norton AntiVirus\Quarantine\0C734402.dll=>(Quarantine-2)
                  Infected with: Trojan.Proxy.Delf.BQ

                  C:\Program Files\Norton AntiVirus\Quarantine\0C734402.dll=>(Quarantine-2)
                  Disinfection failed

                  C:\Program Files\Norton AntiVirus\Quarantine\0C734402.dll=>(Quarantine-2)
                  Deleted

                  C:\Program Files\Norton AntiVirus\Quarantine\20A86806.dll=>(Quarantine-2)
                  Infected with: Trojan.Proxy.Delf.BQ

                  C:\Program Files\Norton AntiVirus\Quarantine\20A86806.dll=>(Quarantine-2)
                  Disinfection failed

                  C:\Program Files\Norton AntiVirus\Quarantine\20A86806.dll=>(Quarantine-2)
                  Deleted

                  C:\Program Files\Norton AntiVirus\Quarantine\39A75B0A.exe=>(Quarantine-2)
                  Infected with: Worm.Vb.AN

                  C:\Program Files\Norton AntiVirus\Quarantine\39A75B0A.exe=>(Quarantine-2)
                  Disinfection failed

                  C:\Program Files\Norton AntiVirus\Quarantine\39A75B0A.exe=>(Quarantine-2)
                  Deleted

                  C:\Program Files\Norton AntiVirus\Quarantine\39AA0506.tmp=>(Quarantine-2)
                  Infected with: Worm.Vb.AN

                  C:\Program Files\Norton AntiVirus\Quarantine\39AA0506.tmp=>(Quarantine-2)
                  Disinfection failed

                  C:\Program Files\Norton AntiVirus\Quarantine\39AA0506.tmp=>(Quarantine-2)
                  Deleted

                  C:\Program Files\Norton AntiVirus\Quarantine\3E5C5FDC.exe=>(Quarantine-2)
                  Infected with: Worm.Vb.AN

                  C:\Program Files\Norton AntiVirus\Quarantine\3E5C5FDC.exe=>(Quarantine-2)
                  Disinfection failed

                  C:\Program Files\Norton AntiVirus\Quarantine\3E5C5FDC.exe=>(Quarantine-2)
                  Deleted

                  C:\Program Files\Norton AntiVirus\Quarantine\43991CF1.exe=>(Quarantine-2)
                  Infected with: Trojan.Proxy.Small.Y

                  C:\Program Files\Norton AntiVirus\Quarantine\43991CF1.exe=>(Quarantine-2)
                  Disinfection failed

                  C:\Program Files\Norton AntiVirus\Quarantine\43991CF1.exe=>(Quarantine-2)
                  Deleted

                  C:\Program Files\Norton AntiVirus\Quarantine\6CD73627.tmp=>(Quarantine-2)
                  Infected with: Worm.Vb.AN

                  C:\Program Files\Norton AntiVirus\Quarantine\6CD73627.tmp=>(Quarantine-2)
                  Disinfection failed

                  C:\Program Files\Norton AntiVirus\Quarantine\6CD73627.tmp=>(Quarantine-2)
                  Deleted

                  Et le nouveau de HiJackThis :

                  Logfile of HijackThis v1.99.1
                  Scan saved at 12:23:56, on 2007-03-03
                  Platform: Windows XP SP1 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                  C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                  C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                  C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  C:\WINDOWS\System32\CTsvcCDA.exe
                  C:\Program Files\Norton AntiVirus\navapsvc.exe
                  C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                  C:\WINDOWS\System32\MsPMSPSv.exe
                  C:\WINDOWS\System32\HPZipm12.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Documents and Settings\Owner\Desktop\Lo\hijackthis_199\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/saint-lin-laurentides
                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                  O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {6EDF07CD-9F74-42E8-ABD9-4EDEEBB78656} - C:\WINDOWS\system32\eabaeab.dll
                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                  O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                  O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                  O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                  O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                  O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                  O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
                  O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                  O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
                  O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                  O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
                  O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                  O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                  O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                  O4 - HKLM\..\Run: [SunServer] C:\Program Files\Sunbelt Software\CounterSpy\Consumer\sunserver.exe
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O4 - Global Startup: hp psc 1000 series.lnk = ?
                  O4 - Global Startup: hpoddt01.exe.lnk = ?
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                  O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                  O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://www.gamespy.com
                  O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
                  O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                  O20 - Winlogon Notify: urnwygvs - C:\WINDOWS\SYSTEM32\eabaeab.dll
                  O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                  O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                  O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                  O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                  O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                  O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                  O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                  O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
                  O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                  O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                  O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                  O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

                  Je dois encore partir au travail.. Si tu peux m'envoyer la marche à suivre, je vais continuer en revenant :)
                  0
                  1. Modérateur
                    Salut

                    # Relance HijackThis : choisis " do a scan only" coche la case devant les lignes ci-dessous et clique en bas sur "fix checked" :

                    O2 - BHO: (no name) - {6EDF07CD-9F74-42E8-ABD9-4EDEEBB78656} - C:\WINDOWS\system32\eabaeab.dll

                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"

                    O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
                    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

                    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O4 - Global Startup: hp psc 1000 series.lnk = ?
                    O4 - Global Startup: hpoddt01.exe.lnk = ?

                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                    O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://www.gamespy.com
                    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx

                    O20 - Winlogon Notify: urnwygvs - C:\WINDOWS\SYSTEM32\eabaeab.dll

                    ensuite :

                    # Affiche les dossiers système et fichiers cachés :
                    Ouvrir le poste de travail :
                    - Outils --> Options des dossiers
                    - Affichage --> zone Paramètres avancés
                    - Cocher : Afficher le contenu des dossiers système
                    - Cocher : Afficher les fichiers et dossiers cachés
                    - Décocher : Masquer les extensions des fichiers dont le type est connu
                    - Décocher : Masquer les fichiers protégés du système d'exploitation (recommandé)
                    répondre Oui au message
                    Clique sur "Appliquer à tous les dossiers"
                    Clique sur OK

                    #Télécharge Killbox sur ton Bureau :

                    http://www.downloads.subratam.org/KillBox.exe

                    Double-clique killbox.exe.

                    Copie les lignes en gras ci-bas (sélectionne tout avec ta souris, clic-droit et "Copier") :

                    C:\WINDOWS\SYSTEM32\eabaeab.dll
                    C:\WINDOWS\Downloaded Program Files\gsda.dll


                    * Sélectionnz "delete on reboot"
                    * Cliquez sur le menu "File" -> "Past from clip board"
                    * Cliquez sur All Files
                    * Cliquez sur la croix rouge et et blanche
                    * Répondez yes et laisse redémarrer ton pc.
                    *poste un nouveau blacklight

                    cf démo : http://mickael.barroux.free.fr/securite/killbox.html

                    # passe un coup de ccleaner + cleanup :

                    * CleanUp40 (qui élimine les fichiers temporaires + cookies : gratuit )
                    http://pageperso.aol.fr/Balltrap34/CleanUp40.exe

                    tuto : (merci à Balltrap) http://pageperso.aol.fr/balltrap34/democleanup.htm

                    et enfin, remets un nouveau hijack stp, précise tes soucis s'il en reste !

                    @+

                    0
                    1. Merci d'etre revenu! :)

                      Bon.. d'abord il y a eu une erreur sur hijackthis (send comments to **** ....) et eabaeab.dll est toujours la...
                      Ensuite, dans le pocket killbox, apres avoir clické sur la croix rouge, j'ai ce message :

                      PendingFileRenameOperations Registry Data hes been Removed by External Process!

                      ..et l'ordi ne redémarre pas. (??)
                      0
                      1. J'ai redémarré l'ordinateur à la main (sans killbox) et l'alerte Norton est toujours la. J'ai aussi fait les scan de ccleaner et de CleanUp! mais ce dernier a fait geler mon ordi (durant le scan)!

                        ..de retour demain midi ;O
                        0
                    2. Modérateur
                      Salut

                      reposte un nouveau hijack stp

                      ++
                      0
                      1. Bonjour!

                        Logfile of HijackThis v1.99.1
                        Scan saved at 10:16:33, on 2007-03-04
                        Platform: Windows XP SP1 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                        C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                        C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\System32\hkcmd.exe
                        C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                        C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
                        C:\Program Files\iTunes\iTunesHelper.exe
                        C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        C:\WINDOWS\System32\CTsvcCDA.exe
                        C:\Program Files\Norton AntiVirus\navapsvc.exe
                        C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                        C:\WINDOWS\System32\MsPMSPSv.exe
                        C:\Program Files\iPod\bin\iPodService.exe
                        C:\WINDOWS\System32\wuauclt.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Documents and Settings\Owner\Desktop\Lo\hijackthis_199\HijackThis.exe

                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/saint-lin-laurentides
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                        O2 - BHO: (no name) - {6EDF07CD-9F74-42E8-ABD9-4EDEEBB78656} - C:\WINDOWS\system32\eabaeab.dll
                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                        O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                        O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                        O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                        O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                        O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                        O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                        O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
                        O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                        O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                        O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                        O20 - Winlogon Notify: urnwygvs - C:\WINDOWS\SYSTEM32\eabaeab.dll
                        O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                        O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                        O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                        O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                        O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                        O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                        O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                        O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
                        O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                        O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                        0
                        1. Modérateur
                          ok

                          refais cette manip en mode sans echec :

                          windows xp demarrage en mode sans echec

                          Double-clique killbox.exe.

                          Copie les lignes en gras ci-bas (sélectionne tout avec ta souris, clic-droit et "Copier") :

                          C:\WINDOWS\SYSTEM32\eabaeab.dll
                          C:\WINDOWS\Downloaded Program Files\gsda.dll
                          C:\WINDOWS\System32\aqrubygi.dll


                          * Sélectionnz "delete on reboot"
                          * Cliquez sur le menu "File" -> "Past from clip board"
                          * Cliquez sur All Files
                          * Cliquez sur la croix rouge et et blanche
                          * Répondez yes et laisse redémarrer ton pc.
                          *poste un nouveau blacklight

                          cf démo : http://mickael.barroux.free.fr/securite/killbox.html

                          ensuite, reposte un nouveau hijack stp

                          ++
                          0
                          1. Il me fait le meme message meme en mode sans échec et ne veut pas redémarrer...

                            je t'envoie quand mm le blacklight dans pas long
                            0
                            1. *No hidden files were found* ...
                              0
                          2. Modérateur
                            oups : pour blacklight, c'est normal, ligne en trop :)

                            poste un nouveau hijack stp

                            ++
                            0
                            1. Logfile of HijackThis v1.99.1
                              Scan saved at 11:02:03, on 2007-03-04
                              Platform: Windows XP SP1 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                              C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                              C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\System32\hkcmd.exe
                              C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                              C:\Program Files\iTunes\iTunesHelper.exe
                              C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              C:\WINDOWS\System32\CTsvcCDA.exe
                              C:\Program Files\Norton AntiVirus\navapsvc.exe
                              C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                              C:\WINDOWS\System32\MsPMSPSv.exe
                              C:\Program Files\Internet Explorer\iexplore.exe
                              C:\Program Files\iPod\bin\iPodService.exe
                              C:\Documents and Settings\Owner\Desktop\Lo\hijackthis_199\HijackThis.exe

                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.meteomedia.com/ca/meteo/quebec/saint-lin-laurentides
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: (no name) - {6EDF07CD-9F74-42E8-ABD9-4EDEEBB78656} - C:\WINDOWS\system32\eabaeab.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                              O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                              O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
                              O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                              O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
                              O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
                              O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
                              O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
                              O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
                              O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
                              O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                              O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
                              O20 - Winlogon Notify: urnwygvs - C:\WINDOWS\SYSTEM32\eabaeab.dll
                              O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                              O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
                              O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
                              O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
                              O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                              O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
                              O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                              O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
                              O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
                              O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                              O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
                              O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
                              O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
                              O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
                              O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                              0
                          3. Modérateur
                            Toujours là :/

                            on essaye autre chose :

                            Téléchargez VundoFix.exe (par Atribune) sur ton Bureau :

                            http://www.atribune.org/ccount/click.php?id=4

                            *Double-clique VundoFix.exe afin de le lancer.
                            * Cochez Run VundoFix as a task.
                            * l'outil va se fermer et s'ouvrir à nouveau : cliquez Ok
                            * Cliquez sur le bouton Scan for Vundo.
                            * Lorsque le scan est complété, cliquez sur le bouton Remove Vundo.
                            * Une invite vous demandera supprimer les fichiers, clique YES
                            * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers
                            * le PC va s'éteindre ("shutdown") : clique OK
                            * Démarrez votre PC à nouveau
                            * Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis! dans ta prochaine réponse.

                            ++
                            0
                            1. *No infected files* loll.. =S
                              0
                            2. @baubyil me reste 7 mins avant le travail ;(
                              0
                            3. @baubyVraiment dsl je dois encore partir.. ca serait gentil de me dire la/les prochaines heures que tu sera disponible! :P Comme ca j'essayerai de me connecter..

                              Merci infiniment pour ton temps, de retour plus tard!
                              0
                          4. Modérateur
                            Je ne suis jamais bien loin :)

                            Téléchargement du logiciel dllfix.exe

                            http://cjoint.com/data/derLEAcitQ.htm

                            -Pose-le sur le bureau.
                            -Double-clique.
                            - Décompresse-le sur le bureau.
                            -Double-clique "Start.bat" et choisis l'option 1 pour le rapport.
                            -Une fois la recherche terminée, un fichier txt doit apparaître sous
                            le nom "Output.txt" et sera sauvegardé dans le dossier.

                            poste le stp

                            ++

                            0
                            1. re! voila :

                              2007-03-04
                              17:53

                              System Info:

                              Microsoft Windows XP [Version 5.1.2600]
                              C: "" (002D:80D6) - FS:NTFS clusters:4k
                              Total: 39 974 858 752 [37G] - Free: 17 226 117 120 [16G]

                              *IE version and Service packs:
                              6.0.2800.1106 C:\Program Files\Internet Explorer\Iexplore.exe
                              *Notepad version :
                              5.1.2600.0 C:\WINDOWS\system32\notepad.exe
                              5.1.2600.0 C:\WINDOWS\notepad.exe
                              *Media Player version :
                              10.0.0.3802 C:\Program Files\Windows Media Player\wmplayer.exe

                              ! REG.EXE VERSION 2.0

                              HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings
                              MinorVersion REG_SZ ;SP1;

                              Locked or 'Suspect' file(s) found...
                              These may be other files that Dllfix doesnt target.
                              \\?\C:\WINDOWS\System32\AQRUBYGI.DLL +++ File read error
                              \\?\C:\WINDOWS\System32\AQRUBYGI.DLL +++ File read error

                              Scanning for main Hijacker:

                              REGEDIT4

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                              "AppInit_DLLs"=""
                              "DeviceNotSelectedTimeout"="15"
                              "GDIProcessHandleQuota"=dword:00002710
                              "Spooler"="yes"
                              "swapdisk"=""
                              "TransmissionRetryTimeout"="90"
                              "USERProcessHandleQuota"=dword:00002710

                              REGEDIT4

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
                              @=""

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
                              @=""

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EDF07CD-9F74-42E8-ABD9-4EDEEBB78656}]

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
                              "NoExplorer"=dword:00000001

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BDF3E430-B101-42AD-A544-FADC6B084872}]
                              @="NAV Helper"

                              REGEDIT4

                              [HKEY_CLASSES_ROOT\PROTOCOLS\Filter]

                              [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\Class Install Handler]
                              @="AP Class Install Handler filter"
                              "CLSID"="{32B533BB-EDAE-11d0-BD5A-00AA00B92AF1}"

                              [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\deflate]
                              @="AP Deflate Encoding/Decoding Filter "
                              "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}"

                              [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\gzip]
                              @="AP GZIP Encoding/Decoding Filter "
                              "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}"

                              [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\lzdhtml]
                              @="AP lzdhtml encoding/decoding Filter"
                              "CLSID"="{8f6b0360-b80d-11d0-a9b3-006097942311}"

                              [HKEY_CLASSES_ROOT\PROTOCOLS\Filter\text/webviewhtml]
                              @="WebView MIME Filter"
                              "CLSID"="{733AC4CB-F1A4-11d0-B951-00A0C90312E1}"

                              ! REG.EXE VERSION 2.0

                              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
                              AppInit_Dlls REG_SZ

                              *Security settings for 'Windows' key:

                              RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
                              Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
                              This program is Freeware, use it on your own risk!

                              Access Control List for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
                              (ID-NI) ALLOW Read BUILTIN\Users
                              (ID-IO) ALLOW Read BUILTIN\Users
                              (ID-NI) ALLOW Full access BUILTIN\Administrators
                              (ID-IO) ALLOW Full access BUILTIN\Administrators
                              (ID-NI) ALLOW Full access NT AUTHORITY\SYSTEM
                              (ID-IO) ALLOW Full access NT AUTHORITY\SYSTEM
                              (ID-IO) ALLOW Full access CREATOR OWNER

                              Effective permissions for Registry key hklm\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows:
                              Read BUILTIN\Users
                              Full access BUILTIN\Administrators
                              Full access NT AUTHORITY\SYSTEM
                              0
                          5. Modérateur
                            Salut

                            -Relance "dllfix.exe" du début. Cette fois-ci option "2 : run fix"

                            Sous menu "1- Enter dll name..."

                            Tu rentres le nom : C:\WINDOWS\System32\AQRUBYGI.DLL

                            Touche entrée.

                            -Il va la chercher et la supprimer après un redémarrage.

                            ensuie télécharge ceci et execute les :

                            ad aware

                            https://www.trendmicro.com/en_us/forHome.html

                            @+
                            0
                            1. Salut!

                              Voici le log de DllFix..
                              ..quant à Ad-Aware, il n'a détecté que des tracking cookies.

                              *Je dois bien entrer AQRUBYGI.DLL (tout en maj.)?*

                              Backing up Registry Hive

                              The operation completed successfully

                              Deleting Windows Key

                              The operation completed successfully

                              Adding Test Windows Key

                              The operation completed successfully

                              Restoring temp Values Key

                              The operation completed successfully

                              Deleting Bad Appinit Value

                              The operation completed successfully

                              Backup of Modified Hiv

                              The operation completed successfully

                              Deleting test Windows key

                              The operation completed successfully

                              Deleting Filter text
                              Running from C:\Documents and Settings\Owner\Desktop\dllfix
                              Scanning for Locked File
                              If this repeats 4 times than you may have another
                              Locked File not related to About:blank Hijack
                              Scanning For main hijacker.
                              Processing File Manually
                              C:\WINDOWS\system32\AQRUBYGI.DLL
                              Md5 Check of C:\WINDOWS\system32\AQRUBYGI.DLL

                              Md5 tested As
                              File was found but md5 didnt match
                              MD5 was:
                              Resetting file attributes
                              Processing ACL of: <\\?\C:\WINDOWS\system32\AQRUBYGI.DLL>

                              SetACL finished successfully.
                              File was zipped for submission to Shadowwar
                              File is located at C:\Documents and Settings\Owner\Desktop\dllfix\submit.zip
                              please Email a copy to spywaresubmit at aol.com
                              Please include a link to your post.
                              File is still in original location now unlocked.
                              It is now ok to proceed with Rest of Cleanup.

                              Adding Back Windows Key

                              The operation completed successfully

                              Restoring Registry Hive

                              The operation completed successfully

                              Restoring Cleaned Appinit Value

                              The operation completed successfully

                              * Je dois bien entrer AQRUBYGI.DLL (tout en maj.)?

                              ..quant à Ad-Aware, il n'a détecté que des tracking cookies.
                              0
                          • 1
                          • 2
                          • 3