[Virus] Infecté par win32/Rustock.gen!C

Bonjour je suis infecter du virus "win32/Rustock.gen!C"a cause de se virus mon pc redemarre kan je clik sur une aplication en particulier et jai lontemps chercher sur le net sans trouver
SVP Pouvais Vous Maider car jen et vraiment besoin !
Merci d Avance
Configuration: Windows XP
Internet Explorer 7.0

13 réponses

  1. Contributeur sécurité
    Bonsoir,

    Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau:

    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
    Redémarre ton ordinateur
    Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
    A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
    Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
    Choisis ton compte.
    Déroule la liste des instructions ci-dessous :
    Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur RunThis.bat pour lancer le script.
    Appuie sur Y pour commencer le processus de nettoyage.
    Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
    Appuie sur une touche pour redémarrer le PC.
    Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
    Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
    Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
    Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum !

    a+
    0
    1. SDFix: Version 1.84

      Run by Mahamadou Magassa - 15/05/2007 - 20:30:53,85

      Microsoft Windows XP [version 5.1.2600]

      Running From: C:\DOCUME~1\MAHAMA~1\Bureau\SDFix

      Safe Mode:
      Checking Services:

      Restoring Windows Registry Values
      Restoring Windows Default Hosts File

      Rebooting...

      Normal Mode:
      Checking Files:

      No Trojan Files Found...

      Removing Temp Files...

      ADS Check:

      Checking if ADS is attached to system32 Folder
      C:\WINDOWS\system32
      No streams found.

      Checking if ADS is attached to svchost.exe
      C:\WINDOWS\system32\svchost.exe
      No streams found.

      Final Check:

      Remaining Services:
      ------------------

      [COLOR=RED][B]Rootkit PE386 Found, Use a Rootkit scanner ![/COLOR][/B]

      Authorized Application Key Export:

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe"="C:\\Program Files\\MessengerDiscovery\\MessengerDiscovery Live.exe:*:Enabled:MessengerDiscovery Live the Windows Live Messenger addon"
      "C:\\Program Files\\MessengerDiscovery\\Loader.exe"="C:\\Program Files\\MessengerDiscovery\\Loader.exe:*:Enabled:Loader"
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
      "C:\\Program Files\\Azureus\\Azureus.exe"="C:\\Program Files\\Azureus\\Azureus.exe:*:Enabled:Azureus"
      "C:\\Program Files\\Pando Networks\\Pando\\pando.exe"="C:\\Program Files\\Pando Networks\\Pando\\pando.exe:*:Enabled:pando"
      "C:\\Program Files\\Shareaza\\Shareaza.exe"="C:\\Program Files\\Shareaza\\Shareaza.exe:*:Enabled:Shareaza"
      "C:\\Documents and Settings\\Mahamadou Magassa\\Mes documents\\Logiciel\\PSP\\USB\\USB.exe"="C:\\Documents and Settings\\Mahamadou Magassa\\Mes documents\\Logiciel\\PSP\\USB\\USB.exe:*:Enabled:USB"
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
      "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
      "C:\\Program Files\\eMule\\eMule.exe"="C:\\Program Files\\eMule\\eMule.exe:*:Enabled:eMule Plus"
      "C:\\DOCUME~1\\MAHAMA~1\\LOCALS~1\\Temp\\win15.tmp.exe"="C:\\DOCUME~1\\MAHAMA~1\\LOCALS~1\\Temp\\win15.tmp.exe:*:Enabled:win15.tmp"
      "C:\\WINDOWS\\TEMP\\win79.tmp.exe"="C:\\WINDOWS\\TEMP\\win79.tmp.exe:*:Enabled:win79.tmp"

      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
      "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

      Remaining Files:
      ---------------

      Checking For Files with Hidden Attributes:

      C:\Documents and Settings\Mahamadou Magassa\Local Settings\Application Data\Microsoft\Messenger\fatdesfmnan-hy@hotmail.fr\Sharing Folders\lolita_lempicka94@hotmail.com\Thumbs.db
      C:\Documents and Settings\Mamou Magassa\Local Settings\Application Data\Microsoft\Messenger\fatdesfmnan-hy@hotmail.fr\Sharing Folders\lolita_lempicka94@hotmail.com\Thumbs.db
      C:\Program Files\eRightSoft\SUPER\cygwin1.dll
      C:\Program Files\eRightSoft\SUPER\cygz.dll
      C:\Program Files\eRightSoft\SUPER\_Setup.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\14_43260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\28_83260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\atrc3260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\cook3260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\ddnt3260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\dnet3260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\drv13260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\drv23260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\drv33260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\drv43260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\dspr3260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\ivvideo.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\qtmlClient.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\raac.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\rnco3260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\rnlt3260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\rv103260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\rv203260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\rv303260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\rv403260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\sipr3260.dll
      C:\Program Files\eRightSoft\SUPER\mencoder\tokr3260.dll
      C:\WINDOWS\system32\flvDX.dll
      C:\WINDOWS\system32\msfDX.dll
      C:\WINDOWS\system32\ssttr.dll
      C:\Program Files\eRightSoft\SUPER\Setup.exe
      C:\Documents and Settings\Mahamadou Magassa\Application Data\Purple Ghost Software, Inc\PodPlus\1.1.0.0\WinPP.sys
      C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp
      C:\Documents and Settings\Mahamadou Magassa\Mes documents\Logiciel\fatou\~WRL3283.tmp
      C:\Documents and Settings\Mahamadou Magassa\Mes documents\Logiciel\fatou\~WRL3651.tmp
      C:\Documents and Settings\Mamou Magassa\Mes documents\fatou\~WRL3283.tmp
      C:\Documents and Settings\Mamou Magassa\Mes documents\fatou\~WRL3651.tmp
      C:\WINDOWS\system32\rttss.tmp

      Finished
      0
      1. Contributeur sécurité
        Bonsoir,

        télécharge HijackThis:

        http://pchelpbordeaux.free.fr/logiciels.html

        Tutorial:

        http://pchelpbordeaux.free.fr/tuto.html

        Démo en image:

        http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

        Fais un scan et poste l'analyse.

        a+
        0
        1. Logfile of HijackThis v1.99.1
          Scan saved at 15:41:00, on 16/05/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16441)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
          C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\MSN Messenger\usnsvc.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
          C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Windows Media Player\WMPNSCFG.exe
          C:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe
          C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\WINDOWS\explorer.exe
          C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: (no name) - {55DB983C-BDBF-426f-86F0-187B02DDA39B} - C:\WINDOWS\system32\jlmpxgxi.dll
          O2 - BHO: (no name) - {6962DFAD-97FE-467A-AE04-574E096F59D0} - C:\WINDOWS\system32\ssttr.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
          O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1036
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
          O4 - HKLM\..\Run: [WindowsUpdate] "rundll32.exe" "C:\WINDOWS\system32\wjmyldva.dll",realset
          O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
          O4 - Global Startup: BTTray.lnk = ?
          O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie_ctx.htm
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
          O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
          O11 - Options group: [INTERNATIONAL] International*
          O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
          O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
          O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O20 - Winlogon Notify: ssttr - C:\WINDOWS\system32\ssttr.dll
          O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
          O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
          O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
          O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
          O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
          0
          1. Contributeur sécurité
            Bonjour,

            houla, y a du boulot!

            Télécharge rustbfix (par ejvindh) de l'un de ces deux liens :

            http://www.uploads.ejvindh.net/rustbfix.exe

            http://uploads.ejvindh.andymanchesta.com/Rustbfix.exe

            ...et sauvegarde-le sur ton Bureau.

            Double clique rustbfix.exe afin de lancer l'outil.
            Si une infection Rustock.b est détectée, une invite t'indiquera qu'il est nécessaire de redémarrer l'ordi. Ce redémarrage pourrait être plus long que d'habitude, et il est possible que deux redémarrages soient requis. Tout cela se fera automatiquement.
            Suite au(x) redémarrage(s), deux rapports s'ouvriront : (%root%\avenger.txt & %root%\rustbfix\pelog.txt).
            Poste (Copie/Colle) le contenu de ces deux rapports, ainsi qu'un nouveau log HijackThis dans ta prochaine réponse.

            a+
            0
            1. Le premier
              ************************* Rustock.b-fix -- By ejvindh *************************
              16/05/2007 22:37:47,56

              ******************* Pre-run Status of system *******************

              Rootkit driver PE386 is found. Starting the unload-procedure....

              Rustock.b-ADS attached to the System32-folder:
              :lzx32.sys 79094
              Total size: 79094 bytes.
              Attempting to remove ADS...
              system32: deleted 79094 bytes in 1 streams.

              Looking for Rustock.b-files in the System32-folder:
              No Rustock.b-files found in system32

              ******************* Post-run Status of system *******************

              Rustock.b-driver on the system: NONE!

              Rustock.b-ADS attached to the System32-folder:
              No System32-ADS found.

              Looking for Rustock.b-files in the System32-folder:
              No Rustock.b-files found in system32

              ******************************* End of Logfile ********************************

              Le dexieme
              Logfile of The Avenger version 1, by Swandog46
              Running from registry key:
              \Registry\Machine\System\CurrentControlSet\Services\revrmtuw

              *******************

              Script file located at: \??\C:\WINDOWS\system32\xoudaxfn.txt
              Script file opened successfully.

              Script file read successfully

              Backups directory opened successfully at C:\Avenger

              *******************

              Beginning to process script file:

              Driver PE386 unloaded successfully.
              Program C:\Rustbfix\2run.bat successfully set up to run once on reboot.

              Completed script processing.

              *******************

              Finished! Terminate.
              Et Le Log hijackthis
              Logfile of HijackThis v1.99.1
              Scan saved at 22:49:18, on 16/05/2007
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16441)

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\WINDOWS\Explorer.EXE
              C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
              C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
              C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\MSN Messenger\MsnMsgr.Exe
              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
              O2 - BHO: (no name) - {55DB983C-BDBF-426f-86F0-187B02DDA39B} - C:\WINDOWS\system32\jlmpxgxi.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
              O2 - BHO: (no name) - {C9E9E1B5-B56F-4F59-97E4-07AC4B722EEA} - C:\WINDOWS\system32\ssttr.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
              O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1036
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
              O4 - HKLM\..\Run: [WindowsUpdate] "rundll32.exe" "C:\WINDOWS\system32\wjmyldva.dll",realset
              O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
              O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
              O4 - Global Startup: BTTray.lnk = ?
              O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie_ctx.htm
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
              O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
              O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
              O11 - Options group: [INTERNATIONAL] International*
              O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
              O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
              O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
              O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
              O20 - Winlogon Notify: ssttr - C:\WINDOWS\system32\ssttr.dll
              O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
              O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
              O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
              O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
              O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

              Merci de ton aide did71 mais esque c grave ?
              0
              1. Contributeur sécurité
                re,

                ok, on continue!

                Télécharge ComboFix (par sUBs) d'un de ces liens sur ton bureau:

                http://www.techsupportforum.com/sectools/combofix.exe

                http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                Double clique combofix.exe et suis les invites

                Poste le rapport

                a+
                0
                1. "Mahamadou Magassa" - 2007-05-17 14:23:11 Service Pack 2
                  ComboFix 07-05.17.V - Running from: "C:\Documents and Settings\Mahamadou Magassa\Bureau\"

                  (((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

                  C:\WINDOWS\system32\aovuptjk.dll
                  C:\WINDOWS\system32\hggedca.dll
                  C:\WINDOWS\system32\jlmpxgxi.dll
                  C:\WINDOWS\system32\ubfyaigs.dll
                  C:\WINDOWS\system32\wjmyldva.dll
                  C:\WINDOWS\system32\efcbaba.dll
                  C:\WINDOWS\system32\khfefcd.dll
                  C:\WINDOWS\system32\kjtpuvoa.ini
                  C:\WINDOWS\system32\rttss.bak1
                  C:\WINDOWS\system32\rttss.bak2
                  C:\WINDOWS\system32\rttss.ini
                  C:\WINDOWS\system32\rttss.ini2
                  C:\WINDOWS\system32\rttss.tmp
                  C:\WINDOWS\system32\sgiayfbu.ini
                  C:\WINDOWS\system32\avdlymjw.ini
                  C:\WINDOWS\system32\ssttr.dll

                  * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

                  (((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

                  C:\install.log

                  ((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-17 ))))))))))))))))))))))))))))))))))

                  2007-05-16 22:44 <REP> d-------- C:\avenger
                  2007-05-16 22:37 <REP> d-------- C:\Rustbfix
                  2007-05-16 16:18 <REP> d-------- C:\WINDOWS\LastGood
                  2007-05-16 15:40 <REP> d-------- C:\Program Files\Hijackthis Version Fran‡aise
                  2007-05-15 20:56 <REP> d-------- C:\WINDOWS\LastGood.Tmp
                  2007-05-15 16:03 1,040,384 --a------ C:\WINDOWS\system32\libeay32.dll
                  2007-05-15 16:02 196,608 --a------ C:\WINDOWS\system32\ssleay32.dll
                  2007-05-15 15:36 <REP> d-------- C:\DOCUME~1\MAMOUM~1\APPLIC~1\Webroot
                  2007-05-13 23:51 <REP> d-------- C:\Program Files\MP3Gain
                  2007-05-13 20:28 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
                  2007-05-13 20:27 <REP> dr------- C:\DOCUME~1\LOCALS~1\Mes documents
                  2007-05-13 20:27 <REP> dr------- C:\DOCUME~1\LOCALS~1\Favoris
                  2007-05-13 20:27 <REP> d-------- C:\DOCUME~1\LOCALS~1\Menu D‚marrer
                  2007-05-13 20:27 <REP> d-------- C:\DOCUME~1\LOCALS~1\Bureau
                  2007-05-13 19:16 <REP> d-------- C:\Program Files\a-squared Free
                  2007-05-13 18:47 <REP> d-------- C:\DOCUME~1\NETWOR~1\APPLIC~1\Webroot
                  2007-05-13 16:33 <REP> d-------- C:\Program Files\Windows Live Safety Center
                  2007-05-13 15:17 22,080 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
                  2007-05-13 15:17 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
                  2007-05-13 15:17 20,544 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
                  2007-05-13 15:17 144,448 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
                  2007-05-13 15:17 <REP> d-------- C:\Program Files\Webroot
                  2007-05-13 15:17 <REP> d-------- C:\DOCUME~1\LOCALS~1\APPLIC~1\Webroot
                  2007-05-13 15:17 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Webroot
                  2007-05-13 15:15 <REP> d-------- C:\DOCUME~1\MAHAMA~1\APPLIC~1\Webroot
                  2007-05-13 01:21 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
                  2007-05-13 00:06 <REP> d-------- C:\Program Files\Replay Media Catcher
                  2007-05-11 00:42 <REP> d-------- C:\DOCUME~1\MAHAMA~1\APPLIC~1\Activision
                  2007-05-11 00:39 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
                  2007-05-11 00:39 255,848 --a------ C:\WINDOWS\system32\xactengine2_6.dll
                  2007-05-11 00:39 251,672 --a------ C:\WINDOWS\system32\xactengine2_5.dll
                  2007-05-11 00:39 2,297,552 --a------ C:\WINDOWS\system32\d3dx9_26.dll
                  2007-05-11 00:17 <REP> d-------- C:\Program Files\MIKSOFT
                  2007-05-10 00:16 <REP> d-------- C:\Program Files\Xilisoft
                  2007-05-06 20:06 <REP> d-------- C:\Program Files\MSXML 4.0
                  2007-05-06 00:39 <REP> d-------- C:\DOCUME~1\MAHAMA~1\APPLIC~1\TransRender
                  2007-05-06 00:39 <REP> d-------- C:\DOCUME~1\MAHAMA~1\APPLIC~1\Temporary
                  2007-05-06 00:39 <REP> d-------- C:\DOCUME~1\MAHAMA~1\APPLIC~1\ConvertTemp
                  2007-05-06 00:37 <REP> d-------- C:\DOCUME~1\MAHAMA~1\APPLIC~1\Samsung
                  2007-05-06 00:21 5,632 --a------ C:\WINDOWS\system32\drivers\StarOpen.sys
                  2007-05-06 00:21 174,592 --a------ C:\WINDOWS\system32\framedyn.dll
                  2007-05-06 00:21 <REP> d-------- C:\WINDOWS\system32\Samsung_USB_Drivers
                  2007-05-06 00:21 <REP> d-------- C:\Program Files\Samsung
                  2007-05-06 00:10 <REP> d-------- C:\Program Files\LizardTech
                  2007-04-30 11:59 <REP> d-------- C:\Program Files\Lavasoft
                  2007-04-30 11:59 <REP> d-------- C:\DOCUME~1\MAHAMA~1\APPLIC~1\Lavasoft
                  2007-04-22 02:45 <REP> d-------- C:\Program Files\Lavalys
                  2007-04-22 02:45 <REP> d-------- C:\Program Files\CCleaner
                  2007-04-18 23:26 442,368 -ra------ C:\WINDOWS\system32\vp6vfw.dll

                  (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

                  2007-05-17 10:44:02 -------- d-----w C:\Program Files\Messenger Plus! Live
                  2007-05-17 10:44:01 -------- d-----w C:\Program Files\MSN Messenger
                  2007-05-16 20:49:11 -------- d-----w C:\Program Files\Hijackthis Version Française
                  2007-05-16 16:29:50 -------- d-----w C:\Program Files\StarOffice7
                  2007-05-16 12:02:55 -------- d-----w C:\Program Files\L'Entraîneur 2007
                  2007-05-13 17:37:45 -------- d-----w C:\Program Files\DAEMON Tools
                  2007-05-13 13:14:43 -------- d-----w C:\DOCUME~1\MAHAMA~1\APPLIC~1\Azureus
                  2007-05-13 00:11:19 -------- d-----w C:\Program Files\SpeedPost Project
                  2007-05-11 15:11:13 -------- d-----w C:\DOCUME~1\MAHAMA~1\APPLIC~1\Screenshot Sender
                  2007-05-11 10:29:45 -------- d--h--w C:\Program Files\InstallShield Installation Information
                  2007-05-05 22:14:39 -------- d-----w C:\Program Files\Google
                  2007-05-05 12:40:10 -------- d-----w C:\Program Files\StuffPlug3
                  2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
                  2007-04-30 15:41:55 85,952 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
                  2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
                  2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
                  2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
                  2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
                  2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
                  2007-04-20 21:48:30 -------- d-----w C:\Program Files\Windows Media Connect 2
                  2007-04-16 22:38:08 -------- d-----w C:\Program Files\Free Audio Pack
                  2007-04-15 16:39:49 -------- d-----w C:\Program Files\Belkin
                  2007-04-15 16:24:18 -------- d-----w C:\DOCUME~1\MAHAMA~1\APPLIC~1\AdobeUM
                  2007-04-13 18:20:07 -------- d-----w C:\DOCUME~1\MAHAMA~1\APPLIC~1\Purple Ghost Software, Inc
                  2007-04-10 23:42:33 -------- d-----w C:\Program Files\Alcohol Soft
                  2007-04-10 23:39:28 639,224 ----a-w C:\WINDOWS\system32\drivers\sptd.sys
                  2007-04-01 21:17:00 -------- d-----w C:\DOCUME~1\MAHAMA~1\APPLIC~1\Help
                  2007-03-27 19:48:45 -------- d-----w C:\Program Files\MessengerDiscovery
                  2007-03-25 12:58:05 -------- d-----w C:\DOCUME~1\MAHAMA~1\APPLIC~1\Ahead
                  2007-03-25 12:27:32 63,614 ----a-w C:\WINDOWS\system32\perfc00C.dat
                  2007-03-25 12:27:32 445,016 ----a-w C:\WINDOWS\system32\perfh00C.dat
                  2007-03-17 13:44:47 293,376 ----a-w C:\WINDOWS\system32\winsrv.dll
                  2007-03-15 23:49:44 -------- d-----w C:\Program Files\eRightSoft
                  2007-03-15 21:39:35 -------- d-----w C:\Program Files\pspvideo9
                  2007-03-15 21:39:35 -------- d-----w C:\Program Files\AviSynth 2.5
                  2007-03-15 21:36:46 -------- d-----w C:\DOCUME~1\MAHAMA~1\APPLIC~1\Apple Computer
                  2007-03-15 18:41:47 -------- d-----w C:\Program Files\Shareaza
                  2007-03-12 18:31:41 -------- d-----w C:\Program Files\AudioCommander
                  2007-03-12 18:31:10 -------- d-----w C:\DOCUME~1\MAHAMA~1\APPLIC~1\Seven Zip
                  2007-03-12 16:21:22 -------- d-----w C:\Program Files\Micro Application
                  2007-03-12 16:21:04 -------- d-----w C:\Program Files\Fichiers communs\InstallShield
                  2007-03-12 16:15:18 -------- d-----w C:\Program Files\QuickTime
                  2007-03-11 22:16:58 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
                  2007-03-11 01:47:49 -------- d--h--r C:\DOCUME~1\MAHAMA~1\APPLIC~1\SecuROM
                  2007-03-08 15:37:50 578,560 ----a-w C:\WINDOWS\system32\user32.dll
                  2007-03-08 15:37:50 40,960 ----a-w C:\WINDOWS\system32\mf3216.dll
                  2007-03-08 15:37:50 281,600 ----a-w C:\WINDOWS\system32\gdi32.dll
                  2007-03-08 15:33:58 1,843,712 ----a-w C:\WINDOWS\system32\win32k.sys
                  2007-03-02 00:57:44 41 ---h--w C:\WINDOWS\dsez7212.dat
                  2007-02-21 23:48:01 60 ----a-w C:\WINDOWS\system32\SYSDRV.DAT
                  2007-02-21 14:56:50 69,632 ----a-w C:\WINDOWS\uinst001.exe
                  2007-02-21 11:47:16 31,744 --sh--r C:\WINDOWS\system32\msfDX.dll
                  2007-02-05 20:19:06 185,344 ----a-w C:\WINDOWS\system32\upnphost.dll

                  (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

                  *Note* empty entries & legit default entries are not shown

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
                  {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
                  {9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 21:33]
                  {AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar2.dll [2007-01-20 00:56]
                  {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}=C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll [2007-05-06 00:11]

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "SoundMan"="SOUNDMAN.EXE" []
                  "NvCplDaemon"="RUNDLL32.exe" [2004-08-05 21:00 C:\WINDOWS\system32\rundll32.exe]
                  "nwiz"="nwiz.exe" [2005-08-02 16:35 C:\WINDOWS\system32\nwiz.exe]
                  "NvMediaCenter"="RUNDLL32.exe" [2004-08-05 21:00 C:\WINDOWS\system32\rundll32.exe]
                  "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50]
                  "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2002-09-13 14:42]
                  "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 17:42]
                  "DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2006-11-12 12:48]
                  "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 11:54]
                  "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
                  "WindowsUpdate"="rundll32.exe" [2004-08-05 21:00 C:\WINDOWS\system32\rundll32.exe]
                  "SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-01-25 21:58]

                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                  "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 21:00]
                  "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 12:55]
                  "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-06 00:11]
                  "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-03 10:59]

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                  Authentication Packages msv1_0
                  Security Packages kerberos msv1_0 schannel wdigest
                  Notification Packages scecli

                  [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
                  HTTPFilter HTTPFilter
                  LocalService Alerter WebClient LmHosts RemoteRegistry upnphost SSDPSRV
                  NetworkService DnsCache
                  DcomLaunch DcomLaunch TermService
                  rpcss RpcSs
                  imgsvc StiSvc
                  termsvcs TermService
                  WudfServiceGroup WUDFSvc

                  HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

                  [HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\Z]
                  Shell\AutoRun\command C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

                  ********************************************************************

                  catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
                  Rootkit scan 2007-05-17 14:27:13
                  Windows 5.1.2600 Service Pack 2 NTFS

                  scanning hidden processes ...

                  scanning hidden autostart entries ...

                  scanning hidden files ...

                  scan completed successfully
                  hidden files: 0

                  ********************************************************************

                  Completion time: 2007-05-17 14:30:04 - machine was rebooted
                  C:\ComboFix-quarantined-files.txt ... 2007-05-17 14:30

                  --- E O F ---
                  (((((((((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

                  C:\WINDOWS\system32\aovuptjk.dll
                  C:\WINDOWS\system32\hggedca.dll
                  C:\WINDOWS\system32\jlmpxgxi.dll
                  C:\WINDOWS\system32\ubfyaigs.dll
                  C:\WINDOWS\system32\wjmyldva.dll
                  C:\WINDOWS\system32\efcbaba.dll
                  C:\WINDOWS\system32\khfefcd.dll
                  C:\WINDOWS\system32\kjtpuvoa.ini
                  C:\WINDOWS\system32\rttss.bak1
                  C:\WINDOWS\system32\rttss.bak2
                  C:\WINDOWS\system32\rttss.ini
                  C:\WINDOWS\system32\rttss.ini2
                  C:\WINDOWS\system32\rttss.tmp
                  C:\WINDOWS\system32\sgiayfbu.ini
                  C:\WINDOWS\system32\avdlymjw.ini
                  C:\WINDOWS\system32\ssttr.dll

                  * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

                  (((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

                  C:\install.log

                  ((((((((((((((((((((((((((((((( Files Created from 17/0-01-07 to 17/05/2007 ))))))))))))))))))))))))))))))))))
                  0
                  1. Contributeur sécurité
                    Bonjour,

                    peux tu poster un nouvel hijackthis!

                    a+
                    0
                    1. Logfile of HijackThis v1.99.1
                      Scan saved at 22:10:14, on 17/05/2007
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16441)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                      C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Program Files\MSN Messenger\usnsvc.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                      C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\MSN Messenger\MsnMsgr.Exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\Windows Media Player\WMPNSCFG.exe
                      C:\Program Files\Belkin\Logiciel Bluetooth\BTTray.exe
                      C:\PROGRA~1\Belkin\LOGICI~1\BTSTAC~1.EXE
                      C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
                      C:\Program Files\Hijackthis Version Française\hijackthis vf.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                      O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
                      O4 - HKLM\..\Run: [NvMediaCenter] "RUNDLL32.EXE" C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1036
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                      O4 - HKLM\..\Run: [WindowsUpdate] "rundll32.exe" "C:\WINDOWS\system32\wjmyldva.dll",realset
                      O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                      O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"
                      O4 - Global Startup: BTTray.lnk = ?
                      O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie_ctx.htm
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
                      O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Belkin\Logiciel Bluetooth\btsendto_ie.htm
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
                      O11 - Options group: [INTERNATIONAL] International*
                      O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
                      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8300.cab
                      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
                      O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
                      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                      O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\Belkin\Logiciel Bluetooth\bin\btwdins.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
                      O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
                      0
                      1. Contributeur sécurité
                        re,

                        le rapport est propre!

                        comment se comporte le pc?

                        a+
                        0
                        1. Merci de ton aide did71 maintenant tous marche sur des roulette !!!
                          0
                          1. Contributeur sécurité
                            re,

                            Content d'avoir pu t'aider!

                            Dénonce ton infection pour faire condamner les auteurs.

                            Crée un message pour faire avancer les choses sur Malware-Complaints, nous devons être les plus nombreux possibles, alors rends compte de ton infection :

                            - Voir les règles du forum : https://malwarecomplaints.info/
                            - Après t'être enregistré à l'aide du bouton en haut se nommant "Register"
                            Si tu as plus de 13 ans, choisir : "I Agree to these terms and am over or exactly 13 years of age"
                            Si tu as moins, clique sur : "I Agree to these terms and am under 13 years of age"

                            Tu as alors, sous forme de liste, un sujet par type d'infection (Look2Me, Smitfraud, SpywareQuake etc..).

                            *** Ton infection : rootkit pe386

                            >> https://malwarecomplaints.info/

                            Si le malware que tu as eu n'apparaît pas dans la liste, ou si tu ne sais pas par quoi tu étais infecté(e), crée un message dans le sujet Autres infections, conforme au règle du forum (âge, ville, département etc..)

                            Indique aussi le nom du Forum qui t'a aidé, CCM!

                            a+
                            0