Comment supprimer DriveCleaner?

Résolu
Bonjour à tous,

J'ai DriveCleaner qui s'ouvre sur mon ordi.
J'ai parcouru le forum et j'ai vu qu'il fallait lancer HijackThis+Blacklight
Je colle donc les rapports ici (Blacklight ne détecte rien) , si quelqu'un pouvait les interpréter et m'aider.
Merci d'avance.

Logfile of HijackThis v1.99.1
Scan saved at 14:48:56, on 09/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
C:\Program Files\D-Tools\daemon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Documents and Settings\All Users\Application Data\vajmfsjo.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\SuperCopier2\SuperCopier2.exe
C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\JM\Bureau\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=5060926
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/hws/sb/dell-row/fr/side.html?channel=fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/hws/sb/dell-row/fr/side.html?channel=fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/hws/sb/dell-row/fr/side.html?channel=fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=5060926
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\nvxmycyc.dll",realset
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [vajmfsjo.exe] C:\Documents and Settings\All Users\Application Data\vajmfsjo.exe
O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [Le Petit Robert Hyperappel] C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?9304318fd6ba4c688e3e9758727a8025
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?9304318fd6ba4c688e3e9758727a8025
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

----------------------------------
06/09/07 14:51:46 [Info]: BlackLight Engine 1.0.61 initialized
06/09/07 14:51:46 [Info]: OS: 5.1 build 2600 (Service Pack 2)
06/09/07 14:51:46 [Note]: 7019 4
06/09/07 14:51:46 [Note]: 7005 0
06/09/07 14:52:00 [Note]: 7006 0
06/09/07 14:52:00 [Note]: 7011 1056
06/09/07 14:52:00 [Note]: 7026 0
06/09/07 14:52:00 [Note]: 7026 0
06/09/07 14:52:04 [Note]: FSRAW library version 1.7.1021
Configuration: Windows XP
Firefox 2.0.0.4

34 réponses

Résumé de la discussion

Le fil expose une infection présumée par DriveCleaner apparue sur un PC Windows XP, analysée via des rapports HijackThis et un scan avec BlackLight pour repérer les entrées suspectes. Des conseils pratiques se succèdent: exécuter CCleaner, lancer un scan antivirus en ligne et poster le rapport, puis utiliser VundoFix pour supprimer les fichiers malveillants et réparer le registre. Plusieurs utilisateurs partagent des rapports successifs et des actions récentes, montrant une coordination autour de la suppression de DLL et d’entrées de démarrage, avec des résultats partiels et la nécessité de vérifications ultérieures.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    · Télécharge Brute Force Uninstaller (de Merjin)
    http://www.merijn.org/files/bfu.zip
    et décompresse-le dans un dossier propre à lui (C:\BFU).
    Fais un clic droit de souris sur ce lien :
    http://metallica.geekstogo.com/EGDACCESS.bfu

    et choisis "Enregistrer sous" (dans IE c'est "Enregistrer le lien sous..") afin de télécharger EGDACCESS.bfu, Type "Tous les fichiers". Sauvegarde dans le dossier créé (C:\BFU).

    · Clic droit sur le lien suivant et choisis "Enregistrer sous" (dans IE c'est "Enregistrer le lien sous..")
    afin de télécharger Winsoftware.bfu, Type "Tous les fichiers".
    ·
    http://www.alt-shift-return.org/Info/Fichiers/Winsoftware.bfu
    Sauvegarde dans le dossier créé (c:\BFU)

    · Télécharge Navipromo.zip (de Lazzzy)
    · http://www.alt-shift-return.org/Info/Fichiers/Navipromo073.zip
    et décompresse-le sur ton bureau.

    · Copie la suite des instructions dans un fichier texte, sur ton bureau et Redémarre en mode sans échec
    Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou autre.
    Lance le fichier Navipromo.bat qui se trouve dans le dossier Navipromo, sur ton bureau.

    · Options :

    Sélectionne l'option "Recherche et suppression automatique". Patiente.
    ·
    S'il trouve quelque chose, tu verras défiler des lignes dans la fenêtre de commande et au bout de quelques instants, il faudra que tu appuies sur une touche pour que le nettoyage soit lancé puis valide en appuyant sur Entrée.
    ·
    Relance l'outil, Sélectionne l'option "Suppression Heuristique", et patiente quelques minutes. Lorsqu'il a terminé, ferme le rapport qui s'est ouvert.

    Démarre le "Brute Force Uninstaller" en double-cliquant sur BFU.exe.
    Clique sur le petit dossier jaune, à la droite de la boîte "Scriptline to execute", et double-clique sur : EGDACCESS.bfu
    Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\EGDACCESS.bfu
    Clique sur "Execute" et laisse-le faire son travail.
    Attendre que "Complete script exécution" apparaisse et clique sur OK. Clique exit pour fermer le programme BFU.

    Recommence encore une fois l'exécution du script Egdaccess.BFU

    Démarre encore le "Brute Force Uninstaller" en double-cliquant sur BFU.exe.
    Clique sur le petit dossier jaune, à la droite de la boîte "Scriptline to execute", et double-clique sur : Winsoftware.bfu
    - Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\Winsoftware.bfu
    Clique sur "Execute" et laisse-le faire son travail.
    Attendre que "Complete script execution" apparaisse et clique sur OK.
    Clique exit pour fermer le programme BFU.

    Recommence encore une fois

    Démarrer -> panneau de configuration -> options internet.
    o Clique sur l'onglet "Contenu" puis onglet "Certificats" et si tu trouves ceci, en particulier dans "éditeurs approuvés" :

    electronic-group - egroup - Montorgueil - VIP - "Sunny Day Design Ltd

    Supprime-les tous.

    Redémarre normalement et poste le contenu du fichier Navipromo.txt qui se trouve dans Poste de travail > disque C:\
    0
    1. Contributeur sécurité
      je te laisse faire j'avai pas vu
      0
    2. Merci de répondre aussi vite. Je fais les manips.
      0
  2. Contributeur sécurité
    pour drive cleaner essaye ROGUE REMOVER

    http://www.libellules.ch/dotclear/index.php?2006/11/29/1518-rogue-remover

    sinon

    Utile ? Votez !
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    Télécharger sur le bureau
    Navilog.zip
    = Double-Clic navilog1.zip
    = Extraire tout sur le bureau
    = Double-Clic navilog1 qui est sur le bureau
    = Appuyer sur une touche jusqu' arriver aux options
    = Choisir option 1

    un rapport : fixnavi.txt dans C : va se creer
    le copier/coller dans ton prochain message.

    = Redémarrer en mode Sans Échec (le démarrage peut prendre plusieurs minutes)
    Attention, pas d’accès à internet dans ce mode. Enregistrer ou imprimer les consignes. Relancer le Pc et tapoter la touche F8, jusqu’à l’apparition des inscriptions avec choix de démarrage
    Avec les touches « flèches », sélectionner Mode sans échec ==> entrée ==>nom utilisateur habituel
    = Lance navilog1
    = Cette fois-ci choisi l'option 2
    = Navilog va faire le nettoyage.. patient jusqu'à ce qui soit marqué *** Nettoyage Termine le ..... ***
    = Un rapport va être génrer sur ton C:\ qui sera en option 2
    Note: le bureau disparaît

    = Redémarre en mode normal et colle le contenu du rapport de navilog (qui est en option 2)

    utilise aussi pour supprimer tes traces

    CCLEANER: (lance un netoyage et repare les clés)
    https://www.01net.com/

    ensuite:

    scan avec des antiespions(en mode sans echec):

    spybot :

    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/26157.html

    si tout c'est bien passer redemarre en mode normal et desactive la restauration syteme pour purger les virus qui seraient dedans puis reactive là (dans DEMARRER puis TOUS LES PROGRAMMES puis ACCESSOIRE puis OUTILS SYSTEME puis RESTAURATION SYSTEME puis parametre)

    D/puis fait un scan en ligne avec un des suivants: et colle le rapport)

    Panda en ligne :
    http://pandasoftware.fr

    kaspersky en ligne :
    https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html
    0
    1. Papyber, j'ai fait les manips, voilà le rapport Navipromo.

      Rapport Navipromo.bat 0.73 effectué le 09/06/2007 à 15:32:55,89
      C:\Documents and Settings\JM\Bureau
      L'opération se déroule en mode sans échec sous le compte "JM"

      ** Recherche...

      Fin du rapport de recherche
      Adware Navipromo non trouvé avec cette méthode

      Engagement de la méthode Heuristique

      Rapport Navipromo.bat 0.73 effectué le 09/06/2007 à 15:32:56,14
      L'opération se déroule en mode sans échec sous le compte "JM"

      ## Suppression Heuristique

      * Backups :

      Aucun résultat par la recherche heuristique

      ## Fin du rapport Heuristique

      -------------

      Rapport Navipromo.bat 0.73 effectué le 09/06/2007 à 15:35:05,37
      L'opération se déroule en mode sans échec sous le compte "JM"

      ## Suppression Heuristique

      * Backups :

      Aucun résultat par la recherche heuristique

      ## Fin du rapport Heuristique
      0
      1. Contributeur sécurité
        remets moi un rapport hijack this
        0
        1. Et voilà:
          Logfile of HijackThis v1.99.1
          Scan saved at 16:03:54, on 09/06/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\Ati2evxx.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
          C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
          C:\WINDOWS\stsystra.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
          C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
          C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
          C:\Program Files\D-Tools\daemon.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\wdfmgr.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\Documents and Settings\All Users\Application Data\vajmfsjo.exe
          C:\Program Files\SuperCopier2\SuperCopier2.exe
          C:\WINDOWS\ehome\mcrdsvc.exe
          C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe
          C:\Program Files\Digital Line Detect\DLG.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\WINDOWS\System32\alg.exe
          C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
          C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\MSN Messenger\msnmsgr.exe
          C:\Documents and Settings\JM\Bureau\HijackThis.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=5060926
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/hws/sb/dell-row/fr/side.html?channel=fr
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr/hws/sb/dell-row/fr/side.html?channel=fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/hws/sb/dell-row/fr/side.html?channel=fr
          R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=5060926
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
          O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
          O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
          O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
          O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
          O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
          O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
          O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\system32\nvxmycyc.dll",realset
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [vajmfsjo.exe] C:\Documents and Settings\All Users\Application Data\vajmfsjo.exe
          O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
          O4 - HKCU\..\Run: [Le Petit Robert Hyperappel] C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe
          O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
          O4 - Global Startup: Digital Line Detect.lnk = ?
          O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?9304318fd6ba4c688e3e9758727a8025
          O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?9304318fd6ba4c688e3e9758727a8025
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
          O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
          0
          1. Contributeur sécurité
            télécharge GenProc de Jean-Chretien1 et Narco4 sur ton bureau
            http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip

            dézippe le dossier, double-clique sur GenProc.bat et poste le contenu du rapport qui s'ouvre

            Aide en images : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
            poste les rapports car parfois il faut ajouter des consignes à la manip pour que cela fonctionne parfaitement
            0
            1. Voilà:
              Rapport GenProc 0.54 [1] effectué le 09/06/2007 à 16:15:36,85 - SystemRoot = C:\WINDOWS

              Dans CCleaner, clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.

              # Etape 1/ Télécharge :

              - VundoFix.exe (par Atribune) http://www.atribune.org/ccount/click.php?id=4 sur ton Bureau

              - combofix.exe (par [b]sUBs[/b]) http://download.bleepingcomputer.com/sUBs/ComboFix.exe sur ton Bureau

              ***** Copie ce qui suit dans un fichier texte et redémarre en mode sans échec comme indiqué ici https://docs.microsoft.com/en-us/?mfr=true (choisis ta session courante "JM") *****

              # Etape 2/

              * Double-clique VundoFix.exe afin de le lancer
              Clique sur le bouton Scan for Vundo
              Lorsque le scan est complété, clique sur le bouton "Remove Vundo"
              Une invite te demandera si tu veux supprimer les fichiers, clique YES
              Après avoir cliqué Yes, le Bureau disparaîtra un moment lors de la suppression des fichiers
              Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK

              Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo

              * Double clique [b]combofix.exe[/b].
              Tape sur la touche Y (Yes) pour démarrer le scan.
              Lorsque le scan sera complété, un rapport apparaîtra

              # Etape 3/

              Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.

              # Etape 4/

              Redémarre normalement et poste :
              - Un nouveau rapport HijackThis, toutes fenêtres et applications fermées http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis_v2.exe ;
              - Le contenu du rapport situé dans C:\vundofix.txt ;
              - Le contenu du rapport situé dans C:\Combofix.txt ;

              Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
              0
              1. Contributeur sécurité
                tu fais très exactement ce que demande GenProc et tu postes les rapports
                0
                1. Désolé, je peux pas continuer aujourd'hui. Je finirai demain.
                  En attendant je poste le rapport Vundo.
                  Merci pour ton aide.
                  A plus

                  -----------------
                  VundoFix V6.4.2

                  Checking Java version...

                  Java version is 1.5.0.6
                  Old versions of java are exploitable and should be removed.

                  Java version is 1.5.0.9
                  Old versions of java are exploitable and should be removed.

                  Java version is 1.5.0.10

                  Java version is 1.5.0.11

                  Scan started at 16:26:18 09/06/2007

                  Listing files found while scanning....

                  C:\WINDOWS\system32\byxxwts.dll
                  C:\WINDOWS\system32\cycymxvn.ini
                  C:\WINDOWS\system32\mnnmp.bak1
                  C:\WINDOWS\system32\mnnmp.bak2
                  C:\WINDOWS\system32\mnnmp.ini
                  C:\WINDOWS\system32\nnnnljh.dll
                  C:\WINDOWS\system32\nvxmycyc.dll
                  C:\WINDOWS\system32\pmnnm.dll
                  C:\WINDOWS\system32\yayvtrp.dll

                  Beginning removal...

                  Attempting to delete C:\WINDOWS\system32\byxxwts.dll
                  C:\WINDOWS\system32\byxxwts.dll Could not be deleted.

                  Attempting to delete C:\WINDOWS\system32\cycymxvn.ini
                  C:\WINDOWS\system32\cycymxvn.ini Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\mnnmp.bak1
                  C:\WINDOWS\system32\mnnmp.bak1 Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\mnnmp.bak2
                  C:\WINDOWS\system32\mnnmp.bak2 Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\mnnmp.ini
                  C:\WINDOWS\system32\mnnmp.ini Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\nnnnljh.dll
                  C:\WINDOWS\system32\nnnnljh.dll Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\nvxmycyc.dll
                  C:\WINDOWS\system32\nvxmycyc.dll Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\pmnnm.dll
                  C:\WINDOWS\system32\pmnnm.dll Could not be deleted.

                  Attempting to delete C:\WINDOWS\system32\yayvtrp.dll
                  C:\WINDOWS\system32\yayvtrp.dll Has been deleted!

                  Performing Repairs to the registry.
                  Done!

                  Beginning removal...

                  Attempting to delete C:\WINDOWS\system32\byxxwts.dll
                  C:\WINDOWS\system32\byxxwts.dll Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\mnnmp.ini
                  C:\WINDOWS\system32\mnnmp.ini Has been deleted!

                  Attempting to delete C:\WINDOWS\system32\pmnnm.dll
                  C:\WINDOWS\system32\pmnnm.dll Has been deleted!

                  Performing Repairs to the registry.
                  Done!
                  0
                  1. Contributeur sécurité
                    ok à demain tu feras la suite
                    vundofix a déjà bien travaillé!!
                    0
                    1. Salut Papyber, la forme ?
                      Je te poste les rapports mais il faut que je parte.
                      Si tu peux jetter un coup d'oeil et me dire si tout va bien.
                      Merci beaucoup.
                      A plus
                      -------
                      Logfile of HijackThis v1.99.1
                      Scan saved at 12:57:10, on 10/06/2007
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\csrss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                      C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\Ati2evxx.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                      C:\WINDOWS\stsystra.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                      C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                      C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                      C:\Program Files\D-Tools\daemon.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                      C:\Program Files\SuperCopier2\SuperCopier2.exe
                      C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe
                      C:\Program Files\Digital Line Detect\DLG.exe
                      C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      C:\WINDOWS\eHome\ehRecvr.exe
                      C:\WINDOWS\eHome\ehSched.exe
                      C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
                      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\wdfmgr.exe
                      C:\WINDOWS\ehome\mcrdsvc.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\WINDOWS\system32\dllhost.exe
                      C:\WINDOWS\system32\wbem\wmiapsrv.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                      C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                      C:\Documents and Settings\JM\Bureau\HijackThis.exe
                      C:\WINDOWS\system32\wuauclt.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=5060926
                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: (no name) - {8A61098D-612B-4EF2-943D-64E920684061} - C:\WINDOWS\system32\byxxwts.dll (file missing)
                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                      O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\aegckuvw.dll
                      O2 - BHO: (no name) - {F48F0CAF-2710-418C-A6E2-CF487EF062C6} - C:\WINDOWS\system32\pmnnm.dll (file missing)
                      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                      O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
                      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                      O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                      O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                      O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
                      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                      O4 - HKLM\..\Run: [vajmfsjo.exe] C:\Documents and Settings\All Users\Application Data\vajmfsjo.exe
                      O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
                      O4 - HKCU\..\Run: [Le Petit Robert Hyperappel] C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe
                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                      O4 - Global Startup: Digital Line Detect.lnk = ?
                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?9304318fd6ba4c688e3e9758727a8025
                      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?9304318fd6ba4c688e3e9758727a8025
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
                      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                      O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
                      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                      O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

                      -------------------------
                      "JM" - 2007-06-10 12:38:01 Service Pack 2 NTFS [SAFE MODE]
                      ComboFix 07-06-3B - Running from: "C:\Documents and Settings\JM\Bureau\"

                      (((((((((((((((((((((((((((((((((((((((((((( V Log )))))))))))))))))))))))))))))))))))))))))))))))))))))))

                      C:\WINDOWS\system32\winjks32.dll

                      * * * POST RUN FILES/FOLDERS * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

                      ((((((((((((((((((((((((( Files Created from 2007-05-10 to 2007-06-10 )))))))))))))))))))))))))))))))

                      2007-06-09 16:48 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
                      2007-06-09 16:26 <REP> d-------- C:\VundoFix Backups
                      2007-06-09 15:37 <REP> d-------- C:\WINDOWS\system32\bfubackups
                      2007-06-09 15:32 <REP> d-------- C:\Navipromo
                      2007-06-09 15:21 <REP> d-------- C:\BFU
                      2007-06-09 13:03 57,344 --a------ C:\DOCUME~1\ALLUSE~1\APPLIC~1\vajmfsjo.exe
                      2007-06-08 18:56 <REP> d-------- C:\Program Files\CCleaner
                      2007-06-08 18:51 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
                      2007-06-08 18:29 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Spybot - Search & Destroy
                      2007-06-07 19:46 58,420 --a------ C:\WINDOWS\system32\aegckuvw.dll
                      2007-05-25 14:12 16 --a------ C:\WINDOWS\popcinfo.dat
                      2007-05-25 13:52 <REP> d-------- C:\DOCUME~1\JM\APPLIC~1\Zylom
                      2007-05-25 13:51 <REP> d-------- C:\Program Files\Zylom Games
                      2007-05-25 13:51 <REP> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Zylom
                      2007-05-19 19:35 <REP> d-------- C:\Program Files\Radio Fr Solo
                      2007-05-10 18:53 <REP> d-------- C:\Program Files\Microsoft CAPICOM 2.1.0.2

                      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

                      2007-06-05 17:14:37 -------- d-----w C:\Program Files\tvants
                      2007-06-01 16:43:45 -------- d-----w C:\Program Files\MSN Messenger
                      2007-06-01 16:41:58 -------- d-----w C:\DOCUME~1\JM\APPLIC~1\ppStream
                      2007-06-01 00:00:25 -------- d-----w C:\Program Files\Windows Live Toolbar
                      2007-05-25 13:54:09 -------- d-----w C:\DOCUME~1\JM\APPLIC~1\BSplayer Pro
                      2007-05-13 14:03:20 -------- d-----w C:\Program Files\Fichiers communs\Sonic Shared
                      2007-05-12 22:34:41 -------- d-----w C:\Program Files\BSplayerPro
                      2007-05-11 12:31:12 65,800 ----a-w C:\WINDOWS\system32\perfc00C.dat
                      2007-05-11 12:31:12 449,978 ----a-w C:\WINDOWS\system32\perfh00C.dat
                      2007-05-05 22:58:54 -------- d-----w C:\Program Files\Ratajik Software
                      2007-05-05 18:55:28 -------- d-----w C:\Program Files\Octoshape Streaming Services
                      2007-04-30 15:46:10 745,600 ----a-w C:\WINDOWS\system32\aswBoot.exe
                      2007-04-30 15:41:55 85,952 -c--a-w C:\WINDOWS\system32\drivers\aswmon.sys
                      2007-04-30 15:41:42 94,552 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
                      2007-04-30 15:39:41 23,416 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
                      2007-04-30 15:38:51 43,176 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
                      2007-04-30 15:37:23 26,888 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
                      2007-04-30 15:35:28 95,872 ----a-w C:\WINDOWS\system32\AVASTSS.scr
                      2007-04-19 12:14:49 -------- d-----w C:\DOCUME~1\JM\APPLIC~1\Skype
                      2007-04-18 16:14:18 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
                      2007-04-12 22:06:00 -------- d-----w C:\DOCUME~1\JM\APPLIC~1\SopCast
                      2007-04-12 22:05:50 -------- d-----w C:\Program Files\SopCast
                      2007-03-17 12:38:12 1,568 -c--a-w C:\DOCUME~1\JM\APPLIC~1\mpauth.dat
                      2007-03-16 03:55:58 40,960 ----a-w C:\WINDOWS\system32\frapsvid.dll
                      2006-10-05 08:46:26 1,890 -csha-w C:\WINDOWS\system32\KGyGaAvL.sys

                      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

                      *Note* empty entries & legit default entries are not shown

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
                      {53707962-6F74-2D53-2644-206D7942484F}=C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2005-05-31 01:04]
                      {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
                      {8A61098D-612B-4EF2-943D-64E920684061}=C:\WINDOWS\system32\byxxwts.dll []
                      {9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-07-07 13:29]
                      {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\Windows Live Toolbar\msntb.dll [2007-02-12 15:56]
                      {CA6319C0-31B7-401E-A518-A07C3DB8F777}=C:\Program Files\BAE\BAE.dll [2006-08-30 18:40]
                      {E12BFF69-38A7-406e-A8EF-2738107A7831}=C:\WINDOWS\system32\aegckuvw.dll [2007-06-07 19:46]
                      {F48F0CAF-2710-418C-A6E2-CF487EF062C6}=C:\WINDOWS\system32\pmnnm.dll []

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
                      "SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 23:30 C:\WINDOWS\stsystra.exe]
                      "ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 17:41]
                      "IntelZeroConfig"="C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" [2006-05-01 09:28]
                      "IntelWireless"="C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" [2006-05-01 09:28]
                      "ISUSPM Startup"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" [2005-06-10 10:44]
                      "ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2005-06-10 10:44]
                      "DAEMON Tools-1033"="C:\Program Files\D-Tools\daemon.exe" [2004-08-22 16:05]
                      "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-11-09 19:24]
                      "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-04-30 16:42]
                      "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-05-30 13:30]
                      "vajmfsjo.exe"="C:\Documents and Settings\All Users\Application Data\vajmfsjo.exe" [2007-06-09 13:03]

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "SuperCopier2.exe"="C:\Program Files\SuperCopier2\SuperCopier2.exe" [2005-03-14 00:37]
                      "Le Petit Robert Hyperappel"="C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe" [2001-10-11 11:11]

                      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                      "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
                      "InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
                      "DisableRegistryTools"=0 (0x0)

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                      "{8A61098D-612B-4EF2-943D-64E920684061}"="C:\WINDOWS\system32\byxxwts.dll" []
                      "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2007-05-30 13:29]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Dell Network Assistant.lnk]
                      path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Dell Network Assistant.lnk
                      backup=C:\WINDOWS\pss\Dell Network Assistant.lnkCommon Startup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^JM^Menu Démarrer^Programmes^Démarrage^Stardock ObjectDock.lnk]
                      path=C:\Documents and Settings\JM\Menu Démarrer\Programmes\Démarrage\Stardock ObjectDock.lnk
                      backup=C:\WINDOWS\pss\Stardock ObjectDock.lnkStartup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
                      "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Corel Photo Downloader]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTSVolFE.exe]
                      "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Dell QuickSet]
                      C:\Program Files\Dell\QuickSet\quickset.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DellSupport]
                      "C:\Program Files\Dell Support\DSAgnt.exe" /startup

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
                      "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
                      C:\Program Files\Logitech\Video\ISStart.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
                      C:\Program Files\Logitech\Video\LogiTray.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ModemOnHold]
                      C:\Program Files\NetWaiting\netWaiting.exe

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
                      C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Norton Ghost 10.0]
                      "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

                      HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*

                      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
                      AutoRun\command- F:\AutoRun.exe TMM50

                      Contents of the 'Scheduled Tasks' folder
                      2007-06-10 10:51:00 C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job

                      **************************************************************************

                      catchme 0.3.692 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
                      Rootkit scan 2007-06-10 12:43:57
                      Windows 5.1.2600 Service Pack 2 NTFS

                      scanning hidden processes ...

                      scanning hidden autostart entries ...

                      HKCU\Software\Microsoft\Windows\CurrentVersion\Run
                      Le Petit Robert Hyperappel = C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe??????????????????????????????????????????????????????????????????????????????????????????????????????????\??? /??\??????????????????????|? ??\???Q??|x???m??|????????\???n??|Z????????????,K?????8??????

                      scanning hidden files ...

                      scan completed successfully
                      hidden files: 0

                      **************************************************************************

                      Completion time: 2007-06-10 12:46:24 - machine was rebooted
                      C:\ComboFix-quarantined-files.txt ... 2007-06-10 12:46

                      --- E O F ---
                      +
                      [code]
                      2007-06-07 19:41 18944 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\winjks32.dll.vir

                      Structure du dossier
                      Le num‚ro de s‚rie du volume est 04C8-EE73
                      C:\QOOBOX
                      \---Quarantine
                      +---C
                      | +---avenger
                      | \---WINDOWS
                      | \---system32
                      | winjks32.dll.vir
                      |
                      \---Registry_backups
                      [/code]
                      0
                      1. Contributeur sécurité
                        si tu as le temps on continue la désinfection maintenant sinon ce sera ce soir ou demain car l'étude du rapport "combofix" et de hijack montre encore de l'infection
                        j'attends ta réponse pour préparer la suite
                        0
                        1. Je peux pas continuer pour l'instant.
                          J'essaierai ce soir sinon demain soir.
                          Bonne journée.
                          0
                          1. Contributeur sécurité
                            ok fais moi signe quant tu seras disponible
                            0
                            1. Salut Papyber! T'es là ?
                              Je suis prêt à éradiquer ces virus.
                              0
                              1. Contributeur sécurité
                                pk je te mets la manip
                                0
                                1. Contributeur sécurité
                                  vundo est souvent récalcitrant
                                  il en reste donc tu fais ceci en suivant bien les consignes
                                  Relance Vundofix

                                  http://www.atribune.org/ccount/click.php?id=4

                                  * Ne clique pas sur "Scan for a vundo"
                                  * Clique droit au milieu de la fenêtre
                                  * Clique sur Add more files ?
                                  * Copie/colle les fichiers ci-dessous ( un par case) :

                                  C:\WINDOWS\system32\aegckuvw.dll

                                  * Clique sur Add files
                                  * Ensuite clique sur Close Windows
                                  * Enfin, clique sur Remove Vundo ( les fichiers précédents doivent apparaitre dans la fenêtre principale)
                                  * Si l'outil demande un redémarrage, accepte
                                  · Poste le rapport Vundofix, ainsi qu'un nouveau log hijackthis

                                  lance hijack pour un scan seulement et coche les lignes suivantes si encore présentes
                                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                  O2 - BHO: (no name) - {8A61098D-612B-4EF2-943D-64E920684061} - C:\WINDOWS\system32\byxxwts.dll (file missing)
                                  O2 - BHO: (no name) - {E12BFF69-38A7-406e-A8EF-2738107A7831} - C:\WINDOWS\system32\aegckuvw.dll
                                  O2 - BHO: (no name) - {F48F0CAF-2710-418C-A6E2-CF487EF062C6} - C:\WINDOWS\system32\pmnnm.dll (file missing)
                                  O4 - HKLM\..\Run: [vajmfsjo.exe] C:\Documents and Settings\All Users\Application Data\vajmfsjo.exe
                                  ferme toutes tes fenêtres y compris internet et clic sur fixer l'objet

                                  Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.
                                  http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

                                  clic double sur OTMoveIt.exe pour le lancer.
                                  copie la liste qui se trouve en citation ci-dessous,
                                  et colle-la dans le cadre de gauche de OTMoveIt :
                                  Paste List of Files/Folders to be moved.

                                  C:\Documents and Settings\All Users\Application Data\vajmfsjo.exe

                                  clique sur MoveIt! pour lancer la suppression.
                                  le résultat apparaitra dans le cadre Results.
                                  clique sur Exit pour fermer.
                                  poste le rapport situé dans C:\\\_OTMoveIt\MovedFiles.

                                  il te sera peut-être demander de redémarrer le pc pour achever la suppression.
                                  si c'est le cas accepte par Yes.

                                  Va sur VIRUS TOTAL
                                  http://www.virustotal.com/en/indexf.html

                                  Colle dans la case à gauche de "parcourir" :

                                  C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe

                                  clique ensuite sur "send". Il faut patienter car tu es sur une file d'attente.
                                  Le rapport ne sera complet que lorsque tu verras la mention "FINISHED"sur la droite.

                                  Dépose le dans ta réponse. avec ton nouveau rapport hijack et le rapport vundo
                                  0
                                  1. J'en ai pour une demi heure d'attente sur Virus Total donc en attendant, je te poste les rapports vundo+OTMoveIt:

                                    VundoFix V6.4.2

                                    Checking Java version...

                                    Java version is 1.5.0.6
                                    Old versions of java are exploitable and should be removed.

                                    Java version is 1.5.0.9
                                    Old versions of java are exploitable and should be removed.

                                    Java version is 1.5.0.10

                                    Java version is 1.5.0.11

                                    Scan started at 16:26:18 09/06/2007

                                    Listing files found while scanning....

                                    C:\WINDOWS\system32\byxxwts.dll
                                    C:\WINDOWS\system32\cycymxvn.ini
                                    C:\WINDOWS\system32\mnnmp.bak1
                                    C:\WINDOWS\system32\mnnmp.bak2
                                    C:\WINDOWS\system32\mnnmp.ini
                                    C:\WINDOWS\system32\nnnnljh.dll
                                    C:\WINDOWS\system32\nvxmycyc.dll
                                    C:\WINDOWS\system32\pmnnm.dll
                                    C:\WINDOWS\system32\yayvtrp.dll

                                    Beginning removal...

                                    Attempting to delete C:\WINDOWS\system32\byxxwts.dll
                                    C:\WINDOWS\system32\byxxwts.dll Could not be deleted.

                                    Attempting to delete C:\WINDOWS\system32\cycymxvn.ini
                                    C:\WINDOWS\system32\cycymxvn.ini Has been deleted!

                                    Attempting to delete C:\WINDOWS\system32\mnnmp.bak1
                                    C:\WINDOWS\system32\mnnmp.bak1 Has been deleted!

                                    Attempting to delete C:\WINDOWS\system32\mnnmp.bak2
                                    C:\WINDOWS\system32\mnnmp.bak2 Has been deleted!

                                    Attempting to delete C:\WINDOWS\system32\mnnmp.ini
                                    C:\WINDOWS\system32\mnnmp.ini Has been deleted!

                                    Attempting to delete C:\WINDOWS\system32\nnnnljh.dll
                                    C:\WINDOWS\system32\nnnnljh.dll Has been deleted!

                                    Attempting to delete C:\WINDOWS\system32\nvxmycyc.dll
                                    C:\WINDOWS\system32\nvxmycyc.dll Has been deleted!

                                    Attempting to delete C:\WINDOWS\system32\pmnnm.dll
                                    C:\WINDOWS\system32\pmnnm.dll Could not be deleted.

                                    Attempting to delete C:\WINDOWS\system32\yayvtrp.dll
                                    C:\WINDOWS\system32\yayvtrp.dll Has been deleted!

                                    Performing Repairs to the registry.
                                    Done!

                                    Beginning removal...

                                    Attempting to delete C:\WINDOWS\system32\byxxwts.dll
                                    C:\WINDOWS\system32\byxxwts.dll Has been deleted!

                                    Attempting to delete C:\WINDOWS\system32\mnnmp.ini
                                    C:\WINDOWS\system32\mnnmp.ini Has been deleted!

                                    Attempting to delete C:\WINDOWS\system32\pmnnm.dll
                                    C:\WINDOWS\system32\pmnnm.dll Has been deleted!

                                    Performing Repairs to the registry.
                                    Done!

                                    Beginning removal...

                                    Attempting to delete C:\WINDOWS\system32\aegckuvw.dll
                                    C:\WINDOWS\system32\aegckuvw.dll Has been deleted!

                                    Performing Repairs to the registry.
                                    Done!
                                    ---------------------------------
                                    C:\Documents and Settings\All Users\Application Data\vajmfsjo.exe moved successfully.

                                    Created on 06/11/2007 18:40:51
                                    0
                                    1. Voilà les rapports Hijack et Virus Total:

                                      Logfile of HijackThis v1.99.1
                                      Scan saved at 19:22:33, on 11/06/2007
                                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                                      Running processes:
                                      C:\WINDOWS\System32\smss.exe
                                      C:\WINDOWS\system32\csrss.exe
                                      C:\WINDOWS\system32\winlogon.exe
                                      C:\WINDOWS\system32\services.exe
                                      C:\WINDOWS\system32\lsass.exe
                                      C:\WINDOWS\system32\Ati2evxx.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\System32\svchost.exe
                                      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                      C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\Ati2evxx.exe
                                      C:\WINDOWS\Explorer.EXE
                                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
                                      C:\WINDOWS\stsystra.exe
                                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                                      C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
                                      C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
                                      C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                                      C:\Program Files\D-Tools\daemon.exe
                                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                      C:\Program Files\SuperCopier2\SuperCopier2.exe
                                      C:\Program Files\Digital Line Detect\DLG.exe
                                      C:\WINDOWS\system32\spoolsv.exe
                                      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      C:\WINDOWS\eHome\ehRecvr.exe
                                      C:\WINDOWS\eHome\ehSched.exe
                                      C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
                                      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\svchost.exe
                                      C:\WINDOWS\system32\wdfmgr.exe
                                      C:\WINDOWS\ehome\mcrdsvc.exe
                                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                      C:\WINDOWS\system32\dllhost.exe
                                      C:\WINDOWS\system32\wbem\wmiprvse.exe
                                      C:\WINDOWS\System32\alg.exe
                                      C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe
                                      C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
                                      C:\Documents and Settings\JM\Bureau\HijackThis.exe

                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://runonce.msn.com/?v=msgrv75
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.dell.com/fr-fr?c=fr&l=fr&s=gen&redirect=1
                                      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.fr/ig/dell?hl=fr&client=dell-row&channel=fr&ibd=5060926
                                      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr
                                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                      O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                                      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
                                      O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
                                      O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
                                      O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
                                      O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
                                      O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\isuspm.exe" -startup
                                      O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start
                                      O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
                                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                      O4 - HKCU\..\Run: [SuperCopier2.exe] C:\Program Files\SuperCopier2\SuperCopier2.exe
                                      O4 - HKCU\..\Run: [Le Petit Robert Hyperappel] C:\Program Files\Le Robert\Le Petit Robert\prhyper.exe
                                      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                      O4 - Global Startup: Digital Line Detect.lnk = ?
                                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                                      O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?9304318fd6ba4c688e3e9758727a8025
                                      O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?9304318fd6ba4c688e3e9758727a8025
                                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
                                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
                                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\WINDOWS\system32\shdocvw.dll
                                      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                                      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                                      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                                      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                      O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
                                      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                                      O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel(R) Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

                                      ----------------------------------------
                                      http://www.virustotal.com/vt/en/resultadof?119b2927dc3bd2a733886bf9849af8aa

                                      Complete scanning result of "prhyper.exe", received in VirusTotal at 06.11.2007, 19:42:25 (CET).
                                      Antivirus Version Update Result
                                      AhnLab-V3 2007.6.12.0 06.11.2007 no virus found
                                      AntiVir 7.4.0.32 06.11.2007 no virus found
                                      Authentium 4.93.8 06.11.2007 no virus found
                                      Avast 4.7.997.0 06.09.2007 no virus found
                                      AVG 7.5.0.467 06.10.2007 no virus found
                                      BitDefender 7.2 06.11.2007 no virus found
                                      CAT-QuickHeal 9.00 06.11.2007 no virus found
                                      ClamAV devel-20070416 06.11.2007 no virus found
                                      DrWeb 4.33 06.11.2007 no virus found
                                      eSafe 7.0.15.0 06.11.2007 no virus found
                                      eTrust-Vet 30.7.3710 06.11.2007 no virus found
                                      Ewido 4.0 06.11.2007 no virus found
                                      FileAdvisor 1 06.11.2007 no virus found
                                      Fortinet 2.85.0.0 06.11.2007 no virus found
                                      F-Prot 4.3.2.48 06.08.2007 no virus found
                                      F-Secure 6.70.13030.0 06.11.2007 no virus found
                                      Ikarus T3.1.1.8 06.11.2007 no virus found
                                      Kaspersky 4.0.2.24 06.11.2007 no virus found
                                      McAfee 5050 06.11.2007 no virus found
                                      Microsoft 1.2503 06.11.2007 no virus found
                                      NOD32v2 2323 06.11.2007 no virus found
                                      Norman 5.80.02 06.11.2007 no virus found
                                      Panda 9.0.0.4 06.11.2007 no virus found
                                      Prevx1 V2 06.11.2007 no virus found
                                      Sophos 4.18.0 06.01.2007 no virus found
                                      Sunbelt 2.2.907.0 06.09.2007 no virus found
                                      Symantec 10 06.11.2007 no virus found
                                      TheHacker 6.1.6.132 06.11.2007 no virus found
                                      VBA32 3.12.0.1 06.11.2007 no virus found
                                      VirusBuster 4.3.23:9 06.11.2007 no virus found
                                      Webwasher-Gateway 6.0.1 06.11.2007 no virus found

                                      Aditional Information
                                      File size: 22560 bytes
                                      MD5: baf49f90f6f5c212f16a3953335ed8a6
                                      SHA1: 7500eda1105641101371a4b601c789f7bc5cc54e
                                      0
                                      1. Contributeur sécurité
                                        cela me semble pas trop mal tout cela
                                        comment va le PC?

                                        si tout va bien supprime tout ce qu'on a utilisé car ce ne sera plus utile désormais
                                        passe un coup de ccleaner
                                        https://www.pcastuces.com/logitheque/ccleaner.htm
                                        faire un scan antivirus en ligne avec internet explorer et accepter l'activex
                                        poster le rapport ici ensuite
                                        https://www.bitdefender.fr/

                                        En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
                                        Dans la nouvelle fenêtre, clique sur I agree
                                        La fenêtre change encore, clique sur Click here to scan
                                        Les signatures se chargent, etc.

                                        tuto en image
                                        http://pageperso.aol.fr/rginformatique/mapage/defender.htm
                                        0
                                        • 1
                                        • 2