[rapport bitdefender] comment désinfecter ?

Résolu
bonjour, suite au rapport du scan bitdefender, je vois mon pc est infecté...
je ne sais pas comment supprimer ces virus, si quelqu'un peut m'aider pour la désinfection ?
merci
voici le résultat du scan :

BitDefender Online Scanner

Scan report generated at: Wed, Aug 22, 2007 - 11:36:13

Scan path: C:\;D:\;E:\;F:\;

Statistics

Time

01:50:28

Files

485871

Folders

8872

Boot Sectors

3

Archives

18405

Packed Files

32229

Results

Identified Viruses

3

Infected Files

3

Suspect Files

0

Warnings

0

Disinfected

0

Deleted Files

3

Engines Info

Virus Definitions

749495

Engine build

AVCORE v1.0 (build 2411) (i386) (Jul 9 2007 12:10:22)

Scan plugins

14

Archive plugins

37

Unpack plugins

6

E-mail plugins

6

System plugins

1

Scan Settings

First Action

Disinfect

Second Action

Delete

Heuristics

Yes

Enable Warnings

Yes

Scanned Extensions

*;

Exclude Extensions

Scan Emails

Yes

Scan Archives

Yes

Scan Packed

Yes

Scan Files

Yes

Scan Boot

Yes

Scanned File

Status

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6126757C.exe=>(Quarantine-2)=>(CAB Sfx r)=>myplaycity_WhenUSave_Installer.exe

Infected with: Generic.Adw.SaveNow.F4BE966D

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6126757C.exe=>(Quarantine-2)=>(CAB Sfx r)=>myplaycity_WhenUSave_Installer.exe

Disinfection failed

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6126757C.exe=>(Quarantine-2)=>(CAB Sfx r)=>myplaycity_WhenUSave_Installer.exe

Deleted

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6126757C.exe=>(Quarantine-2)=>(CAB Sfx r)

Update failed

C:\WINDOWS\system32\omemkz.exe

Infected with: Trojan.Skintrim.AFI

C:\WINDOWS\system32\omemkz.exe

Disinfection failed

C:\WINDOWS\system32\omemkz.exe

Deleted

C:\WINDOWS\system32\viywrjmv.exe

Infected with: Trojan.Skintrim.AFO

C:\WINDOWS\system32\viywrjmv.exe

Disinfection failed

C:\WINDOWS\system32\viywrjmv.exe

Deleted
Configuration: Windows XP
Firefox 2.0.0.6

23 réponses

  1. voici le rapport hijackthis :
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:30:14, on 22/08/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\arservice.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\ARPWRMSG.EXE
    C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
    C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\USB Disk Win98 Driver\Res.EXE
    C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Mio Technology\MioSync\mioSync.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\HP\KBD\KBD.EXE
    c:\windows\system\hpsysdrv.exe
    C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\Microsoft Encarta\Collection Encarta 2004 DVD\EDICT.EXE
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=hp-desktop.msn.com&ocid=HPDHP&pc=HPDTDF
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: MioSync.lnk = C:\Program Files\Mio Technology\MioSync\mioSync.exe
    O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
    O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    0
    1. Contributeur sécurité
      Salut

      Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
      et sauvegarde le sur ton bureau et pas ailleurs!

      Double-clic sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.
      Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
      0
      1. bonjour et merci de me venir en aide.
        en faisant double clic sur combofix, avast trouve un cheval de troie "Win32:Dadobra-EY [Trj]" dans le fichier "C:\ComboFix\Cfiles.cf".
        que dois je faire ?
        0
        1. Contributeur sécurité
          Salut

          Ignore le c est un faux positif, tu peux me faire confiance.

          A+
          0
          1. voici le rapport combofix
            ComboFix 07-08-17.2 - "HP_Administrateur" 2007-08-22 14:26:19.1 - NTFSx86
            Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.294 [GMT 2:00]
            * Created a new restore point

            ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

            D:\Autorun.inf

            ((((((((((((((((((((((((( Files Created from 2007-07-22 to 2007-08-22 )))))))))))))))))))))))))))))))

            2007-08-22 13:59 51,200 --a------ C:\WINDOWS\nircmd.exe
            2007-08-12 07:03 <REP> d-------- C:\DOCUME~1\HP_ADM~1\.housecall6.6
            2007-07-29 11:04 7,340,032 --a------ C:\DOCUME~1\HP_ADM~1\ntuser.dat
            2007-07-28 14:09 <REP> d-------- C:\DOCUME~1\HP_ADM~1\APPLIC~1\OpenOffice.org2
            2007-07-28 10:51 <REP> d-------- C:\Program Files\OpenOffice.org 2.2
            2007-07-27 16:18 <REP> d-------- C:\WINDOWS\BDOSCAN8
            2007-07-25 23:20 3,908 --a------ C:\WINDOWS\system32\tmp.reg
            2007-07-25 23:10 53,248 --a------ C:\WINDOWS\system32\Process.exe
            2007-07-25 23:10 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
            2007-07-25 23:10 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
            2007-07-22 17:55 <REP> d-------- C:\Program Files\SpywareBlaster

            (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

            2007-08-15 01:36 --------- d-------- C:\Program Files\Pure Pinball 2.0 REDUX
            2007-08-08 07:43 --------- d-------- C:\Program Files\eMule
            2007-07-28 10:43 --------- d-------- C:\Program Files\OpenOffice.org1.1.4
            2007-07-28 00:07 783224 --a------ C:\WINDOWS\system32\aswBoot.exe
            2007-07-28 00:02 94416 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
            2007-07-28 00:02 92848 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
            2007-07-28 00:00 23152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
            2007-07-27 23:59 42912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
            2007-07-27 23:58 26624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
            2007-07-27 23:57 95608 --a------ C:\WINDOWS\system32\AVASTSS.scr
            2007-07-19 22:45 --------- d-------- C:\DOCUME~1\HP_ADM~1\APPLIC~1\dvdcss
            2007-07-19 14:32 --------- d-------- C:\Program Files\Trend Micro
            2007-07-19 08:58 3583488 --a------ C:\WINDOWS\system32\dllcache\mshtml.dll
            2007-07-18 21:42 --------- d-------- C:\Program Files\Fichiers communs\Teleca Shared
            2007-07-17 21:21 --------- d-------- C:\DOCUME~1\HP_ADM~1\APPLIC~1\Lavasoft
            2007-07-17 21:19 --------- d-------- C:\Program Files\Lavasoft
            2007-07-17 07:05 --------- d-------- C:\DOCUME~1\HP_ADM~1\APPLIC~1\vlc
            2007-07-17 06:55 --------- d-------- C:\Program Files\VideoLAN
            2007-07-14 13:01 --------- d-------- C:\Program Files\LM Version-2.5-F
            2007-07-13 01:30 765952 --a------ C:\WINDOWS\system32\dllcache\vgx.dll
            2007-07-09 22:05 261120 --a------ C:\WINDOWS\system32\jnqkwbb.exe
            2007-07-06 03:30 --------- d-------- C:\Program Files\CCleaner
            2007-06-27 15:24 823808 --a------ C:\WINDOWS\system32\dllcache\wininet.dll
            2007-06-27 15:24 671232 --a------ C:\WINDOWS\system32\dllcache\mstime.dll
            2007-06-27 15:24 477696 --a------ C:\WINDOWS\system32\dllcache\mshtmled.dll
            2007-06-27 15:24 232960 --a------ C:\WINDOWS\system32\dllcache\webcheck.dll
            2007-06-27 15:24 193024 --a------ C:\WINDOWS\system32\dllcache\msrating.dll
            2007-06-27 15:24 1152000 --a------ C:\WINDOWS\system32\dllcache\urlmon.dll
            2007-06-27 15:24 105984 --a------ C:\WINDOWS\system32\dllcache\url.dll
            2007-06-27 15:24 102400 --a------ C:\WINDOWS\system32\dllcache\occache.dll
            2007-06-27 15:23 6058496 --------- C:\WINDOWS\system32\dllcache\ieframe.dll
            2007-06-27 15:23 52224 --------- C:\WINDOWS\system32\dllcache\msfeedsbs.dll
            2007-06-27 15:23 459264 --------- C:\WINDOWS\system32\dllcache\msfeeds.dll
            2007-06-27 15:23 44544 --a------ C:\WINDOWS\system32\dllcache\iernonce.dll
            2007-06-27 15:23 27648 --a------ C:\WINDOWS\system32\dllcache\jsproxy.dll
            2007-06-27 15:23 267776 --------- C:\WINDOWS\system32\dllcache\iertutil.dll
            2007-06-27 15:22 384512 --a------ C:\WINDOWS\system32\dllcache\iedkcs32.dll
            2007-06-27 15:22 383488 --------- C:\WINDOWS\system32\dllcache\ieapfltr.dll
            2007-06-27 15:22 230400 --a------ C:\WINDOWS\system32\dllcache\ieaksie.dll
            2007-06-27 15:22 153088 --a------ C:\WINDOWS\system32\dllcache\ieakeng.dll
            2007-06-27 15:22 132608 --a------ C:\WINDOWS\system32\dllcache\extmgr.dll
            2007-06-27 15:22 124928 --a------ C:\WINDOWS\system32\dllcache\advpack.dll
            2007-06-27 10:28 625152 --a------ C:\WINDOWS\system32\dllcache\iexplore.exe
            2007-06-27 10:27 63488 --a------ C:\WINDOWS\system32\dllcache\ie4uinit.exe
            2007-06-27 10:27 13824 --------- C:\WINDOWS\system32\dllcache\ieudinit.exe
            2007-06-27 09:00 161792 --a------ C:\WINDOWS\system32\dllcache\ieakui.dll
            2007-06-26 08:09 1104896 --a------ C:\WINDOWS\system32\msxml3.dll
            2007-06-26 08:09 1104896 --a------ C:\WINDOWS\system32\dllcache\msxml3.dll
            2007-06-22 15:15 --------- d--h----- C:\Program Files\InstallShield Installation Information
            2007-06-22 15:14 --------- d-------- C:\Program Files\QuickTime
            2007-06-22 15:11 --------- d-------- C:\Program Files\Web Media Player
            2007-06-22 14:05 --------- d-------- C:\Program Files\DivX
            2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\gdi32.dll
            2007-06-19 15:32 282112 --a------ C:\WINDOWS\system32\dllcache\gdi32.dll
            2007-06-13 15:22 1037312 --a------ C:\WINDOWS\system32\dllcache\explorer.exe
            2007-06-13 15:22 1037312 --a------ C:\WINDOWS\explorer.exe
            2007-06-12 07:20 401408 --a------ C:\WINDOWS\system32\hjocscqx.exe
            2007-06-11 23:51 10834944 --a------ C:\WINDOWS\system32\dllcache\wmp.dll
            2007-03-11 23:47 3947008 --ahs---- C:\Program Files\ehthumbs.db
            2006-02-19 10:28 12288 --a------ C:\WINDOWS\Fonts.\RandFont.dll
            2006-11-26 13:48:06 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys

            ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

            *Note* empty entries & legit default entries are not shown

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 20:34]
            "ftutil2"="ftutil2.dll" [2004-06-07 14:05 C:\WINDOWS\system32\ftutil2.dll]
            "RTHDCPL"="RTHDCPL.EXE" [2006-07-22 01:56 C:\WINDOWS\RTHDCPL.EXE]
            "AlwaysReady Power Message APP"="ARPWRMSG.EXE" [2005-08-03 02:15 C:\WINDOWS\arpwrmsg.exe]
            "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-05-10 00:50]
            "nwiz"="nwiz.exe" [2006-05-10 00:50 C:\WINDOWS\system32\nwiz.exe]
            "DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 09:05]
            "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 22:14]
            "HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 22:34]
            "HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2006-02-19 03:41]
            "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-07-28 00:03]
            "USB Storage Toolbox"="C:\Program Files\USB Disk Win98 Driver\Res.EXE" [2005-09-14 20:44]
            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 04:00]
            "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-03-09 00:02]
            "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25]
            "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-09-12 05:40]
            "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50]

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 13:00]
            "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-13 15:09]
            "MsnMsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]

            C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
            HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 05:21:22]
            MioSync.lnk - C:\Program Files\Mio Technology\MioSync\mioSync.exe [2007-05-04 22:08:18]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
            "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
            "InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

            R0 VOBID;VOBID;C:\WINDOWS\system32\DRIVERS\vobid.sys
            R1 vobiw;vobiw;C:\WINDOWS\system32\drivers\vobiw.sys
            R3 CAM1210;USB Video Camera;C:\WINDOWS\system32\Drivers\cam1210.sys
            R3 cdrdrv;Cdrdrv;C:\WINDOWS\system32\Drivers\Cdrdrv.sys
            S2 DVC120;Dazzle DVC120;C:\WINDOWS\system32\Drivers\dvc120.sys
            S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
            S3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

            Contents of the 'Scheduled Tasks' folder
            2007-07-28 12:02:24 C:\WINDOWS\Tasks\Connexion facile à Internet.job
            2007-08-22 12:28:23 C:\WINDOWS\Tasks\DMATask 0 {D2B22905-47C9-4b82-8E74-47AA9D2DE378} 0~0.job - c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe

            **************************************************************************

            catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2007-08-22 14:29:15
            Windows 5.1.2600 Service Pack 2 NTFS

            scanning hidden processes ...

            scanning hidden autostart entries ...

            scanning hidden files ...

            scan completed successfully
            hidden files: 0

            **************************************************************************

            Completion time: 2007-08-22 14:30:12
            C:\ComboFix-quarantined-files.txt ... 2007-08-22 14:29

            --- E O F ---
            0
            1. Contributeur sécurité
              ok

              Fais un clic droit sur ce lien :
              http://perso.orange.fr/il.mafioso/Navifix/Navilog1.zip
              Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
              Fais un clic droit sur navilog1.zip et choisis "tout extraire"
              Ensuite double clique sur navilog1.exe pour lancer l'installation.
              Une fois l'installation terminée, le fix s'exécutera automatiquement.
              (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

              Laisse-toi guider. Au menu principal, choisis 1 et valides.
              (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
              Patiente jusqu'au message :
              *** Analyse Termine le ..... ***
              Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
              Copie-colle l'intégralité dans une réponse. Referme le blocnote.
              Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

              A+
              0
              1. mission accomplie, voici le rapport navilog1 :
                Search Navipromo version 2.0.9 commencé le 22/08/2007 à 15:06:16,18

                !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                !!! Poster ce rapport sur le forum pour le faire analyser !!!
                !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

                Fix lancé depuis C:\Program Files\navilog1
                Mise a jour le 20.08.2007 a 22h30 by IL-MAFIOSO

                Executé en mode normal

                *** Recherche Programmes installes ***

                *** Recherche dossiers dans C:\WINDOWS ***

                *** Recherche dossiers dans C:\Program Files ***

                *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

                *** Recherche dossiers dans C:\Documents and Settings\HP_Administrateur\Application Data ***

                *** Recherche avec BlackLight Engine/F-secure ***
                BlackLight Engine est un produit de F-secure, pour + d'infos :
                https://www.f-secure.com/en

                F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
                ======================================

                Copyright 2005-2006 F-Secure Corporation. All rights reserved.
                This is a beta version. It will expire on 1st of October, 2007.
                Version information: 2.2.1064.

                [+] Started on 08/22/07 at 15:06:18.
                [+] Initializing ...
                [+] Starting scan, press Ctrl-C to abort.
                [+] Scanning for hidden items .....................................................................................................................
                [+] Scan complete.
                [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
                [+] Exited on 08/22/07 at 15:20:06 (return code = 0).

                *** Recherche avec GenericNaviSearch ***
                !!! Tous Ces résultats peuvent révéler des fichiers légitimes !!!
                !!! A verifier impérativement avant toute suppression manuelle !!!

                Fichiers trouvés :

                C:\WINDOWS\system32\jnqkwbb.exe trouvé !

                Fichiers suspects :

                Aucun Fichier suspect trouvé !

                *** Recherche fichiers ***

                *** Recherche cles registre ***

                Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

                Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

                Recherche Clé Magic Control

                *** Module de Recherche complémentaire ***
                (Recherche fichiers spécifiques)

                1)Recherche fichiers connus:

                2)Recherche Heuristique :
                *
                **
                ***
                ****
                *****
                ******
                *******
                ********

                3)Recherche Certificats :

                Certificat Egroup absent !

                *** Analyse Terminé le 22/08/2007 à 15:21:55,32 ***
                0
                1. Contributeur sécurité
                  Ok

                  Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
                  Au menu principal, choisis 4 et valide.

                  Le fix va te demander de saisir le nom de fichier.
                  Saisies ce qui est en gras ci-dessous et rien d'autre puis valide:

                  jnqkwbb

                  Le fix va te demander de le resaisir, fais-le et valide

                  Le fix va t'informer qu'il va alors redémarrer ton PC
                  Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
                  Appuie sur une touche comme demandé.
                  (si ton Pc ne redémarre pas automatiquement, fais le toi même)
                  Au redémarrage de ton PC, choisis ta session habituelle.

                  Patiente jusqu'au message :
                  *** Nettoyage Termine le ..... ***
                  Le blocnote va s'ouvrir.
                  Sauvegarde le rapport de manière à le retrouver
                  Referme le blocnote. Ton bureau va réapparaitre

                  PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
                  Puis rends-toi à l'onglet "processus". Cliques en haut à gauche sur fichiers et choisis "exécuter"
                  Tapes explorer et valides. Celà te fera apparaitre ton bureau

                  A+
                  0
                  1. je te mets le resultat :

                    Clean Navipromo version 2.0.9 commencé le 22/08/2007 à 15:56:07,50

                    Fix lancé depuis C:\Program Files\navilog1
                    Mise a jour le 20.08.2007 a 22h30 by IL-MAFIOSO

                    Mode suppression par méthode manuelle

                    Nom du fichier saisi : jnqkwbb

                    *** Recherche, Creation backups et suppression ***

                    C:\WINDOWS\system32\jnqkwbb.dat absent !
                    C:\WINDOWS\system32\jnqkwbb_nav.dat absent !
                    C:\WINDOWS\system32\jnqkwbb_navps.dat absent !
                    C:\WINDOWS\system32\jnqkwbb_navup.dat absent !
                    C:\WINDOWS\system32\jnqkwbb_navtmp.dat absent !
                    C:\WINDOWS\system32\jnqkwbb_m2s.xml absent !
                    C:\WINDOWS\prefetch\jnqkwbb*.pf absent !

                    C:\WINDOWS\System32\jnqkwbb.exe trouvé !
                    Copie C:\WINDOWS\system32\jnqkwbb.exe réalise avec succes !
                    C:\WINDOWS\system32\jnqkwbb.exe supprimé !

                    *** Recherche avec GenericNaviSearch ***
                    !!! Ces résultats peuvent révéler des fichiers légitimes !!!
                    !!! A verifier impérativement avant toute suppression manuelle !!!

                    Fichiers trouvés supprimés avec backups :

                    Aucun Fichier trouvé !

                    Fichiers suspects :

                    Aucun Fichier suspect trouvé !

                    *** Suppression dossiers dans C:\WINDOWS ***

                    *** Suppression dossiers dans C:\Program Files ***

                    *** Suppression dossiers dans C:\Documents and Settings\All Users\Application Data ***

                    *** Suppression dossiers dans C:\Documents and Settings\HP_Administrateur\Application Data ***

                    *** Suppression fichiers ***

                    *** Suppression fichiers temporaires ***

                    Nettoyage contenu C:\WINDOWS\Temp effectué !
                    Nettoyage contenu C:\Documents and Settings\HP_Administrateur\Local Settings\Temp effectué !

                    *** Traitement Recherche complémentaire ***
                    (Recherche fichiers spécifiques)

                    1)Recherche fichiers connus:

                    2)Recherche et Suppression Heuristique :

                    *
                    **
                    ***
                    ****
                    *****
                    ******
                    *******
                    ********

                    3)Certificats :

                    Certificat Egroup absent !

                    *** Sauvegarde du registre vers dossier Backupnavi ***

                    sauvegarde du registre réalise avec succes !

                    *** Nettoyage registre ***

                    Erreur application fixreg

                    Le registre n'a pas été nettoyé !

                    *** Nettoyage termine le 22/08/2007 à 16:03:32,01 ***
                    0
                    1. Contributeur sécurité
                      Ok, remet un Hijackthis + un combofix

                      a+
                      0
                      1. je dois m'absenter, si tu peux me donner les instructions à suivre, ça serait cool.
                        je ferais les manip ce soir en rentrant.
                        sincèrement merci pour ta disponibilité et ton aide
                        0
                        1. voici le nouveau rapport hijackthis :
                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 16:36:50, on 22/08/2007
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v7.00 (7.00.6000.16512)
                          Boot mode: Normal

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\arservice.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          C:\WINDOWS\eHome\ehRecvr.exe
                          C:\WINDOWS\eHome\ehSched.exe
                          C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          C:\WINDOWS\system32\nvsvc32.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\WINDOWS\system32\dllhost.exe
                          C:\WINDOWS\ehome\ehtray.exe
                          C:\WINDOWS\eHome\ehmsas.exe
                          C:\WINDOWS\RTHDCPL.EXE
                          C:\WINDOWS\ARPWRMSG.EXE
                          C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe
                          C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\Program Files\USB Disk Win98 Driver\Res.EXE
                          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
                          C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                          C:\WINDOWS\system32\ctfmon.exe
                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          C:\Program Files\Mio Technology\MioSync\mioSync.exe
                          C:\Program Files\Microsoft Encarta\Collection Encarta 2004 DVD\EDICT.EXE
                          C:\Program Files\Mozilla Firefox\firefox.exe
                          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                          C:\HP\KBD\KBD.EXE
                          c:\windows\system\hpsysdrv.exe
                          C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://fr.search.yahoo.com/?fr=cb-hp06
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = https://fr.search.yahoo.com/?fr=cb-hp06
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
                          O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                          O4 - HKLM\..\Run: [ftutil2] rundll32.exe ftutil2.dll,SetWriteCacheMode
                          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                          O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"
                          O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                          O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                          O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [USB Storage Toolbox] C:\Program Files\USB Disk Win98 Driver\Res.EXE
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
                          O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                          O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
                          O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')
                          O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                          O4 - Global Startup: MioSync.lnk = C:\Program Files\Mio Technology\MioSync\mioSync.exe
                          O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
                          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
                          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                          O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
                          O9 - Extra button: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                          O9 - Extra 'Tools' menuitem: Aide à la connexion - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                          O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                          O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u2-windows-i586-jc.cab
                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                          O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                          O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                          0
                          1. Contributeur sécurité
                            Ok.

                            Moi aussi je dois m absenter...

                            Vas sur le site https://virusscan.jotti.org/
                            - Clic en haut à droite sur "Parcourir", navigue dans les dossiers et sélectionne ce fichier : C:\WINDOWS\system32\hjocscqx.exe
                            - Clic sur submit toujours en haut à droite
                            - Le scan va se lancer, ça va prendre un petit instant
                            - En bas, tu as le résultat du scan, copie/colle le résultat complet du scan ici.
                            Aide : https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId662799

                            A+
                            0
                            1. voici le rapport du scan du fichier "C:\WINDOWS\system32\hjocscqx.exe"

                              Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1
                              File to upload & scan: Virus

                              Service
                              Service load:
                              0% 100%
                              File: hjocscqx.exe
                              Status:
                              INFECTED/MALWARE
                              MD5: 6d470ec95de4f97bb6e9e04012656793
                              Packers detected:
                              PE_PATCH
                              Bit9 reports: File not found
                              Scanner results
                              Scan taken on 22 Aug 2007 20:11:36 (GMT)
                              A-Squared
                              Found nothing
                              AntiVir
                              Found ADSPY/Navipromo.LH.1
                              ArcaVir
                              Found Heur.W32
                              Avast
                              Found nothing
                              AVG Antivirus
                              Found nothing
                              BitDefender
                              Found nothing
                              ClamAV
                              Found nothing
                              CPsecure
                              Found nothing
                              Dr.Web
                              Found nothing
                              F-Prot Antivirus
                              Found nothing
                              F-Secure Anti-Virus
                              Found nothing
                              Fortinet
                              Found nothing
                              Kaspersky Anti-Virus
                              Found nothing
                              NOD32
                              Found nothing
                              Norman Virus Control
                              Found nothing
                              Panda Antivirus
                              Found nothing
                              Rising Antivirus
                              Found Trojan.Win32.Skintrim.g
                              Sophos Antivirus
                              Found nothing
                              VirusBuster
                              Found nothing
                              VBA32
                              Found nothing

                              Powered by
                              images/asquared.png images/antivir.png images/arcabit.png images/avast.png images/avg.gif images/bitdefender.png images/clamav-logo1.png images/cpsecure.gif images/drweb.gif images/f-prot.png images/f-secure_logo.gif images/fortinet.gif images/kaspersky.png images/nod32.gif images/norman.png images/panda.png images/rising.gif images/sophos.gif images/virusbuster.gif images/vba32.png Bit9
                              Disclaimer
                              This service is by no means 100% safe. If this scanner says 'OK', it does not necessarily mean the file is clean. There could be a whole new virus on the loose. NEVER EVER rely on one single product only, not even this service, even though it utilizes several products. Therefore, We cannot and will not be held responsible for any damage caused by results presented by this non-profit online service.

                              Also, we are aware of the implications of a setup like this. We are sure this whole thing is by no means scientifically correct, since this is a fully automated service (although manual correction is possible). We are aware, in spite of efforts to proactively counter these, false positives might occur, for example. We do not consider this a very big issue, so please do not e-mail us about it. This is a simple online scan service, not the university of Wichita.

                              Scanning can take a while, since several scanners are being used, plus the fact some scanners use very high levels of (time consuming) heuristics. Scanners used are Linux versions, differences with Windows scanners may or may not occur. Another note: some scanners will only report one virus when scanning archives with multiple pieces of malware.

                              Virus definitions are updated every hour. There is a 10Mb limit per file. Please refrain from uploading tons of hex-edited or repacked variants of the same sample.

                              Please do not ask for viruses uploaded here, unless you work for an anti-virus vendor. They are not for trade. This is a legitimate service, not a VX site. Viruses uploaded here will be distributed to antivirus vendors without exception. Read more about this in our privacy policy. If you do not want your files to be distributed, please do not send them at all.

                              Sponsored by donations (in random order) from: Stormbyte Technologies LLC, The ClamAV project, Steve S., Eric Johansen, Eric Schechter, Paul Bokel, Wilders Security, Wilfried Lilie, Prevx, SonicWALL, Lance Mueller, Ewido networks, HotelScraper.com, people who donated in the past, and some people who prefer to remain anonymous... many thanks to all!
                              Statistics
                              Last file scanned at least one scanner reported something about: b7d3a1fce301f8cff0a971068ce9788f (MD5: b7d3a1fce301f8cff0a971068ce9788f, size: 61440 bytes), detected by:

                              Scanner Malware name
                              A-Squared X
                              AntiVir W32/Virut.P
                              ArcaVir Trojan.Downloader.Agent.Bys
                              Avast Win32:Agent-JQL
                              AVG Antivirus X
                              BitDefender Win32.Virtob.2.Gen
                              ClamAV Virut.set1.00
                              CPsecure Troj.Downloader.W32.Agent.bys
                              Dr.Web Win32.Virut.5
                              F-Prot Antivirus X
                              F-Secure Anti-Virus Trojan-Downloader.Win32.Agent.bys
                              Fortinet X
                              Kaspersky Anti-Virus Trojan-Downloader.Win32.Agent.bys
                              NOD32 Win32/Virut.NAK
                              Norman Virus Control X
                              Panda Antivirus X
                              Rising Antivirus Trojan.DL.Mnless.zq
                              Sophos Antivirus W32/Vetor-C
                              VirusBuster Win32.Virut.Gen
                              VBA32 X

                              You're free to (mis)interpret these automated, flawed statistics at your own discretion. For antivirus comparisons, visit AV comparatives
                              We are not affiliated with any third parties that conduct tests using this service.

                              Frequently asked questions - Feedback - Privacy policy

                              Debian

                              Page generated by JTPL

                              Copyright © 2004-2007 Jordi Bosveld <jotti@jotti.org>

                              j' ai copié/collé toute la page du résultat du scan pour être sûre de ne rien oublier.
                              en attendant tes prochaines instructions, passe une bonne soirée
                              0
                              1. Contributeur sécurité
                                Ok

                                Passé une bonne soirée?

                                télécharge OTMoveIt http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe (de Old_Timer) sur ton Bureau.
                                double-clique sur OTMoveIt.exe pour le lancer.
                                copie la liste qui se trouve ci-dessous,
                                et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                                C:\WINDOWS\system32\hjocscqx.exe

                                clique sur MoveIt! pour lancer la suppression.
                                le résultat apparaitra dans le cadre "Results".
                                clique sur Exit pour fermer.
                                poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                                A+
                                0
                                1. contente de te retrouver.
                                  voici le rapport OTMoveIt :

                                  C:\WINDOWS\system32\hjocscqx.exe moved successfully.

                                  Created on 08/22/2007 23:35:26
                                  0
                                  1. Contributeur sécurité
                                    Salut

                                    Ou en sont tes soucis?

                                    A+
                                    0
                                    1. je n'en sais rien, je n'ai pas eu le temps de m' en rendre compte.
                                      tu crois qu'on les a pulvérisés ces virus ?
                                      0
                                      1. Contributeur sécurité
                                        Re,

                                        a toi de me dire si tu n as plus de soucis :)

                                        A demain , bonne nuit.
                                        0
                                        1. je te tiens au courant.
                                          encore merci, c'est super sympa de m'avoir dépannée.
                                          bonne nuit
                                          0
                                          • 1
                                          • 2