Pubs intempestves

kevin596 -  
g!rly Messages postés 18462 Statut Contributeur -
Bonjour,depuiq quelques semaines j'ai l'impression que mon pc rame quelque peu.En plus de cela j'ai souvent des pubs quand je vais sur le net (spyware secure souvent) donc je voudrais que qqn m'aide à régler ce probleme!merci d'avance!

Search Navipromo version 3.3.7 commencé le 11/12/2007 à 14:03:47,59

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 08.12.2007 à 16h00 par IL-MAFIOSO

Microsoft Windows XP [version 5.1.2600]
Internet Explorer : 7.0.5730.11
Système de fichiers : NTFS

Executé en mode normal

*** Recherche Programmes installés ***

InternetGameBox

*** Recherche dossiers dans C:\WINDOWS ***

*** Recherche dossiers dans C:\Program Files ***

C:\Program Files\InternetGameBox trouvé !

*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

*** Recherche dossiers dans "C:\Documents and Settings\kevin.ALLART\application data" ***

*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Fichier(s) caché(s) :

C:\WINDOWS\system32\wtsxqjzmz.dat
C:\WINDOWS\system32\wtsxqjzmz.exe
C:\WINDOWS\system32\wtsxqjzmz_nav.dat
C:\WINDOWS\system32\wtsxqjzmz_navps.dat

*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans C:\WINDOWS\system32 *

* Recherche dans "C:\Documents and Settings\kevin.ALLART\local settings\application data" *

*** Recherche fichiers ***

c:\documents and settings\kevin.allart\bureau\InternetGameBox.lnk trouvé !
C:\WINDOWS\Downloaded Program Files\EGAUTH.inf trouvé !
C:\WINDOWS\Downloaded Program Files\EGDACCESS.inf trouvé !
C:\WINDOWS\Downloaded Program Files\EGDACCESS_ASPIV4.inf trouvé !
C:\WINDOWS\Downloaded Program Files\sysnetsvc32.inf trouvé !
C:\WINDOWS\Downloaded Program Files\syswbsvc32.inf trouvé !
C:\WINDOWS\Downloaded Program Files\sysiasvc32.inf trouvé !
C:\WINDOWS\tmlpcert2007 trouvé !
C:\WINDOWS\system32\nvs2.inf trouvé !
C:\WINDOWS\prefetch\INTERNETGAMEBOX.EXE-151FE1D3.pf trouvé !

*** Recherche clés spécifiques dans le Registre ***

*** Module de Recherche complémentaire ***
(Recherche fichiers spécifiques)

1)Recherche fichiers connus :

2)Recherche Heuristique :

* Dans C:\WINDOWS\system32 :

wtsxqjzmz.dat trouvé !

* Dans "C:\Documents and Settings\kevin.ALLART\local settings\application data" :

3)Recherche Certificats :

Certificat Egroup trouvé !

*** Analyse terminée le 11/12/2007 à 14:13:41,48 ***

27 réponses

kevin596
 
bonsoir,voici le rapport de combofix

ComboFix 07-12-12.3 - kevin 2007-12-12 18:25:57.1 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.142 [GMT 1:00]
Running from: C:\Downloads\ComboFix.exe
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\Fichiers communs\{584E7~1
C:\WINDOWS\IA
C:\WINDOWS\system32\winnb58.dll
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_FOPF

((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-12 to 2007-12-12 ))))))))))))))))))))))))))))))))))))
.

2007-12-12 15:53 . 2007-12-12 15:54 1,393 --a------ C:\WINDOWS\imsins.BAK
2007-12-11 18:05 . 2007-12-11 18:05 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\Grisoft
2007-12-11 18:05 . 2007-12-11 18:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-11 18:05 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-12-11 17:51 . 2007-12-11 17:51 <REP> d-------- C:\Program Files\Avira
2007-12-11 17:51 . 2007-12-11 17:51 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
2007-12-11 17:41 . 2007-12-11 17:41 <REP> d-------- C:\Program Files\Sunbelt Software
2007-12-11 15:55 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
2007-12-11 15:37 . 2007-12-11 15:37 13,233,454 --a------ C:\upload_moi_ALLART.tar.gz
2007-12-11 14:01 . 2007-12-11 21:44 <REP> d-------- C:\Program Files\Navilog1
2007-12-09 00:29 . 2007-12-09 00:29 <REP> d-------- C:\Program Files\Change Extension
2007-12-09 00:29 . 2007-12-09 00:29 88,064 --a------ C:\WINDOWS\AMUninst01c.exe
2007-12-08 16:08 . 2007-12-08 16:10 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\DeepBurner
2007-12-08 12:01 . 2007-12-09 19:32 <REP> d-------- C:\Program Files\Incomplete
2007-12-08 09:33 . 2007-12-08 19:14 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2007-12-08 09:33 . 2007-12-08 09:33 1,409 --a------ C:\WINDOWS\QTFont.for
2007-12-06 22:44 . 2007-12-06 22:44 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
2007-12-06 22:43 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp59C06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp58C06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp4DC06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp21D06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp15D06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp13D06.FOT
2007-12-06 17:56 . 2007-12-06 17:56 1,409 --a------ C:\WINDOWS\system32\tmp06D06.FOT
2007-12-05 14:22 . 2007-12-05 14:34 <REP> d-------- C:\Program Files\AlienSky
2007-12-04 23:50 . 2007-12-05 16:31 <REP> d-------- C:\Program Files\Zone.com Deluxe Games
2007-12-04 17:11 . 2007-12-04 17:11 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\Windows Live Writer
2007-12-02 19:12 . 2007-12-02 19:13 <REP> d-------- C:\WINDOWS\AU_Temp
2007-12-02 17:22 . 2007-12-02 17:22 <REP> d-------- C:\WINDOWS\report
2007-12-02 17:22 . 2007-12-02 17:21 39,801,177 --a------ C:\WINDOWS\LPT$VPN.855
2007-12-02 17:21 . 2007-12-02 19:13 <REP> d-------- C:\WINDOWS\AU_Backup
2007-12-02 17:21 . 2007-12-02 17:21 39,801,177 --a------ C:\WINDOWS\VPTNFILE.855
2007-12-02 17:21 . 2007-12-02 17:21 1,899,383 --a------ C:\WINDOWS\tsc.ptn
2007-12-02 17:21 . 2007-12-02 19:13 1,163,344 --a------ C:\WINDOWS\vsapi32.dll
2007-12-02 17:21 . 2007-12-02 17:21 267,845 --a------ C:\WINDOWS\tsc.exe
2007-12-02 17:21 . 2007-12-02 19:13 86,094 --a------ C:\WINDOWS\BPMNT.dll
2007-12-02 17:21 . 2007-12-02 17:21 71,749 --a------ C:\WINDOWS\hcextoutput.dll
2007-12-02 17:21 . 2007-12-02 19:13 823 --a------ C:\WINDOWS\tsc.ini
2007-12-02 17:13 . 2007-12-02 17:13 <REP> d-------- C:\WINDOWS\AU_Log
2007-12-02 17:13 . 2007-12-02 17:13 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
2007-12-02 17:13 . 2007-12-02 17:13 286,720 --a------ C:\WINDOWS\PATCH.EXE
2007-12-02 17:13 . 2007-12-02 17:13 69,689 --a------ C:\WINDOWS\UNZIP.DLL
2007-12-02 17:13 . 2007-12-02 19:12 170 --a------ C:\WINDOWS\GetServer.ini
2007-12-02 15:11 . 2006-11-29 13:06 3,426,072 --a------ C:\WINDOWS\system32\d3dx9_32.dll
2007-12-02 15:09 . 2007-12-02 15:09 <REP> d-------- C:\Program Files\Microsoft SQL Server Compact Edition
2007-12-02 14:52 . 2007-12-02 14:55 <REP> d--hsc--- C:\Program Files\Fichiers communs\WindowsLiveInstaller
2007-11-30 18:02 . 2004-01-02 01:04 <REP> d-------- C:\Documents and Settings\Administrateur\WINDOWS
2007-11-30 18:02 . 2004-01-01 23:45 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
2007-11-30 18:02 . 2004-01-01 23:45 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2007-11-30 18:02 . 2006-10-26 21:41 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
2007-11-30 18:02 . 2006-10-26 21:40 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
2007-11-30 18:02 . 2006-10-26 21:40 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
2007-11-30 18:02 . 2006-10-26 14:06 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
2007-11-30 18:02 . 2004-01-01 23:45 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
2007-11-30 18:02 . 2004-01-01 21:38 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Symantec
2007-11-30 18:02 . 2004-01-02 01:38 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\SampleView
2007-11-30 18:02 . 2004-01-02 00:55 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Intervideo
2007-11-30 18:02 . 2004-01-02 01:04 <REP> d-------- C:\Documents and Settings\Administrateur\Application Data\Apple Computer
2007-11-30 16:02 . 2007-11-30 16:02 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2007-11-29 14:54 . 2007-11-29 14:54 <REP> d-------- C:\temp
2007-11-21 15:44 . 2007-12-12 17:11 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\OpenOffice.org2
2007-11-19 23:15 . 2007-11-19 23:15 <REP> d-------- C:\Documents and Settings\kevin.ALLART\Application Data\MySpace
2007-11-19 13:47 . 2007-11-19 13:47 <REP> d-------- C:\Program Files\OpenOffice.org 2.3

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-12 17:26 --------- d-----w C:\Program Files\FlashGet
2007-12-12 17:21 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2007-12-12 17:13 --------- d-----w C:\Program Files\Wanadoo
2007-12-12 14:11 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-12 14:10 --------- d-----w C:\Documents and Settings\kevin.ALLART\Application Data\Lavasoft
2007-12-11 10:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-12-11 10:35 --------- d-----w C:\Program Files\Windows Journal Viewer
2007-12-11 09:48 --------- d-----w C:\Documents and Settings\kevin.ALLART\Application Data\MSNInstaller
2007-12-09 18:32 --------- d-----w C:\Program Files\LimeWire
2007-12-05 18:54 --------- d-----w C:\Program Files\GOM
2007-12-05 18:35 --------- d-----w C:\Program Files\Windows Media Connect 2
2007-12-05 18:06 --------- d-----w C:\Program Files\Windows Media Connect
2007-12-05 17:11 --------- d--h--w C:\Program Files\InstallShield Installation Information
2007-12-05 15:11 --------- d-----w C:\Documents and Settings\kevin.ALLART\Application Data\LimeWire
2007-12-04 16:12 --------- d-----w C:\Program Files\Windows Live
2007-12-04 13:53 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2007-12-04 12:30 --------- d-----w C:\Program Files\Symantec
2007-12-04 12:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2007-12-02 13:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2007-12-01 21:45 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
2007-11-29 14:01 --------- d-----w C:\Program Files\Microsoft Works
2007-11-20 11:54 --------- d-----w C:\Program Files\Java
2007-11-16 07:08 --------- d-----w C:\Program Files\InterCasino France
2007-11-13 10:25 20,480 ----a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-10-29 22:43 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2007-10-25 13:55 151,552 ----a-w C:\WINDOWS\system32\Netlog24Uninstaller.exe
2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
2007-10-18 10:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
2007-10-02 22:44 107,888 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
.

((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
-c--a-w 61,440 2003-02-11 19:02:48 C:\hp\KBD\bak\KBD.EXE
----a-w 61,440 2003-02-11 19:02:48 C:\hp\KBD\kbd.exe

----a-w 155,896 2006-09-19 08:34:39 C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\bak\GoogleToolbarNotifier.exe

----a-w 286,720 2004-05-10 23:48:38 C:\Program Files\iTunes\bak\iTunesHelper.exe
----a-w 256,576 2006-10-30 08:36:36 C:\Program Files\iTunes\iTunesHelper.exe

----a-w 98,304 2004-01-02 00:03:59 C:\Program Files\QuickTime\bak\qttask.exe
----a-w 282,624 2006-10-25 17:58:18 C:\Program Files\QuickTime\qttask.exe

----a-w 24,576 2004-10-13 14:12:06 C:\Program Files\Wanadoo\bak\CnxMon.exe
----a-w 24,576 2004-10-13 15:12:06 C:\Program Files\Wanadoo\CnxMon.exe

----a-w 49,152 2004-10-13 14:12:08 C:\Program Files\Wanadoo\bak\TaskbarIcon.exe
------w 49,152 2004-10-13 15:12:08 C:\Program Files\Wanadoo\TaskBarIcon.exe

----a-w 24,576 2004-10-13 14:12:08 C:\Program Files\Wanadoo\bak\Watch.exe
------w 24,576 2004-10-13 15:12:08 C:\Program Files\Wanadoo\Watch.exe

-c--a-w 118,784 2003-12-17 22:31:42 C:\WINDOWS\CREATOR\bak\Remind_XP.exe
----a-w 118,784 2003-12-17 22:31:42 C:\WINDOWS\CREATOR\Remind_XP.exe

-c--a-w 233,472 2004-04-14 19:43:46 C:\WINDOWS\SMINST\bak\RECGUARD.EXE
----a-w 233,472 2004-04-14 19:43:46 C:\WINDOWS\SMINST\Recguard.exe

-c--a-w 52,736 1998-05-07 15:04:38 C:\WINDOWS\system\bak\hpsysdrv.exe
----a-w 52,736 1998-05-07 15:04:38 C:\WINDOWS\system\hpsysdrv.exe

.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 11:00]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-28 09:57]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.exe" [2004-08-05 11:00 C:\WINDOWS\system32\rundll32.exe]
"MDNS"="C:\WINDOWS\system32\service.exe" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2007-09-08 15:10]
"Mercora"="C:\Program Files\Mercora\MercoraClient.exe" []
"WOOTASKBARICON"="C:\PROGRA~1\Wanadoo\TaskbarIcon.exe" [2004-10-13 16:12]
"EPSON Stylus Photo RX420 Series (Copie 1)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" []
"EPSON Stylus Photo RX420 Series (Copie 2)"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" []
"EPSON Stylus Photo RX420 Series"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9CE.exe" []
"zzzHPSETUP"="E:\Setup.exe" []
"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2007-12-12 10:34]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"^SetupICWDesktop"="" []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^DSLMON.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\DSLMON.lnk
backup=C:\WINDOWS\pss\DSLMON.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Windows Desktop Search.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Windows Desktop Search.lnk
backup=C:\WINDOWS\pss\Windows Desktop Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^kevin.ALLART^Menu Démarrer^Programmes^Démarrage^MSN Pictures Displayer.lnk]
path=C:\Documents and Settings\kevin.ALLART\Menu Démarrer\Programmes\Démarrage\MSN Pictures Displayer.lnk
backup=C:\WINDOWS\pss\MSN Pictures Displayer.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^kevin.ALLART^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 2.3.lnk]
path=C:\Documents and Settings\kevin.ALLART\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 2.3.lnk
backup=C:\WINDOWS\pss\OpenOffice.org 2.3.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdVantage]
C:\Program Files\AdVantage\AdVantage.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGRSMMSG]
AGRSMMSG.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount]
C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe /automount

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcxMonitor]
ALCXMNTR.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
C:\Program Files\BitTorrent\bittorrent.exe --force_start_minimized

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-05 11:00 15360 --a------ C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
C:\Program Files\DAEMON Tools\daemon.exe -lang 1033

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Efface Historique 2.0]
C:\PROGRA~1\EFFACE~1\EFFACE~1.EXE -s

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\FlashGet.exe /min

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
1998-05-07 16:04 52736 --a------ c:\windows\system\hpsysdrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2006-10-30 09:36 256576 --a------ C:\Program Files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2003-02-11 20:02 61440 --a------ C:\HP\KBD\KBD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /installquiet /keeploaded /nodetect

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PS2]
2003-09-12 20:13 98304 --a------ C:\WINDOWS\system32\ps2.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe -atboottime

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
2004-04-14 20:43 233472 --a------ C:\WINDOWS\SMINST\RECGUARD.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiS Windows KeyHook]
2004-05-20 09:47 249856 --a------ C:\WINDOWS\system32\keyhook.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
2007-07-28 09:57 68856 --a------ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe -osboot

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VTTimer]
VTTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhenUSearchWHSE]
C:\Program Files\DAEMON Tools SearchBar\whse.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WooCnxMon]
2004-10-13 16:12 24576 --a------ C:\PROGRA~1\Wanadoo\CnxMon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOTASKBARICON]
2004-10-13 16:12 49152 --------- C:\PROGRA~1\Wanadoo\TaskbarIcon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WOOWATCH]
2004-10-13 16:12 24576 --------- C:\PROGRA~1\Wanadoo\Watch.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ykgfcqv]
c:\windows\system32\ykgfcqv.exe ykgfcqv

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ZoneAlarm Client]
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\_SetRes]
c:\hp\bin\cloaker c:\hp\bin\res.bat

R0 sfdrv01a;StarForce Protection Environment Driver (version 1.x.a);C:\WINDOWS\system32\drivers\sfdrv01a.sys
R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys
R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys
R2 SPF4;Sunbelt Personal Firewall 4;"C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe"
S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys
S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
\Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
"2007-12-08 12:46:02 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-12-07 19:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Analyser mon ordinateur - kévin.job"
"2007-12-03 13:21:24 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-12 18:34:21
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\Program Files\ArcSoft\PhotoImpression 5\share\pihook.dll
.
Completion time: 2007-12-12 18:38:19 - machine was rebooted
.
2007-12-12 14:57:02 --- E O F ---

bonne nuit a tous ;;))
0
g!rly Messages postés 18462 Statut Contributeur 406
 
salut kevin,

Desinstalleur Norton:
http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/fr_docid/20050414110429924

car il reste des traces

¤
1/Télécharge Brute Force Uninstaller (de Merijn)
http://www.merijn.org/files/bfu.zip

dezip le sur ton bureau et double click sur bfu.exe pour l´ouvrir

regarde ceci en guise de tutoriel pour la suite :

http://serveur1.archive-host.com/membres/up/1366464061/cbc8b13c.gif

2 coche les cases suivantes :

* Use settings specified in script for the above option
* Show log after script ends

3 click sur le boutton WEb dans le coin en haut a droite

4 copie et colle l´url suivante dans la barre d´adresse qui va s´afficher :

http://metallica.geekstogo.com/alcanshorty.bfu

5 execute le script en cliquant le bouton execute

6 quand il aura fini click sur le bouton save pour avoir une copie du rapport

7. post ce rapport ici

¤
supprime tous ce qui suit :

C:\WINDOWS\imsins.BAK
C:\upload_moi_ALLART.tar.gz
C:\Program Files\Navilog1 -> par le panneau de configuration ajoue et suppression de programme puis le dossier dans tes programme files
C:\Program Files\Incomplete
C:\WINDOWS\QTFont.qfn
C:\WINDOWS\QTFont.for
c:\windows\system32\ykgfcqv.exe = si present
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe -> par le panneau de configuration ajoue et suppression de programme puis le dossier dans tes programme files

fais moi savoir si tu n´arrive pas a les supprimer

¤
Fix.reg

Ouvre le bloc-notes (click droit sur le bureau > dans l´arborescence choisie nouveau et nouveau fichier texte) et fais un copier coller de ce qui est en citation ci-dessous (copie tout d'un trait-sans les barres(X)) :

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SweetIM]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ykgfcqv]

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
note : il y a une ligne balnache a la fin et regedit4 est sur la premiere ligne
Puis click sur "fichier"/"enregistrer sous" :
dans : sur le bureau
Nom du fichier : fix.reg
Type de fichier : "tous les fichiers"
clique sur "enregistrer"

ca doit ressembler a ca une fois enrregistré :

http://img520.imageshack.us/img520/4251/screenshot005ps2.png

quitte internet et double clique sur fix.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
Si c'est bien le cas, clique sur "oui"

¤
fais un scan en mode sans echec a l´aide d´antivir et post le rapport ici stp

Comment redémarrer en mode sans echec?

Tu redemarre le pc et tapote la touche F8 des le début de l allumage sans t´arrêter.
Une fenêtre sur fond noir va s’ouvrir, tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
capture d´ecran : http://www.coupdepoucepc.com/images_cdppc4/fichespratiques/windowsxp/modese/modese2.jpg
Une fois sur le bureau si il n y a pas toutes les couleurs et autres c´est normal!
Ps : si F8 ne marche pas utilise la touche F5.

donc post le rapport de bfu et celui d´antivir dans ta reponse

@+
0
kevin596
 
bonjour,j'ai un probleme ds ce que tu me emande de faire.une fois brute force uninstaller téléchargé,je n'arrive pas a l'ouvrir.on me dit que le fichier est inconnu ou endommagé!!:s merci de me dire comment faire
0
g!rly Messages postés 18462 Statut Contributeur 406
 
salut kevin

essaie de le prendre directement sur le site de l´auteur

http://merijn.org/
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
kevin596
 
Bonsoir,désolé du retard j'ai eu quelques empêchements ;;))
voici le rapport de bfu

BFU v1.10.0
Windows XP SP2 (WinNT 5.01.2600 SP2)
Script started at 23:47:23, on 21/12/2007

Warning: unknown command 'OptionStatusOn' on line #7
Failed: DllUnregister C:\WINDOWS\DH.dll|1 (file not found)
Failed: DllUnregister C:\Program Files\Deskbar\deskbar.dll|1 (file not found)
Failed: DllUnregister \asappsrv.dll|1 (file not found)
Failed: DllUnregister \MyToolBar.dll|1 (file not found)
Failed: DllUnregister \888Bar.dll|1 (file not found)
Failed: ServiceStop Network Monitor (service not found)
Failed: ServiceStop cmdService (service not found)
Failed: ServiceDisable Network Monitor (service not found)
Failed: ServiceDisable cmdService (service not found)
Failed: ServiceDelete Network Monitor (service not found)
Failed: ServiceDelete cmdService (service not found)
Failed: RegDelValue HKCU\Microsoft\Windows\CurrentVersion\policies\Explorer\Run|WinUpdate.exe (key not found)
Option pause between commands: 300 ms
Option pause between commands: 50 ms
Failed: FolderDelete C:\Program Files\MsConfigs (folder not found)
Failed: FolderDelete C:\Program Files\winupdates (folder not found)
Failed: FolderDelete C:\Program Files\winupdate (folder not found)
Failed: FolderDelete C:\Program Files\winsupdater (folder not found)
Failed: FolderDelete C:\Program Files\MsUpdate (folder not found)
Failed: FolderDelete C:\Program Files\MsMovies (folder not found)
Failed: FolderDelete C:\Program Files\wmplayer (folder not found)
Failed: FolderDelete C:\Program Files\outlook (folder not found)
Failed: FileDelete C:\Program Files\Common Files\Windows\mc-*-*.exe (operation failed)
Failed: FileDelete C:\Program Files\Common Files\Download\mc-*-*.exe (operation failed)
Failed: FolderDelete C:\WINDOWS\system32\nstlr (folder not found)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\update.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\services.dll (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\activate.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-1033-*-*}\MyToolBar.dll (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\update.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\services.dll (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\activate.exe (operation failed)
Failed: FileDelete C:\Program Files\common files\{*-*-2057-*-*}\MyToolBar.dll (operation failed)
Failed: FolderDelete C:\Program Files\toolbar888 (folder not found)
Failed: FolderDelete C:\Program Files\e-mailpaysu toolbar (folder not found)
Failed: FolderDelete C:\Program Files\EMUSIC TOOLBAR (folder not found)
Failed: FolderDelete C:\Program Files\find dvd toolbar (folder not found)
Failed: FolderDelete C:\Program Files\GULESIDER VERKTøYLINJE (folder not found)
Failed: FolderDelete C:\Program Files\sesam-p4 toolbar (folder not found)
Failed: FolderDelete C:\Program Files\slownik ling (folder not found)
Failed: FolderDelete C:\Program Files\MediaPipe (folder not found)
Failed: FolderDelete C:\Program Files\p2pnetworks (folder not found)
Failed: FileDelete C:\Documents and Settings\kevin\LOADADV*.EXE (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFD713.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFE7CA.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFE85C.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFF9E1.tmp (operation failed)
Failed: FileDelete C:\DOCUME~1\KEVIN~1.ALL\LOCALS~1\Temp\~DFFA0D.tmp (operation failed)
Failed: FolderDelete C:\Program Files\Maxifiles (folder not found)
Failed: FolderDelete C:\Program Files\DNS (folder not found)
Failed: FolderDelete C:\Program Files\EQAdvice (folder not found)
Failed: FolderDelete C:\Program Files\FCAdvice (folder not found)
Failed: FolderDelete C:\Program Files\PSCastor (folder not found)
Failed: FolderDelete C:\Program Files\CMIntex (folder not found)
Failed: FolderDelete C:\Program Files\PadsysAssistant (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\FreeProd1 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\FreeProd2 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\InetGet (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\InetGet2 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\svchostsys (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\simtest (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\misc001 (folder not found)
Failed: FolderDelete C:\Program Files\InetGet2 (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\VCClient (folder not found)
Failed: FolderDelete C:\Program Files\Network Monitor (folder not found)
Failed: FolderDelete C:\WINDOWS\inet20001 (folder not found)
Failed: FolderDelete C:\WINDOWS\inet20000 (folder not found)
Failed: FolderDelete C:\Program Files\Update06 (folder not found)
Failed: FolderDelete C:\Program Files\Update03 (folder not found)
Failed: FolderDelete C:\Program Files\Update04 (folder not found)
Failed: FolderDelete C:\Program Files\Update08 (folder not found)
Failed: FolderDelete C:\Program Files\W-Update (folder not found)
Failed: FolderDelete C:\Program Files\Yazzle Sudoku (folder not found)
Failed: FolderDelete C:\Program Files\Cas (folder not found)
Failed: FolderDelete C:\Program Files\CasStub (folder not found)
Failed: FolderDelete C:\Program Files\Cas2Stub (folder not found)
Failed: FolderDelete C:\Program Files\ipwins (folder not found)
Failed: FolderDelete C:\Program Files\Ipwindows (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\Snowball Wars (folder not found)
Failed: FolderDelete C:\Program Files\folder.js (folder not found)
Failed: FolderDelete C:\Program Files\ini.ini (folder not found)
Failed: FolderDelete C:\temp (folder not found)
Failed: FolderDelete C:\WINDOWS\mdrive (folder not found)
Failed: FolderDelete C:\WINDOWS\system32\crunner (folder not found)
Failed: FolderDelete C:\Program Files\PECarlin (folder not found)
Failed: FolderDelete C:\Program Files\AXVenore (folder not found)
Failed: FolderDelete C:\Program Files\SDVita (folder not found)
Failed: FolderDelete C:\Program Files\EQBranch (folder not found)
Failed: FolderDelete C:\Program Files\EQArticle (folder not found)
Failed: FolderDelete C:\Program Files\PSHope (folder not found)
Failed: FolderDelete C:\Program Files\Batty (folder not found)
Failed: FolderDelete C:\Program Files\Batty2 (folder not found)
Failed: FolderDelete C:\Program Files\AXFibula (folder not found)
Failed: FolderDelete C:\Program Files\CMFibula (folder not found)
Failed: FolderDelete C:\Program Files\PSLister (folder not found)
Failed: FolderDelete C:\Program Files\PSCloner (folder not found)
Failed: FolderDelete C:\Program Files\PSDream (folder not found)
Failed: FolderDelete C:\Program Files\cmapp (folder not found)
Failed: FolderDelete C:\Program Files\cmman (folder not found)
Failed: FolderDelete C:\Program Files\cmsystem (folder not found)
Failed: FolderDelete C:\Program Files\fcengine (folder not found)
Failed: FolderDelete C:\Program Files\wincmapp (folder not found)
Failed: FolderDelete C:\Program Files\Deskbar\Cache (folder not found)
Failed: FolderDelete C:\Program Files\popupwithcast (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\cloader (folder not found)
Failed: FolderDelete C:\Program Files\Common Files\misc001 (folder not found)
Failed: FolderDelete C:\Program Files\Web Buying (folder not found)
Failed: FolderCreate C:\bintheredunthat (folder already exists)
Failed: FileMove C:\WINDOWS\win*-*.exe|C:\bintheredunthat (source file not found)
Script completed.

et le rapport de antivir :

AntiVir PersonalEdition Classic
Report file date: samedi 22 décembre 2007 00:57

Scanning for 985234 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]

Version information:
BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14/12/2007 16:57:38
ANTIVIR2.VDF : 7.0.1.96 2048 Bytes 14/12/2007 16:57:38
ANTIVIR3.VDF : 7.0.1.138 185344 Bytes 21/12/2007 17:00:49
AVEWIN32.DLL : 7.6.0.46 3084800 Bytes 21/12/2007 17:00:49
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
AVPACK32.DLL : 7.6.0.2 360488 Bytes 21/12/2007 17:00:49
AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

Configuration settings for the scan:
Jobname..........................: Rootkit search
Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\rootkit.avp
Logging..........................: high
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Scan memory......................: off
Process scan.....................: off
Scan registry....................: off
Search for rootkits..............: on
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: high
Expanded search settings.........: 0x00300922

Start of the scan: samedi 22 décembre 2007 00:57

Starting search for hidden objects.
The driver could not be initialized.

End of the scan: samedi 22 décembre 2007 00:57
Used time: 00:03 min

The scan has been done completely.

0 Scanning directories
0 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
0 Files cannot be scanned
0 Files not concerned
0 Archives were scanned
0 Warnings
0 Notes
0
g!rly Messages postés 18462 Statut Contributeur 406
 
bonsoir kevin596,

je viens tout juste de rentrer de vacances, je te souhaite mes meilleurs voeux pour cette nouvelle année 2008 ;-)

comme cela fait un petit moment, peux tu poster un nouveau hijack this stp

@+
0
^^Marie^^ Messages postés 126523 Date d'inscription   Statut Membre Dernière intervention   3 279
 
Salut

Pour avancer

AVG ► Aucune action entreprise. N'a pas fonctionné ;;))

Faut le refaire

Tu l'installes. 
Lance AVG Anti-Spyware et clique sur le bouton Mise à jour. 
Patiente! 
Lance AVG Anti-Spyware 
Clique sur le bouton Analyse (de la barre d'outils) 
Puis sur l'onglets Comment réagir, clique sur Actions recommandées. 
Reviens à l'onglet Analyse. Clique sur Analyse complète du système. 
/!\ Si un fichier est infecté en fin d'analyse /!\
choisis l'option " Appliquer toutes les actions " en bas. 
Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous" 
Enregistre ce fichier texte sur ton bureau.
Copie/colle le rapport


-1