Virus MSN Photo2007-12 ou Image2007-12

Résolu
shaka975 -  
Le sioux Messages postés 4907 Statut Contributeur sécurité -
Bonjour,

J'ai malheureusement accepté un fichier zip d'une personne de confiance, et je me retrouve avec un virus qui propage un fichier photo2007-12.zip ou Image2007-12.zip à tous mes contacts lorsque je me connecte.
J'ai lancé MSNFix ainsi que Highjackthis, ça semblait avoir réglé le probème, mais le virus est toujours la. Le fichier joint change de nom, et même si je le supprime, il finit par revenir de je ne sais quelle façon dans mes fichiers Windows. De plus, j'ai deux sessions MSN (deux adresses utilisées pour la connexion à MSN) et parfois, le virus change de session, quand il disparait sur une session, et que je me connecte en même temps sur l'autre, il se propage à travers cette autre session.
J'ai lancé LiveKill qui ne me détecte aucune infection. Malheureusement ce virus continue de se propager.
Ca fait 3 jours que j'essaie en vain de m'en dépétrer.
Quelqu'un aurait-il une vraie solution efficace à me proposer ?

Merci d'avance !!
Shaka975
A voir également:

73 réponses

shaka975
 
voici le rapport vundofix.
Ensuite ?

VundoFix V6.7.7

Checking Java version...

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.11

Scan started at 19:36:47 18/12/2007

Listing files found while scanning....

C:\WINDOWS\system32\awtqq.dll
C:\WINDOWS\system32\awttspq.dll
C:\WINDOWS\system32\awtuvtq.dll
C:\WINDOWS\system32\cbxwx.dll
C:\WINDOWS\system32\cbxyvuu.dll
C:\WINDOWS\system32\fccyvvv.dll
C:\WINDOWS\system32\qomlihf.dll
C:\WINDOWS\system32\xwxbc.ini
C:\WINDOWS\system32\xwxbc.ini2

Beginning removal...

Attempting to delete C:\WINDOWS\system32\awtqq.dll
C:\WINDOWS\system32\awtqq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\awttspq.dll
C:\WINDOWS\system32\awttspq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\awtuvtq.dll
C:\WINDOWS\system32\awtuvtq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cbxwx.dll
C:\WINDOWS\system32\cbxwx.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cbxyvuu.dll
C:\WINDOWS\system32\cbxyvuu.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fccyvvv.dll
C:\WINDOWS\system32\fccyvvv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomlihf.dll
C:\WINDOWS\system32\qomlihf.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\xwxbc.ini
C:\WINDOWS\system32\xwxbc.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\xwxbc.ini2
C:\WINDOWS\system32\xwxbc.ini2 Has been deleted!

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\qomlihf.dll
C:\WINDOWS\system32\qomlihf.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...
1
Utilisateur anonyme
 
Télécharge sur le bureau
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
=> Double clic sur VirtumundoBeGone.exe
=> Clic Continue ==> clic Start
=> Clic Oui
=> A la fin si Vundo est présent , le PC s’éteint et redémarre
- Si Ecran bleu et message : Erreur fatale .. pas de problème
=> Poster le rapport VBG.TXT qui est sur le bureau
1
shaka975
 
comment de logiciels de ce genre vais-je devoir lancer ? avez-vous pu avoir une idée d'où se situe le problème ?
merci
1
shaka975
 
oups, combien de logiciels bien sur, pas comment
1

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
shaka975
 
Voici le rapport VBG :

[12/18/2007, 22:03:39] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Stéphane Coste\Bureau\VirtumundoBeGone.exe" )
[12/18/2007, 22:03:51] - Detected System Information:
[12/18/2007, 22:03:51] - Windows Version: 5.1.2600, Service Pack 2
[12/18/2007, 22:03:51] - Current Username: Stéphane Coste (Admin)
[12/18/2007, 22:03:51] - Windows is in NORMAL mode.
[12/18/2007, 22:03:51] - Searching for Browser Helper Objects:
[12/18/2007, 22:03:51] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[12/18/2007, 22:03:51] - BHO 2: {0EAA8C8F-FDC8-49F1-B6C9-A5946FD96C0E} ()
[12/18/2007, 22:03:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/18/2007, 22:03:51] - Checking for HKLM\...\Winlogon\Notify\cbxwx
[12/18/2007, 22:03:51] - Key not found: HKLM\...\Winlogon\Notify\cbxwx, continuing.
[12/18/2007, 22:03:51] - BHO 3: {2E03C0FD-4C48-43A7-9A54-00240C70FF16} (ECarteBleueBrowserHelper Class)
[12/18/2007, 22:03:51] - BHO 4: {3401DB32-7F00-4EC7-A890-A75F64973843} ()
[12/18/2007, 22:03:51] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/18/2007, 22:03:51] - Checking for HKLM\...\Winlogon\Notify\urqpqpo
[12/18/2007, 22:03:51] - Found: HKLM\...\Winlogon\Notify\urqpqpo - This is probably Virtumundo.
[12/18/2007, 22:03:51] - Assigning {3401DB32-7F00-4EC7-A890-A75F64973843} MSEvents Object
[12/18/2007, 22:03:52] - BHO list has been changed! Starting over...
[12/18/2007, 22:03:52] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[12/18/2007, 22:03:52] - BHO 2: {0EAA8C8F-FDC8-49F1-B6C9-A5946FD96C0E} ()
[12/18/2007, 22:03:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/18/2007, 22:03:52] - Checking for HKLM\...\Winlogon\Notify\cbxwx
[12/18/2007, 22:03:52] - Key not found: HKLM\...\Winlogon\Notify\cbxwx, continuing.
[12/18/2007, 22:03:52] - BHO 3: {2E03C0FD-4C48-43A7-9A54-00240C70FF16} (ECarteBleueBrowserHelper Class)
[12/18/2007, 22:03:52] - BHO 4: {3401DB32-7F00-4EC7-A890-A75F64973843} (MSEvents Object)
[12/18/2007, 22:03:52] - ALERT: Found MSEvents Object!
[12/18/2007, 22:03:52] - BHO 5: {53707962-6F74-2D53-2644-206D7942484F} ()
[12/18/2007, 22:03:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/18/2007, 22:03:52] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[12/18/2007, 22:03:52] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[12/18/2007, 22:03:52] - BHO 6: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[12/18/2007, 22:03:52] - BHO 7: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[12/18/2007, 22:03:52] - BHO 8: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} (ST)
[12/18/2007, 22:03:52] - BHO 9: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[12/18/2007, 22:03:52] - BHO 10: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[12/18/2007, 22:03:52] - BHO 11: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (MSNToolBandBHO)
[12/18/2007, 22:03:52] - BHO 12: {E22F2DFF-FE3B-4774-AD31-13F00B6FCE40} ()
[12/18/2007, 22:03:52] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/18/2007, 22:03:52] - Checking for HKLM\...\Winlogon\Notify\hgdcc
[12/18/2007, 22:03:52] - Key not found: HKLM\...\Winlogon\Notify\hgdcc, continuing.
[12/18/2007, 22:03:53] - Finished Searching Browser Helper Objects
[12/18/2007, 22:03:53] - *** Detected MSEvents Object
[12/18/2007, 22:03:53] - Trying to remove MSEvents Object...
[12/18/2007, 22:03:54] - Terminating Process: IEXPLORE.EXE
[12/18/2007, 22:03:54] - Terminating Process: RUNDLL32.EXE
[12/18/2007, 22:03:54] - Disabling Automatic Shell Restart
[12/18/2007, 22:03:54] - Terminating Process: EXPLORER.EXE
[12/18/2007, 22:03:55] - Suspending the NT Session Manager System Service
[12/18/2007, 22:03:55] - Terminating Windows NT Logon/Logoff Manager
[12/18/2007, 22:03:56] - Re-enabling Automatic Shell Restart
[12/18/2007, 22:03:56] - File to disable: C:\WINDOWS\system32\urqpqpo.dll
[12/18/2007, 22:03:56] - Renaming C:\WINDOWS\system32\urqpqpo.dll -> C:\WINDOWS\system32\urqpqpo.dll.vir
[12/18/2007, 22:03:56] - File successfully renamed!
[12/18/2007, 22:03:56] - Removing HKLM\...\Browser Helper Objects\{3401DB32-7F00-4EC7-A890-A75F64973843}
[12/18/2007, 22:03:56] - Removing HKCR\CLSID\{3401DB32-7F00-4EC7-A890-A75F64973843}
[12/18/2007, 22:03:56] - Adding Kill Bit for ActiveX for GUID: {3401DB32-7F00-4EC7-A890-A75F64973843}
[12/18/2007, 22:03:56] - Deleting ATLEvents/MSEvents Registry entries
[12/18/2007, 22:03:57] - Removing HKLM\...\Winlogon\Notify\urqpqpo
[12/18/2007, 22:03:57] - Searching for Browser Helper Objects:
[12/18/2007, 22:03:57] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[12/18/2007, 22:03:57] - BHO 2: {0EAA8C8F-FDC8-49F1-B6C9-A5946FD96C0E} ()
[12/18/2007, 22:03:57] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/18/2007, 22:03:57] - Checking for HKLM\...\Winlogon\Notify\cbxwx
[12/18/2007, 22:03:57] - Key not found: HKLM\...\Winlogon\Notify\cbxwx, continuing.
[12/18/2007, 22:03:57] - BHO 3: {2E03C0FD-4C48-43A7-9A54-00240C70FF16} (ECarteBleueBrowserHelper Class)
[12/18/2007, 22:03:57] - BHO 4: {53707962-6F74-2D53-2644-206D7942484F} ()
[12/18/2007, 22:03:57] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/18/2007, 22:03:58] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[12/18/2007, 22:03:58] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[12/18/2007, 22:03:58] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[12/18/2007, 22:03:58] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[12/18/2007, 22:03:58] - BHO 7: {9394EDE7-C8B5-483E-8773-474BF36AF6E4} (ST)
[12/18/2007, 22:03:58] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[12/18/2007, 22:03:58] - BHO 9: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[12/18/2007, 22:03:59] - BHO 10: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (MSNToolBandBHO)
[12/18/2007, 22:03:59] - BHO 11: {E22F2DFF-FE3B-4774-AD31-13F00B6FCE40} ()
[12/18/2007, 22:03:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/18/2007, 22:03:59] - Checking for HKLM\...\Winlogon\Notify\hgdcc
[12/18/2007, 22:03:59] - Key not found: HKLM\...\Winlogon\Notify\hgdcc, continuing.
[12/18/2007, 22:03:59] - Finished Searching Browser Helper Objects
[12/18/2007, 22:03:59] - Finishing up...
[12/18/2007, 22:03:59] - A restart is needed.
[12/18/2007, 22:04:13] - Attempting to Restart via STOP error (Blue Screen!)
1
Utilisateur anonyme
 
bonjour ton pc devait ramer c'est derniers jours ! tu as eu une petite infection msn ca c'est encore pas dramatique , avec l'infection msn tu as eu un hameconnage de ton pare feu ce qui as permis a tout pleins de troyens de s'instaler bien au chaud dans ton pc , je ne fait que te faire suivre les procedures de desinfection preconise si tu veu jeter deux trois recherches pour etre sur que je ne te fait pas faire n'importe quoi! recherche trojan virtumonde , si veu que l'on termine dit le moi ! car il peu encore rester du boulot !! je pense que tu dois deja sentir une petite difference sur ton pc ?!
1
shaka975
 
Bonsoir,
Mon PC a tjs ramé, il commence à se faire vieux, et ça se sent, donc je n'avais pas noté de différence particulière, si ce n'est ce satané virus qui se planque et se transmet par msn... Il est tjs la d'ailleurs, j'ai fait une tentative de connexion hier soir, et il a de nouveau tenté d'envoyer le fichier à mes contacts ! Seulement, le fichier ayant disparu, il n'a pu transmettre que la phrase d'accroche... C'est déjà un bon point !
Je souhaite bien évidemment qu'on continue, je veux me débarrasser de cette saleté. Je demandais simplement des précisions, et merci d'ailleurs de me les avoir fournies.
En passant, cela fait deux fois que j'ai un message d'erreur RUNDLL qui s'affiche. Il dit : "Erreur de chargement de ÿÿÿÿ. Le module spécifié est introuvable". Qu'est-ce que ça signifie ?
Merci bcp !
1
Utilisateur anonyme
 
bonsoir desoles je suis pas mal pris par petite fille voici la suite

Télécharge Combofix.exe de sUBs sur ton Bureau,

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement

Double clique sur Combofix.exe
Mets le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan
Lorsque le scan sera terminé, un rapport apparaîtra.

Poste lerapport dans ta prochaine réponse.

Note : Le rapport se trouve également là : C:\Combofix.txt+

2. Télécharge HijackThis ici:
http://telechargement.zebulon.fr/138-hijackthis-1991.html

Dézippe le dans un dossier prévu à cet effet.
Par exemple C:\hijackthis < Enregistre-le bien dans c : !
Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/Hijenr.gif

renome le betaile.exe ( clic droit puis renomer)
Lance le puis:
Clique sur "do a system scan and save logfile" (cf démo)
Faire un copier coller du log entier sur le forum

Démo : (Merci a Balltrap34 pour cette réalisation)
http://pageperso.aol.fr/balltrap34/demohijack.htm
1
shaka975
 
Voici le rapport Combofix ! Vous n'avez pas à vous excuser, je comprends parfaitement ;) Savez-vous ce que le message d'erreur de RUNDLL signifie ? il est de nouveau apparu lorsque mon PC a redémarré. Le fichier zip est quant à lui réapparu sur mon bureau cette fois, j'ignore comment... Ca commence à m'inquièter, j'espère qu'on réussira vite à nettoyer le PC ! En tous les cas, merci bcp de votre aide !

ComboFix 07-12-19.2 - Stéphane Coste 2007-12-19 21:35:25.1 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.121 [GMT -3:00]
Running from: C:\Documents and Settings\Stéphane Coste\Bureau\ComboFix.exe
* Created a new restore point
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\pack.epk
C:\WINDOWS\system32\byxxxxy.dll
C:\WINDOWS\system32\ccdgh.ini
C:\WINDOWS\system32\ccdgh.ini2
C:\WINDOWS\system32\hgdcc.dll
C:\WINDOWS\system32\jkklmjh.dll
C:\WINDOWS\system32\kunhsjxx.exe
C:\WINDOWS\system32\lhcvhrmx.dll
C:\WINDOWS\system32\ljjgdca.dll
C:\WINDOWS\system32\pmnlllm.dll
C:\WINDOWS\system32\qomlihf.dll
C:\WINDOWS\system32\udlskrtt.dll
C:\WINDOWS\system32\urqnoon.dll
C:\WINDOWS\system32\xmrhvchl.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_DOMAINSERVICE
-------\LEGACY_IPRIP
-------\DomainService
-------\Iprip

((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-20 to 2007-12-20 ))))))))))))))))))))))))))))))))))))
.

2007-12-19 01:41 . 2007-12-19 01:41 22,321 --a------ C:\device.exe
2007-12-19 01:38 . 2007-12-19 21:48 22,457 --a------ C:\WINDOWS\img2007-12.zip
2007-12-19 01:38 . 2007-12-19 01:38 22,321 -r-hs---- C:\WINDOWS\devices.exe
2007-12-19 01:38 . 2007-12-19 01:38 22,321 --a------ C:\devices.exe
2007-12-18 20:20 . 2007-12-18 20:20 38,912 --a------ C:\WINDOWS\system32\urqpqpo.dll.vir
2007-12-18 20:14 . 2007-12-18 20:14 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-12-18 19:36 . 2007-12-18 19:36 <REP> d-------- C:\VundoFix Backups
2007-12-18 19:12 . 2007-12-19 21:48 21,957 --a------ C:\WINDOWS\photo2007-12.zip
2007-12-18 18:56 . 2007-12-18 18:56 <REP> d-------- C:\WINDOWS\ERUNT
2007-12-18 18:53 . 2007-12-18 18:53 <REP> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2007-12-18 01:46 . 2007-12-18 01:46 <REP> d-------- C:\Program Files\LiveKillCleanMessenger
2007-12-17 18:16 . 2007-12-17 18:16 <REP> d-------- C:\Program Files\Spyware Doctor
2007-12-17 18:16 . 2007-12-17 18:19 74,240 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-17 18:16 . 2007-12-17 18:19 56,832 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-17 18:16 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-17 18:16 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-12-17 18:15 . 2007-12-17 18:15 <REP> d-------- C:\Program Files\Webroot
2007-12-17 18:15 . 2007-12-17 18:15 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2007-12-17 18:15 . 2007-12-17 18:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2007-12-17 18:15 . 2007-03-01 19:54 144,960 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2007-12-17 18:15 . 2007-03-01 19:54 22,080 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2007-12-17 18:15 . 2007-03-01 19:54 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2007-12-17 18:15 . 2007-03-01 19:54 20,544 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2007-12-17 18:15 . 2007-12-17 18:15 164 --a------ C:\install.dat
2007-12-17 18:13 . 2007-12-17 18:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2007-12-17 16:40 . 2007-12-17 16:40 21,821 --------- C:\WINDOWS\cservs.exe
2007-12-17 16:40 . 2007-12-17 16:40 21,821 --a------ C:\pb8.exe
2007-12-17 00:49 . 2007-12-17 00:49 121 --a------ C:\WINDOWS\wininit.ini
2007-12-08 21:35 . 2007-12-08 21:35 268 --ah----- C:\sqmdata06.sqm
2007-12-08 21:35 . 2007-12-08 21:35 244 --ah----- C:\sqmnoopt06.sqm
2007-12-08 12:09 . 2007-12-08 12:09 268 --ah----- C:\sqmdata05.sqm
2007-12-08 12:09 . 2007-12-08 12:09 244 --ah----- C:\sqmnoopt05.sqm
2007-12-07 22:46 . 2007-12-07 22:46 268 --ah----- C:\sqmdata04.sqm
2007-12-07 22:46 . 2007-12-07 22:46 244 --ah----- C:\sqmnoopt04.sqm

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-10-26 21:56 --------- d-----w C:\Documents and Settings\All Users\Application Data\TERMINAL Studio
2007-10-26 21:54 --------- d-----w C:\Program Files\RiseofAtlantis_at
2007-02-10 18:35 467 ----a-w C:\Program Files\Options.ini
2005-12-25 22:05 582 ----a-w C:\Program Files\BlackLst.ecb
2005-09-13 03:13 2,318 ----a-w C:\Program Files\license.txt
2005-01-15 02:38 2,117,632 ----a-w C:\Program Files\EasyClea.exe
2003-11-21 23:08 226 ----a-w C:\Program Files\File_id.diz
.

((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0EAA8C8F-FDC8-49F1-B6C9-A5946FD96C0E}]
C:\WINDOWS\system32\cbxwx.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeRAM XP"="C:\unzipped\framxpro\FreeRAM XP Pro 1.40.exe" [2003-11-30 23:13]
"SuperCopier.exe"="C:\Program Files\SuperCopier\SuperCopier.exe" [2003-04-24 19:03]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-12-18 17:32]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2004-10-08 12:06]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23]
"NetAppel"="C:\Program Files\NetAppel\NetAppel.exe" [2007-04-13 12:09]
"VoipBuster"="C:\program files\voipbuster.com\voipbuster\voipbuster.exe" [2007-07-02 12:08]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 20:09]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 12:52]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hcontrol"="C:\WINDOWS\Hcontrol.exe" [2002-06-18 19:08]
"SiSUSBRG"="C:\WINDOWS\sisUSBrg.exe" [2002-10-01 21:00]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-07-28 18:26]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-08-01 16:07]
"SiS KHooker"="C:\WINDOWS\System32\khooker.exe" [2002-01-25 02:30]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-10-08 12:31]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-10-08 12:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 07:06]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 19:17]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 19:30]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-03-28 15:48]
"SetDefPrt"="C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 18:02]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [2006-04-10 14:58]
"x1x5161x6"="cserv.exe" []
"win32serv"="cservs.exe" [2007-12-17 16:40 C:\WINDOWS\cservs.exe]
"System Device"="devices.exe" [2007-12-19 01:38 C:\WINDOWS\devices.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 20:09]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ :\WINDOWS\syste

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^ASUS Hotkey.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\ASUS Hotkey.lnk
backup=C:\WINDOWS\pss\ASUS Hotkey.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Stéphane Coste^Menu Démarrer^Programmes^Démarrage^Webshots.lnk]
path=C:\Documents and Settings\Stéphane Coste\Menu Démarrer\Programmes\Démarrage\Webshots.lnk
backup=C:\WINDOWS\pss\Webshots.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ElbyCheckElbyCDFL]
C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe /L ElbyCDFL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]

R3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2002-06-06 14:06]
S3 sbext;Sound Blaster Extigy Audio Driver;C:\WINDOWS\system32\DRIVERS\sbext.sys []

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-19 21:48:07
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\Program Files\SuperCopier\SCHook.DLL
.
Completion time: 2007-12-19 21:51:15 - machine was rebooted
1
shaka975
 
Voici le rapport hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:17:45, on 19/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Hcontrol.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\khooker.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\WINDOWS\ATKOSD.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\cservs.exe
C:\WINDOWS\devices.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\unzipped\framxpro\FreeRAM XP Pro 1.40.exe
C:\Program Files\SuperCopier\SuperCopier.exe
C:\Program Files\Brother\Brmfcmon\BrMfcmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\NetAppel\NetAppel.exe
C:\program files\voipbuster.com\voipbuster\voipbuster.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\Hijackthis\betaile.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.cheznoo.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0EAA8C8F-FDC8-49F1-B6C9-A5946FD96C0E} - C:\WINDOWS\system32\cbxwx.dll (file missing)
O2 - BHO: (no name) - {24D760DC-8DB7-4F69-91B1-73774003B1C3} - C:\WINDOWS\system32\geecc.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\Hcontrol.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [BrMfcWnd] "C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] "C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe"
O4 - HKLM\..\Run: [ControlCenter3] "C:\Program Files\Brother\ControlCenter3\brctrcen.exe" /autorun
O4 - HKLM\..\Run: [x1x5161x6] cserv.exe
O4 - HKLM\..\Run: [win32serv] cservs.exe
O4 - HKLM\..\Run: [System Device] devices.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\unzipped\framxpro\FreeRAM XP Pro 1.40.exe" -win
O4 - HKCU\..\Run: [SuperCopier.exe] C:\Program Files\SuperCopier\SuperCopier.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [NetAppel] "C:\Program Files\NetAppel\NetAppel.exe" -nosplash -minimized
O4 - HKCU\..\Run: [VoipBuster] "C:\program files\voipbuster.com\voipbuster\voipbuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Grouper.lnk = C:\Program Files\Grouper\Grouper.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: ljjigec - C:\WINDOWS\SYSTEM32\ljjigec.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
1
Utilisateur anonyme
 
bonjour !desoles je t'avais un peu oublie ou en sont tes problemes ?
1
shaka975
 
Bonsoir, j'espère que vous avez passé de bonnes fêtes. Désolée pour la réponse tardive.
Voici le rapport Combofix :

ComboFix 07-12-19.2 - Stéphane Coste 2007-12-27 21:54:48.2 - [color=red][b]FAT32[/b][/color]x86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.203 [GMT -3:00]
Running from: C:\Documents and Settings\Stéphane Coste\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Stéphane Coste\Bureau\CFScript.txt
* Created a new restore point

FILE
C:\pb8.exe
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\sqmnoopt06.sqm
C:\WINDOWS\cservs.exe
C:\WINDOWS\img2007-12.zip
C:\WINDOWS\photo2007-12.zip
C:\WINDOWS\system32\urqpqpo.dll.vir
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\pb8.exe
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\sqmnoopt06.sqm
C:\WINDOWS\img2007-12.zip
C:\WINDOWS\photo2007-12.zip
C:\WINDOWS\system32\akmdmxpt.dll
C:\WINDOWS\system32\cceeg.ini
C:\WINDOWS\system32\cceeg.ini2
C:\WINDOWS\system32\cithpsxu.exe
C:\WINDOWS\system32\geecc.dll
C:\WINDOWS\system32\gjmojvtr.ini
C:\WINDOWS\system32\hxbtgimi.dll
C:\WINDOWS\system32\ljjigec.dll
C:\WINDOWS\system32\qomkhee.dll
C:\WINDOWS\system32\rtvjomjg.dll
C:\WINDOWS\system32\tuvsroo.dll
C:\WINDOWS\system32\urqpqpo.dll.vir
C:\WINDOWS\system32\vqplxrly.exe
C:\WINDOWS\system32\xmnsanha.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
-------\LEGACY_DOMAINSERVICE
-------\DomainService

((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-28 to 2007-12-28 ))))))))))))))))))))))))))))))))))))
.

2007-12-27 21:40 . 2007-12-27 21:40 81,986 --a------ C:\[u]0[/u]h00.exe
2007-12-21 10:13 . 2007-12-27 21:08 987,634 ---hs---- C:\WINDOWS\system32\lcvdlpis.ini
2007-12-20 22:11 . 2007-12-20 22:11 987,454 ---hs---- C:\WINDOWS\system32\bvkwijqt.ini
2007-12-20 12:16 . 2007-12-27 22:04 23,456 --a------ C:\WINDOWS\img5-2007.zip
2007-12-20 12:16 . 2007-12-20 12:16 23,304 -r-hs---- C:\WINDOWS\devic.exe
2007-12-20 12:16 . 2007-12-20 12:16 23,304 --a------ C:\devic.exe
2007-12-19 22:16 . 2007-12-19 22:16 <REP> d-------- C:\Hijackthis
2007-12-19 01:41 . 2007-12-20 06:02 22,321 --a------ C:\device.exe
2007-12-19 01:38 . 2007-12-19 01:38 22,321 --a------ C:\devices.exe
2007-12-18 20:14 . 2007-12-18 20:14 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2007-12-18 19:36 . 2007-12-18 19:36 <REP> d-------- C:\VundoFix Backups
2007-12-18 18:56 . 2007-12-18 18:56 <REP> d-------- C:\WINDOWS\ERUNT
2007-12-18 18:53 . 2007-12-18 18:53 <REP> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2007-12-18 01:46 . 2007-12-18 01:46 <REP> d-------- C:\Program Files\LiveKillCleanMessenger
2007-12-17 18:16 . 2007-12-17 18:16 <REP> d-------- C:\Program Files\Spyware Doctor
2007-12-17 18:16 . 2007-12-17 18:19 74,240 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-17 18:16 . 2007-12-17 18:19 56,832 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-17 18:16 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-17 18:16 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-12-17 18:15 . 2007-12-17 18:15 <REP> d-------- C:\Program Files\Webroot
2007-12-17 18:15 . 2007-12-17 18:15 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2007-12-17 18:15 . 2007-12-17 18:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2007-12-17 18:15 . 2007-03-01 19:54 144,960 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2007-12-17 18:15 . 2007-03-01 19:54 22,080 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2007-12-17 18:15 . 2007-03-01 19:54 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2007-12-17 18:15 . 2007-03-01 19:54 20,544 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2007-12-17 18:15 . 2007-12-17 18:15 164 --a------ C:\install.dat
2007-12-17 18:13 . 2007-12-17 18:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2007-12-17 00:49 . 2007-12-17 00:49 121 --a------ C:\WINDOWS\wininit.ini

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-02-10 18:35 467 ----a-w C:\Program Files\Options.ini
2005-12-25 22:05 582 ----a-w C:\Program Files\BlackLst.ecb
2005-09-13 03:13 2,318 ----a-w C:\Program Files\license.txt
2005-01-15 02:38 2,117,632 ----a-w C:\Program Files\EasyClea.exe
2003-11-21 23:08 226 ----a-w C:\Program Files\File_id.diz
2004-08-19 23:09 81,986 --sh--r C:\WINDOWS\system32\svho.exe
.

((((((((((((((((((((((((((((( snapshot@2007-12-19_21.49.51.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-28 01:04:18 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_598.dat
- 2007-12-20 00:47:08 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_600.dat
+ 2007-12-28 01:03:54 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_600.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeRAM XP"="C:\unzipped\framxpro\FreeRAM XP Pro 1.40.exe" [2003-11-30 23:13]
"SuperCopier.exe"="C:\Program Files\SuperCopier\SuperCopier.exe" [2003-04-24 19:03]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-12-18 17:32]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2004-10-08 12:06]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23]
"NetAppel"="C:\Program Files\NetAppel\NetAppel.exe" [2007-04-13 12:09]
"VoipBuster"="C:\program files\voipbuster.com\voipbuster\voipbuster.exe" [2007-07-02 12:08]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 20:09]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 12:52]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hcontrol"="C:\WINDOWS\Hcontrol.exe" [2002-06-18 19:08]
"SiSUSBRG"="C:\WINDOWS\sisUSBrg.exe" [2002-10-01 21:00]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-07-28 18:26]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-08-01 16:07]
"SiS KHooker"="C:\WINDOWS\System32\khooker.exe" [2002-01-25 02:30]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-10-08 12:31]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-10-08 12:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-09-06 07:06]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 19:17]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 19:30]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-03-28 15:48]
"SetDefPrt"="C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 18:02]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [2006-04-10 14:58]
"System Device"="devices.exe" []
"SystemDevic"="devic.exe" [2007-12-20 12:16 C:\WINDOWS\devic.exe]
"System Service Manager Device"="svho.exe" [2004-08-19 20:09 C:\WINDOWS\system32\svho.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"System Service Manager Device"="svho.exe" [2004-08-19 20:09 C:\WINDOWS\system32\svho.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 20:09]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ :\WINDOWS\syste

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^ASUS Hotkey.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\ASUS Hotkey.lnk
backup=C:\WINDOWS\pss\ASUS Hotkey.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Stéphane Coste^Menu Démarrer^Programmes^Démarrage^Webshots.lnk]
path=C:\Documents and Settings\Stéphane Coste\Menu Démarrer\Programmes\Démarrage\Webshots.lnk
backup=C:\WINDOWS\pss\Webshots.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ElbyCheckElbyCDFL]
C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe /L ElbyCDFL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]

R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2002-06-06 14:06]
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
S3 sbext;Sound Blaster Extigy Audio Driver;C:\WINDOWS\system32\DRIVERS\sbext.sys []

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-27 22:05:05
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\Program Files\SuperCopier\SCHook.DLL
.
Completion time: 2007-12-27 22:08:10 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-19 21:51
1
shaka975
 
Et le rapport Hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:20:45, on 27/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Hcontrol.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\khooker.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\ATKOSD.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\devic.exe
C:\WINDOWS\system32\svho.exe
C:\unzipped\framxpro\FreeRAM XP Pro 1.40.exe
C:\Program Files\SuperCopier\SuperCopier.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\NetAppel\NetAppel.exe
C:\program files\voipbuster.com\voipbuster\voipbuster.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.cheznoo.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\Hcontrol.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [BrMfcWnd] "C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] "C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe"
O4 - HKLM\..\Run: [ControlCenter3] "C:\Program Files\Brother\ControlCenter3\brctrcen.exe" /autorun
O4 - HKLM\..\Run: [System Device] devices.exe
O4 - HKLM\..\Run: [SystemDevic] devic.exe
O4 - HKLM\..\Run: [System Service Manager Device] svho.exe
O4 - HKLM\..\RunServices: [System Service Manager Device] svho.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\unzipped\framxpro\FreeRAM XP Pro 1.40.exe" -win
O4 - HKCU\..\Run: [SuperCopier.exe] C:\Program Files\SuperCopier\SuperCopier.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [NetAppel] "C:\Program Files\NetAppel\NetAppel.exe" -nosplash -minimized
O4 - HKCU\..\Run: [VoipBuster] "C:\program files\voipbuster.com\voipbuster\voipbuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Grouper.lnk = C:\Program Files\Grouper\Grouper.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: wvusrqr - C:\WINDOWS\SYSTEM32\wvusrqr.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
1
Le sioux Messages postés 4907 Statut Contributeur sécurité 496
 
Bonsoir Shaka 975

On continu ;)

Jette le CFScript qui est sur ton Bureau, on va en créer un autre :

ComboFix avec CFScript :

* Sélectionne le texte suivant (en gras) dans son intégralité :


Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SystemDevic"=-
"System Service Manager Device"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"System Service Manager Device"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

File::
C:\[u]0[/u]h00.exe
C:\WINDOWS\system32\lcvdlpis.ini
C:\WINDOWS\system32\bvkwijqt.ini
C:\WINDOWS\img5-2007.zip
C:\WINDOWS\devic.exe
C:\devic.exe
C:\WINDOWS\system32\VundoFixSVC.exe
C:\WINDOWS\system32\svho.exe

Folder::
C:\Program Files\Options.ini
C:\Program Files\license.txt
C:\Program Files\File_id.diz


* Copie le texte sélectionné (CTRL+C).
* Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
* Colle le texte copié dans ce bloc-notes (CTRL+V).
* Sauvegarde ce fichier sous le nom de CFScript.txt

Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement

* Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe ( sur ton Bureau)

* Une fenêtre bleue va apparaître: au message qui apparaît Type 1 to continue, or 2 to abort , tape 1 puis valide.

* Patiente le temps du scan. Le Bureau va disparaître à plusieurs reprises : c'est normal!

Ne touche à rien tant que le scan n'est pas terminé.


* Une fois le scan achevé, un rapport va s'afficher : tu posteras son contenu et un nouveau rapport HijackThis.

* Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

@ +
1
shaka975
 
Bonsoir,voici le rapport ComboFix:

ComboFix 07-12-19.2 - Stéphane Coste 2007-12-28 14:42:30.3 - [color=red][b]FAT32[/b][/color]x86
Running from: C:\Documents and Settings\Stéphane Coste\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\Stéphane Coste\Bureau\CFScript.txt
* Created a new restore point

FILE
C:\[u]0[/u]h00.exe
C:\devic.exe
C:\WINDOWS\devic.exe
C:\WINDOWS\img5-2007.zip
C:\WINDOWS\system32\bvkwijqt.ini
C:\WINDOWS\system32\lcvdlpis.ini
C:\WINDOWS\system32\svho.exe
C:\WINDOWS\system32\VundoFixSVC.exe
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\devic.exe
C:\Program Files\File_id.diz\
C:\Program Files\license.txt\
C:\Program Files\Options.ini\
C:\WINDOWS\devic.exe
C:\WINDOWS\img5-2007.zip
C:\WINDOWS\system32\bvkwijqt.ini
C:\WINDOWS\system32\lcvdlpis.ini
C:\WINDOWS\system32\mlnmp.ini
C:\WINDOWS\system32\mlnmp.ini2
C:\WINDOWS\system32\pmnlm.dll
C:\WINDOWS\system32\svho.exe
C:\WINDOWS\system32\VundoFixSVC.exe
C:\WINDOWS\system32\wvusrqr.dll

.
((((((((((((((((((((((((((((( Fichiers cr‚‚s 2007-11-28 to 2007-12-28 ))))))))))))))))))))))))))))))))))))
.

2007-12-28 14:49 . 2007-12-28 14:49 268 --ah----- C:\sqmdata05.sqm
2007-12-28 14:49 . 2007-12-28 14:49 244 --ah----- C:\sqmnoopt05.sqm
2007-12-27 23:14 . 2007-12-27 23:14 268 --ah----- C:\sqmdata04.sqm
2007-12-27 23:14 . 2007-12-27 23:14 244 --ah----- C:\sqmnoopt04.sqm
2007-12-27 21:40 . 2007-12-27 21:40 81,986 --a------ C:\[u]0[/u]h00.exe
2007-12-19 22:16 . 2007-12-19 22:16 <REP> d-------- C:\Hijackthis
2007-12-19 01:41 . 2007-12-20 06:02 22,321 --a------ C:\device.exe
2007-12-19 01:38 . 2007-12-19 01:38 22,321 --a------ C:\devices.exe
2007-12-18 19:36 . 2007-12-18 19:36 <REP> d-------- C:\VundoFix Backups
2007-12-18 18:56 . 2007-12-18 18:56 <REP> d-------- C:\WINDOWS\ERUNT
2007-12-18 18:53 . 2007-12-18 18:53 <REP> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2007-12-18 01:46 . 2007-12-18 01:46 <REP> d-------- C:\Program Files\LiveKillCleanMessenger
2007-12-17 18:16 . 2007-12-17 18:16 <REP> d-------- C:\Program Files\Spyware Doctor
2007-12-17 18:16 . 2007-12-17 18:19 74,240 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2007-12-17 18:16 . 2007-12-17 18:19 56,832 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2007-12-17 18:16 . 2007-10-18 00:14 41,288 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2007-12-17 18:16 . 2007-10-18 00:16 29,000 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2007-12-17 18:15 . 2007-12-17 18:15 <REP> d-------- C:\Program Files\Webroot
2007-12-17 18:15 . 2007-12-17 18:15 <REP> d-------- C:\Documents and Settings\LocalService\Application Data\Webroot
2007-12-17 18:15 . 2007-12-17 18:15 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Webroot
2007-12-17 18:15 . 2007-03-01 19:54 144,960 --a------ C:\WINDOWS\system32\drivers\ssidrv.sys
2007-12-17 18:15 . 2007-03-01 19:54 22,080 --a------ C:\WINDOWS\system32\drivers\sshrmd.sys
2007-12-17 18:15 . 2007-03-01 19:54 21,056 --a------ C:\WINDOWS\system32\drivers\sskbfd.sys
2007-12-17 18:15 . 2007-03-01 19:54 20,544 --a------ C:\WINDOWS\system32\drivers\SSFS0509.sys
2007-12-17 18:15 . 2007-12-17 18:15 164 --a------ C:\install.dat
2007-12-17 18:13 . 2007-12-17 18:13 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
2007-12-17 00:49 . 2007-12-17 00:49 121 --a------ C:\WINDOWS\wininit.ini

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AVASTSS.scr
2007-02-10 18:35 467 ----a-w C:\Program Files\Options.ini
2005-12-25 22:05 582 ----a-w C:\Program Files\BlackLst.ecb
2005-09-13 03:13 2,318 ----a-w C:\Program Files\license.txt
2005-01-15 02:38 2,117,632 ----a-w C:\Program Files\EasyClea.exe
2003-11-21 23:08 226 ----a-w C:\Program Files\File_id.diz
.

((((((((((((((((((((((((((((( snapshot@2007-12-19_21.49.51.96 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-28 17:50:34 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_644.dat
+ 2007-12-28 17:50:58 16,384 ----a-w C:\WINDOWS\Temp\Perflib_Perfdata_b0.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FreeRAM XP"="C:\unzipped\framxpro\FreeRAM XP Pro 1.40.exe" [2003-11-30 23:13]
"SuperCopier.exe"="C:\Program Files\SuperCopier\SuperCopier.exe" [2003-04-24 19:03]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-12-18 17:32]
"LogitechSoftwareUpdate"="C:\Program Files\Logitech\Video\ManifestEngine.exe" [2004-10-08 12:06]
"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23]
"NetAppel"="C:\Program Files\NetAppel\NetAppel.exe" [2007-04-13 12:09]
"VoipBuster"="C:\program files\voipbuster.com\voipbuster\voipbuster.exe" [2007-07-02 12:08]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 20:09]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-18 12:52]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Hcontrol"="C:\WINDOWS\Hcontrol.exe" [2002-06-18 19:08]
"SiSUSBRG"="C:\WINDOWS\sisUSBrg.exe" [2002-10-01 21:00]
"SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2005-07-28 18:26]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2005-08-01 16:07]
"SiS KHooker"="C:\WINDOWS\System32\khooker.exe" [2002-01-25 02:30]
"LogitechVideoRepair"="C:\Program Files\Logitech\Video\ISStart.exe" [2004-10-08 12:31]
"LVCOMSX"="C:\WINDOWS\system32\LVCOMSX.EXE" [2004-10-08 11:52]
"LogitechVideoTray"="C:\Program Files\Logitech\Video\LogiTray.exe" [2004-10-08 12:24]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 10:00]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 06:24]
"SSBkgdUpdate"="C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 10:22]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 19:17]
"IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 19:30]
"BrMfcWnd"="C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" [2006-03-28 15:48]
"SetDefPrt"="C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe" [2005-01-26 18:02]
"ControlCenter3"="C:\Program Files\Brother\ControlCenter3\brctrcen.exe" [2006-04-10 14:58]
"System Device"="devices.exe" []

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-19 20:09]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ :\WINDOWS\syste

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^ASUS Hotkey.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\ASUS Hotkey.lnk
backup=C:\WINDOWS\pss\ASUS Hotkey.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Stéphane Coste^Menu Démarrer^Programmes^Démarrage^Webshots.lnk]
path=C:\Documents and Settings\Stéphane Coste\Menu Démarrer\Programmes\Démarrage\Webshots.lnk
backup=C:\WINDOWS\pss\Webshots.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ElbyCheckElbyCDFL]
C:\Program Files\Elaborate Bytes\CloneCD\ElbyCheck.exe /L ElbyCDFL

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck]

R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\system32\drivers\sis7012.sys [2002-06-06 14:06]
S3 BrScnUsb;Brother USB Still Image driver;C:\WINDOWS\system32\DRIVERS\BrScnUsb.sys [2004-10-15 12:50]
S3 sbext;Sound Blaster Extigy Audio Driver;C:\WINDOWS\system32\DRIVERS\sbext.sys []

.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-28 14:52:20
Windows 5.1.2600 Service Pack 2 FAT NTAPI

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.2180]
-> C:\Program Files\SuperCopier\SCHook.DLL
.
Completion time: 2007-12-28 14:54:31 - machine was rebooted
C:\ComboFix2.txt ... 2007-12-27 22:08
C:\ComboFix3.txt ... 2007-12-19 21:51
1
shaka975
 
Encoremerci pour l'aide.

Et maintenant le rapport HijackThis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:56:03, on 28/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Hcontrol.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\System32\khooker.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\WINDOWS\ATKOSD.exe
C:\unzipped\framxpro\FreeRAM XP Pro 1.40.exe
C:\Program Files\SuperCopier\SuperCopier.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\NetAppel\NetAppel.exe
C:\program files\voipbuster.com\voipbuster\voipbuster.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.exe
C:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.cheznoo.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: e-Carte Bleue Browser Helper Object - {2E03C0FD-4C48-43A7-9A54-00240C70FF16} - C:\WINDOWS\system32\BhoECart.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\Hcontrol.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\sisUSBrg.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [BrMfcWnd] "C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe" /AUTORUN
O4 - HKLM\..\Run: [SetDefPrt] "C:\Program Files\Brother\Brmfl06a\BrStDvPt.exe"
O4 - HKLM\..\Run: [ControlCenter3] "C:\Program Files\Brother\ControlCenter3\brctrcen.exe" /autorun
O4 - HKLM\..\Run: [System Device] devices.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\unzipped\framxpro\FreeRAM XP Pro 1.40.exe" -win
O4 - HKCU\..\Run: [SuperCopier.exe] C:\Program Files\SuperCopier\SuperCopier.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [NetAppel] "C:\Program Files\NetAppel\NetAppel.exe" -nosplash -minimized
O4 - HKCU\..\Run: [VoipBuster] "C:\program files\voipbuster.com\voipbuster\voipbuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = C:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Global Startup: Grouper.lnk = C:\Program Files\Grouper\Grouper.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Run DAP - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab56986.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Moteur Webroot Spy Sweeper (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
1
Le sioux Messages postés 4907 Statut Contributeur sécurité 496
 
Bonjour Shaka

Bien joué.

On continu ;)

Cleanzip

* Télécharge clean zip de Malekal_Morte http://www.malekal.com/download/clean.zip

* Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier clean.
* Ouvre le dossier Clean qui se trouve sur ton bureau.
* Double-clique sur clean.cmd.
Une fenêtre noire va apparaître,

choisis l'option 1

Puis poste le rapport qui se trouve ici C:\rapport_clean.txt

@ suivre
1
Le sioux Messages postés 4907 Statut Contributeur sécurité 496
 
Re

Puis fait cela aussi stp :

* Va sur VIRUS TOTAL https://www.virustotal.com/gui/

* Clique sur "parcourir" : C:\devices.exe

* Recherche le fichier à analyser, puis clique ensuite sur "send".

Il faut patienter car tu es sur une file d'attente.
Le rapport ne sera complet que lorsque tu verras la mention "FINISHED"sur la droite.

Dépose le dans ta prochaine réponse.

Tuto
: http://pageperso.aol.fr/loraline60/virus_total.htm

Note : Il est possible que tu es besoin d'avoir accès aux dossiers et fichiers cachés, pour cela "Affiche les dossiers cachés" Aide toi de B ) Afficher les dossiers cachés ici https://forum.pcastuces.com/sujet.asp?f=25&s=3902 si besoin.

@ +
1
shaka975
 
Bonsoir, voici le rapport CLEAN.
Je lance Virus Total.
@+

28/12/2007 a 20:22:03,66

*** Recherche des fichiers dans C:

*** Recherche des fichiers dans C:\WINDOWS\
C:\WINDOWS\windebug.log FOUND
C:\WINDOWS\windebug.log FOUND

*** Recherche des fichiers dans C:\WINDOWS\system32

*** Recherche des fichiers dans C:\Program Files
"C:\Program Files\msn messenger\riched20.dll" FOUND
1
Utilisateur anonyme
 
bonsoir shaka975 bonsoir le sioux , pour faire avancer
shaka975
Redémarre ton PC en mode sans échec :
Redémarre en mode sans échec (Pour cela : démarrer le PC en tapotant sur la touche F8 du clavier jusqu'à ce que le menu des options avancées de Windows apparaisse puis avec les touches fléchées du clavier, sélectionner Mode sans échec puis appuyer sur la touche Entrée...)
Double-clic sur clean. Cela va ouvrir une fenêtre noire.
Un menu va apparaître, choisis l'option 2 en appuyant sur la touche 2 de ton clavier.
Clean va travailler.
Un rapport Va etre généré, envoie le moi dans ta prochaine réponse !
1