Fenetre intempestive

Bonjour,

j'ai besoin d'aide, j'ai enormement de probleme des que je me connecte sur internet:
fenetre pub intempestive:
j'ai suivi vos conseils generaux voici ls différents rapports:

rapport AVG Anti-Spyware - Rapport d'analyse:
---------------------------------------------------------

+ Créé à: 11:51:14 16/12/2007

+ Résultat de l'analyse:

C:\Program Files\dr.exe -> Adware.Generic : Ignoré.
C:\Program Files\serial.dat -> Adware.Generic : Ignoré.
C:\Program Files\serial.zip -> Adware.Generic : Ignoré.
C:\Program Files\user32.exe -> Adware.Generic : Ignoré.
C:\Program Files\shell32.exe -> Downloader.IstBar.pm : Ignoré.
C:\WINDOWS\user32.exe -> Downloader.Small.dui : Ignoré.
C:\WINDOWS\patcher.exe -> Logger.Agent : Ignoré.

Fin du rapport

rapport BitDefender Online Scanner:

Scan report generated at: Wed, Dec 26, 2007 - 12:38:54

Scan path: C:\;D:\;E:\;F:\;H:\;

Statistics

Time
00:23:20

Files
166447

Folders
5634

Boot Sectors
3

Archives
1021

Packed Files
7986

Results

Identified Viruses
4

Infected Files
21

Suspect Files
0

Warnings
0

Disinfected
0

Deleted Files
20

Engines Info

Virus Definitions
884335

Engine build
AVCORE v1.0 (build 2422) (i386) (Sep 25 2007 08:26:36)

Scan plugins
14

Archive plugins
38

Unpack plugins
7

E-mail plugins
6

System plugins
1

Scan Settings

First Action
Disinfect

Second Action
Delete

Heuristics
Yes

Enable Warnings
Yes

Scanned Extensions
*;

Exclude Extensions

Scan Emails
Yes

Scan Archives
Yes

Scan Packed
Yes

Scan Files
Yes

Scan Boot
Yes

Scanned File
Status

C:\WINDOWS\system32\brbvxbdu.exe
Infected with: Trojan.Fotomoto.H

C:\WINDOWS\system32\brbvxbdu.exe
Disinfection failed

C:\WINDOWS\system32\brbvxbdu.exe
Deleted

C:\WINDOWS\system32\cbxyaba.dll
Infected with: Trojan.Vundo.DTJ

C:\WINDOWS\system32\cbxyaba.dll
Disinfection failed

C:\WINDOWS\system32\cbxyaba.dll
Deleted

C:\WINDOWS\system32\cwpaqpyj.dll
Infected with: Trojan.Vundo.DSJ

C:\WINDOWS\system32\cwpaqpyj.dll
Disinfection failed

C:\WINDOWS\system32\cwpaqpyj.dll
Deleted

C:\WINDOWS\system32\ddcdeca.dll
Infected with: Trojan.Vundo.DTJ

C:\WINDOWS\system32\ddcdeca.dll
Disinfection failed

C:\WINDOWS\system32\ddcdeca.dll
Deleted

C:\WINDOWS\system32\frwfajxg.dll
Infected with: Trojan.Vundo.DSJ

C:\WINDOWS\system32\frwfajxg.dll
Disinfection failed

C:\WINDOWS\system32\frwfajxg.dll
Deleted

C:\WINDOWS\system32\kcgoqigl.exe
Infected with: Trojan.Fotomoto.H

C:\WINDOWS\system32\kcgoqigl.exe
Disinfection failed

C:\WINDOWS\system32\kcgoqigl.exe
Deleted

C:\WINDOWS\system32\ljjiheb.dll
Infected with: Trojan.Vundo.DTJ

C:\WINDOWS\system32\ljjiheb.dll
Disinfection failed

C:\WINDOWS\system32\ljjiheb.dll
Delete failed

C:\WINDOWS\system32\lmfmexhi.exe
Infected with: Trojan.Fotomoto.H

C:\WINDOWS\system32\lmfmexhi.exe
Disinfection failed

C:\WINDOWS\system32\lmfmexhi.exe
Deleted

C:\WINDOWS\system32\lsaolfkc.exe
Infected with: Trojan.Fotomoto.H

C:\WINDOWS\system32\lsaolfkc.exe
Disinfection failed

C:\WINDOWS\system32\lsaolfkc.exe
Deleted

C:\WINDOWS\system32\mhctdrkp.exe
Infected with: Trojan.Fotomoto.H

C:\WINDOWS\system32\mhctdrkp.exe
Disinfection failed

C:\WINDOWS\system32\mhctdrkp.exe
Deleted

C:\WINDOWS\system32\mkrvyhxj.dll
Infected with: Trojan.Vundo.DSJ

C:\WINDOWS\system32\mkrvyhxj.dll
Disinfection failed

C:\WINDOWS\system32\mkrvyhxj.dll
Deleted

C:\WINDOWS\system32\mljjggf.dll
Infected with: Trojan.Vundo.DTJ

C:\WINDOWS\system32\mljjggf.dll
Disinfection failed

C:\WINDOWS\system32\mljjggf.dll
Deleted

C:\WINDOWS\system32\ninnuscl.exe
Infected with: Trojan.Fotomoto.H

C:\WINDOWS\system32\ninnuscl.exe
Disinfection failed

C:\WINDOWS\system32\ninnuscl.exe
Deleted

C:\WINDOWS\system32\oaftfcxy.dll
Infected with: Trojan.Vundo.DSJ

C:\WINDOWS\system32\oaftfcxy.dll
Disinfection failed

C:\WINDOWS\system32\oaftfcxy.dll
Deleted

C:\WINDOWS\system32\snjayuqi.exe
Infected with: Trojan.Fotomoto.H

C:\WINDOWS\system32\snjayuqi.exe
Disinfection failed

C:\WINDOWS\system32\snjayuqi.exe
Deleted

C:\WINDOWS\system32\tndgapmd.dll
Infected with: Trojan.Vundo.DRT

C:\WINDOWS\system32\tndgapmd.dll
Disinfection failed

C:\WINDOWS\system32\tndgapmd.dll
Deleted

C:\WINDOWS\system32\ujktosfh.dll
Infected with: Trojan.Vundo.DSJ

C:\WINDOWS\system32\ujktosfh.dll
Disinfection failed

C:\WINDOWS\system32\ujktosfh.dll
Deleted

C:\WINDOWS\system32\vturspm.dll
Infected with: Trojan.Vundo.DTJ

C:\WINDOWS\system32\vturspm.dll
Disinfection failed

C:\WINDOWS\system32\vturspm.dll
Deleted

C:\WINDOWS\system32\vtuspmk.dll
Infected with: Trojan.Vundo.DTJ

C:\WINDOWS\system32\vtuspmk.dll
Disinfection failed

C:\WINDOWS\system32\vtuspmk.dll
Deleted

C:\WINDOWS\system32\wmqqynaf.dll
Infected with: Trojan.Vundo.DSJ

C:\WINDOWS\system32\wmqqynaf.dll
Disinfection failed

C:\WINDOWS\system32\wmqqynaf.dll
Deleted

C:\WINDOWS\system32\yaywvur.dll
Infected with: Trojan.Vundo.DTJ

C:\WINDOWS\system32\yaywvur.dll
Disinfection failed

C:\WINDOWS\system32\yaywvur.dll
Deleted

rapport hijack:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:50:58, on 26/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\WINDOWS\vVX1000.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Microsoft LifeCam\MSCamS32.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Fichiers communs\LibreSystem\strpmon.exe
C:\Program Files\AdvancedCleaner Free\UADCcw.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\WINDOWS\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.neuf.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [5806a434] rundll32.exe "C:\WINDOWS\system32\ctovrels.dll",b
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Fichiers communs\LibreSystem\strpmon.exe" dm=http://ww25.libresystem.com/ ad=http://ww25.libresystem.com/ sd=http://ww25.repay.libresystem.com/
O4 - HKLM\..\Run: [UADCFR_2949259188] "C:\Program Files\AdvancedCleaner Free\UADCcw.exe" -c
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\nwybmsae.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe

--
End of file - 8792 bytes

merci d'avance
Configuration: Windows XP
Internet Explorer 7.0

6 réponses

  1. Contributeur sécurité
    bonjour,

    on va vérifier fait ceci :

    Télécharge navilog1 (Merci il.mafioso!)

    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    * Ensuite double clique sur navilog1.exe pour lancer l'installation.

    * Une fois l'installation terminée, le fix s'exécutera automatiquement.

    * (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    * Laisse-toi guider. Au menu principal, choisis 1 et valides.

    /*\ Ne fais pas le choix 2,3 ou 4 sans notre avis/accord /*\

    * Patiente jusqu'au message : *** Analyse terminée le ..... ***

    * Appuie sur une touche comme demandé, le Bloc-notes va s'ouvrir.

    * Copie-colle l'intégralité du rapport dans ta prochaine réponse. Referme le Bloc-notes.

    * Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    0
    1. merci à toi de te pencher sur mon cas voici le rapport que tu m'as demandé:

      Search Navipromo version 3.3.8 commencé le 26/12/2007 à 16:56:02,54

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Mise à jour le 11.12.2007 à 18h00 par IL-MAFIOSO

      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.11
      Système de fichiers : NTFS

      Executé en mode normal

      *** Recherche Programmes installés ***

      *** Recherche dossiers dans C:\WINDOWS ***

      *** Recherche dossiers dans C:\Program Files ***

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

      *** Recherche dossiers dans "C:\Documents and Settings\uti\application data" ***

      *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Aucun Fichier trouvé

      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans C:\WINDOWS\system32 *

      * Recherche dans "C:\Documents and Settings\uti\local settings\application data" *

      *** Recherche fichiers ***

      *** Recherche clés spécifiques dans le Registre ***

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :

      2)Recherche Heuristique :

      * Dans C:\WINDOWS\system32 :

      * Dans "C:\Documents and Settings\uti\local settings\application data" :

      3)Recherche Certificats :

      Certificat Egroup absent !

      4)Recherche fichiers connus :

      C:\WINDOWS\system32\rtstv.ini2 trouvé ! infection Vundo possible non traitée par cet outil !

      *** Analyse terminée le 26/12/2007 à 16:57:52,21 ***
      0
      1. Contributeur sécurité
        re merci,

        c'est du vundo

        * Télécharge VundoFix.exe (par Atribune) sur ton Bureau

        http://www.atribune.org/ccount/click.php?id=4

        * Double-clique VundoFix.exe afin de le lancer

        * Clique sur le bouton Scan for Vundo

        * Lorsque le scan est complété, clique sur le bouton Remove Vundo

        * Une invite te demandera si tu veux supprimer les fichiers, clique YES

        * Après avoir cliqué "Yes", le Bureau disparaîtra un moment lors de la suppression des fichiers

        * Tu verras une invite qui t'annonce que ton PC va redémarrer; clique OK

        * Copie/colle le contenu du rapport situé dans C:\vundofix.txt ainsi qu'un nouveau rapport HijackThis dans ta prochaine réponse

        Note: Il est possible que VundoFix soit confronté à un fichier qu'il ne peut supprimer. Si tel est le cas, l'outil se lancera au prochain redémarrage; il faut simplement suivre les instructions ci-haut, à partir de "clique sur le bouton Scan for Vundo".
        0
        1. salut, voici les 2 rapports:

          VundoFix V6.7.6

          Checking Java version...

          Sun Java not detected
          Scan started at 17:51:27 26/12/2007

          Listing files found while scanning....

          C:\windows\system32\gebyw.dll
          C:\WINDOWS\system32\ljjiheb.dll
          C:\windows\system32\sstqo.dll
          C:\windows\system32\vtutq.dll

          Beginning removal...

          Attempting to delete C:\windows\system32\gebyw.dll
          C:\windows\system32\gebyw.dll Has been deleted!

          Attempting to delete C:\WINDOWS\system32\ljjiheb.dll
          C:\WINDOWS\system32\ljjiheb.dll Could not be deleted.

          Attempting to delete C:\windows\system32\sstqo.dll
          C:\windows\system32\sstqo.dll Has been deleted!

          Attempting to delete C:\windows\system32\vtutq.dll
          C:\windows\system32\vtutq.dll Has been deleted!

          Performing Repairs to the registry.
          Done!

          VundoFix V6.7.6

          Checking Java version...

          Sun Java not detected
          Scan started at 18:01:27 26/12/2007

          Listing files found while scanning....

          No infected files were found.

          Beginning removal...

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 18:09:29, on 26/12/2007
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16574)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          C:\Program Files\Microsoft LifeCam\MSCamS32.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Spyware Doctor\svcntaux.exe
          C:\Program Files\Spyware Doctor\swdsvc.exe
          C:\Program Files\Spyware Doctor\SDTrayApp.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\SearchIndexer.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\System32\alg.exe
          C:\WINDOWS\system32\SearchProtocolHost.exe
          C:\Program Files\Analog Devices\Core\smax4pnp.exe
          C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
          C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
          C:\WINDOWS\vVX1000.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
          C:\Program Files\Fichiers communs\LibreSystem\strpmon.exe
          C:\Program Files\AdvancedCleaner Free\UADCcw.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\WINDOWS\system32\SearchFilterHost.exe
          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.neuf.fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://french.icrfast.com/index.php?rvs=hompag
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
          O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
          O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
          O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
          O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [5806a434] rundll32.exe "C:\WINDOWS\system32\ctovrels.dll",b
          O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Fichiers communs\LibreSystem\strpmon.exe" dm=http://ww25.libresystem.com/ ad=http://ww25.libresystem.com/ sd=http://ww25.repay.libresystem.com/
          O4 - HKLM\..\Run: [UADCFR_2949259188] "C:\Program Files\AdvancedCleaner Free\UADCcw.exe" -c
          O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
          O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
          O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
          O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
          O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\nwybmsae.exe (file missing)
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
          O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
          O23 - Service: Windows Live Setup Service (WLSetupSvc) - Unknown owner - C:\Program Files\Windows Live\installer\WLSetupSvc.exe
          0
          1. Contributeur sécurité
            re

            parfait, on continue

            * lance hijackthis "do a system scan only" puis coche ces lignes :

            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.fr/0SEFRFR/SAOS01?FORM=TOOLBR
            R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
            O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [5806a434] rundll32.exe "C:\WINDOWS\system32\ctovrels.dll",b
            O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Fichiers communs\LibreSystem\strpmon.exe" dm=http://libresystem.com ad=http://libresystem.com sd=http://repay.libresystem.com
            O4 - HKLM\..\Run: [UADCFR_2949259188] "C:\Program Files\AdvancedCleaner Free\UADCcw.exe" -c
            O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\nwybmsae.exe (file missing)

            * toutes applications fermées et HORS CONNEXION, clique sur FIX CHECKED

            * via ajout et suppression de programmes, supprime si tu le trouves

            AdvancedCleaner Free


            puis

            Télécharge OTMoveIt (de Old_Timer) sur ton Bureau.
            http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe

            double-clique sur OTMoveIt.exe pour le lancer.
            copie la liste qui se trouve en citation ci-dessous,
            et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

            C:\WINDOWS\system32\nwybmsae.exe
            C:\Program Files\AdvancedCleaner Free
            C:\WINDOWS\system32\ctovrels.dll


            clique sur MoveIt! pour lancer la suppression.
            le résultat apparaitra dans le cadre Results.
            clique sur Exit pour fermer.
            poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

            il te sera peut-être demander de redémarrer le pc pour achever la suppression.
            si c'est le cas accepte par Yes.

            également

            * Télécharge combofix.exe (par sUBs) sur ton Bureau
            http://download.bleepingcomputer.com/sUBs/ComboFix.exe
            IMPORTANT

            *désactive ton antivirus, antispyware, et spybot (résident) durant l'utilisation de ComboFix . Merci. Tu réactives ensuite
            puis

            * Double clique combofix.exe.

            * Tape sur la touche Y (Yes) pour démarrer le scan.

            * Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse

            NOTE : Le rapport se trouve également ici : C:\Combofix.txt

            ainsi qu'un nouveau rapport hijackthis
            0
            1. Search Navipromo version 3.5.6 commencé le 10.05.2008 à 17:20:02.14

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Postez ce rapport sur le forum pour le faire analyser !!!
              !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

              Outil exécuté depuis C:\Program Files\navilog1
              Session actuelle : "Admin"

              Mise à jour le 02.05.2008 à 22h00 par IL-MAFIOSO

              Microsoft Windows XP [version 5.1.2600]
              Internet Explorer : 6.0.2900.2180
              Système de fichiers : NTFS

              Executé en mode normal

              *** Recherche Programmes installés ***

              *** Recherche dossiers dans "C:\WINDOWS" ***

              *** Recherche dossiers dans "C:\Program Files" ***

              *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***

              *** Recherche dossiers dans "c:\docume~1\alluse~1\menudm~1\progra~1" ***

              *** Recherche dossiers dans "C:\Documents and Settings\Admin\applic~1" ***

              *** Recherche dossiers dans "C:\Documents and Settings\Admin\locals~1\applic~1" ***

              *** Recherche dossiers dans "C:\Documents and Settings\Admin\menudm~1\progra~1" ***

              *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
              pour + d'infos : http://www.gmer.net

              Aucun Fichier trouvé

              *** Recherche avec GenericNaviSearch ***
              !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
              !!! A vérifier impérativement avant toute suppression manuelle !!!

              * Recherche dans "C:\WINDOWS\system32" *

              * Recherche dans "C:\Documents and Settings\Admin\locals~1\applic~1" *

              *** Recherche fichiers ***

              *** Recherche clés spécifiques dans le Registre ***

              *** Module de Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Recherche nouveaux fichiers Instant Access :

              2)Recherche Heuristique :

              * Dans "C:\WINDOWS\system32" :

              * Dans "C:\Documents and Settings\Admin\locals~1\applic~1" :

              3)Recherche Certificats :

              Certificat Egroup absent !
              Certificat Electronic-Group absent !
              Certificat OOO-Favorit absent !
              Certificat Sunny-Day-Design-Ltd absent !

              4)Recherche fichiers connus :

              C:\WINDOWS\system32\sttEgfii.ini2 trouvé ! infection Vundo possible non traitée par cet outil !
              C:\WINDOWS\system32\yFMWHkkj.ini2 trouvé ! infection Vundo possible non traitée par cet outil !

              *** Analyse terminée le 10.05.2008 à 17:21:55.82 ***
              0