Des centaines de couuriers sortant

helene -  
 helene -
Bonjour,

Je viens vers vous car mon pc semble être infecté par un cheval de troie dont je n'arrive pas à me débarrasser. Des centaines de courriers d'inconnus sortant passent par mon ordinateur, rien que 7000 en 1h30.
Que me conseillez vous?
D'avance merci pour votre aide et vos conseils
A bientôt
Helene
Configuration: Windows XP
Firefox 2.0.0.11

110 réponses

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
Résumé de la discussion

Une infection par un cheval de Troie sur Windows XP provoque l'envoi de centaines de courriers sortants, signe de compromission et d'un besoin d'élimination rapide. Des réponses proposent des outils de décontamination comme SDFix et ComboFix, avec des rapports décrivant les fichiers et services supprimés et des scans identifiant des éléments malveillants du système. En parallèle, des détections antivirus ( Avast, AVG) et des rapports SDFix évoquent des composants supprimés comme srtwe.sys, sans garantie d'une restauration immédiate sur le système analysé. D'autres échanges évoquent la persistance des courriers sortants et les questions sur l'identification de l'adresse IP, sans clause finale sur la résolution du fil ni sur son issue.

Bobot (l'IA à votre service)
  1. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonsoir
    commence par ceci
    Télécharge sur le bureau
    ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    => Double-clic dessus
    => installe
    => Clic Do a system scan and save the log
    => coller le rapport
    si problème voir l'aide
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
    0
  2. Mundows Messages postés 169 Statut Membre 15
     
    Bonsoir,

    Vous êtes infectée par un troyen qui a transformé votre ordinateur en zombie pour le compte d'un spammeur.
    La première chose à faire est de déconnecter du réseau l'ordinateur infecté et d'utiliser un autre ordinateur si c'est possible.

    Questions:
    Avez vous un Antivirus ?
    Avez vous un pare feu ?

    Si vous n'avez aps de pare feu installez ceci : Sunbelt personal firewall : https://www.vipre.com/vipre-home-protection-products/
    Ensuite celui ci (antivirus) Antivir (si vous avez déjà un antivirus désinstallez le avant)

    après avoir installé le pare feu, celui ci vous permettra d'empêcher la connexion a internet du troyen.
    0
  3. helene
     
    Merci pour votre réponse
    Voici le rapport demandé
    J'espère avoir bien suivi vos instructions
    A plus tard
    Helene

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:12:52, on 01/24/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
    C:\WINDOWS\Explorer.EXE
    C:\ATI-CPanel\atiptaxx.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\Intuwave Ltd\Shared\mRouterRunTime\mRouterConfig.exe
    C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
    C:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {89A1E40D-0254-4F99-B9AE-B60A2D8754A9} - C:\WINDOWS\system32\cbxxyaa.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
    O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
    O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [mRouterConfig] "C:\Program Files\Intuwave Ltd\Shared\mRouterRunTime\mRouterConfig.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-21-1454471165-688789844-839522115-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Serge')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - S-1-5-21-1454471165-688789844-839522115-1006 Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe (User 'Serge')
    O4 - S-1-5-21-1454471165-688789844-839522115-1006 Startup: y'z toolbar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe (User 'Serge')
    O4 - S-1-5-21-1454471165-688789844-839522115-1006 User Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe (User 'Serge')
    O4 - S-1-5-21-1454471165-688789844-839522115-1006 User Startup: y'z toolbar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe (User 'Serge')
    O4 - Startup: stardock objectdock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
    O8 - Extra context menu item: &Download with TrueDownloader! - C:\Program Files\TrueDownloader\TrueDownloader.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
    O20 - Winlogon Notify: cbxxyaa - C:\WINDOWS\SYSTEM32\cbxxyaa.dll
    O20 - Winlogon Notify: winpsa32 - C:\WINDOWS\SYSTEM32\winpsa32.dll
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
    O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
    0
  4. Mundows Messages postés 169 Statut Membre 15
     
    infection par "C:\WINDOWS\SYSTEM32\winpsa32.dll"
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. helene
     
    bonsoir Mundows,
    merci pour le diagnostic, et maintenant, que dois je faire svp pour éradiquer ce truedownloader?
    d'avance merci à vous et à ep44
    helene
    0
  7. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Télécharge sur le Bureau.
    http://www.atribune.org/ccount/click.php?id=4

    => Double-clic VundoFix.exe.
    => Clic OK
    => Attendre le redemarrage de Vundofix
    => Clic Scan for Vundo
    => Le scan est assez long , à la fin
    => Clic Remove Vundo
    => Puis yes
    => Le Bureau disparaît un moment lors de la suppression des fichiers.
    => Message shutdown
    => clic OK
    => Redémarrage auto
    => copier le rapport qui est dans C:vundofix.txt

    ensuite

    Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    et sauvegarde le sur ton bureau et pas ailleurs!

    Double-clic sur combofix,
    Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
    @+
    0
    1. helene
       
      Bonjour ep44
      Si j'ai ce ver dont tu parles et que tu ne sais pas comment l'éradiquer, qui le saura??
      En tout cas merci de toujours t'occuper de moi ;-) quelle pugnacité, quelle patience et quelle générosité pour donner ainsi autant de son temps à des inconnus perdus:-)
      Voici le rapport combofix
      A ce soir
      Bise
      helene

      voComboFix 08-02-25.3 - Hélène 2008-02-26 13:12:22.8 - NTFSx86
      Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.145 [GMT 1:00]
      Endroit: C:\Documents and Settings\Hélène\Bureau\ComboFix.exe
      * Création d'un nouveau point de restauration

      [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
      .

      ((((((((((((((((((((((((((((( Fichiers créés 2008-01-26 to 2008-02-26 ))))))))))))))))))))))))))))))))))))
      .

      2008-02-25 11:51 . 2008-02-25 11:51 54,156 --ah----- C:\WINDOWS\QTFont.qfn
      2008-02-25 11:51 . 2008-02-25 11:51 1,409 --a------ C:\WINDOWS\QTFont.for
      2008-02-24 17:08 . 2008-02-25 19:32 <REP> d-------- C:\Program Files\CleanUp!
      2008-02-11 22:23 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
      2008-02-10 23:04 . 2008-02-24 17:11 <REP> d-------- C:\Rustbfix
      2008-02-10 16:27 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
      2008-02-10 16:27 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
      2008-02-10 16:27 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
      2008-02-10 16:27 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
      2008-02-10 16:27 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
      2008-02-10 16:27 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
      2008-02-10 16:27 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
      2008-02-10 12:12 . 2008-02-10 12:13 95,718,986 --a------ C:\Sauv.reg
      2008-02-10 10:22 . 2008-02-25 11:22 <REP> d-------- C:\Program Files\a-squared Free
      2008-02-10 09:40 . 2008-02-10 09:40 <REP> d-------- C:\Program Files\Lavasoft
      2008-02-10 09:39 . 2008-02-10 09:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
      2008-02-07 08:16 . 2008-02-07 08:15 691,545 --a------ C:\WINDOWS\unins000.exe
      2008-02-07 08:16 . 2008-02-07 08:16 3,449 --a------ C:\WINDOWS\unins000.dat
      2008-02-05 20:02 . 2008-02-05 20:02 <REP> d-------- C:\Documents and Settings\Serge\Application Data\SPAMfighter
      2008-02-04 15:59 . 2008-02-10 16:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
      2008-02-03 12:10 . 2008-02-03 12:21 <REP> d-------- C:\ComboFix(2)
      2008-01-31 11:38 . 2008-01-31 11:38 <REP> d-------- C:\Documents and Settings\Serge\Application Data\BitDefender
      2008-01-31 04:25 . 2008-01-31 04:25 3,328 --a------ C:\bitdefenden1201749835_1_02.xml
      2008-01-31 00:19 . 2008-01-31 00:19 <REP> d-------- C:\Documents and Settings\Hélène\Application Data\BitDefender
      2008-01-31 00:16 . 2008-01-31 00:17 <REP> d-------- C:\Program Files\BitDefender
      2008-01-31 00:16 . 2008-01-31 00:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
      2008-01-31 00:14 . 2008-01-31 12:43 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
      2008-01-29 23:22 . 2008-01-29 23:22 268 --ah----- C:\sqmdata00.sqm
      2008-01-29 23:22 . 2008-01-29 23:22 244 --ah----- C:\sqmnoopt00.sqm
      2008-01-29 23:22 . 2008-01-29 23:22 172 --ah----- C:\sqmnoopt01.sqm
      2008-01-29 23:22 . 2008-01-29 23:22 172 --ah----- C:\sqmdata01.sqm

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-02-26 12:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
      2008-02-25 23:00 --------- d-----w C:\Documents and Settings\Serge\Application Data\OpenOffice.org2
      2008-02-25 22:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
      2008-02-25 18:32 --------- d-----w C:\Documents and Settings\Hélène\Application Data\OpenOffice.org2
      2008-02-25 09:43 --------- d-----w C:\Program Files\Trend Micro
      2008-02-24 16:09 --------- d-----w C:\Program Files\eMule
      2008-02-11 21:23 --------- d-----w C:\Program Files\Java
      2008-02-10 08:39 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
      2008-02-07 07:18 --------- d-----w C:\Program Files\Spybot - Search & Destroy
      2008-02-06 21:43 3,543,315 -c--a-w C:\WINDOWS\system32\drivers\fwdrv.err
      2008-01-24 18:19 54,764 ----a-w C:\WINDOWS\system32\drivers\srtwe.sys
      2008-01-16 22:25 --------- d-----w C:\Program Files\iTunes
      2008-01-16 22:25 --------- d-----w C:\Program Files\iPod
      2008-01-16 22:23 --------- d-----w C:\Program Files\QuickTime
      2008-01-10 19:17 --------- d-----w C:\Program Files\mst software
      2008-01-10 19:15 --------- d-----w C:\Program Files\winMd5Sum
      2008-01-10 11:46 --------- d-----w C:\Documents and Settings\Geoffroy\Application Data\OpenOffice.org2
      2008-01-09 15:33 --------- d-----w C:\Program Files\vLite
      2008-01-08 15:01 --------- d-----w C:\Program Files\BitZipper
      2008-01-07 13:02 --------- d-----w C:\Documents and Settings\Hélène\Application Data\Leadertech
      2008-01-07 10:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
      2008-01-07 10:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skyline
      2008-01-07 10:07 --------- d-----w C:\Program Files\OSCILLO
      2008-01-07 10:06 --------- d-----w C:\Program Files\Microsoft Works
      2008-01-07 09:56 --------- d-----w C:\Program Files\Windows Live
      2008-01-07 09:54 --------- d-----w C:\Program Files\Skype
      2008-01-07 09:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
      2008-01-07 09:53 --------- d-----w C:\Program Files\Fichiers communs\Real
      2008-01-07 09:45 --------- d-----w C:\Program Files\Windows Media Connect 2
      2008-01-03 16:56 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
      2008-01-03 16:53 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
      2008-01-03 16:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
      2008-01-01 14:12 --------- d-----w C:\Program Files\OneStepSearch
      2008-01-01 14:07 --------- d-----w C:\Program Files\eChanblard
      2007-12-14 10:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
      2007-12-07 00:47 670,208 ----a-w C:\WINDOWS\system32\wininet.dll
      2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
      2007-11-27 15:46 77,824 ----a-w C:\WINDOWS\system32\xcomm(2).dll
      2007-09-12 12:05 5,632 -csha-w C:\Program Files\Thumbs.db
      2007-03-21 21:27 3,254,166 -c--a-w C:\Program Files\openofficeorg4.cab
      2007-03-21 21:26 60,829,588 -c--a-w C:\Program Files\openofficeorg3.cab
      2007-03-21 21:21 15,288,213 -c--a-w C:\Program Files\openofficeorg2.cab
      2007-03-21 21:20 18,202,413 -c--a-w C:\Program Files\openofficeorg1.cab
      2007-03-21 21:19 217 -c--a-w C:\Program Files\setup.ini
      2007-03-21 21:18 4,856,320 -c--a-w C:\Program Files\openofficeorg22.msi
      2007-03-06 10:34 319,488 -c--a-w C:\Program Files\setup.exe
      2007-02-05 21:37 14,993,976 -c--a-w C:\Program Files\GoogleEarthWin.exe
      2007-02-02 22:27 5,736,656 -c--a-w C:\Program Files\Firefox Setup 2.0.0.1.exe
      2007-01-31 13:44 849 -c--a-w C:\Program Files\AVG Anti-Spyware.lnk
      2007-01-06 18:57 10,703,680 -c--a-w C:\Program Files\NDP1.1sp1-KB867460-X86.exe
      2007-01-05 22:16 1,475,376 -c--a-w C:\Program Files\GenuineCheck.exe
      2007-01-04 19:43 4,569,325 -c--a-w C:\Program Files\Calendrier_2007_Voyages-sncf.com.exe
      2006-12-18 08:29 533 -c-ha-w C:\Documents and Settings\Geoffroy\hpothb07.dat
      2006-12-17 10:35 0 -c--a-w C:\Program Files\cqwydcgt.exe
      2006-11-30 15:17 5,298,688 -c--a-w C:\Program Files\openofficeorg21.msi
      2006-11-22 14:41 935 -c-ha-w C:\Documents and Settings\Hélène\hpothb07.dat
      2006-11-22 14:41 935 -c-ha-w C:\Documents and Settings\Hélène\hpothb07.dat
      2006-11-22 14:41 343 -c-ha-w C:\Documents and Settings\Default User\hpothb07.dat
      2006-11-22 14:41 343 -c-ha-w C:\Documents and Settings\Administrateur\hpothb07.dat
      2006-11-22 14:41 340 -c-ha-w C:\Documents and Settings\NetworkService\hpothb07.dat
      2006-11-22 14:41 336 -c-ha-w C:\Documents and Settings\LocalService\hpothb07.dat
      2006-11-22 14:41 333 -c-ha-w C:\Documents and Settings\Camille\hpothb07.dat
      2006-11-22 14:41 325 -c-ha-w C:\Documents and Settings\All Users\hpothb07.dat
      2006-11-22 14:41 1,003 -c-ha-w C:\Documents and Settings\Serge\hpothb07.dat
      2006-07-18 13:41 1,019,094 -csha-r C:\Program Files\serial.tde
      2006-07-04 21:56 11,290,496 -c--a-w C:\Program Files\setupfre.exe
      2006-06-29 23:00 14,356,904 -c--a-w C:\Program Files\zlsSetup_65_725_000_fr.exe
      2006-05-28 16:46 397,306 -csha-r C:\Program Files\wunauclt.zip
      2006-05-28 16:46 397,306 -csha-r C:\Program Files\wunauclt.tbe
      2006-03-31 22:06 43 -c--a-w C:\Program Files\blank.gif
      2006-03-31 22:06 12,334 -c--a-w C:\Program Files\stubinstaller.ini
      2006-03-18 08:41 1,455,106 -c--a-w C:\Program Files\fdminst.exe
      2006-03-18 08:25 2,628,754 -c--a-w C:\Program Files\SetupTrueDownloader.exe
      2006-03-14 11:30 57,796 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_47_08_small.dmp.zip
      2006-03-14 11:30 56,399 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_46_56_small.dmp.zip
      2006-03-14 11:30 54,334 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_18_40_small.dmp.zip
      2006-03-14 11:30 49,110 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_46_37_small.dmp.zip
      2006-03-14 07:18 65,292 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_17_14_small.dmp.zip
      2006-03-14 07:17 64,644 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_09_39_small.dmp.zip
      2006-02-23 19:35 2,016,856 -c--a-w C:\Program Files\rd2005trial.exe
      2006-02-16 23:00 1,485,368 -c--a-w C:\Program Files\GoogleDesktopSetup.exe
      2006-02-11 22:16 285,580 -c--a-w C:\Program Files\Autoruns.zip
      2006-02-10 22:54 8,634 -c--a-w C:\Program Files\startuplist.txt
      2006-02-10 22:52 58,368 -c--a-w C:\Program Files\StartupList.exe
      2006-02-10 22:41 1,526,976 -c--a-w C:\Program Files\soref_regclean.exe
      2006-02-08 19:35 2,855,080 -c--a-w C:\Program Files\aawsepersonal.exe
      2006-02-08 19:26 5,037,072 -c--a-w C:\Program Files\spybotsd14.exe
      2006-02-06 22:54 849,833 -c--a-w C:\Program Files\Startup_manager_2.0.zip
      2006-02-02 19:09 27,977,025 -c--a-w C:\Program Files\vista-inspirat-pack_vista_inspirat_pack_1.1_francais_15013.exe
      2005-09-16 21:40 985,739 -c--a-w C:\Program Files\ThumbClic.zip
      2005-05-06 10:01 234,240 -c--a-w C:\Program Files\FrReform.exe
      2005-04-18 12:31 2,609,152 -c--a-w C:\Program Files\Ink.msi
      2002-03-11 09:06 1,822,520 -c--a-w C:\Program Files\instmsiw.exe
      2002-03-11 08:45 1,708,856 -c--a-w C:\Program Files\instmsia.exe
      .

      ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      REGEDIT4
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-03-30 11:31 68856]
      "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ATIPTA"="C:\ATI-CPanel\atiptaxx.exe" [2004-05-25 20:10 339968]
      "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
      "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
      "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
      "UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "Windows Time"="winmgr.exe" []

      C:\Documents and Settings\Serge\Menu D‚marrer\Programmes\D‚marrage\
      Stardock ObjectDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe [2005-02-21 14:56:00 1826885]
      y'z toolbar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe [2002-09-29 14:41:00 90112]

      C:\Documents and Settings\H‚lŠne\Menu D‚marrer\Programmes\D‚marrage\
      stardock objectdock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe [2005-02-21 14:56:00 1826885]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
      "AllowLegacyWebView"= 1 (0x1)
      "AllowUnhashedWebView"= 1 (0x1)

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
      "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "EnableFirewall"= 0 (0x0)

      R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-03-16 08:56]
      R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-03-16 08:56]
      R2 CX23880;MSI 8606 Video Capture;C:\WINDOWS\system32\drivers\CX88Vid.SYS [2003-08-28 15:14]
      R2 CX88XBAR;MSI 8606 Crossbar;C:\WINDOWS\system32\drivers\CX88XBar.SYS [2003-03-19 13:50]
      R2 CXTUNE;MSI 8606 Tuner;C:\WINDOWS\system32\drivers\CX88Tune.SYS [2003-08-21 15:35]
      S3 camvid20;Philips ToUcam Camera; Video;C:\WINDOWS\system32\DRIVERS\camdrv21.sys []
      S3 MPCSYS;MPCSYS;C:\WINDOWS\System32\DRIVERS\mpcsys.sys [2007-01-31 09:03]
      S3 PVUSB;CESG502 USB Driver;C:\WINDOWS\system32\DRIVERS\CESG502.sys [2007-12-12 19:16]
      S3 zebrbus;Sony Ericsson Composite Device driver;C:\WINDOWS\system32\DRIVERS\zebrbus.sys [2006-07-25 17:36]

      .
      Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
      "2008-01-16 22:08:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
      - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
      "2008-01-28 08:00:00 C:\WINDOWS\Tasks\At73.job"
      - C:\WINDOWS\user32.exe
      "2008-06-16 09:12:08 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1159858088.job"
      - C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
      .
      **************************************************************************

      catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-02-26 13:19:08
      Windows 5.1.2600 Service Pack 2 NTFS

      Balayage processus cachés ...

      Balayage caché autostart entries ...

      Balayage des fichiers cachés ...

      Scan terminé avec succès
      Les fichiers cachés: 0

      **************************************************************************
      .
      --------------------- DLLs a chargé sous des processus courants ---------------------

      PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
      -> C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\DockShellHook.dll
      .
      Temps d'accomplissement: 2008-02-26 13:22:38
      .
      2008-02-23 10:19:14 --- E O F ---
      0
    2. helene
       
      au fait, pourquoi est ce qu'on ne coche pas tout simplement la ligne 4 du ver pour la supprimer?
      question certainement très stupide...mais je la pose quand même:-)
      à ce soir
      helene
      0
  8. helene
     
    Merci ep44
    je me lance et vous fais signe quand j'ai fini
    à plus tard
    helene
    0
  9. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    ok
    0
  10. helene
     
    dites ep44, pendant que vindofix scanne, je vois qu'après je dois télécharger un logiciel et le sauvegarder sur le bureau et "pas ailleurs"
    comment devrais je m'y prendre
    merci
    0
  11. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    et bien tu le télécharge sur ton bureau et pas ailleurs
    donc que sur ton bureau ;-)))

    et le tutoiement est de vigueur ;-)))
    @++
    0
  12. helene
     
    me revoici ep44 avec le rapport vundofix, sauf erreur, je n'ai pas trouvé celui de combofix
    mon pc rame de plus en plus
    et maintenant, que dois-je faire?
    merci pour tout
    à plus tard
    helene

    VundoFix V6.7.7

    Checking Java version...

    Java version is 1.4.2.3
    Old versions of java are exploitable and should be removed.

    Java version is 1.5.0.2
    Old versions of java are exploitable and should be removed.

    Java version is 1.5.0.4
    Old versions of java are exploitable and should be removed.

    Java version is 1.5.0.6
    Old versions of java are exploitable and should be removed.

    Java version is 1.5.0.9
    Old versions of java are exploitable and should be removed.

    Scan started at 21:35:29 01/24/2008

    Listing files found while scanning....

    C:\WINDOWS\system32\cbxxyaa.dll
    C:\WINDOWS\system32\mljgd.dll
    C:\WINDOWS\system32\winpsa32.dll

    Beginning removal...

    Attempting to delete C:\WINDOWS\system32\cbxxyaa.dll
    C:\WINDOWS\system32\cbxxyaa.dll Could not be deleted.

    Attempting to delete C:\WINDOWS\system32\mljgd.dll
    C:\WINDOWS\system32\mljgd.dll Has been deleted!

    Attempting to delete C:\WINDOWS\system32\winpsa32.dll
    C:\WINDOWS\system32\winpsa32.dll Has been deleted!

    Performing Repairs to the registry.
    Done!

    Beginning removal...
    0
  13. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    pour celui de combofix regarde dans c:
    tu dois avoir un dossier texte
    0
  14. helene
     
    Voici les fichiers .txt trouvés dans C:combofix
    J'ai toujours des courriers qui arrivent mais en nombre semble t-il plus restreint.
    Que disent les rapports?
    Encore merci ep44 et à plus tard peut être demain

    ComboFix 08-01-23.1B - H‚lŠne 2008-01-24 22:18:20.1 - NTFSx86
    Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.204 [GMT 1:00]
    Endroit: C:\Documents and Settings\H‚lŠne\Bureau\ComboFix.exe
    * Création d'un nouveau point de restauration

    [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

    s/\x3b //g
    s/C:\\WINDOWS\\system32\\rundll32\.exe //I
    s/C:\\WINDOWS\\system32\\rundll32 //I
    s/rundll32\.exe //I
    s/rundll32 //I
    s/\x22//g
    s/^ +//
    s/,.*//
    s/<NO NAME>/@/
    s/\t.*\t/\t/
    s/\.exe .*/.exe/I
    s/\.dll .*/.dll/I
    s/\x25programfiles\x25/C:\\Program Files/I
    s/\x25systemroot\x25/C:\\WINDOWS/I
    .

    \??\C:\ntdetect.com\0\0
    \??\C:\boot.ini\0\0
    \??\C:\ntldr\0\0
    \??\C:\WINDOWS\0\0
    \??\C:\WINDOWS\explorer.exe\0\0
    \??\C:\WINDOWS\system32\csrss.exe\0\0
    \??\C:\WINDOWS\system32\lsass.exe\0\0
    \??\C:\WINDOWS\system32\services.exe\0\0
    \??\C:\WINDOWS\system32\smss.exe\0\0
    \??\C:\WINDOWS\system32\svchost.exe\0\0
    \??\C:\WINDOWS\system32\userinit.exe\0\0
    \??\C:\WINDOWS\system32\winlogon.exe\0\0
    \??\C:\WINDOWS\system32\hal.dll\0\0
    \??\C:\WINDOWS\system32\ntdll.dll\0\0
    \??\C:\WINDOWS\system32\config\0\0
    \??\C:\WINDOWS\system32\drivers\0\0
    \??\C:\WINDOWS\system32\wbem\0\0
    0
  15. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    ceci n'est pas le rapport de combofix

    relance combofix et laise le traviller
    il doit passer environ 40 étapes une fois fini il te met un rapport directement sur le bureau
    si tu ne le vois pas il se trouve dans c:
    regarde à quoi ressemble un rapport de combofix
    http://www.commentcamarche.net/forum/affich 4252452 ordinateur aun ralentie?page=2#27
    @+
    et à demain sans soucis ;-))
    0
  16. helene
     
    je sens la sommeil me gagner
    à demain donc
    bonne nuit et merci
    helene
    0
  17. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    ok fait ce que je viens de t'indiquer et à demain en fin de soirée pour moi
    @+
    0
  18. helene
     
    Bonjour ep44

    j'ai refait comme tu me l'as dit un combofix, je l'ai laissé "travailler" tranquillement, mais je n'ai toujours pas de rapport ni sur le bureau ni dans C, je dois mal m'y prendre.........
    j'ai refait un scan vundofix, voici le rapport, il n'a plus rien trouvé mais j'ai toujours les courriers d'inconnus qui défilent et qui ralentissent le pc
    j'attends les nouvelles instructions
    à ce soir
    merci
    helene

    Scan started at 11:13:42 2008-01-25

    Listing files found while scanning....

    No infected files were found.

    Beginning removal...
    0
  19. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonsoir Hélène,

    il serait vraiment bien d'avoir ce rapport il nous donnerait vraiment un bon coup de main
    normaleent tu devrais avoir dans c: un dossier texte nommé combofix.txt
    est-ce que tu la vraiment téléchargé sur ton bureau ?

    Il nous reste ceci à trouver C:\WINDOWS\system32\cbxxyaa.dll
    donc regarde bien si tu as ce rapport
    si tu ne trouve pas dit le moi on essaiera autre chose
    @+ ;-)
    0
    1. helene
       
      Bonjour ep44Merci d'être toujours là:-)
      voici le rapport hijack que tu m'as demandé
      Bonne journée
      A ce soir je pense
      Bise
      helene

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 10:43, on 2008-02-25
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
      C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\a-squared Free\a2service.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\MsPMSPSv.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\Explorer.EXE
      C:\ATI-CPanel\atiptaxx.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
      O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
      O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKUS\S-1-5-18\..\Run: [Windows Time] winmgr.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [Windows Time] winmgr.exe (User 'Default user')
      O4 - Startup: stardock objectdock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
      O8 - Extra context menu item: &Download with TrueDownloader! - C:\Program Files\TrueDownloader\TrueDownloader.htm
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
      O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
      O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
      O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
      0
  20. helene
     
    Bonjour ep44
    Désolée d'avoir tant tardée à répondre, j'étais absente tout le week end et je retrouve mon pc infectée!!!!!!evidemment...........
    Je n'ai définitivement pas trouvé ce fichu rapport! Mais en faisant une recherche avec le nom du "virus", voilà ce que j'ai trouvé:
    cbxxyaa.dll.bad dans le dossier C:vundofix backups
    cbxxyaa.dll.vir dans le dossier C:qoobox/quarantaine/C;/Windows/system32
    Voilà, j'attends toujours des conseils, je suis désolée de ne pas trouver ce rapport
    D'avance merci
    A bientôt
    Helene
    0
  21. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonsoir

    supprime tout les logiciels que nous avons utilisé
    ensuite tu retélécharge combofix et tu attends qu'il ai fini
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    tu doit avoir un rapport qui s'affiche de lui même
    si ce n'est pas le cas regarde dans c: tu doit avoir un dossier texte combofix
    @+
    0
  • 1
  • 2
  • 3
  • 4
  • 5
  • 6