Des centaines de couuriers sortant

Bonjour,

Je viens vers vous car mon pc semble être infecté par un cheval de troie dont je n'arrive pas à me débarrasser. Des centaines de courriers d'inconnus sortant passent par mon ordinateur, rien que 7000 en 1h30.
Que me conseillez vous?
D'avance merci pour votre aide et vos conseils
A bientôt
Helene
Configuration: Windows XP
Firefox 2.0.0.11

110 réponses

Résumé de la discussion

Une infection par un cheval de Troie sur Windows XP provoque l'envoi de centaines de courriers sortants, signe de compromission et d'un besoin d'élimination rapide. Des réponses proposent des outils de décontamination comme SDFix et ComboFix, avec des rapports décrivant les fichiers et services supprimés et des scans identifiant des éléments malveillants du système. En parallèle, des détections antivirus ( Avast, AVG) et des rapports SDFix évoquent des composants supprimés comme srtwe.sys, sans garantie d'une restauration immédiate sur le système analysé. D'autres échanges évoquent la persistance des courriers sortants et les questions sur l'identification de l'adresse IP, sans clause finale sur la résolution du fil ni sur son issue.

Bobot (l’IA à votre service)
  1. Contributeur
    Bonsoir
    commence par ceci
    Télécharge sur le bureau
    ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    => Double-clic dessus
    => installe
    => Clic Do a system scan and save the log
    => coller le rapport
    si problème voir l'aide
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
    0
    1. Bonsoir,

      Vous êtes infectée par un troyen qui a transformé votre ordinateur en zombie pour le compte d'un spammeur.
      La première chose à faire est de déconnecter du réseau l'ordinateur infecté et d'utiliser un autre ordinateur si c'est possible.

      Questions:
      Avez vous un Antivirus ?
      Avez vous un pare feu ?

      Si vous n'avez aps de pare feu installez ceci : Sunbelt personal firewall : https://www.vipre.com/vipre-home-protection-products/
      Ensuite celui ci (antivirus) Antivir (si vous avez déjà un antivirus désinstallez le avant)

      après avoir installé le pare feu, celui ci vous permettra d'empêcher la connexion a internet du troyen.
      0
      1. Merci pour votre réponse
        Voici le rapport demandé
        J'espère avoir bien suivi vos instructions
        A plus tard
        Helene

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 21:12:52, on 01/24/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\System32\MsPMSPSv.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\Program Files\iPod\bin\iPodService.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
        C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
        C:\WINDOWS\Explorer.EXE
        C:\ATI-CPanel\atiptaxx.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\iTunes\iTunesHelper.exe
        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        C:\Program Files\Intuwave Ltd\Shared\mRouterRunTime\mRouterConfig.exe
        C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
        C:\PROGRA~1\INTUWA~1\Shared\MROUTE~1\mRouterRuntime.exe
        C:\Program Files\Outlook Express\msimn.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: (no name) - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: (no name) - {89A1E40D-0254-4F99-B9AE-B60A2D8754A9} - C:\WINDOWS\system32\cbxxyaa.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
        O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
        O3 - Toolbar: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [mRouterConfig] "C:\Program Files\Intuwave Ltd\Shared\mRouterRunTime\mRouterConfig.exe"
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-21-1454471165-688789844-839522115-1006\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Serge')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - S-1-5-21-1454471165-688789844-839522115-1006 Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe (User 'Serge')
        O4 - S-1-5-21-1454471165-688789844-839522115-1006 Startup: y'z toolbar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe (User 'Serge')
        O4 - S-1-5-21-1454471165-688789844-839522115-1006 User Startup: Stardock ObjectDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe (User 'Serge')
        O4 - S-1-5-21-1454471165-688789844-839522115-1006 User Startup: y'z toolbar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe (User 'Serge')
        O4 - Startup: stardock objectdock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
        O8 - Extra context menu item: &Download with TrueDownloader! - C:\Program Files\TrueDownloader\TrueDownloader.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} -
        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
        O20 - Winlogon Notify: cbxxyaa - C:\WINDOWS\SYSTEM32\cbxxyaa.dll
        O20 - Winlogon Notify: winpsa32 - C:\WINDOWS\SYSTEM32\winpsa32.dll
        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
        O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
        0
        1. infection par "C:\WINDOWS\SYSTEM32\winpsa32.dll"
          0
          1. bonsoir Mundows,
            merci pour le diagnostic, et maintenant, que dois je faire svp pour éradiquer ce truedownloader?
            d'avance merci à vous et à ep44
            helene
            0
            1. Contributeur
              Télécharge sur le Bureau.
              http://www.atribune.org/ccount/click.php?id=4

              => Double-clic VundoFix.exe.
              => Clic OK
              => Attendre le redemarrage de Vundofix
              => Clic Scan for Vundo
              => Le scan est assez long , à la fin
              => Clic Remove Vundo
              => Puis yes
              => Le Bureau disparaît un moment lors de la suppression des fichiers.
              => Message shutdown
              => clic OK
              => Redémarrage auto
              => copier le rapport qui est dans C:vundofix.txt

              ensuite

              Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
              et sauvegarde le sur ton bureau et pas ailleurs!

              Double-clic sur combofix,
              Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.
              @+
              0
              1. Bonjour ep44
                Si j'ai ce ver dont tu parles et que tu ne sais pas comment l'éradiquer, qui le saura??
                En tout cas merci de toujours t'occuper de moi ;-) quelle pugnacité, quelle patience et quelle générosité pour donner ainsi autant de son temps à des inconnus perdus:-)
                Voici le rapport combofix
                A ce soir
                Bise
                helene

                voComboFix 08-02-25.3 - Hélène 2008-02-26 13:12:22.8 - NTFSx86
                Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.145 [GMT 1:00]
                Endroit: C:\Documents and Settings\Hélène\Bureau\ComboFix.exe
                * Création d'un nouveau point de restauration

                [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
                .

                ((((((((((((((((((((((((((((( Fichiers créés 2008-01-26 to 2008-02-26 ))))))))))))))))))))))))))))))))))))
                .

                2008-02-25 11:51 . 2008-02-25 11:51 54,156 --ah----- C:\WINDOWS\QTFont.qfn
                2008-02-25 11:51 . 2008-02-25 11:51 1,409 --a------ C:\WINDOWS\QTFont.for
                2008-02-24 17:08 . 2008-02-25 19:32 <REP> d-------- C:\Program Files\CleanUp!
                2008-02-11 22:23 . 2007-09-24 23:31 69,632 --a------ C:\WINDOWS\system32\javacpl.cpl
                2008-02-10 23:04 . 2008-02-24 17:11 <REP> d-------- C:\Rustbfix
                2008-02-10 16:27 . 2007-12-04 14:04 837,496 --a------ C:\WINDOWS\system32\aswBoot.exe
                2008-02-10 16:27 . 2007-12-04 13:54 95,608 --a------ C:\WINDOWS\system32\AvastSS.scr
                2008-02-10 16:27 . 2007-12-04 15:55 94,544 --a------ C:\WINDOWS\system32\drivers\aswmon2.sys
                2008-02-10 16:27 . 2007-12-04 15:56 93,264 --a------ C:\WINDOWS\system32\drivers\aswmon.sys
                2008-02-10 16:27 . 2007-12-04 15:51 42,912 --a------ C:\WINDOWS\system32\drivers\aswTdi.sys
                2008-02-10 16:27 . 2007-12-04 15:49 26,624 --a------ C:\WINDOWS\system32\drivers\aavmker4.sys
                2008-02-10 16:27 . 2007-12-04 15:53 23,152 --a------ C:\WINDOWS\system32\drivers\aswRdr.sys
                2008-02-10 12:12 . 2008-02-10 12:13 95,718,986 --a------ C:\Sauv.reg
                2008-02-10 10:22 . 2008-02-25 11:22 <REP> d-------- C:\Program Files\a-squared Free
                2008-02-10 09:40 . 2008-02-10 09:40 <REP> d-------- C:\Program Files\Lavasoft
                2008-02-10 09:39 . 2008-02-10 09:40 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
                2008-02-07 08:16 . 2008-02-07 08:15 691,545 --a------ C:\WINDOWS\unins000.exe
                2008-02-07 08:16 . 2008-02-07 08:16 3,449 --a------ C:\WINDOWS\unins000.dat
                2008-02-05 20:02 . 2008-02-05 20:02 <REP> d-------- C:\Documents and Settings\Serge\Application Data\SPAMfighter
                2008-02-04 15:59 . 2008-02-10 16:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
                2008-02-03 12:10 . 2008-02-03 12:21 <REP> d-------- C:\ComboFix(2)
                2008-01-31 11:38 . 2008-01-31 11:38 <REP> d-------- C:\Documents and Settings\Serge\Application Data\BitDefender
                2008-01-31 04:25 . 2008-01-31 04:25 3,328 --a------ C:\bitdefenden1201749835_1_02.xml
                2008-01-31 00:19 . 2008-01-31 00:19 <REP> d-------- C:\Documents and Settings\Hélène\Application Data\BitDefender
                2008-01-31 00:16 . 2008-01-31 00:17 <REP> d-------- C:\Program Files\BitDefender
                2008-01-31 00:16 . 2008-01-31 00:18 <REP> d-------- C:\Documents and Settings\All Users\Application Data\BitDefender
                2008-01-31 00:14 . 2008-01-31 12:43 <REP> d-------- C:\Program Files\Fichiers communs\BitDefender
                2008-01-29 23:22 . 2008-01-29 23:22 268 --ah----- C:\sqmdata00.sqm
                2008-01-29 23:22 . 2008-01-29 23:22 244 --ah----- C:\sqmnoopt00.sqm
                2008-01-29 23:22 . 2008-01-29 23:22 172 --ah----- C:\sqmnoopt01.sqm
                2008-01-29 23:22 . 2008-01-29 23:22 172 --ah----- C:\sqmdata01.sqm

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-02-26 12:10 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
                2008-02-25 23:00 --------- d-----w C:\Documents and Settings\Serge\Application Data\OpenOffice.org2
                2008-02-25 22:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                2008-02-25 18:32 --------- d-----w C:\Documents and Settings\Hélène\Application Data\OpenOffice.org2
                2008-02-25 09:43 --------- d-----w C:\Program Files\Trend Micro
                2008-02-24 16:09 --------- d-----w C:\Program Files\eMule
                2008-02-11 21:23 --------- d-----w C:\Program Files\Java
                2008-02-10 08:39 --------- d-----w C:\Program Files\Fichiers communs\Wise Installation Wizard
                2008-02-07 07:18 --------- d-----w C:\Program Files\Spybot - Search & Destroy
                2008-02-06 21:43 3,543,315 -c--a-w C:\WINDOWS\system32\drivers\fwdrv.err
                2008-01-24 18:19 54,764 ----a-w C:\WINDOWS\system32\drivers\srtwe.sys
                2008-01-16 22:25 --------- d-----w C:\Program Files\iTunes
                2008-01-16 22:25 --------- d-----w C:\Program Files\iPod
                2008-01-16 22:23 --------- d-----w C:\Program Files\QuickTime
                2008-01-10 19:17 --------- d-----w C:\Program Files\mst software
                2008-01-10 19:15 --------- d-----w C:\Program Files\winMd5Sum
                2008-01-10 11:46 --------- d-----w C:\Documents and Settings\Geoffroy\Application Data\OpenOffice.org2
                2008-01-09 15:33 --------- d-----w C:\Program Files\vLite
                2008-01-08 15:01 --------- d-----w C:\Program Files\BitZipper
                2008-01-07 13:02 --------- d-----w C:\Documents and Settings\Hélène\Application Data\Leadertech
                2008-01-07 10:12 --------- d--h--w C:\Program Files\InstallShield Installation Information
                2008-01-07 10:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skyline
                2008-01-07 10:07 --------- d-----w C:\Program Files\OSCILLO
                2008-01-07 10:06 --------- d-----w C:\Program Files\Microsoft Works
                2008-01-07 09:56 --------- d-----w C:\Program Files\Windows Live
                2008-01-07 09:54 --------- d-----w C:\Program Files\Skype
                2008-01-07 09:54 --------- d-----w C:\Documents and Settings\All Users\Application Data\Skype
                2008-01-07 09:53 --------- d-----w C:\Program Files\Fichiers communs\Real
                2008-01-07 09:45 --------- d-----w C:\Program Files\Windows Media Connect 2
                2008-01-03 16:56 --------- d-----w C:\Program Files\Microsoft SQL Server Compact Edition
                2008-01-03 16:53 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
                2008-01-03 16:51 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                2008-01-01 14:12 --------- d-----w C:\Program Files\OneStepSearch
                2008-01-01 14:07 --------- d-----w C:\Program Files\eChanblard
                2007-12-14 10:32 12,632 ----a-w C:\WINDOWS\system32\lsdelete.exe
                2007-12-07 00:47 670,208 ----a-w C:\WINDOWS\system32\wininet.dll
                2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll
                2007-11-27 15:46 77,824 ----a-w C:\WINDOWS\system32\xcomm(2).dll
                2007-09-12 12:05 5,632 -csha-w C:\Program Files\Thumbs.db
                2007-03-21 21:27 3,254,166 -c--a-w C:\Program Files\openofficeorg4.cab
                2007-03-21 21:26 60,829,588 -c--a-w C:\Program Files\openofficeorg3.cab
                2007-03-21 21:21 15,288,213 -c--a-w C:\Program Files\openofficeorg2.cab
                2007-03-21 21:20 18,202,413 -c--a-w C:\Program Files\openofficeorg1.cab
                2007-03-21 21:19 217 -c--a-w C:\Program Files\setup.ini
                2007-03-21 21:18 4,856,320 -c--a-w C:\Program Files\openofficeorg22.msi
                2007-03-06 10:34 319,488 -c--a-w C:\Program Files\setup.exe
                2007-02-05 21:37 14,993,976 -c--a-w C:\Program Files\GoogleEarthWin.exe
                2007-02-02 22:27 5,736,656 -c--a-w C:\Program Files\Firefox Setup 2.0.0.1.exe
                2007-01-31 13:44 849 -c--a-w C:\Program Files\AVG Anti-Spyware.lnk
                2007-01-06 18:57 10,703,680 -c--a-w C:\Program Files\NDP1.1sp1-KB867460-X86.exe
                2007-01-05 22:16 1,475,376 -c--a-w C:\Program Files\GenuineCheck.exe
                2007-01-04 19:43 4,569,325 -c--a-w C:\Program Files\Calendrier_2007_Voyages-sncf.com.exe
                2006-12-18 08:29 533 -c-ha-w C:\Documents and Settings\Geoffroy\hpothb07.dat
                2006-12-17 10:35 0 -c--a-w C:\Program Files\cqwydcgt.exe
                2006-11-30 15:17 5,298,688 -c--a-w C:\Program Files\openofficeorg21.msi
                2006-11-22 14:41 935 -c-ha-w C:\Documents and Settings\Hélène\hpothb07.dat
                2006-11-22 14:41 935 -c-ha-w C:\Documents and Settings\Hélène\hpothb07.dat
                2006-11-22 14:41 343 -c-ha-w C:\Documents and Settings\Default User\hpothb07.dat
                2006-11-22 14:41 343 -c-ha-w C:\Documents and Settings\Administrateur\hpothb07.dat
                2006-11-22 14:41 340 -c-ha-w C:\Documents and Settings\NetworkService\hpothb07.dat
                2006-11-22 14:41 336 -c-ha-w C:\Documents and Settings\LocalService\hpothb07.dat
                2006-11-22 14:41 333 -c-ha-w C:\Documents and Settings\Camille\hpothb07.dat
                2006-11-22 14:41 325 -c-ha-w C:\Documents and Settings\All Users\hpothb07.dat
                2006-11-22 14:41 1,003 -c-ha-w C:\Documents and Settings\Serge\hpothb07.dat
                2006-07-18 13:41 1,019,094 -csha-r C:\Program Files\serial.tde
                2006-07-04 21:56 11,290,496 -c--a-w C:\Program Files\setupfre.exe
                2006-06-29 23:00 14,356,904 -c--a-w C:\Program Files\zlsSetup_65_725_000_fr.exe
                2006-05-28 16:46 397,306 -csha-r C:\Program Files\wunauclt.zip
                2006-05-28 16:46 397,306 -csha-r C:\Program Files\wunauclt.tbe
                2006-03-31 22:06 43 -c--a-w C:\Program Files\blank.gif
                2006-03-31 22:06 12,334 -c--a-w C:\Program Files\stubinstaller.ini
                2006-03-18 08:41 1,455,106 -c--a-w C:\Program Files\fdminst.exe
                2006-03-18 08:25 2,628,754 -c--a-w C:\Program Files\SetupTrueDownloader.exe
                2006-03-14 11:30 57,796 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_47_08_small.dmp.zip
                2006-03-14 11:30 56,399 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_46_56_small.dmp.zip
                2006-03-14 11:30 54,334 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_18_40_small.dmp.zip
                2006-03-14 11:30 49,110 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_46_37_small.dmp.zip
                2006-03-14 07:18 65,292 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_17_14_small.dmp.zip
                2006-03-14 07:17 64,644 -c--a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2006_03_14_08_09_39_small.dmp.zip
                2006-02-23 19:35 2,016,856 -c--a-w C:\Program Files\rd2005trial.exe
                2006-02-16 23:00 1,485,368 -c--a-w C:\Program Files\GoogleDesktopSetup.exe
                2006-02-11 22:16 285,580 -c--a-w C:\Program Files\Autoruns.zip
                2006-02-10 22:54 8,634 -c--a-w C:\Program Files\startuplist.txt
                2006-02-10 22:52 58,368 -c--a-w C:\Program Files\StartupList.exe
                2006-02-10 22:41 1,526,976 -c--a-w C:\Program Files\soref_regclean.exe
                2006-02-08 19:35 2,855,080 -c--a-w C:\Program Files\aawsepersonal.exe
                2006-02-08 19:26 5,037,072 -c--a-w C:\Program Files\spybotsd14.exe
                2006-02-06 22:54 849,833 -c--a-w C:\Program Files\Startup_manager_2.0.zip
                2006-02-02 19:09 27,977,025 -c--a-w C:\Program Files\vista-inspirat-pack_vista_inspirat_pack_1.1_francais_15013.exe
                2005-09-16 21:40 985,739 -c--a-w C:\Program Files\ThumbClic.zip
                2005-05-06 10:01 234,240 -c--a-w C:\Program Files\FrReform.exe
                2005-04-18 12:31 2,609,152 -c--a-w C:\Program Files\Ink.msi
                2002-03-11 09:06 1,822,520 -c--a-w C:\Program Files\instmsiw.exe
                2002-03-11 08:45 1,708,856 -c--a-w C:\Program Files\instmsia.exe
                .

                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                REGEDIT4
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-03-30 11:31 68856]
                "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 11:43 2097488]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "ATIPTA"="C:\ATI-CPanel\atiptaxx.exe" [2004-05-25 20:10 339968]
                "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 10:25 6731312]
                "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
                "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
                "UserFaultCheck"="C:\WINDOWS\system32\dumprep 0 -u" [ ]

                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                "Windows Time"="winmgr.exe" []

                C:\Documents and Settings\Serge\Menu D‚marrer\Programmes\D‚marrage\
                Stardock ObjectDock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe [2005-02-21 14:56:00 1826885]
                y'z toolbar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\YzToolbar\YzToolBar.exe [2002-09-29 14:41:00 90112]

                C:\Documents and Settings\H‚lŠne\Menu D‚marrer\Programmes\D‚marrage\
                stardock objectdock.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe [2005-02-21 14:56:00 1826885]

                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
                "AllowLegacyWebView"= 1 (0x1)
                "AllowUnhashedWebView"= 1 (0x1)

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
                "AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                "EnableFirewall"= 0 (0x0)

                R1 fwdrv;Firewall Driver;C:\WINDOWS\system32\drivers\fwdrv.sys [2007-03-16 08:56]
                R1 khips;Kerio HIPS Driver;C:\WINDOWS\system32\drivers\khips.sys [2007-03-16 08:56]
                R2 CX23880;MSI 8606 Video Capture;C:\WINDOWS\system32\drivers\CX88Vid.SYS [2003-08-28 15:14]
                R2 CX88XBAR;MSI 8606 Crossbar;C:\WINDOWS\system32\drivers\CX88XBar.SYS [2003-03-19 13:50]
                R2 CXTUNE;MSI 8606 Tuner;C:\WINDOWS\system32\drivers\CX88Tune.SYS [2003-08-21 15:35]
                S3 camvid20;Philips ToUcam Camera; Video;C:\WINDOWS\system32\DRIVERS\camdrv21.sys []
                S3 MPCSYS;MPCSYS;C:\WINDOWS\System32\DRIVERS\mpcsys.sys [2007-01-31 09:03]
                S3 PVUSB;CESG502 USB Driver;C:\WINDOWS\system32\DRIVERS\CESG502.sys [2007-12-12 19:16]
                S3 zebrbus;Sony Ericsson Composite Device driver;C:\WINDOWS\system32\DRIVERS\zebrbus.sys [2006-07-25 17:36]

                .
                Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                "2008-01-16 22:08:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
                - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
                "2008-01-28 08:00:00 C:\WINDOWS\Tasks\At73.job"
                - C:\WINDOWS\user32.exe
                "2008-06-16 09:12:08 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1159858088.job"
                - C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe4-I
                .
                **************************************************************************

                catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-02-26 13:19:08
                Windows 5.1.2600 Service Pack 2 NTFS

                Balayage processus cachés ...

                Balayage caché autostart entries ...

                Balayage des fichiers cachés ...

                Scan terminé avec succès
                Les fichiers cachés: 0

                **************************************************************************
                .
                --------------------- DLLs a chargé sous des processus courants ---------------------

                PROCESS: C:\WINDOWS\explorer.exe [6.00.2900.3156]
                -> C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\DockShellHook.dll
                .
                Temps d'accomplissement: 2008-02-26 13:22:38
                .
                2008-02-23 10:19:14 --- E O F ---
                0
              2. au fait, pourquoi est ce qu'on ne coche pas tout simplement la ligne 4 du ver pour la supprimer?
                question certainement très stupide...mais je la pose quand même:-)
                à ce soir
                helene
                0
            2. Merci ep44
              je me lance et vous fais signe quand j'ai fini
              à plus tard
              helene
              0
              1. dites ep44, pendant que vindofix scanne, je vois qu'après je dois télécharger un logiciel et le sauvegarder sur le bureau et "pas ailleurs"
                comment devrais je m'y prendre
                merci
                0
                1. Contributeur
                  et bien tu le télécharge sur ton bureau et pas ailleurs
                  donc que sur ton bureau ;-)))

                  et le tutoiement est de vigueur ;-)))
                  @++
                  0
                  1. me revoici ep44 avec le rapport vundofix, sauf erreur, je n'ai pas trouvé celui de combofix
                    mon pc rame de plus en plus
                    et maintenant, que dois-je faire?
                    merci pour tout
                    à plus tard
                    helene

                    VundoFix V6.7.7

                    Checking Java version...

                    Java version is 1.4.2.3
                    Old versions of java are exploitable and should be removed.

                    Java version is 1.5.0.2
                    Old versions of java are exploitable and should be removed.

                    Java version is 1.5.0.4
                    Old versions of java are exploitable and should be removed.

                    Java version is 1.5.0.6
                    Old versions of java are exploitable and should be removed.

                    Java version is 1.5.0.9
                    Old versions of java are exploitable and should be removed.

                    Scan started at 21:35:29 01/24/2008

                    Listing files found while scanning....

                    C:\WINDOWS\system32\cbxxyaa.dll
                    C:\WINDOWS\system32\mljgd.dll
                    C:\WINDOWS\system32\winpsa32.dll

                    Beginning removal...

                    Attempting to delete C:\WINDOWS\system32\cbxxyaa.dll
                    C:\WINDOWS\system32\cbxxyaa.dll Could not be deleted.

                    Attempting to delete C:\WINDOWS\system32\mljgd.dll
                    C:\WINDOWS\system32\mljgd.dll Has been deleted!

                    Attempting to delete C:\WINDOWS\system32\winpsa32.dll
                    C:\WINDOWS\system32\winpsa32.dll Has been deleted!

                    Performing Repairs to the registry.
                    Done!

                    Beginning removal...
                    0
                    1. Contributeur
                      pour celui de combofix regarde dans c:
                      tu dois avoir un dossier texte
                      0
                      1. Voici les fichiers .txt trouvés dans C:combofix
                        J'ai toujours des courriers qui arrivent mais en nombre semble t-il plus restreint.
                        Que disent les rapports?
                        Encore merci ep44 et à plus tard peut être demain

                        ComboFix 08-01-23.1B - H‚lŠne 2008-01-24 22:18:20.1 - NTFSx86
                        Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.204 [GMT 1:00]
                        Endroit: C:\Documents and Settings\H‚lŠne\Bureau\ComboFix.exe
                        * Création d'un nouveau point de restauration

                        [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                        s/\x3b //g
                        s/C:\\WINDOWS\\system32\\rundll32\.exe //I
                        s/C:\\WINDOWS\\system32\\rundll32 //I
                        s/rundll32\.exe //I
                        s/rundll32 //I
                        s/\x22//g
                        s/^ +//
                        s/,.*//
                        s/<NO NAME>/@/
                        s/\t.*\t/\t/
                        s/\.exe .*/.exe/I
                        s/\.dll .*/.dll/I
                        s/\x25programfiles\x25/C:\\Program Files/I
                        s/\x25systemroot\x25/C:\\WINDOWS/I
                        .

                        \??\C:\ntdetect.com\0\0
                        \??\C:\boot.ini\0\0
                        \??\C:\ntldr\0\0
                        \??\C:\WINDOWS\0\0
                        \??\C:\WINDOWS\explorer.exe\0\0
                        \??\C:\WINDOWS\system32\csrss.exe\0\0
                        \??\C:\WINDOWS\system32\lsass.exe\0\0
                        \??\C:\WINDOWS\system32\services.exe\0\0
                        \??\C:\WINDOWS\system32\smss.exe\0\0
                        \??\C:\WINDOWS\system32\svchost.exe\0\0
                        \??\C:\WINDOWS\system32\userinit.exe\0\0
                        \??\C:\WINDOWS\system32\winlogon.exe\0\0
                        \??\C:\WINDOWS\system32\hal.dll\0\0
                        \??\C:\WINDOWS\system32\ntdll.dll\0\0
                        \??\C:\WINDOWS\system32\config\0\0
                        \??\C:\WINDOWS\system32\drivers\0\0
                        \??\C:\WINDOWS\system32\wbem\0\0
                        0
                        1. Contributeur
                          ceci n'est pas le rapport de combofix

                          relance combofix et laise le traviller
                          il doit passer environ 40 étapes une fois fini il te met un rapport directement sur le bureau
                          si tu ne le vois pas il se trouve dans c:
                          regarde à quoi ressemble un rapport de combofix
                          http://www.commentcamarche.net/forum/affich 4252452 ordinateur aun ralentie?page=2#27
                          @+
                          et à demain sans soucis ;-))
                          0
                          1. je sens la sommeil me gagner
                            à demain donc
                            bonne nuit et merci
                            helene
                            0
                            1. Contributeur
                              ok fait ce que je viens de t'indiquer et à demain en fin de soirée pour moi
                              @+
                              0
                              1. Bonjour ep44

                                j'ai refait comme tu me l'as dit un combofix, je l'ai laissé "travailler" tranquillement, mais je n'ai toujours pas de rapport ni sur le bureau ni dans C, je dois mal m'y prendre.........
                                j'ai refait un scan vundofix, voici le rapport, il n'a plus rien trouvé mais j'ai toujours les courriers d'inconnus qui défilent et qui ralentissent le pc
                                j'attends les nouvelles instructions
                                à ce soir
                                merci
                                helene

                                Scan started at 11:13:42 2008-01-25

                                Listing files found while scanning....

                                No infected files were found.

                                Beginning removal...
                                0
                                1. Contributeur
                                  Bonsoir Hélène,

                                  il serait vraiment bien d'avoir ce rapport il nous donnerait vraiment un bon coup de main
                                  normaleent tu devrais avoir dans c: un dossier texte nommé combofix.txt
                                  est-ce que tu la vraiment téléchargé sur ton bureau ?

                                  Il nous reste ceci à trouver C:\WINDOWS\system32\cbxxyaa.dll
                                  donc regarde bien si tu as ce rapport
                                  si tu ne trouve pas dit le moi on essaiera autre chose
                                  @+ ;-)
                                  0
                                  1. Bonjour ep44Merci d'être toujours là:-)
                                    voici le rapport hijack que tu m'as demandé
                                    Bonne journée
                                    A ce soir je pense
                                    Bise
                                    helene

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 10:43, on 2008-02-25
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
                                    C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\a-squared Free\a2service.exe
                                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\System32\MsPMSPSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\ATI-CPanel\atiptaxx.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                    C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
                                    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ustart.org
                                    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = "C:\Program Files\Outlook Express\msimn.exe"
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                    O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
                                    O4 - HKLM\..\Run: [ATIPTA] C:\ATI-CPanel\atiptaxx.exe
                                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                    O4 - HKUS\S-1-5-18\..\Run: [Windows Time] winmgr.exe (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [Windows Time] winmgr.exe (User 'Default user')
                                    O4 - Startup: stardock objectdock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat\ObjectDock\ObjectDock.exe
                                    O8 - Extra context menu item: &Download with TrueDownloader! - C:\Program Files\TrueDownloader\TrueDownloader.htm
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                                    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
                                    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
                                    O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
                                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
                                    O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
                                    0
                                2. Bonjour ep44
                                  Désolée d'avoir tant tardée à répondre, j'étais absente tout le week end et je retrouve mon pc infectée!!!!!!evidemment...........
                                  Je n'ai définitivement pas trouvé ce fichu rapport! Mais en faisant une recherche avec le nom du "virus", voilà ce que j'ai trouvé:
                                  cbxxyaa.dll.bad dans le dossier C:vundofix backups
                                  cbxxyaa.dll.vir dans le dossier C:qoobox/quarantaine/C;/Windows/system32
                                  Voilà, j'attends toujours des conseils, je suis désolée de ne pas trouver ce rapport
                                  D'avance merci
                                  A bientôt
                                  Helene
                                  0
                                  1. Contributeur
                                    Bonsoir

                                    supprime tout les logiciels que nous avons utilisé
                                    ensuite tu retélécharge combofix et tu attends qu'il ai fini
                                    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                                    tu doit avoir un rapport qui s'affiche de lui même
                                    si ce n'est pas le cas regarde dans c: tu doit avoir un dossier texte combofix
                                    @+
                                    0
                                    • 1
                                    • 2
                                    • 3
                                    • 4
                                    • 5
                                    • 6