Besoin d'aide pour éliminer Trojan Metajuan

coc23 -  
 melanie -
Bonjour,
Symantec m'indique que mon pc est infecté par le trojan Metajuan. J'ai régulièrement des pages de pub qui s'ouvrent lorsque je navigue sur le net et Symantec me signale régulièrement d'autres menaces qui doivent être ramenées par le trojan.
J'ai effectué un scan en ligne Panda et un scan HiJack This. Les rapports sont là:

Scan Panda:

Incident Status Location

Adware:adware/comet Not disinfected Windows Registry
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\R&D\Application Data\Mozilla\Firefox\Profiles\sbkh5plt.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\R&D\Application Data\Mozilla\Firefox\Profiles\sbkh5plt.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@ad.yieldmanager[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@ad.yieldmanager[3].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@adrevolver[3].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@adtech[1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@adtech[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@advertising[1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@advertising[2].txt
Spyware:Cookie/Adviva Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@adviva[3].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@apmebf[2].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@apmebf[3].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@atdmt[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@atdmt[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@atdmt[3].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@atwola[1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@bluestreak[3].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@bs.serving-sys[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@bs.serving-sys[3].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@burstnet[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@casalemedia[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@cgi-bin[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@cgi-bin[6].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@doubleclick[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@doubleclick[2].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@ehg-dig.hitbox[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@fastclick[1].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@fe.lea.lycos[1].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@fe.lea.lycos[2].txt
Spyware:Cookie/Comclick Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@fl01.ct2.comclick[2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@go[1].txt
Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@linksynergy[1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@media.fastclick[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@mediaplex[2].txt
Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@metriweb[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@overture[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@perf.overture[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@questionmarket[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@questionmarket[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@realmedia[2].txt
Spyware:Cookie/Research-int Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@research-int[1].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@revenue[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@searchportal.information[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@server.iad.liveperson[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@server.iad.liveperson[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@serving-sys[1].txt
Spyware:Cookie/Smartadserver Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@smartadserver[1].txt
Spyware:Cookie/Smartadserver Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@smartadserver[3].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@statcounter[2].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@statse.webtrendslive[2].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@toplist[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@trafficmp[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@tribalfusion[3].txt
Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@weborama[1].txt
Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@weborama[2].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@www.myaffiliateprogram[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@xiti[1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@xiti[2].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@yadro[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@zedo[1].txt
Virus:Generic Malware Disinfected C:\Program Files\eMule\Incoming\[PC GAME] Pro Cycling Manager Saison 2007 No CD Crack + Keygen by nikita32\PC Game - Crack.exe
Possible Virus. Not disinfected C:\WINDOWS\Temp\bnmcfs23.exe

Scan HiJackThis:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:58:14, on 05/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\SAV\DefWatch.exe
C:\WINDOWS\system32\CBA\pds.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\flexlm\lmgrd.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SAV\Rtvscan.exe
C:\flexlm\SW_D.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SAV\VPTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SAV\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [708c159f] rundll32.exe "C:\WINDOWS\system32\lmeixuig.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Policies\Explorer\Run: [WinUpdating] WinUpdating.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\SAV\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe
O23 - Service: Service de repérage Symantec System Center (NSCTOP) - Symantec Corporation - C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SolidWorks SolidNetWork License Manager - Macrovision Corporation - C:\flexlm\lmgrd.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\SAV\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
A voir également:

101 réponses

Utilisateur anonyme
 
bonjour ,

Apprenez a lire les gars !

Spyware:Spyware/Virtumonde No Désinfecté C:\WINDOWS\system32\vtusron.dll
Trojan vundo

Ben arête de mettre Navilog à toute les sauces ! c'est pas du magic control ici !!

Et c'est pas non plus une histoire de cookies !

Pour coc23

Télécharge VundoFix ici -> http://www.atribune.org/ccount/click.php?id=4

lance Vundofix.exe
Coche la case Run VundoFix as a task,
Un pop-up va s'ouvrir , repond ok
Il va se refermer et réouvrir au bout d'une 1 minute environ.
Quand il est réouvert, clique sur Scan for Vundo
Quand le scan est terminé, clique sur Remove Vundo
Réponds Yes à la demande de suppression des fichiers.
Il te sera demandé de redémarrer ton ordinateur, accepte bien sûr.
Colle le rapport situé dans "c:\vundofix.txt" dans ta réponse

Télécharge VirtumondoBegone :

http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

Redémarre en MSE et lance le,
Et poste moi le rapport.
a+

1
Pilcrw Messages postés 608 Statut Membre 51
 
Salut,

Tu as trop de cookies, enleve deja tes cookies et tes fichier temporaires et refait un scan stp on y verra mieux ;)
0
coc23
 
J'ai fait un nettoyage des dossiers Cookies et Temporaire (effectivement nécessaire...) et relancer le scan Panda et le scan Hijack This.

Voici les rapports:

Incident Status Location

Adware:adware/comet Not disinfected Windows Registry
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\R&D\Application Data\Mozilla\Firefox\Profiles\sbkh5plt.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\R&D\Application Data\Mozilla\Firefox\Profiles\sbkh5plt.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@ad.yieldmanager[1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@advertising[2].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\R&D\Cookies\r&d@bluestreak[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1005.txt
Spyware:Cookie/Weborama Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1063.txt
Spyware:Cookie/Weborama Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1064.txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1215.txt
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1308.txt
Spyware:Cookie/Xiti Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1309.txt
Spyware:Cookie/Yadro Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1313.txt
Spyware:Cookie/Zedo Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1323.txt
Spyware:Cookie/Zedo Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1324.txt
Spyware:Cookie/Advertising Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1335.txt
Spyware:Cookie/Bluestreak Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1336.txt
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc1339.txt
Possible Virus. Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc141.exe
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc210.txt
Spyware:Cookie/YieldManager Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc211.txt
Spyware:Cookie/Adrevolver Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc225.txt
Spyware:Cookie/Adtech Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc242.txt
Spyware:Cookie/Adtech Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc243.txt
Spyware:Cookie/Advertising Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc248.txt
Spyware:Cookie/Advertising Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc249.txt
Spyware:Cookie/Adviva Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc251.txt
Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc274.txt
Spyware:Cookie/Apmebf Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc275.txt
Spyware:Cookie/Atlas DMT Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc287.txt
Spyware:Cookie/Atlas DMT Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc288.txt
Spyware:Cookie/Atlas DMT Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc289.txt
Spyware:Cookie/Atwola Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc293.txt
Spyware:Cookie/Bluestreak Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc328.txt
Spyware:Cookie/Serving-sys Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc335.txt
Spyware:Cookie/Serving-sys Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc336.txt
Spyware:Cookie/BurstNet Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc340.txt
Spyware:Cookie/Casalemedia Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc352.txt
Spyware:Cookie/Cgi-bin Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc357.txt
Spyware:Cookie/Cgi-bin Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc362.txt
Spyware:Cookie/Doubleclick Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc435.txt
Spyware:Cookie/Doubleclick Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc436.txt
Spyware:Cookie/Hitbox Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc454.txt
Spyware:Cookie/FastClick Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc491.txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc492.txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc493.txt
Spyware:Cookie/Comclick Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc503.txt
Spyware:Cookie/Go Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc556.txt
Spyware:Cookie/Linksynergy Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc641.txt
Spyware:Cookie/FastClick Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc675.txt
Spyware:Cookie/Mediaplex Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc680.txt
Spyware:Cookie/MetriWeb Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc692.txt
Spyware:Cookie/Overture Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc757.txt
Spyware:Cookie/Overture Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc758.txt
Spyware:Cookie/Overture Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc776.txt
Spyware:Cookie/QuestionMarket Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc808.txt
Spyware:Cookie/QuestionMarket Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc809.txt
Spyware:Cookie/RealMedia Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc826.txt
Spyware:Cookie/Research-int Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc834.txt
Spyware:Cookie/WUpd Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc838.txt
Spyware:Cookie/Searchportal Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc880.txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc888.txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc889.txt
Spyware:Cookie/Serving-sys Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc894.txt
Spyware:Cookie/Smartadserver Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc908.txt
Spyware:Cookie/Smartadserver Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc909.txt
Spyware:Cookie/Statcounter Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc933.txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc939.txt
Spyware:Cookie/Toplist Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc981.txt
Spyware:Cookie/Tradedoubler Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc992.txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\RECYCLER\S-1-5-21-1645522239-1417001333-839522115-1003\Dc993.txt

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:54:00, on 05/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\SAV\DefWatch.exe
C:\WINDOWS\system32\CBA\pds.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\flexlm\lmgrd.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SAV\Rtvscan.exe
C:\flexlm\SW_D.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SAV\VPTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Solidworks 2007\sldworks.exe
C:\DOCUME~1\R&D\LOCALS~1\Temp\SolidWorksLicTemp.0001
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Adobe\Acrobat 6.0\Acrobat\Acrobat.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SAV\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [708c159f] rundll32.exe "C:\WINDOWS\system32\lmeixuig.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Policies\Explorer\Run: [WinUpdating] WinUpdating.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\SAV\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe
O23 - Service: Service de repérage Symantec System Center (NSCTOP) - Symantec Corporation - C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SolidWorks SolidNetWork License Manager - Macrovision Corporation - C:\flexlm\lmgrd.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\SAV\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
0
coc23
 
Les pages de pub intempestives affluent de plus en plus et comme l'ordinateur infecté est mon pc professionnel, mon rendement est vraiment en baisse...

Est-ce que quelqu'un pourrait m'aider rapidement à décrypter les rapports de scan s'il vous plaît?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
coc23
 
S'il vous plaît, quelqu'un pourrait-il m'aider? merci.
0
Pilcrw Messages postés 608 Statut Membre 51
 
Avant de te lancé sur ton rapport, supprime tout tes cookie et fichier temporaire !!!!!
0
coc23
 
Désolée j'avais oublié de supprimer les cookies de la Corbeille. J'espère que c'est plus clair maintenant:

Incident Statut Analyse

Spyware:Spyware/Virtumonde No Désinfecté C:\WINDOWS\system32\vtusron.dll
Adware:adware/comet No Désinfecté Registre Windows
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\R&D\Application Data\Mozilla\Firefox\Profiles\sbkh5plt.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Toplist No Désinfecté C:\Documents and Settings\R&D\Application Data\Mozilla\Firefox\Profiles\sbkh5plt.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/YieldManager No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@ad.yieldmanager[1].txt
Spyware:Cookie/AdvancedCleaner No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@advancedcleaner[1].txt
Spyware:Cookie/Advertising No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@advertising[2].txt
Spyware:Cookie/Apmebf No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@apmebf[1].txt
Spyware:Cookie/Bluestreak No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@bluestreak[1].txt
Spyware:Cookie/Casalemedia No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@casalemedia[2].txt
Spyware:Cookie/FastClick No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@fastclick[2].txt
Spyware:Cookie/Tradedoubler No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@tradedoubler[1].txt
Spyware:Cookie/Zedo No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@zedo[2].txt
Spyware:Spyware/Virtumonde

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:56:41, on 07/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\SAV\DefWatch.exe
C:\WINDOWS\system32\CBA\pds.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\flexlm\lmgrd.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SAV\Rtvscan.exe
C:\flexlm\SW_D.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SAV\VPTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\PROGRA~1\SOLIDW~2\sldworks.exe
C:\DOCUME~1\R&D\LOCALS~1\Temp\SolidWorksLicTemp.0001
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SAV\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [708c159f] rundll32.exe "C:\WINDOWS\system32\qmmcrvrd.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Policies\Explorer\Run: [WinUpdating] WinUpdating.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\SAV\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe
O23 - Service: Service de repérage Symantec System Center (NSCTOP) - Symantec Corporation - C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SolidWorks SolidNetWork License Manager - Macrovision Corporation - C:\flexlm\lmgrd.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\SAV\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
0
Pilcrw Messages postés 608 Statut Membre 51
 
Apparement il te reste des cookies :s regarde ...

"Spyware:Spyware/Virtumonde No Désinfecté C:\WINDOWS\system32\vtusron.dll
Adware:adware/comet No Désinfecté Registre Windows
Spyware:Cookie/Xiti No Désinfecté C:\Documents and Settings\R&D\Application Data\Mozilla\Firefox\Profiles\sbkh5plt.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Toplist No Désinfecté C:\Documents and Settings\R&D\Application Data\Mozilla\Firefox\Profiles\sbkh5plt.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/YieldManager No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@ad.yieldmanager[1].txt
Spyware:Cookie/AdvancedCleaner No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@advancedcleaner[1].txt
Spyware:Cookie/Advertising No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@advertising[2].txt
Spyware:Cookie/Apmebf No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@apmebf[1].txt
Spyware:Cookie/Bluestreak No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@bluestreak[1].txt
Spyware:Cookie/Casalemedia No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@casalemedia[2].txt
Spyware:Cookie/FastClick No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@fastclick[2].txt
Spyware:Cookie/Tradedoubler No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@tradedoubler[1].txt
Spyware:Cookie/Zedo No Désinfecté C:\Documents and Settings\R&D\Cookies\r&d@zedo[2].txt
Spyware:Spyware/Virtumonde "

ca doit etre ca qui beug, si tu n'arrive pas a les supprimé va dans :
poste de travail -> C: -> Documents and Settings ->"Ton nom d'utilisateur" -> Cookies
Et supprime tout...
0
coc23
 
En fait ce sont des cookies qui réapparaissent pendant le scan Panda. Je vide complètement le dossier cookies avant le scan mais comme le scan est long, y a des cookies qui arrivent avant que le scan arrive au dossier Cookies. Et vu que des fenêtres de pub s'ouvrent régulièrement, les cookies affluent. Depuis ce matin j'ai moins de fenêtres de pub alors je réessaye un scan en espérant éviter les cookies cette fois.
0
Pilcrw Messages postés 608 Statut Membre 51
 
Dans ta base de registre et dans ton disque dur, recherche toute information relative a "r&d","virtumonde","Zedo","Xiti","sbkh5plt.default","vtusron.dll "... si ca ne veut pas supprimer essaye en mode sans echec !
0
coc23
 
J'ai réussi à tout supprimer sauf vtusron.dll. Même en mode sans échec un message me dit qu'il est utilisé par une autre application...
0
Pilcrw Messages postés 608 Statut Membre 51
 
ok et sinon ? tu as encore des popup ??
0
ben15 Messages postés 464 Statut Membre 12
 
Bonjour a tout les deux si les pub persistent fais ceci:

va a cette adressse et télécharge : http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

choisis Enregistrer et enregistre-le sur ton bureau.

(2) Ensuite double clique sur navilog1.exe pour lancer l'installation.
Une fois l'installation terminée, le fix s'exécutera automatiquement.
(Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

Laisse-toi guider. Au menu principal, choisis 1 et valides.
(ne fais pas le choix 2,3 ou 4 sans notre avis/accord)
Patiente jusqu'au message " Analyse Termine le ....."

Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
Copie/colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

Nb: si ton antivirus trouve un trojan ignore le.
0
coc23
 
J'ai fait tourner Navilog:

Search Navipromo version 3.4.4 commencé le 11/02/2008 à 12:25:50,74

!!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
!!! Postez ce rapport sur le forum pour le faire analyser !!!
!!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

Outil exécuté depuis C:\Program Files\navilog1
Mise à jour le 10.02.2008 à 12h00 par IL-MAFIOSO

Microsoft Windows XP [version 5.1.2600]
Système de fichiers : NTFS

Executé en mode normal

*** Recherche Programmes installés ***

*** Recherche dossiers dans C:\WINDOWS ***

*** Recherche dossiers dans C:\Program Files ***

*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

*** Recherche dossiers dans "C:\Documents and Settings\R&D\applic~1" ***

*** Recherche dossiers dans "C:\Documents and Settings\R&D\locals~1\applic~1" ***

*** Recherche dossiers dans "C:\Documents and Settings\R&D\\" ***

*** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

*** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
pour + d'infos : http://www.gmer.net

Aucun Fichier trouvé

*** Recherche avec GenericNaviSearch ***
!!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
!!! A vérifier impérativement avant toute suppression manuelle !!!

* Recherche dans C:\WINDOWS\system32 *

* Recherche dans "C:\Documents and Settings\R&D\locals~1\applic~1" *

*** Recherche fichiers ***

*** Recherche clés spécifiques dans le Registre ***
0
coc23
 
Bonjour cyrildu17,

Voici le rapport Vundofix:

VundoFix V6.7.8

Checking Java version...

Scan started at 14:19:47 11/02/2008

Listing files found while scanning....

C:\WINDOWS\system32\awtspoo.dll
C:\WINDOWS\system32\byxyayw.dll
C:\WINDOWS\system32\cbxywut.dll
C:\WINDOWS\system32\cbxyyya.dll
C:\WINDOWS\system32\ddcbbya.dll
C:\WINDOWS\system32\efcccya.dll
C:\WINDOWS\system32\fccaaay.dll
C:\WINDOWS\system32\fccabcy.dll
C:\WINDOWS\system32\fccawwt.dll
C:\WINDOWS\system32\fccbbyw.dll
C:\WINDOWS\system32\gvcqqhlh.ini
C:\WINDOWS\system32\hlhqqcvg.dll
C:\WINDOWS\system32\hplbcbvb.dll
C:\WINDOWS\system32\nnnnopp.dll
C:\WINDOWS\system32\nxgmmfnv.dll
C:\WINDOWS\system32\oiicalbs.dll
C:\WINDOWS\system32\qomkjjh.dll
C:\WINDOWS\system32\rqrqnlm.dll
C:\WINDOWS\system32\tuvvutq.dll
C:\WINDOWS\system32\urqnkih.dll
C:\WINDOWS\system32\urqnoli.dll
C:\WINDOWS\system32\vtsqr.dll
C:\WINDOWS\system32\vtusppm.dll
C:\WINDOWS\system32\vtusron.dll
C:\WINDOWS\system32\vtutuvv.dll
C:\WINDOWS\system32\xxywtrs.dll
C:\WINDOWS\system32\xxywttq.dll
C:\WINDOWS\system32\yayxxxw.dll
C:\WINDOWS\Temp\123lfd.exe

Beginning removal...

Attempting to delete C:\WINDOWS\system32\awtspoo.dll
C:\WINDOWS\system32\awtspoo.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\byxyayw.dll
C:\WINDOWS\system32\byxyayw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cbxywut.dll
C:\WINDOWS\system32\cbxywut.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\cbxyyya.dll
C:\WINDOWS\system32\cbxyyya.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddcbbya.dll
C:\WINDOWS\system32\ddcbbya.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\efcccya.dll
C:\WINDOWS\system32\efcccya.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fccaaay.dll
C:\WINDOWS\system32\fccaaay.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fccabcy.dll
C:\WINDOWS\system32\fccabcy.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fccawwt.dll
C:\WINDOWS\system32\fccawwt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\fccbbyw.dll
C:\WINDOWS\system32\fccbbyw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\gvcqqhlh.ini
C:\WINDOWS\system32\gvcqqhlh.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\hlhqqcvg.dll
C:\WINDOWS\system32\hlhqqcvg.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\hplbcbvb.dll
C:\WINDOWS\system32\hplbcbvb.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nnnnopp.dll
C:\WINDOWS\system32\nnnnopp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nxgmmfnv.dll
C:\WINDOWS\system32\nxgmmfnv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\oiicalbs.dll
C:\WINDOWS\system32\oiicalbs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\qomkjjh.dll
C:\WINDOWS\system32\qomkjjh.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rqrqnlm.dll
C:\WINDOWS\system32\rqrqnlm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\tuvvutq.dll
C:\WINDOWS\system32\tuvvutq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\urqnkih.dll
C:\WINDOWS\system32\urqnkih.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\urqnoli.dll
C:\WINDOWS\system32\urqnoli.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtsqr.dll
C:\WINDOWS\system32\vtsqr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtusppm.dll
C:\WINDOWS\system32\vtusppm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtusron.dll
C:\WINDOWS\system32\vtusron.dll Could not be deleted.

Attempting to delete C:\WINDOWS\system32\vtutuvv.dll
C:\WINDOWS\system32\vtutuvv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxywtrs.dll
C:\WINDOWS\system32\xxywtrs.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xxywttq.dll
C:\WINDOWS\system32\xxywttq.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\yayxxxw.dll
C:\WINDOWS\system32\yayxxxw.dll Has been deleted!

Attempting to delete C:\WINDOWS\Temp\123lfd.exe
C:\WINDOWS\Temp\123lfd.exe Has been deleted!

Performing Repairs to the registry.
Done!

et voici le rapport Virtumondobegone:

[02/11/2008, 15:05:31] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\R&D\Bureau\VirtumundoBeGone.exe" )
[02/11/2008, 15:05:37] - Detected System Information:
[02/11/2008, 15:05:37] - Windows Version: 5.1.2600, Service Pack 2
[02/11/2008, 15:05:37] - Current Username: R&D (Admin)
[02/11/2008, 15:05:37] - Windows is in SAFE mode with Networking.
[02/11/2008, 15:05:37] - Searching for Browser Helper Objects:
[02/11/2008, 15:05:37] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/11/2008, 15:05:37] - BHO 2: {06E4F2A6-253A-47F3-9608-4D95D0F45CCB} ()
[02/11/2008, 15:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:37] - Checking for HKLM\...\Winlogon\Notify\pmkhf
[02/11/2008, 15:05:37] - Key not found: HKLM\...\Winlogon\Notify\pmkhf, continuing.
[02/11/2008, 15:05:37] - BHO 3: {09870598-3F69-438A-8103-2B9C0DFC5DA0} ()
[02/11/2008, 15:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:37] - Checking for HKLM\...\Winlogon\Notify\pmkjk
[02/11/2008, 15:05:37] - Key not found: HKLM\...\Winlogon\Notify\pmkjk, continuing.
[02/11/2008, 15:05:37] - BHO 4: {23D44BCF-AA7A-41D6-8905-E808F16322EF} ()
[02/11/2008, 15:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:37] - Checking for HKLM\...\Winlogon\Notify\yaywtsq
[02/11/2008, 15:05:37] - Found: HKLM\...\Winlogon\Notify\yaywtsq - This is probably Virtumundo.
[02/11/2008, 15:05:37] - Assigning {23D44BCF-AA7A-41D6-8905-E808F16322EF} MSEvents Object
[02/11/2008, 15:05:37] - BHO list has been changed! Starting over...
[02/11/2008, 15:05:37] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/11/2008, 15:05:37] - BHO 2: {06E4F2A6-253A-47F3-9608-4D95D0F45CCB} ()
[02/11/2008, 15:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:37] - Checking for HKLM\...\Winlogon\Notify\pmkhf
[02/11/2008, 15:05:37] - Key not found: HKLM\...\Winlogon\Notify\pmkhf, continuing.
[02/11/2008, 15:05:37] - BHO 3: {09870598-3F69-438A-8103-2B9C0DFC5DA0} ()
[02/11/2008, 15:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:37] - Checking for HKLM\...\Winlogon\Notify\pmkjk
[02/11/2008, 15:05:37] - Key not found: HKLM\...\Winlogon\Notify\pmkjk, continuing.
[02/11/2008, 15:05:37] - BHO 4: {23D44BCF-AA7A-41D6-8905-E808F16322EF} (MSEvents Object)
[02/11/2008, 15:05:37] - ALERT: Found MSEvents Object!
[02/11/2008, 15:05:37] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/11/2008, 15:05:37] - BHO 6: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/11/2008, 15:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:37] - No filename found. Continuing.
[02/11/2008, 15:05:37] - BHO 7: {A1A23B1C-41B1-4978-A039-8C39E3A4B0E6} ()
[02/11/2008, 15:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:37] - Checking for HKLM\...\Winlogon\Notify\vtusron
[02/11/2008, 15:05:37] - Key not found: HKLM\...\Winlogon\Notify\vtusron, continuing.
[02/11/2008, 15:05:37] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[02/11/2008, 15:05:37] - BHO 9: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[02/11/2008, 15:05:37] - BHO 10: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[02/11/2008, 15:05:37] - BHO 11: {DFAB7F2D-2106-47DB-A5D7-C6B45B9793DB} ()
[02/11/2008, 15:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:37] - Checking for HKLM\...\Winlogon\Notify\vtsqr
[02/11/2008, 15:05:37] - Key not found: HKLM\...\Winlogon\Notify\vtsqr, continuing.
[02/11/2008, 15:05:37] - BHO 12: {f0f8a5d2-84ef-456c-a2c5-b0126414b822} ()
[02/11/2008, 15:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:37] - Checking for HKLM\...\Winlogon\Notify\cadowtxq
[02/11/2008, 15:05:37] - Key not found: HKLM\...\Winlogon\Notify\cadowtxq, continuing.
[02/11/2008, 15:05:37] - Finished Searching Browser Helper Objects
[02/11/2008, 15:05:37] - *** Detected MSEvents Object
[02/11/2008, 15:05:37] - Trying to remove MSEvents Object...
[02/11/2008, 15:05:38] - Terminating Process: IEXPLORE.EXE
[02/11/2008, 15:05:38] - Terminating Process: RUNDLL32.EXE
[02/11/2008, 15:05:38] - Disabling Automatic Shell Restart
[02/11/2008, 15:05:38] - Terminating Process: EXPLORER.EXE
[02/11/2008, 15:05:38] - Suspending the NT Session Manager System Service
[02/11/2008, 15:05:39] - Terminating Windows NT Logon/Logoff Manager
[02/11/2008, 15:05:39] - Re-enabling Automatic Shell Restart
[02/11/2008, 15:05:39] - File to disable: C:\WINDOWS\system32\yaywtsq.dll
[02/11/2008, 15:05:39] - Renaming C:\WINDOWS\system32\yaywtsq.dll -> C:\WINDOWS\system32\yaywtsq.dll.vir
[02/11/2008, 15:05:39] - File successfully renamed!
[02/11/2008, 15:05:39] - Removing HKLM\...\Browser Helper Objects\{23D44BCF-AA7A-41D6-8905-E808F16322EF}
[02/11/2008, 15:05:39] - Removing HKCR\CLSID\{23D44BCF-AA7A-41D6-8905-E808F16322EF}
[02/11/2008, 15:05:39] - Adding Kill Bit for ActiveX for GUID: {23D44BCF-AA7A-41D6-8905-E808F16322EF}
[02/11/2008, 15:05:39] - Deleting ATLEvents/MSEvents Registry entries
[02/11/2008, 15:05:39] - Removing HKLM\...\Winlogon\Notify\yaywtsq
[02/11/2008, 15:05:39] - Searching for Browser Helper Objects:
[02/11/2008, 15:05:39] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/11/2008, 15:05:39] - BHO 2: {06E4F2A6-253A-47F3-9608-4D95D0F45CCB} ()
[02/11/2008, 15:05:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:39] - Checking for HKLM\...\Winlogon\Notify\pmkhf
[02/11/2008, 15:05:39] - Key not found: HKLM\...\Winlogon\Notify\pmkhf, continuing.
[02/11/2008, 15:05:39] - BHO 3: {09870598-3F69-438A-8103-2B9C0DFC5DA0} ()
[02/11/2008, 15:05:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:39] - Checking for HKLM\...\Winlogon\Notify\pmkjk
[02/11/2008, 15:05:39] - Key not found: HKLM\...\Winlogon\Notify\pmkjk, continuing.
[02/11/2008, 15:05:39] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/11/2008, 15:05:39] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[02/11/2008, 15:05:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:39] - No filename found. Continuing.
[02/11/2008, 15:05:39] - BHO 6: {A1A23B1C-41B1-4978-A039-8C39E3A4B0E6} ()
[02/11/2008, 15:05:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:39] - Checking for HKLM\...\Winlogon\Notify\vtusron
[02/11/2008, 15:05:39] - Key not found: HKLM\...\Winlogon\Notify\vtusron, continuing.
[02/11/2008, 15:05:39] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[02/11/2008, 15:05:39] - BHO 8: {AE7CD045-E861-484f-8273-0445EE161910} (AcroIEToolbarHelper Class)
[02/11/2008, 15:05:39] - BHO 9: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[02/11/2008, 15:05:39] - BHO 10: {DFAB7F2D-2106-47DB-A5D7-C6B45B9793DB} ()
[02/11/2008, 15:05:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:39] - Checking for HKLM\...\Winlogon\Notify\vtsqr
[02/11/2008, 15:05:39] - Key not found: HKLM\...\Winlogon\Notify\vtsqr, continuing.
[02/11/2008, 15:05:39] - BHO 11: {f0f8a5d2-84ef-456c-a2c5-b0126414b822} ()
[02/11/2008, 15:05:39] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/11/2008, 15:05:39] - Checking for HKLM\...\Winlogon\Notify\cadowtxq
[02/11/2008, 15:05:39] - Key not found: HKLM\...\Winlogon\Notify\cadowtxq, continuing.
[02/11/2008, 15:05:39] - Finished Searching Browser Helper Objects
[02/11/2008, 15:05:39] - Finishing up...
[02/11/2008, 15:05:39] - A restart is needed.
[02/11/2008, 15:05:39] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[02/11/2008, 15:05:45] - Attempting to Restart via STOP error (Blue Screen!)
0
Utilisateur anonyme
 
Re ,

Merci de renommer le fichier ' Hijackthis.exe '(situé dans le dossier dans C:\ ) en HJT.exe

Le chemin d'accés du programme doit être ressemblant à celui-ci : C:\Programme\Hijackthis\HJT.exe

Puis lance-le et choisi l'option '' do a system scan and save a logfile '' et poste moi le rapport ( qui apparait sur le bloc-note )

a+
0
coc23
 
Bonjour,

Voici le rapport du petit scan HijackThis du matin :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:56:36, on 12/02/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\SAV\DefWatch.exe
C:\WINDOWS\system32\CBA\pds.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\flexlm\lmgrd.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\SAV\Rtvscan.exe
C:\flexlm\SW_D.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\PROGRA~1\SAV\VPTray.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HJT.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {06E4F2A6-253A-47F3-9608-4D95D0F45CCB} - C:\WINDOWS\system32\pmkhf.dll (file missing)
O2 - BHO: (no name) - {23D44BCF-AA7A-41D6-8905-E808F16322EF} - C:\WINDOWS\system32\tuvvwtu.dll
O2 - BHO: {5d286411-e4e0-c58a-f004-ab6428c372d6} - {6d273c82-46ba-400f-a85c-0e4e114682d5} - C:\WINDOWS\system32\sbxsgqdd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {A1A23B1C-41B1-4978-A039-8C39E3A4B0E6} - C:\WINDOWS\system32\vtusron.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {DD254905-DD77-4F5F-988C-43321A593640} - C:\WINDOWS\system32\pmkjk.dll
O2 - BHO: (no name) - {DFAB7F2D-2106-47DB-A5D7-C6B45B9793DB} - C:\WINDOWS\system32\vtsqr.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SAV\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [708c159f] rundll32.exe "C:\WINDOWS\system32\mbvdluif.dll",b
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Policies\Explorer\Run: [WinUpdating] WinUpdating.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Assistant d'Acrobat.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (Contrôleur de DownloadManager) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: tuvvwtu - C:\WINDOWS\SYSTEM32\tuvvwtu.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\SAV\DefWatch.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel PDS - LANDesk Software Ltd. - C:\WINDOWS\system32\CBA\pds.exe
O23 - Service: Service de repérage Symantec System Center (NSCTOP) - Symantec Corporation - C:\PROGRA~1\Symantec\SYMANT~1\NSCTOP.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Fichiers communs\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: SolidWorks SolidNetWork License Manager - Macrovision Corporation - C:\flexlm\lmgrd.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\SAV\Rtvscan.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
0
Utilisateur anonyme
 
Re ,

Ta version d'Adobe n'est pas à jour , désinstalle ta version actuelle en passant par ' ajout et supréssion de programmes '

Puis télécharge la dernière , via ce site --> https://get2.adobe.com/reader/otherversions/

Bulletin de sécurité sur les versions Adobe 7.0.8 et antérieures :

https://www.adobe.com/support/security/bulletins/apsb07-01.html

**********************

Télécharge OTMoveIt2 ( de Old Timer )

Une fois téléchargé double-clique sur OTMoveIt2.exe pour le lancer.

Assure toi que la case Unregister Dll's and Ocx's soit bien cochée

puis copie les lignes en gras qui se trouvent en dessous :

C:\WINDOWS\system32\hlhqqcvg.dll
C:\WINDOWS\system32\vtusron.dll
C:\WINDOWS\system32\tuvvwtu.dll
C:\WINDOWS\system32\sbxsgqdd.dll
C:\WINDOWS\system32\pmkjk.dll
C:\WINDOWS\system32\mbvdluif.dll


et colle-les dans le cadre de gauche de OTMoveIt : "Paste Standard List Of Files/Folders to Move."
clique sur MoveIt! pour lancer la suppression.
le résultat apparaitra dans le cadre Results.
clique sur Exit pour fermer.
2) Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

3) Il te sera peut-être demander de redémarrer le pc pour achever la suppression -> Accepte ( si il ne fait pas automatiquement , fait-le toi même )

/!\ Note : Au démarrage ton bureau RISQUE de ne plus apparaître , dans ce cas fait --> CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
Puis rends toi à l'onglet "Processus". Clique en haut à gauche sur Fichiers et choisis "Exécuter"

Tape explorer.exe et valide. Cela fera re-apparaître le Bureau.

****************

Poste le rapport.

A+
0
coc23
 
Voici le rapport de OTMoveIt:

DllUnregisterServer procedure not found in C:\WINDOWS\system32\hlhqqcvg.dll
C:\WINDOWS\system32\hlhqqcvg.dll NOT unregistered.
C:\WINDOWS\system32\hlhqqcvg.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\vtusron.dll
C:\WINDOWS\system32\vtusron.dll NOT unregistered.
C:\WINDOWS\system32\vtusron.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\tuvvwtu.dll
C:\WINDOWS\system32\tuvvwtu.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\tuvvwtu.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\sbxsgqdd.dll
C:\WINDOWS\system32\sbxsgqdd.dll NOT unregistered.
C:\WINDOWS\system32\sbxsgqdd.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmkjk.dll
C:\WINDOWS\system32\pmkjk.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\pmkjk.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\mbvdluif.dll
C:\WINDOWS\system32\mbvdluif.dll NOT unregistered.
C:\WINDOWS\system32\mbvdluif.dll moved successfully.

OTMoveIt2 v1.0.19 log created on 02122008_135852
0
coc23
 
Voici le rapport OTMoveIt2:

DllUnregisterServer procedure not found in C:\WINDOWS\system32\hlhqqcvg.dll
C:\WINDOWS\system32\hlhqqcvg.dll NOT unregistered.
C:\WINDOWS\system32\hlhqqcvg.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\vtusron.dll
C:\WINDOWS\system32\vtusron.dll NOT unregistered.
C:\WINDOWS\system32\vtusron.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\tuvvwtu.dll
C:\WINDOWS\system32\tuvvwtu.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\tuvvwtu.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\sbxsgqdd.dll
C:\WINDOWS\system32\sbxsgqdd.dll NOT unregistered.
C:\WINDOWS\system32\sbxsgqdd.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\pmkjk.dll
C:\WINDOWS\system32\pmkjk.dll NOT unregistered.
File move failed. C:\WINDOWS\system32\pmkjk.dll scheduled to be moved on reboot.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\mbvdluif.dll
C:\WINDOWS\system32\mbvdluif.dll NOT unregistered.
C:\WINDOWS\system32\mbvdluif.dll moved successfully.

OTMoveIt2 v1.0.19 log created on 02122008_135852
0