Problème avec ali.exe !!

Bonjour,

voila j'arrive pas a supprimé le trojan ali.exe qui se trouve dans système32, j'ai essayer avec Hijackthis de le fixé et de le détruire avec OtMoveit mais sa marche pas, il réapparait a chaque fois. quelqu'un pourrai m'aider a trouver la bonne manipulation pour léradiqué une bonne fois pour toute !!

voici le scan de hijackthis.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:06:22, on 05/05/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
D:\ad-aware 2007\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\UberIcon\UberIcon Manager.exe
C:\Program Files\styler\Styler.exe
C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Razer\Copperhead\razerhid.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ASUS\ASUS DH Remote\AsDhRemote.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
D:\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Razer\Copperhead\razertra.exe
C:\Program Files\Razer\Copperhead\razerofa.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
D:\Steam\Steam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Ultimate Edition
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O1 - Hosts: ::1 localhost
O1 - Hosts: 66.249.93.99 www.google.fr
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
O4 - HKLM\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\Vistadrive\vsdrv.exe
O4 - HKLM\..\Run: [Styler] C:\Program Files\styler\Styler.exe
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
O4 - HKLM\..\Run: [Ai Quicker Help] "C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe"
O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\RunOnce: [*Bandook] C:\WINDOWS\system32\ali.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\ad-aware 2007\aawservice.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Alcohol 120\StarWind\StarWindServiceAE.exe

--
End of file - 10092 bytes
Configuration: Windows XP
Firefox 2.0.0.14

35 réponses

Résumé de la discussion

Le problème de suppression persistante d’un trojan ali.exe placé dans le répertoire système et détecté par HijackThis sur Windows XP SP2, réapparaissant après les tentatives classiques. Des solutions évoquées incluent l’outil The Avenger et des approches comme OTMoveIt, avec des rapports montrant que ali.exe est ciblé via des entrées RunOnce et des processus système compromis. Les échanges documentent des résultats variables: des suppressions réalisées par The Avenger, puis des messages d’objets introuvables ou des scripts invalides, et des scans HijackThis persistants malgré les nettoyages partiels. En cas de persistance, la nuance utile est que les outils peuvent supprimer le fichier et laisser des artefacts ou services résiduels, nécessitant une vérification manuelle des démarrages et des clés Run.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    tu as le CD authentique de Windows avec le numéro de licence à 25 caractères collé sur l'unité centrale ?

    Imprime ces instructions car tu n'y auras pas accès durant le passage en mode sans échec.
    Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
    • Redémarre ton ordinateur
    • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
    • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
    • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
    • Choisis ton compte.
    Déroule la liste des instructions ci-dessous :
    • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.cmd pour lancer le scrïpt.
    • Appuie sur Y pour commencer le processus de nettoyage.
    • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
    • Appuie sur une touche pour redémarrer le PC.
    • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
    • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    • Appuie sur une touche pour finir l'exécution du scrïpt et charger les icônes de ton Bureau.
    • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
    • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !
    1. dsl mais c'est pas une version authentique de xp j'ai pas les moyens :( mais bon y a pas une autre solutions que cela pour le supprimer ??
      1. heuu c'est à dire a partir d'ou?? le téléchargement du logiciel sdfix ??
        1. re,

          quand je fais f8 au démarrage de windows, j'ai un menu qui s'affiche mais pas de menu démarrage mode sans échec, il m'affiche :
          please selcet boot device:
          1st FLOPPY DRIVE
          HDD:3M-Hitachi h0t725032vla360
          CDROM:38-ASUS DRW-1814BLT

          et c'est tout j'ai rien d'autre,comment faire pour avoir le menu avec le démarrage sans échec ?
          ou alors quel menu choisir? j'ai essayer le premier et sa me redémarrage le pc normalement ....

          désolé suis un novice ^^
          1. Contributeur sécurité
            Re

            essaye avec F5 au lieu de F8.

            Sinon, tu dois avoir la réponse dans la brochuire de l'ordi.
            1. re,

              j'ai fait tout ce que tu m'a indiqué avec le mode sans échec mais malheureusement le fichier ali.exe ce trouve toujours dans mon dossier système 32.

              que faire ??
              1. Pour passer en Mode sans echec tu laisses ton ordinateur démarrer et quand tu entends un bip, appuis rapidement sur F8 (juste avant que le logo de windows n'apparait ;) ). Tu devrais voir un menu avec pleins de choix :) dont le fameux Mode Sans Echec
            2. Contributeur sécurité
              Bonjour,

              poste le rapport de SDFix avec un nouveau rapport Hijackthis
              1. voila le rapport

                b]SDFix: Version 1.180 [/b]
                Run by pacpac on 06/05/2008 at 18:33

                Microsoft Windows XP [version 5.1.2600]
                Running From: C:\SDFix

                [b]Checking Services [/b]:

                Restoring Windows Registry Values
                Restoring Windows Default Hosts File
                Restoring Missing Security Center Service

                Rebooting

                [b]Checking Files [/b]:

                No Trojan Files Found

                Removing Temp Files

                [b]ADS Check [/b]:

                [b]Final Check [/b]:

                catchme 0.3.1353.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-05-06 18:36:14
                Windows 5.1.2600 Service Pack 2 NTFS

                scanning hidden processes ...

                scanning hidden services & system hive ...

                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
                "h0"=dword:00000000
                "ujdew"=hex:53,00,ad,b4,92,80,3a,69,55,c7,a1,d3,0f,92,de,07,f4,d3,28,36,0e,..
                "p0"="D:\Alcohol 120\"
                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
                "p0"="C:\Program Files\DAEMON Tools Lite\"
                "h0"=dword:00000001
                "khjeh"=hex:0c,a1,bc,c5,7e,60,74,59,8f,ca,e6,2d,cf,4c,c5,af,79,09,34,98,18,..

                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
                "a0"=hex:20,01,00,00,70,d1,ce,91,e0,ae,14,18,60,30,bc,08,e4,0b,73,c6,e6,..
                "khjeh"=hex:16,cb,e5,5d,e1,3d,32,c1,31,89,e6,b2,4f,bf,34,92,02,19,2f,e2,42,..

                [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
                "khjeh"=hex:80,97,7f,dc,84,ba,84,8d,70,09,d5,dc,ea,a5,17,66,8f,7f,27,f6,63,..
                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\0D79C293C1ED61418462E24595C90D04]
                "h0"=dword:00000000
                "ujdew"=hex:53,00,ad,b4,92,80,3a,69,55,c7,a1,d3,0f,92,de,07,f4,d3,28,36,0e,..
                "p0"="D:\Alcohol 120\"
                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
                "p0"="C:\Program Files\DAEMON Tools Lite\"
                "h0"=dword:00000001
                "khjeh"=hex:0c,a1,bc,c5,7e,60,74,59,8f,ca,e6,2d,cf,4c,c5,af,79,09,34,98,18,..

                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
                "a0"=hex:20,01,00,00,70,d1,ce,91,e0,ae,14,18,60,30,bc,08,e4,0b,73,c6,e6,..
                "khjeh"=hex:16,cb,e5,5d,e1,3d,32,c1,31,89,e6,b2,4f,bf,34,92,02,19,2f,e2,42,..

                [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
                "khjeh"=hex:80,97,7f,dc,84,ba,84,8d,70,09,d5,dc,ea,a5,17,66,8f,7f,27,f6,63,..

                scanning hidden registry entries ...

                scanning hidden files ...

                scan completed successfully
                hidden processes: 0
                hidden services: 0
                hidden files: 0

                [b]Remaining Services [/b]:

                Authorized Application Key Export:

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                "C:\\Program Files\\Ubisoft\\Ghost Recon Advanced Warfighter\\GRAW.exe"="C:\\Program Files\\Ubisoft\\Ghost Recon Advanced Warfighter\\GRAW.exe:*:Enabled:GRAW"
                "D:\\Ubisoft\\Ghost Recon Advanced Warfighter\\GRAW.exe"="D:\\Ubisoft\\Ghost Recon Advanced Warfighter\\GRAW.exe:*:Enabled:GRAW"
                "D:\\HLSW\\hlsw.exe"="D:\\HLSW\\hlsw.exe:*:Enabled:hlsw"
                "D:\\Steam\\SteamApps\\froibad\\counter-strike source\\hl2.exe"="D:\\Steam\\SteamApps\\froibad\\counter-strike source\\hl2.exe:*:Enabled:hl2"
                "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"
                "D:\\Steam\\SteamApps\\froibad\\race\\Race_Steam.exe"="D:\\Steam\\SteamApps\\froibad\\race\\Race_Steam.exe:*:Enabled:Race"
                "C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe"="C:\\Program Files\\Nero\\Nero 7\\Nero Home\\NeroHome.exe:*:Enabled:Nero Home"
                "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
                "D:\\Microsoft Games\\Age of Empires III\\age3.exe"="D:\\Microsoft Games\\Age of Empires III\\age3.exe:*:Enabled:Age of Empires 3"
                "D:\\Unreal Tournament 3\\Binaries\\UT3.exe"="D:\\Unreal Tournament 3\\Binaries\\UT3.exe:*:Enabled:Unreal Tournament 3"
                "D:\\Command & Conquer 3 les guerres du tiberium\\RetailExe\\1.0\\cnc3game.dat"="D:\\Command & Conquer 3 les guerres du tiberium\\RetailExe\\1.0\\cnc3game.dat:*:Enabled:Command & Conquer 3 Les guerres du TiberiumT"
                "C:\\Documents and Settings\\Mickael\\Local Settings\\Temp\\ElectronicArts_Patcher_000.exe"="C:\\Documents and Settings\\Mickael\\Local Settings\\Temp\\ElectronicArts_Patcher_000.exe:*:Enabled:ElectronicArts_Patcher_000"
                "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
                "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
                "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
                "D:\\eMule\\emule.exe"="D:\\eMule\\emule.exe:*:Enabled:eMule"
                "D:\\Steam\\SteamApps\\froibad\\source dedicated server\\srcds.exe"="D:\\Steam\\SteamApps\\froibad\\source dedicated server\\srcds.exe:*:Enabled:srcds"
                "C:\\Program Files\\Fichiers communs\\Ahead\\Nero Web\\SetupX.exe"="C:\\Program Files\\Fichiers communs\\Ahead\\Nero Web\\SetupX.exe:*:Enabled:Nero ProductSetup"
                "C:\\Documents and Settings\\Mickael\\Local Settings\\Temp\\Nero Web\\SetupXu.exe"="C:\\Documents and Settings\\Mickael\\Local Settings\\Temp\\Nero Web\\SetupXu.exe:*:Enabled:Nero ProductSetup"
                "D:\\Steam\\Steam.exe"="D:\\Steam\\Steam.exe:*:Enabled:Steam"
                "C:\\Documents and Settings\\Mickael\\Local Settings\\Application Data\\ftp.exe"="C:\\Documents and Settings\\Mickael\\Local Settings\\Application Data\\ftp.exe:*:Disabled:Programm zur Dateibertragung"
                "D:\\Steam\\SteamApps\\froibad\\half-life 2 deathmatch\\hl2.exe"="D:\\Steam\\SteamApps\\froibad\\half-life 2 deathmatch\\hl2.exe:*:Enabled:hl2"
                "D:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"="D:\\Call of Duty 4 - Modern Warfare\\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
                "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

                [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
                "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
                "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

                [b]Remaining Files [/b]:

                File Backups: - C:\SDFix\backups\backups.zip

                [b]Files with Hidden Attributes [/b]:

                Mon 7 Jan 2008 444 ...HR --- "C:\Documents and Settings\Mickael\Application Data\SecuROM\UserData\securom_v7_01.bak"
                Sun 21 May 2006 114,688 A.SH. --- "C:\Documents and Settings\Mickael\Mes documents\Mes images\photo lan addams\100KM006\SIV1BD.tmp"
                Tue 2 May 2006 352,256 A.SH. --- "C:\Documents and Settings\Mickael\Mes documents\Mes images\photo lan addams\100KM006\SIV3D.tmp"
                Tue 2 May 2006 126,976 A.SH. --- "C:\Documents and Settings\Mickael\Mes documents\Mes images\photo lan addams\100KM006\SIV40.tmp"
                Sat 10 Sep 2005 282,624 A.SH. --- "C:\Documents and Settings\Mickael\Mes documents\Mes images\photo lan addams\100KM006\SIV42.tmp"
                Fri 26 May 2006 299,008 A.SH. --- "C:\Documents and Settings\Mickael\Mes documents\Mes images\photo lan addams\100KM006\SIV4C.tmp"
                Mon 26 Dec 2005 184,320 A.SH. --- "C:\Documents and Settings\Mickael\Mes documents\Mes images\photo lan addams\100KM006\SIV837.tmp"
                Wed 20 Sep 2006 565,248 A.SH. --- "C:\Documents and Settings\Mickael\Mes documents\Mes images\photo lan addams\100KM006\SIVA.tmp"
                Wed 20 Sep 2006 262,144 A.SH. --- "C:\Documents and Settings\Mickael\Mes documents\Mes images\photo lan addams\100KM006\SIVB.tmp"

                [b]Finished![/b]

                et celui de hijackthis

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 20:02:33, on 06/05/2008
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16574)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\csrss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\svchost.exe
                D:\ad-aware 2007\aawservice.exe
                C:\WINDOWS\Explorer.EXE
                C:\Program Files\Internet Explorer\IEXPLORE.EXE
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                C:\Program Files\Spyware Doctor\pctsAuxs.exe
                C:\Program Files\Spyware Doctor\pctsSvc.exe
                C:\Program Files\Spyware Doctor\pctsTray.exe
                D:\Alcohol 120\StarWind\StarWindServiceAE.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\alg.exe
                C:\Program Files\UberIcon\UberIcon Manager.exe
                C:\Program Files\styler\Styler.exe
                C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe
                C:\Program Files\ASUS\ASUS DH Remote\AsDhRemote.exe
                C:\WINDOWS\system32\RUNDLL32.EXE
                C:\WINDOWS\RTHDCPL.EXE
                C:\Program Files\Razer\Copperhead\razerhid.exe
                C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                C:\Program Files\DAEMON Tools Lite\daemon.exe
                C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                C:\Program Files\Razer\Copperhead\razertra.exe
                C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                C:\Program Files\Razer\Copperhead\razerofa.exe
                D:\Steam\Steam.exe
                D:\Teamspeak2_RC2\TeamSpeak.exe
                D:\TSO\tso.exe
                d:\steam\steamapps\froibad\counter-strike source\hl2.exe
                D:\Steam\GameOverlayUI.exe
                C:\Program Files\Mozilla Firefox\firefox.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
                C:\WINDOWS\system32\wbem\wmiprvse.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/keyword/%s
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://actus.sfr.fr
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://actus.sfr.fr
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.fr/?gws_rd=ssl
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://actus.sfr.fr
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = https://actus.sfr.fr
                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Ultimate Edition
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                R3 - URLSearchHook: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
                O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                O2 - BHO: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
                O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                O3 - Toolbar: free-downloads.net Toolbar - {ecdee021-0d17-467f-a1ff-c7a115230949} - C:\Program Files\free-downloads.net\tbfree.dll
                O4 - HKLM\..\Run: [UberIcon] "C:\Program Files\UberIcon\UberIcon Manager.exe"
                O4 - HKLM\..\Run: [Vistadrv] C:\WINDOWS\system32\Vistadrive\vsdrv.exe
                O4 - HKLM\..\Run: [Styler] C:\Program Files\styler\Styler.exe
                O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\JM\JMInsIDE.exe
                O4 - HKLM\..\Run: [Ai Quicker Help] "C:\Program Files\ASUS\ASUS DH Remote\AsRc.exe"
                O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\Copperhead\razerhid.exe
                O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
                O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
                O4 - HKLM\..\RunOnce: [*Bandook] C:\WINDOWS\system32\ali.exe
                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                O4 - HKCU\..\Run: [AlcoholAutomount] "D:\Alcohol 120\axcmd.exe" /automount
                O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
                O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
                O4 - HKUS\S-1-5-19\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\RunOnce: [nltide3] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\RunOnce: [nltide2] cmd.exe /C rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,L,,4,N (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_2] regsvr32 /s /n /i:U shell32 (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\RunOnce: [TSClientMSIUninstaller] cmd.exe /C "cscript %systemroot%\Installer\TSClientMsiTrans\tscuinst.vbs" (User 'Default user')
                O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
                O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
                O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - D:\ad-aware 2007\aawservice.exe
                O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
                O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - D:\Alcohol 120\StarWind\StarWindServiceAE.exe
                1. Contributeur sécurité
                  Re,

                  Télécharge OAD http://sosvirus.changelog.fr/OAD.exe
                  - Enregistre le sur ton Bureau

                  Double clique sur le OAD pour le lancer

                  - nom de fichier à rechercher tape ou fais un copier coller de : ali.exe
                  - Type de recherche : sélectionne l'option 6 puis valide [entree]

                  OAD va maintenant rechercher le fichier. Laisse le travailler jusqu'à ce qu'il en ai terminé.
                  Le rapport de recherche s'affichera automatiquement à dès qu'il en aura terminé.

                  - Fais un copier / coller de ce rapport dans ton prochain post.

                  Note importante : Suivant la taille des disques dur cette recherche peut prendre plusieurs minutes. Sois patient(e)
                  1. voila c'est fais mais toujours ali.exe dans mon fichier

                    voila le rapport

                    06/05/2008 ---- 20:23:11,10

                    ----------------------------------
                    §§§§§§ [C:\WINDOWS\system32\ali.exe] §§§§§§
                    ----------------------------------
                    [X] Registre

                    -------------- [ ] rapide
                    -- Fichier --- [ ] disque systeme
                    ------------- [X] complete

                    ********************
                    [Registre]
                    ********************

                    Aucune entrée détectée

                    *******************
                    [Fichier]
                    *******************

                    *********************
                    [Même date]
                    *********************

                    Aucun fichier créé à la même date détecté

                    Outil Aide Diagnostic By !aur3n7 Version 1.1
                    ----------------------------------
                    §§§§§ Fin Rapport §§§§§
                    ----------------------------------
                    1. Contributeur sécurité
                      Re,

                      1) la maneuvre va laosser le fichier et je le sais.

                      2) je ne t'ai pas demandé de faire une recherche sur C:\WINDOWS\system32\ali.exe

                      mais sur

                      ali.exe

                      Recommence.
                      1. Contributeur sécurité
                        Re,

                        fais exactement ça :

                        Double clique sur le OAD pour le lancer

                        - nom de fichier à rechercher tape ou fais un copier coller de : ali.exe
                        - Type de recherche : sélectionne l'option 6 puis valide [entree]

                        OAD va maintenant rechercher le fichier. Laisse le travailler jusqu'à ce qu'il en ai terminé.
                        Le rapport de recherche s'affichera automatiquement à dès qu'il en aura terminé.

                        - Fais un copier / coller de ce rapport dans ton prochain post.

                        Note importante : Suivant la taille des disques dur cette recherche peut prendre plusieurs minutes. Sois patient(e)
                        1. voila le new rapport, est- ce que c'est bon ?

                          06/05/2008 ---- 23:08:45,70

                          ----------------------------------
                          §§§§§§ [ali.exe] §§§§§§
                          ----------------------------------
                          [X] Registre

                          -------------- [ ] rapide
                          -- Fichier --- [ ] disque systeme
                          ------------- [X] complete

                          ********************
                          [Registre]
                          ********************

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{B6A807N6-42DF-4W02-93E5-B156B3FA8AL1}]
                          "StubPath"="C:\\WINDOWS\\system32\\ali.exe"

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                          "*Bandook"="C:\\WINDOWS\\system32\\ali.exe"

                          [HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Microsoft\Windows\ShellNoRoam\MUICache]
                          "C:\\Documents and Settings\\Mickael\\Bureau\\virer ali.exe"="virer ali"

                          [HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Microsoft\Windows\ShellNoRoam\MUICache]
                          "C:\\WINDOWS\\system32\\ali.exe"="ali"

                          [HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Notepad2\Recent Files]
                          "b"="C:\\Documents and Settings\\Mickael\\Bureau\\virer ali.exe"

                          *******************
                          [Fichier]
                          *******************

                          c:\_OTMoveIt\MovedFiles\WINDOWS\system32\ali.exe
                          c:\WINDOWS\system32\ali.exe

                          *********************
                          [Même date]
                          *********************

                          [13/02/2008 ] ---> C:\WINDOWS\system32\928 ali.exe

                          Outil Aide Diagnostic By !aur3n7 Version 1.1
                          ----------------------------------
                          §§§§§ Fin Rapport §§§§§
                          ----------------------------------
                          1. Contributeur sécurité
                            Bonsoir,

                            oui, c'était bien ça que je voulais;

                            double-clique sur OTMoveIt.exe pour le lancer.

                            copie la liste qui se trouve en gras ci-dessous,

                            et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{B6A807N6-42DF-4W02-93E5-B156B3FA8AL1}

                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\*Bandook

                            HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Microsoft\Windows\ShellNoRoam\MUICache\\C:\Documents and Settings\Mickael\Bureau\virer ali.exe

                            HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Microsoft\Windows\ShellNoRoam\MUICache\\C:\WINDOWS\system32\ali.exe

                            HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Notepad2\Recent Files\\"b"

                            C:\Documents and Settings\Mickael\Bureau\virer ali.exe

                            C:\WINDOWS\system32\ali.exe

                            C:\WINDOWS\system32\928 ali.exe


                            clique sur MoveIt! pour lancer la suppression.

                            le résultat apparaitra dans le cadre "Results".

                            clique sur Exit pour fermer.

                            poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                            il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                            Sinon, fais redémarrer l'ordi toi même.

                            Refais une recherche avec OAD sur ali.exe (pour vérifier si la maneuvre a fonctionné)
                            1. voila c'est fais mais a ne l'a pas supprimer :(

                              voila le rapport

                              File/Folder HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{B6A807N6-42DF-4W02-93E5-B156B3FA8AL1} not found.
                              File/Folder not found.
                              File/Folder HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\\*Bandook not found.
                              File/Folder not found.
                              File/Folder HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Microsoft\Windows\ShellN­oRoam\MUICache\\C:\Documents and Settings\Mickael\Bureau\virer ali.exe not found.
                              File/Folder not found.
                              File/Folder HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Microsoft\Windows\ShellN­oRoam\MUICache\\C:\WINDOWS\system32\ali.exe not found.
                              File/Folder not found.
                              File/Folder HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Notepad2\Recent Files\\"b" not found.
                              File/Folder not found.
                              File/Folder C:\Documents and Settings\Mickael\Bureau\virer ali.exe not found.
                              File/Folder not found.
                              C:\WINDOWS\system32\ali.exe moved successfully.
                              File/Folder not found.
                              File/Folder C:\WINDOWS\system32\928 ali.exe not found.

                              Created on 05/07/2008 00:17:51
                              1. Contributeur sécurité
                                Re,

                                on fait autrement.

                                Ouvre le Bloc Notes.
                                Copie le texte ci-dessous (entre les * mais sans les *) avec le texte qui se trouve dans l'espace ci-dessous (copie/colle) :

                                *****************************
                                REGEDIT4

                                [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{B6A807N6-42DF-4W02-93E5-B156B3FA8AL1}]

                                [KEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]

                                "*Bandook"= -

                                [HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Microsoft\Windows\ShellNoRoam\MUICache]
                                "C:\Documents and Settings\Mickael\Bureau\virer ali.exe"= -

                                [HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Microsoft\Windows\ShellNoRoam\MUICache]
                                "C:\WINDOWS\system32\ali.exe"= -

                                [HKEY_USERS\S-1-5-21-1708537768-1336601894-725345543-1002\Software\Notepad2\Recent Files]
                                "b"= -

                                *****************************
                                Clique sur "Fichier", "Enregistrer sous".
                                Clique sur Bureau (dans la colonne de gauche)
                                Dans Nom du fichier tu écris fix.reg
                                Pour Type tu choisis "tous les fichiers" avec le menu déroulant.
                                Tu cliques sur Enregistrer.
                                Tu fermes le Bloc-notes

                                Sur ton bureau, tu double-clique sur l'icône de Fix.reg
                                Tu acceptes l'avertissement concernant la fusion
                                Le fix va travailler sans se manifester.
                                A la fin, tu vas voir un message disant que la fusion est terminée. Tu valides.

                                Tu remets un log Hijackthis.

                                tu fais aussi une nouvelle recherche avec OAD sur ali.exe
                                • 1
                                • 2