Fichiers .dll infectant mon ordi

Résolu
dmc -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Bonjour a tous,
(excusez par avance les fautes, j utilise un clavier suedois, il manque certains signes tel que les accents)

Je pense etre infecte par un ou plusieurs virus.
je precise en premier lieu que mon antivirus [avast] est a jour et que j ai deja fait un scan tres complet mais sans resultat...

Le logiciel scotty qui gere le demarrage de programmes me demande incessamment si j accepte l ouverture de ces programmes dont je vous recopie le raccourci ici
C:\Windows\System32\ljDUnnn.dll,#1
C:\Windows\System32\ipfpqpsk.dll,s
C:\Windows\System32\hgGwxYPH.dll
C:\Windows\System32\hettrrnx.dll

J ai beau preciser que je n accepte pas de les ouvrir il reitere la demande toutes les trente secondes [ce qui est agacant]

A cela s ajoute le fait que ma connection internet est enormement ralenti, je ne peux quasiment pas surfer. Cela serait du au fait que l ordi m indique qu un programme ne marche plus [quelque chose comme wllproxy.exe, desole je nai pas marque le nom..].
J ai le malware Conducteurprive (et peut etre d autres) qui m embete: j ai essaye de faire un scan en ligne mais ma connection est lente en premier lieu, et tous ces malwares font planter IE ou firefox.

Bref, comme vous le voyez c est la cata.
Je pensais a formater tout ca cependant le truc est que je l ai jamais fait (un peu flippant) et que je suis pour encore quelques mois tres loin de chez moi et sans cd windows.
Ou sinon une restauration pour revenir quelques jours avant, mais ca a l air trop facile pour regler ces problemes.

si quelqu un a la moindre piste je suis carrement preneur, j ai une tonne de boulot a faire sur cet ordi cette semaine!

merci a tous de me lire et bonne journee
Configuration: Windows Vista
Firefox 2

14 réponses

  1. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    slt,

    Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

    - Va dans démarrer puis panneau de configuration
    - Double Clique sur l'icône "Comptes d'utilisateurs"
    - Clique ensuite sur désactiver et valide.

    télécharge combofix (par sUBs) ici :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    et enregistre le sur le bureau.
    déconnecte toi d'internet et ferme toutes tes applications.

    désactive tes protections (antivirus, parefeu, garde en temps réel de l'antispyware)

    double-clique sur combofix.exe et suis les instructions

    à la fin, il va produire un rapport C:\ComboFix.txt

    réactive ton parefeu, ton antivirus, la garde de ton antispyware

    copie/colle le rapport C:\ComboFix.txt dans ta prochaine réponse.

    Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi.

    Tu as un tutoriel complet ici :

    https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

    ____________________

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :
    http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."
    0
  2. dmc
     
    Merci jlpjlp de repondre aussi vite et de me faire beneficier de ton analyse.

    Je precise avant tout que j ai relance un scan avec Avast, il m a trouve trois nouveaux cheval de troie qui sont en quarantaine, j ai enleve tous les spywares trouves.
    J ai maintenant d autres messages de scooty, qui me demande de valider (je refuse a chaque fois):
    mmkkdglp.dll,s
    mertkvsb.dll,b
    mlJBULcY.dll,#1

    C est maintenant le malware disquedurprotection qui sevit, j ai beau ne rien accepter il me lance des pages internet de partout (mais je pense que vous n avez pas vraiment de solution pour ca a ce que j ai pu voir dans d autres topics...)

    Je te donne dans l ordre le rapport combofix puis celui hijackthis :

    Je vous remercie vraiment de votre patience et de votre entraide (surtout jlpjlp en ce moment)

    COMBOFIX

    ComboFix 08-05-12.1 - Dempsey 2008-05-15 13:57:48.1 - NTFSx86
    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1157 [GMT 2:00]
    Endroit: C:\Users\Dempsey\Desktop\ComboFix.exe
    * Création d'un nouveau point de restauration
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Users\Dempsey\AppData\Roaming\inst.exe
    C:\Windows\System32\dofokddj.ini
    C:\Windows\System32\HPYxwGgh.ini
    C:\Windows\System32\HPYxwGgh.ini2
    C:\Windows\System32\jlUwvyxx.ini
    C:\Windows\System32\jlUwvyxx.ini2
    C:\Windows\system32\kvqyydlw.ini
    C:\Windows\system32\mcrh.tmp
    C:\Windows\System32\vCMUwGgh.ini
    C:\Windows\System32\vCMUwGgh.ini2
    C:\Windows\system32\x64

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-15 to 2008-05-15 ))))))))))))))))))))))))))))))))))))
    .

    Pas de nouveau fichier cr‚‚ dans cet espace de temps

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-05-15 12:02 350,468 ---ha-w C:\Windows\system32\drivers\vsconfig.xml
    2008-05-15 11:22 --------- d-----w C:\Users\Dempsey\AppData\Roaming\Grisoft
    2008-05-15 11:21 --------- d-----w C:\ProgramData\Grisoft
    2008-05-15 11:20 --------- d-----w C:\Users\Dempsey\AppData\Roaming\Lavasoft
    2008-05-15 08:48 134,720 ----a-w C:\Windows\System32\hettrrnx.dll
    2008-05-15 08:34 --------- d-----w C:\Program Files\Last.fm
    2008-05-15 08:33 --------- d-----w C:\Program Files\Minilyrics
    2008-05-15 08:27 2,112 ----a-w C:\Windows\System32\cmhblrie.exe
    2008-05-15 08:25 115,264 ----a-w C:\Windows\System32\wldyyqvk.dll
    2008-05-15 08:24 125,504 ----a-w C:\Windows\System32\skvwaxcg.dll
    2008-05-15 08:20 91,744 ----a-w C:\Windows\BPMNT.dll
    2008-05-15 08:20 71,749 ----a-w C:\Windows\hcextoutput.dll
    2008-05-15 08:20 333,576 ----a-w C:\Windows\TSC.exe
    2008-05-15 08:20 1,213,784 ----a-w C:\Windows\vsapi32.dll
    2008-05-15 08:19 69,689 ----a-w C:\Windows\UNZIP.DLL
    2008-05-15 08:19 507,904 ----a-w C:\Windows\TMUPDATE.DLL
    2008-05-15 08:19 286,720 ----a-w C:\Windows\PATCH.EXE
    2008-05-15 08:04 126,464 ----a-w C:\Windows\System32\mltrjbcd.dll
    2008-05-15 08:03 369,664 ----a-w C:\Windows\System32\hgGwUMCv.dll
    2008-05-14 16:37 --------- d-----w C:\Users\Dempsey\AppData\Roaming\Skype
    2008-05-14 16:36 --------- d-----w C:\Users\Dempsey\AppData\Roaming\skypePM
    2008-05-14 07:42 2,112 ----a-w C:\Windows\System32\mnucrxur.exe
    2008-05-14 07:39 133,696 ----a-w C:\Windows\System32\xrelkpai.dll
    2008-05-14 07:33 114,240 ----a-w C:\Windows\System32\jddkofod.dll
    2008-05-14 07:20 123,456 ----a-w C:\Windows\System32\ipfpqpsk.dll
    2008-05-14 07:08 123,456 ----a-w C:\Windows\System32\whriqswo.dll
    2008-05-14 07:07 371,200 ----a-w C:\Windows\System32\xxyvwUlj.dll
    2008-05-13 21:14 --------- d-----w C:\Users\Dempsey\AppData\Roaming\uTorrent
    2008-05-13 17:29 371,200 ----a-w C:\Windows\System32\hgGwxYPH.dll
    2008-05-13 17:04 57,344 ----a-w C:\Windows\System32\mlJBULcY.dll
    2008-05-12 16:37 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
    2008-05-12 13:04 --------- d-----w C:\Users\Dempsey\AppData\Roaming\OpenOffice.org2
    2008-05-05 18:42 600,064 ----a-w C:\Windows\Internet Logs\xDB8BF9.tmp
    2008-05-04 22:24 --------- d-----w C:\Program Files\Mozilla Thunderbird
    2008-05-04 21:26 --------- d-----w C:\Program Files\Soulseek
    2008-05-03 17:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-05-03 17:03 --------- d-----w C:\Program Files\KONAMI
    2008-05-03 00:10 3,432,448 ----a-w C:\Windows\Internet Logs\xDB954C.tmp
    2008-04-29 08:25 --------- d-----w C:\Program Files\uTorrent
    2008-04-26 12:29 2,112,000 ----a-w C:\Windows\Internet Logs\xDB99DE.tmp
    2008-04-19 18:32 --------- d-----w C:\Users\Dempsey\AppData\Roaming\Winamp
    2008-04-08 16:12 32 ----a-w C:\Users\All Users\ezsid.dat
    2008-04-08 16:12 32 ----a-w C:\ProgramData\ezsid.dat
    2008-04-08 16:11 --------- d-----w C:\Program Files\Skype
    2008-04-08 16:11 --------- d-----w C:\Program Files\Common Files\Skype
    2008-03-26 17:56 --------- d-----w C:\Program Files\DC++
    2008-03-24 07:48 --------- d-----w C:\Program Files\Zone Labs
    2008-03-24 07:48 --------- d-----w C:\Program Files\Yadu Digital
    2008-03-24 07:48 --------- d-----w C:\Program Files\Photofiltre
    2008-03-24 07:44 30,153 ----a-w C:\Windows\system32\drivers\kwfupper.log
    2008-03-24 07:34 60,624 ----a-w C:\Windows\system32\drivers\kwflower.log
    2008-03-20 21:07 --------- d-----w C:\Program Files\Kerio
    2008-02-29 06:51 19,000 ----a-w C:\Windows\System32\kd1394.dll
    2008-02-29 06:39 40,960 ----a-w C:\Windows\System32\srclient.dll
    2008-02-29 06:39 371,712 ----a-w C:\Windows\System32\srcore.dll
    2008-02-29 06:38 313,856 ----a-w C:\Windows\System32\rstrui.exe
    2008-02-29 06:38 16,384 ----a-w C:\Windows\System32\srdelayed.exe
    2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
    2008-02-29 06:34 7,168 ----a-w C:\Windows\System32\f3ahvoas.dll
    2008-02-29 04:16 2,027,008 ----a-w C:\Windows\System32\win32k.sys
    2008-02-21 04:43 826,368 ----a-w C:\Windows\System32\wininet.dll
    2008-02-21 04:43 56,320 ----a-w C:\Windows\System32\iesetup.dll
    2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
    2008-02-21 04:43 296,448 ----a-w C:\Windows\System32\gdi32.dll
    2008-02-21 04:43 26,624 ----a-w C:\Windows\System32\ieUnatt.exe
    2008-02-19 05:10 620,088 ----a-w C:\Windows\System32\ci.dll
    2008-02-18 09:11 6,367,551 ----a-w C:\Windows\Internet Logs\tvDebug.zip
    2007-10-10 14:53 72,304 ----a-w C:\Users\Dempsey\AppData\Roaming\GDIPFONTCACHEV1.DAT
    2007-07-21 17:54 47,360 ----a-w C:\Users\Dempsey\AppData\Roaming\pcouffin.sys
    2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
    2007-12-16 15:44 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    2007-12-16 15:44 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    2007-12-16 15:44 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    .

    ------- Sigcheck -------

    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{04475EB3-543E-4C91-B0A4-3FCE195DC4C5}]
    2008-05-13 19:29 371200 --a------ C:\Windows\system32\hgGwxYPH.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 13:49 1232896]
    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2008-01-13 00:42 5724184]
    "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]
    "RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-09-02 14:58 495616]
    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSServer"="C:\Windows\system32\mlJBULcY.dll" [2008-05-13 19:04 57344]
    "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-06 11:02 98304]
    "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-06 11:05 106496]
    "Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-06 11:02 81920]
    "WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 09:56 317152]
    "hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 09:32 472800]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-28 05:17 959976]
    "WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-04-19 19:33 271936]
    "Monitor"="C:\Windows\PixArt\PAC207\Monitor.exe" [2006-11-03 11:01 319488]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-14 23:15 185896]
    "4f4ce6b9"="C:\Windows\system32\wldyyqvk.dll" [2008-05-15 10:25 115264]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]
    "BM4c7fd525"="C:\Windows\system32\skvwaxcg.dll" [2008-05-15 10:24 125504]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    VirtuaWin.lnk - C:\Program Files\VirtuaWin\VirtuaWin.exe [2008-03-10 23:11:31 121856]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{2AA0726C-95B7-4216-AA43-B5BDD524892F}"= C:\Windows\system32\mlJBULcY.dll [2008-05-13 19:04 57344]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.YV12"= yv12vfw.dll
    "msacm.ac3filter"= ac3filter.acm

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-991961723-1612249020-4045812409-1000]
    "EnableNotifications"=dword:00000001
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{461D84E1-A19F-4016-9741-46504709B0B7}"= UDP:C:\Program Files\HP\QuickPlay\QP.exe:QP
    "{523EF620-4D94-46A4-81C3-EA992D6C3A66}"= TCP:C:\Program Files\HP\QuickPlay\QP.exe:QP
    "{538B1A3D-0712-4BC6-A606-DDD3426516B5}"= UDP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
    "{15EED3ED-E39D-4253-A7B4-8B84137A8EEE}"= TCP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
    "TCP Query User{3D9C1AE4-4315-476E-B2DD-16AD1510DC65}C:\\program files\\last.fm\\lastfm.exe"= UDP:C:\program files\last.fm\lastfm.exe:Last.fm
    "UDP Query User{D329045F-6BC6-4277-9F1B-35FBE348271F}C:\\program files\\last.fm\\lastfm.exe"= TCP:C:\program files\last.fm\lastfm.exe:Last.fm
    "{6FD0C1B1-5303-4B16-8283-77BE9C14A769}"= Disabled:UDP:C:\Program Files\Joost\xulrunner\tvprunner.exe:tvprunner
    "{B7B440BB-F89E-48A3-B88F-615323D284A6}"= Disabled:TCP:C:\Program Files\Joost\xulrunner\tvprunner.exe:tvprunner
    "{74E739DA-79E2-4B56-90AE-73AB88A7E82E}"= UDP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
    "{DA3CA175-AC82-44F2-8F29-7C2E5B193607}"= TCP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
    "{9890C3FB-845C-4BB0-8982-5AA4932FA81B}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
    "{9B7D3852-7637-4687-B2C8-EE50238B6090}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
    "{6FD06885-678E-4DE6-B41E-7833302AA5CF}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
    "{865D88D3-B268-4DE0-B03C-AE39C7B11A1A}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
    "{AD1E3837-4687-49AE-93AD-B9F014BA57CF}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
    "{310C7382-273D-46DF-8289-B325F1B1B0C6}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
    "{075BA41E-0634-44A8-BB5C-B3F779BF7041}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
    "{B43DAD72-3475-4C56-A8E9-692DA9575FC8}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
    "{B9480D58-D503-472F-A958-1B5EEED47E3E}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
    "{9A319038-FCAC-4F37-85F8-E50F117841BB}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
    "{B0B967F1-61EA-452C-A2BE-7DBABFBE2914}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
    "{966602AF-B6C8-4783-BF1E-B2A2E70085CB}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
    "{D8032A05-92E0-4FB6-97BD-67489C5993B6}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
    "{A604B406-9816-4B68-8054-0F5D213A0B61}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
    "{A059122A-9959-42ED-BAA0-ED032DBC86AD}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
    "{28866874-21D6-4041-A404-6E25317EE898}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
    "{698A31D2-B242-4642-ABB5-904FEFC98F64}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
    "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77a6e2ea-3641-11dc-8dcc-806e6f6e6963}]
    \shell\AutoRun\command - E:\autorun6e.exe

    *Newly Created Service* - AVGASCLN
    .
    Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
    "2008-05-14 17:36:08 C:\Windows\Tasks\User_Feed_Synchronization-{4E236CEE-48BF-4C0E-98E4-B4E5D83FB0AD}.job"
    - C:\Windows\system32\msfeedssync.exe
    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-05-15 14:03:25
    Windows 6.0.6000 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 0

    **************************************************************************
    .
    --------------------- DLLs a charg‚ sous des processus courants ---------------------

    PROCESS: C:\Windows\system32\winlogon.exe
    -> C:\Windows\system32\mlJBULcY.dll

    PROCESS: C:\Windows\Explorer.exe
    -> C:\Program Files\RocketDock\RocketDock.dll
    -> C:\Windows\system32\wldyyqvk.dll
    -> C:\Windows\system32\skvwaxcg.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Windows\System32\audiodg.exe
    C:\Windows\System32\ZoneLabs\vsmon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\VirtuaWin\modules\VWAssigner.exe
    C:\Program Files\VirtuaWin\modules\WinList.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\System32\drivers\XAudio.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Windows\System32\WUDFHost.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\System32\conime.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\System32\rundll32.exe
    C:\Windows\System32\igfxsrvc.exe
    C:\Windows\System32\dllhost.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-05-15 14:11:17 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-05-15 12:10:24

    Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
    Le texte du message associ‚ au num‚ro 0x2379 est introuvable dans le fichier de messages pour Application.

    255 --- E O F --- 2008-05-09 11:11:47

    --------------------------------------------------------------------- ---------------------------------------------------

    HIJACKTHIS

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:30:48, on 15/05/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16643)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Windows\PixArt\Pac207\Monitor.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\RocketDock\RocketDock.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\VirtuaWin\VirtuaWin.exe
    C:\Program Files\VirtuaWin\modules\VWAssigner.exe
    C:\Program Files\VirtuaWin\modules\WinList.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\conime.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\system32\rundll32.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fnsr%3D1%26ui%3Dhtml%26zy%3Dl&ltmpl=default&ltmplcache=2
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\Run: [BM4c7fd525] Rundll32.exe "C:\Windows\system32\mmkkdglp.dll",s
    O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\mlJBULcY.dll,#1
    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Global Startup: VirtuaWin.lnk = C:\Program Files\VirtuaWin\VirtuaWin.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O13 - Gopher Prefix:
    O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - https://about.proquest.com/products-services/ebooks/ebooks-main.html
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe (file missing)
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    0
  3. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    analyse ces fichiers sur virus total et ceux qui sont considérés comme inféctés tu les rajoutes dans la citation OTMOVIT en plus des 4 fichiers déjà inscris

    : https://www.virustotal.com/gui/

    C:\Windows\System32\hettrrnx.dll
    C:\Windows\System32\cmhblrie.exe
    C:\Windows\System32\wldyyqvk.dll
    C:\Windows\System32\skvwaxcg.dll
    C:\Windows\System32\hgGwUMCv.dll
    C:\Windows\System32\mnucrxur.exe
    C:\Windows\System32\xrelkpai.dll
    C:\Windows\System32\jddkofod.dll
    C:\Windows\System32\ipfpqpsk.dll
    C:\Windows\System32\whriqswo.dll
    C:\Windows\System32\xxyvwUlj.dll
    C:\Windows\System32\hgGwxYPH.dll
    C:\Windows\system32\drivers\kwfupper.log
    C:\Windows\system32\drivers\kwflower.log
    C:\Windows\System32\kd1394.dll
    C:\Windows\System32\srclient.dll
    C:\Windows\System32\srcore.dll
    :\Windows\System32\rstrui.exe
    C:\Windows\System32\srdelayed.exe
    C:\Windows\System32\kbd106n.dll
    C:\Windows\System32\f3ahvoas.dll

    ______________________

    télécharge OTMoveIt
    http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
    double-clique sur OTMoveIt.exe pour le lancer.
    copie la liste qui se trouve en citation ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

    Citation :

    C:\Windows\system32\mertkvsb.dll
    C:\Windows\system32\mmkkdglp.dll
    C:\Windows\system32\mlJBULcY.dll
    HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{04475EB3-543E-4C91-B0A4-3FCE195DC4C5

    clique sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    clique sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

    ________________

    vire ce qui est dans MOVED FILES en allant dans PSOTE DE TRAVIL puis C puis OTMOVIT

    ______________

    scan avec
    MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
    ___________

    recolle un hijackhtis et dis tes soucis actuels
    0
  4. dmc
     
    Je viens de faire toutes les opérations que tu as décrites. Vraiment merci de m'offrir ton temps ainsi, je suis épaté !

    Je te poste les différents rapports en dessous.
    En allumant l'ordinateur après la fin des opérations j'ai eu deux évenements :
    - Scooty m'a demandé si j'acceptais d'ouvrir C:\Windows\System32\ifhhuicb.dll
    - Une fenêtre microsoft s'est lancé en me prevenant "Microsoft(C) Register Server a cessé de fonctionner". Je ne l'ai pas coché de peur de ne pouvoir accéder à internet.
    Je te tiens au courant des éventuels autres bobos du pc!

    le rapport Outmov

    DllUnregisterServer procedure not found in C:\Windows\system32\mertkvsb.dll
    C:\Windows\system32\mertkvsb.dll NOT unregistered.
    C:\Windows\system32\mertkvsb.dll moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\system32\mmkkdglp.dll
    C:\Windows\system32\mmkkdglp.dll NOT unregistered.
    C:\Windows\system32\mmkkdglp.dll moved successfully.
    File/Folder C:\Windows\system32\mlJBULcY.dll not found.
    < HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{04475EB3-543E-4C91-B0A4-3FCE195DC4C5 >
    Registry key HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{04475EB3-543E-4C91-B0A4-3FCE195DC4C5\\ not found.
    DllUnregisterServer procedure not found in C:\Windows\System32\hettrrnx.dll
    C:\Windows\System32\hettrrnx.dll NOT unregistered.
    C:\Windows\System32\hettrrnx.dll moved successfully.
    C:\Windows\System32\cmhblrie.exe moved successfully.
    File/Folder C:\Windows\System32\wldyyqvk.dll not found.
    DllUnregisterServer procedure not found in C:\Windows\System32\skvwaxcg.dll
    C:\Windows\System32\skvwaxcg.dll NOT unregistered.
    C:\Windows\System32\skvwaxcg.dll moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\System32\hgGwUMCv.dll
    C:\Windows\System32\hgGwUMCv.dll NOT unregistered.
    C:\Windows\System32\hgGwUMCv.dll moved successfully.
    C:\Windows\System32\mnucrxur.exe moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\System32\xrelkpai.dll
    C:\Windows\System32\xrelkpai.dll NOT unregistered.
    C:\Windows\System32\xrelkpai.dll moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\System32\jddkofod.dll
    C:\Windows\System32\jddkofod.dll NOT unregistered.
    C:\Windows\System32\jddkofod.dll moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\System32\ipfpqpsk.dll
    C:\Windows\System32\ipfpqpsk.dll NOT unregistered.
    C:\Windows\System32\ipfpqpsk.dll moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\System32\whriqswo.dll
    C:\Windows\System32\whriqswo.dll NOT unregistered.
    C:\Windows\System32\whriqswo.dll moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\System32\xxyvwUlj.dll
    C:\Windows\System32\xxyvwUlj.dll NOT unregistered.
    C:\Windows\System32\xxyvwUlj.dll moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\System32\hgGwxYPH.dll
    C:\Windows\System32\hgGwxYPH.dll NOT unregistered.
    File move failed. C:\Windows\System32\hgGwxYPH.dll scheduled to be moved on reboot.

    OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 05152008_164532

    Files moved on Reboot...
    DllUnregisterServer procedure not found in C:\Windows\System32\hgGwxYPH.dll
    C:\Windows\System32\hgGwxYPH.dll NOT unregistered.
    File move failed. C:\Windows\System32\hgGwxYPH.dll scheduled to be moved on reboot.

    ____________________________________ _____________________________________________

    MalwareBytes

    Malwarebytes' Anti-Malware 1.12
    Version de la base de données: 752

    Type de recherche: Examen complet (C:\|)
    Eléments examinés: 174146
    Temps écoulé: 36 minute(s), 22 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 1
    Clé(s) du Registre infectée(s): 9
    Valeur(s) du Registre infectée(s): 4
    Elément(s) de données du Registre infecté(s): 2
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 7

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    C:\Windows\System32\hgGwxYPH.dll (Trojan.Vundo) -> No action taken.

    Clé(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4ae2c9da-f023-4f40-982b-18b796310677} (Trojan.Vundo) -> No action taken.
    HKEY_CLASSES_ROOT\CLSID\{4ae2c9da-f023-4f40-982b-18b796310677} (Trojan.Vundo) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> No action taken.
    HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> No action taken.
    HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> No action taken.
    HKEY_CLASSES_ROOT\CLSID\{2aa0726c-95b7-4216-aa43-b5bdd524892f} (Trojan.Vundo) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.

    Valeur(s) du Registre infectée(s):
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4f4ce6b9 (Trojan.Vundo) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM4c7fd525 (Trojan.Agent) -> No action taken.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{2aa0726c-95b7-4216-aa43-b5bdd524892f} (Trojan.Vundo) -> No action taken.

    Elément(s) de données du Registre infecté(s):
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\hggwxyph -> No action taken.
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\hggwxyph -> No action taken.

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    C:\Windows\System32\hgGwxYPH.dll (Trojan.Vundo) -> No action taken.
    C:\Windows\System32\HPYxwGgh.ini (Trojan.Vundo) -> No action taken.
    C:\Windows\System32\HPYxwGgh.ini2 (Trojan.Vundo) -> No action taken.
    C:\Windows\System32\ufdjutca.dll (Trojan.Vundo) -> No action taken.
    C:\Windows\System32\actujdfu.ini (Trojan.Vundo) -> No action taken.
    C:\Windows\System32\mlJYrpQK.dll (Trojan.Agent) -> No action taken.
    C:\Windows\System32\vxpdpsmr.dll (Trojan.Agent) -> No action taken.

    ___________________________________ ____________________________________________

    Hijackthis

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 17:46:07, on 15/05/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16643)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Windows\PixArt\Pac207\Monitor.exe
    C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\RocketDock\RocketDock.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\VirtuaWin\VirtuaWin.exe
    C:\Program Files\VirtuaWin\modules\VWAssigner.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\VirtuaWin\modules\WinList.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
    C:\Program Files\Mozilla Thunderbird\thunderbird.exe
    C:\Windows\system32\regsvr32.exe
    C:\Windows\system32\WerFault.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\Eden.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fnsr%3D1%26ui%3Dhtml%26zy%3Dl&ltmpl=default&ltmplcache=2
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: (no name) - {011BCAB1-4995-486A-84D4-F91D9DF5E11A} - C:\Windows\system32\hgGwxYPH.dll
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Global Startup: VirtuaWin.lnk = C:\Program Files\VirtuaWin\VirtuaWin.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O13 - Gopher Prefix:
    O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - https://about.proquest.com/products-services/ebooks/ebooks-main.html
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe (file missing)
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. dmc
     
    Je rajoute qu'après quelques minutes, d'autres événements se passent :
    - Scooty me demande d'ouvrir cxjjsukq.dll,s
    - Windows m'affirme que c'est WLLoginProxy.exe qui a cessé de fonctionner
    - disquedurprotection m'enquiquine en me lançant sur des sites internet

    Moi qui pensait qu'après tout ça je tenais le bon bout... Mais je garde espoir!
    0
  7. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    installe
    SPYWAREBLASTER qui est gratuit pour immuniser le système contre vundo que tu avais notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/28872.html

    _______________

    pour fusionner: regarde bien ce lien:

    http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
    _____________

    Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

    - Va dans démarrer puis panneau de configuration
    - Double Clique sur l'icône "Comptes d'utilisateurs"
    - Clique ensuite sur désactiver et valide.

    Ferme tout tes navigateurs (donc copie ou imprime les instructions avant)

    Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

    File::
    C:\Windows\system32\hgGwxYPH.dll
    C:\Windows\system32\mlJBULcY.dll
    C:\Windows\system32\skvwaxcg.dll
    C:\Windows\system32\wldyyqvk.dll
    C:\Windows\system32\mlJBULcY.dll
    C:\Windows\system32\cxjjsukq.dll

    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{04475EB3-543E-4C91-B0A4-3FCE195DC4C5}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSServer"="-
    "4f4ce6b9"=-
    "BM4c7fd525"=-
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{2AA0726C-95B7-4216-AA43-B5BDD524892F}"=-

    Enregistre ce fichier sous le nom CFscript

    Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

    Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

    Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

    Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

    Ne touche à rien tant que le scan n'est pas terminé.

    Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

    Remets aussi un rapport Hijackthis

    Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

    ________________

    as tu encore des problèmes???
    0
  8. dmc
     
    Et bien, voilà deux heures environ que les manipulations sont terminées, j'ai surfé sur internet, regardé des vidéos, consulté des mails, parlé sur des messageries instantanées,... bref, aucun soucis jusque là.
    Je n'en reviens pas du tout!

    Vraiment un très très très gros merci à toi jlpjlp, ca tombe sous le coup de l'évidence de dire que je n'y serai jamais arrivé sans toi, mais c'est toujours bon à rappeler. Je reste à l'affut pour d'éventuels désagréments qui ressurgiraient, mais j'ai bon espoir.
    Par ailleurs, à part le fait que ce soit un/des virus qui étai(en)t présent(s) sur mon pc, sais tu s'il y a une cause bien particulière? une manip que j'ai horriblement mal fait, ... je sais que la MAJ des outils de protection, bien que nécessaires, ne sont pas une protection totale, mais bon s'il y a erreur a rectifier, autant que cela soit fait.

    Encore une fois merci (à vous tous!)

    Et à bientôt!
    0
  9. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    tu as le rapports combofix de la manip??
    0
  10. dmc
     
    Hm pardon je suis distrait effectivement, je te met les deux rapports :

    COMBOFIX

    ComboFix 08-05-12.1 - Dempsey 2008-05-15 18:22:46.2 - NTFSx86
    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6000.0.1252.1.1036.18.1270 [GMT 2:00]
    Endroit: C:\Users\Dempsey\Desktop\ComboFix.exe
    Command switches used :: C:\Users\Dempsey\Desktop\CFscript.txt
    * Création d'un nouveau point de restauration

    FILE ::
    C:\Windows\system32\hgGwxYPH.dll
    C:\Windows\system32\mlJBULcY.dll
    C:\Windows\system32\skvwaxcg.dll
    C:\Windows\system32\wldyyqvk.dll
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Windows\system32\bsvktrem.ini
    C:\Windows\system32\hgGwxYPH.dll
    C:\Windows\System32\HPYxwGgh.ini
    C:\Windows\System32\HPYxwGgh.ini2

    .
    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-15 to 2008-05-15 ))))))))))))))))))))))))))))))))))))
    .

    Pas de nouveau fichier cr‚‚ dans cet espace de temps

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-05-15 16:29 350,468 ---ha-w C:\Windows\system32\drivers\vsconfig.xml
    2008-05-15 16:14 --------- d-----w C:\ProgramData\TEMP
    2008-05-15 16:14 --------- d-----w C:\Program Files\SpywareBlaster
    2008-05-15 14:57 --------- d-----w C:\Users\Dempsey\AppData\Roaming\Malwarebytes
    2008-05-15 14:57 --------- d-----w C:\ProgramData\Malwarebytes
    2008-05-15 14:57 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
    2008-05-15 12:29 --------- d-----w C:\Program Files\Trend Micro
    2008-05-15 11:22 --------- d-----w C:\Users\Dempsey\AppData\Roaming\Grisoft
    2008-05-15 11:21 --------- d-----w C:\ProgramData\Grisoft
    2008-05-15 11:20 --------- d-----w C:\Users\Dempsey\AppData\Roaming\Lavasoft
    2008-05-15 08:34 --------- d-----w C:\Program Files\Last.fm
    2008-05-15 08:33 --------- d-----w C:\Program Files\Minilyrics
    2008-05-15 08:20 91,744 ----a-w C:\Windows\BPMNT.dll
    2008-05-15 08:20 71,749 ----a-w C:\Windows\hcextoutput.dll
    2008-05-15 08:20 333,576 ----a-w C:\Windows\TSC.exe
    2008-05-15 08:20 1,213,784 ----a-w C:\Windows\vsapi32.dll
    2008-05-15 08:19 69,689 ----a-w C:\Windows\UNZIP.DLL
    2008-05-15 08:19 507,904 ----a-w C:\Windows\TMUPDATE.DLL
    2008-05-15 08:19 286,720 ----a-w C:\Windows\PATCH.EXE
    2008-05-14 16:37 --------- d-----w C:\Users\Dempsey\AppData\Roaming\Skype
    2008-05-14 16:36 --------- d-----w C:\Users\Dempsey\AppData\Roaming\skypePM
    2008-05-13 21:14 --------- d-----w C:\Users\Dempsey\AppData\Roaming\uTorrent
    2008-05-12 16:37 50,768 ----a-w C:\Windows\system32\drivers\aswMonFlt.sys
    2008-05-12 13:04 --------- d-----w C:\Users\Dempsey\AppData\Roaming\OpenOffice.org2
    2008-05-05 18:46 27,048 ----a-w C:\Windows\system32\drivers\mbamcatchme.sys
    2008-05-05 18:46 15,864 ----a-w C:\Windows\system32\drivers\mbam.sys
    2008-05-05 18:42 600,064 ----a-w C:\Windows\Internet Logs\xDB8BF9.tmp
    2008-05-04 22:24 --------- d-----w C:\Program Files\Mozilla Thunderbird
    2008-05-04 21:26 --------- d-----w C:\Program Files\Soulseek
    2008-05-03 17:07 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-05-03 17:03 --------- d-----w C:\Program Files\KONAMI
    2008-05-03 00:10 3,432,448 ----a-w C:\Windows\Internet Logs\xDB954C.tmp
    2008-04-29 08:25 --------- d-----w C:\Program Files\uTorrent
    2008-04-26 12:29 2,112,000 ----a-w C:\Windows\Internet Logs\xDB99DE.tmp
    2008-04-19 18:32 --------- d-----w C:\Users\Dempsey\AppData\Roaming\Winamp
    2008-04-08 16:12 32 ----a-w C:\Users\All Users\ezsid.dat
    2008-04-08 16:12 32 ----a-w C:\ProgramData\ezsid.dat
    2008-04-08 16:11 --------- d-----w C:\Program Files\Skype
    2008-04-08 16:11 --------- d-----w C:\Program Files\Common Files\Skype
    2008-03-26 17:56 --------- d-----w C:\Program Files\DC++
    2008-03-24 07:48 --------- d-----w C:\Program Files\Zone Labs
    2008-03-24 07:48 --------- d-----w C:\Program Files\Yadu Digital
    2008-03-24 07:48 --------- d-----w C:\Program Files\Photofiltre
    2008-03-24 07:44 30,153 ----a-w C:\Windows\system32\drivers\kwfupper.log
    2008-03-24 07:34 60,624 ----a-w C:\Windows\system32\drivers\kwflower.log
    2008-03-20 21:07 --------- d-----w C:\Program Files\Kerio
    2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll
    2008-02-18 09:11 6,367,551 ----a-w C:\Windows\Internet Logs\tvDebug.zip
    2007-10-10 14:53 72,304 ----a-w C:\Users\Dempsey\AppData\Roaming\GDIPFONTCACHEV1.DAT
    2007-07-21 17:54 47,360 ----a-w C:\Users\Dempsey\AppData\Roaming\pcouffin.sys
    2006-11-02 12:50 174 --sha-w C:\Program Files\desktop.ini
    2007-12-16 15:44 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    2007-12-16 15:44 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    2007-12-16 15:44 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    .

    ------- Sigcheck -------

    .
    ((((((((((((((((((((((((((((( snapshot@2008-05-15_14.09.45.93 )))))))))))))))))))))))))))))))))))))))))
    .
    - 2008-05-15 12:02:50 67,584 --s-a-w C:\Windows\bootstat.dat
    + 2008-05-15 16:29:14 67,584 --s-a-w C:\Windows\bootstat.dat
    - 2008-05-15 11:46:38 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
    + 2008-05-15 15:57:23 262,144 ----a-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\UsrClass.dat
    - 2008-05-15 12:03:15 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
    + 2008-05-15 16:29:46 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
    + 2008-05-15 16:29:46 262,144 ---ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
    - 2008-05-15 11:57:06 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
    + 2008-05-15 16:21:56 262,144 ----a-w C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\UsrClass.dat
    - 2008-05-15 12:03:15 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
    + 2008-05-15 16:29:46 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
    + 2008-05-15 16:29:46 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
    - 2008-05-15 12:02:59 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    + 2008-05-15 16:30:49 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2008-05-15 12:02:59 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-05-15 16:30:49 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-05-15 12:02:59 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-05-15 16:30:49 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-05-15 15:53:19 126,016 ----a-w C:\Windows\System32\cxjjsukq.dll
    + 2008-05-15 14:56:08 133,184 ----a-w C:\Windows\System32\ifhhuvcb.dll
    - 2008-04-06 05:56:20 19,836,024 ----a-w C:\Windows\System32\MRT.exe
    + 2008-05-09 21:35:04 16,863,864 ----a-w C:\Windows\System32\MRT.exe
    - 2008-05-15 08:33:33 11,168 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-991961723-1612249020-4045812409-1000_UserData.bin
    + 2008-05-15 15:44:22 11,780 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-991961723-1612249020-4045812409-1000_UserData.bin
    - 2008-05-15 08:33:33 67,358 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2008-05-15 15:44:22 68,222 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    - 2008-05-15 08:33:31 49,026 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-05-15 15:44:20 49,854 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
    + 2008-05-15 14:28:09 133,120 ----a-w C:\Windows\System32\wfeqmolh.dll
    + 2008-05-15 14:23:01 125,952 ----a-w C:\Windows\System32\wykqbtja.dll
    .
    -- Snapshot reset to current date --
    .
    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    REGEDIT4
    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-09 13:49 1232896]
    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2008-01-13 00:42 5724184]
    "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 19:03 152872]
    "RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-09-02 14:58 495616]
    "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-06 11:02 98304]
    "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-06 11:05 106496]
    "Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-06 11:02 81920]
    "WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 09:56 317152]
    "hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 09:32 472800]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-06-28 05:17 959976]
    "WinPatrol"="C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe" [2007-04-19 19:33 271936]
    "Monitor"="C:\Windows\PixArt\PAC207\Monitor.exe" [2006-11-03 11:01 319488]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 03:06 40048]
    "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-02-14 23:15 185896]
    "!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 11:25 6731312]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "Launcher"="%WINDIR%\SMINST\launcher.exe" [ ]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
    VirtuaWin.lnk - C:\Program Files\VirtuaWin\VirtuaWin.exe [2008-03-10 23:11:31 121856]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableLUA"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.YV12"= yv12vfw.dll
    "msacm.ac3filter"= ac3filter.acm

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-991961723-1612249020-4045812409-1000]
    "EnableNotifications"=dword:00000001
    "EnableNotificationsRef"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{461D84E1-A19F-4016-9741-46504709B0B7}"= UDP:C:\Program Files\HP\QuickPlay\QP.exe:QP
    "{523EF620-4D94-46A4-81C3-EA992D6C3A66}"= TCP:C:\Program Files\HP\QuickPlay\QP.exe:QP
    "{538B1A3D-0712-4BC6-A606-DDD3426516B5}"= UDP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
    "{15EED3ED-E39D-4253-A7B4-8B84137A8EEE}"= TCP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
    "TCP Query User{3D9C1AE4-4315-476E-B2DD-16AD1510DC65}C:\\program files\\last.fm\\lastfm.exe"= UDP:C:\program files\last.fm\lastfm.exe:Last.fm
    "UDP Query User{D329045F-6BC6-4277-9F1B-35FBE348271F}C:\\program files\\last.fm\\lastfm.exe"= TCP:C:\program files\last.fm\lastfm.exe:Last.fm
    "{6FD0C1B1-5303-4B16-8283-77BE9C14A769}"= Disabled:UDP:C:\Program Files\Joost\xulrunner\tvprunner.exe:tvprunner
    "{B7B440BB-F89E-48A3-B88F-615323D284A6}"= Disabled:TCP:C:\Program Files\Joost\xulrunner\tvprunner.exe:tvprunner
    "{74E739DA-79E2-4B56-90AE-73AB88A7E82E}"= UDP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
    "{DA3CA175-AC82-44F2-8F29-7C2E5B193607}"= TCP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
    "{9890C3FB-845C-4BB0-8982-5AA4932FA81B}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
    "{9B7D3852-7637-4687-B2C8-EE50238B6090}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
    "{6FD06885-678E-4DE6-B41E-7833302AA5CF}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
    "{865D88D3-B268-4DE0-B03C-AE39C7B11A1A}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
    "{AD1E3837-4687-49AE-93AD-B9F014BA57CF}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
    "{310C7382-273D-46DF-8289-B325F1B1B0C6}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
    "{075BA41E-0634-44A8-BB5C-B3F779BF7041}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
    "{B43DAD72-3475-4C56-A8E9-692DA9575FC8}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
    "{B9480D58-D503-472F-A958-1B5EEED47E3E}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
    "{9A319038-FCAC-4F37-85F8-E50F117841BB}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
    "{B0B967F1-61EA-452C-A2BE-7DBABFBE2914}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
    "{966602AF-B6C8-4783-BF1E-B2A2E70085CB}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
    "{D8032A05-92E0-4FB6-97BD-67489C5993B6}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
    "{A604B406-9816-4B68-8054-0F5D213A0B61}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
    "{A059122A-9959-42ED-BAA0-ED032DBC86AD}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype
    "{28866874-21D6-4041-A404-6E25317EE898}"= Disabled:UDP:C:\Program Files\Skype\Phone\Skype.exe:Skype
    "{698A31D2-B242-4642-ABB5-904FEFC98F64}"= Disabled:TCP:C:\Program Files\Skype\Phone\Skype.exe:Skype

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
    "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall"= 0 (0x0)

    R1 aswSP;avast! Self Protection;C:\Windows\system32\drivers\aswSP.sys [2008-05-12 18:36]
    R2 aswFsBlk;aswFsBlk;C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-05-12 18:38]
    R2 aswMonFlt;aswMonFlt;C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-05-12 18:37]
    R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 19:39]
    R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-06 12:29]
    S3 BCM43XV;Pilote de la carte réseau extensible Broadcom 802.11;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-11-17 18:20]
    S3 MBAMCatchMe;MBAMCatchMe;C:\Windows\system32\drivers\mbamcatchme.sys [2008-05-05 20:46]
    S3 PAC207;SoC PC-Camera;C:\Windows\system32\DRIVERS\PFC027.SYS [2006-12-05 11:34]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{77a6e2ea-3641-11dc-8dcc-806e6f6e6963}]
    \shell\AutoRun\command - E:\autorun6e.exe

    .
    Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
    "2008-05-14 17:36:08 C:\Windows\Tasks\User_Feed_Synchronization-{4E236CEE-48BF-4C0E-98E4-B4E5D83FB0AD}.job"
    - C:\Windows\system32\msfeedssync.exe
    .
    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-05-15 18:30:07
    Windows 6.0.6000 NTFS

    Balayage processus cach‚s ...

    Balayage cach‚ autostart entries ...

    Balayage des fichiers cach‚s ...

    C:\Users\Dempsey\AppData\Roaming\Microsoft\Windows\Cookies\dempsey@live[1].txt

    Scan termin‚ avec succŠs
    Les fichiers cach‚s: 1

    **************************************************************************
    .
    --------------------- DLLs a charg‚ sous des processus courants ---------------------

    PROCESS: C:\Windows\Explorer.exe
    -> C:\Program Files\RocketDock\RocketDock.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\Windows\System32\audiodg.exe
    C:\Windows\System32\ZoneLabs\vsmon.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\System32\drivers\XAudio.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Windows\System32\WUDFHost.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\VirtuaWin\modules\VWAssigner.exe
    C:\Program Files\VirtuaWin\modules\WinList.exe
    C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Service.exe
    C:\Windows\System32\conime.exe
    C:\Windows\System32\igfxsrvc.exe
    C:\Windows\System32\dllhost.exe
    .
    **************************************************************************
    .
    Temps d'accomplissement: 2008-05-15 18:38:41 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-05-15 16:38:17
    ComboFix2.txt 2008-05-15 12:11:18

    Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
    Le texte du message associ‚ au num‚ro 0x2379 est introuvable dans le fichier de messages pour Application.

    260 --- E O F --- 2008-05-09 11:11:47

    ___________________________________ _____________________________________

    HIJACKTHIS

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 18:39:25, on 15/05/2008
    Platform: Windows Vista (WinNT 6.00.1904)
    MSIE: Internet Explorer v7.00 (7.00.6000.16643)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\igfxtray.exe
    C:\Windows\System32\hkcmd.exe
    C:\Windows\System32\igfxpers.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
    C:\Windows\PixArt\Pac207\Monitor.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Windows\ehome\ehtray.exe
    C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files\RocketDock\RocketDock.exe
    C:\Program Files\VirtuaWin\VirtuaWin.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\VirtuaWin\modules\VWAssigner.exe
    C:\Program Files\VirtuaWin\modules\WinList.exe
    C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Windows\system32\conime.exe
    C:\Windows\Explorer.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Program Files\Trend Micro\HijackThis\Eden.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=https%3A%2F%2Fmail.google.com%2Fmail%2F%3Fnsr%3D1%26ui%3Dhtml%26zy%3Dl&ltmpl=default&ltmplcache=2
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-notebook.msn.com&ocid=HPDHP&pc=CPNTDF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
    O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe
    O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Global Startup: VirtuaWin.lnk = C:\Program Files\VirtuaWin\VirtuaWin.exe
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
    O13 - Gopher Prefix:
    O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - https://about.proquest.com/products-services/ebooks/ebooks-main.html
    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Unknown owner - C:\Program Files\Roxio\Roxio MyDVD Basic v9\InstallShield\Driver\1050\Intel 32\IDriverT.exe (file missing)
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    0
  11. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok parfait on tient le bon bout

    pour finir je pense alanlyse ces ficheirs sur virus total et si inféctés tu les mets dans otmovit pour les virer:

    https://www.virustotal.com/gui/

    C:\Windows\System32\cxjjsukq.dll
    C:\Windows\System32\ifhhuvcb.dll
    C:\Windows\System32\wfeqmolh.dll
    C:\Windows\System32\wykqbtja.dll

    __________________

    télécharge OTMoveIt
    http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe (de Old_Timer) sur ton Bureau. Ou sur https://www.luanagames.com/index.fr.html
    double-clique sur OTMoveIt.exe pour le lancer.
    copie la liste qui se trouve en citation ci-dessous,
    et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

    Citation :

    clique sur MoveIt! pour lancer la suppression.
    le résultat apparaitra dans le cadre "Results".
    clique sur Exit pour fermer.
    poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

    il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

    __________________

    vire ce qui est dans MOVED FILES en allant dans POSTE DE TRAVAIL puis C puis OTMOVIT
    0
  12. dmc
     
    Voici le rapport de OtmoveIt

    Veux tu un bilan de combofix?? hijackthis???

    DllUnregisterServer procedure not found in C:\Windows\System32\cxjjsukq.dll
    C:\Windows\System32\cxjjsukq.dll NOT unregistered.
    C:\Windows\System32\cxjjsukq.dll moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\System32\ifhhuvcb.dll
    C:\Windows\System32\ifhhuvcb.dll NOT unregistered.
    C:\Windows\System32\ifhhuvcb.dll moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\System32\wfeqmolh.dll
    C:\Windows\System32\wfeqmolh.dll NOT unregistered.
    C:\Windows\System32\wfeqmolh.dll moved successfully.
    DllUnregisterServer procedure not found in C:\Windows\System32\wykqbtja.dll
    C:\Windows\System32\wykqbtja.dll NOT unregistered.
    C:\Windows\System32\wykqbtja.dll moved successfully.

    OTMoveIt2 by OldTimer - Version 1.0.4.1 log created on 05152008_215148
    0
  13. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    vire ce qui est dans MOVED FILES en allant dans POSTE DE TRAVAIL puis C puis OTMOVIT

    ______

    pour virer les logiciels de desinfection utilisés:

    Télécharge ToolsCleaner sur ton bureau.
    --> https://www.commentcamarche.net/telecharger/ 34055291 toolsclean(...)
    # Clique sur Recherche et laisse le scan agir ...
    # Clique sur Suppression pour finaliser.
    # Tu peux, si tu le souhaites, te servir des Options facultatives.
    # Clique sur Quitter pour obtenir le rapport.
    # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

    ps : pas besoin de m´envoyer le rapport si tout a ete supprimer ;-)

    __________

    voilà c'est fini

    bonne continuation
    0
  14. dmc
     
    Presque tout est supprimé!! Il y a un résistant :

    -->- Recherche:

    C:\Combofix: trouvé !
    C:\Qoobox: trouvé !
    C:\Program Files\Trend Micro\HijackThis: trouvé !
    C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\HijackThis: trouvé !
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis: trouvé !
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: trouvé !
    C:\Users\Dempsey\Downloads\HJTInstall.exe: trouvé !

    ---------------------------------
    -->- Suppression:

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis\HijackThis.lnk: supprimé !
    C:\Users\Dempsey\Downloads\HJTInstall.exe: supprimé !
    C:\Combofix: supprimé !
    C:\Qoobox: supprimé !
    C:\Program Files\Trend Micro\HijackThis: supprimé !
    C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\HijackThis: ERREUR DE SUPPRESSION !!
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HijackThis: supprimé !
    0
  15. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    vire alors manuellement hijakthis de ton ordinateur

    voilà bonne suite!
    0