Ynbxsfwb .dll

Packito77 -  
jlpjlp Messages postés 52399 Statut Contributeur sécurité -
Emplacement du fichier : c:\windows\system32\ynbxsfwb .dll

Bonjour,

Voila je viens de résoudre un problème de ralentissement de mon pc en virant ce fichier sous windows en mode sans échec.

Je l'ai fait analyser par https://www.virustotal.com/gui/ ce qui ma donné el résultat suivant :

Antivirus
AntiVir 7.8.0.19 2008.05.23 TR/Vundo.Gen
Avast 4.8.1195.0 2008.05.22 Win32:Zapchast-FO
AVG 7.5.0.516 2008.05.22 Vundo.R
eSafe 7.0.15.0 2008.05.22 Suspicious File
eTrust-Vet 31.4.5814 2008.05.22 Win32/Vundo!generic
F-Secure 6.70.13260.0 2008.05.23 Vundo.gen176
FoGData 2.0.7306.1023 2008.05.23 Win32:Zapchast-FO
Ikarus T3.1.1.26.0 2008.05.23 Win32.Rigel.6468
McAfee 5301 2008.05.22 Vundo.gen.c
Microsoft 1.3520 2008.05.23 Trojan:Win32/Vundo.HIT
Norman 5.80.02 2008.05.22 Vundo.gen176
Prevx1 V2 2008.05.23 Cloaked Malware
Sophos 4.29.0 2008.05.23 Troj/Virtum-Gen
Webwasher-Gateway 6.6.2 2008.05.23 Trojan.Vundo.Gen

Information additionnelle
File size: 99904 bytes
MD5...: ada5a5372acd1a35f34f224a43038828
SHA1..: a4295cab05742d2185dedd45d52bc0af1102bad7
SHA256: 82b1930725c13ea838354d7661cf746899704cc6a820223ac61a3e398094a8ca
SHA512: 538e182abf4cacbcae2b251d5383f9e70c431d8eaff1a631cd768e675740222f
f3837ca13243fd4f37fc6facbf5ed57e55389a729cd9dad339cdf855e699ca06
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x10006556
timedatestamp.....: 0xf5ffd962L (invalid)
machinetype.......: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x1a000 0x5a00 7.79 38d626febf23dde99cf65dae5f91993c
.data 0x1b000 0x12000 0x12000 7.99 269dadaa6eed5fd21ce7c0bbf4b9756a
.rdata 0x2d000 0x1000 0x400 7.18 43d246f68686024c34424fa992380b45
.idata 0x2e000 0x1000 0x400 2.00 4af752df086f1adab3670566504af97f

( 1 imports )
> kernel32.dll: EnterCriticalSection, ExitProcess, FreeResource, InitializeCriticalSection, LeaveCriticalSection, LocalAlloc, OpenFile, ReadFile, SetEndOfFile, lstrcpynA, lstrlenA

( 0 exports )

Prevx info: http://info.prevx.com/aboutprogramtext.asp?PX5=B97B2E1A407FB29A8679010EDFE41200E0E45D0D

Voila en gros ce fichier est virussé à mort je ne vous ai mis que les antivirus le détectant.

Ce que j'aimerai savoir c'est :
- si plusieurs virus se sont logé dans ce fichier ou si c'est un virus que les logiciels ont du mal à identifier ?
et
- à quoi sert ce fichier ?

Merci par avance pour vos réponses :)
Configuration: Windows Vista
Internet Explorer 7.0

9 réponses

  1. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    slt,

    Téléchargez VundoFix -> http://www.atribune.org/ccount/click.php?id=4

    Double cliquez VundoFix.exe pour l'exécuter.
    Quand VundoFix s'ouvre, cliquez sur le bouton Scan for Vundo.
    Une fois le scan fini, cliquez sur le bouton Remove Vundo.
    Vous recevrez un avertissement vous demandant si vous voulez effacer ces
    fichiers répondez en cliquant sur YES
    Une fois que vous avez cliqué yes, votre bureau deviendra vide au moment où il
    enlève Vundo.

    Quand c'est fini, il vous sera demandé de redémarrer votre ordinateur, cliquez OK.
    _________________
    Ensuite

    Virtumondebegone
    http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

    ____________

    colle un rapport hijackthis

    http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

    manuel :
    http://pagesperso-orange.fr/rginformatique/section%20virus/demohijack.htm
    https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

    Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

    ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

    Ensuite avec Explorer créer un dossier c:\hijackthis
    Décompresser Hijackthis dans ce dossier.
    C'est important pour les sauvegardes."

    et

    Télécharge combofix.exe (par sUBs) sur ton Bureau.

    -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    -> Double clique combofix.exe.
    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
    0
    1. Packito77
       
      [05/23/2008, 17:04:41] - VirtumundoBeGone v1.5 ( "F:\Temp net\Fichiers Internet temporaires\Content.IE5\IUFAIPN6\VirtumundoBeGone[1].exe" )
      [05/23/2008, 17:04:43] - Detected System Information:
      [05/23/2008, 17:04:43] - Windows Version: 6.0.6000,
      [05/23/2008, 17:04:43] - Current Username: Seb (Admin)
      [05/23/2008, 17:04:43] - Windows is in NORMAL mode.
      [05/23/2008, 17:04:43] - Searching for Browser Helper Objects:
      [05/23/2008, 17:04:43] - BHO 1: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
      [05/23/2008, 17:04:43] - Finished Searching Browser Helper Objects
      [05/23/2008, 17:04:43] - Finishing up...
      [05/23/2008, 17:04:43] - Nothing found! Exiting...




      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:05:33, on 23/05/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16643)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\conime.exe
      C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
      D:\Programmes\ZoneAlarm\zlclient.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\ehome\ehmsas.exe
      D:\Programmes\Clavier et souris logitech\SetPoint\SetPoint.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
      C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
      C:\Windows\Explorer.exe
      C:\Windows\system32\notepad.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\SearchFilterHost.exe
      D:\Programmes\Jaquou.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
      O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Programmes\ZoneAlarm\zlclient.exe"
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
      O4 - Startup: Cookies Manager.lnk = D:\Programmes\Cookies manager\Cookies Manager.exe
      O4 - Global Startup: Logitech SetPoint.lnk = ?
      O8 - Extra context menu item: Convertir en Adobe PDF - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir en un fichier PDF existant - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\Office\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Programmes\WinHTTrack\WinHTTrackIEBar.dll
      O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Programmes\WinHTTrack\WinHTTrackIEBar.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Office\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
      O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
      O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
      O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: NBService - Nero AG - D:\Programmes\Néro\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - D:\Programmes\Alcohol 120\StarWind\StarWindServiceAE.exe (file missing)
      O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
      0
    2. Packito77
       
      merci pour ton coup de main :)

      j'ai fais tout ce que tu m'as dis apparement vundo était sur un autre logiciel (poweriso) que j'ai désisntalé par la même occasion

      pis aprés j'ai fais le reste de la procédure que tuy demandais ça a apparement viré pas mal de trucs infectés merci ça va soulager ma machine :)
      0
  2. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    tu as quel antivirus
    0
    1. Packito77
       
      au moment du scan aucun je venais de désinstaler AVG car je pensais avoir un soucis de ralentissement à cause de lui
      0
  3. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    ok

    tu peux virer combofix, virtubeogone, vundofix

    tout a l'air ok pour verifier scan avec un antivirus (antivir par exemple) et un antiespion comme tu n'avais aucune protection (malwarebytes)
    ____________

    installe spywareblaster
    pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

    https://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/28872.html

    _____________

    scan avec
    MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    ______________

    je te conseille antivir comme antivirus , colle moi le rapport

    https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)

    pour protéger gratos ton ordi

    http://www.commentcamarche.net/telecharger/logiciel 4 securite

    mettre un antivirus

    AVAST en français ou ANTIVIR (en anglais mais très efficace)
    https://www.malekal.com/avira-free-security-antivirus-gratuit/ (merci Malekal)
    -------------
    des anti-espions :
    MalwareByte's Anti-Malware + SPYBOT +/- si tea timer non active de spybot:
    WINDOWS DEFENDER ou SPYWARE TERMINATOR

    +
    SPYWAREBLASTER pour immuniser le système contre vundo notamment mais en anglais (mais facile d'utilisation : il suffit de faire "update" pour mettre à jour tous les mois et ensuite" enable all protection" pour immuniser)...

    Rq : spybot et ad-aware ont sorti de nouvelles versions cette année vérifiez que vous avez la dernière version
    --------
    un pare feu :
    celui de (Windows) ou mieux Online armor ou KERIO ou JETICO ou ZONE ALARM (mettre que le parefeu gratuit)

    http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

    https://forum.pcastuces.com/sujet.asp?f=25&s=35606
    https://www.clubic.com/telecharger-fiche11071-sunbelt-personal-firewall-ex-kerio.html
    https://manuelsdaide.com/contact/
    http://www.open-files.com/forum/index.php?showtopic=29277
    http://www.commentcamarche.net/telecharger/telecharger 157 zonealarm

    -----------
    CCLEANER pour effacer les traces de surf
    ---------
    naviguer avec firefox ou safari ou opera et non internet explorer plus touché par les virus
    http://www.mozilla-europe.org/fr/products/firefox/
    0
    1. Packito77
       
      merci encore et toujours pour ton aide ;)

      voila le rapport d'antivir :

      Scanning for 1286440 virus strains and unwanted programs.

      Licensed to: Avira AntiVir PersonalEdition Classic
      Serial number: 0000149996-ADJIE-0001
      Platform: Windows Vista
      Windows version: (plain) [6.0.6000]
      Boot mode: Normally booted
      Username: SYSTEM
      Computer name: PACKITO

      Version information:
      BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
      AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
      AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
      LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
      LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
      ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
      ANTIVIR2.VDF : 7.0.4.53 1848832 Bytes 17/05/2008 16:27:18
      ANTIVIR3.VDF : 7.0.4.86 158720 Bytes 24/05/2008 16:27:18
      Engineversion : 8.1.0.46
      AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
      AESCRIPT.DLL : 8.1.0.33 266618 Bytes 24/05/2008 16:27:24
      AESCN.DLL : 8.1.0.18 119156 Bytes 24/05/2008 16:27:24
      AERDL.DLL : 8.1.0.20 418165 Bytes 24/05/2008 16:27:23
      AEPACK.DLL : 8.1.1.5 364918 Bytes 24/05/2008 16:27:23
      AEOFFICE.DLL : 8.1.0.18 192890 Bytes 24/05/2008 16:27:22
      AEHEUR.DLL : 8.1.0.29 1253750 Bytes 24/05/2008 16:27:22
      AEHELP.DLL : 8.1.0.14 115063 Bytes 24/05/2008 16:27:21
      AEGEN.DLL : 8.1.0.21 303477 Bytes 24/05/2008 16:27:20
      AEEMU.DLL : 8.1.0.6 430451 Bytes 24/05/2008 16:27:20
      AECORE.DLL : 8.1.0.29 168311 Bytes 24/05/2008 16:27:19
      AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
      AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
      AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
      AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
      AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
      SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
      SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
      NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
      RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
      RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11

      Configuration settings for the scan:
      Jobname..........................: Complete system scan
      Configuration file...............: d:\programmes\avira\antivir personaledition classic\sysscan.avp
      Logging..........................: low
      Primary action...................: interactive
      Secondary action.................: ignore
      Scan master boot sector..........: on
      Scan boot sector.................: on
      Boot sectors.....................: C:, D:, F:,
      Scan memory......................: on
      Process scan.....................: on
      Scan registry....................: on
      Search for rootkits..............: off
      Scan all files...................: Intelligent file selection
      Scan archives....................: on
      Recursion depth..................: 20
      Smart extensions.................: on
      Macro heuristic..................: on
      File heuristic...................: high

      Start of the scan: samedi 24 mai 2008 18:28

      The scan of running processes will be started
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Scan process 'spywareblaster.exe' - '1' Module(s) have been scanned
      Scan process 'spywareblaster.exe' - '1' Module(s) have been scanned
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'VSSVC.exe' - '1' Module(s) have been scanned
      Scan process 'iexplore.exe' - '1' Module(s) have been scanned
      Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
      Scan process 'LVComSX.exe' - '1' Module(s) have been scanned
      Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
      Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
      Scan process 'KHALMNPR.exe' - '1' Module(s) have been scanned
      Scan process 'SetPoint.exe' - '1' Module(s) have been scanned
      Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
      Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
      Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
      Scan process 'ehtray.exe' - '1' Module(s) have been scanned
      Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
      Scan process 'zlclient.exe' - '0' Module(s) have been scanned
      Scan process 'Communications_Helper.exe' - '1' Module(s) have been scanned
      Scan process 'explorer.exe' - '1' Module(s) have been scanned
      Scan process 'taskeng.exe' - '1' Module(s) have been scanned
      Scan process 'dwm.exe' - '1' Module(s) have been scanned
      Scan process 'taskeng.exe' - '1' Module(s) have been scanned
      Scan process 'alg.exe' - '1' Module(s) have been scanned
      Scan process 'WUDFHost.exe' - '1' Module(s) have been scanned
      Scan process 'eRecoveryService.exe' - '1' Module(s) have been scanned
      Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'MemCheck.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
      Scan process 'vsmon.exe' - '0' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
      Scan process 'audiodg.exe' - '0' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'lsm.exe' - '1' Module(s) have been scanned
      Scan process 'lsass.exe' - '1' Module(s) have been scanned
      Scan process 'services.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'wininit.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'smss.exe' - '1' Module(s) have been scanned
      57 processes with 57 modules were scanned

      Starting master boot sector scan:
      Master boot sector HD0
      [INFO] No virus was found!
      Master boot sector HD1
      [INFO] No virus was found!
      [WARNING] Le périphérique n'est pas prêt.
      [INFO] Please restart the search with Administrator rights
      Master boot sector HD2
      [INFO] No virus was found!
      [WARNING] Le périphérique n'est pas prêt.
      [INFO] Please restart the search with Administrator rights
      Master boot sector HD3
      [INFO] No virus was found!
      [WARNING] Le périphérique n'est pas prêt.
      [INFO] Please restart the search with Administrator rights
      Master boot sector HD4
      [INFO] No virus was found!
      [WARNING] Le périphérique n'est pas prêt.
      [INFO] Please restart the search with Administrator rights

      Start scanning boot sectors:
      Boot sector 'C:\'
      [INFO] No virus was found!
      Boot sector 'D:\'
      [INFO] No virus was found!
      Boot sector 'F:\'
      [INFO] No virus was found!

      Starting to scan the registry.
      The registry was scanned ( '6' files ).


      Starting the file scan:

      Begin scan in 'C:\' <Système>
      C:\hiberfil.sys
      [WARNING] The file could not be opened!
      C:\pagefile.sys
      [WARNING] The file could not be opened!
      C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
      [0] Archive type: RSRC
      --> Object
      [DETECTION] Contains detection pattern of the worm WORM/Pykse.M.1
      [NOTE] The file was deleted!
      C:\Program Files\Dot1XCfg\Dot1XCfg.exe.vir
      [DETECTION] Is the Trojan horse TR/Dldr.Adload.PR
      [NOTE] The file was deleted!
      C:\Program Files\MSN Messenger\msntemp\Temps msn.exe
      [DETECTION] Contains suspicious code HEUR/Malware
      [NOTE] The fund was classified as suspicious.
      [NOTE] The file was moved to '48a543f5.qua'!
      C:\QooBox\Quarantine\C\Windows\System32\arhcvoov.dll.vir
      [DETECTION] Is the Trojan horse TR/Vundo.Gen
      [NOTE] The file was deleted!
      C:\QooBox\Quarantine\C\Windows\System32\dsglmehn.dll.vir
      [DETECTION] Is the Trojan horse TR/Vundo.Gen
      [NOTE] The file was deleted!
      C:\Users\Seb\AppData\Roaming\Microsoft\Windows\rayiou.exe.vir
      [DETECTION] Is the Trojan horse TR/Dldr.Agent.cgd.2
      [NOTE] The file was deleted!
      C:\Windows\System32\drivers\sptd.sys
      [WARNING] The file could not be opened!
      Begin scan in 'D:\' <DATA>
      D:\Programmes\backups\backup-20080521-154852-910.dll
      [DETECTION] Is the Trojan horse TR/Vundo.Gen
      [NOTE] The file was deleted!
      Begin scan in 'F:\' <Temporaire>


      End of the scan: samedi 24 mai 2008 19:16
      Used time: 47:23 min

      The scan has been done completely.

      17742 Scanning directories
      437701 Files were scanned
      6 viruses and/or unwanted programs were found
      1 Files were classified as suspicious:
      6 files were deleted
      0 files were repaired
      1 files were moved to quarantine
      0 files were renamed
      3 Files cannot be scanned
      437695 Files not concerned
      2906 Archives were scanned
      7 Warnings
      7 Notes
      0
  4. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    vire ce qui et dans le dossier quarantine en allant dans poste de travail puis

    C:\QooBox\Quarantine

    ____________

    vire ce qui et dans le dossier backups en allant dans poste de travail puis

    D:\Programmes\backups

    ______________

    vire ce qui est en quarantaine dans antivir et recolle un rapport avec antivir et dis tes soucis atuels
    0
    1. Packito77
       
      Voila le rapport antivir



      Avira AntiVir Personal
      Report file date: dimanche 25 mai 2008 18:25

      Scanning for 1286436 virus strains and unwanted programs.

      Licensed to: Avira AntiVir PersonalEdition Classic
      Serial number: 0000149996-ADJIE-0001
      Platform: Windows Vista
      Windows version: (plain) [6.0.6000]
      Boot mode: Normally booted
      Username: Seb
      Computer name: PACKITO

      Version information:
      BUILD.DAT : 8.1.00.295 16479 Bytes 09/04/2008 16:24:00
      AVSCAN.EXE : 8.1.2.12 311553 Bytes 18/03/2008 09:02:56
      AVSCAN.DLL : 8.1.1.0 53505 Bytes 07/02/2008 08:43:37
      LUKE.DLL : 8.1.2.9 151809 Bytes 28/02/2008 08:41:23
      LUKERES.DLL : 8.1.2.1 12033 Bytes 21/02/2008 08:28:40
      ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
      ANTIVIR1.VDF : 7.0.3.2 5447168 Bytes 07/03/2008 13:08:58
      ANTIVIR2.VDF : 7.0.4.53 1848832 Bytes 17/05/2008 16:27:18
      ANTIVIR3.VDF : 7.0.4.88 158720 Bytes 25/05/2008 16:19:50
      Engineversion : 8.1.0.46
      AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:21
      AESCRIPT.DLL : 8.1.0.33 266618 Bytes 24/05/2008 16:27:24
      AESCN.DLL : 8.1.0.18 119156 Bytes 24/05/2008 16:27:24
      AERDL.DLL : 8.1.0.20 418165 Bytes 24/05/2008 16:27:23
      AEPACK.DLL : 8.1.1.5 364918 Bytes 24/05/2008 16:27:23
      AEOFFICE.DLL : 8.1.0.18 192890 Bytes 24/05/2008 16:27:22
      AEHEUR.DLL : 8.1.0.29 1253750 Bytes 24/05/2008 16:27:22
      AEHELP.DLL : 8.1.0.14 115063 Bytes 24/05/2008 16:27:21
      AEGEN.DLL : 8.1.0.21 303477 Bytes 24/05/2008 16:27:20
      AEEMU.DLL : 8.1.0.6 430451 Bytes 24/05/2008 16:27:20
      AECORE.DLL : 8.1.0.29 168311 Bytes 24/05/2008 16:27:19
      AVWINLL.DLL : 1.0.0.7 14593 Bytes 23/01/2008 17:07:53
      AVPREF.DLL : 8.0.0.1 25857 Bytes 18/02/2008 10:37:50
      AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:26:47
      AVREG.DLL : 8.0.0.0 30977 Bytes 23/01/2008 17:07:49
      AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
      AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 28/02/2008 08:31:31
      SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
      SMTPLIB.DLL : 1.2.0.19 28929 Bytes 23/01/2008 17:08:39
      NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
      RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 10/03/2008 14:37:25
      RCTEXT.DLL : 8.0.32.0 86273 Bytes 06/03/2008 12:02:11

      Configuration settings for the scan:
      Jobname..........................: Local Drives
      Configuration file...............: D:\Programmes\Avira\AntiVir PersonalEdition Classic\alldrives.avp
      Logging..........................: low
      Primary action...................: interactive
      Secondary action.................: ignore
      Scan master boot sector..........: on
      Scan boot sector.................: on
      Boot sectors.....................: C:, D:, F:, H:, I:, J:, K:, E:, G:, L:,
      Scan memory......................: on
      Process scan.....................: on
      Scan registry....................: on
      Search for rootkits..............: off
      Scan all files...................: All files
      Scan archives....................: on
      Recursion depth..................: 20
      Smart extensions.................: on
      Macro heuristic..................: on
      File heuristic...................: high

      Start of the scan: dimanche 25 mai 2008 18:25

      The scan of running processes will be started
      Scan process 'avscan.exe' - '1' Module(s) have been scanned
      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
      Scan process 'taskeng.exe' - '1' Module(s) have been scanned
      Scan process 'iexplore.exe' - '1' Module(s) have been scanned
      Scan process 'mobsync.exe' - '1' Module(s) have been scanned
      Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
      Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
      Scan process 'unsecapp.exe' - '1' Module(s) have been scanned
      Scan process 'NclMSBTSrv.exe' - '1' Module(s) have been scanned
      Scan process 'NclRSSrv.exe' - '1' Module(s) have been scanned
      Scan process 'NclUSBSrv.exe' - '1' Module(s) have been scanned
      Scan process 'ServiceLayer.exe' - '1' Module(s) have been scanned
      Scan process 'alg.exe' - '1' Module(s) have been scanned
      Scan process 'LVComSX.exe' - '1' Module(s) have been scanned
      Scan process 'taskeng.exe' - '1' Module(s) have been scanned
      Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
      Scan process 'WmiPrvSE.exe' - '1' Module(s) have been scanned
      Scan process 'WUDFHost.exe' - '1' Module(s) have been scanned
      Scan process 'eRecoveryService.exe' - '1' Module(s) have been scanned
      Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'RichVideo.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'LSSrvc.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'avguard.exe' - '1' Module(s) have been scanned
      Scan process 'MemCheck.exe' - '1' Module(s) have been scanned
      Scan process 'KHALMNPR.exe' - '1' Module(s) have been scanned
      Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
      Scan process 'SetPoint.exe' - '1' Module(s) have been scanned
      Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
      Scan process 'ehtray.exe' - '1' Module(s) have been scanned
      Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
      Scan process 'zlclient.exe' - '0' Module(s) have been scanned
      Scan process 'Communications_Helper.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'sched.exe' - '1' Module(s) have been scanned
      Scan process 'taskeng.exe' - '1' Module(s) have been scanned
      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
      Scan process 'explorer.exe' - '1' Module(s) have been scanned
      Scan process 'dwm.exe' - '1' Module(s) have been scanned
      Scan process 'vsmon.exe' - '0' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
      Scan process 'audiodg.exe' - '0' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'svchost.exe' - '1' Module(s) have been scanned
      Scan process 'lsm.exe' - '1' Module(s) have been scanned
      Scan process 'lsass.exe' - '1' Module(s) have been scanned
      Scan process 'services.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'wininit.exe' - '1' Module(s) have been scanned
      Scan process 'csrss.exe' - '1' Module(s) have been scanned
      Scan process 'smss.exe' - '1' Module(s) have been scanned
      60 processes with 60 modules were scanned

      Starting master boot sector scan:
      Master boot sector HD0
      [INFO] No virus was found!
      Master boot sector HD1
      [INFO] No virus was found!
      [WARNING] Le périphérique n'est pas prêt.
      [INFO] Please restart the search with Administrator rights
      Master boot sector HD2
      [INFO] No virus was found!
      [WARNING] Le périphérique n'est pas prêt.
      [INFO] Please restart the search with Administrator rights
      Master boot sector HD3
      [INFO] No virus was found!
      [WARNING] Le périphérique n'est pas prêt.
      [INFO] Please restart the search with Administrator rights
      Master boot sector HD4
      [INFO] No virus was found!
      [WARNING] Le périphérique n'est pas prêt.
      [INFO] Please restart the search with Administrator rights

      Start scanning boot sectors:
      Boot sector 'C:\'
      [INFO] No virus was found!
      Boot sector 'D:\'
      [INFO] No virus was found!
      Boot sector 'F:\'
      [INFO] No virus was found!
      Boot sector 'H:\'
      [INFO] In the drive 'H:\' no data medium is inserted!
      Boot sector 'I:\'
      [INFO] In the drive 'I:\' no data medium is inserted!
      Boot sector 'J:\'
      [INFO] In the drive 'J:\' no data medium is inserted!
      Boot sector 'K:\'
      [INFO] In the drive 'K:\' no data medium is inserted!

      Starting to scan the registry.
      The registry was scanned ( '12' files ).


      Starting the file scan:

      Begin scan in 'C:\' <Système>
      C:\hiberfil.sys
      [WARNING] The file could not be opened!
      C:\pagefile.sys
      [WARNING] The file could not be opened!
      C:\Windows\System32\drivers\sptd.sys
      [WARNING] The file could not be opened!
      Begin scan in 'D:\' <DATA>
      Begin scan in 'F:\' <Temporaire>
      Begin scan in 'H:\'
      Search path H:\ could not be opened!
      Le périphérique n'est pas prêt.

      Begin scan in 'I:\'
      Search path I:\ could not be opened!
      Le périphérique n'est pas prêt.

      Begin scan in 'J:\'
      Search path J:\ could not be opened!
      Le périphérique n'est pas prêt.

      Begin scan in 'K:\'
      Search path K:\ could not be opened!
      Le périphérique n'est pas prêt.

      Begin scan in 'E:\'
      Search path E:\ could not be opened!
      Le périphérique n'est pas prêt.

      Begin scan in 'G:\'
      Search path G:\ could not be opened!
      Le périphérique n'est pas prêt.

      Begin scan in 'L:\'
      Search path L:\ could not be opened!
      Le périphérique n'est pas prêt.



      End of the scan: dimanche 25 mai 2008 19:25
      Used time: 1:00:34 min

      The scan has been done completely.

      17724 Scanning directories
      435569 Files were scanned
      0 viruses and/or unwanted programs were found
      0 Files were classified as suspicious:
      0 files were deleted
      0 files were repaired
      0 files were moved to quarantine
      0 files were renamed
      3 Files cannot be scanned
      435569 Files not concerned
      2860 Archives were scanned
      7 Warnings
      0 Notes




      Je n'ai plsu trop de problème maintenant hormis une certaine lenteur voir impossibilité (par momment) d'ouvrir une page web avec internet explorer ou firfox...

      Voila en tout cas merci pour ton aide j'espère ne plus avoir de soucis maintenant
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    scan avec
    MalwareByte's Anti-Malware et vire ce qui est trouvé et colle le rapport

    https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

    _____________

    Fais un clic droit sur ce lien : (IL-MAFIOSO)
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)
    0
    1. Packito77
       
      Search Navipromo version 3.5.7 commencé le 25/05/2008 à 23:29:04,15

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "Seb"

      Mise à jour le 11.05.2008 à 18h00 par IL-MAFIOSO

      Microsoft Windows Vista 6.0.6000
      Internet Explorer : 7.0.6000.16643
      Système de fichiers : NTFS

      Recherche executé en mode normal

      *** Recherche Programmes installés ***


      *** Recherche dossiers dans "C:\Windows" ***


      *** Recherche dossiers dans "C:\Program Files" ***


      *** Recherche dossiers dans "C:\ProgramData" ***


      *** Recherche dossiers dans "c:\progra~2\micros~1\windows\startm~1\programs" ***


      *** Recherche dossiers dans "c:\users\seb\appdata\roaming\micros~1\windows\startm~1\programs" ***


      *** Recherche dossiers dans "C:\Users\Seb\AppData\Local\virtualstore\Program Files" ***


      *** Recherche dossiers dans "C:\Users\Seb\AppData\Roaming" ***

      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net

      Aucun Fichier trouvé


      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans "C:\Windows\system32" *

      * Recherche dans "C:\Users\Seb\AppData\Local\Microsoft" *

      * Recherche dans "C:\Users\Seb\AppData\Local\virtualstore\windows\system32" *

      * Recherche dans "C:\Users\Seb\AppData\Local" *



      *** Recherche fichiers ***



      *** Recherche clés spécifiques dans le Registre ***


      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :


      2)Recherche Heuristique :

      * Dans "C:\Windows\system32" :


      * Dans "C:\Users\Seb\AppData\Local\Microsoft" :


      * Dans "C:\Users\Seb\AppData\Local\virtualstore\windows\system32" :


      * Dans "C:\Users\Seb\AppData\Local" :


      3)Recherche Certificats :

      Certificat Egroup absent !
      Certificat Electronic-Group absent !
      Certificat OOO-Favorit absent !
      Certificat Sunny-Day-Design-Ltd absent !

      4)Recherche fichiers connus :



      *** Analyse terminée le 25/05/2008 à 23:35:38,94 ***
      0
  7. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    non rien !

    désinstalle via ton panneau de configuration navilog (AJOUT/SUPPRESSION DE PROGRAMME)

    recolle un hijakchits pour verifier

    et un rapport combofix
    0
    1. Packito77
       
      voila voila comme tu me l'as demandé :) dslé pour le retard j'ai bossé toute la nuit :p
      encore merci pour ton aide :D


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 09:02:17, on 27/05/2008
      Platform: Windows Vista (WinNT 6.00.1904)
      MSIE: Internet Explorer v7.00 (7.00.6000.16643)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\Dwm.exe
      C:\Windows\system32\taskeng.exe
      C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
      D:\Programmes\ZoneAlarm\zlclient.exe
      D:\Programmes\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Windows\ehome\ehtray.exe
      C:\Program Files\Windows Media Player\wmpnscfg.exe
      C:\Windows\ehome\ehmsas.exe
      D:\Programmes\Clavier et souris logitech\SetPoint\SetPoint.exe
      C:\Windows\system32\wbem\unsecapp.exe
      C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
      C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
      C:\Program Files\PC Connectivity Solution\Transports\NclMSBTSrv.exe
      C:\Windows\system32\conime.exe
      C:\Windows\system32\SearchFilterHost.exe
      C:\Windows\Explorer.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      D:\Programmes\Jaquou.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
      O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
      O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [ZoneAlarm Client] "D:\Programmes\ZoneAlarm\zlclient.exe"
      O4 - HKLM\..\Run: [avgnt] "D:\Programmes\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 6\PCSuite.exe" -onlytray
      O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
      O4 - Startup: Cookies Manager.lnk = D:\Programmes\Cookies manager\Cookies Manager.exe
      O4 - Global Startup: Logitech SetPoint.lnk = ?
      O8 - Extra context menu item: Convertir en Adobe PDF - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir en un fichier PDF existant - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir la cible du lien en Adobe PDF - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la cible du lien en un fichier PDF existant - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir la sélection en Adobe PDF - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
      O8 - Extra context menu item: Convertir la sélection en un fichier PDF existant - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
      O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: Convertir les liens sélectionnés en un fichier PDF existant - res://D:\Programmes\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://D:\PROGRA~1\Office\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Programmes\WinHTTrack\WinHTTrackIEBar.dll
      O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - D:\Programmes\WinHTTrack\WinHTTrackIEBar.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\Office\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/VistaMSNPUpldfr-fr.cab
      O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
      O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
      O23 - Service: ePerformance Service (AcerMemUsageCheckService) - Unknown owner - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
      O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - D:\Programmes\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - D:\Programmes\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: NBService - Nero AG - D:\Programmes\Néro\Nero 7\Nero BackItUp\NBService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
      O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
      O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - D:\Programmes\Alcohol 120\StarWind\StarWindServiceAE.exe (file missing)
      O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe
      0
  8. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    colle le rapport d'un scan en ligne
    avec un des suivants:

    bitdefender en ligne :
    http://www.bitdefender.fr/scan_fr/scan8/ie.html

    Panda en ligne :
    http://pandasoftware.fr
    0
    1. Packito77
       
      BitDefender Online Scanner - Rapport virus en temps réel

      Généré à: Tue, May 27, 2008 - 18:49:12


      --------------------------------------------------------------------------------
      Info d'analyse

      Fichiers scannés
      97233

      Infectés Fichiers
      0

      Virus Détectés
      Aucun virus trouvé.

      --------------------------------------------------------------------------------

      Ce sommaire du processus d'analyse sera utilisé par les laboratoires Antivirus BitDefender pour créer des statistiques agréguées sur l'activité des virus dans le monde.
      0
  9. jlpjlp Messages postés 52399 Statut Contributeur sécurité 5 041
     
    encore des problèmes?
    0
    1. Packito77
       
      non on dirait que non sauf par moment ou internet explorer met du temsp à afficher une page alros que normalement vu ma connexion et mon ordi devrait pas y avoir de pb... vais essayer firfox je pense mais de toute façon ça arrive rarement ce ralentissement
      0