Pub virale ? a chaque ouverture de page net

Bonjour,

J'ai un gros soucis, quand j'ouvre une page net 2 ou 3 secondes apres une nouvelle pages de publicité s'ouvre .
résultat ralentissement du débit et je n'arrive plus à me connecter a msn . j'ai téléchargé un parefeu correct et chose hallucinante toute les deux secondes il me trouvait une méchante alerte je l'ai désinstallé . et ai lu quelques pages de votre site mais je dois dire que je me sens quelque peu perdu...
Configuration: Windows XP
Internet Explorer 7.0

18 réponses

  1. Modérateur
    Salut,

    - Télécharge HijackThis V 2.02 (HijackThis Installer) :
    http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

    - Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

    - Clique sur Install ensuite sur I Accept

    - Clique sur Do a scan system and save log file

    - Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
    0
    1. ok voila

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:34:05, on 18/06/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      C:\Program Files\DNA\btdna.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
      C:\WINDOWS\explorer.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - {13346FEB-4738-473D-8F71-2D202A38B320} - C:\WINDOWS\system32\geBrsSJa.dll
      O2 - BHO: {5ea77b18-7d8b-adab-c334-c7ea43f95745} - {54759f34-ae7c-433c-bada-b8d781b77ae5} - C:\WINDOWS\system32\uwtndx.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: (no name) - {C6EA321D-EE5F-4ED5-B1FF-3A87F9D81ABF} - C:\WINDOWS\system32\iifgEvWM.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [BMafc26a47] Rundll32.exe "C:\WINDOWS\system32\owbybmus.dll",s
      O4 - HKLM\..\Run: [acf159db] rundll32.exe "C:\WINDOWS\system32\visrrdeo.dll",b
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
      O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
      O16 - DPF: {C8751A11-7A61-4FD3-893B-8CD7757C2C71} (Webaddon3d Control) - http://3d.cannes.fr/maquette3D/plugin/Webaddon3D.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O20 - Winlogon Notify: iifgEvWM - C:\WINDOWS\SYSTEM32\iifgEvWM.dll
      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
      O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
      0
      1. Modérateur
        DllD ---> Tu t'en occupes ? ;)
        0
        1. Salut
          Oui ===> Merci.

          ;-)
          0
      2. Bonsoir,

        > Télécharge ComboFix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe (par sUBs) sur ton Bureau.
        Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement.
        - Double clique combofix.exe
        - Tape sur la touche 1 (Yes) pour démarrer le scan.
        - Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
        NOTE : Le rapport se trouve également ici : C:\Combofix.txt
        Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer la machine.

        A+
        0
        1. Modérateur
          lutina ---> Tu n'as pas la même infection.
          0
          1. c adire?
            0
          2. @luticaSalut,
            Il serait préférable que tu crées ton propre topique (= discussion). Cela rendra celui-ci plus compréhensible, et tu obtiendras des réponses à ton problème avec plus d’efficacité.

            Donc,
            fais ce qui suit stp : http://pagesperso-orange.fr/rginformatique/section%20virus/demofairesontmessage.htm
            (Flash-player de Balltrap).

            A++
            0
        2. Modérateur
          lutica ---> Tu pollues le topic à djaydjay, merci de créer ton propre sujet.
          0
          1. pushd "C:\327882R2FWJFW\"
            Killing '2380'
            "C:\WINDOWS\System32\rundll32.exe" setupapi,InstallHinfSection DefaultInstall 132 C:\327882R2FWJFW\nircmd.inf (2380)

            =============================================

            ALLUSERSPROFILE=C:\Documents and Settings\All Users
            APPDATA=C:\Documents and Settings\Cindy\Application Data
            cfldr=327882R2FWJFW
            CLASSPATH=.;C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
            CLIENTNAME=Console
            CommonProgramFiles=C:\Program Files\Fichiers communs
            COMPUTERNAME=MONPC
            ComSpec=C:\WINDOWS\system32\cmd.exe
            FP_NO_HOST_CHECK=NO
            HOMEDRIVE=C:
            HOMEPATH=\Documents and Settings\Cindy
            kmd=CF26866.exe
            LOGONSERVER=\\MONPC
            NUMBER_OF_PROCESSORS=2
            OS=Windows_NT
            Path=C:\327882R2FWJFW;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\system32\wbem;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Samsung\Samsung PC Studio 3\;C:\Program Files\QuickTime\QTSystem\
            PATHEXT=.cfexe;.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
            PROCESSOR_ARCHITECTURE=x86
            PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel
            PROCESSOR_LEVEL=15
            PROCESSOR_REVISION=0209
            ProgramFiles=C:\Program Files
            PROMPT=$
            QTJAVA=C:\Program Files\Java\jre1.6.0_05\lib\ext\QTJava.zip
            SESSIONNAME=Console
            sfxname=C:\ComboFix.exe
            system=C:\WINDOWS\system32
            SystemDrive=C:
            SystemRoot=C:\WINDOWS
            TEMP=C:\DOCUME~1\Cindy\LOCALS~1\Temp
            TMP=C:\DOCUME~1\Cindy\LOCALS~1\Temp
            USERDOMAIN=MONPC
            USERNAME=Cindy
            USERPROFILE=C:\Documents and Settings\Cindy
            windir=C:\WINDOWS

            =============================================

            if not defined sfxname goto END

            If [] == [] Set "SfxCmd="

            if /I "C:\327882R2FWJFW" NEQ "C:\327882R2FWJFW" goto Abort

            if exist "C:\DOCUME~1\Cindy\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log" del "C:\DOCUME~1\Cindy\LOCALS~1\Temp\327882R2FWJFW327882R2FWJFW.log"
            SteelWerX Extended Configuration Access Control Lists
            Written by Bobbi Flekman 2006 (C)
            Ownerchange for "C:\WINDOWS\system32\cmd.exe" to Administrators group was successful

            copy /y "C:\WINDOWS\system32\cmd.exe" "C:\WINDOWS\system32\CF26866.exe"
            1 fichier(s) copi‚(s).

            if not exist "C:\WINDOWS\system32\CF26866.exe" catchme -l nul -c "C:\WINDOWS\system32\cmd.exe" "C:\WINDOWS\system32\CF26866.exe"

            For /F "tokens=*" %g in ("C:\ComboFix.exe") do @(
            set "FileName=%~ng"
            set "FilePath=%~dpg"
            )

            Set FileName 1>FileName 2>nul

            GREP -Gisqx "FileName=[-[:alnum:]@.]*" FileName || (
            nircmd infobox "You cannot rename ComboFix as ComboFix~n~nPlease use another name, preferbaly made up of alphanumeric characters" ""
            goto END
            )

            DIR /AD/B C:\* | Findstr -IVX ComboFix 1>dirname00

            Findstr -LIXC:"ComboFix" dirname00 1>nul && call :NameChk

            If exist dirname0? del /Q dirname0?

            If exist "\ComboFix" DIR /AD "\ComboFix" 1>nul && (
            rd /s/q "\ComboFix"
            If exist "\ComboFix" (
            PV -kf Findstr *.cfexe
            rd /s/q "\ComboFix"
            )
            If exist "\ComboFix" (
            handle "C:\ComboFix" | SED -r "/pid:/!d; s/.*: (.*): .*/\1/" 1>temp00
            for /F "tokens=1,2" %g in (temp00) do @echo.y | Handle -p %g -c %h
            del /q temp00
            rd /s/q "\ComboFix"
            )
            )

            If exist "\ComboFix" rd /s/q "\ComboFix"

            If exist "\ComboFix" goto :eof

            VER | Findstr -ic:"[Version 6.0" && (Call :Vista ) ||

            CD ..

            Set "comspec=C:\WINDOWS\system32\CF26866.exe"

            (
            echo.md "\ComboFix"
            echo.Move /y "\327882R2FWJFW\*" "\ComboFix"
            echo.RD /S/Q "\327882R2FWJFW"
            echo.Start "." /d"C:\ComboFix" "C:\WINDOWS\system32\CF26866.exe" /k c.bat
            echo.pv -kf cmd.exe
            ) 1>Start_.cmd

            NirCmd exec hide "C:\WINDOWS\system32\CF26866.exe" /f:off /d /c call Start_.cmd

            NirCmd execmd del "\327882R2FWJFW\prep.cmd"

            EXIT

            voila
            0
            1. Re,
              C'est pas le bon rapport.

              Je te remets la manip.
              > Télécharge ComboFix : http://download.bleepingcomputer.com/sUBs/ComboFix.exe (par sUBs) sur ton Bureau.
              Déconnecte toi du net et désactive ton antivirus pour que Combofix puisse s'exécuter normalement.
              - Double clique combofix.exe
              - Tape sur la touche 1 (Yes) pour démarrer le scan.
              - Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
              NOTE : Le rapport se trouve également ici : C:\Combofix.txt
              Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer la machine.

              A+
              0
          2. alors, j'ai une fentre bleue qui apparait puis un signal d'erreur datée du 18/06/08
            j'ai bien désactivé mon parefeu mon antivir. ouille
            0
            1. dessus est aussi ecrit check your setting
              0
              1. Re,
                J'étais à table.

                Alors on va faire autrement :

                > Télécharge MalwareByte's Anti-Malware : http://www.malwarebytes.org/mbam/program/mbam-setup.exe
                - Installe le programme puis lance le stp.
                NB : S'il te manque COMCTL32.OCX alors télécharge le ici : https://www.malekal.com/tutorial-aboutbuster/
                - Fais les mises à jour (clique sur "Mises à jour" puis "Recherche de mises à jour")
                - Démarre en mode sans échec (image). Si problème : tuto ici
                - Lance le MalwareByte's Anti-Malware puis clique sur "Executer un examen complet" puis "Rechercher" et sélectionne tous tes disques durs => le scan débute....patiente...
                - A la fin du scanne, clique sur "supprimer" (Si des éléments sont difficiles à supprimer, un message te demandera de redémarrer : clique sur "Oui" alors)
                - Après suppression des infections : un rapport va être généré : sauvegarde le et poste le sur forum stp.

                Ensuite,
                Reposte un HijackT stp

                A+
                0
                1. Malwarebytes' Anti-Malware 1.20
                  Version de la base de données: 932
                  Windows 5.1.2600 Service Pack 2

                  22:28:33 18/06/2008
                  mbam-log-6-18-2008 (22-28-33).txt

                  Type de recherche: Examen complet (C:\|D:\|)
                  Eléments examinés: 111523
                  Temps écoulé: 35 minute(s), 40 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 3
                  Clé(s) du Registre infectée(s): 10
                  Valeur(s) du Registre infectée(s): 3
                  Elément(s) de données du Registre infecté(s): 2
                  Dossier(s) infecté(s): 0
                  Fichier(s) infecté(s): 12

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  C:\WINDOWS\system32\geBrsSJa.dll (Trojan.Vundo) -> Unloaded module successfully.
                  C:\WINDOWS\system32\visrrdeo.dll (Trojan.Vundo) -> Unloaded module successfully.
                  C:\WINDOWS\system32\iifgEvWM.dll (Trojan.Vundo) -> Unloaded module successfully.

                  Clé(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{13346feb-4738-473d-8f71-2d202a38b320} (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{13346feb-4738-473d-8f71-2d202a38b320} (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_CLASSES_ROOT\CLSID\{c6ea321d-ee5f-4ed5-b1ff-3a87f9d81abf} (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c6ea321d-ee5f-4ed5-b1ff-3a87f9d81abf} (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iifgevwm (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\acf159db (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{c6ea321d-ee5f-4ed5-b1ff-3a87f9d81abf} (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bmafc26a47 (Trojan.Agent) -> Quarantined and deleted successfully.

                  Elément(s) de données du Registre infecté(s):
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\gebrssja -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\gebrssja -> Quarantined and deleted successfully.

                  Dossier(s) infecté(s):
                  (Aucun élément nuisible détecté)

                  Fichier(s) infecté(s):
                  C:\WINDOWS\system32\geBrsSJa.dll (Trojan.Vundo) -> Delete on reboot.
                  C:\WINDOWS\system32\aJSsrBeg.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\aJSsrBeg.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\qmynptwv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\vwtpnymq.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\visrrdeo.dll (Trojan.Vundo) -> Delete on reboot.
                  C:\WINDOWS\system32\oedrrsiv.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\iifgEvWM.dll (Trojan.Vundo) -> Delete on reboot.
                  C:\Documents and Settings\Cindy\Local Settings\Temporary Internet Files\Content.IE5\1BP28VJA\kb456456[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\System Volume Information\_restore{91DBE0B7-8705-4C3D-A018-88C3B6CC7EBB}\RP139\A0046383.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
                  C:\WINDOWS\system32\owbybmus.dll (Trojan.Agent) -> Delete on reboot.
                  0
                  1. Ok,

                    Bien joué.

                    Réessaye un Combofix stp puis poste le rappot.

                    MErci.
                    0
                    1. puis le hjackthis

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 22:32:51, on 18/06/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
                      C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
                      C:\Program Files\iTunes\iTunesHelper.exe
                      C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                      C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      C:\Program Files\DNA\btdna.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                      C:\WINDOWS\system32\wscntfy.exe
                      C:\Program Files\iPod\bin\iPodService.exe
                      C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\WINDOWS\system32\NOTEPAD.EXE
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: {5ea77b18-7d8b-adab-c334-c7ea43f95745} - {54759f34-ae7c-433c-bada-b8d781b77ae5} - C:\WINDOWS\system32\uwtndx.dll
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe
                      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe"
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://appldnld.apple.com/QuickTime/qtactivex/qtplugin.cab
                      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                      O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                      O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
                      O16 - DPF: {C8751A11-7A61-4FD3-893B-8CD7757C2C71} (Webaddon3d Control) - http://3d.cannes.fr/maquette3D/plugin/Webaddon3D.cab
                      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                      O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                      O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe
                      O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
                      O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
                      0
                      1. combofix ne marche tjrs pas mr ou mdme dlld
                        0
                        1. est ce que je dois faire des recherces sur une eventuelle mise a jour du logiciel combofix....?
                          malheureusement j'ai l'impression qu'ily a bcp de questionnement sur ce log qui selon certains est peu fiables ....
                          puis je utiliser un autre cheminement ou perseverer vers celui ci
                          0
                          1. Re,
                            Ok,

                            Afin d'éviter les trojans... :
                            > Installe un pare feu :
                            - Je te conseille Kerio : http://www.commentcamarche.net/telecharger/telecharger 206 kerio . Si problème, tuto : https://kerio.probb.fr/
                            - Si tu as des difficultés avec les configuration de Kerio, alors installe Zone Alarme : /telecharger/telecharger-157-zonealarm, en cas de problème : http://forum.telecharger.01net.com/forum/high-tech/PRODUITS/Questions-techniques/zonealarm-tutorial-sujet_169658_1.htm
                            - Installe le nouveau pare-feu, puis désactive le pare-feu windows.

                            On continue le nettoyage.

                            > Télécharge et installe Ccleaner :
                            - Fais les mises à jour puis ferme le programme.
                            Si besoin est tu trouveras des Tutoriaux : ici, ici et là.

                            > Télécharge Clean (de Malekal Morte) (différent de Ccleaner)

                            > Télécharge SDFix (de AndyManchesta) sur ton bureau :
                            - Double clique sur l'archive SDFix qui à été créé sur le Bureau et installe le programme (l'installation va créer un dossier (à la racine du disque dur par défaut) nommé SDFix. Ferme ensuite le programme.

                            > Commence par faire un copier/coller de ce poste (cette manip.): (conseillé)
                            Ouvre un nouveau fichier Bloc notes (clique sur "Démarrer" => "Programmes" =>"Accessoires" => "Bloc notes"),
                            puis fait un copier/coller de tout le contenu de la fenêtre de ce poste dans le fichier texte.
                            Sauvegarde le sur le bureau, tu pourras alors y avoir accès même déconnecté ou en mode sans échec.

                            > Démarre en mode sans échec : (image). Si problème : tuto ici

                            > Lance Ccleaner,
                            - Choisi l’onglet "Options" puis clique sur "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier temp de Windows, plus vieux que 48 heures" (tout doit être supprimé).
                            - Dans l'onglet "Nettoyeur" clique sur "Analyse".
                            - Une fois l'analyse terminée, clique sur "Lancer le Nettoyage".
                            - Dans l'onglet "registre" => Recherches des erreurs => Réparer les erreurs sélectionnées => enregistre une sauvegarde => corriger toutes erreurs sélectionnées => ok => fermer.
                            N.B : Si Ccleaner te propose d'enregistrer une sauvegarde, reponds oui et enregistre sous 'Bureau'
                            Recommence jusqu’à ce qu’il ne trouve plus rien (cela varie en général entre 1 et 4 fois).

                            > Pour Clean (encore en mode sans échec) :
                            - Double-clic sur clean.cmd
                            - Une fenêtre va apparaître, choisis l'option 2, suis les consignes et poste le rapport clean (Le rapport clean se trouve ici : C:\rapport_clean.txt)
                            NB : Si besoin : Tuto

                            > Pour SDFix (toujours en mode sans échec) :
                            - Vas dans c:/SDFix et double-clique sur RunThis.bat
                            - Appuie sur < Y > puis < Entrée >....Le nettoyage commence....patience...
                            - Le programme va te demander de relancer le PC, frappe une touche...
                            - Le nettoyage se termine...un rapport apparait...
                            -Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse

                            > Relance ton PC en mode normal

                            > Relance Hijackthis :
                            Puis sélectionne < do a system scan and save a logfile >,
                            Et envoie moi, par collier/coller, ton log Hijackthis,

                            Bon courage,

                            A+
                            0