Gros problème avec Antivirus XP 2008.

Résolu/Fermé
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 - 4 août 2008 à 17:09
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 - 6 août 2008 à 19:00
Bonjour,


J'ai une fenêtre qui c'est ouverte lors d'une navigation sur internet... Cela à télécharger automatiquement un programme nommé : Antivirus XP 2008 sur mon ordinateur.

J'ai immédiatement essayer de le suprimer en allant dans Ajout/Suppression de programme et je l'ai supprimer (du moins je pense l'avoir tout supprimer). Mais depuis ce jour, aucune des mes application de fonctionne. Par exemple , quand je vaus sur Démarrer => Panneau de configuration => AJout/Suppression de programme ou Centre de sécurité ou n'importe quoi, j'ai une erreur qui s'affcihe et viens du fichier : rundll32.exe , plus rien de va, je ne sais plus aller sur firefox ni IE. Plus de mise à jour possible même en allant sur le site de microsoft. Plus moyen de changer de papier pain et toujours la même erreur : Rundll32.exe...

Merci pour les solutions apportées. J'ai lu les messages qu'avaient poster les personnes ayantt eu Antivirus XP 2008 mais pas exactement les même symptômes donc je poste quand même...

Merci de votre aide !
A voir également:

37 réponses

Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
4 août 2008 à 17:52
Salut,

- Télécharge et installe MalwareByte's Anti-Malware :
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm

- Mets-le à jour

- Redémarre en mode sans échec (Recommandé) :
https://www.malekal.com/demarrer-windows-mode-sans-echec/

- Choisis ta session habituelle

- Fais un scan complet avec MalwareByte's Anti-Malware

- Supprime tout ce que le logiciel trouve, enregistre le rapport

- Redémarre en mode normal et poste le rapport ici

Tutorial :
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
1
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
4 août 2008 à 21:17
Bonsoir,

bien merci ! Je vais faire çà de suite et je t'envoie le rapport !
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
4 août 2008 à 22:01
---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

/!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

---> Double-clique sur Combofix.exe
Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
Accepte en cliquant sur "Oui"

---> Mets-le en langue française F
Tape sur la touche 1 (Yes) pour démarrer le scan.

/!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

/!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

Note : Le rapport se trouve également là : C:\ComboFix.txt
1
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
4 août 2008 à 23:16
D'accord. Je poste çà demain car je part travailler tôt demain...

J'ai refais une analyse et j'ai 17 menaces ... J'ai du l'arrêter , j'en referai une demain puis je ferai ce que tu m'a dit juste après ;). Merci pour ton aide !
0
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
4 août 2008 à 23:25
Impossible à l'installer, j'ai désactiver mon antivirus et quand je lance le programme, il me met une erreur de find.exe et de cmd.exe

Quand j'allume on ordinateur et que je me connecte sur ma session, je doit lancer explorer.exe manuellement en faisant

CTRL + ALT + DELETE et créer une nouvelle tache... Je ne sais plus activer les mises à jour dans panneau de configuration aussi. Bref, ce virus m'a pourri mon ordinateur ... Je reprendrai demain la tête reposée, j'ai vu que tu avais réolus pas mal de personne et je ne veux pas lacher maintenant ! Un grand merci de t'occuper des problèmes des autre comme çà ;).
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
4 août 2008 à 23:33
Pour l'erreur, c'est général, je crois qu'il y a un problème avec ComboFix.
1
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
5 août 2008 à 11:33
D'accord, mais je ne sais pas comment supprimer les menaces que lui ne sais pas supprimer (MAM )

Je refais une analyse complète de mes 3 disques dure au cas ou et je supprime ce qui sait faire...
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
5 août 2008 à 12:39
- Télécharge HijackThis V 2.02 (HijackThis Installer) :
http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe

- Fais un double-clic sur HJTInstall.exe afin de lancer l'installation

- Clique sur Install ensuite sur I Accept

- Clique sur Do a scan system and save log file

- Le bloc-notes s'ouvrira, fais un copier-coller de tout son contenu ici dans ta prochaine réponse.
1

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
5 août 2008 à 12:47
Peux-tu réessayer ComboFix ?
1
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
5 août 2008 à 13:20
Oui, tu peux essayer en mode sans échec.
1
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
5 août 2008 à 19:49
Oui.
1
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
5 août 2008 à 20:08
Retélécharge ComboFix et réessaie.
1
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
5 août 2008 à 23:57
---> Télécharge le fichier CFScript et enregistre-le sur ton bureau :
http://www.zshare.net/

---> Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme sur la capture :
http://img.photobucket.com/albums/v666/sUBs/CFScript.gif

[*] Une fenêtre bleue va apparaître : au message qui apparaît (Type 1 to continue, or 2 to abort), tape 1 puis valide.

[*] Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
Ne touche à rien tant que le scan n'est pas terminé.

[*] Une fois le scan achevé, un rapport va s'afficher : poste-le

[*] Si le fichier ne s'ouvre pas, il se trouve ici C:\ComboFix.txt
1
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
6 août 2008 à 12:47
Voici quand même le rapport générer par ComboFix...

Je n'ai pas vu de message (Type 1 to continue, or 2 to abort) pourtant j'ai déposer le script sur ComboFix.exe comme tu m'a dis...



ComboFix 08-08-04.01 - chantal 2008-08-06 12:22:48.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.32.1036.18.599 [GMT 2:00]
Endroit: C:\Documents and Settings\chantal\Bureau\ComboFix.exe
Command switches used :: C:\Documents and Settings\chantal\Bureau\cfscript.txt
* Création d'un nouveau point de restauration

[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_BOONTY_GAMES
-------\Legacy_MSXXX1
-------\Legacy_VHACK
-------\Service_Boonty Games
-------\Service_MSXXX1
-------\Service_vhack


((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-06 to 2008-08-06 ))))))))))))))))))))))))))))))))))))
.

2008-08-05 21:52 . 2008-08-05 21:52 <REP> d-------- C:\Documents and Settings\chris\Application Data\Malwarebytes
2008-08-05 21:11 . 2008-08-05 21:11 <REP> d-------- C:\Documents and Settings\josé
2008-08-05 21:11 . <REP> C:\Documents and Settings\josÚ\Local Settings
2008-08-05 21:11 . <REP> C:\Documents and Settings\josÚ\Local Settings
2008-08-05 19:36 . 2008-08-05 19:36 2,048 --a------ C:\WINDOWS\system32\fwywflqo.exe
2008-08-04 18:35 . 2008-08-04 18:35 <REP> d-------- C:\Documents and Settings\chantal\VAIO Information FLOW
2008-08-04 18:00 . 2008-08-04 18:00 <REP> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-08-04 18:00 . 2008-08-04 18:00 <REP> d-------- C:\Documents and Settings\chantal\Application Data\Malwarebytes
2008-08-04 18:00 . 2008-08-04 18:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-08-04 18:00 . 2008-07-30 20:07 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2008-08-04 18:00 . 2008-07-30 20:07 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
2008-08-04 16:31 . 2008-08-04 16:31 <REP> d-------- C:\Documents and Settings\chantal\Application Data\Apple Computer
2008-08-04 12:07 . 2008-08-04 12:07 92 --a------ C:\WINDOWS\system32\test.html
2008-08-04 12:07 . 2008-08-04 12:07 92 --a------ C:\WINDOWS\system32\OLD1A.tmp
2008-08-04 11:58 . 2008-08-04 11:58 283 --a------ C:\Raccourci vers VAIO (C).lnk
2008-08-02 17:17 . 2008-08-02 17:17 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-08-01 21:54 . 2008-08-01 21:54 45,000 --ah----- C:\WINDOWS\system32\mlfcache.dat
2008-08-01 17:27 . 2008-08-01 17:28 <REP> d-------- C:\Program Files\Safari
2008-07-31 17:28 . 2008-07-31 18:18 <REP> d-------- C:\Documents and Settings\chris\Application Data\Pro Cycling Manager 2008 - Demo
2008-07-31 17:28 . 2008-07-31 17:28 87,680 --a------ C:\WINDOWS\system32\drivers\appdrv01.fs.{A7E56839-0B44-4261-8167-6DCA58E79946}.sys
2008-07-31 17:19 . 2008-07-31 17:19 <REP> d-------- C:\Program Files\Cyanide
2008-07-31 17:06 . 2001-07-15 13:15 3,428,115 --------- C:\WINDOWS\LittleCS.CAB
2008-07-31 17:06 . 2008-07-31 17:06 253,952 --------- C:\WINDOWS\Setup1.exe
2008-07-31 17:06 . 2008-07-31 17:06 74,752 --a------ C:\WINDOWS\ST6UNST.EXE
2008-07-31 17:06 . 2008-07-31 17:06 1,732 --a------ C:\WINDOWS\ST6UNST.000
2008-07-29 20:59 . 2008-07-29 20:59 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
2008-07-29 18:14 . 2008-07-29 18:14 107,888 --a------ C:\WINDOWS\system32\CmdLineExt.dll
2008-07-24 20:06 . 2008-07-24 20:10 <REP> d-------- C:\Program Files\Inkscape
2008-07-24 20:01 . 2008-07-24 20:01 <REP> d-------- C:\Documents and Settings\chris\Application Data\Stellarium
2008-07-24 20:00 . 2008-07-24 20:43 <REP> d-------- C:\Program Files\Stellarium
2008-07-23 14:53 . 2008-07-23 14:53 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Registry Helper
2008-07-23 14:36 . 2008-07-23 14:39 <REP> d-------- C:\Program Files\Perfect Macro Recorder
2008-07-23 14:36 . 2006-01-26 04:43 282,624 --a------ C:\WINDOWS\system32\acomte445.ocx
2008-07-23 14:36 . 2005-08-24 17:25 221,184 --a------ C:\WINDOWS\system32\jbet33.ocx
2008-07-23 14:36 . 2004-02-23 00:00 150,528 --a------ C:\WINDOWS\system32\TLBINF32.DLL
2008-07-23 14:36 . 2005-02-01 03:46 20,480 --a------ C:\WINDOWS\system32\re324224.exe
2008-07-19 16:51 . 2008-07-19 16:51 <REP> d-------- C:\Program Files\ALLCapture 3.0 Essai
2008-07-19 16:51 . 2008-07-19 17:02 <REP> d-------- C:\Documents and Settings\chris\Application Data\ALLCapture
2008-07-18 15:41 . 2008-07-18 15:41 <REP> d-------- C:\Documents and Settings\chantal\Application Data\Symantec
2008-07-17 20:35 . 2008-07-17 20:35 <REP> d-------- C:\Program Files\Inno Setup 5
2008-07-17 16:56 . 2008-07-17 18:24 <REP> d-------- C:\Documents and Settings\chris\Application Data\Dev-Cpp
2008-07-17 16:55 . 2008-07-18 12:52 <REP> d-------- C:\Dev-Cpp
2008-07-16 15:53 . 2008-07-18 12:26 <REP> d-------- C:\Documents and Settings\chris\Application Data\codeblocks
2008-07-16 13:18 . 2006-06-29 13:07 14,048 --------- C:\WINDOWS\system32\spmsg2.dll
2008-07-15 11:08 . 2008-07-15 11:11 <REP> d-------- C:\Program Files\Fichiers communs\Macromedia
2008-07-14 22:08 . 2008-07-14 22:08 468 --a------ C:\WINDOWS\rsagent.ini
2008-07-14 17:01 . 2008-07-18 13:06 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer
2008-07-14 16:42 . 2008-07-14 16:42 <REP> d-------- C:\WINDOWS\system32\3Planesoft
2008-07-14 16:42 . 2008-07-14 16:42 <REP> d-------- C:\Program Files\Watermill 3D Screensaver
2008-07-14 16:42 . 2008-07-14 16:42 <REP> d-------- C:\Program Files\3Planesoft Screensaver Manager
2008-07-14 16:35 . 2008-07-14 16:35 <REP> d-------- C:\Program Files\Fichiers communs\Totem Shared
2008-07-12 20:21 . 2008-07-12 20:21 <REP> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-07-09 01:17 . 2008-07-09 01:58 <REP> d-------- C:\WINDOWS\system32\hdined32.nls.{00021401-0000-0000-C000-000000000046}
2008-07-08 19:34 . 2008-07-08 19:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Messenger Plus!
2008-07-08 19:27 . 2004-08-10 14:00 18,944 --a------ C:\WINDOWS\system32\simptcp.dll
2008-07-08 19:27 . 2004-08-10 14:00 18,944 --a--c--- C:\WINDOWS\system32\dllcache\simptcp.dll
2008-07-08 19:27 . 2004-08-10 14:00 12,173 --a------ C:\WINDOWS\system32\ftpctrs.ini
2008-07-08 19:27 . 2004-08-10 14:00 7,680 --a------ C:\WINDOWS\system32\ftpctrs2.dll
2008-07-08 19:27 . 2004-08-10 14:00 7,680 --a--c--- C:\WINDOWS\system32\dllcache\ftpctrs2.dll
2008-07-08 19:27 . 2004-08-10 14:00 2,549 --a------ C:\WINDOWS\system32\ftpctrs.h
2008-07-06 23:55 . 2008-07-06 23:55 20 --a------ C:\WINDOWS\TemplateWizard.INI
2008-07-06 23:01 . 2001-11-14 20:19 16,384 --a------ C:\WINDOWS\system32\FileOps.exe
2008-07-06 23:00 . 2008-07-06 23:00 <REP> d-------- C:\Program Files\Namo
2008-07-06 15:45 . 2008-07-06 15:50 <REP> d-------- C:\Documents and Settings\chris\dwhelper

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-06 10:29 --------- d-----w C:\Program Files\Fichiers communs\Symantec Shared
2008-08-06 10:14 --------- d-----w C:\Documents and Settings\chantal\Application Data\skypePM
2008-08-06 10:04 --------- d-----w C:\Program Files\Crawler
2008-08-05 19:13 --------- d-----w C:\Documents and Settings\chantal\Application Data\VMNTOOLBAR
2008-08-05 19:00 --------- d-----w C:\Documents and Settings\chantal\Application Data\Skype
2008-08-05 11:49 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-08-04 12:59 --------- d-----w C:\Documents and Settings\chris\Application Data\FileZilla
2008-08-04 10:08 --------- d-----w C:\Program Files\Notepad++
2008-08-01 20:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-01 19:39 --------- d-----w C:\Documents and Settings\chris\Application Data\Apple Computer
2008-08-01 17:16 --------- d-----w C:\Documents and Settings\chris\Application Data\vmntoolbar
2008-08-01 16:04 --------- d-----w C:\Program Files\Apple Software Update
2008-08-01 16:00 --------- d-----w C:\Program Files\QuickTime
2008-07-30 18:07 --------- d-----w C:\Program Files\FileZilla FTP Client
2008-07-30 15:42 23,888 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-07-30 15:28 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-07-30 15:28 10,537 ----a-w C:\WINDOWS\system32\drivers\coh_mon.cat
2008-07-22 16:57 --------- d-----w C:\Program Files\Virtual Creatures
2008-07-22 15:49 805 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.INF
2008-07-22 15:49 123,952 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-07-22 15:49 10,671 ----a-w C:\WINDOWS\system32\drivers\SYMEVENT.CAT
2008-07-22 15:49 --------- d-----w C:\Program Files\Symantec
2008-07-22 15:47 --------- d-----w C:\Documents and Settings\chris\Application Data\Skype
2008-07-22 14:01 --------- d-----w C:\Documents and Settings\chris\Application Data\skypePM
2008-07-18 15:14 --------- d-----w C:\Program Files\HyCam2
2008-07-16 12:26 --------- d-----w C:\Program Files\Google
2008-07-16 10:28 --------- d-----w C:\Program Files\MSN Messenger
2008-07-15 09:10 --------- d-----w C:\Program Files\Macromedia
2008-07-14 18:28 --------- d-----w C:\Documents and Settings\chris\Application Data\gtk-2.0
2008-07-12 14:52 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-07-09 20:21 --------- d-----w C:\Program Files\Fichiers communs\Blizzard Entertainment
2008-07-08 23:12 --------- d-----w C:\Documents and Settings\chris\Application Data\Vso
2008-07-08 18:38 --------- d-----w C:\Program Files\No-IP
2008-07-06 14:16 --------- d-----w C:\Program Files\Norton 360
2008-07-04 19:04 --------- d-----w C:\Documents and Settings\chris\Application Data\Symantec
2008-07-04 16:07 --------- d-----w C:\Program Files\Windows Sidebar
2008-06-21 19:13 --------- d-----w C:\Program Files\Samsung
2008-06-20 11:51 361,600 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
2008-06-20 11:40 138,496 ----a-w C:\WINDOWS\system32\drivers\afd.sys
2008-06-20 11:08 225,856 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
2008-06-18 13:11 --------- d-----w C:\Documents and Settings\chris\Application Data\Shareaza
2008-06-18 12:06 --------- d-----w C:\Program Files\LAVClock
2008-06-17 16:51 --------- d-----w C:\Documents and Settings\chris\Application Data\Blender Foundation
2008-06-17 12:04 --------- d-----w C:\Program Files\SWiSH Max2
2008-06-15 20:12 --------- d-----w C:\Documents and Settings\chris\Application Data\Inkscape
2008-06-14 17:33 272,768 ------w C:\WINDOWS\system32\drivers\bthport.sys
2008-06-14 10:22 --------- d-----w C:\Program Files\Vista Buttons Trial
2008-06-13 16:52 --------- d-----w C:\Program Files\DynDNS Updater
2008-06-13 16:52 --------- d-----w C:\Documents and Settings\chris\Application Data\Kana Solution
2008-06-13 16:19 --------- d-----w C:\Program Files\Super macro
2008-06-13 12:14 31,280 ----a-w C:\WINDOWS\system32\drivers\SymIM.sys
2008-06-13 12:14 13,093 ----a-w C:\WINDOWS\system32\drivers\SymRedir.cat
2008-06-13 12:14 1,611 ----a-w C:\WINDOWS\system32\drivers\SymRedir.inf
2008-06-13 12:13 96,432 ----a-w C:\WINDOWS\system32\drivers\symfw.sys
2008-06-13 12:13 41,008 ----a-w C:\WINDOWS\system32\drivers\symndisv.sys
2008-06-13 12:13 38,576 ----a-w C:\WINDOWS\system32\drivers\symids.sys
2008-06-13 12:13 37,424 ----a-w C:\WINDOWS\system32\drivers\symndis.sys
2008-06-13 12:13 22,320 ----a-w C:\WINDOWS\system32\drivers\symredrv.sys
2008-06-13 12:13 184,240 ----a-w C:\WINDOWS\system32\drivers\symtdi.sys
2008-06-13 12:13 13,616 ----a-w C:\WINDOWS\system32\drivers\symdns.sys
2008-06-12 14:04 --------- d-----w C:\Program Files\Seagrand
2008-01-20 15:02 2,830 ----a-w C:\Documents and Settings\chris\Application Data\wklnhst.dat
2007-08-20 14:40 47,360 ----a-w C:\Documents and Settings\chris\Application Data\pcouffin.sys
2007-07-30 11:16 5,548 ----a-w C:\Documents and Settings\chris\ymwued.exe
2007-07-30 11:10 5,548 ----a-w C:\Documents and Settings\chris\zztazb.exe
2007-07-30 10:56 5,548 ----a-w C:\Documents and Settings\chris\vjhmyh.exe
2007-07-30 10:50 5,548 ----a-w C:\Documents and Settings\chris\tbwzqj.exe
2007-07-30 10:43 5,547 ----a-w C:\Documents and Settings\chris\uzdztr.exe
2007-07-30 10:36 5,548 ----a-w C:\Documents and Settings\chris\znbyki.exe
2007-07-30 10:30 5,548 ----a-w C:\Documents and Settings\chris\gjpehl.exe
2007-07-30 10:16 5,548 ----a-w C:\Documents and Settings\chris\hoakpf.exe
2007-07-30 10:03 5,548 ----a-w C:\Documents and Settings\chris\ajzdbb.exe
2007-07-30 09:57 5,548 ----a-w C:\Documents and Settings\chris\yujzyk.exe
2007-07-30 09:50 5,548 ----a-w C:\Documents and Settings\chris\mfqila.exe
2007-07-30 09:43 5,548 ----a-w C:\Documents and Settings\chris\xgxrhf.exe
2007-07-30 09:36 5,548 ----a-w C:\Documents and Settings\chris\yeqvki.exe
2007-07-30 09:30 5,548 ----a-w C:\Documents and Settings\chris\rcjueh.exe
2007-07-30 09:23 5,548 ----a-w C:\Documents and Settings\chris\rwdxhe.exe
2007-07-30 09:16 5,548 ----a-w C:\Documents and Settings\chris\flrdkx.exe
2007-07-30 09:10 5,548 ----a-w C:\Documents and Settings\chris\qmzwwz.exe
2007-07-30 09:03 5,548 ----a-w C:\Documents and Settings\chris\glenog.exe
2007-07-30 08:56 5,548 ----a-w C:\Documents and Settings\chris\hntcje.exe
2007-07-30 08:50 5,548 ----a-w C:\Documents and Settings\chris\aksjoj.exe
2007-07-30 08:36 5,548 ----a-w C:\Documents and Settings\chris\etxjjg.exe
2007-07-30 08:23 5,546 ----a-w C:\Documents and Settings\chris\vkdglw.exe
2007-07-30 08:16 5,548 ----a-w C:\Documents and Settings\chris\bysecm.exe
2007-07-30 08:10 5,547 ----a-w C:\Documents and Settings\chris\edagle.exe
2007-07-30 08:03 5,548 ----a-w C:\Documents and Settings\chris\xijgax.exe
2007-07-30 07:57 5,548 ----a-w C:\Documents and Settings\chris\goxkpx.exe
2007-07-30 07:50 5,548 ----a-w C:\Documents and Settings\chris\gptbue.exe
2007-07-30 07:43 5,548 ----a-w C:\Documents and Settings\chris\xhiazc.exe
2007-07-30 07:37 5,548 ----a-w C:\Documents and Settings\chris\chioeo.exe
2007-02-19 06:26 774,144 ----a-w C:\Program Files\RngInterstitial.dll
2007-12-13 21:43 88 --sh--r C:\WINDOWS\system32\72AB846474.sys
2007-12-13 21:43 2,828 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
2007-10-19 19:20 9,104 --sh--r C:\WINDOWS\system32\msivs10.dll
.

((((((((((((((((((((((((((((( snapshot@2008-08-05_21.10.39.34 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-20 17:09:59 86,815 ----a-w C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
+ 2008-08-05 21:39:35 86,968 ----a-w C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat
+ 2008-08-06 10:28:48 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_1f8.dat
+ 2008-08-06 10:29:01 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_33c.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayExcluded]
@="{4433A54A-1AC8-432F-90FC-85F045CF383C}"
[HKEY_CLASSES_ROOT\CLSID\{4433A54A-1AC8-432F-90FC-85F045CF383C}]
2008-02-26 10:34 576352 --a------ C:\Program Files\Fichiers communs\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayPending]
@="{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}"
[HKEY_CLASSES_ROOT\CLSID\{F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225}]
2008-02-26 10:34 576352 --a------ C:\Program Files\Fichiers communs\Symantec Shared\Backup\buShell.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\OverlayProtected]
@="{476D0EA3-80F9-48B5-B70B-05E677C9C148}"
[HKEY_CLASSES_ROOT\CLSID\{476D0EA3-80F9-48B5-B70B-05E677C9C148}]
2008-02-26 10:34 576352 --a------ C:\Program Files\Fichiers communs\Symantec Shared\Backup\buShell.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 12:34 5724184]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 16:57 68856]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-13 19:34 15360]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-30 17:33 22058792]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-07-31 12:47 1836544]
"snp2std"="C:\WINDOWS\vsnp2std.exe" [2005-11-16 16:14 344064]
"PaperPort PTD"="C:\Program Files\Scansoft\PaperPort\pptd40nt.exe" [2002-07-08 11:10 45108]
"IndexSearch"="C:\Program Files\Scansoft\PaperPort\IndexSearch.exe" [2002-07-08 11:41 36864]
"SetDefPrt"="C:\Program Files\Brother\BRMFLPRO\BrDefPrt.exe" [2002-12-18 15:31 40960]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2008-02-18 13:37 51048]
"osCheck"="C:\Program Files\Norton 360\osCheck.exe" [2008-02-26 16:50 988512]
"AppleSyncNotifier"="C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 20:42 116040]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2008-04-13 19:34 15360]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2006-06-20 16:11 73728 C:\WINDOWS\system32\VESWinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"VIDC.dvsd"= C:\PROGRA~1\FICHIE~1\SONYSH~1\VideoLib\sonydv.dll
"vidc.CDVC"= cdvccodc.dll
"vids.CDVC"= cdvccodc.dll
"vidc.xvid"= xvid.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\chris3191007\\counter-strike\\hl.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\chris3191007\\dedicated server\\hlds.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\maury844\\dedicated server\\hlds.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"C:\\Program Files\\Shareaza Applications\\Shareaza\\Shareaza.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\PHPEdit\\DBG\\DbgListener.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\WINDOWS\\system32\\winver.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\chris3191007\\condition zero\\hl.exe"=
"C:\\Program Files\\Valve\\Steam\\SteamApps\\chris3191007\\condition zero deleted scenes\\hl.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"80:TCP"= 80:TCP:80 TCP
"80:UDP"= 80:UDP:UDP
"3587:TCP"= 3587:TCP:Groupement homologue Windows
"3540:UDP"= 3540:UDP:Protocole PNRP (Peer Name Resolution Protocol)
"3389:TCP"= 3389:TCP:*:Disabled:@xpsp2res.dll,-22009

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)

R2 LiveUpdate Notice;LiveUpdate Notice;C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe [2008-02-18 13:37]
R2 MSSQL$VAIO_VEDB;MSSQL$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe [2002-12-17 18:55]
R3 ti21sony;ti21sony;C:\WINDOWS\system32\drivers\ti21sony.sys [2006-02-21 11:32]
S3 brfilt;Pilote de filtre Brother MFC;C:\WINDOWS\system32\Drivers\Brfilt.sys [2001-08-17 22:12]
S3 BrSerWDM;Pilote série Brother;C:\WINDOWS\system32\Drivers\BrSerWdm.sys [2001-08-17 22:12]
S3 BrUsbMdm;Brother MFC USB modem télécopieur uniquement;C:\WINDOWS\system32\Drivers\BrUsbMdm.sys [2001-08-17 22:12]
S3 BrUsbScn;Pilote de scanneur Brother MFC USB;C:\WINDOWS\system32\Drivers\BrUsbScn.sys [2001-08-17 22:12]
S3 COH_Mon;COH_Mon;C:\WINDOWS\system32\Drivers\COH_Mon.sys [2008-07-30 17:42]
S3 p2pgasvc;Authentification de groupe réseau homologue;C:\WINDOWS\system32\svchost.exe [2008-04-13 19:34]
S3 p2pimsvc;Gestionnaire d'identité réseau homologue;C:\WINDOWS\system32\svchost.exe [2008-04-13 19:34]
S3 p2psvc;Réseau homologue;C:\WINDOWS\system32\svchost.exe [2008-04-13 19:34]
S3 PNRPSvc;Protocole de résolution de noms d'homologues;C:\WINDOWS\system32\svchost.exe [2008-04-13 19:34]
S3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2005-11-18 18:29]
S3 SQLAgent$VAIO_VEDB;SQLAgent$VAIO_VEDB;C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlagent.EXE [2002-12-17 18:23]
S3 wampapache;wampapache;c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe [2008-01-18 01:37]
S3 wampmysqld;wampmysqld;c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe wampmysqld []

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc

*Newly Created Service* - COMHOST
.
Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'

2008-07-29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
.
**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-06 12:29:46
Windows 5.1.2600 Service Pack 3 NTFS

Balayage processus cach‚s ...

Balayage cach‚ autostart entries ...

Balayage des fichiers cach‚s ...

Scan termin‚ avec succŠs
Les fichiers cach‚s: 0

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\system32\drivers\CDANTSRV.EXE
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
.
**************************************************************************
.
Temps d'accomplissement: 2008-08-06 12:36:15 - machine was rebooted [chantal]
ComboFix-quarantined-files.txt 2008-08-06 10:36:05
ComboFix2.txt 2008-08-05 19:11:09

Pre-Run: 5,898,219,520 octets libres
Post-Run: 5,881,466,880 octets libres

343 --- E O F --- 2008-07-09 20:31:51
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
6 août 2008 à 14:53
---> Télécharge OTMoveIt2 à partir du lien ci-dessous :
http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe

---> Enregistre le fichier sur le Bureau.

---> Double-clique sur le fichier OTMoveIt2.exe pour lancer l'outil.
Assure-toi que la case Unregister Dll's and Ocx's soit bien cochée.

---> Copie l'intégralité du texte ci-dessous et colle-le dans la fenêtre intitulée Paste Standard List of Files/Folders to be moved.




C:\WINDOWS\system32\fwywflqo.exe
C:\Documents and Settings\chris\ymwued.exe
C:\Documents and Settings\chris\zztazb.exe
C:\Documents and Settings\chris\vjhmyh.exe
C:\Documents and Settings\chris\tbwzqj.exe
C:\Documents and Settings\chris\uzdztr.exe
C:\Documents and Settings\chris\znbyki.exe
C:\Documents and Settings\chris\gjpehl.exe
C:\Documents and Settings\chris\hoakpf.exe
C:\Documents and Settings\chris\ajzdbb.exe
C:\Documents and Settings\chris\yujzyk.exe
C:\Documents and Settings\chris\mfqila.exe
C:\Documents and Settings\chris\xgxrhf.exe
C:\Documents and Settings\chris\yeqvki.exe
C:\Documents and Settings\chris\rcjueh.exe
C:\Documents and Settings\chris\rwdxhe.exe
C:\Documents and Settings\chris\flrdkx.exe
C:\Documents and Settings\chris\qmzwwz.exe
C:\Documents and Settings\chris\glenog.exe
C:\Documents and Settings\chris\hntcje.exe
C:\Documents and Settings\chris\aksjoj.exe
C:\Documents and Settings\chris\etxjjg.exe
C:\Documents and Settings\chris\vkdglw.exe
C:\Documents and Settings\chris\bysecm.exe
C:\Documents and Settings\chris\edagle.exe
C:\Documents and Settings\chris\xijgax.exe
C:\Documents and Settings\chris\goxkpx.exe
C:\Documents and Settings\chris\gptbue.exe
C:\Documents and Settings\chris\xhiazc.exe
C:\Documents and Settings\chris\chioeo.exe
C:\WINDOWS\system32\72AB846474.sys
C:\DOCUME~1\chris\LOCALS~1\Temp\Rar$EX00.859\IfoundnoNameforit Hack v0.1 Beta\IfoundnoNameforit Hack v0.1 Beta\IfnNfiH.sys
C:\DOCUME~1\chris\LOCALS~1\Temp\Rar$EX00.797\vhack.sys
C:\Program Files\Crawler\
C:\Program Files\Fichiers communs\BOONTY Shared\




---> Clique sur MoveIt! pour lancer la suppression.
Lorsqu'un résultat apparaît dans le cadre Results, clique sur Exit.

Note : Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.

---> Poste le rapport de OTMoveIt qui se trouve dans C:\_OTMoveIt\MovedFiles.
1
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
6 août 2008 à 17:13
Voici :



C:\WINDOWS\system32\fwywflqo.exe moved successfully.
C:\Documents and Settings\chris\ymwued.exe moved successfully.
C:\Documents and Settings\chris\zztazb.exe moved successfully.
C:\Documents and Settings\chris\vjhmyh.exe moved successfully.
C:\Documents and Settings\chris\tbwzqj.exe moved successfully.
C:\Documents and Settings\chris\uzdztr.exe moved successfully.
C:\Documents and Settings\chris\znbyki.exe moved successfully.
C:\Documents and Settings\chris\gjpehl.exe moved successfully.
C:\Documents and Settings\chris\hoakpf.exe moved successfully.
C:\Documents and Settings\chris\ajzdbb.exe moved successfully.
C:\Documents and Settings\chris\yujzyk.exe moved successfully.
C:\Documents and Settings\chris\mfqila.exe moved successfully.
C:\Documents and Settings\chris\xgxrhf.exe moved successfully.
C:\Documents and Settings\chris\yeqvki.exe moved successfully.
C:\Documents and Settings\chris\rcjueh.exe moved successfully.
C:\Documents and Settings\chris\rwdxhe.exe moved successfully.
C:\Documents and Settings\chris\flrdkx.exe moved successfully.
C:\Documents and Settings\chris\qmzwwz.exe moved successfully.
C:\Documents and Settings\chris\glenog.exe moved successfully.
C:\Documents and Settings\chris\hntcje.exe moved successfully.
C:\Documents and Settings\chris\aksjoj.exe moved successfully.
C:\Documents and Settings\chris\etxjjg.exe moved successfully.
C:\Documents and Settings\chris\vkdglw.exe moved successfully.
C:\Documents and Settings\chris\bysecm.exe moved successfully.
C:\Documents and Settings\chris\edagle.exe moved successfully.
C:\Documents and Settings\chris\xijgax.exe moved successfully.
C:\Documents and Settings\chris\goxkpx.exe moved successfully.
C:\Documents and Settings\chris\gptbue.exe moved successfully.
C:\Documents and Settings\chris\xhiazc.exe moved successfully.
C:\Documents and Settings\chris\chioeo.exe moved successfully.
C:\WINDOWS\system32\72AB846474.sys moved successfully.
File/Folder C:\DOCUME~1\chris\LOCALS~1\Temp\Rar$EX00.859\IfoundnoNameforit Hack v0.1 Beta\IfoundnoNameforit Hack v0.1 Beta\IfnNfiH.sys not found.
File/Folder C:\DOCUME~1\chris\LOCALS~1\Temp\Rar$EX00.797\vhack.sys not found.
C:\Program Files\Crawler\Update moved successfully.
C:\Program Files\Crawler\TempDir moved successfully.
C:\Program Files\Crawler\TBR5LanguageAct moved successfully.
C:\Program Files\Crawler\Languages moved successfully.
C:\Program Files\Crawler\firefox\components moved successfully.
Folder move failed. C:\Program Files\Crawler\firefox\chrome scheduled to be moved on reboot.
Folder move failed. C:\Program Files\Crawler\firefox scheduled to be moved on reboot.
C:\Program Files\Crawler\Cache\COMMON moved successfully.
C:\Program Files\Crawler\Cache moved successfully.
Folder move failed. C:\Program Files\Crawler scheduled to be moved on reboot.
C:\Program Files\Fichiers communs\BOONTY Shared\Service moved successfully.
C:\Program Files\Fichiers communs\BOONTY Shared moved successfully.

OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08062008_170711

Files moved on Reboot...
C:\Program Files\Crawler\firefox\chrome moved successfully.
C:\Program Files\Crawler\firefox moved successfully.
C:\Program Files\Crawler moved successfully.
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
6 août 2008 à 18:11
---> Relance HijackThis et choisis Do a system scan only

---> Coche les cases qui sont devant les lignes suivantes :

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66006

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66006

R3 - URLSearchHook: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll (file missing)

O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll (file missing)

O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll (file missing)

O4 - HKCU\..\Run: [Registry Helper] "C:\Program Files\Registry Helper\LaunchRegistryHelper.Exe" "C:\Program Files\Registry Helper\RegistryHelper.Exe" /boot

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll (file missing)

---> Clique en bas sur Fix checked. Mets oui si HijackThis te demande quelque chose.

---> Redémarre ton PC et reposte un nouveau rapport HijackThis
1
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
6 août 2008 à 18:28
Dernière étape :

---> Télécharge CCleaner (N'installe pas la Yahoo Toolbar) :
https://www.ccleaner.com/ccleaner/download

---> Lance-le. Va dans "Options" puis "Avancé", tu décoches la case "Effacer uniquement les fichiers etc...". Tu vas dans "Nettoyeur", tu fais "Analyse". Une fois terminé, tu lances le nettoyage. Puis tu vas dans "Registre", tu fais "Chercher des erreurs". Une fois terminé, tu répares toutes les erreurs sans sauvegarder la base de registre.

Télécharge Tools Cleaner sur ton bureau.
http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
Clique sur Recherche et laisse le scan agir.
Clique sur Suppression pour finaliser.
Tu peux, si tu le souhaites, te servir des Options facultatives.
Clique sur Quitter pour obtenir le rapport.
Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger :
http://www.infos-du-net.com/forum/272480-11-desactiver-activer-restauration-systeme

---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
https://www.vulgarisation-informatique.com/creer-point-restauration.php

;)
1
ticooo Messages postés 11 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 4 août 2008
4 août 2008 à 17:56
J'aii eu le meme pb j'saiis pas sii tu a vu mon sujet et a ce jour mon pc ne démarre plus meme en mode sans echec !! Rrrr
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
4 août 2008 à 17:58
ticooo ---> Je t'ai répondu.
0
Destrio5 Messages postés 85985 Date d'inscription dimanche 11 juillet 2010 Statut Modérateur Dernière intervention 17 février 2023 10 291
4 août 2008 à 21:25
Ok.
0
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
4 août 2008 à 21:46
Voici le rapport après la suppression... Mais il y a certain élément qui n'ont pas été supprimer (j'ai eu un message le signalant...)
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1024
Windows 5.1.2600 Service Pack 3

21:36:47 04/08/2008
mbam-log-8-4-2008 (21-36-47).txt

Type de recherche: Examen complet (D:\|)
Eléments examinés: 36296
Temps écoulé: 3 minute(s), 1 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 3
Clé(s) du Registre infectée(s): 32
Valeur(s) du Registre infectée(s): 8
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 11
Fichier(s) infecté(s): 36

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
C:\WINDOWS\system32\ssqQjjiI.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\dtzmjf.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\jkkIXPjG.dll (Trojan.Vundo) -> Delete on reboot.

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83ccbd00-caa7-475e-9c97-5122d2517d84} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{83ccbd00-caa7-475e-9c97-5122d2517d84} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92b1fcf3-5544-4964-97be-aec37920bbf2} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{92b1fcf3-5544-4964-97be-aec37920bbf2} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{6ff22309-a6ed-462b-abec-877625c012f3} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6ff22309-a6ed-462b-abec-877625c012f3} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkkixpjg (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{24f5c348-8803-4d7b-82b6-a3beb136c9f5} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{24f5c348-8803-4d7b-82b6-a3beb136c9f5} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3c7a90cc-8a9d-4c4c-801e-137ffafc82f8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3c7a90cc-8a9d-4c4c-801e-137ffafc82f8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b65c99d0-8312-46a4-8591-d3514e5a7348} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b65c99d0-8312-46a4-8591-d3514e5a7348} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\rhc7f8j0eaaa (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmmt32 (Dialer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysLibrary (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\54a58e5f (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6ff22309-a6ed-462b-abec-877625c012f3} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm5796bdc3 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc3f8j0eaaa (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smrhc7f8j0eaaa (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\ssqqjjii -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\ssqqjjii -> Delete on reboot.

Dossier(s) infecté(s):
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\WINDOWS\system32\dtzmjf.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\ssqQjjiI.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\IijjQqss.ini (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\IijjQqss.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eFWpnlIx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xIlnpWFe.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xIlnpWFe.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fccywvWq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qWvwyccf.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qWvwyccf.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hcttkhjy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yjhkttch.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\naeyqoit.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tioqyean.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\oqfagkyr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rykgafqo.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\trxvtulu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ulutvxrt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\walharaw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\warahlaw.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jkkIXPjG.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\cpsecbjk.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\amkgrvcu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winmmt32.dll (Dialer) -> Delete on reboot.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\d.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pmnLeDUo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM5796bdc3.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM5796bdc3.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lphc3f8j0eaaa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\photos2007_79.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\photos2007_88.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\czhfsbftjy_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\czhfsbftjy_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nvs2.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
0
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
4 août 2008 à 21:46
Voici le rapport après la suppression... Mais il y a certain élément qui n'ont pas été supprimer (j'ai eu un message le signalant...)
Malwarebytes' Anti-Malware 1.24
Version de la base de données: 1024
Windows 5.1.2600 Service Pack 3

21:36:47 04/08/2008
mbam-log-8-4-2008 (21-36-47).txt

Type de recherche: Examen complet (D:\|)
Eléments examinés: 36296
Temps écoulé: 3 minute(s), 1 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 3
Clé(s) du Registre infectée(s): 32
Valeur(s) du Registre infectée(s): 8
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 11
Fichier(s) infecté(s): 36

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
C:\WINDOWS\system32\ssqQjjiI.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\dtzmjf.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\jkkIXPjG.dll (Trojan.Vundo) -> Delete on reboot.

Clé(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83ccbd00-caa7-475e-9c97-5122d2517d84} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{83ccbd00-caa7-475e-9c97-5122d2517d84} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{92b1fcf3-5544-4964-97be-aec37920bbf2} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{92b1fcf3-5544-4964-97be-aec37920bbf2} (Trojan.Vundo) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{6ff22309-a6ed-462b-abec-877625c012f3} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6ff22309-a6ed-462b-abec-877625c012f3} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkkixpjg (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{24f5c348-8803-4d7b-82b6-a3beb136c9f5} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{24f5c348-8803-4d7b-82b6-a3beb136c9f5} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3c7a90cc-8a9d-4c4c-801e-137ffafc82f8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3c7a90cc-8a9d-4c4c-801e-137ffafc82f8} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b65c99d0-8312-46a4-8591-d3514e5a7348} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b65c99d0-8312-46a4-8591-d3514e5a7348} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\rhc7f8j0eaaa (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winmmt32 (Dialer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysLibrary (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\54a58e5f (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6ff22309-a6ed-462b-abec-877625c012f3} (Trojan.Vundo) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bm5796bdc3 (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc3f8j0eaaa (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\smrhc7f8j0eaaa (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo) -> Data: c:\windows\system32\ssqqjjii -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\ssqqjjii -> Delete on reboot.

Dossier(s) infecté(s):
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\chris\Application Data\rhc7f8j0eaaa\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.

Fichier(s) infecté(s):
C:\WINDOWS\system32\dtzmjf.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\ssqQjjiI.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\IijjQqss.ini (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\IijjQqss.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\eFWpnlIx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xIlnpWFe.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\xIlnpWFe.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\fccywvWq.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qWvwyccf.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\qWvwyccf.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\hcttkhjy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\yjhkttch.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\naeyqoit.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\tioqyean.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\oqfagkyr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\rykgafqo.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\trxvtulu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\ulutvxrt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\walharaw.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\warahlaw.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\jkkIXPjG.dll (Trojan.Vundo) -> Delete on reboot.
C:\WINDOWS\system32\cpsecbjk.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\amkgrvcu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winmmt32.dll (Dialer) -> Delete on reboot.
C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
C:\d.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\pskt.ini (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\pmnLeDUo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM5796bdc3.xml (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\BM5796bdc3.txt (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\lphc3f8j0eaaa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\photos2007_79.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\photos2007_88.zip (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\czhfsbftjy_navps.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\czhfsbftjy_nav.dat (Adware.NaviPromo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\nvs2.inf (Adware.EGDAccess) -> Quarantined and deleted successfully.
0
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
5 août 2008 à 12:44
Voilà :


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:43:52, on 05/08/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\vsnp2std.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Scansoft\PaperPort\SmartUI\SmartUI.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Safari\Safari.exe
C:\Documents and Settings\chantal\Bureau\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-be
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-be
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-be
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=66006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66006
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-be
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=66006
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.club-vaio.com/fr/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Show Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Fichiers communs\Symantec Shared\coShared\Browser\2.6\CoIEPlg.dll
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\BRMFLPRO\BrDefPrt.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton 360\osCheck.exe"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: SmartUI.lnk = ?
O8 - Extra context menu item: &Traduire à partir de l'anglais - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ajouter un site de support RSS à VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O8 - Extra context menu item: Pages liées - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Pages similaires - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Recherche &Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Version de la page actuelle disponible dans le cache Google - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr/
O15 - Trusted Zone: *.sony-europe.com
O15 - Trusted Zone: *.sonystyle-europe.com
O15 - Trusted Zone: *.vaio-link.com
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://bmm.imgag.com/imgag/cp/install/crusher-fr.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL dtzmjf.dll
O21 - SSODL: printers - {B7CCC6E9-72C9-4E71-AF39-27FFDBE91D27} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\system32\DRIVERS\CDANTSRV.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\VAScanner\comHost.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
O23 - Service: wampapache - Apache Software Foundation - c:\wamp\bin\apache\apache2.2.8\bin\httpd.exe
O23 - Service: wampmysqld - Unknown owner - c:\wamp\bin\mysql\mysql5.0.51b\bin\mysqld-nt.exe
0
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
5 août 2008 à 12:57
4 fenêtres apparaissent l'une à la suite de l'autre chaque fois que je clique sur OK...



find.exe - Erreur d'application.

L'application n'a pas réussi à s'initialiser correctement (0xc0000005). CLiquez sur OK pour arrêter l'application.

cmd.exe - Erreur d'application.

L'application n'a pas réussi à s'initialiser correctement (0xc0000005). CLiquez sur OK pour arrêter l'application.


find.exe - Erreur d'application.

L'application n'a pas réussi à s'initialiser correctement (0xc0000005). CLiquez sur OK pour arrêter l'application.


cmd.exe - Erreur d'application.

L'application n'a pas réussi à s'initialiser correctement (0xc0000005). CLiquez sur OK pour arrêter l'application.


Puis après :

Error - Win32 Only.


OS incompatible. CombaFix ne fonctionne que pour Windows 2000 et XP


=> j'ai windows XP en plus :/

EDITE : Je peux peut être essayer de lancer comboFix en mode sans échec ?
0
The Big Pan Messages postés 38 Date d'inscription lundi 4 août 2008 Statut Membre Dernière intervention 6 novembre 2008 1
5 août 2008 à 19:34
Excuse moi pour le restard, j'ai du m'absenter....

Ca ne fonctionne toujours pas, même en mode sans échec...

J'ai refais une annalyse avec MAM, non pas sur 1 disque (36.000 fichiers environs) mais sur mes 2 disques (190.000 fichiers environs)

je poste le rapport générer après effacement des infections détectées ? (toutes n'ont pas çu êtres suprimée :/)
0