XP 2008 ANTIVIRUS

Résolu
kaoarmony -  
 Utilisateur anonyme -
Bonjour à tous,
Voilà j'ai un petit problême, j'ai dû choper le virus XP 2008 ANTIVIRUS,
je me suis un peu renseigné sur le forum et j'ai pu voir qu'il fallait télécharger HIJACKTHIS.
Que dois-je faire par la suite?
Merci
Configuration: Windows XP
Internet Explorer 7.0

2 réponses

  1. Utilisateur anonyme
     
    lu
    salut, lit d'abort ce tuto si t'as tjrs besoin d'aide dit moi ou alors!

    Télécharge combofix.exe (par sUBs) sur ton Bureau. a partir de ce lien:http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    -> Double clique combofix.exe.
    -> Tape sur la touche 1 (Yes) pour démarrer le scan.
    -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

    Avant d'utiliser ComboFix :

    -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

    -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

    Une fois fait, sur ton bureau double-clic sur Combofix.exe.

    - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

    /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

    - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

    - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

    -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

    -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

    Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
    dit moi quant c'est fait!

    ____________________________________________________________________
     
    A Vaincre Sans Péril,On Triomphe Sans Gloire !!!!!!
    0
    1. kaoarmony
       
      ok je vais faire ça et je te tiens au courant, merci!!
      0
      1. Utilisateur anonyme > kaoarmony
         
        re
        tu as lu le tuto avant car tu as la solution dedans!

        ____________________________________________________________________
         
        A Vaincre Sans Péril,On Triomphe Sans Gloire !!!!!!
        0
      2. kaoarmony > Utilisateur anonyme
         
        La solutionComboFix 08-08-19.06 - Benjamin&Zohra 2008-08-21 14:49:34.2 - [color=red][b]FAT32[/b][/color]x86
        Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.596 [GMT 2:00]
        Endroit: C:\Documents and Settings\Benjamin&Zohra\Bureau\ComboFix.exe

        [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
        .
        Error: Cfiles.dat

        ((((((((((((((((((((((((((((( Fichiers créés 2008-07-21 to 2008-08-21 ))))))))))))))))))))))))))))))))))))
        .

        2008-08-21 14:16 . 2008-08-21 14:16 <REP> d-------- C:\Program Files\RogueRemover FREE
        2008-08-21 11:42 . 2008-08-21 11:42 <REP> d-------- C:\Program Files\Alwil Software
        2008-08-21 10:31 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
        2008-08-21 10:31 . 2001-08-23 17:04 12,288 --a------ C:\WINDOWS\system32\dllcache\mouhid.sys
        2008-08-20 20:50 . 2008-08-20 20:50 <REP> d-------- C:\Program Files\Spybot - Search & Destroy
        2008-08-20 20:50 . 2008-08-20 20:50 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
        2008-08-20 20:29 . 2008-08-20 20:29 131,584 --a------ C:\Program Files\KB31189.exe
        2008-08-20 20:29 . 2008-08-20 20:29 126,976 --a------ C:\WINDOWS\wxml92466.dll
        2008-08-20 19:57 . 2008-08-20 19:57 <REP> d-------- C:\Documents and Settings\All Users\Application Data\services
        2008-08-20 19:55 . 2008-08-20 19:55 126,976 --a------ C:\WINDOWS\wxml12136.dll
        2008-08-20 19:48 . 2008-08-20 19:48 103,428 --a------ C:\WINDOWS\system32\msxml71.dll
        2008-08-20 14:19 . 2008-08-20 14:19 <REP> d-------- C:\Program Files\DivX
        2008-08-20 12:34 . 2008-08-20 12:34 <REP> d-------- C:\Program Files\Lavasoft
        2008-08-20 12:34 . 2008-08-20 12:34 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
        2008-08-20 12:33 . 2008-08-20 12:33 <REP> d-------- C:\Program Files\Fichiers communs\Wise Installation Wizard
        2008-08-20 11:18 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
        2008-08-20 11:18 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys
        2008-08-20 11:13 . 2008-08-20 11:13 <REP> d-------- C:\Program Files\uTorrent
        2008-08-20 11:12 . 2008-08-20 11:12 <REP> d-------- C:\Documents and Settings\Benjamin&Zohra\Application Data\uTorrent
        2008-08-20 10:56 . 2008-08-20 10:56 <REP> d-------- C:\WINDOWS\system32\fr-fr
        2008-08-20 10:36 . 2008-08-20 10:36 <REP> d-------- C:\Program Files\Google
        2008-08-20 10:36 . 2008-08-20 10:36 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Google Updater
        2008-08-19 09:37 . 2008-08-19 09:37 <REP> d-------- C:\Documents and Settings\Benjamin&Zohra\Application Data\AdobeUM
        2008-08-19 00:18 . 2004-08-05 05:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
        2008-08-19 00:11 . 2008-08-19 00:11 <REP> d-------- C:\Program Files\Fichiers communs\ArcSoft
        2008-08-19 00:11 . 2008-08-19 00:11 <REP> d-------- C:\Program Files\Acer
        2008-08-19 00:11 . 2005-02-23 14:58 11,776 --a------ C:\WINDOWS\system32\drivers\afc.sys
        2008-08-19 00:10 . 1995-08-01 04:44 212,480 --a------ C:\WINDOWS\PCDLIB32.DLL
        2008-08-19 00:09 . 2008-08-19 00:09 <REP> d-------- C:\Program Files\Java
        2008-08-19 00:09 . 2008-08-19 00:09 <REP> d-------- C:\Program Files\Fichiers communs\Java
        2008-08-19 00:09 . 2005-03-04 03:36 49,265 --a------ C:\WINDOWS\system32\jpicpl32.cpl
        2008-08-19 00:08 . 2005-09-06 12:42 <REP> d-------- C:\WINDOWS\system32\config\systemprofile\Application Data\Symantec
        2008-08-19 00:08 . 2005-09-06 12:25 <REP> d--h----- C:\Documents and Settings\Benjamin&Zohra\Voisinage réseau
        2008-08-19 00:08 . 2005-09-06 12:25 <REP> d--h----- C:\Documents and Settings\Benjamin&Zohra\Voisinage d'impression
        2008-08-19 00:08 . 2005-09-06 12:25 <REP> d--h----- C:\Documents and Settings\Benjamin&Zohra\Modèles
        2008-08-19 00:08 . 2008-08-20 10:57 <REP> dr------- C:\Documents and Settings\Benjamin&Zohra\Mes documents
        2008-08-19 00:08 . 2005-09-06 12:25 <REP> dr------- C:\Documents and Settings\Benjamin&Zohra\Menu Démarrer
        2008-08-19 00:08 . 2008-08-19 00:08 <REP> dr------- C:\Documents and Settings\Benjamin&Zohra\Favoris
        2008-08-19 00:08 . 2005-09-06 12:25 <REP> d-------- C:\Documents and Settings\Benjamin&Zohra\Bureau
        2008-08-19 00:08 . 2005-09-06 12:42 <REP> d-------- C:\Documents and Settings\Benjamin&Zohra\Application Data\Symantec
        2008-08-19 00:08 . 2008-08-19 00:08 <REP> d-------- C:\Documents and Settings\Benjamin&Zohra
        2008-08-19 00:04 . 2008-08-19 00:04 <REP> d--hs---- C:\FOUND.001
        2008-08-18 23:49 . 2008-08-18 23:49 <REP> d--hs---- C:\FOUND.000
        2008-07-23 18:48 . 2008-07-23 18:48 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll
        2008-07-23 18:48 . 2008-07-23 18:48 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll

        .
        (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\es.dll
        2008-07-07 20:31 253,952 ----a-w C:\WINDOWS\system32\dllcache\es.dll
        2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
        2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\dllcache\mscms.dll
        2008-06-24 08:28 3,592,192 ------w C:\WINDOWS\system32\dllcache\mshtml.dll
        2008-06-23 09:21 70,656 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe
        2008-06-23 09:21 625,664 ------w C:\WINDOWS\system32\dllcache\iexplore.exe
        2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
        2008-06-21 05:23 161,792 ------w C:\WINDOWS\system32\dllcache\ieakui.dll
        2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
        2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
        2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
        2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
        2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
        2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
        .

        ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
        REGEDIT4

        [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{18BDC10D-63B9-30E7-B677-12A641CD1C58}]
        2008-08-20 20:29 126976 --a------ C:\WINDOWS\wxml92466.dll

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
        "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-08-20 10:36 39408]
        "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-08-18 18:41 1832272]
        "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 05:00 15360]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "LaunchApp"="Alaunch" [X]
        "ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15 45056]
        "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
        "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 05:00 208952]
        "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 05:00 59392]
        "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 05:00 455168]
        "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 05:00 455168]
        "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-08-16 09:56 368640]
        "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-08-02 09:35 7110656]
        "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-08-02 09:35 86016]
        "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe" [2005-03-04 03:36 36975]
        "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2005-08-16 17:36 114688]
        "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-07-22 09:16 425984]
        "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-07-19 16:38 78008]
        "High Definition Audio Property Page Shortcut"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe]
        "RTHDCPL"="RTHDCPL.EXE" [2005-06-08 14:42 14565376 C:\WINDOWS\RTHDCPL.EXE]
        "nwiz"="nwiz.exe" [2005-08-02 09:35 1519616 C:\WINDOWS\system32\nwiz.exe]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 05:00 15360]

        C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
        Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "C:\\Program Files\\uTorrent\\uTorrent.exe"=

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
        "3886:UDP"= 3886:UDP:Windows Media Format SDK (iexplore.exe)
        "3887:UDP"= 3887:UDP:Windows Media Format SDK (iexplore.exe)

        R0 m5287;m5287;C:\WINDOWS\system32\drivers\m5287.sys [2005-02-05 22:00]
        R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 16:35]
        R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 16:37]
        R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]

        *Newly Created Service* - AAVMKER4
        *Newly Created Service* - ASWFSBLK
        *Newly Created Service* - ASWMON2
        *Newly Created Service* - ASWRDR
        *Newly Created Service* - ASWSP
        *Newly Created Service* - ASWTDI
        *Newly Created Service* - ASWUPDSV
        *Newly Created Service* - AVAST!_ANTIVIRUS
        *Newly Created Service* - AVAST!_MAIL_SCANNER
        *Newly Created Service* - AVAST!_WEB_SCANNER
        *Newly Created Service* - CATCHME
        *Newly Created Service* - INT15.SYS
        *Newly Created Service* - PROCEXP90
        .
        .
        ------- Supplementary Scan -------
        .
        R0 -: HKCU-Main,Start Page = hxxp://yahoo.fr/
        R0 -: HKCU-Main,SearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
        .

        **************************************************************************

        catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-08-21 14:50:38
        Windows 5.1.2600 Service Pack 2 FAT NTAPI

        Balayage processus cachés ...

        Balayage caché autostart entries ...

        Balayage des fichiers cachés ...

        Scan terminé avec succès
        Les fichiers cachés: 0

        **************************************************************************
        .
        Temps d'accomplissement: 2008-08-21 14:51:03
        ComboFix-quarantined-files.txt 2008-08-21 12:51:02
        ComboFix2.txt 2008-08-21 12:48:36

        Pre-Run: 89,536,364,544 octets libres
        Post-Run: 89,525,321,728 octets libres

        153 --- E O F --- 2008-08-20 13:05:48
        ? je vais jeter un coup d'oeil en tout cas voila le log:
        0
      3. Utilisateur anonyme > kaoarmony
         
        lu combofix ta déja regler quelques petites ereur!
        maintenant :
        telecharge cela:util pour voir ce que peut etre l infection et agir ensuite.

        hitcjackthis

        installe le normallement comme tout autre programme dans c/programme/...............
        clique sur do a scan and save a logfile, tu obtiens un rapport que tu colles.
        parfois alerte comme quoi, sans la fonction administrateur le rapport ne peut pas etre complet .
        a ce moment relance hijack avec un clique droit sur le raccourci et executer en tant qu administrateur
        Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse
        et colle moi ton rapport dans ta prochaine réponse!


        ____________________________________________________________________
         
        A Vaincre Sans Péril,On Triomphe Sans Gloire !!!!!!
        0
  2. kaoarmony
     
    C'est le log de combofix.
    0
    1. Utilisateur anonyme
       
      je sais fait avec hijacthis maintenant!

      ____________________________________________________________________
       
      A Vaincre Sans Péril,On Triomphe Sans Gloire !!!!!!
      0
    2. kaoarmony > Utilisateur anonyme
       
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 15:05:07, on 21/08/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Acer\Empowering Technology\eRecovery\Monitor.exe
      C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
      C:\Program Files\Acer\Acer eMode Management\AspireService.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\uTorrent\uTorrent.exe
      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      C:\WINDOWS\explorer.exe
      C:\Documents and Settings\Benjamin&Zohra\Bureau\HiJackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: D - {18BDC10D-63B9-30E7-B677-12A641CD1C58} - C:\WINDOWS\wxml92466.dll
      O2 - BHO: (no name) - {500BCA15-57A7-4eaf-8143-8C619470B13D} - (no file)
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.6972\swg.dll
      O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - (no file)
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [LaunchApp] Alaunch
      O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
      O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
      O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
      O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\BENJAM~1\LOCALS~1\Temp\E.tmp.exe
      O4 - HKCU\..\Run: [s9201] "C:\Documents and Settings\All Users\Application Data\Secure Solutions\Antispyware 2008 XP\as2008xp.exe" /autorun
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      0
    3. Utilisateur anonyme > kaoarmony
       
      ok lu
      tu auras 3 voir 4 ligne a fixer!
      mais maintenant telecharge Malwarebyte's Anti-Malware a cette adresse:
      https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

      ensuite:
      . sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
      . enregistres le sur le bureau
      . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
      . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
      . si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
      . Une fois la mise à jour terminée,fermes Malwarebytes
      . redemarres en mode sans échec pour savoir comment au cas ou tu ne saurrais pas regarde plus bas
      . une fois en mode sans echec tu double-cliques sur l'icône de malwarebytes
      . une fois ouvert rend-toi dans l'onglet, Recherche
      . Sélectionnes Exécuter un examen complet
      . Cliques sur Rechercher
      . Le scan démarre.
      . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
      . Cliques sur Ok pour poursuivre.
      . Si des malwares ont été détectés, cliques sur Afficher les résultats
      . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
      . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
      . redemarre le pc
      . une fois redémarré en mode normal double-cliques sur malwarebytes
      . rends toi dans l'onglet rapport/log
      . tu cliques dessus pour l'afficher une fois affiché
      . tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
      . tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
      . tu me colle ton rapport=>clic droit coller



      ____________________________________________________________________
       
      A Vaincre Sans Péril,On Triomphe Sans Gloire !!!!!!
      0
    4. Utilisateur anonyme > Utilisateur anonyme
       
      je bouge juste pendant 30 mn et je reviens de suite une fois malwarebite's passer de toutes façon ton pc sera nettoyer on fixera tes lignes a mon retour je m'dépèche!
      a de suite!
      mode sans echec F8 et demarer en mode sans echec fait ça en redemarant le pc!
      ____________________________________________________________________
       
      A Vaincre Sans Péril,On Triomphe Sans Gloire !!!!!!
      0
    5. kaoarmony > Utilisateur anonyme
       
      J'ai tout fais comme tu m'as dit, voilà le résultat:

      Malwarebytes' Anti-Malware 1.25
      Version de la base de données: 1075
      Windows 5.1.2600 Service Pack 2

      15:34:50 21/08/2008
      mbam-log-08-21-2008 (15-34-50).txt

      Type de recherche: Examen complet (C:\|D:\|)
      Eléments examinés: 57697
      Temps écoulé: 2 minute(s), 19 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 4
      Valeur(s) du Registre infectée(s): 5
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 6

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_CLASSES_ROOT\xml.xml.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500bca15-57a7-4eaf-8143-8c619470b13d} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18bdc10d-63b9-30e7-b677-12a641cd1c58} (Trojan.BHO) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{18bdc10d-63b9-30e7-b677-12a641cd1c58} (Trojan.BHO) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Somefox (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\System Volume Information\_restore{42310EC4-7D2B-4715-A05C-0D953851EDA5}\RP4\A0000444.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\QooBox\Quarantine\C\WINDOWS\system32\lphcv1cj0er1q.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\Program Files\KB31189.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
      C:\Documents and Settings\All Users\Application Data\services\services.dll (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\WINDOWS\wxml92466.dll (Trojan.BHO) -> Quarantined and deleted successfully.
      0