INFECTEE

Résolu
Bonjour,

Au secours! Je suis infectée!!!
Message d'erreur sur mon bureau iindiquant:

WARNING Win32/Adware.Virtumonde
WARNING Win32/Privacy/Remover.M64

Quelqu'un peut-il m'aider?

Merci d'avance
Configuration: Windows XP
Firefox 2.0.0.16

23 réponses

  1. Contributeur
    Bonjour

    Télécharge sur le Bureau HijackThis

    http://download.hijackthis.eu/HJTInstall.exe

    = Double-clique sur dessus pour l'installer
    = Clique sur Do a system scan and save the log
    = Colle le rapport
    si problème voir l'aide
    http://www.swl1f.net/viewtopic.php?f=14&t=153&p=1100#p1100
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    @+
    0
    1. Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 17:04:53, on 23/08/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      C:\Program Files\LogMeIn\x86\RaMaint.exe
      C:\Program Files\LogMeIn\x86\LogMeIn.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Spyware Doctor\pctsAuxs.exe
      C:\Program Files\Spyware Doctor\pctsSvc.exe
      C:\Program Files\Spyware Doctor\pctsTray.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
      C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
      C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
      C:\WINDOWS\system32\lphcglnj0e3cl.exe
      C:\Program Files\MSN Messenger\MsnMsgr.Exe
      C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\FICHIE~1\Nokia\MPAPI\MPAPI3s.exe
      C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
      C:\Program Files\rhcllnj0e3cl\rhcllnj0e3cl.exe
      C:\Program Files\Shareaza\Shareaza.exe
      C:\Documents and Settings\admin\Bureau\VundoFix.exe
      C:\Documents and Settings\admin\Bureau\HiJackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = french.ircfast.com/index.php?rvs=hompag
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
      O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\Plugins\RazaWebHook.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: My Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
      O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
      O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
      O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
      O4 - HKLM\..\Run: [lphcglnj0e3cl] C:\WINDOWS\system32\lphcglnj0e3cl.exe
      O4 - HKLM\..\Run: [SMrhcllnj0e3cl] C:\Program Files\rhcllnj0e3cl\rhcllnj0e3cl.exe
      O4 - HKLM\..\RunOnce: [NCInstallQueue] rundll32 netman.dll,ProcessQueue
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
      O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
      O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
      O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
      O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
      O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~4\GOEC62~1.DLL
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
      O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
      O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
      0
      1. et j'ai oublié d'être polie...
        MERCI!
        0
        1. Contributeur
          Ton PC est infecté

          Télécharge ToolBar-S&D ( Merci à Eric_71, Angeldark, Sham_Rock et XmichouX )
          https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

          * Double-clique sur ToolBar-SD afin de lancer l'installation, un raccourci sera ajouté sur le Bureau.
          * Double-clique dessus pour démarrer l'outil; choisis la langue.
          * Sous Vista, faire un clic droit et "Exécuter en tant qu'administrateur" (Elévation des privilèges), puis -> Continuer.
          * Tape 2 puis sur la touche [Entrée] afin de lancer la suppression.
          * Patiente jusqu'à la fin de la recherche.
          * À la fin du scan, le rapport s'ouvrira dans le Bloc-notes.
          * Poste ce rapport, par copier/coller, dans ta prochaine réponse.
          * Le rapport se trouve également sous : C:\TB.txt

          ** Aide en images
          https://sites.google.com/site/toolbarsd/aideenimages

          ensuite
          Télécharge combofix.exe (par sUBs) et sauvegarde le sur ton bureau.
          http://download.bleepingcomputer.com/sUBs/ComboFix.exe
          * Déconnecte toi d'internet et ferme toutes tes applications.
          * Désactive tes protections (antivirus, parefeu,antispyware) provisoirement et seulement le temps de l'utilisation de ComboFix,
          * Double-clic sur combofix.exe, il est possible que ton parefeu te demande si tu acceptes ou non l'accès de nircmd.cfexe à la zone sûre: accepte.
          * /! Ne touche à rien tant que le scan n'est pas terminé.Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne /!
          * Attends que Combofix ait terminé, un rapport sera créé.
          * réactive ton parefeu, ton antivirus, la garde de ton antispyware
          * copie/colle le rapport, le rapport se trouve dans : C:Combofix.txt
          * Réactive tes protections en temps réel, Antivirus, Antispywares, avant de te reconnecter à internet.

          @+ :)
          0
          1. ComboFix 08-08-21.02 - admin 2008-08-23 18:07:43.1 - NTFSx86
            Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1471 [GMT 2:00]
            Endroit: C:\DOCUME~1\admin\Bureau\ComboFix.exe
            * Création d'un nouveau point de restauration

            [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]
            .

            (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
            .

            C:\DOCUME~1\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk
            C:\DOCUME~1\admin\Application Data\rhcllnj0e3cl
            C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008
            C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008.lnk
            C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008\Antivirus XP 2008.lnk
            C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
            C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008\License Agreement.lnk
            C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008\Register Antivirus XP 2008.lnk
            C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008\Uninstall.lnk
            C:\Program Files\rhcllnj0e3cl
            C:\WINDOWS\system32\a.exe
            C:\WINDOWS\system32\blphcglnj0e3cl.scr
            C:\WINDOWS\system32\lphcglnj0e3cl.exe
            C:\WINDOWS\system32\phcglnj0e3cl.bmp
            C:\WINDOWS\system32\pphcglnj0e3cl.exe

            .
            ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-07-23 to 2008-08-23 ))))))))))))))))))))))))))))))))))))
            .

            2008-08-23 17:32 . 2008-08-23 17:32 3,634 --a------ C:\Documents and Settings\Orph.egd
            2008-08-23 17:30 . 2008-08-23 17:33 <REP> d-------- C:\ToolBar SD
            2008-08-23 17:00 . 2008-08-23 18:17 106,496 --a------ C:\WINDOWS\system32\94.tmp
            2008-08-23 17:00 . 2008-08-23 18:16 106,496 --a------ C:\WINDOWS\system32\93.tmp
            2008-08-23 17:00 . 2008-08-23 17:55 106,496 --a------ C:\WINDOWS\system32\92.tmp
            2008-08-23 15:20 . 2008-08-23 15:20 <REP> d-------- C:\VundoFix Backups
            2008-08-23 13:51 . 2008-08-23 13:51 <REP> d-------- C:\Program Files\Enigma Software Group
            2008-08-17 13:50 . 2008-08-17 13:50 <REP> d-------- C:\DOCUME~1\admin\Application Data\ACD Systems
            2008-08-17 13:50 . 2008-08-17 13:50 <REP> d-------- C:\DOCUME~1\admin\Application Data\ACD Systems
            2008-08-17 13:47 . 2008-08-17 13:47 <REP> d-------- C:\Program Files\Fichiers communs\ACD Systems
            2008-08-17 13:47 . 2008-08-17 13:47 <REP> d-------- C:\Program Files\ACD Systems
            2008-08-17 13:47 . 2008-08-17 13:47 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ACD Systems
            2008-08-17 13:46 . 2008-08-17 13:46 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys

            .
            (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2008-08-23 16:22 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
            2008-08-23 09:57 --------- d-----w C:\DOCUME~1\admin\Application Data\Azureus
            2008-08-23 09:57 --------- d-----w C:\DOCUME~1\admin\Application Data\Azureus
            2008-08-23 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
            2008-08-22 22:11 --------- d-----w C:\Program Files\LogMeIn
            2008-08-22 21:02 --------- d-----w C:\Program Files\Spyware Doctor
            2008-07-07 07:50 --------- d-----w C:\Program Files\Azureus
            2006-10-12 16:17 3,072 ----a-w C:\Program Files\mozilla firefox\plugins\ractrlkeyhook.dll
            2006-02-13 11:07 245,408 ----a-w C:\Program Files\mozilla firefox\plugins\unicows.dll
            .
            [code]<pre>
            ----a-w 702,149 2007-01-04 13:19:30 C:\Documents and Settings\admin\Bureau\setup Chipset .exe
            </pre>[/code]

            ------- Sigcheck -------

            2006-03-09 10:25 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\system32\user32.dll

            2006-04-12 20:13 667648 241dbc4c2714b2f39afded49459ed420 C:\WINDOWS\system32\wininet.dll

            2006-02-14 21:56 359808 667192a11db19f36624119c0dd4de4f2 C:\WINDOWS\system32\drivers\tcpip.sys

            2006-05-09 10:11 2017280 50b3a210b6fa8d3089a36a32e7d8b21f C:\WINDOWS\system32\ntkrnlpa.exe

            2006-03-09 10:25 2137600 e75f7aa5a33479f29c636fd0890f5762 C:\WINDOWS\system32\ntoskrnl.exe

            2006-03-09 10:25 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\system32\spoolsv.exe
            .
            ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s
            REGEDIT4

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 13:55 5674352]
            "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-29 15:55 68856]
            "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 16:21 1449984]
            "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" [N/A]
            "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09 15360]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
            "LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03 63048]
            "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
            "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-25 11:44 1836544]
            "NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 01:12 2658304]
            "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-19 19:45 266497]
            "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
            "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
            "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-03-02 02:22 185896]
            "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 13:55 1103240]
            "NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [N/A]
            "Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2005-06-27 10:21 221184]
            "lphcglnj0e3cl"="C:\WINDOWS\system32\lphcglnj0e3cl.exe" [N/A]
            "SMrhcllnj0e3cl"="C:\Program Files\rhcllnj0e3cl\rhcllnj0e3cl.exe" [N/A]
            "nwiz"="nwiz.exe" [2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe]
            "NvMediaCenter"="NvMCTray.dll" [2006-10-22 13:22 86016 C:\WINDOWS\system32\nvmctray.dll]
            "RTHDCPL"="RTHDCPL.EXE" [2006-01-11 17:23 15961088 C:\WINDOWS\RTHDCPL.exe]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
            "NCInstallQueue"="netman.dll" [2006-03-09 10:25 197632 C:\WINDOWS\system32\netman.dll]

            [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
            "MemCheckBoxInRunDlg"= 1 (0x1)
            "NoSMBalloonTip"= 1 (0x1)
            "NoDesktopCleanupWizard"= 1 (0x1)
            "NoWelcomeScreen"= 1 (0x1)
            "NoStrCmpLogical"= 0 (0x0)
            "NoInstrumentation"= 0 (0x0)

            [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
            "MemCheckBoxInRunDlg"= 1 (0x1)
            "NoSMBalloonTip"= 1 (0x1)
            "NoDesktopCleanupWizard"= 1 (0x1)
            "NoWelcomeScreen"= 1 (0x1)

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
            2008-01-04 01:20 87352 C:\WINDOWS\system32\LMIinit.dll

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
            "VIDC.ACDV"= ACDV.dll

            [HKEY_LOCAL_MACHINE\software\microsoft\security center]
            "AntiVirusOverride"=dword:00000001
            "FirewallOverride"=dword:00000001
            "AntiVirusDisableNotify"=dword:00000001
            "UpdatesDisableNotify"=dword:00000001
            "DisablePagingExecutive"=dword:00000001
            "SecondLevelDataCache"=dword:00000200

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
            "EnableFirewall"= 0 (0x0)
            "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
            "C:\\Program Files\\MSN Messenger\\livecall.exe"=
            "C:\\Program Files\\iTunes\\iTunes.exe"=
            "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
            "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=

            R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2007-04-17 14:00]
            R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-04-05 11:55]
            S3 kwwalpgr;kwwalpgr;C:\DOCUME~1\admin\LOCALS~1\Temp\kwwalpgr.sys []
            S3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);C:\WINDOWS\system32\DRIVERS\SMCWGU.sys [2005-12-16 05:41]

            [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{582610B8-E496-4813-993C-4B027173FE38}]
            C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
            .
            Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'

            2008-07-29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
            - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]
            .
            0
        2. -----------\\ ToolBar S&D 1.1.3 XP/Vista

          Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
          X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU 6400 @ 2.13GHz )
          Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
          X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU 6400 @ 2.13GHz )
          Phoenix - AwardBIOS v6.00PG
          USER : admin ( Administrator )
          BOOT : Normal boot

          "C:\ToolBar SD" ( MAJ : 22-08-2008|17:30 )
          Option : [2] ( 23/08/2008|17:31 )

          -----------\\ SUPPRESSION

          Supprime! - C:\Program Files\MySearch\bar
          Supprime! - C:\Program Files\MySearch

          -----------\\ Recherche de Fichiers / Dossiers ...

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Search Page"="https://www.google.com/?gws_rd=ssl"
          "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
          "Local Page"="C:\\WINDOWS\\system32\\blank.htm"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
          "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
          "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
          "Start Page"="https://www.msn.com/fr-fr/"
          "Search Bar"="https://www.bing.com/?toHttps=1&redig=8F3F334EA60E4B1CB4D040DCFE393A89{SUB_RFC1766}/srchasst/srchasst.htm"

          --------------------\\ Recherche d'autres infections

          --------------------\\ Cracks & Keygens ..

          C:\DOCUME~1\ALLUSE~1\Documents\Ma musique\My Playlists\Music\Bomfunk MC's\Late Registration\Kanye West - Crack Music.mp3
          C:\DOCUME~1\ALLUSE~1\Documents\Ma musique\My Playlists\Music\Kanye West\Late Registration\Kanye West - Crack Music.mp3

          -----------\\ Fin du rapport a 17:33:06,79
          0
          1. j'ai fais tout ce que vous avez dit...
            Mon ordi s'est etient en plein millieu de la procédure...
            je ne sais pas si ca a marché...

            Merci encore de bien vouloir m'aider
            0
            1. Contributeur
              selectionne ceci

              Registry::
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "lphcglnj0e3cl"=-
              "SMrhcllnj0e3cl"=-

              File::
              C:\WINDOWS\system32\92.tmp
              C:\WINDOWS\system32\94.tmp
              C:\WINDOWS\system32\93.tmp
              C:\Documents and Settings\Orph.egd
              C:\Documents and Settings\admin\Bureau\setup Chipset .exe


              * Copie le texte sélectionné (CTRL+C).
              * Ouvre le bloc-notes (programme>Accessoires >bloc-notes).
              * Veille à ce que Retour à la ligne ne soit pas coché dans Format.
              * Colle le texte copié dans ce bloc-notes (CTRL+V).
              * Sauvegarde ce fichier sous le nom de CFScript.txt
              * Fais un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe comme ceci
              http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
              * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal!
              Ne touche à rien tant que le scan n'est pas terminé.
              * Une fois le scan achevé, un rapport va s'afficher : Poste son contenu.
              * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt


              Note: Le code ci-dessus a été intentionnellement rédigé pour CET utilisateur.
              si vous n'êtes pas CET utilisateur, NE PAS appliquer ces directives : elles pourraient endommager votre système.

              @+
              0
              1. alors voici :
                ComboFix 08-08-21.02 - admin 2008-08-23 19:10:05.1 - NTFSx86
                Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1476 [GMT 2:00]
                Endroit: C:\Documents and Settings\admin\Bureau\ComboFix.exe
                Command switches used :: C:\Documents and Settings\admin\Bureau\CFScript.txt
                * Création d'un nouveau point de restauration

                [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                FILE ::
                C:\Documents and Settings\admin\Bureau\setup Chipset .exe
                C:\Documents and Settings\Orph.egd
                C:\WINDOWS\system32\92.tmp
                C:\WINDOWS\system32\93.tmp
                C:\WINDOWS\system32\94.tmp
                .

                (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                .

                C:\Documents and Settings\admin\Bureau\setup Chipset .exe
                C:\Documents and Settings\Orph.egd
                .
                ---- Previous Run -------
                .
                C:\DOCUME~1\admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk
                C:\DOCUME~1\admin\Application Data\rhcllnj0e3cl
                C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008
                C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008.lnk
                C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008\Antivirus XP 2008.lnk
                C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk
                C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008\License Agreement.lnk
                C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008\Register Antivirus XP 2008.lnk
                C:\DOCUME~1\ALLUSE~1\Menu Démarrer\Programmes\Antivirus XP 2008\Uninstall.lnk
                C:\Program Files\rhcllnj0e3cl
                C:\WINDOWS\system32\a.exe
                C:\WINDOWS\system32\blphcglnj0e3cl.scr
                C:\WINDOWS\system32\lphcglnj0e3cl.exe
                C:\WINDOWS\system32\phcglnj0e3cl.bmp
                C:\WINDOWS\system32\pphcglnj0e3cl.exe

                .
                ((((((((((((((((((((((((((((( Fichiers créés 2008-07-23 to 2008-08-23 ))))))))))))))))))))))))))))))))))))
                .

                2008-08-23 18:58 . 2008-08-23 18:58 <REP> d-------- C:\Program Files\CCleaner
                2008-08-23 17:30 . 2008-08-23 17:33 <REP> d-------- C:\ToolBar SD
                2008-08-23 15:20 . 2008-08-23 15:20 <REP> d-------- C:\VundoFix Backups
                2008-08-23 13:51 . 2008-08-23 13:51 <REP> d-------- C:\Program Files\Enigma Software Group
                2008-08-17 13:50 . 2008-08-17 13:50 <REP> d-------- C:\DOCUME~1\admin\Application Data\ACD Systems
                2008-08-17 13:47 . 2008-08-17 13:47 <REP> d-------- C:\Program Files\Fichiers communs\ACD Systems
                2008-08-17 13:47 . 2008-08-17 13:47 <REP> d-------- C:\Program Files\ACD Systems
                2008-08-17 13:47 . 2008-08-17 13:47 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ACD Systems
                2008-08-17 13:46 . 2008-08-17 13:46 9,856 --a------ C:\WINDOWS\system32\drivers\pfc.sys

                .
                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                .
                2008-08-23 16:50 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
                2008-08-23 09:57 --------- d-----w C:\DOCUME~1\admin\Application Data\Azureus
                2008-08-23 09:15 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
                2008-08-22 22:11 --------- d-----w C:\Program Files\LogMeIn
                2008-08-22 21:02 --------- d-----w C:\Program Files\Spyware Doctor
                2008-07-07 07:50 --------- d-----w C:\Program Files\Azureus
                2006-10-12 16:17 3,072 ----a-w C:\Program Files\mozilla firefox\plugins\ractrlkeyhook.dll
                2006-02-13 11:07 245,408 ----a-w C:\Program Files\mozilla firefox\plugins\unicows.dll
                .

                ------- Sigcheck -------

                2006-03-09 10:25 578048 0df75fb73f705b011630159a43d7c354 C:\WINDOWS\system32\user32.dll

                2006-04-12 20:13 667648 241dbc4c2714b2f39afded49459ed420 C:\WINDOWS\system32\wininet.dll

                2006-02-14 21:56 359808 667192a11db19f36624119c0dd4de4f2 C:\WINDOWS\system32\drivers\tcpip.sys

                2006-05-09 10:11 2017280 50b3a210b6fa8d3089a36a32e7d8b21f C:\WINDOWS\system32\ntkrnlpa.exe

                2006-03-09 10:25 2137600 e75f7aa5a33479f29c636fd0890f5762 C:\WINDOWS\system32\ntoskrnl.exe

                2006-03-09 10:25 57856 da81ec57acd4cdc3d4c51cf3d409af9f C:\WINDOWS\system32\spoolsv.exe
                .
                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                .
                .
                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                REGEDIT4

                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 13:55 5674352]
                "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-29 15:55 68856]
                "PcSync"="C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" [2006-06-27 16:21 1449984]
                "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-19 17:09 15360]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-10-22 13:22 7700480]
                "LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-04-17 14:03 63048]
                "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 05:25 144784]
                "Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2007-08-25 11:44 1836544]
                "NSLauncher"="C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe" [2006-11-28 01:12 2658304]
                "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-07-19 19:45 266497]
                "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
                "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-04 15:18 267048]
                "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-03-02 02:22 185896]
                "ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 13:55 1103240]
                "Device Detector"="C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" [2005-06-27 10:21 221184]
                "nwiz"="nwiz.exe" [2006-10-22 13:22 1622016 C:\WINDOWS\system32\nwiz.exe]
                "NvMediaCenter"="NvMCTray.dll" [2006-10-22 13:22 86016 C:\WINDOWS\system32\nvmctray.dll]
                "RTHDCPL"="RTHDCPL.EXE" [2006-01-11 17:23 15961088 C:\WINDOWS\RTHDCPL.exe]

                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
                "NCInstallQueue"="netman.dll" [2006-03-09 10:25 197632 C:\WINDOWS\system32\netman.dll]

                C:\DOCUME~1\ALLUSE~1\Menu D‚marrer\Programmes\D‚marrage\
                Acc‚l‚rateur de d‚marrage AutoCAD.lnk - C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe [2004-02-25 04:35:22 10872]
                Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2007-12-29 00:19:35 40048]
                Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-23 01:01:50 734872]
                Outil de mise … jour Google.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-05-29 15:55:41 125624]

                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                "MemCheckBoxInRunDlg"= 1 (0x1)
                "NoSMBalloonTip"= 1 (0x1)
                "NoDesktopCleanupWizard"= 1 (0x1)
                "NoWelcomeScreen"= 1 (0x1)
                "NoStrCmpLogical"= 0 (0x0)
                "NoInstrumentation"= 0 (0x0)

                [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
                "MemCheckBoxInRunDlg"= 1 (0x1)
                "NoSMBalloonTip"= 1 (0x1)
                "NoDesktopCleanupWizard"= 1 (0x1)
                "NoWelcomeScreen"= 1 (0x1)

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
                2008-01-04 01:20 87352 C:\WINDOWS\system32\LMIinit.dll

                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                "VIDC.ACDV"= ACDV.dll

                [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                "AntiVirusOverride"=dword:00000001
                "FirewallOverride"=dword:00000001
                "AntiVirusDisableNotify"=dword:00000001
                "UpdatesDisableNotify"=dword:00000001
                "DisablePagingExecutive"=dword:00000001
                "SecondLevelDataCache"=dword:00000200

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                "EnableFirewall"= 0 (0x0)
                "DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)

                [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                "%windir%\\system32\\sessmgr.exe"=
                "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                "C:\\Program Files\\MSN Messenger\\livecall.exe"=
                "C:\\Program Files\\iTunes\\iTunes.exe"=
                "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
                "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=

                R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\RaInfo.sys [2007-04-17 14:00]
                R2 LMIRfsDriver;LogMeIn Remote File System Driver;C:\WINDOWS\system32\drivers\LMIRfsDriver.sys [2007-04-05 11:55]
                S3 kwwalpgr;kwwalpgr;C:\DOCUME~1\admin\LOCALS~1\Temp\kwwalpgr.sys []
                S3 SMCWGU(SMC);SMCWUSB-G 802.11g Wireless USB 2.0 Adapter(SMC);C:\WINDOWS\system32\DRIVERS\SMCWGU.sys [2005-12-16 05:41]

                *Newly Created Service* - CATCHME

                [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{582610B8-E496-4813-993C-4B027173FE38}]
                C:\Program Files\PixiePack Codec Pack\InstallerHelper.exe
                .
                Contenu du dossier 'Scheduled Tasks/Tâches planifiées'

                2008-07-29 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
                - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 15:57]
                .
                - - - - ORPHANS REMOVED - - - -

                HKCU-Run-IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
                HKLM-Run-NBKeyScan - C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
                HKLM-Run-lphcglnj0e3cl - C:\WINDOWS\system32\lphcglnj0e3cl.exe
                HKLM-Run-SMrhcllnj0e3cl - C:\Program Files\rhcllnj0e3cl\rhcllnj0e3cl.exe

                **************************************************************************

                catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                Rootkit scan 2008-08-23 19:20:28
                Windows 5.1.2600 Service Pack 2 NTFS

                Balayage processus cachés ...

                Balayage caché autostart entries ...

                Balayage des fichiers cachés ...

                Scan terminé avec succès
                Les fichiers cachés: 0

                **************************************************************************
                .
                Temps d'accomplissement: 2008-08-23 19:23:52
                ComboFix-quarantined-files.txt 2008-08-23 17:23:45

                Pre-Run: 7,821,471,744 octets libres
                Post-Run: 7,809,339,392 octets libres

                164
                0
                1. Contributeur
                  ok on continu

                  Télécharge malwarebytes
                  http://www.malwarebytes.org/mbam/program/mbam-setup.exe
                  Une aide pour l'installation
                  http://www.swl1f.net/viewtopic.php?f=14&t=68

                  => Installe le
                  => Ensuite va en mode sans echec

                  Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
                  Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel

                  => Lance malwarebytes
                  => Coche "Executer un examen complet"
                  => Si tu es en présence d'une infection à la fin de l'examen clique sur "ok"
                  => Clique sur Supprimer la sélection
                  => Pour poster le rapport Clique sur l'onglet Rapports/Logs, sélectionne celui t'intéresse et clique sur Ouvrir
                  => Fait copier coller et poste le rapport

                  --------------------------

                  ensuite

                  * Télécharge CCleaner
                  https://filehippo.com/download_ccleaner/
                  => Aide toi de ce tuto pour l'utiliser
                  http://www.swl1f.net/viewtopic.php?f=14&t=69

                  --------------------------

                  Ensuite refais un nouveau HijackThis
                  0
                  1. merci vraiment pour ton aide... j'essaye
                    0
                    1. et voilou!

                      Malwarebytes' Anti-Malware 1.25
                      Version de la base de données: 1078
                      Windows 5.1.2600 Service Pack 2

                      02:46:20 24/08/2008
                      mbam-log-08-24-2008 (02-46-20).txt

                      Type de recherche: Examen complet (C:\|E:\|)
                      Eléments examinés: 90935
                      Temps écoulé: 2 hour(s), 54 minute(s), 19 second(s)

                      Processus mémoire infecté(s): 0
                      Module(s) mémoire infecté(s): 0
                      Clé(s) du Registre infectée(s): 1
                      Valeur(s) du Registre infectée(s): 3
                      Elément(s) de données du Registre infecté(s): 0
                      Dossier(s) infecté(s): 0
                      Fichier(s) infecté(s): 6

                      Processus mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Module(s) mémoire infecté(s):
                      (Aucun élément nuisible détecté)

                      Clé(s) du Registre infectée(s):
                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{014da6cb-189f-421a-88cd-07cfe51cff10} (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                      Valeur(s) du Registre infectée(s):
                      HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                      HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.

                      Elément(s) de données du Registre infecté(s):
                      (Aucun élément nuisible détecté)

                      Dossier(s) infecté(s):
                      (Aucun élément nuisible détecté)

                      Fichier(s) infecté(s):
                      C:\QooBox\Quarantine\C\WINDOWS\system32\blphcglnj0e3cl.scr.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\System Volume Information\_restore{A52419C6-9CDF-40C6-A643-0918985DF52B}\RP186\A0027771.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\System Volume Information\_restore{A52419C6-9CDF-40C6-A643-0918985DF52B}\RP186\A0027784.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\System Volume Information\_restore{A52419C6-9CDF-40C6-A643-0918985DF52B}\RP186\A0027791.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\System Volume Information\_restore{A52419C6-9CDF-40C6-A643-0918985DF52B}\RP186\A0027999.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      C:\System Volume Information\_restore{A52419C6-9CDF-40C6-A643-0918985DF52B}\RP187\A0028014.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                      0
                      1. Contributeur
                        Bonjour

                        pour la suite

                        fait un scan en ligne

                        avec bitdefender et colle le rapport

                        https://www.bitdefender.com/toolbox/

                        Scan à faire sous Internet Explorer

                        un tuto
                        http://pageperso.aol.fr/rginformatique/mapage/defender.htm

                        ensuite un nouveau rapport hijack stp
                        @+
                        0
                        1. j'arrive pas àà exporter le rapporde bitfender...
                          Il l'enregistre en .html mais quand j'ouvre la page c'est vide :-(
                          0
                          1. voici au moins hijack...

                            Logfile of Trend Micro HijackThis v2.0.2
                            Scan saved at 11:57:19, on 24/08/2008
                            Platform: Windows XP SP2 (WinNT 5.01.2600)
                            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                            Boot mode: Normal

                            Running processes:
                            C:\WINDOWS\System32\smss.exe
                            C:\WINDOWS\system32\winlogon.exe
                            C:\WINDOWS\system32\services.exe
                            C:\WINDOWS\system32\lsass.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\WINDOWS\System32\svchost.exe
                            C:\WINDOWS\system32\spoolsv.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            C:\WINDOWS\Explorer.EXE
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            C:\Program Files\Bonjour\mDNSResponder.exe
                            C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            C:\Program Files\LogMeIn\x86\RaMaint.exe
                            C:\Program Files\LogMeIn\x86\LogMeIn.exe
                            C:\WINDOWS\system32\nvsvc32.exe
                            C:\Program Files\Spyware Doctor\pctsAuxs.exe
                            C:\Program Files\Spyware Doctor\pctsSvc.exe
                            C:\Program Files\Spyware Doctor\pctsTray.exe
                            C:\WINDOWS\system32\svchost.exe
                            C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
                            C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                            C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
                            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                            C:\Program Files\iTunes\iTunesHelper.exe
                            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                            C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
                            C:\WINDOWS\RTHDCPL.EXE
                            C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
                            C:\Program Files\MSN Messenger\MsnMsgr.Exe
                            C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
                            C:\WINDOWS\system32\ctfmon.exe
                            C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                            C:\Program Files\iPod\bin\iPodService.exe
                            C:\PROGRA~1\FICHIE~1\Nokia\MPAPI\MPAPI3s.exe
                            C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
                            C:\Program Files\Mozilla Firefox\firefox.exe
                            C:\Program Files\internet explorer\iexplore.exe
                            C:\Program Files\MSN Messenger\usnsvc.exe
                            C:\Documents and Settings\admin\Bureau\HiJackThis.exe

                            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = french.ircfast.com/index.php?rvs=hompag
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                            R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
                            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                            O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\Plugins\RazaWebHook.dll
                            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                            O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
                            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                            O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
                            O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
                            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                            O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                            O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
                            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                            O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                            O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
                            O4 - HKLM\..\RunOnce: [NCInstallQueue] rundll32 netman.dll,ProcessQueue
                            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                            O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
                            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
                            O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
                            O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                            O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                            O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                            O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
                            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                            O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                            O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                            O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                            O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                            O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                            O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
                            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                            O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                            O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
                            O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
                            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                            O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                            O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                            O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
                            0
                            1. Contributeur
                              Va dans panneau de configuration ensuite sur ajout et suppression de programme et désinstalle
                              Shareaza

                              ensuite reposte un nouveau HijackThis stp

                              0
                              1. et voilou:-)

                                Logfile of Trend Micro HijackThis v2.0.2
                                Scan saved at 12:04:27, on 24/08/2008
                                Platform: Windows XP SP2 (WinNT 5.01.2600)
                                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                Boot mode: Normal

                                Running processes:
                                C:\WINDOWS\System32\smss.exe
                                C:\WINDOWS\system32\winlogon.exe
                                C:\WINDOWS\system32\services.exe
                                C:\WINDOWS\system32\lsass.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\WINDOWS\System32\svchost.exe
                                C:\WINDOWS\system32\spoolsv.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                C:\WINDOWS\Explorer.EXE
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                C:\Program Files\Bonjour\mDNSResponder.exe
                                C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                C:\Program Files\LogMeIn\x86\RaMaint.exe
                                C:\Program Files\LogMeIn\x86\LogMeIn.exe
                                C:\WINDOWS\system32\nvsvc32.exe
                                C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                C:\Program Files\Spyware Doctor\pctsSvc.exe
                                C:\Program Files\Spyware Doctor\pctsTray.exe
                                C:\WINDOWS\system32\svchost.exe
                                C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
                                C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
                                C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                C:\Program Files\iTunes\iTunesHelper.exe
                                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
                                C:\WINDOWS\RTHDCPL.EXE
                                C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
                                C:\Program Files\MSN Messenger\MsnMsgr.Exe
                                C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
                                C:\WINDOWS\system32\ctfmon.exe
                                C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                C:\Program Files\iPod\bin\iPodService.exe
                                C:\PROGRA~1\FICHIE~1\Nokia\MPAPI\MPAPI3s.exe
                                C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
                                C:\Program Files\Mozilla Firefox\firefox.exe
                                C:\Program Files\internet explorer\iexplore.exe
                                C:\Program Files\MSN Messenger\usnsvc.exe
                                C:\Documents and Settings\admin\Bureau\HiJackThis.exe

                                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = french.ircfast.com/index.php?rvs=hompag
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
                                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\Plugins\RazaWebHook.dll
                                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)
                                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
                                O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
                                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
                                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                                O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
                                O4 - HKLM\..\RunOnce: [NCInstallQueue] rundll32 netman.dll,ProcessQueue
                                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
                                O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
                                O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
                                O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                                O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                                O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
                                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
                                O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
                                O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
                                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                                O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
                                0
                                1. Contributeur
                                  tu ne la pas désinstaller

                                  Relance HijackThis et clique sur "Do a system scan only"
                                  Ensuite recherche ces lignes et coches les cases

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = french.ircfast.com/index.php?rvs=hompag
                                  O2 - BHO: Shareaza Web Download Hook - {0EEDB912-C5FA-486F-8334-57288578C627} - C:\Program Files\Shareaza\Plugins\RazaWebHook.dll
                                  O3 - Toolbar: (no name) - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - (no file)

                                  Une fois coché, ferme toutes les fenêtres et applications et clique sur "Fix checked"

                                  Télécharge OTMoveIt (de OldTimer) sur ton Bureau.
                                  http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
                                  clic double sur OTMoveIt.exe pour le lancer.
                                  copie la liste qui se trouve en citation ci-dessous,
                                  et colle-la dans le cadre de gauche de OTMoveIt :
                                  Paste List of Files/Folders to be moved.

                                  C:\Program Files\Shareaza
                                  EmptyTemp

                                  clique sur MoveIt! pour lancer la suppression.
                                  le résultat apparaîtra dans le cadre Results.
                                  clique sur Exit pour fermer.
                                  poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                                  il te sera peut-être demandé de faire redémarrer le PC pour achever la suppression.

                                  0
                                  1. C:\Program Files\Shareaza\Plugins moved successfully.
                                    C:\Program Files\Shareaza moved successfully.
                                    < EmptyTemp >
                                    File delete failed. C:\DOCUME~1\admin\LOCALS~1\Temp\~DFB98E.tmp scheduled to be deleted on reboot.
                                    Temp folders emptied.
                                    IE temp folders emptied.

                                    OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 08242008_121735

                                    Files moved on Reboot...
                                    C:\DOCUME~1\admin\LOCALS~1\Temp\~DFB98E.tmp moved successfully.
                                    0
                                    1. Contributeur
                                      très bien reposte un nouveau HijackThis et dit moi si tu as encore des soucis
                                      0
                                      1. Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 12:42:33, on 24/08/2008
                                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\WINDOWS\System32\smss.exe
                                        C:\WINDOWS\system32\winlogon.exe
                                        C:\WINDOWS\system32\services.exe
                                        C:\WINDOWS\system32\lsass.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\WINDOWS\System32\svchost.exe
                                        C:\WINDOWS\system32\spoolsv.exe
                                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                        C:\WINDOWS\Explorer.EXE
                                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                        C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        C:\Program Files\Bonjour\mDNSResponder.exe
                                        C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        C:\Program Files\LogMeIn\x86\RaMaint.exe
                                        C:\Program Files\LogMeIn\x86\LogMeIn.exe
                                        C:\WINDOWS\system32\nvsvc32.exe
                                        C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                        C:\Program Files\Spyware Doctor\pctsSvc.exe
                                        C:\Program Files\Spyware Doctor\pctsTray.exe
                                        C:\WINDOWS\system32\svchost.exe
                                        C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
                                        C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
                                        C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe
                                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                        C:\Program Files\iTunes\iTunesHelper.exe
                                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                                        C:\WINDOWS\RTHDCPL.EXE
                                        C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe
                                        C:\Program Files\MSN Messenger\MsnMsgr.Exe
                                        C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
                                        C:\WINDOWS\system32\ctfmon.exe
                                        C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
                                        C:\Program Files\iPod\bin\iPodService.exe
                                        C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                        C:\PROGRA~1\FICHIE~1\Nokia\MPAPI\MPAPI3s.exe
                                        C:\Program Files\Mozilla Firefox\firefox.exe
                                        C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
                                        C:\Documents and Settings\admin\Bureau\HiJackThis.exe

                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://login.live.com/ppsecure/sha1auth.srf?lc=1036
                                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                                        O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                        O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit
                                        O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
                                        O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                                        O4 - HKLM\..\Run: [NSLauncher] C:\Program Files\Nokia\Nokia Software Launcher\NSLauncher.exe /startup
                                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                        O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                                        O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
                                        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                        O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Fichiers communs\ACD Systems\FR\DevDetect.exe" -autorun
                                        O4 - HKLM\..\RunOnce: [NCInstallQueue] rundll32 netman.dll,ProcessQueue
                                        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                                        O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                        O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
                                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                        O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
                                        O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
                                        O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
                                        O4 - Global Startup: Accélérateur de démarrage AutoCAD.lnk = C:\Program Files\Fichiers communs\Autodesk Shared\acstart16.exe
                                        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
                                        O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
                                        O4 - Global Startup: Outil de mise à jour Google.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
                                        O8 - Extra context menu item: Download with &Shareaza - res://C:\Program Files\Shareaza\Plugins\RazaWebHook.dll/3000
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
                                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
                                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
                                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                        O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                        O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                        O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                        O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe
                                        O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                        O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                        O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                        O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
                                        O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
                                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                        O23 - Service: PC Tools Auxiliary Service (sdauxservice) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
                                        O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
                                        O23 - Service: ServiceLayer - Nokia. - C:\Program Files\Fichiers communs\PCSuite\Services\ServiceLayer.exe
                                        0
                                        • 1
                                        • 2