Virus Smart Antivirus 2009

Destroyer0701 Messages postés 43 Statut Membre -  
sKe69 Messages postés 21955 Statut Contributeur sécurité -
Bonjour,

Cette apr-s-midi tout d'un coup j'ai eu c virus Smart Antivirus 2009

Donc j'ai passé Spybot, il m'a trouvais plusieur truc d'un coup, un trojan et encore ce virus là queje vous parle.

li m'en a supprimé une partie mais pas tout et je passe donc mon antivirus qui est Symantec Corporate Edition 10.0 je crois et il m'en trouve 23 des virus et m'en vire que 4 sur 23...

Et je décide donc je refémarrer l'ordi et là quelques secondes après avoir accès OU non accès(resté à l'endroit où l'ont doit mettre mon mot de passe) a mon bureau , lordi m'affiche un écran bleu en disant des truc en anglais notamentcomme quoi :

Windows a détecté une error et il arrète windows avant que cela soit pire et il me dise de faire une restauration system qui fonctionne mais ne m'arrange pas l'ordi (toujours le rédémarrage prsent puis écran bleu)

Et encore un message écrit dessus :

Technical information : STOP : 0x0000000A (0x00000000, 0x00000002, 0x00000001, 0x8224E7E0)

Donc voilà mon ordinateur ne fonctonne plus et j'aurais voulu ne pas le formater ....

Merci beaucoup de votre aide car là je suis désespéré au point de croire que l'ordinateur ne marchera plus même avec les cd de réinstallation !

Romain
Configuration: Windows Vista
Internet Explorer 7.0

59 réponses

  • 1
  • 2
  • 3
Résumé de la discussion

Une infection virale importante survient après l'apparition d'un écran bleu STOP 0x0000000A et le déploiement d'erreurs Windows sur un système Windows Vista, malgré des détections par plusieurs antivirus. Des solutions proposées incluent des scans en ligne (BitDefender Online) et des outils de collecte système (RSIT, HijackThis) pour identifier les éléments malveillants et préparer le nettoyage. Des recommandations mentionnent aussi la possibilité de restaurer le système ou de formater si la réparation ne suffit pas, afin de repartir sur une base propre. Pour limiter les risques de réinfection, il peut être nécessaire de réinstaller les pilotes critiques et d'appliquer rapidement les mises à jour de sécurité après le formatage.

Bobot (l'IA à votre service)
  1. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    Salut,

    protocole à suivre pour Windows Vista :

    *Désactiver le contrôle des comptes utilisateurs ou UAC (le réactiver seulement à la fin de la désinfection) :

    Aller dans "démarrer" puis "panneau de configuration" :
    --->Sur la droite de la fenêtre , cliques sur " affichage classique "
    --->Double-Cliquer sur l'icône "Comptes d'utilisateurs"
    --->Cliquer ensuite sur "Activer ou désactiver le contrôle ..." .
    --->Décocher la case "utlisiser le contrôle ..." et cliquer sur OK .
    Puis redémarrer le PC quand il le vous saura demandé ...

    Tuto : https://forum.malekal.com/viewtopic.php?f=59&t=6517

    * Important :
    Pour installer ou pour lancer les outils, que tu utiliseras au court de la désinfection, fait toujours ainsi :
    cliques DROIT ( sur le setup d'installe ou l'outil )-> choisis " Exécuter entant qu'administrateur " .
    Fais ce-ci systématiquement ! ...

    Une fois ceci fais et pris en compte , fais ce qui suit :

    Télécharges et installes le logiciel HijackThis :

    ici ftp://ftp.commentcamarche.com/download/HJTInstall.exe
    ou ici http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe
    ou ici https://www.clubic.com/telecharger-fiche17891-hijackthis.html

    1- Cliques sur le setup pour lancer l'installe : laisses toi guider et ne modifies pas les paramètres d'installation .
    A la fin de l'installe , le prg ce lance automatiquement : fermes le en cliquant sur la croix rouge .
    Au final, tu dois avoir un raccourci sur ton bureau et aussi un cheminement comme :
    "C:\ program files\Trend Micro\HijackThis\HijackThis.exe " .

    tuto pour utilisation :
    Regardes ici, c'est parfaitement expliqué en images (merci balltrap34),
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
    ( Ne fixes encore AUCUNE ligne, cela pourrait empêcher ton PC de fonctionner correctement )

    2- !! Déconnectes toi et fermes toute tes applications en cours !!

    Cliques sur le raccourci du bureau pour lancer le prg :
    fais un scan HijackThis en cliquant sur : "Do a system scan and save a logfile"

    ---> Postes le rapport généré pour analyse ...
    0
  2. Destroyer0701 Messages postés 43 Statut Membre
     
    Voilà le tout fait en mode sans échec ...

    Et je copie a chaque fois tout sur un autre ordi avec un DDexterne vu que je n'ai pa accès a internet :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:45:51, on 04/10/2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Safe mode

    Running processes:
    C:\Windows\Explorer.EXE
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.243.124.114:80
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
    O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
    O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O8 - Extra context menu item: &Download All with Rapidshare Downloader - C:\Users\Romain\AppData\Local\Temp\RarSFX0\jc_all.htm
    O8 - Extra context menu item: &Download with Rapidshare Downloader - C:\Users\Romain\AppData\Local\Temp\RarSFX0\jc_link.htm
    O8 - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Ajouter à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O13 - Gopher Prefix:
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - https://www.systemrequirementslab.com/cyri
    O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
    O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O20 - AppInit_DLLs: acaptuser32.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
    O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe
    O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
    O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
    O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\stacsv.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
    O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
    O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
    O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
    O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    0
  3. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    Re,

    il me faut le rapport fais en mode NORMAL stp ... recommences merci ... ;)
    0
  4. Destroyer0701 Messages postés 43 Statut Membre
     
    j'ai écrit en haut que en mode normale l'ordinateur ne marche pas plus de 10 seconde après j'ai un message d'erreur sur fond Bleu qui s'affiche et hop l'ordinateur se redémarre tout seul ....

    Je sais pas comment faire là je suis vraiment bloqué

    j'ai l'impression il anque un fichier pour faire fonctionner windows je sais pas du tout

    Merci de ton aide
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    ok .... Fais ce qui suit :

    Télécharges SmitfraudFix (de S!Ri, balltrap34 et moe31 ) :
    http://siri.urz.free.fr/Fix/SmitfraudFix.exe

    Installes le soft sur ton bureau ( et pas ailleurs! ) .

    !! Déconnectes toi, fermes toute tes applications et désactives tes défenses ( anti-virus ,anti-spyware,...) le temps de la manipe !!

    Tuto ( aide ) : http://siri.urz.free.fr/Fix/SmitfraudFix.php

    Utilisation ---> option 1 / Recherche :
    Double cliques sur l'icône "Smitfraudfix.exe" et sélectionnes 1 (et pas sur autre chose sans notre accord !) pour créer un rapport des fichiers responsables de l'infection.

    Postes le rapport ( "rapport.txt" qui se trouve sous C\: ) et attends la suite ...

    (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool". Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité.)
    0
  7. Destroyer0701 Messages postés 43 Statut Membre
     
    Voilà le rapport toujours en "mode sans échec" :

    SmitFraudFix v2.356

    Scan done at 21:26:49,87, 04/10/2008
    Run from C:\Users\Romain\Desktop\SmitfraudFix
    OS: Microsoft Windows [version 6.0.6001] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» Process

    C:\Windows\system32\csrss.exe
    C:\Windows\system32\csrss.exe
    C:\Windows\system32\wininit.exe
    C:\Windows\system32\winlogon.exe
    C:\Windows\system32\services.exe
    C:\Windows\system32\lsass.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\System32\svchost.exe
    C:\Windows\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\Windows\system32\svchost.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\cmd.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    hosts file corrupted !

    127.0.0.1 www.legal-at-spybot.info
    127.0.0.1 legal-at-spybot.info

    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Romain

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Romain\Application Data

    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Romain\FAVORI~1

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
    !!!Attention, following keys are not inevitably infected!!!

    o4Patch
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
    !!!Attention, following keys are not inevitably infected!!!

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
    !!!Attention, following keys are not inevitably infected!!!

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
    !!!Attention, following keys are not inevitably infected!!!

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
    !!!Attention, following keys are not inevitably infected!!!

    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"="acaptuser32.dll"

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "Userinit"="C:\\Windows\\system32\\userinit.exe,"
    "System"=""

    »»»»»»»»»»»»»»»»»»»»»»»» RK

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{7609C7B4-B65D-48EC-A005-6790C5C4548D}: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{B1D253E1-0545-40A2-9B07-897D366BA524}: DhcpNameServer=82.216.111.122 82.216.111.123
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{7609C7B4-B65D-48EC-A005-6790C5C4548D}: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{B1D253E1-0545-40A2-9B07-897D366BA524}: DhcpNameServer=82.216.111.122 82.216.111.123
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{7609C7B4-B65D-48EC-A005-6790C5C4548D}: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{B1D253E1-0545-40A2-9B07-897D366BA524}: DhcpNameServer=82.216.111.122 82.216.111.123
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1

    »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

    »»»»»»»»»»»»»»»»»»»»»»»» End
    0
  8. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    Bien ...

    uite de la manipe ( nettoyage ), fais exactement ce qui suit :

    Impératif : Démarrer en mode sans echec .

    /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

    Comment aller en Mode sans échec :
    1) Redémarres ton ordi .
    2) Tapotes la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
    3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
    4) Choisis la première option : Sans Échec , et valides en tapant sur [Entrée] .
    5) Choisis ton compte habituel ( et pas Administrateur ).
    attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...

    * Double-cliques sur SmitfraudFix.exe

    * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

    --> Si besion :

    * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presser Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

    ( Le correctif déterminera si le fichier wininet.dll est infecté.)

    * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
    pour remplacer le fichier corrompu.

    * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

    Le rapport se trouve à la racine de C\:
    (dans le fichier "rapport.txt")

    Postes moi ce dernier rapport accompagné ( Pour le chapitre" hosts " du rapport, postes seulement le début car il est trop long sinon ...).
    Postes aussi un nouveau rapport hijackthis ( Re-essayes en mode normal si possible ) et attends les instructions ...
    0
  9. Destroyer0701 Messages postés 43 Statut Membre
     
    SmitFraudFix v2.356

    Scan done at 21:40:16,78, 04/10/2008
    Run from C:\Users\Romain\Desktop\SmitfraudFix
    OS: Microsoft Windows [version 6.0.6001] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    127.0.0.1 localhost
    ::1 localhost
    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com
    127.0.0.1 www.100888290cs.com
    127.0.0.1 100888290cs.com
    127.0.0.1 www.100sexlinks.com
    127.0.0.1 100sexlinks.com
    127.0.0.1 www.10sek.com
    127.0.0.1 10sek.com
    127.0.0.1 www.123topsearch.com
    127.0.0.1 123topsearch.com
    127.0.0.1 www.132.com
    127.0.0.1 132.com
    127.0.0.1 www.136136.net
    127.0.0.1 136136.net
    127.0.0.1 www.163ns.com
    127.0.0.1 163ns.com
    127.0.0.1 171203.com
    127.0.0.1 17-plus.com
    127.0.0.1 www.1800searchonline.com
    127.0.0.1 1800searchonline.com
    127.0.0.1 www.180searchassistant.com
    127.0.0.1 180searchassistant.com
    127.0.0.1 www.180solutions.com
    127.0.0.1 180solutions.com
    127.0.0.1 www.181.365soft.info
    127.0.0.1 181.365soft.info
    127.0.0.1 www.1987324.com
    127.0.0.1 1987324.com
    127.0.0.1 www.1-domains-registrations.com
    127.0.0.1 1-domains-registrations.com
    127.0.0.1 www.1sexparty.com
    127.0.0.1 1sexparty.com
    127.0.0.1 www.1stantivirus.com
    127.0.0.1 1stantivirus.com
    127.0.0.1 www.1stpagehere.com
    127.0.0.1 1stpagehere.com
    127.0.0.1 www.1stsearchportal.com
    127.0.0.1 1stsearchportal.com
    127.0.0.1 2.82211.net
    127.0.0.1 www.2006ooo.com
    127.0.0.1 2006ooo.com
    127.0.0.1 www.2007-download.com
    127.0.0.1 2007-download.com
    127.0.0.1 www.2008-search-destroy.com
    127.0.0.1 2008-search-destroy.com
    127.0.0.1 www.2020search.com
    127.0.0.1 2020search.com
    127.0.0.1 20x2p.com
    127.0.0.1 www.24.365soft.info
    127.0.0.1 24.365soft.info
    127.0.0.1 www.24-7pharmacy.info
    127.0.0.1 24-7pharmacy.info
    127.0.0.1 www.24-7searching-and-more.com
    127.0.0.1 24-7searching-and-more.com
    127.0.0.1 www.24teen.com
    127.0.0.1 24teen.com
    127.0.0.1 2ndpower.com
    127.0.0.1 www.2search.com
    127.0.0.1 2search.com
    127.0.0.1 www.2search.org
    127.0.0.1 2search.org
    127.0.0.1 www.2squared.com
    127.0.0.1 2squared.com
    127.0.0.1 www.3322.org
    127.0.0.1 3322.org
    127.0.0.1 365soft.info
    127.0.0.1 www.36site.com
    127.0.0.1 36site.com
    127.0.0.1 3721.com
    127.0.0.1 39-93.com
    127.0.0.1 www.3bay.it
    127.0.0.1 3bay.it
    127.0.0.1 www.3xclipsonline.com
    127.0.0.1 3xclipsonline.com
    127.0.0.1 www.3xcurves.com
    127.0.0.1 3xcurves.com
    127.0.0.1 www.3xfestival.com
    127.0.0.1 3xfestival.com
    127.0.0.1 www.3x-festival.com
    127.0.0.1 3x-festival.com
    127.0.0.1 www.3x-galls.com
    127.0.0.1 3x-galls.com
    127.0.0.1 www.3xmiracle.com
    127.0.0.1 3xmiracle.com
    127.0.0.1 www.3xmoviesblog.com
    127.0.0.1 3xmoviesblog.com
    127.0.0.1 www.404dns.com
    127.0.0.1 404dns.com
    127.0.0.1 www.4199.com
    127.0.0.1 4199.com
    127.0.0.1 www.4corn.net
    127.0.0.1 4corn.net
    127.0.0.1 www.4ebay.it
    127.0.0.1 4ebay.it
    127.0.0.1 4klm.com
    127.0.0.1 www.4mpg.com
    127.0.0.1 4mpg.com
    127.0.0.1 www.59cn.cn
    127.0.0.1 59cn.cn
    127.0.0.1 www.5zgmu7o20kt5d8yq.com
    127.0.0.1 5zgmu7o20kt5d8yq.com
    127.0.0.1 www.680180.net
    127.0.0.1 680180.net
    127.0.0.1 www.6sek.com
    127.0.0.1 6sek.com
    127.0.0.1 www.70-music.com
    127.0.0.1 70-music.com
    127.0.0.1 www.7322.com
    127.0.0.1 7322.com
    127.0.0.1 www.745970.com
    127.0.0.1 745970.com
    127.0.0.1 75tz.com
    127.0.0.1 www.777search.com
    127.0.0.1 777search.com
    127.0.0.1 www.777top.com
    127.0.0.1 777top.com
    127.0.0.1 www.7939.com
    127.0.0.1 7939.com
    127.0.0.1 www.7search.com
    127.0.0.1 7search.com
    127.0.0.1 80gw6ry3i3x3qbrkwhxhw.032439.com
    127.0.0.1 www.80-music.com
    127.0.0.1 80-music.com
    127.0.0.1 82211.net
    127.0.0.1 8866.org
    127.0.0.1 www.88vcd.com
    127.0.0.1 88vcd.com
    127.0.0.1 www.8ad.com
    127.0.0.1 8ad.com
    127.0.0.1 www.90-music.com
    127.0.0.1 90-music.com
    127.0.0.1 www.9505.com
    127.0.0.1 9505.com
    127.0.0.1 www.971searchbox.com
    127.0.0.1 971searchbox.com
    127.0.0.1 9mmporn.com
    127.0.0.1 a.bestmanage.org
    127.0.0.1 www.aaabesthomepage.com
    127.0.0.1 aaabesthomepage.com
    127.0.0.1 aaasexypics.com
    127.0.0.1 www.aaawebfinder.com
    127.0.0.1 aaawebfinder.com
    127.0.0.1 www.aaqadarsztriv.com
    127.0.0.1 aaqadarsztriv.com
    127.0.0.1 www.aaqada-rsztriv.com
    127.0.0.1 aaqada-rsztriv.com
    127.0.0.1 www.aaqadaueorn.com
    127.0.0.1 aaqadaueorn.com
    127.0.0.1 www.aaqada-ueorn.com
    127.0.0.1 aaqada-ueorn.com
    127.0.0.1 www.aaqada-ygco.com
    127.0.0.1 aaqada-ygco.com
    127.0.0.1 www.aaqada-ymct.com
    127.0.0.1 aaqada-ymct.com
    127.0.0.1 www.aav2008.com
    127.0.0.1 aav2008.com
    127.0.0.1 aavc.com
    127.0.0.1 www.abccodec.com
    127.0.0.1 abccodec.com
    127.0.0.1 www.abcdperformance.com
    127.0.0.1 abcdperformance.com
    127.0.0.1 www.abc-find.info
    127.0.0.1 abc-find.info
    127.0.0.1 www.abcsearch.com
    127.0.0.1 abcsearch.com
    127.0.0.1 www.abcways.com
    127.0.0.1 abcways.com
    127.0.0.1 www.abetterinternet.com
    127.0.0.1 abetterinternet.com
    127.0.0.1 www.abnetsoft.info
    127.0.0.1 abnetsoft.info
    127.0.0.1 www.about-adult.net
    127.0.0.1 about-adult.net
    127.0.0.1 www.aboutclicker.com
    127.0.0.1 aboutclicker.com
    127.0.0.1 www.abrp.net
    127.0.0.1 abrp.net
    127.0.0.1 www.absolutee.com
    127.0.0.1 absolutee.com
    127.0.0.1 www.abyssmedia.com
    127.0.0.1 abyssmedia.com
    127.0.0.1 www.ac66.cn
    127.0.0.1 ac66.cn
    127.0.0.1 access.navinetwork.com
    127.0.0.1 access.rapid-pass.net
    127.0.0.1 www.accessactivexvideo.com
    127.0.0.1 accessactivexvideo.com
    127.0.0.1 www.accessclips.com
    127.0.0.1 accessclips.com
    127.0.0.1 www.access-dvd.com
    127.0.0.1 access-dvd.com
    127.0.0.1 www.accesskeygenerator.com
    127.0.0.1 accesskeygenerator.com
    127.0.0.1 www.accessthefuture.net
    127.0.0.1 accessthefuture.net
    127.0.0.1 www.accessvid.net
    127.0.0.1 accessvid.net
    127.0.0.1 www.acemedic.com
    127.0.0.1 acemedic.com
    127.0.0.1 www.ace-webmaster.com
    127.0.0.1 ace-webmaster.com
    127.0.0.1 acjp.com
    127.0.0.1 www.acrobat-2007.com
    127.0.0.1 acrobat-2007.com
    127.0.0.1 www.acrobat-8.com
    127.0.0.1 acrobat-8.com
    127.0.0.1 www.acrobat-center.com
    127.0.0.1 acrobat-center.com
    127.0.0.1 www.acrobat-hq.com
    127.0.0.1 acrobat-hq.com
    127.0.0.1 www.acrobatreader-8.com
    127.0.0.1 acrobatreader-8.com
    127.0.0.1 www.acrobat-reader-8.de
    127.0.0.1 acrobat-reader-8.de
    127.0.0.1 www.acrobat-stop.com
    127.0.0.1 acrobat-stop.com
    127.0.0.1 www.actionbreastcancer.org
    127.0.0.1 actionbreastcancer.org
    127.0.0.1 www.activesearcher.info
    127.0.0.1 activesearcher.info
    127.0.0.1 www.activexaccessobject.com
    127.0.0.1 activexaccessobject.com
    127.0.0.1 www.activexaccessvideo.com
    127.0.0.1 activexaccessvideo.com
    127.0.0.1 www.activexemedia.com
    127.0.0.1 activexemedia.com
    127.0.0.1 www.activexmediaobject.com
    127.0.0.1 activexmediaobject.com
    127.0.0.1 www.activexmediapro.com
    127.0.0.1 activexmediapro.com
    127.0.0.1 www.activexmediasite.com
    127.0.0.1 activexmediasite.com
    127.0.0.1 www.activexmediasoftware.com
    127.0.0.1 activexmediasoftware.com
    127.0.0.1 www.activexmediasource.com
    127.0.0.1 activexmediasource.com
    127.0.0.1 www.activexmediatool.com
    127.0.0.1 activexmediatool.com
    127.0.0.1 www.activexmediatour.com
    127.0.0.1 activexmediatour.com
    127.0.0.1 www.activexsoftwares.com
    127.0.0.1 activexsoftwares.com
    127.0.0.1 www.activexsource.com
    127.0.0.1 activexsource.com
    127.0.0.1 www.activexupdate.com
    127.0.0.1 activexupdate.com
    127.0.0.1 www.activexvideo.com
    127.0.0.1 activexvideo.com
    127.0.0.1 www.activexvideotool.com
    127.0.0.1 activexvideotool.com
    127.0.0.1 www.ad.marketingsector.com
    127.0.0.1 ad.marketingsector.com
    127.0.0.1 www.ad.mokead.com
    127.0.0.1 ad.mokead.com
    127.0.0.1 ad.oinadserver.com
    127.0.0.1 ad.outerinfoads.com
    127.0.0.1 www.ad25.com
    127.0.0.1 ad25.com
    127.0.0.1 www.ad45.com
    127.0.0.1 ad45.com
    127.0.0.1 www.ad77.com
    127.0.0.1 ad77.com
    127.0.0.1 www.ad86.com
    127.0.0.1 ad86.com
    127.0.0.1 www.adamsupportgroup.org
    127.0.0.1 adamsupportgroup.org
    127.0.0.1 www.adarmor.com
    127.0.0.1 adarmor.com
    127.0.0.1 www.adasearch.com
    127.0.0.1 adasearch.com
    127.0.0.1 adaware.cc
    127.0.0.1 www.adawarenow.com
    127.0.0.1 adawarenow.com
    127.0.0.1 adchannel.contextplus.net
    127.0.0.1 www.addetect.com
    127.0.0.1 addetect.com
    127.0.0.1 www.add-hhh.info
    127.0.0.1 add-hhh.info
    127.0.0.1 www.addictivetechnologies.com
    127.0.0.1 addictivetechnologies.com
    127.0.0.1 www.addictivetechnologies.net
    127.0.0.1 addictivetechnologies.net
    127.0.0.1 www.addioerrori.com
    127.0.0.1 addioerrori.com
    127.0.0.1 www.add-manager.com
    127.0.0.1 add-manager.com
    127.0.0.1 www.adgate.info
    127.0.0.1 adgate.info
    127.0.0.1 www.adintelligence.net
    127.0.0.1 adintelligence.net
    127.0.0.1 www.adioserrores.com
    127.0.0.1 adioserrores.com
    127.0.0.1 www.adipics.com
    127.0.0.1 adipics.com
    127.0.0.1 www.adlogix.com
    127.0.0.1 adlogix.com
    127.0.0.1 www.admin2cash.biz
    127.0.0.1 admin2cash.biz
    127.0.0.1 adnet-plus.com
    127.0.0.1 www.adnetserver.com
    127.0.0.1 adnetserver.com
    127.0.0.1 adobe-download-now.com
    127.0.0.1 www.adobe-downloads.com
    127.0.0.1 adobe-downloads.com
    127.0.0.1 www.adobe-reader-8.fr
    127.0.0.1 adobe-reader-8.fr
    127.0.0.1 www.adprotect.com
    127.0.0.1 adprotect.com
    127.0.0.1 ads.centralmedia.ws
    127.0.0.1 ads.k8l.info
    127.0.0.1 ads.kmpads.com
    127.0.0.1 ads.kw.revenue.net
    127.0.0.1 ads.marketingsector.com
    127.0.0.1 ads.searchingbooth.com
    127.0.0.1 ads.z-quest.com
    127.0.0.1 ads1.revenue.net
    127.0.0.1 www.ads183.com
    127.0.0.1 ads183.com
    127.0.0.1 www.adscontex.com
    127.0.0.1 adscontex.com
    127.0.0.1 www.adservices1.enhance.com
    127.0.0.1 adservices1.enhance.com
    127.0.0.1 adservs.com
    127.0.0.1 www.adsextend.net
    127.0.0.1 adsextend.net
    127.0.0.1 www.adshttp.com
    127.0.0.1 adshttp.com
    127.0.0.1 www.adsniffer.com
    127.0.0.1 adsniffer.com
    127.0.0.1 www.adsonwww.com
    127.0.0.1 adsonwww.com
    127.0.0.1 www.adspics.com
    127.0.0.1 adspics.com
    127.0.0.1 www.adsrevenue.net
    127.0.0.1 adsrevenue.net
    127.0.0.1 www.adtrak.net
    127.0.0.1 adtrak.net
    127.0.0.1 adtrgt.com
    127.0.0.1 www.adult18codec.com
    127.0.0.1 adult18codec.com
    127.0.0.1 www.adult777search.info
    127.0.0.1 adult777search.info
    127.0.0.1 www.adultan.com
    127.0.0.1 adultan.com
    127.0.0.1 www.adultcodec-2008.com
    127.0.0.1 adultcodec-2008.com
    127.0.0.1 www.adultcodecstars.com
    127.0.0.1 adultcodecstars.com
    127.0.0.1 www.adult-engine-search.com
    127.0.0.1 adult-engine-search.com
    127.0.0.1 www.adult-erotic-guide.net
    127.0.0.1 adult-erotic-guide.net
    127.0.0.1 www.adultfilmsite.com
    127.0.0.1 adultfilmsite.com
    127.0.0.1 www.adult-friends-finder.net
    127.0.0.1 adult-friends-finder.net
    127.0.0.1 adultgambling.org
    127.0.0.1 adult-host.org
    127.0.0.1 www.adulthyperlinks.com
    127.0.0.1 adulthyperlinks.com
    127.0.0.1 www.adultmovieplus.com
    127.0.0.1 adultmovieplus.com
    127.0.0.1 www.adult-mpg.net

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

    S!Ri's WS2Fix: LSP not Found.

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

    »»»»»»»»»»»»»»»»»»»»»»»» RK

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{7609C7B4-B65D-48EC-A005-6790C5C4548D}: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CCS\Services\Tcpip\..\{B1D253E1-0545-40A2-9B07-897D366BA524}: DhcpNameServer=82.216.111.122 82.216.111.123
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{7609C7B4-B65D-48EC-A005-6790C5C4548D}: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{B1D253E1-0545-40A2-9B07-897D366BA524}: DhcpNameServer=82.216.111.122 82.216.111.123
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{7609C7B4-B65D-48EC-A005-6790C5C4548D}: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{B1D253E1-0545-40A2-9B07-897D366BA524}: DhcpNameServer=82.216.111.122 82.216.111.123
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1

    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""

    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» End

    Je te le mets hijackthis en mode "sans echec " car il m'affiche toujours la même chose :

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:52:31, on 04/10/2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Safe mode

    Running processes:
    C:\Windows\Explorer.EXE
    C:\Windows\System32\WerFault.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\wbem\unsecapp.exe

    O8 - Extra context menu item: &Download All with Rapidshare Downloader - C:\Users\Romain\AppData\Local\Temp\RarSFX0\jc_all.htm
    O8 - Extra context menu item: &Download with Rapidshare Downloader - C:\Users\Romain\AppData\Local\Temp\RarSFX0\jc_link.htm
    O8 - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Ajouter à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O13 - Gopher Prefix:
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O20 - AppInit_DLLs: acaptuser32.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
    O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe
    O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
    O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
    O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\stacsv.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
    O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
    O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
    O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
    O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    0
  10. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    Ok ...

    fais ceci alors :

    Télécharges MalwareByte's :
    ici ftp://ftp.commentcamarche.com/download/mbam-setup.exe
    ou ici : http://www.malwarebytes.org/mbam.php

    Installes le ( choisis bien "francais" ; ne modifies pas les paramètres d'installe ) et mets le à jour .

    (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharges le ici : https://www.malekal.com/tutorial-aboutbuster/ )

    Potasses le tuto pour te familiariser avec le prg : https://forum.pcastuces.com/sujet.asp?f=31&s=3
    ( cela dis, il est très simple d'utilisation ).

    Impératif : Démarrer en mode sans echec .

    /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

    Comment aller en Mode sans échec :
    1) Redémarres ton ordi .
    2) Tapotes la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
    3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
    4) Choisis la première option : Sans Échec , et valides en tapant sur [Entrée] .
    5) Choisis ton compte habituel ( et pas Administrateur ).
    attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...

    Lances Malwarebyte's .

    Fais un scan dit "complet" ( sélectionnes bien tous tes disks avant le scan ! ) et supprimes tout ce qu'il peut trouver, c'est à dire :
    -->Laisses le scan se terminer,puis à la fin tu cliques sur "résultat" .
    -->Vérifies que tous les objets infectés soient validés, puis cliques sur " suppression " .

    Redémarres ton PC ( mode normal ).

    Postes le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date) accompagné d'un nouvel hijackthis ( fait en mode normal ) ...
    0
  11. Destroyer0701 Messages postés 43 Statut Membre
     
    Voici le rapport (j'avais déjà au paravant fonctionné Malwarebytes' .... là je l'ai refait avec ce nouveau rapport :

    Malwarebytes' Anti-Malware 1.28
    Version de la base de données: 1134
    Windows 6.0.6001 Service Pack 1

    04/10/2008 23:25:06
    mbam-log-2008-10-04 (23-25-06).txt

    Type de recherche: Examen rapide
    Eléments examinés: 43830
    Temps écoulé: 2 minute(s), 35 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)

    et il ne veux toujours pas resté plus de 10 seconde en mode normale donc je ne peux te donner le résultat hijackthis.

    MAIS JE SUIS PRESQUE SUR QUE J'AI DU SUPPRIME UN FICHIER SYSTEM QUAND J'AI VOULU MANUELLEMENT TOUT AU D2BUT SUPPRIME CE VIRUS ...

    PEUT TU ENCORE M'AIDER ET PEUT ON ENCORE REPARER CE PROBLEME ???

    MERCI bcp de ton aide pour vu que l'on y arrive !
    0
  12. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    Re,

    j'ai demandé un examen COMPLET et pas rapide .... :-/

    Type de recherche: Examen rapide
    Eléments examinés: 43830
    Temps écoulé: 2 minute(s), 35 second(s)


    Recommences stp ...
    0
  13. Destroyer0701 Messages postés 43 Statut Membre
     
    Je reffet mais je te copie ce que l'écran bleu m'affiche exactement car après traduction sa me fait peur :

    a probelm has been detected and windows has been shut down to prevent damage to you computer
    IRQL_NOT_LESS_OR_EQUAL
    IF this is the firs time you've seen this stop error screen, .........
    ......................................(................................).........................
    collecting data for crash dump...
    initializing disk for crash dump...
    beginning dump of physical memory.
    dumping physical memory to disk :100
    physical memory dump complete
    contact your system admin or technical support group for further assistance

    Sa veut dire quoi tout ça c'est grave ou quoi????

    meerci bien de votre aid je post le raport complt dès que possible
    0
  14. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    JE SUIS PRESQUE SUR QUE J'AI DU SUPPRIME UN FICHIER SYSTEM QUAND J'AI VOULU MANUELLEMENT TOUT AU D2BUT SUPPRIME CE VIRUS ...

    -> si tu ne peux pas me dire lequel exactement , cela ne m'avancera pas à grand chose ... ^^

    M'est d'avis que cette écran bleu est du aux malware ... mais une fois qu'on l'aura touché , cela devrai s'arranger ...

    J'attends donc les rapports demandés ... ;)
    0
  15. Destroyer0701 Messages postés 43 Statut Membre
     
    Malwarebytes' Anti-Malware 1.28
    Version de la base de données: 1134
    Windows 6.0.6001 Service Pack 1

    04/10/2008 23:15:38
    mbam-log-2008-10-04 (23-15-38).txt

    Type de recherche: Examen complet (C:\|I:\|)
    Eléments examinés: 203499
    Temps écoulé: 1 hour(s), 2 minute(s), 27 second(s)

    Processus mémoire infecté(s): 0
    Module(s) mémoire infecté(s): 0
    Clé(s) du Registre infectée(s): 0
    Valeur(s) du Registre infectée(s): 0
    Elément(s) de données du Registre infecté(s): 0
    Dossier(s) infecté(s): 0
    Fichier(s) infecté(s): 0

    Processus mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Module(s) mémoire infecté(s):
    (Aucun élément nuisible détecté)

    Clé(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Valeur(s) du Registre infectée(s):
    (Aucun élément nuisible détecté)

    Elément(s) de données du Registre infecté(s):
    (Aucun élément nuisible détecté)

    Dossier(s) infecté(s):
    (Aucun élément nuisible détecté)

    Fichier(s) infecté(s):
    (Aucun élément nuisible détecté)
    0
  16. Destroyer0701 Messages postés 43 Statut Membre
     
    j'ai supprimé des fichiers dans :

    AppData sous User;
    Temp;

    et c'est tout donc je sais pas si c'est des fichier qui sont important et pouvvant créer se problème seule toi peut me le dire :)

    Merci de ton aide
    0
  17. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    Bizard que MBAM ne trouve rien ...

    Donc fais ceci en mode sans échec donc :

    Télécharges ComboFix (par sUBs) sur ton Bureau :
    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    Impératif : Démarrer en mode sans echec .

    /!\ Ne jamais démarrer en mode sans échec via MSCONFIG /!\

    Comment aller en Mode sans échec :
    1) Redémarres ton ordi .
    2) Tapotes la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip" .
    3) Tu tapotes jusqu' à l'apparition de l'écran avec les options de démarrage .
    4) Choisis la première option : Sans Échec , et valides en tapant sur [Entrée] .
    5) Choisis ton compte habituel ( et pas Administrateur ).
    attention : pas de connexion possible en mode sans échec , donc copies ou imprimes bien la manipe pour éviter les erreurs ...

    *Double-cliquer combofix.exe pour lancer l'outil .

    *Appuyer sur la touche Y (Yes) pour démarrer le scan .

    Notes importantes :
    -> n'utilises pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne. Cela pourrait figer l'ordi .
    -> Il se peut que le PC redémarre de lui même ( pour finaliser le nettoyage ) , laisses le faire .
    -> Si l'outil t'anonce ceci : "combofix a détecté la présence de rootkit et a besoin de faire redémarer votre machine", tu acceptes ...
    -> si un message d'erreur windows apparait à un momment : cliques sur la croix rouge en haut à droite de la fenêtre pour la fermer ( et pas sur autre chose ! sinon pas de rapport ... )

    Le rapport sera crée dans C:\Combofix.txt

    Postes le rapport Combofix et un nouveau rapport Hijackthis pour analyse ...

    0
  18. Destroyer0701 Messages postés 43 Statut Membre
     
    ComboFix 08-10-04.01 - Romain 2008-10-05 0:06:40.1 - NTFSx86 MINIMAL
    Microsoft® Windows Vista™ Édition Familiale Premium 6.0.6001.1.1252.1.1036.18.1585 [GMT 2:00]
    Lancé depuis: C:\Users\Romain\Desktop\ComboFix.exe

    [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
    .

    ((((((((((((((((((((((((((((( Fichiers créés du 2008-09-04 au 2008-10-04 ))))))))))))))))))))))))))))))))))))
    .

    Pas de nouveau fichier créé dans ce laps de temps

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-10-04 19:40 691 ----a-w C:\Users\Romain\AppData\Roaming\GetValue.vbs
    2008-10-04 19:40 35 ----a-w C:\Users\Romain\AppData\Roaming\SetValue.bat
    2008-10-04 19:40 3,134 ----a-w C:\Windows\System32\tmp.reg
    2008-10-04 18:43 --------- d-----w C:\Program Files\Trend Micro
    2008-10-04 17:44 --------- d-----w C:\Program Files\Spybot - Search & Destroy
    2008-10-04 17:44 --------- d-----w C:\PROGRA~2\Spybot - Search & Destroy
    2008-10-04 17:04 --------- d-----w C:\Users\Romain\AppData\Roaming\Malwarebytes
    2008-10-04 17:04 --------- d-----w C:\Program Files\Malwarebytes' Anti-Malware
    2008-10-04 17:04 --------- d-----w C:\PROGRA~2\Malwarebytes
    2008-10-04 15:32 --------- d-----w C:\Program Files\Enigma Software Group
    2008-10-04 15:25 --------- d-----w C:\Program Files\BarreConfCMCIC
    2008-10-04 12:21 --------- d-----w C:\Users\Romain\AppData\Roaming\LimeWire
    2008-10-04 11:19 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2008-10-01 13:51 87,552 ----a-w C:\Windows\System32\VACFix.exe
    2008-09-22 17:53 --------- d-----w C:\PROGRA~2\NortonInstaller
    2008-09-19 10:26 82,944 ----a-w C:\Windows\System32\o4Patch.exe
    2008-09-19 10:26 82,944 ----a-w C:\Windows\System32\IEDFix.C.exe
    2008-09-16 17:16 --------- d-----w C:\PROGRA~2\WinZip
    2008-09-16 17:01 --------- d-----w C:\Program Files\7-Zip
    2008-09-14 14:34 --------- d-----w C:\Program Files\iTunes
    2008-09-14 14:34 --------- d-----w C:\Program Files\iPod
    2008-09-14 14:34 --------- d-----w C:\PROGRA~2\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
    2008-09-14 14:32 --------- d-----w C:\Program Files\Bonjour
    2008-09-14 14:31 --------- d-----w C:\Program Files\QuickTime
    2008-09-14 14:31 --------- d-----w C:\Program Files\Common Files\Apple
    2008-09-14 14:22 108,438 ----a-w C:\Users\Romain\AppData\Roaming\nvModes.dat
    2008-09-11 17:17 --------- d-----w C:\PROGRA~2\FLEXnet
    2008-09-11 16:29 --------- d-----w C:\Program Files\Common Files\Adobe
    2008-09-10 18:27 --------- d-----w C:\PROGRA~2\Microsoft Help
    2008-09-10 18:22 --------- d-----w C:\Program Files\Microsoft Works
    2008-09-09 22:04 38,528 ----a-w C:\Windows\system32\drivers\mbamswissarmy.sys
    2008-09-09 22:03 17,200 ----a-w C:\Windows\system32\drivers\mbam.sys
    2008-09-09 17:01 --------- d-----w C:\Program Files\Norton Ghost
    2008-09-09 17:01 --------- d-----w C:\Program Files\Common Files\Symantec Shared
    2008-09-09 17:01 --------- d-----w C:\PROGRA~2\Symantec
    2008-09-09 16:40 --------- d-----w C:\Users\Romain\AppData\Roaming\Symantec
    2008-09-09 15:44 --------- d---a-w C:\PROGRA~2\TEMP
    2008-09-09 14:34 --------- d-----w C:\Program Files\SystemRequirementsLab
    2008-09-08 21:38 88,576 ----a-w C:\Windows\System32\AntiXPVSTFix.exe
    2008-09-08 18:39 --------- d-----w C:\PROGRA~2\Roxio
    2008-09-07 14:00 --------- d-----w C:\Program Files\VirtualDJ
    2008-08-29 08:18 87,336 ----a-w C:\Windows\System32\dns-sd.exe
    2008-08-29 07:53 61,440 ----a-w C:\Windows\System32\dnssd.dll
    2008-08-27 21:33 130,208 ------r C:\Windows\bwUnin-8.1.1.87-8876480SL.exe
    2008-08-27 19:39 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-08-27 19:23 --------- d-----w C:\Program Files\Common Files\Logishrd
    2008-08-27 19:22 --------- d-----w C:\Program Files\Common Files\Logitech
    2008-08-18 19:19 --------- d-----w C:\Program Files\Microsoft Silverlight
    2008-08-18 10:19 82,432 ----a-w C:\Windows\System32\404Fix.exe
    2008-08-14 19:46 --------- d-----w C:\PROGRA~2\WLInstaller
    2008-08-14 19:02 --------- d-----w C:\Program Files\Symantec AntiVirus
    2008-08-13 21:06 --------- d-----w C:\Program Files\Everest Poker
    2008-08-12 23:07 --------- d-----w C:\Program Files\Windows Mail
    2008-08-12 20:28 --------- d-----w C:\Program Files\LimeWire
    2008-08-11 19:18 --------- d-----w C:\Users\Romain\AppData\Roaming\Microgaming
    2008-08-10 18:46 --------- d-----w C:\Program Files\Lecteur CANALPLAY
    2008-08-10 17:21 --------- d-----w C:\Program Files\DivX
    2008-08-10 17:21 --------- d-----w C:\Program Files\Common Files\PX Storage Engine
    2008-08-10 17:00 --------- d-----w C:\Users\Romain\AppData\Roaming\DNA
    2008-08-10 17:00 --------- d-----w C:\Users\Romain\AppData\Roaming\BitTorrent
    2008-08-10 16:16 --------- d-----w C:\Program Files\Godlike Developers
    2008-08-10 15:35 --------- d-----w C:\Program Files\Diskeeper Corporation
    2008-08-10 15:31 --------- d-----w C:\PROGRA~2\WindowsSearch
    2008-08-10 13:29 --------- d-----w C:\Program Files\Lavasoft
    2008-08-10 13:29 --------- d-----w C:\PROGRA~2\Lavasoft
    2008-08-05 14:44 --------- d-----w C:\Program Files\Apple Software Update
    2008-08-02 03:26 36,864 ----a-w C:\Windows\System32\cdd.dll
    2008-07-31 03:32 460,288 ----a-w C:\Windows\AppPatch\AcSpecfc.dll
    2008-07-31 03:32 28,160 ----a-w C:\Windows\System32\Apphlpdm.dll
    2008-07-31 03:32 2,154,496 ----a-w C:\Windows\AppPatch\AcGenral.dll
    2008-07-31 03:32 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll
    2008-07-31 01:13 4,240,384 ----a-w C:\Windows\System32\GameUXLegacyGDFs.dll
    2008-07-19 05:10 53,448 ----a-w C:\Windows\System32\wuauclt.exe
    2008-07-19 05:10 45,768 ----a-w C:\Windows\System32\wups2.dll
    2008-07-19 05:10 36,552 ----a-w C:\Windows\System32\wups.dll
    2008-07-19 05:09 563,912 ----a-w C:\Windows\System32\wuapi.dll
    2008-07-19 05:09 1,811,656 ----a-w C:\Windows\System32\wuaueng.dll
    2008-07-19 03:44 83,456 ----a-w C:\Windows\System32\wudriver.dll
    2008-07-19 03:44 1,524,736 ----a-w C:\Windows\System32\wucltux.dll
    2008-07-18 20:08 163,904 ----a-w C:\Windows\System32\wuwebv.dll
    2008-07-18 18:44 31,232 ----a-w C:\Windows\System32\wuapp.exe
    2008-07-16 01:32 2,048 ----a-w C:\Windows\System32\tzres.dll
    2008-03-29 16:49 174 --sha-w C:\Program Files\desktop.ini
    2008-03-15 11:13 23 --sha-w C:\Windows\System32\fceadad0_r.dll
    .

    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-10-15 115816]
    "vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2007-01-04 135216]
    "NvSvc"="C:\Windows\system32\nvsvc.dll" [2007-10-30 86016]
    "NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2007-10-30 8429568]
    "NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2007-10-30 81920]
    "Apoint"="C:\Program Files\Apoint\Apoint.exe" [2007-06-10 118784]
    "Adobe Acrobat Speed Launcher"="C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
    "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-11 640376]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
    "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-09-06 413696]
    "AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-09-03 111936]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-09-10 289576]
    "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-02-29 C:\Windows\KHALMNPR.Exe]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
    "GrpConv"="grpconv -o" [X]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
    "LogonHoursAction"= 2 (0x2)
    "DontDisplayLogonHoursWarnings"= 1 (0x1)
    "NoSecCpl"= 0 (0x0)
    "DisableChangePassword"= 0 (0x0)
    "DisableLockWorkstation"= 0 (0x0)

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\system]
    "LogonHoursAction"= 2 (0x2)
    "DontDisplayLogonHoursWarnings"= 1 (0x1)

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoStartMenuPinnedList"= 0 (0x0)
    "NoStartMenuMFUprogramsList"= 0 (0x0)
    "NoUserNameInStartMenu"= 0 (0x0)
    "NoStartMenuSubFolders"= 0 (0x0)
    "NoCommonGroups"= 0 (0x0)
    "NoPrinterTabs"= 0 (0x0)
    "NoDeletePrinter"= 0 (0x0)
    "NoAddPrinter"= 0 (0x0)
    "NoPrinters"= 0 (0x0)
    "NoFavoritesMenu"= 0 (0x0)
    "NoRecentDocsNetHood"= 0 (0x0)
    "NoChangeAnimation"= 0 (0x0)
    "NoChangeKeyboardNavigationIndicators"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
    2007-08-14 21:05 98304 C:\Windows\System32\VESWinlogon.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=acaptuser32.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "VIDC.dvsd"= C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AppInfo]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\KeyIso]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\NTDS]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ProfSvc]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sacsvr]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SWPRV]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TabletInputService]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TBS]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TrustedInstaller]
    @="Service"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgr.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\volmgrx.sys]
    @="Driver"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{6BDD1FC1-810F-11D0-BEC7-08002BE2092F}]
    @="IEEE 1394 Bus host controllers"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D48179BE-EC20-11D1-B6B8-00C04FA372A7}]
    @="SBP2 IEEE 1394 Devices"

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{D94EE5D8-D189-4994-83D2-F68D7D41B0E6}]
    @="SecurityDevices"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"="0x00000000"
    "UpdatesDisableNotify"="0x00000000"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    R0 CLFS;Common Log (CLFS);C:\Windows\system32\CLFS.sys [2008-01-19 247352]
    R0 Ecache;ReadyBoost Caching Driver;C:\Windows\system32\drivers\ecache.sys [2008-01-19 143416]
    R0 FileInfo;File Information FS MiniFilter;C:\Windows\system32\drivers\fileinfo.sys [2008-01-19 58936]
    R0 iaStorV;Intel RAID Controller Vista;C:\Windows\system32\drivers\iastorv.sys [2006-11-02 232040]
    R0 msisadrv;Pilote de classe ISA/EISA;C:\Windows\system32\drivers\msisadrv.sys [2008-01-19 16440]
    R0 volmgr;Pilote du Gestionnaire de volume;C:\Windows\system32\drivers\volmgr.sys [2008-01-19 52792]
    R0 volmgrx;Dynamic Volume Manager;C:\Windows\system32\drivers\volmgrx.sys [2008-01-19 294456]
    R2 ProfSvc;Service de profil utilisateur;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    R3 iScsiPrt;Pilote iScsiPort;C:\Windows\system32\DRIVERS\msiscsi.sys [2008-01-19 181304]
    R3 KeyIso;Isolation de clé CNG;C:\Windows\system32\lsass.exe [2008-01-19 9728]
    R3 SFEP;Sony Firmware Extension Parser;C:\Windows\system32\DRIVERS\SFEP.sys [2007-08-29 9344]
    R3 umbus;Pilote d’énumérateur UMBus;C:\Windows\system32\DRIVERS\umbus.sys [2008-01-19 34816]
    S0 spldr;Security Processor Loader Driver;C:\Windows\system32\drivers\spldr.sys [2008-01-19 21048]
    S1 DfsC;DFS Namespace Client Driver;C:\Windows\system32\Drivers\dfsc.sys [2008-01-19 75264]
    S1 nsiproxy;NSI proxy service;C:\Windows\system32\drivers\nsiproxy.sys [2008-01-19 16384]
    S1 RDPENCDD;RDP Encoder Mirror Driver;C:\Windows\system32\drivers\rdpencdd.sys [2008-01-19 6144]
    S1 Smb;Protocoles TCP/IP et TCP/IPv6 orienté messages (session SMB);C:\Windows\system32\DRIVERS\smb.sys [2008-01-19 66560]
    S1 tdx;Pilote de prise en charge TDI héritée NetIO;C:\Windows\system32\DRIVERS\tdx.sys [2008-01-19 71680]
    S1 Wanarpv6;Remote Access IPv6 ARP Driver;C:\Windows\system32\DRIVERS\wanarp.sys [2008-01-19 62464]
    S2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-11 124832]
    S2 AudioEndpointBuilder;Générateur de points de terminaison du service Audio Windows;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S2 BFE;Moteur de filtrage de base;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 DPS;Service de stratégie de diagnostic;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S2 EMDMgmt;Service ReadyBoost;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 FDResPub;Publication des ressources de découverte de fonctions;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 gpsvc;Client de stratégie de groupe;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 IKEEXT;Modules de génération de clés IKE et AuthIP;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 iphlpsvc;Assistance IP;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S2 KtmRm;Service KtmRm pour Distributed Transaction Coordinator;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S2 lltdio;Pilote d’E/S du mappage de découverte de topologie de la couche de liaison;C:\Windows\system32\DRIVERS\lltdio.sys [2008-01-19 47104]
    S2 luafv;UAC File Virtualization;C:\Windows\system32\drivers\luafv.sys [2008-01-19 84480]
    S2 MMCSS;Planificateur de classes multimédias;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 MpsSvc;Pare-feu Windows;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 netprofm;Service Liste des réseaux;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S2 NlaSvc;Connaissance des emplacements réseau;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S2 nsi;Service Interface du magasin réseau;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 PcaSvc;Service de l’Assistant Compatibilité des programmes;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 PEAUTH;PEAUTH;C:\Windows\system32\drivers\peauth.sys [2006-11-02 878080]
    S2 Roxio Upnp Server 10;Roxio Upnp Server 10;C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe [2007-08-24 362992]
    S2 RoxLiveShare10;LiveShare P2P Server 10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [2007-08-24 309744]
    S2 RoxWatch10;Roxio Hard Drive Watcher 10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [2007-08-24 166384]
    S2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-01-28 810320]
    S2 slsvc;Licence du logiciel;C:\Windows\system32\SLsvc.exe [2008-01-19 2623488]
    S2 SysMain;Superfetch;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 TabletInputService;Service Panneau de saisie Tablet PC;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S2 TBS;Services de base de module de plateforme sécurisée;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S2 tcpipreg;TCP/IP Registry Compatibility;C:\Windows\system32\drivers\tcpipreg.sys [2008-01-19 30208]
    S2 UxSms;Gestionnaire de sessions du Gestionnaire de fenêtrage;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2007-09-28 292128]
    S2 WerSvc;Service de rapport d'erreurs Windows;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S2 Wlansvc;Service de configuration automatique WLAN;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S2 WPDBusEnum;Service Énumérateur d’appareil mobile;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 Appinfo;Informations d'application;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 bowser;Bowser;C:\Windows\system32\DRIVERS\bowser.sys [2008-01-19 69632]
    S3 BrFiltLo;Brother USB Mass-Storage Lower Filter Driver;C:\Windows\system32\drivers\brfiltlo.sys [2006-11-02 13568]
    S3 BrFiltUp;Brother USB Mass-Storage Upper Filter Driver;C:\Windows\system32\drivers\brfiltup.sys [2006-11-02 5248]
    S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\Windows\system32\drivers\brusbser.sys [2006-11-02 11904]
    S3 btwaudio;Périphérique audio Bluetooth;C:\Windows\system32\drivers\btwaudio.sys [2007-10-10 81448]
    S3 btwavdt;Bluetooth AVDT Service;C:\Windows\system32\drivers\btwavdt.sys [2007-10-10 99880]
    S3 btwl2cap;Bluetooth L2CAP Service;C:\Windows\system32\DRIVERS\btwl2cap.sys [2007-10-10 28464]
    S3 btwrchid;btwrchid;C:\Windows\system32\DRIVERS\btwrchid.sys [2007-10-10 17448]
    S3 CertPropSvc;Propagation du certificat;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 DFSR;Réplication DFS;C:\Windows\system32\DFSR.exe [2008-01-19 2091520]
    S3 DXGKrnl;LDDM Graphics Subsystem;C:\Windows\system32\drivers\dxgkrnl.sys [2008-08-02 625152]
    S3 E1G60;Intel(R) PRO/1000 NDIS 6 Adapter Driver;C:\Windows\system32\DRIVERS\E1G60I32.sys [2006-11-02 117760]
    S3 fdPHost;Hôte du fournisseur de découverte de fonctions;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 Filetrace;FileTrace;C:\Windows\system32\drivers\filetrace.sys [2008-01-19 27648]
    S3 IPBusEnum;Énumérateur de bus IP PnP-X;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 lltdsvc;Mappage de découverte de topologie de la couche de liaison;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 monitor;Service Pilote de fonction de classe Moniteur Microsoft;C:\Windows\system32\DRIVERS\monitor.sys [2008-01-19 41984]
    S3 mpsdrv;Pilote d’autorisation du Pare-feu Windows;C:\Windows\system32\drivers\mpsdrv.sys [2008-01-19 64000]
    S3 mrxsmb10;SMB 1.x MiniRedirector;C:\Windows\system32\DRIVERS\mrxsmb10.sys [2008-05-08 211968]
    S3 mrxsmb20;SMB 2.0 MiniRedirector;C:\Windows\system32\DRIVERS\mrxsmb20.sys [2008-01-19 78848]
    S3 MSiSCSI;Service Initiateur iSCSI de Microsoft;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 MsRPC;MsRPC;C:\Windows\system32\drivers\MsRPC.sys [2008-01-19 163384]
    S3 NativeWifiP;Filtre NativeWiFi;C:\Windows\system32\DRIVERS\nwifi.sys [2008-05-20 148480]
    S3 p2pimsvc;Gestionnaire d'identité réseau homologue;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 p2psvc;Groupement de mise en réseau de pairs;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 pla;Journaux & alertes de performance;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 PNRPAutoReg;Service de publication des noms d’ordinateurs PNRP;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 PNRPsvc;Protocole de résolution de noms d'homologues;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 QWAVE;Expérience audio-vidéo haute qualité Windows;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 QWAVEdrv;Pilote QWAVE;C:\Windows\system32\drivers\qwavedrv.sys [2008-01-19 31232]
    S3 R5U870FLx86;R5U870 UVC Lower Filter ;C:\Windows\system32\Drivers\R5U870FLx86.sys [2007-10-30 75008]
    S3 R5U870FUx86;R5U870 UVC Upper Filter ;C:\Windows\system32\Drivers\R5U870FUx86.sys [2007-10-30 43904]
    S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [2007-08-24 72176]
    S3 RoxMediaDB10;RoxMediaDB10;C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2007-08-24 1083888]
    S3 SCPolicySvc;Stratégie de retrait de la carte à puce;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 SDRSVC;Sauvegarde Windows;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 SessionEnv;Configuration des services Terminal Server;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 sffp_mmc;SFF Storage Protocol Driver for MMC;C:\Windows\system32\drivers\sffp_mmc.sys [2006-11-02 12800]
    S3 SLUINotify;Service de notification de l’interface utilisateur SL;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 srv2;srv2;C:\Windows\system32\DRIVERS\srv2.sys [2008-01-19 144384]
    S3 srvnet;srvnet;C:\Windows\system32\DRIVERS\srvnet.sys [2008-01-19 98304]
    S3 THREADORDER;Serveur de priorités des threads;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-06-06 812544]
    S3 TrustedInstaller;Programme d’installation de modules Windows;C:\Windows\servicing\TrustedInstaller.exe [2008-01-19 39424]
    S3 tssecsrv;Terminal Services Security Filter Driver;C:\Windows\system32\DRIVERS\tssecsrv.sys [2008-01-19 23552]
    S3 tunnel;Pilote de carte miniport Microsoft IPv6 Tunnel;C:\Windows\system32\DRIVERS\tunnel.sys [2008-01-19 23040]
    S3 UI0Detect;Détection de services interactifs;C:\Windows\system32\UI0Detect.exe [2008-01-19 35840]
    S3 uliagpkx;Uli AGP Bus Filter;C:\Windows\system32\drivers\uliagpkx.sys [2006-11-02 58472]
    S3 USBSTOR;Pilote de stockage de masse USB;C:\Windows\system32\DRIVERS\USBSTOR.SYS [2008-01-19 55296]
    S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-10 745472]
    S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe [2007-06-20 397312]
    S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-20 1089536]
    S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe [2008-03-17 87328]
    S3 wcncsvc;Windows Connect Now - Registre de configuration;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 WcsPlugInService;Système de couleurs Windows;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 WdiServiceHost;Service hôte WDIServiceHost;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 WdiSystemHost;Hôte système de diagnostics;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 Wecsvc;Collecteur d'événements de Windows;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 wercplsupport;Prise en charge de l’application Rapports et solutions aux problèmes du Panneau de configuration;C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 WinRM;Gestion à distance de Windows (Gestion WSM);C:\Windows\System32\svchost.exe [2008-01-19 21504]
    S3 WPCSvc;Contrôle parental;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-10-05 246784]
    S4 adp94xx;adp94xx;C:\Windows\system32\drivers\adp94xx.sys [2006-11-02 420968]
    S4 adpahci;adpahci;C:\Windows\system32\drivers\adpahci.sys [2006-11-02 297576]
    S4 arcsas;arcsas;C:\Windows\system32\drivers\arcsas.sys [2006-11-02 67688]
    S4 Brserid;Brother MFC Serial Port Interface Driver (WDM);C:\Windows\system32\drivers\brserid.sys [2006-11-02 71808]
    S4 BrSerWdm;Brother WDM Serial driver;C:\Windows\system32\drivers\brserwdm.sys [2006-11-02 62336]
    S4 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\Windows\system32\drivers\brusbmdm.sys [2006-11-02 12160]
    S4 circlass;Consumer IR Devices;C:\Windows\system32\drivers\circlass.sys [2006-11-02 35328]
    S4 Crusoe;Transmeta Crusoe Processor Driver;C:\Windows\system32\drivers\crusoe.sys [2006-11-02 38912]
    S4 elxstor;elxstor;C:\Windows\system32\drivers\elxstor.sys [2006-11-02 316520]
    S4 HpCISSs;HpCISSs;C:\Windows\system32\drivers\hpcisss.sys [2006-11-02 37480]
    S4 IPMIDRV;IPMIDRV;C:\Windows\system32\drivers\ipmidrv.sys [2006-11-02 65536]
    S4 iteraid;ITERAID_Service_Install;C:\Windows\system32\drivers\iteraid.sys [2006-11-02 35944]
    S4 LSI_FC;LSI_FC;C:\Windows\system32\drivers\lsi_fc.sys [2006-11-02 65640]
    S4 LSI_SAS;LSI_SAS;C:\Windows\system32\drivers\lsi_sas.sys [2006-11-02 65640]
    S4 LSI_SCSI;LSI_SCSI;C:\Windows\system32\drivers\lsi_scsi.sys [2006-11-02 65640]
    S4 Mcx2Svc;Service Windows Media Center Extender;C:\Windows\system32\svchost.exe [2008-01-19 21504]
    S4 megasas;megasas;C:\Windows\system32\drivers\megasas.sys [2006-11-02 28776]
    S4 mpio;Microsoft Multi-Path Bus Driver;C:\Windows\system32\drivers\mpio.sys [2006-11-02 78952]
    S4 msahci;msahci;C:\Windows\system32\drivers\msahci.sys [2006-11-02 23144]
    S4 msdsm;Microsoft Multi-Path Device Specific Module;C:\Windows\system32\drivers\msdsm.sys [2006-11-02 80488]
    S4 nfrd960;nfrd960;C:\Windows\system32\drivers\nfrd960.sys [2006-11-02 45160]
    S4 ntrigdigi;N-trig HID Tablet Driver;C:\Windows\system32\drivers\ntrigdigi.sys [2006-11-02 20608]
    S4 nvstor;nvstor;C:\Windows\system32\drivers\nvstor.sys [2006-11-02 40040]
    S4 ql2300;QLogic Fibre Channel Miniport Driver;C:\Windows\system32\drivers\ql2300.sys [2006-11-02 900712]
    S4 ql40xx;QLogic iSCSI Miniport Driver;C:\Windows\system32\drivers\ql40xx.sys [2006-11-02 106088]
    S4 SiSRaid4;SiSRaid4;C:\Windows\system32\drivers\sisraid4.sys [2006-11-02 71784]
    S4 uliahci;uliahci;C:\Windows\system32\drivers\uliahci.sys [2006-11-02 235112]
    S4 ulsata2;ulsata2;C:\Windows\system32\drivers\ulsata2.sys [2006-11-02 115816]
    S4 usbcir;eHome Infrared Receiver (USBCIR);C:\Windows\system32\drivers\usbcir.sys [2006-11-02 68608]
    S4 ViaC7;VIA C7 Processor Driver;C:\Windows\system32\drivers\viac7.sys [2006-11-02 39424]
    S4 vsmraid;vsmraid;C:\Windows\system32\drivers\vsmraid.sys [2006-11-02 112232]
    S4 WacomPen;Wacom Serial Pen HID Driver;C:\Windows\system32\drivers\wacompen.sys [2006-11-02 20608]
    S4 Wd;Microsoft Watchdog Timer Driver;C:\Windows\system32\drivers\wd.sys [2006-11-02 19560]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    NetworkServiceNetworkRestricted REG_MULTI_SZ PolicyAgent
    LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc ehstart
    WerSvcGroup REG_MULTI_SZ wersvc
    swprv REG_MULTI_SZ swprv
    regsvc REG_MULTI_SZ RemoteRegistry
    wcssvc REG_MULTI_SZ WcsPlugInService
    DcomLaunch REG_MULTI_SZ PlugPlay DcomLaunch
    wdisvc REG_MULTI_SZ WdiServiceHost
    sdrsvc REG_MULTI_SZ sdrsvc
    secsvcs REG_MULTI_SZ WinDefend

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
    AeLookupSvc
    wercplsupport
    Themes
    CertPropSvc
    SCPolicySvc
    lanmanserver
    gpsvc
    IKEEXT
    AudioSrv
    FastUserSwitchingCompatibility
    Nla
    NWCWorkstation
    SRService
    Wmi
    WmdmPmSp
    TermService
    wuauserv
    BITS
    ShellHWDetection
    LogonHours
    PCAudit
    helpsvc
    uploadmgr
    iphlpsvc
    seclogon
    AppInfo
    msiscsi
    MMCSS
    ProfSvc
    EapHost
    winmgmt
    schedule
    SessionEnv
    browser
    hkmsvc

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{4e5eda48-fe5e-11dc-bed4-001e3d36c089}]
    \shell\Setup\command - setup.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
    C:\Windows\system32\unregmp2.exe /ShowWMP

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{6BF52A52-394A-11d3-B153-00C04F79FAA6}]
    %SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUI
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    HKLM-RunOnce-<NO NAME> - (no file)

    .
    ------- Examen supplémentaire -------
    .
    R1 -: HKCU-Internet Settings,ProxyOverride = <local>;*.local
    R1 -: HKCU-Internet Settings,ProxyServer = 195.243.124.114:80
    O8 -: &Download All with Rapidshare Downloader - C:\Users\Romain\AppData\Local\Temp\RarSFX0\jc_all.htm
    O8 -: &Download with Rapidshare Downloader - C:\Users\Romain\AppData\Local\Temp\RarSFX0\jc_link.htm
    O8 -: Ajouter la cible du lien à un fichier PDF existant - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 -: Ajouter à un fichier PDF existant - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 -: Convertir au format Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O8 -: Convertir la cible du lien au format Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 -: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O8 -: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O18 -: Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-10-05 00:09:48
    Windows 6.0.6001 Service Pack 1 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    AppInit_DLLs = acaptuser32.dll???

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    Heure de fin: 2008-10-05 0:11:00
    ComboFix-quarantined-files.txt 2008-10-04 22:10:44
    ComboFix2.txt 2008-10-04 18:09:56

    Avant-CF: Le texte du message associé au numéro 0x2379 est introuvable dans le fichier de messages pour Application.
    Après-CF: 99,867,570,176 octets libres

    421 --- E O F --- 2008-09-28 09:11:11

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 00:13:56, on 05/10/2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Safe mode

    Running processes:
    C:\Windows\system32\wbem\unsecapp.exe
    C:\Windows\Explorer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.243.124.114:80
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O1 - Hosts: ::1 localhost
    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - C:\PROGRA~1\COMMON~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
    O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - (no file)
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll
    O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
    O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
    O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O8 - Extra context menu item: &Download All with Rapidshare Downloader - C:\Users\Romain\AppData\Local\Temp\RarSFX0\jc_all.htm
    O8 - Extra context menu item: &Download with Rapidshare Downloader - C:\Users\Romain\AppData\Local\Temp\RarSFX0\jc_link.htm
    O8 - Extra context menu item: Ajouter la cible du lien à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Ajouter à un fichier PDF existant - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convertir au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convertir la cible du lien au format Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Envoyer au périphérique &Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O8 - Extra context menu item: Envoyer l'&image au périphérique Bluetooth... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O13 - Gopher Prefix:
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O20 - AppInit_DLLs: acaptuser32.dll
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: ccEvtMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: ccSetMgr - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
    O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
    O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Roxio UPnP Renderer 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe
    O23 - Service: Roxio Upnp Server 10 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 10\RoxioUpnpService10.exe
    O23 - Service: LiveShare P2P Server 10 (RoxLiveShare10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe
    O23 - Service: RoxMediaDB10 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
    O23 - Service: Roxio Hard Drive Watcher 10 (RoxWatch10) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe
    O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\stacsv.exe
    O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
    O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe
    O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
    O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
    O23 - Service: VAIO Content Metadata Intelligent Analyzing Manager (VcmIAlzMgr) - Sony Corporation - C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
    O23 - Service: VAIO Content Metadata XML Interface (VcmXmlIfHelper) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe
    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
    0
  19. sKe69 Messages postés 21955 Statut Contributeur sécurité 463
     
    bon ...

    il faudrais que tu sois en mode sans échec avec "prise en charge du réseau" pour avoir un connexion Internet ...

    1- Avoir accès aux fichiers cachés :

    Vas dans Menu Démarrer->panneau de config.("affichage classique")-> Options des dossiers
    --> vas sur l'onglet " Affichage " .
    * "Afficher les fichiers et dossiers cachés" ---> coché
    * "Masquer les extensions des fichiers dont le type est connu" ---> décoché
    * "masquer les fichiers du système" ---> décoché
    -> valides la modif ( "appliquer" puis "ok" ).
    ( tu remetteras les paramètres de départ une fois la désinfection terminée , pas avant ... )

    2- Rends toi sur ce site :

    https://www.virustotal.com/gui/

    Copies ce qui suit et colles le dans l'espace pour la recherche :
    C:\Windows\System32\dns-sd.exe

    Cliques sur Send File ( = " Envoyer le fichier " ).

    Un rapport va s'élaborer ligne à ligne.

    Attends bien la fin ... Il doit comprendre la taille du fichier envoyé.

    Sauvegarde le rapport avec le bloc-note.

    Copies le dans ta prochaine réponse ...

    ( Si VirusTotal indique que le fichier a déjà été analysé, clique sur le bouton Ré-analyse le fichier maintenant )

    Fais de même pour :
    C:\Windows\System32\dnssd.dll
    C:\Windows\bwUnin-8.1.1.87-8876480SL.exe
    C:\Users\Romain\AppData\Roaming\nvModes.dat
    C:\Windows\System32\fceadad0_r.dll

    postes moi donc ces 5 rapports ( surtout le début avec le listing des AV , et en précisant bien au début de chacuns à quel fichier ils correspondent ) et attends la suite ...
    0
  20. Destroyer0701 Messages postés 43 Statut Membre
     
    Fichier dns-sd.exe reçu le 2008.10.05 12:30:09 (CET)
    Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

    Résultat: 0/36 (0%)
    en train de charger les informations du serveur...
    Votre fichier est dans la file d'attente, en position: ___.
    L'heure estimée de démarrage est entre ___ et ___ .
    Ne fermez pas la fenêtre avant la fin de l'analyse.
    L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
    Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
    Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
    les résultats seront affichés au fur et à mesure de leur génération.
    Formaté Impression des résultats
    Votre fichier a expiré ou n'existe pas.
    Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

    Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
    Email:

    Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.10.3.2 2008.10.03 -
    AntiVir 7.8.1.34 2008.10.04 -
    Authentium 5.1.0.4 2008.10.04 -
    Avast 4.8.1248.0 2008.10.04 -
    AVG 8.0.0.161 2008.10.04 -
    BitDefender 7.2 2008.10.05 -
    CAT-QuickHeal 9.50 2008.10.04 -
    ClamAV 0.93.1 2008.10.04 -
    DrWeb 4.44.0.09170 2008.10.05 -
    eSafe 7.0.17.0 2008.10.02 -
    eTrust-Vet 31.6.6129 2008.10.04 -
    Ewido 4.0 2008.10.05 -
    F-Prot 4.4.4.56 2008.10.04 -
    F-Secure 8.0.14332.0 2008.10.05 -
    Fortinet 3.113.0.0 2008.10.04 -
    GData 19 2008.10.05 -
    Ikarus T3.1.1.34.0 2008.10.05 -
    K7AntiVirus 7.10.484 2008.10.04 -
    Kaspersky 7.0.0.125 2008.10.05 -
    McAfee 5398 2008.10.04 -
    Microsoft 1.4005 2008.10.05 -
    NOD32 3495 2008.10.04 -
    Norman 5.80.02 2008.10.03 -
    Panda 9.0.0.4 2008.10.04 -
    PCTools 4.4.2.0 2008.10.04 -
    Prevx1 V2 2008.10.05 -
    Rising 20.63.62.00 2008.09.28 -
    SecureWeb-Gateway 6.7.6 2008.10.05 -
    Sophos 4.34.0 2008.10.05 -
    Sunbelt 3.1.1675.1 2008.09.27 -
    Symantec 10 2008.10.05 -
    TheHacker 6.3.1.0.101 2008.10.04 -
    TrendMicro 8.700.0.1004 2008.10.03 -
    VBA32 3.12.8.6 2008.10.04 -
    ViRobot 2008.10.4.1406 2008.10.04 -
    VirusBuster 4.5.11.0 2008.10.04 -
    Information additionnelle
    File size: 87336 bytes
    MD5...: ff62846096bf613a86ed0a300319cd0a
    SHA1..: 8b729a7ff9bcc825126d3d41f5e870ffab2a3459
    SHA256: c6d7cbd89ec1c0a7e7d61ea86d71ddda324a427a724e24976ba663b5e195edcf
    SHA512: 9051d6b3f80d2d4c7dfc8a3e1c11725207a22afe4be3ade467d1b412ba3ea5a4
    011436678548ba6baf7e0bccab2a43729d3d583bd434f25c591d8b5d81d785c5
    PEiD..: -
    TrID..: File type identification
    Win64 Executable Generic (59.6%)
    Win32 Executable MS Visual C++ (generic) (26.2%)
    Win32 Executable Generic (5.9%)
    Win32 Dynamic Link Library (generic) (5.2%)
    Generic Win/DOS Executable (1.3%)
    PEInfo: PE Structure information

    ( base data )
    entrypointaddress.: 0x403ca8
    timedatestamp.....: 0x48a4b763 (Thu Aug 14 22:53:23 2008)
    machinetype.......: 0x14c (I386)

    ( 4 sections )
    name viradd virsiz rawdsiz ntrpy md5
    .text 0x1000 0xbf24 0xc000 6.65 98a26b82945fb2f12db3290f061cbff9
    .rdata 0xd000 0x3086 0x4000 4.56 9e5bd224a239a708b345c380bbd745b4
    .data 0x11000 0x3c44 0x2000 1.41 7b5924c53c4646ea35a59ee2ba5335e3
    .rsrc 0x15000 0x57c 0x1000 4.18 b4a39d4359430ce9738432c494ab5c04

    ( 3 imports )
    > dnssd.dll: DNSServiceEnumerateDomains, DNSServiceBrowse, DNSServiceResolve, DNSServiceQueryRecord, DNSServiceRefDeallocate, DNSServiceGetProperty, DNSServiceRegister, DNSServiceCreateConnection, DNSServiceRegisterRecord, DNSServiceRefSockFD, DNSServiceProcessResult, DNSServiceUpdateRecord, DNSServiceAddRecord, DNSServiceRemoveRecord
    > WS2_32.dll: -, -, -
    > KERNEL32.dll: WriteFile, CompareStringW, CompareStringA, CloseHandle, CreateFileA, HeapSize, VirtualAlloc, HeapReAlloc, SetStdHandle, SetFilePointer, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, RtlUnwind, GetLocaleInfoA, GetLocalTime, GetSystemTimeAsFileTime, EnterCriticalSection, LeaveCriticalSection, GetProcAddress, GetModuleHandleA, ExitProcess, GetCurrentProcessId, GetCommandLineA, HeapFree, GetVersionExA, HeapAlloc, GetProcessHeap, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, WideCharToMultiByte, GetTimeZoneInformation, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, GetLastError, SetEnvironmentVariableA, GetConsoleCP, GetConsoleMode, FlushFileBuffers, DeleteCriticalSection, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, Sleep, GetModuleFileNameA, LoadLibraryA, InitializeCriticalSection, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, LCMapStringA, MultiByteToWideChar, LCMapStringW, GetStringTypeA, GetStringTypeW

    ( 0 exports )

    Fichier dnssd.dll reçu le 2008.10.05 12:35:06 (CET)
    Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

    Résultat: 0/36 (0%)
    en train de charger les informations du serveur...
    Votre fichier est dans la file d'attente, en position: 1.
    L'heure estimée de démarrage est entre 37 et 53 secondes.
    Ne fermez pas la fenêtre avant la fin de l'analyse.
    L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
    Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
    Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
    les résultats seront affichés au fur et à mesure de leur génération.
    Formaté Impression des résultats
    Votre fichier a expiré ou n'existe pas.
    Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

    Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
    Email:

    Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.10.3.2 2008.10.03 -
    AntiVir 7.8.1.34 2008.10.04 -
    Authentium 5.1.0.4 2008.10.04 -
    Avast 4.8.1248.0 2008.10.04 -
    AVG 8.0.0.161 2008.10.04 -
    BitDefender 7.2 2008.10.05 -
    CAT-QuickHeal 9.50 2008.10.04 -
    ClamAV 0.93.1 2008.10.04 -
    DrWeb 4.44.0.09170 2008.10.05 -
    eSafe 7.0.17.0 2008.10.02 -
    eTrust-Vet 31.6.6129 2008.10.04 -
    Ewido 4.0 2008.10.05 -
    F-Prot 4.4.4.56 2008.10.04 -
    F-Secure 8.0.14332.0 2008.10.05 -
    Fortinet 3.113.0.0 2008.10.04 -
    GData 19 2008.10.05 -
    Ikarus T3.1.1.34.0 2008.10.05 -
    K7AntiVirus 7.10.484 2008.10.04 -
    Kaspersky 7.0.0.125 2008.10.05 -
    McAfee 5398 2008.10.04 -
    Microsoft 1.4005 2008.10.05 -
    NOD32 3495 2008.10.04 -
    Norman 5.80.02 2008.10.03 -
    Panda 9.0.0.4 2008.10.04 -
    PCTools 4.4.2.0 2008.10.04 -
    Prevx1 V2 2008.10.05 -
    Rising 20.63.62.00 2008.09.28 -
    SecureWeb-Gateway 6.7.6 2008.10.05 -
    Sophos 4.34.0 2008.10.05 -
    Sunbelt 3.1.1675.1 2008.09.27 -
    Symantec 10 2008.10.05 -
    TheHacker 6.3.1.0.101 2008.10.04 -
    TrendMicro 8.700.0.1004 2008.10.03 -
    VBA32 3.12.8.6 2008.10.04 -
    ViRobot 2008.10.4.1406 2008.10.04 -
    VirusBuster 4.5.11.0 2008.10.04 -
    Information additionnelle
    File size: 61440 bytes
    MD5...: a206447164fcf37e047bdb13ea7c2569
    SHA1..: 7c48f67cd92e9812a684bbea13b01d2cd18bbb47
    SHA256: 294708dd90389aa5727e4e9b5a7a384d67fa8d3ff3ad1874c948635cf78495c5
    SHA512: 2496bdc81d39fe445d8df2497f45abb567e3717b23420e6edd571e2856393386 c29ea44e89607231c1c59eabd29016e31e9164f16f9581daff1d4350be5106a7
    PEiD..: -
    TrID..: File type identification
    Win32 Executable MS Visual C++ (generic) (65.2%)
    Win32 Executable Generic (14.7%)
    Win32 Dynamic Link Library (generic) (13.1%)
    Generic Win/DOS Executable (3.4%)
    DOS Executable Generic (3.4%)
    PEInfo: PE Structure information

    ( base data )
    entrypointaddress.: 0x16004113
    timedatestamp.....: 0x48a4b74d (Thu Aug 14 22:53:01 2008)
    machinetype.......: 0x14c (I386)

    ( 5 sections )
    name viradd virsiz rawdsiz ntrpy md5
    .text 0x1000 0x87f4 0x9000 6.44 0881a1b0d4ef360d4b59f7a67457fe64
    .rdata 0xa000 0x1f8a 0x2000 5.55 4e37059eb0c4da9b3bb7b8ce6a909f8e
    .data 0xc000 0x1864 0x1000 2.12 a577cdb9fe7b6937bdaec43fed10eaa9
    .rsrc 0xe000 0x3dc 0x1000 3.71 4e801cf3dc73ae7779648c96095f5c9a
    .reloc 0xf000 0xd34 0x1000 4.01 afd2c29d41a0ce8f9dfb1328028b43fe

    ( 3 imports )
    > WS2_32.dll: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
    > KERNEL32.dll: LCMapStringW, LCMapStringA, GetStringTypeW, GetStringTypeA, GetLocaleInfoA, GetLastError, Sleep, IsDebuggerPresent, HeapAlloc, HeapFree, GetCurrentThreadId, GetCommandLineA, GetVersionExA, GetProcessHeap, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, VirtualFree, VirtualAlloc, HeapReAlloc, HeapDestroy, HeapCreate, GetProcAddress, GetModuleHandleA, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, InterlockedDecrement, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, InitializeCriticalSection, RtlUnwind, LoadLibraryA, GetCPInfo, GetACP, GetOEMCP, HeapSize, MultiByteToWideChar
    > ADVAPI32.dll: EnumServicesStatusA, CloseServiceHandle, OpenSCManagerA

    ( 26 exports )
    DNSServiceAddRecord, DNSServiceBrowse, DNSServiceConstructFullName, DNSServiceCreateConnection, DNSServiceEnumerateDomains, DNSServiceGetProperty, DNSServiceProcessResult, DNSServiceQueryRecord, DNSServiceReconfirmRecord, DNSServiceRefDeallocate, DNSServiceRefSockFD, DNSServiceRegister, DNSServiceRegisterRecord, DNSServiceRemoveRecord, DNSServiceResolve, DNSServiceUpdateRecord, TXTRecordContainsKey, TXTRecordCreate, TXTRecordDeallocate, TXTRecordGetBytesPtr, TXTRecordGetCount, TXTRecordGetItemAtIndex, TXTRecordGetLength, TXTRecordGetValuePtr, TXTRecordRemoveValue, TXTRecordSetValue

    Fichier bwUnin-8.1.1.87-8876480SL.exe reçu le 2008.10.05 12:37:43 (CET)
    Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

    Résultat: 1/36 (2.78%)
    en train de charger les informations du serveur...
    Votre fichier est dans la file d'attente, en position: ___.
    L'heure estimée de démarrage est entre ___ et ___ .
    Ne fermez pas la fenêtre avant la fin de l'analyse.
    L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
    Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
    Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
    les résultats seront affichés au fur et à mesure de leur génération.
    Formaté Impression des résultats
    Votre fichier a expiré ou n'existe pas.
    Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

    Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
    Email:

    Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.10.3.2 2008.10.03 -
    AntiVir 7.8.1.34 2008.10.04 -
    Authentium 5.1.0.4 2008.10.04 -
    Avast 4.8.1248.0 2008.10.04 -
    AVG 8.0.0.161 2008.10.04 -
    BitDefender 7.2 2008.10.05 -
    CAT-QuickHeal 9.50 2008.10.04 -
    ClamAV 0.93.1 2008.10.04 -
    DrWeb 4.44.0.09170 2008.10.05 -
    eSafe 7.0.17.0 2008.10.02 -
    eTrust-Vet 31.6.6129 2008.10.04 -
    Ewido 4.0 2008.10.05 -
    F-Prot 4.4.4.56 2008.10.04 -
    F-Secure 8.0.14332.0 2008.10.05 Suspicious:W32/Netsnake.n!Gemini
    Fortinet 3.113.0.0 2008.10.04 -
    GData 19 2008.10.05 -
    Ikarus T3.1.1.34.0 2008.10.05 -
    K7AntiVirus 7.10.484 2008.10.04 -
    Kaspersky 7.0.0.125 2008.10.05 -
    McAfee 5398 2008.10.04 -
    Microsoft 1.4005 2008.10.05 -
    NOD32 3495 2008.10.04 -
    Norman 5.80.02 2008.10.03 -
    Panda 9.0.0.4 2008.10.05 -
    PCTools 4.4.2.0 2008.10.04 -
    Prevx1 V2 2008.10.05 -
    Rising 20.63.62.00 2008.09.28 -
    SecureWeb-Gateway 6.7.6 2008.10.05 -
    Sophos 4.34.0 2008.10.05 -
    Sunbelt 3.1.1675.1 2008.09.27 -
    Symantec 10 2008.10.05 -
    TheHacker 6.3.1.0.101 2008.10.04 -
    TrendMicro 8.700.0.1004 2008.10.03 -
    VBA32 3.12.8.6 2008.10.04 -
    ViRobot 2008.10.4.1406 2008.10.04 -
    VirusBuster 4.5.11.0 2008.10.04 -
    Information additionnelle
    File size: 130208 bytes
    MD5...: c84b25ae27af071a7fbad6bab574ec5d
    SHA1..: c1b146c378e8b292f6fa42aad4702d38129eff43
    SHA256: 17dd4f657a9ce9140362c485e4a261b54ef4ae51d97f4b990202b803c398f3e3
    SHA512: 6f012e21149d989163f3909e124528d1e3d782e8fb48c310d0809f73e9bfb2b2
    a2eacb55791a571e19045986068a8b928984baaac78a7d07f2b3d1fe525b5b48
    PEiD..: Armadillo v1.71
    TrID..: File type identification
    Win32 Executable MS Visual C++ (generic) (65.2%)
    Win32 Executable Generic (14.7%)
    Win32 Dynamic Link Library (generic) (13.1%)
    Generic Win/DOS Executable (3.4%)
    DOS Executable Generic (3.4%)
    PEInfo: PE Structure information

    ( base data )
    entrypointaddress.: 0x40e536
    timedatestamp.....: 0x47e64e25 (Sun Mar 23 12:33:41 2008)
    machinetype.......: 0x14c (I386)

    ( 4 sections )
    name viradd virsiz rawdsiz ntrpy md5
    .text 0x1000 0xe116 0xf000 6.21 5cc4838c05a582ffe32700b762f2d085
    .rdata 0x10000 0x3c02 0x4000 5.36 4e95d9eea8447cf0ec96c42d37a88f84
    .data 0x14000 0xb718 0x9000 4.90 88029d506fe8c670961cc22c21a73fe8
    .rsrc 0x20000 0x1480 0x2000 3.33 51821de9e562ddbcf3a639e2019ca827

    ( 8 imports )
    > MSVCRT.dll: _except_handler3, _controlfp, __set_app_type, __p__fmode, __p__commode, _adjust_fdiv, __setusermatherr, _initterm, __getmainargs, _acmdln, exit, _XcptFilter, _exit, _onexit, __dllonexit, _chsize, fseek, fwrite, fread, _get_osfhandle, sscanf, _stat, swprintf, memset, strchr, realloc, atoi, fgets, _mbschr, _mbsdec, strncat, malloc, free, _purecall, ctime, fprintf, fflush, ftell, rename, memcpy, _iob, vfprintf, fopen, _unlink, _ftime, _strnicmp, memcmp, strrchr, _setmbcp, _snprintf, _mbslwr, strcpy, strlen, _errno, sprintf, _mbsrchr, __CxxFrameHandler, _mbsicmp, __3@YAXPAX@Z, strcat, strcmp, _rmdir, toupper, _ultoa, strncmp, _findnext, remove, strncpy, strstr, _findclose, __2@YAPAXI@Z, _chmod, _findfirst, _stricmp, fclose
    > MFC42.DLL: -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -, -
    > KERNEL32.dll: ReleaseMutex, GetModuleHandleA, GetFileType, PeekNamedPipe, GetFileTime, GetFileSize, RemoveDirectoryA, LocalFree, OpenMutexA, Sleep, lstrlenW, WideCharToMultiByte, GetTickCount, MultiByteToWideChar, CreateDirectoryA, MoveFileExA, GetWindowsDirectoryA, GetCurrentThread, GetPrivateProfileSectionNamesA, GetPrivateProfileStringA, GetPrivateProfileSectionA, SetLastError, ExpandEnvironmentStringsA, GetEnvironmentVariableA, SetEnvironmentVariableA, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetCurrentThreadId, GetCurrentProcess, OpenProcess, TerminateProcess, GetSystemDirectoryA, WritePrivateProfileStringA, lstrcmpA, GetTempPathA, LoadLibraryExA, GetFileAttributesA, DeleteFileA, CopyFileA, GetLocaleInfoA, SetFileAttributesA, lstrcatA, SleepEx, FindResourceA, LoadResource, SearchPathA, GetShortPathNameA, GetModuleFileNameA, GetStartupInfoA, CreateProcessA, LoadLibraryA, GetProcAddress, FreeLibrary, CreateMutexA, WaitForSingleObject, GetLastError, lstrlenA, lstrcpyA, GetVersionExA, CloseHandle
    > USER32.dll: GetClassNameA, SendMessageTimeoutA, FindWindowA, EnumWindows, GetLastActivePopup, IsWindow, PostMessageA, ExitWindowsEx, IsIconic, GetClientRect, DrawIcon, MessageBoxA, SystemParametersInfoA, UpdateWindow, KillTimer, SendMessageA, SetTimer, EnableWindow, LoadIconA, MsgWaitForMultipleObjects, PeekMessageA, GetSystemMetrics, DispatchMessageA, TranslateMessage, LoadStringA
    > ADVAPI32.dll: RegEnumKeyA, RegDeleteKeyA, RegFlushKey, GetServiceKeyNameA, OpenSCManagerA, CloseServiceHandle, LookupPrivilegeValueA, AdjustTokenPrivileges, GetUserNameA, RegSetValueExA, RegEnumValueA, RegCloseKey, RegCreateKeyExA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, OpenProcessToken, RegDeleteValueA, RegQueryInfoKeyA, RegOpenKeyExA, RegQueryValueExA
    > SHELL32.dll: SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHGetMalloc
    > ole32.dll: CoTaskMemFree, CoUninitialize, StringFromCLSID, CLSIDFromProgID, CoInitialize, CoCreateInstance
    > OLEAUT32.dll: -, -

    ( 2 exports )
    GetUninstallerPath, RemoveUnusedVersions

    Fichier nvModes.dat reçu le 2008.10.05 12:49:26 (CET)
    Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

    Résultat: 0/36 (0%)
    en train de charger les informations du serveur...
    Votre fichier est dans la file d'attente, en position: ___.
    L'heure estimée de démarrage est entre ___ et ___ .
    Ne fermez pas la fenêtre avant la fin de l'analyse.
    L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
    Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
    Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
    les résultats seront affichés au fur et à mesure de leur génération.
    Formaté Impression des résultats
    Votre fichier a expiré ou n'existe pas.
    Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

    Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
    Email:

    Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.10.3.2 2008.10.03 -
    AntiVir 7.8.1.34 2008.10.04 -
    Authentium 5.1.0.4 2008.10.04 -
    Avast 4.8.1248.0 2008.10.04 -
    AVG 8.0.0.161 2008.10.04 -
    BitDefender 7.2 2008.10.05 -
    CAT-QuickHeal 9.50 2008.10.04 -
    ClamAV 0.93.1 2008.10.04 -
    DrWeb 4.44.0.09170 2008.10.05 -
    eSafe 7.0.17.0 2008.10.02 -
    eTrust-Vet 31.6.6129 2008.10.04 -
    Ewido 4.0 2008.10.05 -
    F-Prot 4.4.4.56 2008.10.04 -
    F-Secure 8.0.14332.0 2008.10.05 -
    Fortinet 3.113.0.0 2008.10.04 -
    GData 19 2008.10.05 -
    Ikarus T3.1.1.34.0 2008.10.05 -
    K7AntiVirus 7.10.484 2008.10.04 -
    Kaspersky 7.0.0.125 2008.10.05 -
    McAfee 5398 2008.10.04 -
    Microsoft 1.4005 2008.10.05 -
    NOD32 3495 2008.10.04 -
    Norman 5.80.02 2008.10.03 -
    Panda 9.0.0.4 2008.10.05 -
    PCTools 4.4.2.0 2008.10.04 -
    Prevx1 V2 2008.10.05 -
    Rising 20.63.62.00 2008.09.28 -
    SecureWeb-Gateway 6.7.6 2008.10.05 -
    Sophos 4.34.0 2008.10.05 -
    Sunbelt 3.1.1668.1 2008.09.24 -
    Symantec 10 2008.10.05 -
    TheHacker 6.3.1.0.101 2008.10.04 -
    TrendMicro 8.700.0.1004 2008.10.03 -
    VBA32 3.12.8.6 2008.10.04 -
    ViRobot 2008.10.4.1406 2008.10.04 -
    VirusBuster 4.5.11.0 2008.10.04 -
    Information additionnelle
    File size: 108438 bytes
    MD5...: 080f818a0ed143be7ac1ed1716ccdd85
    SHA1..: 18f4f5eac3b73dcd504b1bc03cad06012fbf6b44
    SHA256: 67f6e8c4867a4a172ca5566f9239fbf91995cd527f5e2eb7a8574816b6506bbd
    SHA512: 6bb610d488cbe65b633dbe2ac71d9a22c49354798bffde245b574822de75be3e
    92b502333f490c444da1cd2a8906ba2a450501130c1a48017ebbfc52b31d2a97
    PEiD..: -
    TrID..: File type identification
    Unknown!
    PEInfo: -

    Fichier fceadad0_r.dll reçu le 2008.10.05 12:50:28 (CET)
    Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE

    Résultat: 0/36 (0%)
    en train de charger les informations du serveur...
    Votre fichier est dans la file d'attente, en position: ___.
    L'heure estimée de démarrage est entre ___ et ___ .
    Ne fermez pas la fenêtre avant la fin de l'analyse.
    L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
    Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
    Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
    les résultats seront affichés au fur et à mesure de leur génération.
    Formaté Impression des résultats
    Votre fichier a expiré ou n'existe pas.
    Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

    Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
    Email:

    Antivirus Version Dernière mise à jour Résultat
    AhnLab-V3 2008.10.3.2 2008.10.03 -
    AntiVir 7.8.1.34 2008.10.04 -
    Authentium 5.1.0.4 2008.10.04 -
    Avast 4.8.1248.0 2008.10.04 -
    AVG 8.0.0.161 2008.10.04 -
    BitDefender 7.2 2008.10.05 -
    CAT-QuickHeal 9.50 2008.10.04 -
    ClamAV 0.93.1 2008.10.04 -
    DrWeb 4.44.0.09170 2008.10.05 -
    eSafe 7.0.17.0 2008.10.02 -
    eTrust-Vet 31.6.6129 2008.10.04 -
    Ewido 4.0 2008.10.05 -
    F-Prot 4.4.4.56 2008.10.04 -
    F-Secure 8.0.14332.0 2008.10.05 -
    Fortinet 3.113.0.0 2008.10.04 -
    GData 19 2008.10.05 -
    Ikarus T3.1.1.34.0 2008.10.05 -
    K7AntiVirus 7.10.484 2008.10.04 -
    Kaspersky 7.0.0.125 2008.10.05 -
    McAfee 5398 2008.10.04 -
    Microsoft 1.4005 2008.10.05 -
    NOD32 3495 2008.10.04 -
    Norman 5.80.02 2008.10.03 -
    Panda 9.0.0.4 2008.10.05 -
    PCTools 4.4.2.0 2008.10.04 -
    Prevx1 V2 2008.10.05 -
    Rising 20.63.62.00 2008.09.28 -
    SecureWeb-Gateway 6.7.6 2008.10.05 -
    Sophos 4.34.0 2008.10.05 -
    Sunbelt 3.1.1675.1 2008.09.27 -
    Symantec 10 2008.10.05 -
    TheHacker 6.3.1.0.101 2008.10.04 -
    TrendMicro 8.700.0.1004 2008.10.03 -
    VBA32 3.12.8.6 2008.10.04 -
    ViRobot 2008.10.4.1406 2008.10.04 -
    VirusBuster 4.5.11.0 2008.10.04 -
    Information additionnelle
    File size: 23 bytes
    MD5...: 6127760d7409cd30765b0e377c1ac934
    SHA1..: 9d4c1e8a024c76bfec236e24ecd2c35edbaeee3f
    SHA256: 457394e885cd02a3841fdf16d7c2259373ce2eaad236532b27e8acdad6ece080
    SHA512: 9035a9f5b3a5b40a3e507de87dead6494ef835fdf1b8852642e21a7789a2e985
    024d3d317a9ef2044cc774ed45cacdff3cbeb29b227939e95a31252e3f454d5d
    PEiD..: -
    TrID..: File type identification
    Unknown!
    PEInfo: -
    0
  21. Destroyer0701 Messages postés 43 Statut Membre
     
    Pouvez vous encore m'aider ??

    Je vous en remercie d'avance

    ROmain
    0
  • 1
  • 2
  • 3