Trojan help......

pano27 -  
 pano27 -
Bonjour,
nous avons fait un scan et a priori nous avons toujours des virus trojan virtumonde et autres....
comment peut on nettoyer completement le pc
je suis totalement novice en la matiere
nous utilisons bit defender comme antivir et antispyware...
merci d avance pour votre aide
pano27
ci joint scan comLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:42:46, on 09/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe
C:\documents and settings\arnaud\local settings\application data\sekkqyg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\trend micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lo.st
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://eo.st
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"
O4 - HKLM\..\Run: [ItsTV] "C:\Program Files\ItsLabel\ItsTV.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [sekkqyg] "c:\documents and settings\arnaud\local settings\application data\sekkqyg.exe" sekkqyg
O4 - HKCU\..\Run: [SfKg6wIPu] C:\Documents and Settings\Arnaud\Application Data\Microsoft\Windows\tpytddiy.exe
O4 - HKCU\..\Run: [WinButler] C:\Documents and Settings\Arnaud\Application Data\WinButler\WinButler.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {88764F69-3831-4EC1-B40B-FF21D8381345} (AdVerifierADPCtrl Class) - https://static.impots.gouv.fr/tdir/static/adpform/AdSignerADP-1.1.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin2.valueactive.eu/Register/Branding/olr3313/OCX/v1018/flashax.cab
O20 - AppInit_DLLs: liwoia.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: PTK License-FIGHTERS-297811811 - Unknown owner - C:\Program Files\Fighters\licenseservice.exe (file missing)
O23 - Service: PTK Live Update-FIGHTERS-297811811 - Unknown owner - C:\Program Files\Fighters\updateservice.exe (file missing)
O23 - Service: PTK Scanner-FIGHTERS-297811811 - Unknown owner - C:\Program Files\Fighters\ScannerService.exe (file missing)
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe

--
End of file - 8153 bytes
plet
Configuration: Windows XP
Internet Explorer 7.0

31 réponses

  • 1
  • 2
Résumé de la discussion

Une machine Windows XP est infestée par des trojans Vundo et Navipromo, provoquant des redirections et des comportements publicitaires, nécessitant une désinfection complète et des traces persistantes dans le registre.
Plusieurs outils ont été employés pour nettoyer l’ordinateur, notamment ComboFix et Malwarebytes Anti-Malware, avec suppression et quarantine de composants, puis redémarrage en mode sans échec et vérifications complémentaires.
Des suppressions manuelles de clés de registre et de programmes au démarrage ont été suggérées et effectuées, et les rapports montrent des éléments tels que des fichiers et services infectés supprimés ou mis en quarantaine.
En cas de réinfection, il est recommandé de vérifier les sources de téléchargements et de maintenir les mises à jour des logiciels de sécurité pour prévenir la réapparition des menaces.

Généré automatiquement par IA
sur la base des meilleures réponses
  1. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Bonjour,

    Ton ordinateur est infecté par MagicControl/navipromo (entre autre !), qui s'installe via des programmes dits "gratuits", dont ceux-ci :

    * go-astro
    * GoRecord
    * HotTVPlayer / HotTVPlayer & Paris Hilton
    * Live-Player
    * MailSkinner
    * Messenger Skinner
    * Instant Access
    * InternetGameBox
    * Officiale Emule (Version d'Emule modifiée)
    * Sudoplanet
    * Webmediaplayer

    Pour désinfecter, merci de suivre exactement cette procédure :

    # Désactive le TeaTimer de Spybot (tu le réactiveras après ta désinfection) :
    Lance Spybot --> clique sur Mode => coche Mode avancé => Outils => Résident => décoche la case Résident Tea Timer

    # Télécharge maintenant Navilog1 depuis-ce lien :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, lance Navilog depuis le raccourci présent sur le bureau

    Au menu principal, Fais le choix 1
    Laisse toi guider et patiente.
    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche le bloc note va s'ouvrir.
    Copie-colle l'intégralité du rapport ici.

    0
    1. pano27
       
      merci pour ton aide nous avons telecharger spybot mais nous avons toujours des soucis ...
      trojan vundo.fxr??????

      ci joint copie rapport analyse

      j ai aussi un probleme concernantles mises a jour automatiques
      message impossble de démarrer le sercie m a jour automatsurord local erreur1058 le service e peut pas etre demarre parce qu il est désactive ou qu aucun peripherique ne lui est associe.comment corrige cela ????
      merci davance
      pano27 Search Navipromo version 3.6.9 commencé le 16/11/2008 à 15:36:56,03

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "Arnaud"

      Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO


      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.13
      Système de fichiers : NTFS

      Recherche executé en mode normal

      *** Recherche Programmes installés ***

      Favorit
      Favorit

      *** Recherche dossiers dans "C:\WINDOWS" ***


      *** Recherche dossiers dans "C:\Program Files" ***


      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


      *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***


      *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\applic~1" ***


      *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" ***


      *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\menudm~1\progra~1" ***


      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net



      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans "C:\WINDOWS\system32" *

      * Recherche dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *



      *** Recherche fichiers ***



      *** Recherche clés spécifiques dans le Registre ***

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :


      2)Recherche Heuristique :

      * Dans "C:\WINDOWS\system32" :


      * Dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" :

      ohjcd.exe trouvé !
      ohjcd.dat trouvé !
      ohjcd_nav.dat trouvé !
      ohjcd_navps.dat trouvé !
      sekkqyg.exe trouvé !
      sekkqyg.dat trouvé !
      sekkqyg_nav.dat trouvé !
      sekkqyg_navps.dat trouvé !

      3)Recherche Certificats :

      Certificat Egroup trouvé !
      Certificat Electronic-Group trouvé !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit trouvé !
      Certificat Sunny-Day-Design-Ltd absent !

      4)Recherche fichiers connus :

      C:\WINDOWS\system32\ycbKTvut.ini2 trouvé ! infection Vundo possible non traitée par cet outil !


      *** Analyse terminée le 16/11/2008 à 15:40:40,16 ***
      0
  2. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Re,

    Relance Navilog à l'aide du raccourci navilog1 présent sur le bureau et laisse-toi guider.

    Au menu principal, choisis 2 et valide.
    Le fix va t'informer qu'il va alors redémarrer ton PC
    Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
    Appuie sur une touche comme demandé.
    (si ton Pc ne redémarre pas automatiquement, fais le toi même)
    Au redémarrage de ton PC, choisis ta session habituelle.

    Patiente jusqu'au message :
    *** Nettoyage Termine le ..... ***

    Puis poste un nouveau rapport hijackthis stp

    Je te rappelle qu'il y a plusieurs infections sur ton PC : ce n'est donc pas terminé.

    0
    1. pano27
       
      merci pour ton aide je pense que l on est en bonne voix....
      ci joint copie du cleaner comme indique
      pour mon probleme de maj automatiques as tu une solution???
      Clean Navipromo version 3.6.9 commencé le 16/11/2008 à 21:05:15,64

      Outil exécuté depuis C:\Program Files\navilog1
      Session actuelle : "Arnaud"

      Mise à jour le 05.11.2008 à 21h00 par IL-MAFIOSO


      Microsoft Windows XP [version 5.1.2600]
      Internet Explorer : 7.0.5730.13
      Système de fichiers : NTFS

      Mode suppression automatique
      avec prise en charge résultats Catchme et GNS


      [b] Nettoyage executé en mode normal et non au reboot
      !! Les résultats ne seront pas optimisés !! /b


      *** fsbl1.txt non trouvé ***
      (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)


      *** Suppression avec sauvegardes résultats GenericNaviSearch ***

      * Suppression dans "C:\WINDOWS\System32" *


      * Suppression dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *



      *** Suppression dossiers dans "C:\WINDOWS" ***


      *** Suppression dossiers dans "C:\Program Files" ***


      *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


      *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\applic~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\menudm~1\progra~1" ***



      *** Suppression fichiers ***


      *** Suppression fichiers temporaires ***

      Nettoyage contenu C:\WINDOWS\Temp effectué !
      Nettoyage contenu C:\Documents and Settings\Arnaud\locals~1\Temp effectué !

      *** Traitement Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

      2)Recherche, création sauvegardes et suppression Heuristique :


      * Dans "C:\WINDOWS\system32" *


      * Dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *


      ohjcd.exe trouvé !
      Copie ohjcd.exe réalisée avec succès !
      ohjcd.exe !!ERREUR SUPPRESSION!!

      ohjcd.dat trouvé !
      Copie ohjcd.dat réalisée avec succès !
      ohjcd.dat supprimé !

      ohjcd_nav.dat trouvé !
      Copie ohjcd_nav.dat réalisée avec succès !
      ohjcd_nav.dat supprimé !

      ohjcd_navps.dat trouvé !
      Copie ohjcd_navps.dat réalisée avec succès !
      ohjcd_navps.dat supprimé !

      C:\WINDOWS\prefetch\ohjcd*.pf trouvé !
      Copie C:\WINDOWS\prefetch\ohjcd*.pf réalisée avec succès !
      C:\WINDOWS\prefetch\ohjcd*.pf supprimé !

      sekkqyg.exe trouvé !
      Copie sekkqyg.exe réalisée avec succès !
      sekkqyg.exe supprimé !

      sekkqyg.dat trouvé !
      Copie sekkqyg.dat réalisée avec succès !
      sekkqyg.dat supprimé !

      sekkqyg_nav.dat trouvé !
      Copie sekkqyg_nav.dat réalisée avec succès !
      sekkqyg_nav.dat supprimé !

      sekkqyg_navps.dat trouvé !
      Copie sekkqyg_navps.dat réalisée avec succès !
      sekkqyg_navps.dat supprimé !


      *** Sauvegarde du Registre vers dossier Safebackup ***

      sauvegarde du Registre réalisée avec succès !

      *** Nettoyage Registre ***

      Nettoyage Registre Ok


      *** Certificats ***

      Certificat Egroup supprimé !
      Certificat Electronic-Group supprimé !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit supprimé !
      Certificat Sunny-Day-Design-Ltdt absent !

      *** Nettoyage terminé le 16/11/2008 à 21:20:15,32 ***
      0
    2. pano27
       
      voilà le second rapport RSIT
      merci pour ton aide

      Logfile of random's system information tool 1.05 (written by random/random)
      Run by Arnaud at 2008-12-30 11:27:54
      Microsoft Windows XP Professionnel
      System drive C: has 61 GB (64%) free of 95 GB
      Total RAM: 447 MB (9% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:28:02, on 30/12/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16762)
      Boot mode: Normal

      Running processes:
      C:\windows\System32\smss.exe
      C:\windows\system32\winlogon.exe
      C:\windows\system32\services.exe
      C:\windows\system32\lsass.exe
      C:\windows\system32\Ati2evxx.exe
      C:\windows\system32\svchost.exe
      C:\windows\System32\svchost.exe
      C:\windows\system32\spoolsv.exe
      C:\windows\System32\svchost.exe
      C:\windows\system32\svchost.exe
      C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
      C:\windows\System32\svchost.exe
      C:\windows\system32\Ati2evxx.exe
      C:\windows\system32\WgaTray.exe
      C:\windows\Explorer.EXE
      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
      C:\windows\system32\ctfmon.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\documents and settings\arnaud\local settings\application data\sgkke.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Documents and Settings\Arnaud\Local Settings\Temporary Internet Files\Content.IE5\ZF0WGT69\RSIT[1].exe
      C:\Program Files\trend micro\HijackThis\Arnaud.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [sgkke] "c:\documents and settings\arnaud\local settings\application data\sgkke.exe" sgkke
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      0
  3. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Re,

    Tout n'a pas été supprimé :(

    Télécharge et installe Malwarebytes' Anti-Malware
    - A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée
    - Lance MBAM et laisse les Mises à jour se télécharger (sinon fais les manuellement au lancement du programme)
    - Puis va dans l'onglet "Recherche", coche "Exécuter un examen rapide" puis "Rechercher"
    - Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
    - A la fin du scan, clique sur Afficher les résultats
    - Coche tous les éléments détectés puis clique sur Supprimer la sélection
    - Enregistre le rapport
    - S'il t'est demandé de redémarrer, clique sur Yes

    Poste le rapport de scan après la suppression ici

    0
    1. pano27
       
      j ai tout executer comme indique ci joint le rapport
      Malwarebytes' Anti-Malware 1.30
      Version de la base de données: 1402
      Windows 5.1.2600 Service Pack 3

      16/11/2008 22:36:34
      mbam-log-2008-11-16 (22-36-34).txt

      Type de recherche: Examen rapide
      Eléments examinés: 48005
      Temps écoulé: 5 minute(s), 24 second(s)

      Processus mémoire infecté(s): 1
      Module(s) mémoire infecté(s): 1
      Clé(s) du Registre infectée(s): 14
      Valeur(s) du Registre infectée(s): 2
      Elément(s) de données du Registre infecté(s): 2
      Dossier(s) infecté(s): 1
      Fichier(s) infecté(s): 13

      Processus mémoire infecté(s):
      C:\documents and settings\Arnaud\local settings\application data\ohjcd.exe (Adware.Navipromo.H) -> Unloaded process successfully.

      Module(s) mémoire infecté(s):
      C:\WINDOWS\system32\tuvTKbcy.dll (Trojan.Vundo.H) -> Delete on reboot.

      Clé(s) du Registre infectée(s):
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9cac3855-04d4-4cdd-afbe-2d0588467bd9} (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_CLASSES_ROOT\CLSID\{9cac3855-04d4-4cdd-afbe-2d0588467bd9} (Trojan.Vundo.H) -> Delete on reboot.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d8cadfe4-81e7-4424-887f-dc661b79eaff} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iifggxon (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{d8cadfe4-81e7-4424-887f-dc661b79eaff} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ee533c95-4946-4a90-b6f9-acd91a98afe3} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{ee533c95-4946-4a90-b6f9-acd91a98afe3} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{9cac3855-04d4-4cdd-afbe-2d0588467bd9} (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d8cadfe4-81e7-4424-887f-dc661b79eaff} (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ohjcd (Adware.Navipromo.H) -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{d8cadfe4-81e7-4424-887f-dc661b79eaff} (Trojan.Vundo) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvtkbcy -> Quarantined and deleted successfully.
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\tuvtkbcy -> Delete on reboot.

      Dossier(s) infecté(s):
      C:\Documents and Settings\Arnaud\Application Data\Facegame (Trojan.Agent) -> Quarantined and deleted successfully.

      Fichier(s) infecté(s):
      C:\WINDOWS\system32\tuvTKbcy.dll (Trojan.Vundo.H) -> Delete on reboot.
      C:\WINDOWS\system32\ycbKTvut.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ycbKTvut.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\iifgGXoN.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\gxngak.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Arnaud\Local Settings\Application Data\ohjcd_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Arnaud\Local Settings\Application Data\ohjcd.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Arnaud\Local Settings\Application Data\ohjcd.exe (Adware.Navipromo.H) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ebujlknl.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Arnaud\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
      C:\WINDOWS\system32\ieupdates.exe (Trojan.Agent) -> Quarantined and deleted successfully.
      C:\Program Files\EoRezo (Rogue.Eorezo) -> Delete on reboot.
      0
  4. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    L'infection Navipromo a été supprimée, mais il reste encore EoRezo et Vundo à supprimer (ça n'a pas été fait complètement).

    Pour EoRezo :

    Télécharge Ad-Remover (de C_XX) sur ton Bureau.

    /!\ Déconnecte toi et ferme toutes les applications en cours /!\

    ● Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
    ● Double clique sur l'icône Ad-remover située sur ton Bureau
    ● Au menu principal choisis l'option "A"
    ● Poste le rapport qui apparait à la fin (il est aussi sauvegardé sous C:\Ad-report(date).log )

    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. pano27
     
    ci joint le rapport comme demande
    F --------- Logfile of AD-Remover 1.0.3.3 by C_XX ---------

    START at: 19:28:58 | 17/11/2008
    ON: Microsoft Windows XP [version 5.1.2600] ( Windows XP )
    Internet Explorer: 7.0.5730.13
    OPTION: Scan
    EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
    USER: Arnaud | PC: PCDEARNAUD
    BOOT MODE: Normal
    DRIVE(S): C:\
    ~> Systemdrive: C:\

    --------- [ PROCESSES ] ---------

    \SystemRoot\System32\smss.exe [512]
    \??\C:\WINDOWS\system32\csrss.exe [572]
    \??\C:\WINDOWS\system32\winlogon.exe [600]
    C:\WINDOWS\system32\services.exe [644]
    C:\WINDOWS\system32\lsass.exe [656]
    C:\WINDOWS\system32\Ati2evxx.exe [812]
    C:\WINDOWS\system32\svchost.exe [824]
    C:\WINDOWS\system32\svchost.exe [916]
    C:\WINDOWS\System32\svchost.exe [980]
    C:\WINDOWS\system32\svchost.exe [1028]
    C:\WINDOWS\system32\svchost.exe [1072]
    C:\WINDOWS\system32\Ati2evxx.exe [1364]
    C:\WINDOWS\Explorer.EXE [1440]
    C:\WINDOWS\system32\spoolsv.exe [1552]
    C:\WINDOWS\system32\ctfmon.exe [1728]
    C:\WINDOWS\System32\svchost.exe [1968]
    C:\WINDOWS\system32\svchost.exe [192]
    C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe [408]
    C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe [276]
    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe [544]
    C:\Program Files\Windows Media Player\WMPNetwk.exe [1156]
    C:\WINDOWS\System32\svchost.exe [1756]
    C:\WINDOWS\System32\alg.exe [2192]
    C:\WINDOWS\system32\wscntfy.exe [2256]

    ---------------------------- [~> 24]

    +---------------------------------------------------------------------------+
    +------------------------------- SERVICES FOUND
    +---------------------------------------------------------------------------+

    +---------------------------------------------------------------------------+
    +------------------------------- REGISTRY ELEMENTS FOUND
    +---------------------------------------------------------------------------+

    "HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1"
    "HKEY_CURRENT_USER\SOFTWARE\EoRezo"
    "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
    "HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
    "HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
    "HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
    "HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"

    +---------------------------------------------------------------------------+
    +------------------------------- FILES\FOLDERS FOUND
    +---------------------------------------------------------------------------+

    [28/10/2008 15:26|d--------] C:\Program Files\EoRezo
    [12/11/2008 23:08|d--------] C:\Documents and Settings\Arnaud\Application Data\EoRezo
    [26/08/2008 22:26|d--------] C:\Documents and Settings\All Users\MENUDM~1\PROGRA~1\EoRezo

    +---------- Added scan ...

    +-----[HKLM\...\Run]

    +-----[HKCU\...\Run]

    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

    +-----[HKLM\...\Internet Explorer\MAIN]

    Start Page : hxxp://www.msn.com/

    +-----[HKCU\...\Internet Explorer\MAIN]

    Start Page : hxxp://www.msn.com/

    +---------------------------------------------------------------------------+
    +------------------------------- [ EOF - 67 lines ]
    +---------------------------------------------------------------------------+

    [ END at: 20:15:27 | 17/11/2008 ] - [ Time elapsed: 46 minutes, 28 seconds ]
    0
  7. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Parfait :)

    /!\ Déconnecte toi et ferme toutes les applications en cours /!\

    ● Relance Ad-remover et choisis l'option B au menu principal → le programme va travailler ...

    ● Poste le rapport qui apparait à la fin (il est aussi sauvegardé sous C:\Ad-report(date).log )

    0
    1. pano27
       
      bonjour

      je n ai eu de reponse suite a mon scan du 18.11.2008 a19h55 y a til un soucis...
      merci de ta reponse
      pano27
      0
  8. pano27
     
    bonjour
    ci joint nouveau scan comme convenu
    F --------- Logfile of AD-Remover 1.0.3.3 by C_XX ---------

    START at: 19:13:19 | 18/11/2008
    ON: Microsoft Windows XP [version 5.1.2600] ( Windows XP )
    Internet Explorer: 7.0.5730.13
    OPTION: Clean
    EXECUTED FROM: C:\Program Files\Ad-remover\AD-Remover.bat
    USER: Arnaud | PC: PCDEARNAUD
    BOOT MODE: Normal
    DRIVE(S): C:\
    ~> Systemdrive: C:\

    --------- [ PROCESSES ] ---------

    \SystemRoot\System32\smss.exe [500]
    \??\C:\WINDOWS\system32\csrss.exe [568]
    \??\C:\WINDOWS\system32\winlogon.exe [596]
    C:\WINDOWS\system32\services.exe [640]
    C:\WINDOWS\system32\lsass.exe [652]
    C:\WINDOWS\system32\Ati2evxx.exe [808]
    C:\WINDOWS\system32\svchost.exe [820]
    C:\WINDOWS\system32\svchost.exe [912]
    C:\WINDOWS\System32\svchost.exe [976]
    C:\WINDOWS\system32\svchost.exe [1024]
    C:\WINDOWS\system32\svchost.exe [1060]
    C:\WINDOWS\system32\Ati2evxx.exe [1356]
    C:\WINDOWS\Explorer.EXE [1436]
    C:\WINDOWS\system32\spoolsv.exe [1548]
    C:\WINDOWS\system32\ctfmon.exe [1732]
    C:\WINDOWS\System32\svchost.exe [1964]
    C:\WINDOWS\system32\svchost.exe [172]
    C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe [408]
    C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe [492]
    C:\Program Files\Windows Media Player\WMPNetwk.exe [844]
    C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe [956]
    C:\WINDOWS\System32\svchost.exe [1832]
    C:\WINDOWS\System32\alg.exe [2180]
    C:\WINDOWS\system32\wscntfy.exe [2504]

    ---------------------------- [~> 24]

    +---------------------------------------------------------------------------+
    +------------------------------- SERVICES DELETED
    +---------------------------------------------------------------------------+

    +---------------------------------------------------------------------------+
    +------------------------------- REGISTRY ELEMENTS DELETED
    +---------------------------------------------------------------------------+

    "HKEY_LOCAL_MACHINE\SOFTWARE\EoRezo"
    "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\eoEngine_is1"
    "HKEY_CURRENT_USER\SOFTWARE\EoRezo"
    "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}"
    "HKEY_CLASSES_ROOT\EoRezoBHO.EoBho"
    "HKEY_CLASSES_ROOT\EoRezoBHO.EoBho.1"
    "HKEY_CLASSES_ROOT\Typelib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}"
    "HKEY_CLASSES_ROOT\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}"

    +---------------------------------------------------------------------------+
    +------------------------------- FILES\FOLDERS DELETED
    +---------------------------------------------------------------------------+

    [28/10/2008 15:26|d--------] C:\Program Files\EoRezo
    [12/11/2008 23:08|d--------] C:\Documents and Settings\Arnaud\Application Data\EoRezo
    [26/08/2008 22:26|d--------] C:\Documents and Settings\All Users\MENUDM~1\PROGRA~1\EoRezo

    (!) ---- Temp files deleted.

    (!) ---- Recycle bin emptied in all drives.

    +---------- Added scan ...

    +-----[HKLM\...\Run]

    +-----[HKCU\...\Run]

    ctfmon.exe REG_SZ C:\WINDOWS\system32\ctfmon.exe

    +-----[HKLM\...\Internet Explorer\MAIN]

    Start Page : hxxp://fr.msn.com/

    +-----[HKCU\...\Internet Explorer\MAIN]

    Start Page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

    +---------------------------------------------------------------------------+
    +------------------------------- [ EOF - 69 lines ]
    +---------------------------------------------------------------------------+

    [ END at: 19:24:44 | 18/11/2008 ] - [ Time elapsed: 11 minutes, 24 seconds ]
    0
  9. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    OK, poste un nouveau rapport hijackthis.

    Ensuite, on va utiliser Combofix pour finir la désinfection. Attention, ce logiciel est très puissant, une mauvaise utilisation peut faire des dégâts... Fais exactement ce qui suit :

    Télécharge ComboFix (de sUBs) sur ton Bureau (et pas ailleurs !) :
    Fais un clic droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix, choisis le bureau comme destination et valide : http://download.bleepingcomputer.com/sUBs/ComboFix.exe

    --------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
    !! déconnecte toi, ferme toutes tes applications en cours et DESACTIVE TOUTES TES DEFENCES (anti-virus, antispyware, pare-feu) le temps de la manipulation : en effet , activés, ils pourraient gêner fortement la procédure de recherche et de nettoyage de l'outil ( voir planter le PC )...Tu les réactiveras donc après !!

    Dans ton cas, il s'agit de BitDefender (et du TeaTimer de Spybot si tu l'as réactivé depuis que je te l'ai fait désactiver)

    ---> Surtout, si tu rencontres des difficultés à ce niveau là, dis le moi avant de poursuivre...

    Tuto ici : https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
    ---------------------------------------------------------------------------------------------------------------------------------

    Ensuite :
    double-clique sur C-Fix.exe (= combofix.exe ) .

    Appuie sur une touche pour démarrer le scan .

    Attention : n'utilise pas ta souris ni ton clavier pendant que le programme tourne. Cela pourrait figer l'ordi ---> si un message d'erreur windows apparait à un moment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer

    Le rapport sera crée dans: C:\Combofix.txt , poste le ici stp

    0
    1. pano27
       
      CI JOINT RAPPORT HIJACKTHIS
      PANO27
      0
    2. pano27
       
      CI JOINT LA RAPPORT OUBLIE
      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 09:45:10, on 22/11/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16735)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
      C:\Documents and Settings\Arnaud\Local Settings\Application Data\caocyyy.exe
      C:\Program Files\trend micro\HijackThis\HijackThis.exe

      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      O2 - BHO: (no name) - {516230fa-d76b-4c4e-bcea-f41d7a67f13f} - (no file)
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: (no name) - {C0A23FB2-B53B-463E-A2D6-E39BEAED7D85} - (no file)
      O2 - BHO: (no name) - {DF9F383A-0073-4546-8AFD-FEA859436BED} - (no file)
      O2 - BHO: (no name) - {F3B899C5-73EF-4586-B88B-4716D1D8EAE3} - (no file)
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O20 - AppInit_DLLs: gxngak.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      0
  10. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Merci, poste maintenant celui de Combofix stp.

    0
    1. pano27
       
      ci joint rapport combo fix
      ComboFix 08-11-22.02 - Arnaud 2008-11-23 15:14:39.2 - NTFSx86
      Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.180 [GMT 1:00]
      Lancé depuis: c:\documents and settings\Arnaud\Bureau\ComboFix.exe
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\windows\system32\bkyfyeeu.ini
      c:\windows\system32\dxfnbkyu.ini
      c:\windows\system32\nfgrmnsu.ini
      c:\windows\system32\quoosepf.ini
      c:\windows\system32\wnugblut.ini
      .
      ---- Previous Run -------
      .
      c:\documents and settings\Arnaud\Local Settings\Application Data\caocyyy.dat
      c:\documents and settings\Arnaud\Local Settings\Application Data\caocyyy.exe
      c:\documents and settings\Arnaud\Local Settings\Application Data\caocyyy_nav.dat
      c:\documents and settings\Arnaud\Local Settings\Application Data\caocyyy_navps.dat
      c:\documents and settings\Arnaud\Local Settings\Application Data\goaosua.dat
      c:\documents and settings\Arnaud\Local Settings\Application Data\goaosua.exe
      c:\documents and settings\Arnaud\Local Settings\Application Data\goaosua_nav.dat
      c:\documents and settings\Arnaud\Local Settings\Application Data\goaosua_navps.dat
      c:\documents and settings\Arnaud\Local Settings\Temporary Internet Files\fbk.sts

      .
      ((((((((((((((((((((((((((((( Fichiers créés du 2008-10-23 au 2008-11-23 ))))))))))))))))))))))))))))))))))))
      .

      2008-11-23 14:54 . 2008-11-23 14:54 <REP> d-------- c:\windows\LastGood
      2008-11-23 13:10 . 2008-11-23 15:04 <REP> d-------- c:\program files\eMule
      2008-11-21 22:35 . 2008-11-21 22:35 <REP> d-------- c:\windows\system32\Adobe
      2008-11-17 19:28 . 2008-11-18 19:24 <REP> d-------- c:\program files\Ad-remover
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Malwarebytes
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
      2008-11-16 22:05 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
      2008-11-16 22:05 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
      2008-11-16 13:05 . 2008-11-16 21:20 <REP> d-------- c:\program files\Navilog1
      2008-11-16 12:08 . 2008-11-16 12:08 912 --a------ c:\windows\system32\onvwcdwj.dll
      2008-11-16 11:55 . 2008-11-16 11:55 912 --a------ c:\windows\system32\frbrkrss.dll
      2008-11-15 10:43 . 2008-11-15 10:43 912 --a------ c:\windows\system32\iykddgbl.dll
      2008-11-14 20:20 . 2008-11-14 20:20 912 --a------ c:\windows\system32\gktuugme.dll
      2008-11-14 10:41 . 2008-11-14 10:41 912 --a------ c:\windows\system32\skajlyvl.dll
      2008-11-13 22:12 . 2008-11-13 22:12 <REP> d-------- c:\program files\Original-Solitaire
      2008-11-12 19:28 . 2008-11-12 19:28 <REP> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
      2008-11-09 13:39 . 2008-11-09 13:39 91 --a------ c:\windows\wininit.ini
      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\program files\Spybot - Search & Destroy
      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
      2008-11-04 23:01 . 2008-11-04 23:01 912 --a------ c:\windows\system32\fyufljuu.dll
      2008-11-03 23:01 . 2008-11-03 23:01 120 ---hs---- c:\windows\system32\vxqdchdy.tmp
      2008-11-02 19:51 . 2008-11-23 14:53 81,984 --a------ c:\windows\system32\bdod.bin
      2008-11-02 18:28 . 2008-11-02 18:29 120 ---hs---- c:\windows\system32\lnkljube.tmp
      2008-11-01 23:48 . 2008-11-01 23:48 268 --ah----- C:\sqmdata02.sqm
      2008-11-01 23:48 . 2008-11-01 23:48 244 --ah----- C:\sqmnoopt02.sqm
      2008-11-01 14:00 . 2008-11-23 15:15 121 --a------ c:\windows\bdagent.INI
      2008-11-01 13:08 . 2008-11-01 13:08 <REP> d-------- c:\program files\BitDefender
      2008-11-01 13:05 . 2008-11-01 13:09 <REP> d-------- c:\program files\Fichiers communs\BitDefender
      2008-11-01 11:58 . 2008-11-01 11:59 <REP> d-------- C:\rsit
      2008-11-01 11:58 . 2008-11-01 12:10 <REP> d-------- c:\program files\trend micro
      2008-10-31 17:39 . 2008-11-02 22:07 <REP> d-------- c:\program files\Fighters
      2008-10-31 17:39 . 2008-10-31 17:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Fighters
      2008-10-31 15:42 . 2008-11-07 22:03 <REP> d-------- c:\documents and settings\All Users\Application Data\Software Licensors
      2008-10-31 09:07 . 2008-11-07 20:51 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
      2008-10-30 20:58 . 2001-08-23 17:47 99,840 --a------ c:\windows\system32\srusd.dll
      2008-10-30 20:58 . 2001-08-23 17:47 99,840 --a--c--- c:\windows\system32\dllcache\srusd.dll
      2008-10-30 20:58 . 2001-08-23 17:47 72,192 --a------ c:\windows\system32\fnfilter.dll
      2008-10-30 20:58 . 2001-08-23 17:47 72,192 --a--c--- c:\windows\system32\dllcache\fnfilter.dll
      2008-10-30 20:58 . 2001-08-23 17:20 6,912 --a------ c:\windows\system32\drivers\serscan.sys
      2008-10-30 20:58 . 2001-08-23 17:20 6,912 --a--c--- c:\windows\system32\dllcache\serscan.sys
      2008-10-30 17:01 . 2008-10-30 19:02 <REP> d-------- c:\documents and settings\Arnaud\Application Data\WinButler
      2008-10-27 15:38 . 2008-11-12 23:50 <REP> d-------- c:\windows\system32\FlashAX
      2008-10-27 15:38 . 2008-10-27 15:38 <REP> d-------- C:\MicroGaming
      2008-10-27 15:38 . 2008-10-27 15:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Microgaming
      2008-10-27 15:38 . 2008-10-27 15:38 <REP> d-------- c:\documents and settings\All Users\Application Data\MGS

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-11-23 12:52 --------- d-----w c:\documents and settings\Arnaud\Application Data\Image Zone Express
      2008-11-12 15:54 --------- d-----w c:\program files\ItsLabel
      2008-11-02 21:13 --------- d--h--w c:\program files\InstallShield Installation Information
      2008-10-31 08:06 --------- d-----w c:\program files\Google
      2008-10-24 22:07 --------- d-----w c:\program files\Microsoft Silverlight
      2008-10-08 18:39 --------- d-----w c:\program files\Fichiers communs\InstallShield
      2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
      2008-08-28 15:46 3,532 ----a-w C:\drmHeader.bin
      2008-08-26 21:19 216,064 ----a-w c:\windows\iun3405.exe
      2008-08-26 08:11 826,368 ----a-w c:\windows\system32\wininet.dll
      2008-05-19 20:09 16,304 ----a-w c:\documents and settings\Arnaud\Application Data\GDIPFONTCACHEV1.DAT
      .

      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
      "eMuleAutoStart"="c:\program files\eMule\emule.exe" [2008-08-01 5480448]

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
      "AppInit_DLLs"=gxngak.dll

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "DisableNotifications"= 1 (0x1)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

      S4 PTK License-FIGHTERS-297811811;PTK License-FIGHTERS-297811811;c:\program files\Fighters\licenseservice.exe []
      S4 PTK Live Update-FIGHTERS-297811811;PTK Live Update-FIGHTERS-297811811;c:\program files\Fighters\updateservice.exe []
      S4 PTK Scanner-FIGHTERS-297811811;PTK Scanner-FIGHTERS-297811811;c:\program files\Fighters\ScannerService.exe []

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1534df1-4b3d-11dd-ba25-0016ec83fae1}]
      \Shell\AutoRun\command - J:\
      \Shell\explore\Command - RECYCLED\INFO.exe
      \Shell\open\Command - RECYCLED\INFO.exe

      *Newly Created Service* - 66B56D82
      *Newly Created Service* - PROCEXP90
      .
      - - - - ORPHELINS SUPPRIMES - - - -

      BHO-{516230fa-d76b-4c4e-bcea-f41d7a67f13f} - (no file)
      BHO-{C0A23FB2-B53B-463E-A2D6-E39BEAED7D85} - (no file)
      BHO-{DF9F383A-0073-4546-8AFD-FEA859436BED} - (no file)
      BHO-{F3B899C5-73EF-4586-B88B-4716D1D8EAE3} - (no file)



      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-11-23 15:15:49
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'winlogon.exe'(604)
      c:\windows\system32\Ati2evxx.dll
      c:\windows\system32\WgaLogon.dll
      .
      Heure de fin: 2008-11-23 15:16:30
      ComboFix-quarantined-files.txt 2008-11-23 14:16:28

      Avant-CF: 69,790,883,840 octets libres
      Après-CF: 69,799,047,168 octets libres

      153 --- E O F --- 2008-10-28 14:30:22
      0
  11. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Toujours avec toutes les protections désactivées, fais ceci :

    Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
    Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

    ----------------------------------------------------------
    File::
    2008-11-16 12:08 . 2008-11-16 12:08 912 --a------ c:\windows\system32\onvwcdwj.dll
    2008-11-16 11:55 . 2008-11-16 11:55 912 --a------ c:\windows\system32\frbrkrss.dll
    2008-11-15 10:43 . 2008-11-15 10:43 912 --a------ c:\windows\system32\iykddgbl.dll
    2008-11-14 20:20 . 2008-11-14 20:20 912 --a------ c:\windows\system32\gktuugme.dll
    2008-11-14 10:41 . 2008-11-14 10:41 912 --a------ c:\windows\system32\skajlyvl.dll
    2008-11-04 23:01 . 2008-11-04 23:01 912 --a------ c:\windows\system32\fyufljuu.dll
    2008-11-03 23:01 . 2008-11-03 23:01 120 ---hs---- c:\windows\system32\vxqdchdy.tmp
    2008-11-02 18:28 . 2008-11-02 18:29 120 ---hs---- c:\windows\system32\lnkljube.tmp

    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-

    ------------------------------------------------------------------

    - Enregistre ce fichier sur ton bureau (et pas ailleurs !) sous le nom CFScript.txt
    - Quitte le Bloc Notes

    · Fais un glisser/déposer de ce fichier CFScript sur le fichier C-Fix.exe (combofix) comme sur ce lien : http://apu.mabul.org/up/apu/2008/09/06/img-2258535my8h.gif

    * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
    Ne touche à rien tant que le scan n'est pas terminé.
    * Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
    * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

    Ensuite, redémarre ton ordinateur et poste un nouveau rapport hijackthis.

    0
    1. pano27
       
      ci joint nouveau scan hijackthis

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 23:47, on 2008-11-24
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16735)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\Ati2evxx.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\eMule\emule.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\trend micro\HijackThis\HijackThis.exe

      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe -AutoStart
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender S.R.L. - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      0
    2. pano27
       
      ci joint rapport combofix
      0
    3. pano27
       
      ci joint rapport oublie lors du dernier envoi

      ComboFix 08-11-23.02 - Arnaud 2008-11-24 19:30:48.3 - NTFSx86
      Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.160 [GMT 1:00]
      Lancé depuis: C:\Documents and Settings\Arnaud\Bureau\ComboFix.exe
      Commutateurs utilisés :: C:\Documents and Settings\Arnaud\Bureau\CFScript.txt
      * Un nouveau point de restauration a été créé

      FILE ::
      2008-11-16 12:08 . 2008-11-16 12:08 912 --a------ c:\windows\system32\onvwcdwj.dll
      .
      0
  12. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Le rapport n'est pas complet...

    0
    1. pano27
       
      Désolé problème de reception internet cette semaine
      Ci -joint le rapport comme demandé (combofix.exe) réponce du 25
      On sera ABS ce weekend
      Merci de faire suite au rapport et finir ci possible la désinfection du PC
      Merci d'avance pour votre aide et a demain soir

      ComboFix 08-11-27.03 - Arnaud 2008-11-29 14:39:59.6 - NTFSx86
      Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.187 [GMT 1:00]
      Lancé depuis: c:\documents and settings\Arnaud\Bureau\ComboFix.exe
      * Resident AV is active


      [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
      .

      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\windows\system32\xcomm.dll
      .
      ---- Previous Run -------
      .
      c:\windows\system32\xcomm.dll

      .
      ((((((((((((((((((((((((((((( Fichiers créés du 2008-10-28 au 2008-11-29 ))))))))))))))))))))))))))))))))))))
      .

      2008-11-28 19:41 . 2008-11-28 19:41 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Yahoo!
      2008-11-28 19:41 . 2008-11-28 19:41 <REP> d-------- c:\documents and settings\All Users\Application Data\Yahoo! Companion
      2008-11-28 19:39 . 2008-11-28 19:39 <REP> d-------- c:\program files\Yahoo!
      2008-11-26 00:52 . 2008-11-26 01:08 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Azureus
      2008-11-26 00:52 . 2008-11-26 00:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Azureus
      2008-11-26 00:51 . 2008-11-26 01:30 <REP> d-------- c:\program files\Vuze
      2008-11-26 00:51 . 2008-11-26 00:51 <REP> d-------- c:\program files\Fichiers communs\i4j_jres
      2008-11-23 16:44 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
      2008-11-23 16:40 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
      2008-11-23 16:14 . 2008-11-23 16:35 122 --a------ c:\windows\system32\privacy.xml
      2008-11-23 15:23 . 2008-11-23 15:23 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Bitdefender
      2008-11-23 15:23 . 2008-11-28 08:27 <REP> d-------- c:\documents and settings\All Users\Application Data\BitDefender
      2008-11-23 13:10 . 2008-11-29 01:26 <REP> d-------- c:\program files\eMule
      2008-11-21 22:35 . 2008-11-21 22:35 <REP> d-------- c:\windows\system32\Adobe
      2008-11-17 19:28 . 2008-11-27 21:38 <REP> d-------- c:\program files\Ad-remover
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Malwarebytes
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
      2008-11-16 22:05 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
      2008-11-16 22:05 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
      2008-11-16 13:05 . 2008-11-28 00:48 <REP> d-------- c:\program files\Navilog1
      2008-11-16 12:08 . 2008-11-16 12:08 912 --a------ c:\windows\system32\onvwcdwj.dll
      2008-11-16 11:55 . 2008-11-16 11:55 912 --a------ c:\windows\system32\frbrkrss.dll
      2008-11-15 10:43 . 2008-11-15 10:43 912 --a------ c:\windows\system32\iykddgbl.dll
      2008-11-14 20:20 . 2008-11-14 20:20 912 --a------ c:\windows\system32\gktuugme.dll
      2008-11-14 10:41 . 2008-11-14 10:41 912 --a------ c:\windows\system32\skajlyvl.dll
      2008-11-13 22:12 . 2008-11-13 22:12 <REP> d-------- c:\program files\Original-Solitaire
      2008-11-12 19:28 . 2008-11-12 19:28 <REP> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
      2008-11-09 13:39 . 2008-11-09 13:39 91 --a------ c:\windows\wininit.ini
      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\program files\Spybot - Search & Destroy
      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
      2008-11-04 23:01 . 2008-11-04 23:01 912 --a------ c:\windows\system32\fyufljuu.dll
      2008-11-03 23:01 . 2008-11-03 23:01 120 ---hs---- c:\windows\system32\vxqdchdy.tmp
      2008-11-02 19:51 . 2008-11-29 14:42 81,984 --a------ c:\windows\system32\bdod.bin
      2008-11-02 18:28 . 2008-11-02 18:29 120 ---hs---- c:\windows\system32\lnkljube.tmp
      2008-11-01 23:48 . 2008-11-01 23:48 268 --ah----- C:\sqmdata02.sqm
      2008-11-01 23:48 . 2008-11-01 23:48 244 --ah----- C:\sqmnoopt02.sqm
      2008-11-01 14:00 . 2008-11-29 14:41 121 --a------ c:\windows\bdagent.INI
      2008-11-01 13:08 . 2008-11-01 13:08 <REP> d-------- c:\program files\BitDefender
      2008-11-01 13:05 . 2008-11-28 08:27 <REP> d-------- c:\program files\Fichiers communs\BitDefender
      2008-11-01 11:58 . 2008-11-01 11:59 <REP> d-------- C:\rsit
      2008-11-01 11:58 . 2008-11-01 12:10 <REP> d-------- c:\program files\trend micro
      2008-10-31 17:39 . 2008-11-02 22:07 <REP> d-------- c:\program files\Fighters
      2008-10-31 17:39 . 2008-10-31 17:39 <REP> d-------- c:\documents and settings\All Users\Application Data\Fighters
      2008-10-31 15:42 . 2008-11-07 22:03 <REP> d-------- c:\documents and settings\All Users\Application Data\Software Licensors
      2008-10-31 09:07 . 2008-11-07 20:51 <REP> d-a------ c:\documents and settings\All Users\Application Data\TEMP
      2008-10-30 20:58 . 2001-08-23 17:47 99,840 --a------ c:\windows\system32\srusd.dll
      2008-10-30 20:58 . 2001-08-23 17:47 99,840 --a--c--- c:\windows\system32\dllcache\srusd.dll
      2008-10-30 20:58 . 2001-08-23 17:47 72,192 --a------ c:\windows\system32\fnfilter.dll
      2008-10-30 20:58 . 2001-08-23 17:47 72,192 --a--c--- c:\windows\system32\dllcache\fnfilter.dll
      2008-10-30 20:58 . 2001-08-23 17:20 6,912 --a------ c:\windows\system32\drivers\serscan.sys
      2008-10-30 20:58 . 2001-08-23 17:20 6,912 --a--c--- c:\windows\system32\dllcache\serscan.sys
      2008-10-30 17:01 . 2008-10-30 19:02 <REP> d-------- c:\documents and settings\Arnaud\Application Data\WinButler

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-11-28 23:55 --------- d-----w c:\program files\DivX
      2008-11-23 12:52 --------- d-----w c:\documents and settings\Arnaud\Application Data\Image Zone Express
      2008-11-12 15:54 --------- d-----w c:\program files\ItsLabel
      2008-11-02 21:13 --------- d--h--w c:\program files\InstallShield Installation Information
      2008-10-31 08:06 --------- d-----w c:\program files\Google
      2008-10-27 14:38 --------- d-----w c:\documents and settings\All Users\Application Data\Microgaming
      2008-10-27 14:38 --------- d-----w c:\documents and settings\All Users\Application Data\MGS
      2008-10-24 22:07 --------- d-----w c:\program files\Microsoft Silverlight
      2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
      2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
      2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
      2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
      2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
      2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
      2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
      2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
      2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
      2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
      2008-10-08 18:39 --------- d-----w c:\program files\Fichiers communs\InstallShield
      2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
      2008-09-25 08:03 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
      2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
      2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll
      2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
      2008-08-28 15:46 3,532 ----a-w C:\drmHeader.bin
      2008-05-19 20:09 16,304 ----a-w c:\documents and settings\Arnaud\Application Data\GDIPFONTCACHEV1.DAT
      .

      ((((((((((((((((((((((((((((( snapshot@2008-11-23_15.16.02.11 )))))))))))))))))))))))))))))))))))))))))
      .
      + 2008-10-24 11:21:09 455,296 ------w c:\windows\Driver Cache\i386\mrxsmb.sys
      - 2008-11-01 12:10:58 61,440 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\helpicon.exe
      + 2008-11-24 21:42:17 61,440 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\helpicon.exe
      - 2008-11-01 12:10:58 32,768 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\maintenance_icon.exe
      + 2008-11-24 21:42:17 32,768 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\maintenance_icon.exe
      - 2008-11-01 12:10:58 22,486 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\register_icon.exe
      + 2008-11-24 21:42:17 22,486 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\register_icon.exe
      - 2008-11-01 12:10:57 57,344 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\texticon.exe
      + 2008-11-24 21:42:17 57,344 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\texticon.exe
      + 2008-11-23 21:00:36 32,768 ----a-r c:\windows\Installer\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}\icon.exe
      - 2008-07-18 20:10:48 94,920 -c--a-w c:\windows\system32\dllcache\cdm.dll
      + 2008-10-16 13:09:44 92,696 -c--a-w c:\windows\system32\dllcache\cdm.dll
      - 2008-04-13 17:33:36 1,104,896 -c--a-w c:\windows\system32\dllcache\msxml3.dll
      + 2008-09-04 17:16:10 1,106,944 -c--a-w c:\windows\system32\dllcache\msxml3.dll
      - 2008-04-13 17:33:36 1,306,624 -c--a-w c:\windows\system32\dllcache\msxml6.dll
      + 2008-09-10 01:15:15 1,307,648 -c--a-w c:\windows\system32\dllcache\msxml6.dll
      - 2008-07-18 20:09:44 563,912 -c--a-w c:\windows\system32\dllcache\wuapi.dll
      + 2008-10-16 13:12:20 561,688 -c--a-w c:\windows\system32\dllcache\wuapi.dll
      - 2008-07-18 20:10:42 53,448 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
      + 2008-10-16 13:09:44 51,224 -c--a-w c:\windows\system32\dllcache\wuauclt.exe
      - 2008-07-18 20:09:42 1,811,656 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
      + 2008-10-16 13:13:40 1,809,944 -c--a-w c:\windows\system32\dllcache\wuaueng.dll
      - 2008-07-18 20:09:46 325,832 -c--a-w c:\windows\system32\dllcache\wucltui.dll
      + 2008-10-16 13:12:22 323,608 -c--a-w c:\windows\system32\dllcache\wucltui.dll
      - 2008-07-18 20:10:20 36,552 -c--a-w c:\windows\system32\dllcache\wups.dll
      + 2008-10-16 13:08:58 34,328 -c--a-w c:\windows\system32\dllcache\wups.dll
      - 2008-07-18 20:09:44 205,000 -c--a-w c:\windows\system32\dllcache\wuweb.dll
      + 2008-10-16 13:13:40 202,776 -c--a-w c:\windows\system32\dllcache\wuweb.dll
      + 2008-01-07 16:41:34 196,368 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
      + 2008-03-14 22:31:26 57,344 ----a-w c:\windows\system32\Macromed\Common\SwSupport.dll
      + 2008-03-14 22:29:22 581,632 ----a-w c:\windows\system32\Macromed\Shockwave 10\Control.dll
      + 2008-03-14 22:12:30 1,490,944 ----a-w c:\windows\system32\Macromed\Shockwave 10\dirapiX.dll
      + 2008-03-14 22:29:58 24,576 ----a-w c:\windows\system32\Macromed\Shockwave 10\DynaPlayer.dll
      + 2008-03-14 22:10:06 606,208 ----a-w c:\windows\system32\Macromed\Shockwave 10\iml32X.dll
      + 2008-03-14 22:28:48 339,968 ----a-w c:\windows\system32\Macromed\Shockwave 10\Plugin.dll
      + 2008-03-14 22:28:56 475,136 ----a-w c:\windows\system32\Macromed\Shockwave 10\PluginPing.dll
      + 2008-03-14 22:21:52 180,224 ----a-w c:\windows\system32\Macromed\Shockwave 10\Proj.dll
      + 2008-03-14 22:31:28 77,824 ----a-w c:\windows\system32\Macromed\Shockwave 10\SwInit.exe
      + 2008-03-15 10:38:08 86,016 ----a-w c:\windows\system32\Macromed\Shockwave 10\SwMenuX.dll
      + 2008-03-14 22:31:28 98,304 ----a-w c:\windows\system32\Macromed\Shockwave 10\SwOnce.dll
      - 2008-10-07 19:19:40 16,721,856 ----a-w c:\windows\system32\MRT.exe
      + 2008-11-04 00:10:25 17,318,336 ----a-w c:\windows\system32\MRT.exe
      + 2008-10-16 13:08:58 34,328 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\7.2.6001.788\wups.dll
      + 2008-10-16 13:09:44 43,544 ----a-w c:\windows\system32\SoftwareDistribution\Setup\ServiceStartup\wups2.dll\7.2.6001.788\wups2.dll
      - 2007-11-30 11:19:06 18,296 ------w c:\windows\system32\spmsg.dll
      + 2008-07-08 13:03:54 18,296 ------w c:\windows\system32\spmsg.dll
      + 2007-01-31 12:50:32 913,408 ----a-w c:\windows\system32\xreglib.dll
      + 2008-09-30 15:42:08 1,286,152 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.20.9870.0_x-ww_a32d74cf\msxml4.dll
      + 2008-09-30 15:45:12 91,656 ----a-w c:\windows\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.1.1.0_x-ww_2a41bceb\msxml4r.dll
      .
      -- Instantané actualisé --
      .
      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
      "eMuleAutoStart"="c:\program files\eMule\emule.exe" [2008-08-01 5480448]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
      "BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2008-11-28 368640]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusOverride"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "DisableNotifications"= 1 (0x1)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

      S4 PTK License-FIGHTERS-297811811;PTK License-FIGHTERS-297811811;c:\program files\Fighters\licenseservice.exe []
      S4 PTK Live Update-FIGHTERS-297811811;PTK Live Update-FIGHTERS-297811811;c:\program files\Fighters\updateservice.exe []
      S4 PTK Scanner-FIGHTERS-297811811;PTK Scanner-FIGHTERS-297811811;c:\program files\Fighters\ScannerService.exe []

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      bdx REG_MULTI_SZ scan

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1534df1-4b3d-11dd-ba25-0016ec83fae1}]
      \Shell\AutoRun\command - J:\
      \Shell\explore\Command - RECYCLED\INFO.exe
      \Shell\open\Command - RECYCLED\INFO.exe
      .

      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-11-29 14:43:41
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************

      [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
      "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\

      [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\bdfsfltr]
      "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'winlogon.exe'(600)
      c:\windows\system32\Ati2evxx.dll
      .
      ------------------------ Autres processus actifs ------------------------
      .
      c:\windows\system32\ati2evxx.exe
      c:\windows\system32\ati2evxx.exe
      c:\windows\system32\WgaTray.exe
      c:\program files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      c:\program files\Windows Media Player\wmpnetwk.exe
      .
      **************************************************************************
      .
      Heure de fin: 2008-11-29 14:45:00 - La machine a redémarré [Arnaud]
      ComboFix-quarantined-files.txt 2008-11-29 13:44:38
      ComboFix2.txt 2008-11-25 20:34:38
      ComboFix3.txt 2008-11-23 14:16:32

      Avant-CF: 61,733,441,536 octets libres
      Après-CF: 61,756,633,088 octets libres

      232 --- E O F --- 2008-11-23 21:03:59
      0
  13. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Là tu as fait un nouveau scan avec Combofix (et tu as oublié de désactiver ton antivirus, tu risques d'endommager ton ordinateur...)

    Ce qu'il faut que tu fasses, c'est le CFScript comme indiqué plus bas

    0
  14. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Oula, oui tu as raison, quel boulet je suis :(
    Merci de l'avoir signalé !

    @ pano27 :

    Excuse moi...
    Toujours avec toutes les protections désactivées, fais ceci :

    Ouvre le bloc-notes (Menu démarrer --> programmes --> accessoires --> bloc-notes)
    Copie/colle dans le bloc-notes ce qui entre les lignes ci dessous (sans les lignes) :

    ----------------------------------------------------------
    File::
    c:\windows\system32\onvwcdwj.dll
    c:\windows\system32\frbrkrss.dll
    c:\windows\system32\iykddgbl.dll
    c:\windows\system32\gktuugme.dll
    c:\windows\system32\skajlyvl.dll
    c:\windows\system32\fyufljuu.dll
    c:\windows\system32\vxqdchdy.tmp
    c:\windows\system32\lnkljube.tmp

    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-

    ------------------------------------------------------------------

    - Enregistre ce fichier sur ton bureau (et pas ailleurs !) sous le nom CFScript.txt
    - Quitte le Bloc Notes

    · Fais un glisser/déposer de ce fichier CFScript sur le fichier C-Fix.exe (combofix) comme sur ce lien : http://apu.mabul.org/up/apu/2008/09/06/img-2258535my8h.gif

    * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises : c'est normal !
    Ne touche à rien tant que le scan n'est pas terminé.
    * Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
    * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

    0
    1. pano27
       
      voilà le rapport comme convenu


      ComboFix 08-11-27.03 - Arnaud 2008-12-02 23:36:04.8 - NTFSx86
      Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.144 [GMT 1:00]
      Lancé depuis: c:\documents and settings\Arnaud\Bureau\ComboFix.exe
      Commutateurs utilisés :: c:\documents and settings\Arnaud\Bureau\CFScript.txt
      * Un nouveau point de restauration a été créé
      * Resident AV is active


      [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
      .

      ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
      .

      2008-12-02 18:48 . 2008-12-02 18:48 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Bitdefender
      2008-12-02 18:48 . 2008-12-02 18:48 <REP> d-------- c:\documents and settings\All Users\Application Data\BitDefender
      2008-11-28 19:41 . 2008-11-28 19:41 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Yahoo!
      2008-11-28 19:39 . 2008-12-02 14:32 <REP> d-------- c:\program files\Yahoo!
      2008-11-26 00:52 . 2008-11-26 01:08 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Azureus
      2008-11-26 00:52 . 2008-11-26 00:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Azureus
      2008-11-26 00:51 . 2008-11-26 01:30 <REP> d-------- c:\program files\Vuze
      2008-11-26 00:51 . 2008-11-26 00:51 <REP> d-------- c:\program files\Fichiers communs\i4j_jres
      2008-11-23 16:44 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
      2008-11-23 16:40 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
      2008-11-23 16:14 . 2008-11-23 16:35 122 --a------ c:\windows\system32\privacy.xml
      2008-11-23 13:10 . 2008-12-02 14:30 <REP> d-------- c:\program files\eMule
      2008-11-21 22:35 . 2008-11-21 22:35 <REP> d-------- c:\windows\system32\Adobe
      2008-11-17 19:28 . 2008-11-27 21:38 <REP> d-------- c:\program files\Ad-remover
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Malwarebytes
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
      2008-11-16 22:05 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
      2008-11-16 22:05 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
      2008-11-16 13:05 . 2008-11-28 00:48 <REP> d-------- c:\program files\Navilog1
      2008-11-16 12:08 . 2008-11-16 12:08 912 --a------ c:\windows\system32\onvwcdwj.dll
      2008-11-16 11:55 . 2008-11-16 11:55 912 --a------ c:\windows\system32\frbrkrss.dll
      2008-11-15 10:43 . 2008-11-15 10:43 912 --a------ c:\windows\system32\iykddgbl.dll
      2008-11-14 20:20 . 2008-11-14 20:20 912 --a------ c:\windows\system32\gktuugme.dll
      2008-11-14 10:41 . 2008-11-14 10:41 912 --a------ c:\windows\system32\skajlyvl.dll
      2008-11-13 22:12 . 2008-11-13 22:12 <REP> d-------- c:\program files\Original-Solitaire
      2008-11-12 19:28 . 2008-11-12 19:28 <REP> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
      2008-11-09 13:39 . 2008-11-09 13:39 91 --a------ c:\windows\wininit.ini
      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\program files\Spybot - Search & Destroy
      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
      2008-11-04 23:01 . 2008-11-04 23:01 912 --a------ c:\windows\system32\fyufljuu.dll
      2008-11-03 23:01 . 2008-11-03 23:01 120 ---hs---- c:\windows\system32\vxqdchdy.tmp
      2008-11-02 19:51 . 2008-11-29 14:42 81,984 --a------ c:\windows\system32\bdod.bin
      2008-11-02 18:28 . 2008-11-02 18:29 120 ---hs---- c:\windows\system32\lnkljube.tmp

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-12-02 17:48 --------- d-----w c:\program files\Fichiers communs\BitDefender
      2008-11-28 23:55 --------- d-----w c:\program files\DivX
      2008-11-23 12:52 --------- d-----w c:\documents and settings\Arnaud\Application Data\Image Zone Express
      2008-11-12 15:54 --------- d-----w c:\program files\ItsLabel
      2008-11-07 21:03 --------- d-----w c:\documents and settings\All Users\Application Data\Software Licensors
      2008-11-07 19:51 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
      2008-11-02 21:13 --------- d--h--w c:\program files\InstallShield Installation Information
      2008-11-02 21:07 --------- d-----w c:\program files\Fighters
      2008-11-01 12:08 --------- d-----w c:\program files\BitDefender
      2008-11-01 11:10 --------- d-----w c:\program files\trend micro
      2008-10-31 16:39 --------- d-----w c:\documents and settings\All Users\Application Data\Fighters
      2008-10-31 08:06 --------- d-----w c:\program files\Google
      2008-10-30 18:02 --------- d-----w c:\documents and settings\Arnaud\Application Data\WinButler
      2008-10-27 14:38 --------- d-----w c:\documents and settings\All Users\Application Data\Microgaming
      2008-10-27 14:38 --------- d-----w c:\documents and settings\All Users\Application Data\MGS
      2008-10-24 22:07 --------- d-----w c:\program files\Microsoft Silverlight
      2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
      2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
      2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
      2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
      2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
      2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
      2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
      2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
      2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
      2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
      2008-10-08 18:39 --------- d-----w c:\program files\Fichiers communs\InstallShield
      2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
      2008-09-25 08:03 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
      2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
      2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll
      2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
      2008-05-19 20:09 16,304 ----a-w c:\documents and settings\Arnaud\Application Data\GDIPFONTCACHEV1.DAT
      .

      ((((((((((((((((((((((((((((( snapshot_2008-11-29_14.44.11.10 )))))))))))))))))))))))))))))))))))))))))
      .
      - 2008-11-24 21:42:17 61,440 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\helpicon.exe
      + 2008-12-02 17:49:09 61,440 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\helpicon.exe
      - 2008-11-24 21:42:17 32,768 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\maintenance_icon.exe
      + 2008-12-02 17:49:09 32,768 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\maintenance_icon.exe
      - 2008-11-24 21:42:17 22,486 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\register_icon.exe
      + 2008-12-02 17:49:09 22,486 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\register_icon.exe
      - 2008-11-24 21:42:17 57,344 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\texticon.exe
      + 2008-12-02 17:49:08 57,344 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\texticon.exe
      - 2008-01-07 16:41:34 196,368 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
      + 2007-08-02 15:03:44 188,432 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
      + 2007-07-20 13:54:30 77,824 ----a-w c:\windows\system32\xcomm.dll
      .
      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
      "BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2007-10-31 311296]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusOverride"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "DisableNotifications"= 1 (0x1)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

      S4 PTK License-FIGHTERS-297811811;PTK License-FIGHTERS-297811811;c:\program files\Fighters\licenseservice.exe []
      S4 PTK Live Update-FIGHTERS-297811811;PTK Live Update-FIGHTERS-297811811;c:\program files\Fighters\updateservice.exe []
      S4 PTK Scanner-FIGHTERS-297811811;PTK Scanner-FIGHTERS-297811811;c:\program files\Fighters\ScannerService.exe []

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      bdx REG_MULTI_SZ scan

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1534df1-4b3d-11dd-ba25-0016ec83fae1}]
      \Shell\AutoRun\command - J:\
      \Shell\explore\Command - RECYCLED\INFO.exe
      \Shell\open\Command - RECYCLED\INFO.exe

      *Newly Created Service* - BDFSFLTR
      .

      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-12-02 23:38:08
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
      "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\





      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
      "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'winlogon.exe'(592)
      c:\windows\system32\Ati2evxx.dll
      .
      Heure de fin: 2008-12-02 23:38:59
      ComboFix-quarantined-files.txt 2008-12-02 22:38:52
      ComboFix2.txt 2008-12-02 13:49:22
      ComboFix3.txt 2008-11-29 13:45:01
      ComboFix4.txt 2008-11-25 20:34:38
      ComboFix5.txt 2008-12-02 20:43:05

      Avant-CF: 61 821 313 024 octets libres
      Après-CF: 61,851,443,200 octets libres

      166 --- E O F --- 2008-11-23 21:03:59
      0
  15. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Le script n'a pas été pris en compte...
    De plus, tu as oublié de désactiver ton antivirus avant de lancer le scan, tu prends des risques...

    Pour le script, vérifie qu'il n'y a aucune ligne blanche au début (la première ligne est File:: ) et qu'il est complet.

    0
    1. pano27
       
      bonjour
      ci joint nouveau combo fix nous avons refait toute la manip en désactivant bitdefender normalement.
      a+ pano2
      ComboFix 08-11-27.03 - Arnaud 2008-12-02 23:36:04.8 - NTFSx86
      Microsoft Windows XP Professionnel 5.1.2600.3.1252.1.1036.18.144 [GMT 1:00]
      Lancé depuis: c:\documents and settings\Arnaud\Bureau\ComboFix.exe
      Commutateurs utilisés :: c:\documents and settings\Arnaud\Bureau\CFScript.txt
      * Un nouveau point de restauration a été créé
      * Resident AV is active


      [COLOR=RED][B]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/B][/COLOR]
      .

      ((((((((((((((((((((((((((((( Fichiers créés du 2008-11-02 au 2008-12-02 ))))))))))))))))))))))))))))))))))))
      .

      2008-12-02 18:48 . 2008-12-02 18:48 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Bitdefender
      2008-12-02 18:48 . 2008-12-02 18:48 <REP> d-------- c:\documents and settings\All Users\Application Data\BitDefender
      2008-11-28 19:41 . 2008-11-28 19:41 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Yahoo!
      2008-11-28 19:39 . 2008-12-02 14:32 <REP> d-------- c:\program files\Yahoo!
      2008-11-26 00:52 . 2008-11-26 01:08 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Azureus
      2008-11-26 00:52 . 2008-11-26 00:52 <REP> d-------- c:\documents and settings\All Users\Application Data\Azureus
      2008-11-26 00:51 . 2008-11-26 01:30 <REP> d-------- c:\program files\Vuze
      2008-11-26 00:51 . 2008-11-26 00:51 <REP> d-------- c:\program files\Fichiers communs\i4j_jres
      2008-11-23 16:44 . 2008-10-24 12:21 455,296 -----c--- c:\windows\system32\dllcache\mrxsmb.sys
      2008-11-23 16:40 . 2008-10-16 14:06 208,744 --a------ c:\windows\system32\muweb.dll
      2008-11-23 16:14 . 2008-11-23 16:35 122 --a------ c:\windows\system32\privacy.xml
      2008-11-23 13:10 . 2008-12-02 14:30 <REP> d-------- c:\program files\eMule
      2008-11-21 22:35 . 2008-11-21 22:35 <REP> d-------- c:\windows\system32\Adobe
      2008-11-17 19:28 . 2008-11-27 21:38 <REP> d-------- c:\program files\Ad-remover
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\Arnaud\Application Data\Malwarebytes
      2008-11-16 22:05 . 2008-11-16 22:05 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
      2008-11-16 22:05 . 2008-10-22 16:10 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
      2008-11-16 22:05 . 2008-10-22 16:10 15,504 --a------ c:\windows\system32\drivers\mbam.sys
      2008-11-16 13:05 . 2008-11-28 00:48 <REP> d-------- c:\program files\Navilog1
      2008-11-16 12:08 . 2008-11-16 12:08 912 --a------ c:\windows\system32\onvwcdwj.dll
      2008-11-16 11:55 . 2008-11-16 11:55 912 --a------ c:\windows\system32\frbrkrss.dll
      2008-11-15 10:43 . 2008-11-15 10:43 912 --a------ c:\windows\system32\iykddgbl.dll
      2008-11-14 20:20 . 2008-11-14 20:20 912 --a------ c:\windows\system32\gktuugme.dll
      2008-11-14 10:41 . 2008-11-14 10:41 912 --a------ c:\windows\system32\skajlyvl.dll
      2008-11-13 22:12 . 2008-11-13 22:12 <REP> d-------- c:\program files\Original-Solitaire
      2008-11-12 19:28 . 2008-11-12 19:28 <REP> d-------- c:\documents and settings\All Users\Application Data\HP Product Assistant
      2008-11-09 13:39 . 2008-11-09 13:39 91 --a------ c:\windows\wininit.ini
      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\program files\Spybot - Search & Destroy
      2008-11-07 21:19 . 2008-11-23 14:54 <REP> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
      2008-11-04 23:01 . 2008-11-04 23:01 912 --a------ c:\windows\system32\fyufljuu.dll
      2008-11-03 23:01 . 2008-11-03 23:01 120 ---hs---- c:\windows\system32\vxqdchdy.tmp
      2008-11-02 19:51 . 2008-11-29 14:42 81,984 --a------ c:\windows\system32\bdod.bin
      2008-11-02 18:28 . 2008-11-02 18:29 120 ---hs---- c:\windows\system32\lnkljube.tmp

      .
      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2008-12-02 17:48 --------- d-----w c:\program files\Fichiers communs\BitDefender
      2008-11-28 23:55 --------- d-----w c:\program files\DivX
      2008-11-23 12:52 --------- d-----w c:\documents and settings\Arnaud\Application Data\Image Zone Express
      2008-11-12 15:54 --------- d-----w c:\program files\ItsLabel
      2008-11-07 21:03 --------- d-----w c:\documents and settings\All Users\Application Data\Software Licensors
      2008-11-07 19:51 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
      2008-11-02 21:13 --------- d--h--w c:\program files\InstallShield Installation Information
      2008-11-02 21:07 --------- d-----w c:\program files\Fighters
      2008-11-01 12:08 --------- d-----w c:\program files\BitDefender
      2008-11-01 11:10 --------- d-----w c:\program files\trend micro
      2008-10-31 16:39 --------- d-----w c:\documents and settings\All Users\Application Data\Fighters
      2008-10-31 08:06 --------- d-----w c:\program files\Google
      2008-10-30 18:02 --------- d-----w c:\documents and settings\Arnaud\Application Data\WinButler
      2008-10-27 14:38 --------- d-----w c:\documents and settings\All Users\Application Data\Microgaming
      2008-10-27 14:38 --------- d-----w c:\documents and settings\All Users\Application Data\MGS
      2008-10-24 22:07 --------- d-----w c:\program files\Microsoft Silverlight
      2008-10-24 11:21 455,296 ----a-w c:\windows\system32\drivers\mrxsmb.sys
      2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
      2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
      2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
      2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
      2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
      2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
      2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
      2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
      2008-10-16 13:06 268,648 ----a-w c:\windows\system32\mucltui.dll
      2008-10-08 18:39 --------- d-----w c:\program files\Fichiers communs\InstallShield
      2008-09-30 15:43 1,286,152 ----a-w c:\windows\system32\msxml4.dll
      2008-09-25 08:03 161,096 ----a-w c:\windows\system32\DivXCodecVersionChecker.exe
      2008-09-15 15:26 1,846,528 ----a-w c:\windows\system32\win32k.sys
      2008-09-10 01:15 1,307,648 ----a-w c:\windows\system32\msxml6.dll
      2008-09-04 17:16 1,106,944 ----a-w c:\windows\system32\msxml3.dll
      2008-05-19 20:09 16,304 ----a-w c:\documents and settings\Arnaud\Application Data\GDIPFONTCACHEV1.DAT
      .

      ((((((((((((((((((((((((((((( snapshot_2008-11-29_14.44.11.10 )))))))))))))))))))))))))))))))))))))))))
      .
      - 2008-11-24 21:42:17 61,440 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\helpicon.exe
      + 2008-12-02 17:49:09 61,440 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\helpicon.exe
      - 2008-11-24 21:42:17 32,768 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\maintenance_icon.exe
      + 2008-12-02 17:49:09 32,768 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\maintenance_icon.exe
      - 2008-11-24 21:42:17 22,486 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\register_icon.exe
      + 2008-12-02 17:49:09 22,486 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\register_icon.exe
      - 2008-11-24 21:42:17 57,344 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\texticon.exe
      + 2008-12-02 17:49:08 57,344 ----a-r c:\windows\Installer\{7764592F-FFE0-4292-82B7-9732C66F10E5}\texticon.exe
      - 2008-01-07 16:41:34 196,368 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
      + 2007-08-02 15:03:44 188,432 ----a-w c:\windows\system32\drivers\bdfsfltr.sys
      + 2007-07-20 13:54:30 77,824 ----a-w c:\windows\system32\xcomm.dll
      .
      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
      REGEDIT4

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2008\IEShow.exe" [2007-10-09 61440]
      "BDAgent"="c:\program files\BitDefender\BitDefender 2008\bdagent.exe" [2007-10-31 311296]

      [HKEY_LOCAL_MACHINE\software\microsoft\security center]
      "AntiVirusOverride"=dword:00000001

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
      "DisableNotifications"= 1 (0x1)

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
      "c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=

      S4 PTK License-FIGHTERS-297811811;PTK License-FIGHTERS-297811811;c:\program files\Fighters\licenseservice.exe []
      S4 PTK Live Update-FIGHTERS-297811811;PTK Live Update-FIGHTERS-297811811;c:\program files\Fighters\updateservice.exe []
      S4 PTK Scanner-FIGHTERS-297811811;PTK Scanner-FIGHTERS-297811811;c:\program files\Fighters\ScannerService.exe []

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
      bdx REG_MULTI_SZ scan

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d1534df1-4b3d-11dd-ba25-0016ec83fae1}]
      \Shell\AutoRun\command - J:\
      \Shell\explore\Command - RECYCLED\INFO.exe
      \Shell\open\Command - RECYCLED\INFO.exe

      *Newly Created Service* - BDFSFLTR
      .

      **************************************************************************

      catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-12-02 23:38:08
      Windows 5.1.2600 Service Pack 3 NTFS

      Recherche de processus cachés ...

      Recherche d'éléments en démarrage automatique cachés ...

      Recherche de fichiers cachés ...

      Scan terminé avec succès
      Fichiers cachés: 0

      **************************************************************************

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
      "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\

      [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
      "ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
      .
      --------------------- DLLs chargées dans les processus actifs ---------------------

      - - - - - - - > 'winlogon.exe'(592)
      c:\windows\system32\Ati2evxx.dll
      .
      Heure de fin: 2008-12-02 23:38:59
      ComboFix-quarantined-files.txt 2008-12-02 22:38:52
      ComboFix2.txt 2008-12-02 13:49:22
      ComboFix3.txt 2008-11-29 13:45:01
      ComboFix4.txt 2008-11-25 20:34:38
      ComboFix5.txt 2008-12-02 20:43:05

      Avant-CF: 61 821 313 024 octets libres
      Après-CF: 61,851,443,200 octets libres

      166 --- E O F --- 2008-11-23 21:03:59
      7
      0
  16. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Le rapport est daté du 27 novembre... On va utiliser un autre logiciel :

    ---> Télécharge OTMoveIt3 (de OldTimer) sur ton Bureau : http://oldtimer.geekstogo.com/OTMoveIt3.exe

    --> Redémarre en mode sans échec : Tuto
    Attention, n'utilise surtout pas la méthode avec l'utilitaire de configuration système !

    ---> Double-clique sur OTMoveIt3.exe afin de le lancer.
    ---> Copie/colle le texte suivant dans le cadre « Paste Instructions for Items to be Moved » et clique sur Moveit :

    :processes 
    explorer.exe 
    
    :files 
    c:\windows\system32\onvwcdwj.dll 
    c:\windows\system32\frbrkrss.dll 
    c:\windows\system32\iykddgbl.dll 
    c:\windows\system32\gktuugme.dll 
    c:\windows\system32\skajlyvl.dll 
    c:\windows\system32\fyufljuu.dll 
    c:\windows\system32\vxqdchdy.tmp 
    c:\windows\system32\lnkljube.tmp 
    
    :Reg 
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] 
    "AppInit_DLLs"=- 
    
    :commands 
    [purity] 
    [emptytemp] 
    [start explorer] 
    [reboot] 


    Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.

    ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles
    Le nom du rapport correspond au moment de sa création : date_heure.log

    0
    1. pano27
       
      bonjour
      je n arrive pas a redemarrer en mode sans échec ya t il une subtilite que je ne connais pas????
      merci davance
      0
  17. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Tu as essayé avec quelle touche ? C'est généralement sur la touche F8 qu'il faut appuyer, mais c'est aussi F5 sur certains PC. Il faut tapoter plusieurs fois de suite dessus avant l'apparition du logo Windows.

    Quand tu le fais, rien ne se passe ?

    0
    1. pano27
       
      bonsoir.desolee j ai peu suivi l affaire depuis 10 jours.un peu debordee par ailleurs.
      ci joint rapport moveit comme demande
      ========== PROCESSES ==========
      Process explorer.exe killed successfully.
      ========== FILES ==========
      LoadLibrary failed for c:\windows\system32\onvwcdwj.dll
      c:\windows\system32\onvwcdwj.dll NOT unregistered.
      c:\windows\system32\onvwcdwj.dll moved successfully.
      LoadLibrary failed for c:\windows\system32\frbrkrss.dll
      c:\windows\system32\frbrkrss.dll NOT unregistered.
      c:\windows\system32\frbrkrss.dll moved successfully.
      LoadLibrary failed for c:\windows\system32\iykddgbl.dll
      c:\windows\system32\iykddgbl.dll NOT unregistered.
      c:\windows\system32\iykddgbl.dll moved successfully.
      LoadLibrary failed for c:\windows\system32\gktuugme.dll
      c:\windows\system32\gktuugme.dll NOT unregistered.
      c:\windows\system32\gktuugme.dll moved successfully.
      LoadLibrary failed for c:\windows\system32\skajlyvl.dll
      c:\windows\system32\skajlyvl.dll NOT unregistered.
      c:\windows\system32\skajlyvl.dll moved successfully.
      LoadLibrary failed for c:\windows\system32\fyufljuu.dll
      c:\windows\system32\fyufljuu.dll NOT unregistered.
      c:\windows\system32\fyufljuu.dll moved successfully.
      c:\windows\system32\vxqdchdy.tmp moved successfully.
      c:\windows\system32\lnkljube.tmp moved successfully.
      ========== REGISTRY ==========
      Registry value HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows\\AppInit_DLLs not found.
      ========== COMMANDS ==========
      User's Temp folder emptied.
      User's Temporary Internet Files folder emptied.
      User's Internet Explorer cache folder emptied.
      Local Service Temp folder emptied.
      File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
      Local Service Temporary Internet Files folder emptied.
      Windows Temp folder emptied.
      Temp folders emptied.
      Explorer started successfully

      OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12142008_220318

      SUITE AU REDEMARRAGE EN MODE SANS ECHEC J AI UN SOUCIS AVEC WINDOWS
      LE MESSAGE SUIVANT APPARAIT
      Cette copie de Windows n'a pas pu être validée.
      La clé de produit Windows détectée sur votre ordinateur n'a pas été attribuée par Microsoft.

      QUE DOIS JE FAIRE?????
      MERCI D AVANCE PANO 27
      0
  18. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Bonsoir,

    Le problème c'est qu'en 10 jours, si tu as réutilisé ton PC, il y a des chances que d'autres fichiers infectés se soient créés... Pour vérifier :
    - Relance MalwareBytes anti-malware et mets le à jour
    - Puis va dans l'onglet "Recherche", coche "Exécuter un examen rapide" puis "Rechercher"
    - Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
    - A la fin du scan, clique sur Afficher les résultats
    - Coche tous les éléments détectés puis clique sur Supprimer la sélection
    - Enregistre le rapport
    - S'il t'est demandé de redémarrer, clique sur Yes

    Poste le rapport de scan après la suppression ici

    Pour le message de Windows, ce n'est pas grave, il va juste falloir refaire l'activation :
    * Menu Démarrer
    * Tous les programmes
    * Accessoires
    * Outils système
    * Clique sur Activation de Windows et laisse toi guider.

    0
    1. pano27
       
      bonsoir ci joint nouveau scan
      Malwarebytes' Anti-Malware 1.31
      Version de la base de données: 1501
      Windows 5.1.2600 Service Pack 3

      15/12/2008 20:16:32
      mbam-log-2008-12-15 (20-16-32).txt

      Type de recherche: Examen rapide
      Eléments examinés: 48586
      Temps écoulé: 4 minute(s), 34 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 4

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      C:\Documents and Settings\Arnaud\Local Settings\Application Data\wgmmuco_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Arnaud\Local Settings\Application Data\wgmmuco_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Arnaud\Local Settings\Application Data\wgmmuco.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
      C:\Documents and Settings\Arnaud\Local Settings\Application Data\wgmmuco.exe (Adware.Navipromo.H) -> Delete on reboot.
      0
  19. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Re,

    L'un des utilisateurs de l'ordinateur a réinstallé l'infection navipromo que nous avions supprimé... Pour rappel, cette infection s'installe à partir des logiciels piégés suivants :

    * go-astro
    * GoRecord
    * HotTVPlayer / HotTVPlayer & Paris Hilton
    * Live-Player
    * MailSkinner
    * Messenger Skinner
    * Instant Access
    * InternetGameBox
    * Officiale Emule (Version d'Emule modifiée)
    * Sudoplanet
    * Webmediaplayer

    Attention à ce que tu télécharges, et pense à prévenir tous les utilisateurs de l'ordinateur...

    Poste un nouveau rapport hijackthis stp

    0
    1. pano27
       
      CI JOINT RAPPORT HIJACKTHIS
      PANO27

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 21:28:55, on 16/12/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16762)
      Boot mode: Normal

      Running processes:
      C:\windows\System32\smss.exe
      C:\windows\system32\winlogon.exe
      C:\windows\system32\services.exe
      C:\windows\system32\lsass.exe
      C:\windows\system32\Ati2evxx.exe
      C:\windows\system32\svchost.exe
      C:\windows\System32\svchost.exe
      C:\windows\system32\spoolsv.exe
      C:\windows\System32\svchost.exe
      C:\windows\system32\svchost.exe
      C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
      C:\windows\System32\svchost.exe
      C:\windows\system32\Ati2evxx.exe
      C:\windows\system32\WgaTray.exe
      C:\windows\Explorer.EXE
      C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
      C:\windows\system32\ctfmon.exe
      C:\Program Files\trend micro\HijackThis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2008\IEToolbar.dll
      O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe"
      O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
      O4 - HKCU\..\Run: [wgmmuco] "c:\documents and settings\arnaud\local settings\application data\wgmmuco.exe" wgmmuco
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\system32\Ati2evxx.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe
      O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S.R.L. - C:\Program Files\BitDefender\BitDefender 2008\vsserv.exe
      O23 - Service: BitDefender Communicator (XCOMM) - BitDefender - C:\Program Files\Fichiers communs\BitDefender\BitDefender Communicator\xcommsvr.exe
      0
    2. pano27
       
      CI JOINT RAPPORT navilog1.exe

      Search Navipromo version 3.7.0 commencé le 18/12/2008 à 23:58:14,87

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Postez ce rapport sur le forum pour le faire analyser !!!
      !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

      Outil exécuté depuis C:\Program Files\navilog1

      Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO

      Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
      X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) D CPU 3.20GHz )
      BIOS : BIOS Date: 01/18/2007 Ver: 08.00.12
      USER : Arnaud ( Administrator )
      BOOT : Normal boot

      Antivirus : Bitdefender Antivirus 8.0 (Activated)


      C:\ (Local Disk) - NTFS - Total:92 Go (Free:57 Go)
      D:\ (Local Disk) - NTFS - Total:93 Go (Free:93 Go)
      E:\ (USB)
      F:\ (USB)
      G:\ (USB)
      H:\ (USB)
      I:\ (CD or DVD)


      Recherche executé en mode normal

      *** Recherche Programmes installés ***

      Favorit
      Favorit
      Favorit
      Favorit

      *** Recherche dossiers dans "C:\windows" ***


      *** Recherche dossiers dans "C:\Program Files" ***


      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


      *** Recherche dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


      *** Recherche dossiers dans "c:\docume~1\alluse~1\applic~1" ***


      *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\applic~1" ***


      *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" ***


      *** Recherche dossiers dans "C:\Documents and Settings\Arnaud\menudm~1\progra~1" ***


      *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
      pour + d'infos : http://www.gmer.net



      *** Recherche avec GenericNaviSearch ***
      !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
      !!! A vérifier impérativement avant toute suppression manuelle !!!

      * Recherche dans "C:\windows\system32" *

      * Recherche dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *



      *** Recherche fichiers ***



      *** Recherche clés spécifiques dans le Registre ***
      !! Les clés trouvées ne sont pas forcément infectées !!

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "wgmmuco"="\"c:\\documents and settings\\arnaud\\local settings\\application data\\wgmmuco.exe\" wgmmuco"

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "emseeyk"="\"c:\\documents and settings\\arnaud\\local settings\\application data\\emseeyk.exe\" emseeyk"


      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche nouveaux fichiers Instant Access :


      2)Recherche Heuristique :

      * Dans "C:\windows\system32" :


      * Dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" :

      emseeyk.exe trouvé !
      emseeyk.dat trouvé !
      emseeyk_nav.dat trouvé !
      emseeyk_navps.dat trouvé !

      3)Recherche Certificats :

      Certificat Egroup absent !
      Certificat Electronic-Group trouvé !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit trouvé !
      Certificat Sunny-Day-Design-Ltd absent !

      4)Recherche autres dossiers et fichiers connus :



      *** Analyse terminée le 19/12/2008 à 0:00:53,34 ***
      0
    3. pano27
       
      merci pour ton aide
      comme convenu voilà le rapport Navilog que tu as demandé

      Clean Navipromo version 3.7.0 commencé le 19/12/2008 à 22:59:23,67

      Outil exécuté depuis C:\Program Files\navilog1

      Mise à jour le 10.12.2008 à 21h00 par IL-MAFIOSO

      Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
      X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) D CPU 3.20GHz )
      BIOS : BIOS Date: 01/18/2007 Ver: 08.00.12
      USER : Arnaud ( Administrator )
      BOOT : Normal boot

      Antivirus : Bitdefender Antivirus 8.0 (Activated)


      C:\ (Local Disk) - NTFS - Total:92 Go (Free:57 Go)
      D:\ (Local Disk) - NTFS - Total:93 Go (Free:93 Go)
      E:\ (USB)
      F:\ (USB)
      G:\ (USB)
      H:\ (USB)
      I:\ (CD or DVD)


      Mode suppression automatique
      avec prise en charge résultats Catchme et GNS


      Nettoyage exécuté au redémarrage de l'ordinateur


      *** fsbl1.txt non trouvé ***
      (Assurez-vous que Catchme n'avait rien trouvé lors de la recherche)


      *** Suppression avec sauvegardes résultats GenericNaviSearch ***

      * Suppression dans "C:\windows\System32" *


      * Suppression dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *



      *** Suppression dossiers dans "C:\windows" ***


      *** Suppression dossiers dans "C:\Program Files" ***


      *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1\progra~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\All Users\menudm~1" ***


      *** Suppression dossiers dans "c:\docume~1\alluse~1\applic~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\applic~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" ***


      *** Suppression dossiers dans "C:\Documents and Settings\Arnaud\menudm~1\progra~1" ***



      *** Suppression fichiers ***


      *** Suppression fichiers temporaires ***

      Nettoyage contenu C:\windows\Temp effectué !
      Nettoyage contenu C:\Documents and Settings\Arnaud\locals~1\Temp effectué !

      *** Traitement Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Suppression avec sauvegardes nouveaux fichiers Instant Access :

      2)Recherche, création sauvegardes et suppression Heuristique :


      * Dans "C:\windows\system32" *


      C:\windows\prefetch\emseeyk*.pf trouvé !
      Copie C:\windows\prefetch\emseeyk*.pf réalisée avec succès !
      C:\windows\prefetch\emseeyk*.pf supprimé !

      C:\windows\prefetch\wgmmuco*.pf trouvé !
      Copie C:\windows\prefetch\wgmmuco*.pf réalisée avec succès !
      C:\windows\prefetch\wgmmuco*.pf supprimé !


      * Dans "C:\Documents and Settings\Arnaud\locals~1\applic~1" *


      emseeyk.exe trouvé !
      Copie emseeyk.exe réalisée avec succès !
      emseeyk.exe supprimé !

      emseeyk.dat trouvé !
      Copie emseeyk.dat réalisée avec succès !
      emseeyk.dat supprimé !

      emseeyk_nav.dat trouvé !
      Copie emseeyk_nav.dat réalisée avec succès !
      emseeyk_nav.dat supprimé !

      emseeyk_navps.dat trouvé !
      Copie emseeyk_navps.dat réalisée avec succès !
      emseeyk_navps.dat supprimé !


      *** Sauvegarde du Registre vers dossier Safebackup ***

      sauvegarde du Registre réalisée avec succès !

      *** Nettoyage Registre ***

      Nettoyage Registre Ok


      *** Certificats ***

      Certificat Egroup absent !
      Certificat Electronic-Group supprimé !
      Certificat Montorgueil absent !
      Certificat OOO-Favorit supprimé !
      Certificat Sunny-Day-Design-Ltdt absent !

      *** Recherche autres dossiers et fichiers connus ***



      *** Nettoyage terminé le 19/12/2008 à 23:03:26,32 ***
      0
    4. pano27
       
      bonjour,
      comme convenu les rapports (RSIT) que tu as demandé dans deux messages différents

      le premier

      info.txt logfile of random's system information tool 1.05 2008-12-30 11:28:08

      ======Uninstall list======

      -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
      -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL
      -->C:\WINDOWS\UNRecode.exe /UNINSTALL
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
      Ad-remover-->C:\Program Files\Ad-remover\Uninstal.exe
      Assistant de connexion Windows Live-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986}
      ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
      Avanquest update-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{76E41F43-59D2-4F30-BA42-9A762EE1E8DE}\Setup.exe" -l0x40c
      BitDefender Antivirus 2008-->MsiExec.exe /I{7764592F-FFE0-4292-82B7-9732C66F10E5}
      Casino Spin Palace-->C:\MicroGaming\Casino\SpinPalace\install.exe -uninstall
      CloneDVD2-->"C:\Program Files\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="C:\Program Files\Elaborate Bytes\CloneDVD2"
      Correctif pour Lecteur Windows Media 11 (KB939683)-->"C:\WINDOWS\$NtUninstallKB939683$\spuninst\spuninst.exe"
      Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      DVD Decoder Pak for Windows XP-->MsiExec.exe /X{92C5DB3D-9D6F-4324-BB11-57825F4C2635}
      DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
      Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /u
      Favorit-->"c:\documents and settings\arnaud\local settings\application data\sgkke.exe" -uninstall
      Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
      Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll"
      HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
      HP Extended Capabilities 6.1-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
      HP Imaging Device Functions 6.1-->C:\Program Files\HP\Digital Imaging\DigitalImagingMonitor\hpzscr01.exe -datfile hpqbud01.dat
      HP Photosmart Essential-->MsiExec.exe /X{D7CAE58E-26DE-49B7-A75D-EAEDF76726BE}
      HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
      HP Product Detection-->MsiExec.exe /X{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}
      HP PSC & OfficeJet 6.1.A-->"C:\Program Files\HP\Digital Imaging\{E5A8DDAB-AE80-48C6-A75B-D0FAB83B299D}\setup\hpzscr01.exe" -datfile hposcr08.dat
      HP Solution Center and Imaging Support Tools 6.1-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
      ItsTV 3.0-->"C:\Program Files\ItsLabel\unins000.exe"
      Lecteur Windows Media 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
      Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
      Microsoft .NET Framework 1.1 French Language Pack-->MsiExec.exe /X{9A394342-4A68-4EBA-85A6-55B559F4E700}
      Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
      Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
      Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\windows\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\windows\$NtUninstallKB954600$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\windows\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955839)-->"C:\windows\$NtUninstallKB955839$\spuninst\spuninst.exe"
      mobile PhoneTools-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F18E8A0F-BE99-4305-96A5-6C0FD9D7D999}\setup.exe" -l0x40c
      MSN-->C:\Program Files\MSN\MsnInstaller\msninst.exe /Action:ARP
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      Navilog1 3.7.0-->"C:\Program Files\Navilog1\unins000.exe"
      Nero 8-->MsiExec.exe /X{5FCCD531-1B38-4A94-924C-127F722F1036}
      neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
      Original-Solitaire-->C:\Program Files\Original-Solitaire\uninst.exe
      Picasa 2-->"C:\Program Files\Picasa2\Uninstall.exe"
      QCad-->C:\WINDOWS\iun3405.exe C:\Program Files\QCad
      QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x40c -removeonly
      Shareaza 2.3.1.0-->"C:\Program Files\Shareaza\Uninstall\unins000.exe"
      TV sur PC-->C:\Program Files\Neuf\TV_PC\uninstall.exe
      VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027}
      VirginMega.Fr Premium-->MsiExec.exe /I{EE467474-04A8-48D5-8DDF-0F8D3A3CCBE5}
      Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
      Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
      Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
      Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"

      System event log

      Computer Name: PCDEARNAUD
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

      Record Number: 5965
      Source Name: Service Control Manager
      Time Written: 20081116140405.000000+060
      Event Type: Informations
      User: PCDEARNAUD\Arnaud

      Computer Name: PCDEARNAUD
      Event Code: 7036
      Message: Le service Téléphonie est entré dans l'état : en cours d'exécution.

      Record Number: 5964
      Source Name: Service Control Manager
      Time Written: 20081116140405.000000+060
      Event Type: Informations
      User:

      Computer Name: PCDEARNAUD
      Event Code: 35
      Message: Le service de temps synchronise maintenant l'heure système avec la
      source de temps time.windows.com (ntp.m|0x1|192.168.1.20:123->207.46.197.32:123).

      Record Number: 5963
      Source Name: W32Time
      Time Written: 20081116140404.000000+060
      Event Type: Informations
      User:

      Computer Name: PCDEARNAUD
      Event Code: 7036
      Message: Le service Service de la passerelle de la couche Application est entré dans l'état : en cours d'exécution.

      Record Number: 5962
      Source Name: Service Control Manager
      Time Written: 20081116140400.000000+060
      Event Type: Informations
      User:

      Computer Name: PCDEARNAUD
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service Service de la passerelle de la couche Application.

      Record Number: 5961
      Source Name: Service Control Manager
      Time Written: 20081116140400.000000+060
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      Application event log

      Computer Name: PCDEARNAUD
      Event Code: 105
      Message: The service was started.

      Record Number: 6007
      Source Name: ATI Smart
      Time Written: 20081107205535.000000+060
      Event Type: Informations
      User:

      Computer Name: PCDEARNAUD
      Event Code: 1524
      Message: Windows ne peut pas décharger vos classes fichier de Registre - il est en cours d'utilisation par d'autres applications ou services. Le fichier sera déchargé quand il ne sera plus utilisé.



      Record Number: 6006
      Source Name: Userenv
      Time Written: 20081107205350.000000+060
      Event Type: Avertissement
      User: PCDEARNAUD\Arnaud

      Computer Name: PCDEARNAUD
      Event Code: 1002
      Message: Application bloquée iexplore.exe, version 7.0.6000.16735, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

      Record Number: 6005
      Source Name: Application Hang
      Time Written: 20081107203802.000000+060
      Event Type: erreur
      User:

      Computer Name: PCDEARNAUD
      Event Code: 1002
      Message: Application bloquée ItsTV.exe, version 1.0.0.1, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

      Record Number: 6004
      Source Name: Application Hang
      Time Written: 20081107203519.000000+060
      Event Type: erreur
      User:

      Computer Name: PCDEARNAUD
      Event Code: 1002
      Message: Application bloquée ItsTV.exe, version 1.0.0.1, module bloqué hungapp, version 0.0.0.0, adresse de blocage 0x00000000.

      Record Number: 6003
      Source Name: Application Hang
      Time Written: 20081107203519.000000+060
      Event Type: erreur
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=15
      "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 6 Stepping 4, GenuineIntel
      "PROCESSOR_REVISION"=0604
      "NUMBER_OF_PROCESSORS"=1
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP

      -----------------EOF-----------------
      0
  20. anthony5151 Messages postés 10927 Statut Contributeur sécurité 790
     
    Re,

    Désolé pour le délai de réponse.

    # Télécharge ToolsCleaner sur ton Bureau pour nettoyer l'ordi de tous les outils qu'on a utilisé : ToolsCleaner
    Lance le, clique sur Recherche et laisse le scan se finir, puis clique sur Suppression pour nettoyer.
    Tu peux aussi supprimer les fichiers temporaires.
    S'il ne supprime pas tout, supprime manuellement ce qui reste.

    Vérifie en particulier que navilog a bien été supprimé.

    # Ensuite, désactive le TeaTimer de Spybot (je te conseille de ne pas le réactiver ensuite...)
    Lance Spybot --> clique sur Mode => coche Mode avancé => Outils => Résident => décoche la case Résident Tea Timer → redémarre ton ordinateur

    # Puis télécharge à nouveau Navilog1 depuis-ce lien : http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, lance Navilog depuis le raccourci présent sur le bureau

    Au menu principal, Fais le choix 1
    Laisse toi guider et patiente.
    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche le bloc note va s'ouvrir.
    Copie-colle l'intégralité du rapport ici.

    0
  • 1
  • 2