BV:AutoRun-E [Wrm]

Résolu
Bonjour,
Voici un virus repéré par Avast: BV:AutoRun-E [Wrm].
Comment faire pour le supprimer?
Dois-je le supprimer?
Merci d'avance!
Configuration: Windows XP
Internet Explorer 7.0

49 réponses

Résumé de la discussion

BV:AutoRun-E [Wrm] est identifié comme un virus par Avast et concerne une infection sur un PC Windows XP avec Internet Explorer 7, suscitant des questionnements sur la suppression et la nécessité d'agir. Plusieurs conseils techniques apparaissent, incluant l'utilisation de HiJackThis pour identifier des traces et un éventuel outil de réparation fourni via Navilog1.exe, sous forme d'instructions pas à pas. En cas d'analyse, un extrait long de HiJackThis montre de nombreuses entrées système et services actifs, illustrant la complexité de l'infection et la prudence nécessaire lors de l'exécution d'outils externes. D'autres éléments mentionnent des outils potentiels douteux et des configurations malveillantes, comme des redirections et des programmes de contrôle, nécessitant une vérification du système et des sauvegardes récentes.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    c'est pas chiquitine29, c'est chiquitine1664
    1. Contributeur sécurité
      slt je passe pour dire un bonjour a tous!

      championne sofie353!
      de l'autorun, du wareout, sweetim , des rootkits tu fais la collection!!!!

      enfin tout pour plaire a chiquitine29
      1. sofie je te prend en charge;

        Fais un clic droit sur ce lien : (IL-MAFIOSO)
        http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
        Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
        Ensuite double clique sur navilog1.exe pour lancer l'installation.
        Une fois l'installation terminée, le fix s'exécutera automatiquement.
        (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

        Laisse-toi guider. Au menu principal, choisis 1 et valides.
        (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

        Patiente jusqu'au message :
        *** Analyse Termine le ..... ***
        Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
        Copie-colle l'intégralité dans une réponse. Referme le blocnote.
        Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

        Tuto: http://www.malekal.com/Adware.Magic_Control.php

        1. Contributeur sécurité
          zut encore un cas pas assez difficile pour chiquitine29 !

          et pourtant
          sofie353 y avait mis le paquet :)

          encore bravo!
          1. Contributeur sécurité
            Bonjour,

            - Télécharge HiJackThis.exe de Merijn(prog de diagnostic) sur ton bureau.
            - Cette version est sans installateur! ( Zip à décompresser )
            - Enregistre le sur ton bureau
            ----> exemple C:\hijackthis *** Enregistre le bien dans C: ! ***
            installer hijackthis correctement:
            https://forums.cnetfrance.fr

            - Double-clique dessus
            - Génère un rapport en suivant ces indications :
            - Exécute le et clique sur "Do a scan and save log file".
            - Le rapport s'ouvre sur le Bloc-Note.
            - Colle le rapport ici, pour cela :
            - Menu Edition / Selectionner Tout
            - Menu Edition / copier
            - Ici dans un nouveau message : clic droit / coller
            - ** ne pas fixer de lignes sans notre avis **
            Aide : N'hésite pas à consulter l'aide HiJackThis de Malekal_morte
            [http://perso.orange.fr/rginformatique/section%20virus/demoh
            1. Modérateur
              Salut,

              --> Télécharge UsbFix (de Chiquitine29) sur ton Bureau :
              http://sd-1.archive-host.com/membres/up/116615172019703188/UsbFix.exe

              --> Lance l'installation avec les paramètres par défaut.

              --> Branche tes sources de données externes à ton PC (clé USB, disque dur externe, etc...) sans les ouvrir.

              --> Double-clique sur le raccourci UsbFix sur ton Bureau.

              --> Choisis l'option 1 (Nettoyage).

              --> Le PC va redémarrer.

              --> Après redémarrage, poste le rapport UsbFix.txt

              Note : le rapport UsbFix.txt est sauvegardé à la racine du disque.

              (Si le Bureau ne réapparait pas, presse Ctrl+Alt+Suppr, Onglet "Fichier", "Nouvelle tâche", tape explorer.exe et valide)
              1. Salut,

                Telecharge UsbFix sur ton bureau

                --> Lance l installation avec les parametres par default

                Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                --> Double clic sur le raccourci UsbFix sur ton bureau

                -->choisi l option 1 (nettoyage)

                --> Le pc va redémarer

                -->Apres redémarrage post le rapport UsbFix.txt

                Note : le rapport UsbFix.txt est sauvegardé a la racine du disque
                1. Contributeur sécurité
                  bisous beau gosse

                  tin,ca déchire grave chez les helpeurs!!
                  ;)
                  1. Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 14:24, on 2008-11-25
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
                    Boot mode: Normal

                    Running processes:
                    C:\WINDOWS\system32\csrss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
                    C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    C:\Program Files\Bonjour\mDNSResponder.exe
                    C:\WINDOWS\eHome\ehRecvr.exe
                    C:\WINDOWS\eHome\ehSched.exe
                    C:\WINDOWS\System32\GEARSec.exe
                    C:\Program Files\Norton Ghost\Agent\VProSvc.exe
                    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                    C:\WINDOWS\system32\igfxext.exe
                    C:\WINDOWS\system32\igfxsrvc.exe
                    C:\WINDOWS\ehome\mcrdsvc.exe
                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                    C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\WINDOWS\System32\alg.exe
                    C:\Program Files\Apoint\Apoint.exe
                    C:\WINDOWS\ehome\ehtray.exe
                    C:\Program Files\Apoint\Apntex.exe
                    C:\WINDOWS\system32\ICO.EXE
                    C:\WINDOWS\system32\hkcmd.exe
                    C:\WINDOWS\system32\igfxpers.exe
                    C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                    C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                    C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                    C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                    C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                    C:\Program Files\Norton Ghost\Agent\GhostTray.exe
                    C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
                    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    C:\Program Files\SweetIM\Messenger\SweetIM.exe
                    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
                    C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
                    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
                    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Rainlendar\Rainlendar.exe
                    C:\Program Files\SM\skymessnet.exe
                    C:\Program Files\OpenOffice.org 3\program\soffice.exe
                    C:\Program Files\OpenOffice.org 3\program\soffice.bin
                    C:\Program Files\iPod\bin\iPodService.exe
                    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\WINDOWS\system32\wbem\wmiapsrv.exe
                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                    C:\Program Files\Java\jre1.6.0_07\bin\jucheck.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                    C:\Program Files\Windows Live\Mail\wlmail.exe
                    C:\Documents and Settings\Sophie Chantrel\Bureau\HiJackThis.exe
                    C:\WINDOWS\system32\wbem\wmiprvse.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fondperso.com/index.php?rub=
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                    R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll
                    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
                    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
                    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll (file missing)
                    O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                    O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
                    O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
                    O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Program Files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
                    O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
                    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                    O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
                    O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                    O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                    O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                    O4 - HKLM\..\Run: [SonyPowerCfg] "C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
                    O4 - HKLM\..\Run: [ISBMgr.exe] C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                    O4 - HKLM\..\Run: [Switcher.exe] C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                    O4 - HKLM\..\Run: [VAIO Update 2] "C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                    O4 - HKLM\..\Run: [Norton Ghost 10.0] "C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
                    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdyvp.exe] C:\WINDOWS\system32\kdyvp.exe
                    O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    O4 - HKCU\..\Run: [DesktopX] "C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\DesktopX Builder.exe" -noui
                    O4 - HKCU\..\Run: [MsnMsgr] ~"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                    O4 - HKCU\..\Run: [ozzrxjvn] c:\documents and settings\sophie chantrel\local settings\application data\ozzrxjvn.exe ozzrxjvn
                    O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                    O4 - HKCU\..\Run: [VeohPlugin] "C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                    O4 - HKCU\..\Run: [ygmms] "c:\documents and settings\sophie chantrel\local settings\application data\ygmms.exe" ygmms
                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                    O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
                    O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                    O4 - Startup: Rainlendar.lnk = ?
                    O4 - Startup: SM.lnk = C:\Program Files\SM\skymessnet.exe
                    O4 - Global Startup: hp psc 1000 series.lnk = ?
                    O4 - Global Startup: hpoddt01.exe.lnk = ?
                    O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKxdm014YYFR
                    O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
                    O8 - Extra context menu item: Ajouter un site de support RSS à VAIO Information FLOW - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
                    O8 - Extra context menu item: Transfert par Image Converter 2 Plus - C:\Program Files\Sony\Image Converter 2\menu.htm
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.com/fr/
                    O15 - Trusted Zone: *.sony-europe.com
                    O15 - Trusted Zone: *.sonystyle-europe.com
                    O15 - Trusted Zone: *.vaio-link.com
                    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/WebfettiInitialSetup1.0.0.15-3.cab
                    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{07D7E714-13C0-4F8A-AC41-7CCA07050B9D}: NameServer = 85.255.112.114;85.255.112.14
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{3F7C65E8-4635-4116-AFB0-AA2BAD451A29}: NameServer = 85.255.112.114;85.255.112.14
                    O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
                    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                    O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
                    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                    O23 - Service: Image Converter video recording monitor for VAIO Entertainment - Sony Corporation - C:\Program Files\Sony\Image Converter 2\IcVzMon.exe
                    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                    O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe
                    O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exe
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe
                    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                    O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                    O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe
                    O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\Avlib\SSScsiSV.exe
                    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                    O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe
                    O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                    O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe
                    O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
                    O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
                    O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe
                    O23 - Service: VAIO Cooporated Initialisation (VCI) - Sony Corporation - C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe
                    O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                    O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                    O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                    1. rapport UsbFix

                      -------------- UsbFix V2.413.1 ---------------

                      * User : Sophie Chantrel - SOPHIE
                      * Outils mis a jours le 24/11/2008 par Chiquitine29 et Chimay8
                      * Recherche effectuée à 14:41:37 le 2008-11-25
                      * Windows Xp - Internet Explorer 7.0.5730.11

                      --------------- [ Processus actifs ] ----------------

                      C:\WINDOWS\system32\csrss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                      C:\WINDOWS\system32\logonui.exe
                      C:\WINDOWS\system32\userinit.exe
                      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                      C:\DOCUME~1\SOPHIE~1\LOCALS~1\Temp\1.tmp\b2e.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                      C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
                      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\WINDOWS\eHome\ehRecvr.exe
                      C:\WINDOWS\eHome\ehSched.exe
                      C:\WINDOWS\System32\GEARSec.exe
                      C:\WINDOWS\eHome\ehRec.exe
                      C:\Program Files\Norton Ghost\Agent\VProSvc.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                      C:\Program Files\Sony\VAIO Cooperated Initialisation\VCI_SVC.exe

                      --------------- [ Informations lecteurs ] ----------------

                      C: - Lecteur fixe

                      D: - Lecteur fixe

                      +- Contenu de l'autorun : D:\autorun.inf

                      [autorun]
                      shellexecute="resycled\boot.com d:"
                      shell\Open\command="resycled\boot.com d:"
                      shell=Open

                      --------------- [ Lecteur C ] ----------------

                      C: - Lecteur fixe

                      +- Listing des fichiers présents :

                      [2006-09-04 12:09][--a------] C:\AUTOEXEC.BAT
                      [2004-08-10 13:00][-rahs----] C:\NTDETECT.COM
                      [2008-11-03 08:21][-rahs----] C:\boot.ini
                      [2008-11-25 14:41][--a------] C:\UsbFix.txt
                      [2006-09-04 12:09][--a------] C:\CONFIG.SYS
                      [2006-09-04 12:09][--a------] C:\hiberfil.sys
                      [2006-09-04 12:09][--a------] C:\IO.SYS
                      [2006-09-04 12:09][--a------] C:\MSDOS.SYS
                      [2006-09-04 12:09][--a------] C:\pagefile.sys

                      --------------- [ Lecteur D ] ----------------

                      D: - Lecteur fixe

                      +- Listing des fichiers présents :

                      [2008-11-03 01:26][-r-hs----] D:\autorun.inf

                      --------------- [ Registre / Startup ] ----------------

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                      "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Search Page"="https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC"
                      "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

                      CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
                      swg=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      DesktopX="C:\PROGRA~1\Stardock\OBJECT~1\DesktopX\DesktopX Builder.exe" -noui
                      MsnMsgr=~"C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      ozzrxjvn=c:\documents and settings\sophie chantrel\local settings\application data\ozzrxjvn.exe ozzrxjvn
                      Veoh="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
                      <NO NAME>=
                      VeohPlugin="C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"
                      ygmms="c:\documents and settings\sophie chantrel\local settings\application data\ygmms.exe" ygmms

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

                      Apoint=C:\Program Files\Apoint\Apoint.exe
                      ehTray=C:\WINDOWS\ehome\ehtray.exe
                      NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      SkyTel=SkyTel.EXE
                      Alcmtr=ALCMTR.EXE
                      AzMixerSel=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                      Mouse Suite 98 Daemon=ICO.EXE
                      igfxtray=C:\WINDOWS\system32\igfxtray.exe
                      igfxhkcmd=C:\WINDOWS\system32\hkcmd.exe
                      igfxpers=C:\WINDOWS\system32\igfxpers.exe
                      SonyPowerCfg="C:\Program Files\Sony\VAIO Power Management\SPMgr.exe"
                      ISBMgr.exe=C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                      Switcher.exe=C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                      VAIO Update 2="C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe" /Stationary
                      ccApp="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                      Acrobat Assistant 7.0="C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
                      Norton Ghost 10.0="C:\Program Files\Norton Ghost\Agent\GhostTray.exe"
                      RoxioDragToDisc="C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
                      TkBellExe="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
                      WinampAgent="C:\Program Files\Winamp\winampa.exe"
                      avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                      C:\WINDOWS\system32\kdyvp.exe=C:\WINDOWS\system32\kdyvp.exe
                      SweetIM=C:\Program Files\SweetIM\Messenger\SweetIM.exe
                      SunJavaUpdateSched="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                      QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
                      iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
                      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
                      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
                      Installed=1
                      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
                      Installed=1
                      NoChange=1
                      HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
                      Installed=1

                      --------------- [ Registre / Mountpoint2 ] ----------------

                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{02de32e4-ee93-11db-a402-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{02de32e4-ee93-11db-a402-0018de9aab9d}\Shell\explore\Command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{02de32e4-ee93-11db-a402-0018de9aab9d}\Shell\open\Command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c7edd5c-11e1-11dd-a5ce-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c7edd5c-11e1-11dd-a5ce-0018de9aab9d}\Shell\explore\Command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0c7edd5c-11e1-11dd-a5ce-0018de9aab9d}\Shell\open\Command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{23f99366-93aa-11db-a399-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{23f99366-93aa-11db-a399-0018de9aab9d}\Shell\explore\Command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{23f99366-93aa-11db-a399-0018de9aab9d}\Shell\open\Command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c3d9e74-a312-11dc-a57d-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c3d9e74-a312-11dc-a57d-0018de9aab9d}\Shell\explore\Command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4c3d9e74-a312-11dc-a57d-0018de9aab9d}\Shell\open\Command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{52d7e7d0-3915-11dc-a497-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{5b14f55f-87d5-11dc-a55c-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{6e785274-9d3c-11dc-a57a-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b0a7e162-4112-11dc-a4ac-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b18fca25-c6f2-11db-a3c6-0013a96007d5}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{b69cfef2-477c-11dc-a4b9-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{cbfea726-f93f-11db-a422-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f2c82088-f5c0-11dc-a5ba-0018de9aab9d}\Shell\AutoRun\command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f2c82088-f5c0-11dc-a5ba-0018de9aab9d}\Shell\explore\Command
                      Supprimé ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f2c82088-f5c0-11dc-a5ba-0018de9aab9d}\Shell\open\Command

                      --------------- [ Nettoyage des disques ] ----------------

                      Supprimé ! - [2007-08-30 14:32][--a------] C:\WINDOWS\autorun.ini
                      D:\autorun.inf ~> fichier appelé : "D:\"resycled\boot.com d:"" ( absent ! )
                      Supprimé ! - [2008-11-04 01:16][dr-hs----] C:\resycled
                      Supprimé ! - [2008-11-03 01:26][-r-hs----] D:\autorun.inf
                      Supprimé ! - [2008-11-04 01:16][dr-hs----] D:\resycled

                      --------------- [ Resumé ] ----------------

                      -> /!\ Le resultat doit etre interprété par un spécialiste /!\

                      [2006-09-04 12:09][--a------] C:\AUTOEXEC.BAT
                      [2004-08-10 13:00][-rahs----] C:\NTDETECT.COM
                      [2008-11-03 08:21][-rahs----] C:\boot.ini

                      --------------- ! Fin du rapport ! ----------------
                      • 1
                      • 2
                      • 3