Virus_ Avis d'expert nécessaire

Résolu
am13 -  
 am13 -
Bonjour,
J'ai des problèmes de virus et autres spyware résistants. J'aurais voulu le conseil d'experts pour m'en débarrasser.
MERCIS !!
AM sur XP / IE & Mozilla

Voici dans l'ordre les résultats de la procédure proposée sur ce site :

---------------------------------------------------------------------------------------------------------------------------------------------------
AVCORE v1.7 (build 8314.19) (i386) (Sep 29 2008 17:19:14)

Scanned File

Status

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\1604004998.exe

Infected with: Packer.Malware.Lighty.E

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\1604004998.exe

Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\1604004998.exe

Delete failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\2733751008.exe

Infected with: Packer.Malware.Lighty.E

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\2733751008.exe

Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\2733751008.exe

Delete failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\868637984.exe

Infected with: Packer.Malware.Lighty.E

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\868637984.exe

Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\868637984.exe

Delete failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\881137984.exe

Infected with: Packer.Malware.Lighty.E

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\881137984.exe

Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\881137984.exe

Delete failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\p2psetup.exe

Detected with: Application.P2p.Networking.D

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\p2psetup.exe

Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Local Settings\Temp\p2psetup.exe

Deleted

C:\Documents and Settings\amg.ORDIAMG\Mes documents\LimeWire\Saved\photoshop french.zip=>Setup.exe

Detected with: Adware.PlayMp3z.B

C:\Documents and Settings\amg.ORDIAMG\Mes documents\LimeWire\Saved\photoshop french.zip=>Setup.exe

Disinfection failed

C:\Documents and Settings\amg.ORDIAMG\Mes documents\LimeWire\Saved\photoshop french.zip=>Setup.exe

Deleted

C:\Documents and Settings\amg.ORDIAMG\Mes documents\LimeWire\Saved\photoshop french.zip

Updated

C:\Program Files\Kazaa\CKGFRs.dll

Detected with: Application.Generic.18283

C:\Program Files\Kazaa\CKGFRs.dll

Disinfection failed

C:\Program Files\Kazaa\CKGFRs.dll

Deleted

C:\Program Files\Kazaa\TopSearch.dll

Detected with: Adware.Altnet.F

C:\Program Files\Kazaa\TopSearch.dll

Deleted

C:\Program Files\Mozilla Firefox\plugins\NPNd2fn.dll

Detected with: Adware.Toolbar.Mywebsearch.O

C:\Program Files\Mozilla Firefox\plugins\NPNd2fn.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>serial.exe

Infected with: Trojan.Generic.1222208

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>serial.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)

Update failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>crack.exe

Infected with: Trojan.Vundo.GBQ

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>crack.exe

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>crack.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)

Update failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>number.exe

Infected with: Trojan.Retapu.D

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>number.exe

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)=>number.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP437\A0027470.exe=>(RAR Sfx o)

Update failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027490.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027490.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027500.DLL

Detected with: Application.Need2find.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027500.DLL

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027500.DLL

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027501.dll

Detected with: Adware.Generic.31649

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027501.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027502.dll

Detected with: Adware.RXToolbar

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027502.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027514.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027514.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027516.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027516.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027518.dll

Detected with: Adware.Generic.31649

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027518.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027519.DLL

Detected with: Application.Need2find.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027519.DLL

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027519.DLL

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027520.dll

Detected with: Adware.RXToolbar

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027520.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027559.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027559.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027561.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027561.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027785.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027785.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027809.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027809.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027815.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027815.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027827.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027827.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027833.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027833.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027836.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027836.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027838.DLL

Detected with: Application.Need2find.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027838.DLL

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027838.DLL

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027839.dll

Detected with: Adware.RXToolbar

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027839.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027841.exe

Detected with: Adware.Topsearch.C

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027841.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027842.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027842.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027844.exe

Infected with: Trojan.Generic.1215518

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027844.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027845.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027845.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027846.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027846.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027847.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027847.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027928.dll

Detected with: Adware.Generic.30220

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027928.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027933.dll

Detected with: Adware.Altnet.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027933.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027934.dll

Detected with: Adware.Altnet.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027934.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027935.exe

Detected with: Adware.Altnet.Q

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027935.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027936.dll

Detected with: Adware.Altnet.F

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027936.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027937.dll

Detected with: Adware.Brilliantdigital.3039.C

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027937.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027938.dll

Detected with: Adware.Altnet.J

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027938.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027939.dll

Detected with: Adware.Altnetbde.B

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027939.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027940.exe

Detected with: Application.Altnetbde.C

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027940.exe

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027940.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027941.exe

Detected with: Application.Altnetbde.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027941.exe

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027941.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027963.DLL

Detected with: Adware.Msearch.M

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027963.DLL

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027964.DLL

Detected with: Adware.Toolbar.Mywebsearch.O

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0027964.DLL

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0028026.dll

Detected with: Adware.Rxbar.D

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP438\A0028026.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0028164.dll

Detected with: Adware.Generic.31649

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0028164.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029196.dll

Infected with: Trojan.Vundo.GBZ

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029196.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029197.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029197.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029198.exe

Infected with: Worm.Generic.37658

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029198.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029206.dll

Infected with: Trojan.Vundo.FUX

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029206.dll

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029206.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029551.DLL

Detected with: Application.P2p.Networking.G

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029551.DLL

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029551.DLL

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029552.cpl

Detected with: Adware.P2pnet.A

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029552.cpl

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029553.exe

Detected with: Application.P2p.Networking.D

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029553.exe

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP440\A0029553.exe

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032621.dll

Detected with: Application.Generic.18283

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032621.dll

Disinfection failed

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032621.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032622.dll

Detected with: Adware.Altnet.F

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032622.dll

Deleted

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032623.dll

Detected with: Adware.Toolbar.Mywebsearch.O

C:\System Volume Information\_restore{58E38B50-4EEE-443B-8008-9FABB023DAFF}\RP441\A0032623.dll

Deleted

C:\WINDOWS\cdmxtras\uninst.exe

Detected with: Application.Generic.23543

C:\WINDOWS\cdmxtras\uninst.exe

Disinfection failed

C:\WINDOWS\cdmxtras\uninst.exe

Deleted
--------------------------------------------------------------------------------------------------------------------------------------------------------------

BitDefender Online Scanner - Real Time Virus Report

Generated at: Fri, Dec 12, 2008 - 04:54:02

Scan Info

Scanned Files 218798

Infected Files 62

Virus Detected

Application.Generic.23543
1

Application.P2p.Networking.G
1

Application.Need2find.A
3

Trojan.Vundo.GBQ
1

Adware.PlayMp3z.B
1

Adware.Rxbar.D
1

Adware.Altnet.Q
1

Application.Generic.18283
2

Adware.Altnet.A
2

Adware.Generic.31649
3

Trojan.Vundo.FUX
1

Application.Altnetbde.A
1

Adware.Brilliantdigital.3039.C
1

Adware.P2pnet.A
1

Trojan.Generic.1215518
1

Application.Altnetbde.C
1

Adware.Topsearch.C
1

Worm.Generic.37658
17

Adware.Altnet.F
3

Trojan.Generic.1222208
1

Trojan.Vundo.GBZ
1

Adware.Generic.30220
1

Adware.RXToolbar
3

Adware.Msearch.M
1

Adware.Toolbar.Mywebsearch.O
3

Adware.Altnet.J
1

Packer.Malware.Lighty.E
4

Adware.Altnetbde.B
1

Application.P2p.Networking.D
2

Trojan.Retapu.D
1

--------------------------------------------------------------------------------------------------------------------------------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 05:19:08, on 12/12/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Philips\SPC220NC\Monitor.exe
E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/spresults.aspx
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: (no name) - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - (no file)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Monitor] C:\WINDOWS\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [HP Software Update] E:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = E:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: TrayMin220.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - E:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O16 - DPF: {127698E4-E730-4E5C-A2B1-21490A70C8A1} (CEnroll Class) - https://static.impots.gouv.fr/abos/securite/xenroll.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://ange-live.spaces.live.com/PhotoUpload/MsnPUpld.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: itneuw.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll xvqehz.dll
O20 - Winlogon Notify: iifcDwxW - C:\WINDOWS\
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

26 réponses

Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
---> Relance MBAM, va dans Quarantaine et supprime tout.

---> Supprime JavaRa.

Ton PC va comment ?
0
am13
 
J'ai refait un scan disk après avoir fait la manip' demandée....plus rien à signaler en quarantaine !!!
Est ce que c'est fini ?? dois je désinstaller des softs téléchargés ??
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
1/

--> Désinstalle HijackThis.

---> Télécharge ToolsCleaner2 sur ton Bureau.
* Double-clique sur ToolsCleaner2.exe pour le lancer.
* Clique sur Recherche et laisse le scan agir.
* Clique sur Suppression pour finaliser.
* Tu peux, si tu le souhaites, te servir des Options Facultatives.
* Clique sur Quitter pour obtenir le rapport.
* Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

2/

---> Télécharge et installe CCleaner (N'installe pas la Yahoo Toolbar) :
* Lance-le. Va dans Options puis Avancé et décoche la case Effacer uniquement les fichiers etc....
* Va dans Nettoyeur, choisis Analyse. Une fois terminé, lance le nettoyage.
* Ensuite, choisis Registre, puis Chercher des erreurs. Une fois terminé, répare toutes les erreurs (Sauvegarde la base de registre).

3/

---> Il est nécessaire de désactiver puis réactiver la restauration système pour la purger :
http://www.infos-du-net.com/forum/272480-11-desactiver-activer-restauration-systeme

---> Je te conseille de créer un point de restauration que tu pourras utiliser plus tard si tu as un problème :
https://www.vulgarisation-informatique.com/creer-point-restauration.php

4/

Conserve MBAM. Il te servira à scanner les fichiers douteux en complément de l'antivirus et scanne le disque dur régulièrement.

Comme navigateur, utilise plutôt Mozilla Firefox qu'Internet Explorer. Tu peux utiliser l'extension Noscript pour plus de sécurité.

Vérifie que les mises à jour automatiques sont bien activées (Menu Démarrer, clique droit sur Poste de travail, Onglet Mises à jour automatiques).

Tu peux aussi modifier le fichier Hosts pour améliorer la sécurité de ton PC :
http://www.commentcamarche.net/faq/sujet 5993 modifier son fichier hosts
https://blog.sosordi.net/category/articles

Par rapport au P2P :
http://www.libellules.ch/...

Voici un dossier complet (A lire avec Adobe Reader ou Foxit Reader) :
https://www.malekal.com/fichiers/projetantimalwares/prevention-protection.pdf

Sois plus vigilant sur Internet ;)
0
am13
 
[ Rapport ToolsCleaner version 2.2.7 (par A.Rothstein & dj QUIOU) ]

-->- Recherche:

C:\TB.txt: trouvé !
C:\UsbFix.txt: trouvé !
C:\_OtMoveIt: trouvé !
C:\Toolbar SD: trouvé !
C:\Rsit: trouvé !
C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis: trouvé !
C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
C:\Documents and Settings\amg.ORDIAMG\Bureau\HijackThis.lnk: trouvé !
C:\Documents and Settings\amg.ORDIAMG\Bureau\HJTInstall.exe: trouvé !
C:\Documents and Settings\amg.ORDIAMG\Bureau\Rsit.exe: trouvé !
C:\Hijack this\HijackThis.exe: trouvé !
C:\Hijack this\hijackthis.log: trouvé !
C:\Program Files\UsbFix: trouvé !

---------------------------------
-->- Suppression:

C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
C:\Documents and Settings\amg.ORDIAMG\Bureau\HijackThis.lnk: supprimé !
C:\Documents and Settings\amg.ORDIAMG\Bureau\HJTInstall.exe: supprimé !
C:\Hijack this\HijackThis.exe: supprimé !
C:\TB.txt: supprimé !
C:\UsbFix.txt: supprimé !
C:\Documents and Settings\amg.ORDIAMG\Bureau\Rsit.exe: supprimé !
C:\Hijack this\hijackthis.log: supprimé !
C:\_OtMoveIt: supprimé !
C:\Toolbar SD: supprimé !
C:\Rsit: supprimé !
C:\Documents and Settings\All Users.WINDOWS\Menu Démarrer\Programmes\HijackThis: supprimé !
C:\Program Files\UsbFix: supprimé !

Corbeille vidée!
Fichiers temporaires nettoyés !
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Tu peux supprimer ToolsCleaner.

Des questions ? Des remarques ?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
am13
 
Super...encore un grand merci !!!
Encore une petite chose, tu peux me dire quoi utiliser comme antivirus gratuit mieux que ma version d'évaluation de kapersky...??
0
Destrio5 Messages postés 99820 Date d'inscription   Statut Modérateur Dernière intervention   10 305
 
Antivir :
http://www.commentcamarche.net/telecharger/telecharger 55 antivir
0
am13
 
merci bcp!
0