Virus spirit de msn / facebook .

Résolu
salut
comme bq de gens j ai ete infecte par le virus spirit de msn facebook . mon avast familiale le detecte me il ne pourra rien faire . j ai installe NOd 32 me tjs pas possible a detruire ce malicieux virus .
j ai lu un peu dans ce site et j ai installe MSNFIX me le probleme c est qu il me donne le msg suivant apres l analyse : " infection absente" et " l infection n a pas ete detectee " ; me j ai tjs ce salaud de " SPIRIT " il bouleverse tout .
alors de l aide svp ... et merci d avance .
Configuration: Windows XP
Internet Explorer 6.0

42 réponses

Résumé de la discussion

Le fil porte sur une infection liée au virus Spirit utilisant MSN/Facebook, détectée ou non par Avast, et sur les difficultés rencontrées sous Windows XP et IE6 à s'en débarrasser. Plusieurs réponses évoquent méthodes techniques comme HijackThis pour générer un rapport et corriger les éléments indésirables, la réparation de l'amorçage via la console de récupération et fixmbr, ou l'usage de SAV32CLI pour MBR. D'autres suggestions portent sur tutoriels, des antivirus à tester et des précautions de sécurité comme l'installation de pare-feu, d'outils anti-spyware et des conseils pour une navigation plus sécurisée. En cas de doute, certains conseils préconisent aussi d'effectuer un scan complet de la partition système, car des traces peuvent persister même après nettoyage ou après une réinstallation partielle.

Bobot (l’IA à votre service)
  1. Contributeur
    salut essaie :
    Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
    • Redémarre ton ordinateur
    • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
    • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
    • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
    • Choisis ton compte.
    Déroule la liste des instructions ci-dessous :
    • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
    • Appuie sur Y pour commencer le processus de nettoyage.
    • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
    • Appuie sur une touche pour redémarrer le PC.
    • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
    • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
    • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
    • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum
    0
    1. salut et merci infiniment . j ai suivi les etapes et j ai eu le rapport suivant:

      [b]SDFix: Version 1.240 [/b]
      Run by srata on 16/12/2008 at 14:15

      Microsoft Windows XP [version 5.1.2600]
      Running From: C:\SDFix

      [b]Checking Services [/b]:

      Restoring Default Security Values
      Restoring Default Hosts File

      Rebooting

      [b]Checking Files [/b]:

      Trojan Files Found:

      C:\WINDOWS\system32\explorer32.exe - Deleted
      C:\WINDOWS\system32\ieupdates.exe - Deleted
      C:\WINDOWS\system32\winsrc.dll - Deleted
      C:\WINDOWS\system32\winsrc.dll.tmp - Deleted

      Removing Temp Files

      [b]ADS Check [/b]:

      [b]Final Check [/b]:

      catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-12-16 14:24:42
      Windows 5.1.2600 Service Pack 2 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      [b]Remaining Services [/b]:

      Authorized Application Key Export:

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\Ares\\Ares.exe"="C:\\Program Files\\Ares\\Ares.exe:*:Enabled:Ares p2p for windows"
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
      "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
      "C:\\Program Files\\ma-config.com\\maconfservice.exe"="C:\\Program Files\\ma-config.com\\maconfservice.exe:LocalSubNet:Enabled:maconfservice"
      "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMuleMorphXT"
      "C:\\Program Files\\DNA\\btdna.exe"="C:\\Program Files\\DNA\\btdna.exe:*:Enabled:DNA"
      "C:\\Program Files\\BitTorrent\\bittorrent.exe"="C:\\Program Files\\BitTorrent\\bittorrent.exe:*:Enabled:BitTorrent"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
      "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"

      [b]Remaining Files [/b]:

      File Backups: - C:\SDFix\backups\backups.zip

      [b]Files with Hidden Attributes [/b]:

      Mon 6 Oct 2008 288,256 A..H. --- "C:\Program Files\e-shamela\Files\rar.exe"
      Mon 25 Aug 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
      Sun 26 Oct 2008 484,352 ...H. --- "C:\Documents and Settings\srata\Mes documents\andalusie\~WRL0003.tmp"
      Sun 26 Oct 2008 499,200 ...H. --- "C:\Documents and Settings\srata\Mes documents\andalusie\~WRL0005.tmp"
      Mon 27 Oct 2008 531,456 ...H. --- "C:\Documents and Settings\srata\Mes documents\andalusie\~WRL2402.tmp"

      [b]Finished![/b]

      *********** alors est ce que mon pc va bien ou il me reste quque chose a faire
      merci bq et desole du retard . j etais ou boulot .
      0
  2. Contributeur
    salut,

    post ce rapport stp

    Télécharge HijackThis ici :

    -> http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

    Tutoriel d´instalation : (Merci a Balltrap34 pour cette réalisation)

    -> http://pageperso.aol.fr/balltrap34/Hijenr.gif

    Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

    -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    Post le rapport généré ici stp...
    0
    1. j ai telecharge hijack this et j l ai installe .
      les autres demarches j ai pas bien compris ce que j dois faire ?? en tout cas le 1 er adresse ne marche pas .
      0
    2. j ai lance hijack et j ai choisi l option " do a system scan only " et voila le rapport :

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 14:55:46, on 16/12/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\SweetIM\Messenger\SweetIM.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
      C:\Program Files\Ares\Ares.exe
      C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
      C:\Program Files\DNA\btdna.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\LG Electronics\Modem USB LG Electronics\IEUM.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.ma/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/?p=us
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/?p=us
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
      O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
      O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
      O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: (no name) - {3194090F-A0AA-4A88-BBED-F17D67FED54B} - C:\WINDOWS\system32\tuvUNfGW.dll (file missing)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
      O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
      O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
      O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
      O4 - HKCU\..\Run: [UMService] C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
      O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
      O4 - HKCU\..\Run: [94276741190140628802057346143358] C:\Program Files\A360\av360.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RESEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
      O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm674YYMA
      O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
      O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
      O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
      O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
      O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/PopularScreenSaversInitialSetup1.0.1.1.cab
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
      O17 - HKLM\System\CCS\Services\Tcpip\..\{C4E93CD8-F0D0-4F42-8890-9AECE5560859}: NameServer = 192.168.50.55 196.12.209.6
      O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
      O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
      O24 - Desktop Component 0: (no name) - http://www.golf5gt.com/userpix/68_Golf_20Zoll_2_1.jpg
      0
  3. Contributeur
    regarde cette video :

    Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

    -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    en fait tu veux générer un rapport et le copier ici , c´est bien mieux expliqué dans la video comparé a ce que je pourrais te dire .)
    0
    1. Contributeur
      ok tu est encore bien infecté...

      Télécharge combofix.exe (par sUBs) sur ton Bureau.

      -> http://download.bleepingcomputer.com/sUBs/ComboFix.exe

      -> Double clique combofix.exe.
      -> Tape sur la touche 1 (Yes) pour démarrer le scan.
      -> Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

      NOTE : Le rapport se trouve également ici : C:\Combofix.txt

      Avant d'utiliser ComboFix :

      -> Déconnecte toi d'internet et referme les fenêtres de tous les programmes en cours.

      -> Désactive provisoirement et seulement le temps de l'utilisation de ComboFix, la protection en temps réel de ton Antivirus et de tes Antispywares, qui peuvent géner fortement la procédure de recherche et de nettoyage de l'outil.

      Une fois fait, sur ton bureau double-clic sur Combofix.exe.

      - Répond oui au message d'avertissement, pour que le programme commence à procéder à l'analyse du pc.

      /!\ Pendant la durée de cette étape, ne te sert pas du pc et n'ouvre aucun programmes.

      - En fin de scan il est possible que ComboFix ait besoin de redemarrer le pc pour finaliser la désinfection\recherche, laisses-le faire.

      - Un rapport s'ouvrira ensuite dans le bloc notes, ce fichier rapport Combofix.txt, est automatiquement sauvegardé et rangé à C:\Combofix.txt)

      -> Réactive la protection en temps réel de ton Antivirus et de tes Antispywares, avant de te reconnecter à internet.

      -> Reviens sur le forum, et copie et colle la totalité du contenu de C:\Combofix.txt dans ton prochain message.

      -> Tutoriel https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix

      @+
      0
      1. voici le rapport de combi fix :

        ComboFix 08-12-15.05 - srata 2008-12-16 15:51:27.1 - NTFSx86
        Microsoft Windows XP Professionnel 5.1.2600.2.1256.212.1036.18.255.81 [GMT 1:00]
        Running from: c:\documents and settings\srata\Bureau\ComboFix.exe
        * Created a new restore point

        [COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
        .

        ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\program files\FunWebProducts
        c:\program files\FunWebProducts\ScreenSaver\Cache\[u]0[/u]08C2D6F.swf
        c:\program files\FunWebProducts\ScreenSaver\Cache\[u]0[/u]0A76DF0
        c:\program files\FunWebProducts\ScreenSaver\Cache\files.ini
        c:\program files\FunWebProducts\ScreenSaver\Images\[u]0[/u]0885A11.urr
        c:\program files\FunWebProducts\ScreenSaver\Images\[u]0[/u]08C2968.urr
        c:\program files\FunWebProducts\ScreenSaver\Images\[u]0[/u]08D62C3.dat
        c:\program files\FunWebProducts\ScreenSaver\Images\[u]0[/u]0AE45D4.dat
        c:\program files\FunWebProducts\ScreenSaver\Images\wrkparam.lst
        c:\program files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
        c:\program files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
        c:\program files\Internet Explorer\msimg32.dll
        c:\program files\MyWebSearch
        c:\program files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
        c:\program files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
        c:\program files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
        c:\program files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
        c:\program files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
        c:\program files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
        c:\program files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
        c:\program files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
        c:\program files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
        c:\program files\MyWebSearch\bar\1.bin\F3REPROX.DLL
        c:\program files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
        c:\program files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
        c:\program files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
        c:\program files\MyWebSearch\bar\1.bin\F3SPACER.WMV
        c:\program files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
        c:\program files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
        c:\program files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
        c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
        c:\program files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
        c:\program files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
        c:\program files\MyWebSearch\bar\1.bin\M3HTML.DLL
        c:\program files\MyWebSearch\bar\1.bin\M3IDLE.DLL
        c:\program files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
        c:\program files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
        c:\program files\MyWebSearch\bar\1.bin\M3MSG.DLL
        c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
        c:\program files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
        c:\program files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
        c:\program files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
        c:\program files\MyWebSearch\bar\1.bin\M3SKIN.DLL
        c:\program files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
        c:\program files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
        c:\program files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
        c:\program files\MyWebSearch\bar\1.bin\MWSBAR.DLL
        c:\program files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
        c:\program files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
        c:\program files\MyWebSearch\bar\1.bin\MWSSVC.EXE
        c:\program files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
        c:\program files\MyWebSearch\bar\Avatar\COMMON.F3S
        c:\program files\MyWebSearch\bar\Cache\[u]0[/u]003693A
        c:\program files\MyWebSearch\bar\Cache\[u]0[/u]08831E7
        c:\program files\MyWebSearch\bar\Cache\[u]0[/u]0887615.bin
        c:\program files\MyWebSearch\bar\Cache\[u]0[/u]0888FC7.bin
        c:\program files\MyWebSearch\bar\Cache\[u]0[/u]088B540.bin
        c:\program files\MyWebSearch\bar\Cache\[u]0[/u]088E181.bin
        c:\program files\MyWebSearch\bar\Cache\files.ini
        c:\program files\MyWebSearch\bar\Game\CHECKERS.F3S
        c:\program files\MyWebSearch\bar\Game\CHESS.F3S
        c:\program files\MyWebSearch\bar\Game\REVERSI.F3S
        c:\program files\MyWebSearch\bar\History\search3
        c:\program files\MyWebSearch\bar\icons\CM.ICO
        c:\program files\MyWebSearch\bar\icons\MFC.ICO
        c:\program files\MyWebSearch\bar\icons\PSS.ICO
        c:\program files\MyWebSearch\bar\icons\SMILEY.ICO
        c:\program files\MyWebSearch\bar\icons\WB.ICO
        c:\program files\MyWebSearch\bar\icons\ZWINKY.ICO
        c:\program files\MyWebSearch\bar\Message\COMMON.F3S
        c:\program files\MyWebSearch\bar\Notifier\COMMON.F3S
        c:\program files\MyWebSearch\bar\Notifier\DOG.F3S
        c:\program files\MyWebSearch\bar\Notifier\FISH.F3S
        c:\program files\MyWebSearch\bar\Notifier\KUNGFU.F3S
        c:\program files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
        c:\program files\MyWebSearch\bar\Notifier\MAID.F3S
        c:\program files\MyWebSearch\bar\Notifier\MAILBOX.F3S
        c:\program files\MyWebSearch\bar\Notifier\OPERA.F3S
        c:\program files\MyWebSearch\bar\Notifier\ROBOT.F3S
        c:\program files\MyWebSearch\bar\Notifier\SEDUCT.F3S
        c:\program files\MyWebSearch\bar\Notifier\SURFER.F3S
        c:\program files\MyWebSearch\bar\Settings\prevcfg2.htm
        c:\program files\MyWebSearch\bar\Settings\s_pid.dat
        c:\program files\MyWebSearch\bar\Settings\setting2.htm
        c:\program files\MyWebSearch\bar\Settings\settings.dat
        c:\program files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
        c:\windows\IE4 Error Log.txt
        c:\windows\system32\awttsRLc.dll
        c:\windows\system32\byXNGaxX.dll
        c:\windows\system32\byXQGaBR.dll
        c:\windows\system32\ddcBRhiI.dll
        c:\windows\system32\efcCvUnN.dll
        c:\windows\system32\efcddbaB.dll
        c:\windows\system32\f3PSSavr.scr
        c:\windows\system32\fccdbYPH.dll
        c:\windows\system32\geBqOffe.dll
        c:\windows\system32\iifcDsRi.dll
        c:\windows\system32\iifcDUND.dll
        c:\windows\system32\jbvyfuhl.dll
        c:\windows\system32\ljJCtuSk.dll
        c:\windows\system32\mlJCTkkj.dll
        c:\windows\system32\opnkhgFu.dll
        c:\windows\system32\pmnkKaWq.dll
        c:\windows\system32\pmnNedeb.dll
        c:\windows\system32\qoMcbcbx.dll
        c:\windows\system32\qoMcccax.dll
        c:\windows\system32\rqRHaXnk.dll
        c:\windows\system32\rqRHyyXp.dll
        c:\windows\system32\ssqQjJBu.dll
        c:\windows\system32\vtULfdcc.dll
        c:\windows\system32\WGfNUvut.ini
        c:\windows\system32\WGfNUvut.ini2
        c:\windows\system32\wvUkKbBr.dll
        c:\windows\system32\xxyArPFW.dll
        c:\windows\system32\yayvVPIC.dll
        c:\windows\system32\yayvWOEX.dll
        c:\windows\system32\yayyAtTk.dll

        .
        ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        -------\Legacy_MYWEBSEARCHSERVICE
        -------\Service_MyWebSearchService

        ((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 )))))))))))))))))))))))))))))))
        .

        2008-12-16 14:11 . 2008-12-16 14:11 <REP> d-------- c:\windows\ERUNT
        2008-12-16 14:03 . 2008-12-16 14:28 <REP> d-------- C:\SDFix
        2008-12-15 23:51 . 2008-12-15 23:51 <REP> d-------- c:\program files\Trend Micro
        2008-12-15 21:54 . 2008-12-15 21:54 <REP> d-------- c:\program files\AxBx
        2008-12-15 20:28 . 2008-12-13 21:04 303,104 --------- c:\windows\system32\trz48.tmp
        2008-12-15 14:17 . 2008-12-15 14:17 <REP> d-------- C:\MSNFix
        2008-12-15 13:05 . 2008-12-15 13:06 1,620,138 ---hs---- c:\windows\system32\lhufyvbj.ini
        2008-12-14 23:15 . 2008-12-14 23:15 <REP> d-------- c:\program files\Ares
        2008-12-14 21:31 . 2008-12-14 21:36 4,014 --a------ C:\mpsn.MSNFix
        2008-12-14 13:03 . 2008-12-14 13:05 1,620,087 ---hs---- c:\windows\system32\iodugboy.ini
        2008-12-14 10:46 . 2008-12-14 23:17 <REP> d-------- c:\program files\ESET
        2008-12-13 22:19 . 2008-12-14 22:25 143 --a------ c:\windows\system32\mcrh.MSNFix
        2008-12-13 20:40 . 2008-12-13 01:16 52,786 --a------ c:\windows\fxstaller.MSNFix
        2008-11-27 00:18 . 2008-11-27 00:21 <REP> d-------- c:\program files\e-shamela
        2008-11-17 22:03 . 2008-11-17 22:03 <REP> d-------- c:\documents and settings\srata\Application Data\FairStars Audio Converter
        2008-11-17 17:00 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

        .
        (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-12-16 14:59 --------- d-----w c:\program files\DNA
        2008-12-16 14:59 --------- d-----w c:\documents and settings\srata\Application Data\DNA
        2008-12-16 14:55 --------- d-----w c:\program files\FlashGet
        2008-12-15 23:11 --------- d-----w c:\documents and settings\srata\Application Data\BitTorrent
        2008-12-11 14:24 --------- d-----w c:\program files\MSN Messenger
        2008-12-08 23:20 --------- d--h--w c:\program files\InstallShield Installation Information
        2008-11-26 23:21 --------- d-----w c:\documents and settings\srata\Application Data\shamela
        2008-11-17 21:03 --------- d-----w c:\program files\FairStars Audio Converter
        2008-11-17 20:51 --------- d-----w c:\program files\MediaCoder
        2008-11-04 11:38 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
        2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
        2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll
        2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
        2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
        2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
        2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
        2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
        2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
        2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
        2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
        2008-10-16 10:38 663,552 ----a-w c:\windows\system32\wininet.dll
        2008-10-03 10:17 247,326 ----a-w c:\windows\system32\strmdll.dll
        .

        ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
        "ares"="c:\program files\Ares\Ares.exe" [2007-11-23 962560]
        "UMService"="c:\program files\LG Electronics\Modem USB LG Electronics\UMAService.exe" [2008-05-09 28672]
        "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-11-19 342336]
        "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_04\bin\jusched.exe" [2005-06-03 36975]
        "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
        "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
        "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-08-05 98304]
        "SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2008-07-06 111928]
        "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-16 185896]
        "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

        [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
        "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
        "msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
        "msacm.mpegacm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\MPEGacm.acm
        "msacm.ulmp3acm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "c:\\Program Files\\Ares\\Ares.exe"=
        "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
        "c:\\Program Files\\MSN Messenger\\livecall.exe"=
        "c:\\Program Files\\eMule\\emule.exe"=
        "c:\\Program Files\\DNA\\btdna.exe"=
        "c:\\Program Files\\BitTorrent\\bittorrent.exe"=

        .
        - - - - ORPHANS REMOVED - - - -

        BHO-{3194090F-A0AA-4A88-BBED-F17D67FED54B} - c:\windows\system32\tuvUNfGW.dll
        WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
        HKCU-Run-94276741190140628802057346143358 - c:\program files\A360\av360.exe
        HKLM-Run-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL

        .
        ------- Supplementary Scan -------
        .
        uStart Page = hxxp://www.google.co.ma/
        mStart Page = hxxp://home.sweetim.com
        uInternet Connection Wizard,ShellNext = iexplore
        uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/?p=us
        IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
        IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm674YYMA
        IE: Backward &Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
        IE: Cac&hed Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
        IE: Download All by FlashGet - c:\program files\FlashGet\jc_all.htm
        IE: Download using FlashGet - c:\program files\FlashGet\jc_link.htm
        IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        IE: Si&milar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html

        O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_0.cab
        c:\windows\Downloaded Program Files\hardwaredetection.inf
        .

        **************************************************************************

        catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2008-12-16 15:58:16
        Windows 5.1.2600 Service Pack 2 NTFS

        scanning hidden processes ...

        scanning hidden autostart entries ...

        scanning hidden files ...

        scan completed successfully
        hidden files: 0

        **************************************************************************
        .
        ------------------------ Other Running Processes ------------------------
        .
        c:\program files\Alwil Software\Avast4\aswUpdSv.exe
        c:\program files\Alwil Software\Avast4\ashServ.exe
        c:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        c:\program files\Alwil Software\Avast4\ashMaiSv.exe
        c:\program files\Fichiers communs\Ahead\Lib\NMIndexStoreSvr.exe
        c:\program files\Alwil Software\Avast4\ashWebSv.exe
        .
        **************************************************************************
        .
        Completion time: 2008-12-16 16:04:28 - machine was rebooted
        ComboFix-quarantined-files.txt 2008-12-16 15:04:22

        Pre-Run: 29ے711ے589ے376 octets libres
        Post-Run: 29,646,999,552 octets libres

        257 --- E O F --- 2008-12-16 12:58:11
        0
    2. Contributeur
      ok

      c´est quoi ce programme :

      c:\program files\e-shamela

      post aussi un nouveau rapport hijack this stp
      0
      1. rapport de hijack thid :

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 16:21:32, on 16/12/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        C:\Program Files\Alwil Software\Avast4\ashServ.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        C:\Program Files\QuickTime\qttask.exe
        C:\Program Files\SweetIM\Messenger\SweetIM.exe
        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
        C:\Program Files\Ares\Ares.exe
        C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
        C:\Program Files\Fichiers communs\Ahead\lib\NMIndexStoreSvr.exe
        C:\Program Files\DNA\btdna.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        C:\WINDOWS\system32\wuauclt.exe
        C:\WINDOWS\explorer.exe
        C:\Program Files\LG Electronics\Modem USB LG Electronics\IEUM.exe
        C:\program files\internet explorer\iexplore.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.ma/?gws_rd=ssl
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/?p=us
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
        O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
        O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
        O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [SweetIM] C:\Program Files\SweetIM\Messenger\SweetIM.exe
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
        O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
        O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
        O4 - HKCU\..\Run: [UMService] C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
        O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
        O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm674YYMA
        O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
        O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
        O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
        O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
        O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
        O17 - HKLM\System\CCS\Services\Tcpip\..\{C4E93CD8-F0D0-4F42-8890-9AECE5560859}: NameServer = 192.168.50.55 196.12.209.6
        O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
        O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
        O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
        O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
        O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        O24 - Desktop Component 0: (no name) - http://www.golf5gt.com/userpix/68_Golf_20Zoll_2_1.jpg
        0
    3. Contributeur
      c´est quoi ce programme :

      c:\program files\e-shamela
      0
      1. salut ..
        e_shamela est une bibliotheque disant un logiciel pour chercher dans des livres ......
        0
        1. Contributeur
          ok

          la suite :

          Copie le texte ci-dessous :

          File::
          c:\windows\system32\trz48.tmp
          c:\windows\system32\lhufyvbj.ini
          c:\windows\system32\iodugboy.ini

          Folder::
          c:\program files\AxBx
          c:\program files\SweetIM

          Registry::
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "SweetIM"=-

          Ouvre le Bloc-Notes puis colle le texte copié.
          (Démarrer\Tous les programmes\Accessoires\Bloc notes.)
          Sauvegarde ce fichier sous le nom de CFScript.txt.

          Glisse maintenant le fichier CFScript.txt dans Combofix.exe comme ci-dessous :

          http://sd-1.archive-host.com/membres/up/1366464061/CFScript.gif

          Cela va relancer Combofix,

          Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

          Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

          Ne touche à rien tant que le scan n'est pas terminé.

          Après redémarrage, poste le contenu du rapport Combofix.txt accompagné d'un rapport Hijackthis.

          S'il n'y a pas de rédémarrage, poste quand même les rapports.

          @+
          0
          1. il y avait un redemarage ..........

            combofix :

            ComboFix 08-12-15.05 - srata 2008-12-16 16:37:23.2 - NTFSx86
            Microsoft Windows XP Professionnel 5.1.2600.2.1256.212.1036.18.255.51 [GMT 1:00]
            Running from: c:\documents and settings\srata\Bureau\ComboFix.exe
            Command switches used :: c:\documents and settings\srata\Bureau\CFScript.txt
            * Created a new restore point

            [COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]

            FILE ::
            c:\windows\system32\iodugboy.ini
            c:\windows\system32\lhufyvbj.ini
            c:\windows\system32\trz48.tmp
            .

            ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
            .

            c:\program files\AxBx
            c:\program files\AxBx\Clean Virus MSN\CleanVirusMSN.exe
            c:\program files\AxBx\Clean Virus MSN\CleanVirusMSN.url
            c:\program files\AxBx\Clean Virus MSN\mdpe_msn.dat
            c:\program files\AxBx\Clean Virus MSN\mdpe_msn2.dat
            c:\program files\AxBx\Clean Virus MSN\sig_msn.dat
            c:\program files\AxBx\Clean Virus MSN\sig_msn2.dat
            c:\program files\AxBx\Clean Virus MSN\unins000.dat
            c:\program files\AxBx\Clean Virus MSN\unins000.exe
            c:\program files\AxBx\Clean Virus MSN\vk_sscan.dll
            c:\program files\SweetIM
            c:\program files\SweetIM\Messenger\default.xml
            c:\program files\SweetIM\Messenger\mgAdaptersProxy.dll
            c:\program files\SweetIM\Messenger\mgAIMAuto.dll
            c:\program files\SweetIM\Messenger\mgAIMMessengerAdapter.dll
            c:\program files\SweetIM\Messenger\mgArchive.dll
            c:\program files\SweetIM\Messenger\mgcommon.dll
            c:\program files\SweetIM\Messenger\mgcommunication.dll
            c:\program files\SweetIM\Messenger\mgconfig.dll
            c:\program files\SweetIM\Messenger\mgFlashPlayer.dll
            c:\program files\SweetIM\Messenger\mghooking.dll
            c:\program files\SweetIM\Messenger\mgIEPlayer.dll
            c:\program files\SweetIM\Messenger\mglogger.dll
            c:\program files\SweetIM\Messenger\mgMediaPlayer.dll
            c:\program files\SweetIM\Messenger\mgMsnAuto.dll
            c:\program files\SweetIM\Messenger\mgMsnMessengerAdapter.dll
            c:\program files\SweetIM\Messenger\mgsimcommon.dll
            c:\program files\SweetIM\Messenger\mgSweetIM.dll
            c:\program files\SweetIM\Messenger\mgUpdateSupport.dll
            c:\program files\SweetIM\Messenger\mgxml_wrapper.dll
            c:\program files\SweetIM\Messenger\mgYahooAuto.dll
            c:\program files\SweetIM\Messenger\mgYahooMessengerAdapter.dll
            c:\program files\SweetIM\Messenger\msvcp71.dll
            c:\program files\SweetIM\Messenger\msvcr71.dll
            c:\program files\SweetIM\Messenger\resources\images\AudibleButton.png
            c:\program files\SweetIM\Messenger\resources\images\DisplayPicturesButton.png
            c:\program files\SweetIM\Messenger\resources\images\EmoticonButton.png
            c:\program files\SweetIM\Messenger\resources\images\NudgeButton.png
            c:\program files\SweetIM\Messenger\resources\images\SoundFxButton.png
            c:\program files\SweetIM\Messenger\resources\images\WinksButton.png
            c:\program files\SweetIM\Messenger\SweetIM.exe
            c:\windows\system32\iodugboy.ini
            c:\windows\system32\lhufyvbj.ini
            c:\windows\system32\trz48.tmp

            .
            ((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 )))))))))))))))))))))))))))))))
            .

            2008-12-16 14:11 . 2008-12-16 14:11 <REP> d-------- c:\windows\ERUNT
            2008-12-16 14:03 . 2008-12-16 14:28 <REP> d-------- C:\SDFix
            2008-12-15 23:51 . 2008-12-15 23:51 <REP> d-------- c:\program files\Trend Micro
            2008-12-15 14:17 . 2008-12-15 14:17 <REP> d-------- C:\MSNFix
            2008-12-14 23:15 . 2008-12-14 23:15 <REP> d-------- c:\program files\Ares
            2008-12-14 21:31 . 2008-12-14 21:36 4,014 --a------ C:\mpsn.MSNFix
            2008-12-14 10:46 . 2008-12-14 23:17 <REP> d-------- c:\program files\ESET
            2008-12-13 22:19 . 2008-12-14 22:25 143 --a------ c:\windows\system32\mcrh.MSNFix
            2008-12-13 20:40 . 2008-12-13 01:16 52,786 --a------ c:\windows\fxstaller.MSNFix
            2008-11-27 00:18 . 2008-11-27 00:21 <REP> d-------- c:\program files\e-shamela
            2008-11-17 22:03 . 2008-11-17 22:03 <REP> d-------- c:\documents and settings\srata\Application Data\FairStars Audio Converter
            2008-11-17 17:00 . 2008-10-24 12:10 453,632 -----c--- c:\windows\system32\dllcache\mrxsmb.sys

            .
            (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
            .
            2008-12-16 15:45 --------- d-----w c:\program files\DNA
            2008-12-16 15:45 --------- d-----w c:\documents and settings\srata\Application Data\DNA
            2008-12-16 14:55 --------- d-----w c:\program files\FlashGet
            2008-12-15 23:11 --------- d-----w c:\documents and settings\srata\Application Data\BitTorrent
            2008-12-11 14:24 --------- d-----w c:\program files\MSN Messenger
            2008-12-08 23:20 --------- d--h--w c:\program files\InstallShield Installation Information
            2008-11-26 23:21 --------- d-----w c:\documents and settings\srata\Application Data\shamela
            2008-11-17 21:03 --------- d-----w c:\program files\FairStars Audio Converter
            2008-11-17 20:51 --------- d-----w c:\program files\MediaCoder
            2008-11-04 11:38 --------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
            2008-10-24 11:10 453,632 ----a-w c:\windows\system32\drivers\mrxsmb.sys
            2008-10-23 13:00 283,648 ----a-w c:\windows\system32\gdi32.dll
            2008-10-16 13:13 202,776 ----a-w c:\windows\system32\wuweb.dll
            2008-10-16 13:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
            2008-10-16 13:12 561,688 ----a-w c:\windows\system32\wuapi.dll
            2008-10-16 13:12 323,608 ----a-w c:\windows\system32\wucltui.dll
            2008-10-16 13:09 92,696 ----a-w c:\windows\system32\cdm.dll
            2008-10-16 13:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
            2008-10-16 13:09 43,544 ----a-w c:\windows\system32\wups2.dll
            2008-10-16 13:08 34,328 ----a-w c:\windows\system32\wups.dll
            2008-10-16 10:38 663,552 ----a-w c:\windows\system32\wininet.dll
            2008-10-03 10:17 247,326 ----a-w c:\windows\system32\strmdll.dll
            .

            ((((((((((((((((((((((((((((( snapshot@2008-12-16_16.03.09.90 )))))))))))))))))))))))))))))))))))))))))
            .
            + 2008-12-16 15:43:06 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_478.dat
            .
            ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
            .
            .
            *Note* empty entries & legit default entries are not shown
            REGEDIT4

            [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Fichiers communs\Ahead\lib\NMBgMonitor.exe" [2005-10-28 94208]
            "ares"="c:\program files\Ares\Ares.exe" [2007-11-23 962560]
            "UMService"="c:\program files\LG Electronics\Modem USB LG Electronics\UMAService.exe" [2008-05-09 28672]
            "BitTorrent DNA"="c:\program files\DNA\btdna.exe" [2008-11-19 342336]
            "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-19 15360]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_04\bin\jusched.exe" [2005-06-03 36975]
            "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
            "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
            "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-08-05 98304]
            "TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-08-16 185896]
            "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

            [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-19 15360]

            [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
            "msacm.dvacm"= c:\progra~1\FICHIE~1\ULEADS~1\Vio\Dvacm.acm
            "msacm.mpegacm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\MPEGacm.acm
            "msacm.ulmp3acm"= c:\progra~1\FICHIE~1\ULEADS~1\MPEG\ulmp3acm.acm

            [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
            "%windir%\\system32\\sessmgr.exe"=
            "c:\\Program Files\\Ares\\Ares.exe"=
            "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
            "c:\\Program Files\\MSN Messenger\\livecall.exe"=
            "c:\\Program Files\\eMule\\emule.exe"=
            "c:\\Program Files\\DNA\\btdna.exe"=
            "c:\\Program Files\\BitTorrent\\bittorrent.exe"=

            .
            - - - - ORPHANS REMOVED - - - -

            HKLM-Run-SweetIM - c:\program files\SweetIM\Messenger\SweetIM.exe

            .
            ------- Supplementary Scan -------
            .
            uStart Page = hxxp://www.google.co.ma/
            mStart Page = hxxp://home.sweetim.com
            uInternet Connection Wizard,ShellNext = iexplore
            uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/?p=us
            IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
            IE: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm674YYMA
            IE: Backward &Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
            IE: Cac&hed Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
            IE: Download All by FlashGet - c:\program files\FlashGet\jc_all.htm
            IE: Download using FlashGet - c:\program files\FlashGet\jc_link.htm
            IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            IE: Si&milar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html

            O16 -: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - hxxp://fichiers.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection_3_0_3_0.cab
            c:\windows\Downloaded Program Files\hardwaredetection.inf
            .

            **************************************************************************

            catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
            Rootkit scan 2008-12-16 16:43:25
            Windows 5.1.2600 Service Pack 2 NTFS

            scanning hidden processes ...

            scanning hidden autostart entries ...

            scanning hidden files ...

            scan completed successfully
            hidden files: 0

            **************************************************************************
            .
            ------------------------ Other Running Processes ------------------------
            .
            c:\program files\Alwil Software\Avast4\aswUpdSv.exe
            c:\program files\Alwil Software\Avast4\ashServ.exe
            c:\program files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
            c:\program files\Alwil Software\Avast4\ashMaiSv.exe
            c:\program files\Alwil Software\Avast4\ashWebSv.exe
            .
            **************************************************************************
            .
            Completion time: 2008-12-16 16:48:48 - machine was rebooted
            ComboFix-quarantined-files.txt 2008-12-16 15:48:42
            ComboFix2.txt 2008-12-16 15:04:30

            Pre-Run: 29ے630ے214ے144 octets libres
            Post-Run: 29,611,905,024 octets libres

            181 --- E O F --- 2008-12-16 12:58:11

            hijack this :

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 16:52:30, on 16/12/2008
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe
            C:\Program Files\Ares\Ares.exe
            C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
            C:\Program Files\DNA\btdna.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\explorer.exe
            C:\WINDOWS\system32\notepad.exe
            C:\Program Files\LG Electronics\Modem USB LG Electronics\IEUM.exe
            C:\program files\internet explorer\iexplore.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.co.ma/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
            R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/?p=us
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
            O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
            O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
            O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Ahead\lib\NMBgMonitor.exe"
            O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
            O4 - HKCU\..\Run: [UMService] C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
            O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Program Files\DNA\btdna.exe"
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
            O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRxdm674YYMA
            O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
            O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
            O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
            O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
            O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
            O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
            O17 - HKLM\System\CCS\Services\Tcpip\..\{C4E93CD8-F0D0-4F42-8890-9AECE5560859}: NameServer = 192.168.50.55 196.12.209.6
            O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
            O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
            O24 - Desktop Component 0: (no name) - http://www.golf5gt.com/userpix/68_Golf_20Zoll_2_1.jpg
            0
            1. Contributeur
              ok bien joué :)

              c´est pas encore fini, maintenant on va passer aux scans...

              Fais un scan avec cet antispyware :

              Telecharge malwarebytes + tutoriel :

              -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

              Tu l´instale; le programme va se mettre automatiquement a jour.

              Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

              Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

              Puis click sur "rechercher".

              Laisse le scanner le pc...

              Si des elements on ete trouvés > click sur supprimer la selection.

              si il t´es demandé de redemarrer > click sur "yes".

              A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

              Copie et colle le rapport stp.

              ps : c´est un peu long, mais...
              0
              1. ok . le scan est fait sans redemarrer . voila le rapport :

                Malwarebytes' Anti-Malware 1.31
                Version de la base de données: 1456
                Windows 5.1.2600 Service Pack 2

                16/12/2008 17:42:57
                mbam-log-2008-12-16 (17-42-57).txt

                Type de recherche: Examen complet (C:\|D:\|E:\|)
                Eléments examinés: 97546
                Temps écoulé: 35 minute(s), 6 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 95
                Valeur(s) du Registre infectée(s): 2
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 31

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.htmlmenu.2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearch.outlookaddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                Valeur(s) du Registre infectée(s):
                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\ (Adware.Hotbar) -> Quarantined and deleted successfully.
                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                C:\Program Files\MSN Messenger\riched20.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\Qoobox\Quarantine\C\WINDOWS\system32\f3PSSavr.scr.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP162\A0075736.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP164\A0078622.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080056.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080058.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080060.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080063.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080065.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080066.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080071.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080072.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080073.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080079.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080080.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080085.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080096.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                C:\System Volume Information\_restore{2D353F17-0DF7-4888-B52B-2426AFAE68C8}\RP166\A0080068.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                0
                1. Contributeur
                  on continu > encore un scan > apres on arrete :)

                  regarde ceci concernant avast :

                  antivir vs avast :

                  -> http://forum.malekal.com/ftopic3528.php

                  alors je te conseille de le desinstaller et d´installer antivir a la place

                  Telecharge et instales l'antivirus Antivir Personal Edition Classic :

                  ->https://www.malekal.com/avira-free-security-antivirus-gratuit/

                  https://www.avira.com/en/prime

                  En francais :

                  https://www.avira.com/

                  Reglages :

                  en image :

                  http://speedweb1.free.fr/frames2.php?page=tuto5

                  mes explications :

                  une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
                  ceux qui ne voie pas root kit search : clcik sur le parapluie dans ta barre des tache > dans la fenetre d´antivir click sur local protection click en suite sur scanner
                  dans la fenetre de droite : tu a rootkit search vers le bas > tu developpe en appuyant sur le petit +
                  et coche tes disques...
                  puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
                  coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
                  puis sur la droite coche les case suivantes :
                  scan boot sectors of selected drives
                  scan master boot sectors
                  scan memory
                  search foe rootkit before scan
                  decoche :
                  ignore off line files
                  toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

                  Je te dis tous ca car j´aimerais que tu performes un scan entier de ta machine a l´aide d´antivir avec les reglages stipulés ci dessus et que tu post le rapport généré ici stp

                  courage`

                  @´+
                  0
                  1. merci bq pour votre soutien ...j ss entrain de telecharger l antivirus ...et j crois qu il va prendre un peu de temps suite a ma faible conexion ..environ 1 heure a ce qu il m indique ici .. merci .. et j vais poste le rapport ici .
                    0
                    1. Contributeur
                      1 heure ?!
                      Bon et bien bon courrage`
                      @+
                      0
                      1. re salut . j ai lance avira suivant les demarches que vous m avez notes .le rapport est tres long . voulez vous vraiment que j le poste ??????
                        0
                        1. ben il y a une mauvaise nouvelle . dans le 1 er scan tout marche bien . me j ai fait un 2 eme scan et l antivirus detecte de nouveau ce maudit " spirit " .que dois j faire ???ecommencer a nouveau toutes les demarches faites .?????
                          0
                          1. Contributeur
                            salut,

                            si le rapport est trop long ne le post pas, donne moi le chemin de "spirit" stp

                            @+
                            0
                            1. ben j ai redemarre et j ai lance un 3 eme scan et il n a detecte aucun virus .
                              remarque : j ai fait juste le scan " recherche des objets cache en cours " .pour ca le rapport n est pas long et j peux le poster ....
                              0
                              1. voici le rapport du dernier scan : sans scaner la partition system :

                                Avira AntiVir Personal
                                Date de création du fichier de rapport : mercredi 17 décembre 2008 00:35

                                La recherche porte sur 1094481 souches de virus.

                                Détenteur de la licence :Avira AntiVir PersonalEdition Classic
                                Numéro de série : 0000149996-ADJIE-0001
                                Plateforme : Windows XP
                                Version de Windows :(Service Pack 2) [5.1.2600]
                                Mode Boot : Démarré normalement
                                Identifiant : srata
                                Nom de l'ordinateur :SRATA-68RGZCRSX

                                Informations de version :
                                BUILD.DAT : 8.2.0.52 16931 Bytes 02-12-2008 14:55:00
                                AVSCAN.EXE : 8.1.4.10 315649 Bytes 18-11-2008 08:21:00
                                AVSCAN.DLL : 8.1.4.1 49921 Bytes 21-07-2008 13:44:27
                                LUKE.DLL : 8.1.4.5 164097 Bytes 12-06-2008 12:44:16
                                LUKERES.DLL : 8.1.4.0 13057 Bytes 04-07-2008 07:30:27
                                ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27-10-2008 11:30:36
                                ANTIVIR1.VDF : 7.1.0.197 1170432 Bytes 07-12-2008 22:14:13
                                ANTIVIR2.VDF : 7.1.0.230 156160 Bytes 14-12-2008 22:15:00
                                ANTIVIR3.VDF : 7.1.0.243 114176 Bytes 16-12-2008 22:15:25
                                Version du moteur: 8.2.0.45
                                AEVDF.DLL : 8.1.0.6 102772 Bytes 14-10-2008 10:05:56
                                AESCRIPT.DLL : 8.1.1.19 336252 Bytes 16-12-2008 22:19:37
                                AESCN.DLL : 8.1.1.5 123251 Bytes 07-11-2008 15:06:41
                                AERDL.DLL : 8.1.1.3 438645 Bytes 04-11-2008 13:58:38
                                AEPACK.DLL : 8.1.3.4 393591 Bytes 11-11-2008 09:41:39
                                AEOFFICE.DLL : 8.1.0.33 196987 Bytes 16-12-2008 22:19:06
                                AEHEUR.DLL : 8.1.0.75 1524087 Bytes 16-12-2008 22:18:45
                                AEHELP.DLL : 8.1.2.0 119159 Bytes 16-12-2008 22:16:17
                                AEGEN.DLL : 8.1.1.8 323956 Bytes 16-12-2008 22:16:06
                                AEEMU.DLL : 8.1.0.9 393588 Bytes 14-10-2008 10:05:56
                                AECORE.DLL : 8.1.5.2 172405 Bytes 16-12-2008 22:15:41
                                AEBB.DLL : 8.1.0.3 53618 Bytes 14-10-2008 10:05:56
                                AVWINLL.DLL : 1.0.0.12 15105 Bytes 09-07-2008 08:40:02
                                AVPREF.DLL : 8.0.2.0 38657 Bytes 16-05-2008 09:27:58
                                AVREP.DLL : 8.0.0.2 98344 Bytes 31-07-2008 12:02:15
                                AVREG.DLL : 8.0.0.1 33537 Bytes 09-05-2008 11:26:37
                                AVARKT.DLL : 1.0.0.23 307457 Bytes 12-02-2008 08:29:19
                                AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12-06-2008 12:27:46
                                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22-01-2008 17:28:02
                                SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12-06-2008 12:49:36
                                NETNT.DLL : 8.0.0.1 7937 Bytes 25-01-2008 12:05:07
                                RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 04-07-2008 07:23:16
                                RCTEXT.DLL : 8.0.52.1 86273 Bytes 17-07-2008 10:08:43

                                Configuration pour la recherche actuelle :
                                Nom de la tâche..................: Recherche de Rootkits
                                Fichier de configuration.........: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\rootkit.avp
                                Documentation....................: élevé
                                Action principale................: interactif
                                Action secondaire................: ignorer
                                Recherche sur les secteurs d'amorçage maître: marche
                                Recherche sur les secteurs d'amorçage: marche
                                Recherche dans les programmes actifs: arrêt
                                Recherche en cours sur l'enregistrement: arrêt
                                Recherche de Rootkits............: marche
                                Fichier mode de recherche........: Tous les fichiers
                                Recherche sur les archives.......: marche
                                Limiter la profondeur de récursivité: 20
                                Archive Smart Extensions.........: marche
                                Heuristique de macrovirus........: marche
                                Heuristique fichier..............: élevé
                                Paramètres étendus de recherche..: 0x00300922

                                Début de la recherche : mercredi 17 décembre 2008 00:35

                                La recherche d'objets cachés commence.
                                '261330' objets ont été contrôlés, '0' objets cachés ont été trouvés.

                                Fin de la recherche : mercredi 17 décembre 2008 00:41
                                Temps nécessaire: 06:02 Minute(s)

                                La recherche a été effectuée intégralement

                                0 Les répertoires ont été contrôlés
                                0 Des fichiers ont été contrôlés
                                0 Des virus ou programmes indésirables ont été trouvés
                                0 Des fichiers ont été classés comme suspects
                                0 Des fichiers ont été supprimés
                                0 Des virus ou programmes indésirables ont été réparés
                                0 Les fichiers ont été déplacés dans la quarantaine
                                0 Les fichiers ont été renommés
                                0 Impossible de contrôler des fichiers
                                0 Fichiers non infectés
                                0 Les archives ont été contrôlées
                                0 Avertissements
                                0 Consignes
                                261330 Des objets ont été contrôlés lors du Rootkitscan
                                0 Des objets cachés ont été trouvés
                                0
                                1. Contributeur
                                  ok

                                  il est long comment l´autre ?

                                  peux tu m´informer sur spirit ?

                                  @+
                                  0
                                  1. j n peux te dire une chose certaine sur " spirit " me j crois qu il a ete detecte au 2 eme scan sous forme de fichier mbro ou quelque chose comme ca ....j ss au 5 eme scan et rien de detecte .un msg disait que l analyse de la partition susteme est fortement recommande et j ai cliker sur " oui " .
                                    0
                                • 1
                                • 2
                                • 3