VUNDO

Résolu
Bonjour,
Je viens de me faire infecter par vundo. J'ai fait fonctionner quelques logiciels et j'ai toujours quelques lignes qui me dérangent sur Hijackthis.
Pouvez vous m'aider s'il vous plait.
Voici mon rapport:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:11:28, on 27/01/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Vtune\TBPanel.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\VM305_STI.EXE
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Wanadoo\Watch.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\monjack.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
O4 - HKLM\..\Run: [Gainward] C:\Program Files\Vtune\TBPanel.exe /A
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera V
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe

--
End of file - 8629 bytes
Configuration: Windows XP
Firefox 3.0.5

44 réponses

Résumé de la discussion

Une infection présumée par Vundo est signalée avec un log HijackThis détaillant de nombreuses entrées et processus Windows, ce qui motive une demande d’aide pour nettoyer le système. Des solutions pratiques sont proposées, notamment l’exécution de GenProc et de smitfraudfix, avec possibilité de désactiver le contrôle des comptes utilisateurs et de poster le contenu des rapports obtenus. En parallèle, d’autres recommandations évoquent l’utilisation d’outils complémentaires et le suivi des instructions des participants pour éviter les fausses manipulations et obtenir des rapports exploitables. Certaines confirmations d’amélioration apparaissent lorsque ces mesures sont appliquées, soulignant une progression du fonctionnement du système après le nettoyage.

Bobot (l’IA à votre service)
  1. Mon Pc va mieux.
    Merci pour ton aide.
    Merci, merci et encore merci.
    Cordialement
    0
    1. je n'ai pas trouvé la ligne "messenger skinner", mais j'ai trouvé à la place "It's TV"
      je ne l'ai pas supprimée

      voici le rapport

      ------- LOGFILE OF AD-REMOVER 1.0.9.3 | ONLY XP/VISTA -------

      Updated by C_XX on 17/01/2009 at 12:00

      *** LIMITED TO ***

      Boonty/Boontygames
      Eorezo
      Everest casino/Everest poker
      Funwebproduct/Myway/Mywebsearch
      Sweetim

      ******************

      Start at: 1:34:36 | Sam 31/01/2009 | Microsoft® Windows XP™ SP3 (V5.1.2600)
      Boot mode: Normal
      Option: CLEAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
      Pc: PERSO | User: Moi ( Current user is an administrator)
      Drive(s):
      - C:\ (File System: NTFS)
      - D:\ (File System: NTFS)
      System Drive: C:\
      Windows Directory: C:\WINDOWS\
      System Directory: C:\WINDOWS\System32\

      --- Running Processes: 37

      (!) ---- IE start pages reset

      +--------------------| Boonty/Boonty Games Elements Deleted :

      .
      .

      +--------------------| Eorezo Elements Deleted :

      .
      HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\EOENGINE
      HKCU\SOFTWARE\EoRezo
      HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
      HKLM\SOFTWARE\EoRezo
      HKLM\SOFTWARE\Classes\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
      HKLM\SOFTWARE\Classes\AppID\EoRezoBHO.DLL
      HKLM\SOFTWARE\Classes\TypeLib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
      .
      C:\Documents and Settings\Moi\Application Data\EoRezo

      +--------------------| Everest Casino/Everest Poker Elements Deleted :

      .
      .

      +--------------------| Funwebproducts/Myway/Mywebsearch/Myglobalsearch Elements Deleted :

      .
      .

      +--------------------| Sweetim Elements Deleted :

      .
      .

      (!) ---- Temp files deleted.
      (!) ---- Recycle bin emptied in all drives.

      +--------------------| Added Scan :

      +---------- SCANNING PREFS.JS ... ( # MOZILLA USER PREFERENCES )

      ..\6blp39lv.default\prefs.js :

      ~~~~ MOZILLA FIREFOX VERSION 3.0.5 ~~~~

      * BROWSER STARTUP HOMEPAGE: "http://www.lo.st"

      .
      REMOVED - user_pref("browser.startup.homepage", "http://www.lo.st");

      +---------------------------------------------------------------------------+

      ~~~~ INTERNET EXPLORER VERSION 6.0.2900.5512 ~~~~

      +--[HKEY_CURRENT_USER\..\INTERNET EXPLORER\MAIN]

      Start page : hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

      +--[HKEY_LOCAL_MACHINE\..\INTERNET EXPLORER\MAIN]

      Start page : hxxp://fr.msn.com/

      +---------------------------------------------------------------------------+

      [~2356 BYTES] - "C:\AD-REPORT-CLEAN-31.01.2009.LOG"
      [~3211 BYTES] - "C:\AD-REPORT-SCAN-30.01.2009.LOG"

      End at: 1:37:27 | 31/01/2009 - Time elapsed: 2 minutes, 50 seconds

      +---------------------------------------------------------------------------+
      +------------------------------- [ E.O.F - 60 Lines ]
      +---------------------------------------------------------------------------+
      0
      1. Contributeur sécurité
        Nettoyage AD-Remover :

        ! Déconnectes toi et fermes toutes applications en cours !

        ? Relances "Ad-remover" : au menu principal choisi l'option "B" .

        ? A l'écran de sélection, choisi le chiffre à gauche de ces lignes en validant par ENTREE à chaque fois :

        Suppression Boonty/BoontyGames
        Suppression Eorezo
        Suppression Everest Poker
        Suppression Funwebproduct/MyWay/MyWebsearch
        Suppression Messenger Skinner
        Suppression Sweetim

        ? Puis choisi "S" , le programme va travailler,

        ? Postes le rapport qui apparait à la fin.

        ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

        (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

        /!\ Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tapes explorer.exe et valides)
        0
        1. Contributeur sécurité
          Télécharges Ad-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :

          /!\ Déconnectes toi et fermes toutes applications en cours, désactive ton antivirus le temps de la manipulation/!\

          ? Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. (C:\Program files )
          ? Double clique sur l'icône Ad-remover située sur ton bureau
          ? Au menu principal choisi l'option "A"
          ? Postes le rapport qui apparaît à la fin .

          ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

          (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)

          Note :

          "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          0
          1. ------- LOGFILE OF AD-REMOVER 1.0.9.3 | ONLY XP/VISTA -------

            Updated by C_XX on 17/01/2009 at 12:00

            Start at: 20:03:20 | Ven 30/01/2009 | Microsoft® Windows XP™ SP3 (V5.1.2600)
            Boot mode: Normal
            Option: SCAN | Executed from: C:\Program Files\Ad-remover\Ad-remover.bat
            Pc: PERSO | User: Moi ( Current user is an administrator)
            Drive(s):
            - C:\ (File System: NTFS)
            - D:\ (File System: NTFS)
            System Drive: C:\
            Windows Directory: C:\WINDOWS\
            System Directory: C:\WINDOWS\System32\

            --- Running Processes: 38

            +--------------------| Boonty/Boonty Games Elements Found :

            .
            .

            +--------------------| Eorezo Elements Found :

            .
            HKCU\SOFTWARE\EoRezo
            HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
            HKLM\SOFTWARE\EoRezo
            HKLM\SOFTWARE\Classes\AppID\{362A53B2-2913-4F8A-82F5-7E0A23FDC6F9}
            HKLM\SOFTWARE\Classes\AppID\EoRezoBHO.DLL
            HKLM\SOFTWARE\Classes\TypeLib\{B6ACB3F1-6A83-432C-B854-3E1056F87F4E}
            HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN\\EOENGINE
            .
            C:\Documents and Settings\Moi\Application Data\EoRezo
            C:\Documents and Settings\Moi\Application Data\EoRezo\cache
            C:\Documents and Settings\Moi\Application Data\EoRezo\cmhost.cyp
            C:\Documents and Settings\Moi\Application Data\EoRezo\ConfMedia.cyp
            C:\Documents and Settings\Moi\Application Data\EoRezo\db
            C:\Documents and Settings\Moi\Application Data\EoRezo\eoDesktop
            C:\Documents and Settings\Moi\Application Data\EoRezo\host.cyp
            C:\Documents and Settings\Moi\Application Data\EoRezo\user.cyp
            C:\Documents and Settings\Moi\Application Data\EoRezo\db\cat.cyp
            C:\Documents and Settings\Moi\Application Data\EoRezo\eoDesktop\config.xml
            C:\Documents and Settings\Moi\Application Data\EoRezo\eoDesktop\eoDesktop.html
            C:\Documents and Settings\Moi\Application Data\EoRezo\eoDesktop\userConfig.xml

            +--------------------| Everest Casino/Everest Poker Elements Found :

            .
            .

            +--------------------| Funwebproducts/Myway/Mywebsearch/Myglobalsearch Elements Found :

            .
            .

            +--------------------| It's TV Elements Found :

            .

            +--------------------| Sweetim Elements Found :

            .
            .

            +--------------------| Added Scan :

            +---------- SCANNING PREFS.JS ... ( # Mozilla user preferences )

            ..\6blp39lv.default\prefs.js :

            ~~~~ MOZILLA FIREFOX VERSION 3.0.5 ~~~~

            * BROWSER STARTUP HOMEPAGE: "http://www.lo.st"

            .
            FOUND - user_pref("browser.startup.homepage", "http://www.lo.st");

            +---------------------------------------------------------------------------+

            ~~~~ INTERNET EXPLORER VERSION 6.0.2900.5512 ~~~~

            +--[HKEY_CURRENT_USER\..\INTERNET EXPLORER\MAIN]

            Start page : hxxp://go.microsoft.com/fwlink/?LinkId=69157

            +--[HKEY_LOCAL_MACHINE\..\INTERNET EXPLORER\MAIN]

            Start page : hxxp://www.msn.com/

            +---------------------------------------------------------------------------+

            [~2870 BYTES] - "C:\AD-REPORT-SCAN-30.01.2009.LOG"

            End at: 20:05:35 | 30/01/2009 - Time elapsed: 2 minutes, 14 seconds

            +---------------------------------------------------------------------------+
            +------------------------------- [ E.O.F - 63 Lines ]
            +---------------------------------------------------------------------------+
            0
        2. Est ce normal que je ne trouve info.txt ni dans ma barre de taches ni dans C:/RSIT ?
          0
          1. Logfile of random's system information tool 1.05 (written by random/random)
            Run by Moi at 2009-01-30 17:59:52
            Microsoft Windows XP Édition familiale Service Pack 3
            System drive C: has 14 GB (27%) free of 53 GB
            Total RAM: 2047 MB (70% free)

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 18:00:11, on 30/01/2009
            Platform: Windows XP SP3 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
            Boot mode: Normal

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\csrss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Tall Emu\Online Armor\oasrv.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            C:\WINDOWS\RTHDCPL.EXE
            C:\Program Files\Vtune\TBPanel.exe
            C:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
            C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
            C:\Program Files\iTunes\iTunesHelper.exe
            C:\Program Files\Java\jre6\bin\jusched.exe
            C:\WINDOWS\VM305_STI.EXE
            C:\Program Files\Tall Emu\Online Armor\oaui.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\Java\jre6\bin\jqs.exe
            C:\Program Files\CDBurnerXP\NMSAccessU.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\WINDOWS\system32\PSIService.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\iPod\bin\iPodService.exe
            C:\WINDOWS\system32\wbem\wmiapsrv.exe
            C:\WINDOWS\System32\alg.exe
            C:\PROGRA~1\Wanadoo\Watch.exe
            C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Documents and Settings\Moi\Bureau\RSIT.exe
            C:\WINDOWS\system32\wbem\wmiprvse.exe
            C:\Program Files\trend micro\Moi.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - Default URLSearchHook is missing
            O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
            O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
            O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
            O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
            O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
            O4 - HKLM\..\Run: [Gainward] C:\Program Files\Vtune\TBPanel.exe /A
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
            O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
            O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
            O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera V
            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
            O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
            O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
            O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
            O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
            O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
            O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - http://www.orange.fr (file missing) (HKCU)
            O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
            O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
            O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
            O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
            O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
            O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
            O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
            O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
            O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
            O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
            0
            1. ok j'ai compris, c'est le poste 4, tu parlais de ton premier poste, c'est pour ca que je trouvais pas
              0
              1. Désolé, je suis nul, je le trouve ou le poste 1

                voici le rapport antivir

                Avira AntiVir Personal
                Report file date: vendredi 30 janvier 2009 14:00

                Scanning for 1299722 virus strains and unwanted programs.

                Licensed to: Avira AntiVir PersonalEdition Classic
                Serial number: 0000149996-ADJIE-0001
                Platform: Windows XP
                Windows version: (Service Pack 3) [5.1.2600]
                Boot mode: Normally booted
                Username: SYSTEM
                Computer name: PERSO

                Version information:
                BUILD.DAT : 8.2.0.337 16934 Bytes 18/11/2008 13:05:00
                AVSCAN.EXE : 8.1.4.10 315649 Bytes 25/11/2008 11:10:47
                AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:40
                LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:19
                LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:52
                ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 22:42:43
                ANTIVIR1.VDF : 7.1.1.113 2817536 Bytes 14/01/2009 12:25:53
                ANTIVIR2.VDF : 7.1.1.172 958464 Bytes 23/01/2009 12:22:02
                ANTIVIR3.VDF : 7.1.1.201 389120 Bytes 29/01/2009 13:07:37
                Engineversion : 8.2.0.60
                AEVDF.DLL : 8.1.0.6 102772 Bytes 17/10/2008 14:56:18
                AESCRIPT.DLL : 8.1.1.32 340347 Bytes 23/01/2009 12:22:27
                AESCN.DLL : 8.1.1.5 123251 Bytes 08/11/2008 11:10:01
                AERDL.DLL : 8.1.1.3 438645 Bytes 06/11/2008 11:10:05
                AEPACK.DLL : 8.1.3.5 393588 Bytes 09/01/2009 12:22:44
                AEOFFICE.DLL : 8.1.0.33 196987 Bytes 11/12/2008 20:11:29
                AEHEUR.DLL : 8.1.0.86 1552759 Bytes 23/01/2009 12:22:26
                AEHELP.DLL : 8.1.2.0 119159 Bytes 19/11/2008 11:09:16
                AEGEN.DLL : 8.1.1.10 323957 Bytes 17/01/2009 12:22:14
                AEEMU.DLL : 8.1.0.9 393588 Bytes 17/10/2008 14:56:02
                AECORE.DLL : 8.1.5.2 172405 Bytes 29/11/2008 11:09:13
                AEBB.DLL : 8.1.0.3 53618 Bytes 17/10/2008 14:55:59
                AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:05
                AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:01
                AVREP.DLL : 8.0.0.2 98344 Bytes 06/08/2008 18:47:35
                AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:40
                AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:23
                AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:49
                SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:02
                SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:40
                NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:10
                RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:07
                RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:37

                Configuration settings for the scan:
                Jobname..........................: Complete system scan
                Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
                Logging..........................: low
                Primary action...................: interactive
                Secondary action.................: ignore
                Scan master boot sector..........: on
                Scan boot sector.................: on
                Boot sectors.....................: C:, D:,
                Process scan.....................: on
                Scan registry....................: on
                Search for rootkits..............: on
                Scan all files...................: All files
                Scan archives....................: on
                Recursion depth..................: 20
                Smart extensions.................: on
                Macro heuristic..................: on
                File heuristic...................: high

                Start of the scan: vendredi 30 janvier 2009 14:00

                Starting search for hidden objects.
                '35975' objects were checked, '0' hidden objects were found.

                The scan of running processes will be started
                Scan process 'avscan.exe' - '1' Module(s) have been scanned
                Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
                Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                Scan process 'Watch.exe' - '1' Module(s) have been scanned
                Scan process 'AlertModule.exe' - '1' Module(s) have been scanned
                Scan process 'PollingModule.exe' - '1' Module(s) have been scanned
                Scan process 'Inactivity.exe' - '1' Module(s) have been scanned
                Scan process 'Toaster.exe' - '1' Module(s) have been scanned
                Scan process 'ComComp.exe' - '1' Module(s) have been scanned
                Scan process 'GestionnaireInternet.exe' - '1' Module(s) have been scanned
                Scan process 'Policies.exe' - '1' Module(s) have been scanned
                Scan process 'alg.exe' - '1' Module(s) have been scanned
                Scan process 'wmiapsrv.exe' - '1' Module(s) have been scanned
                Scan process 'iPodService.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'PSIService.exe' - '1' Module(s) have been scanned
                Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
                Scan process 'NMSAccessU.exe' - '1' Module(s) have been scanned
                Scan process 'jqs.exe' - '1' Module(s) have been scanned
                Scan process 'mDNSResponder.exe' - '1' Module(s) have been scanned
                Scan process 'avguard.exe' - '1' Module(s) have been scanned
                Scan process 'a2service.exe' - '1' Module(s) have been scanned
                Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
                Scan process 'oaui.exe' - '0' Module(s) have been scanned
                Scan process 'VM305_STI.EXE' - '1' Module(s) have been scanned
                Scan process 'jusched.exe' - '1' Module(s) have been scanned
                Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned
                Scan process 'TaskBarIcon.exe' - '1' Module(s) have been scanned
                Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                Scan process 'rundll32.exe' - '1' Module(s) have been scanned
                Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
                Scan process 'sched.exe' - '1' Module(s) have been scanned
                Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                Scan process 'explorer.exe' - '1' Module(s) have been scanned
                Scan process 'oasrv.exe' - '0' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'svchost.exe' - '1' Module(s) have been scanned
                Scan process 'lsass.exe' - '1' Module(s) have been scanned
                Scan process 'services.exe' - '1' Module(s) have been scanned
                Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                Scan process 'csrss.exe' - '1' Module(s) have been scanned
                Scan process 'smss.exe' - '1' Module(s) have been scanned
                43 processes with 43 modules were scanned

                Starting master boot sector scan:
                Master boot sector HD0
                [INFO] No virus was found!
                Master boot sector HD1
                [INFO] No virus was found!
                [WARNING] System error [21]: Le périphérique n'est pas prêt.
                Master boot sector HD2
                [INFO] No virus was found!
                Master boot sector HD3
                [INFO] No virus was found!
                [WARNING] System error [21]: Le périphérique n'est pas prêt.
                Master boot sector HD4
                [INFO] No virus was found!
                [WARNING] System error [21]: Le périphérique n'est pas prêt.

                Start scanning boot sectors:
                Boot sector 'C:\'
                [INFO] No virus was found!
                Boot sector 'D:\'
                [INFO] No virus was found!

                Starting to scan the registry.
                The registry was scanned ( '59' files ).

                Starting the file scan:

                Begin scan in 'C:\'
                C:\pagefile.sys
                [WARNING] The file could not be opened!
                C:\Documents and Settings\Moi\Bureau\SmitfraudFix.exe
                [0] Archive type: RAR SFX (self extracting)
                --> SmitfraudFix\Agent.OMZ.Fix.exe
                [DETECTION] Is the TR/Zlob.78336123.A Trojan
                [NOTE] The file was moved to '49ebfac1.qua'!
                C:\Documents and Settings\Moi\Bureau\SmitfraudFix\Agent.OMZ.Fix.exe
                [DETECTION] Is the TR/Zlob.78336123.A Trojan
                [NOTE] The file was moved to '49e7fac4.qua'!
                C:\System Volume Information\_restore{8B1D1DE3-FF35-4E9E-9AEA-A926D9D43797}\RP171\A0020695.exe
                [DETECTION] Is the TR/Zlob.78336123.A Trojan
                [NOTE] The file was moved to '49b2fd7f.qua'!
                C:\System Volume Information\_restore{8B1D1DE3-FF35-4E9E-9AEA-A926D9D43797}\RP173\A0020745.exe
                [0] Archive type: RAR SFX (self extracting)
                --> SmitfraudFix\Agent.OMZ.Fix.exe
                [DETECTION] Is the TR/Zlob.78336123.A Trojan
                [NOTE] The file was moved to '49b2fd8c.qua'!
                C:\System Volume Information\_restore{8B1D1DE3-FF35-4E9E-9AEA-A926D9D43797}\RP173\A0020746.exe
                [DETECTION] Is the TR/Zlob.78336123.A Trojan
                [NOTE] The file was moved to '49b2fd90.qua'!
                C:\WINDOWS\system32\Agent.OMZ.Fix.exe
                [DETECTION] Is the TR/Zlob.78336123.A Trojan
                [NOTE] The file was moved to '49e7ff13.qua'!
                C:\WINDOWS\system32\kernel32.dll
                [WARNING] The file could not be opened!
                C:\WINDOWS\system32\ntdll.dll
                [WARNING] The file could not be opened!
                C:\WINDOWS\system32\ntkrnlpa.exe
                [WARNING] The file could not be opened!
                C:\WINDOWS\system32\ntoskrnl.exe
                [WARNING] The file could not be opened!
                C:\WINDOWS\system32\user32.dll
                [WARNING] The file could not be opened!
                C:\WINDOWS\system32\win32k.sys
                [WARNING] The file could not be opened!
                C:\WINDOWS\system32\drivers\ndisrd.sys
                [WARNING] The file could not be opened!
                C:\WINDOWS\system32\drivers\OADriver.sys
                [WARNING] The file could not be opened!
                C:\WINDOWS\system32\drivers\OAmon.sys
                [WARNING] The file could not be opened!
                Begin scan in 'D:\' <Docs>

                End of the scan: vendredi 30 janvier 2009 14:23
                Used time: 22:07 Minute(s)

                The scan has been done completely.

                5056 Scanning directories
                275373 Files were scanned
                6 viruses and/or unwanted programs were found
                0 Files were classified as suspicious:
                0 files were deleted
                0 files were repaired
                6 files were moved to quarantine
                0 files were renamed
                10 Files cannot be scanned
                275357 Files not concerned
                1807 Archives were scanned
                13 Warnings
                6 Notes
                35975 Objects were scanned with rootkit scan
                0 Hidden objects were found
                0
                1. Contributeur sécurité
                  Et poste le rapport de antivir stp
                  0
                  1. Contributeur sécurité
                    regarde le poste 1 pour random system information stp

                    Merci
                    0
                    1. j'ai fait des scans
                      Avira antivir m'a trouvé 5 infections
                      a squared m'a trouvé 5 infections

                      Je ne comprends pas ce qu'il faut faire avec RSIT, j'ai essayé avec virustotal, ca me met fichier introuvable
                      0
                      1. Contributeur sécurité
                        Bon je ne vois pas d'infection

                        On va voir plus profond

                        Fais RSIT stp

                        Poste le rapport
                        0
                        1. oups, je crois bien que j'ai fait une boulette, ca devait pas etre fini, desolé
                          0
                          1. Fichier VM305_STI.EXE reçu le 2009.01.30 13:13:48 (CET)
                            Situation actuelle: en cours de chargement ... mis en file d'attente en attente en cours d'analyse terminé NON TROUVE ARRETE
                            Résultat: 0/39 (0%)
                            en train de charger les informations du serveur...
                            Votre fichier est dans la file d'attente, en position: 2.
                            L'heure estimée de démarrage est entre 46 et 66 secondes.
                            Ne fermez pas la fenêtre avant la fin de l'analyse.
                            L'analyseur qui traitait votre fichier est actuellement stoppé, nous allons attendre quelques secondes pour tenter de récupérer vos résultats.
                            Si vous attendez depuis plus de cinq minutes, vous devez renvoyer votre fichier.
                            Votre fichier est, en ce moment, en cours d'analyse par VirusTotal,
                            les résultats seront affichés au fur et à mesure de leur génération.
                            Formaté Formaté
                            Impression des résultats Impression des résultats
                            Votre fichier a expiré ou n'existe pas.
                            Le service est en ce moment, stoppé, votre fichier attend d'être analysé (position : ) depuis une durée indéfinie.

                            Vous pouvez attendre une réponse du Web (re-chargement automatique) ou taper votre e-mail dans le formulaire ci-dessous et cliquer "Demande" pour que le système vous envoie une notification quand l'analyse sera terminée.
                            Email:

                            Antivirus Version Dernière mise à jour Résultat
                            a-squared 4.0.0.93 2009.01.30 -
                            AhnLab-V3 5.0.0.2 2009.01.30 -
                            AntiVir 7.9.0.60 2009.01.30 -
                            Authentium 5.1.0.4 2009.01.30 -
                            Avast 4.8.1281.0 2009.01.29 -
                            AVG 8.0.0.229 2009.01.30 -
                            BitDefender 7.2 2009.01.30 -
                            CAT-QuickHeal 10.00 2009.01.30 -
                            ClamAV 0.94.1 2009.01.30 -
                            Comodo 952 2009.01.29 -
                            DrWeb 4.44.0.09170 2009.01.30 -
                            eSafe 7.0.17.0 2009.01.29 -
                            eTrust-Vet 31.6.6335 2009.01.29 -
                            F-Prot 4.4.4.56 2009.01.29 -
                            F-Secure 8.0.14470.0 2009.01.30 -
                            Fortinet 3.117.0.0 2009.01.30 -
                            GData 19 2009.01.30 -
                            Ikarus T3.1.1.45.0 2009.01.30 -
                            K7AntiVirus 7.10.609 2009.01.29 -
                            Kaspersky 7.0.0.125 2009.01.30 -
                            McAfee 5510 2009.01.29 -
                            McAfee+Artemis 5510 2009.01.29 -
                            Microsoft 1.4306 2009.01.30 -
                            NOD32 3812 2009.01.30 -
                            Norman 6.00.02 2009.01.29 -
                            nProtect 2009.1.8.0 2009.01.30 -
                            Panda 9.5.1.2 2009.01.30 -
                            PCTools 4.4.2.0 2009.01.30 -
                            Prevx1 V2 2009.01.30 -
                            Rising 21.13.42.00 2009.01.23 -
                            SecureWeb-Gateway 6.7.6 2009.01.30 -
                            Sophos 4.38.0 2009.01.30 -
                            Sunbelt 3.2.1835.2 2009.01.16 -
                            Symantec 10 2009.01.30 -
                            TheHacker 6.3.1.5.237 2009.01.30 -
                            TrendMicro 8.700.0.1004 2009.01.30 -
                            VBA32 3.12.8.11 2009.01.30 -
                            ViRobot 2009.1.30.1582 2009.01.30 -
                            VirusBuster 4.5.11.0 2009.01.29 -
                            Information additionnelle
                            File size: 61440 bytes
                            MD5...: a01dbc02125980e2c39b3d27d6c98053
                            SHA1..: 0157d82377d4c81d2caef836b57d9a74a2736e00
                            SHA256: aa0dd2e85bb5208069fab753a60064be311cd39c53e2d27126e0c840eaf9f93d
                            SHA512: 963d3a2c767a44011cf41c66c2c2347235b47054de750e7d83a7a36edc41af3b
                            71b3caf0cef56d4c4145436ebaeaed963aa6e59162072271f3226a032eb748d0
                            ssdeep: 768:Uy1MivGSMlJFE6C6z2Gi/0Gt9Cas57pZmPHQRcvDR5AK9f:71LvGSkzE6Cyi
                            /6as57aPQhKJ
                            PEiD..: InstallShield 2000
                            TrID..: File type identification
                            Win64 Executable Generic (59.6%)
                            Win32 Executable MS Visual C++ (generic) (26.2%)
                            Win32 Executable Generic (5.9%)
                            Win32 Dynamic Link Library (generic) (5.2%)
                            Generic Win/DOS Executable (1.3%)
                            PEInfo: PE Structure information

                            ( base data )
                            entrypointaddress.: 0x3ec0
                            timedatestamp.....: 0x42f311f6 (Fri Aug 05 07:15:02 2005)
                            machinetype.......: 0x14c (I386)

                            ( 4 sections )
                            name viradd virsiz rawdsiz ntrpy md5
                            .text 0x1000 0x8a58 0x9000 6.36 99ca8759ae723d016008c2f3a7d7d23a
                            .rdata 0xa000 0xfa0 0x1000 5.58 3418d87750d21f3d01b61c10cd1a4820
                            .data 0xb000 0x6354 0x3000 1.40 b43014a7200c289d74b8029b5f795de1
                            .rsrc 0x12000 0x3f0 0x1000 1.06 f339f677ece20d4d99e0534307295b31

                            ( 6 imports )
                            > KERNEL32.dll: MapViewOfFile, CreateFileMappingA, GetSystemTime, MultiByteToWideChar, WideCharToMultiByte, UnmapViewOfFile, LoadLibraryA, GetModuleFileNameA, SetFilePointer, FlushFileBuffers, SetStdHandle, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, IsBadCodePtr, IsBadWritePtr, IsBadReadPtr, SetUnhandledExceptionFilter, FindFirstFileA, Sleep, CreateProcessA, CreateMutexA, GetLastError, GetProcAddress, CloseHandle, VirtualAlloc, WriteFile, VirtualFree, HeapCreate, HeapDestroy, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, GetOEMCP, GetACP, GetCPInfo, HeapAlloc, GetCurrentProcess, RtlUnwind, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersion, ExitProcess, HeapFree, TerminateProcess
                            > USER32.dll: TranslateMessage, DispatchMessageA, TranslateAcceleratorA, GetMessageA, LoadAcceleratorsA, RegisterDeviceNotificationA, UnregisterDeviceNotification, RegisterClassExA, CreateWindowExA, DefWindowProcA, SetTimer, MessageBoxA, KillTimer, PostQuitMessage
                            > ADVAPI32.dll: RegOpenKeyA, RegQueryValueExA, RegCloseKey
                            > ole32.dll: CoUninitialize, CoInitialize, CreateBindCtx, CoGetMalloc, MkParseDisplayName, CoCreateInstance
                            > OLEAUT32.dll: -, -
                            > ksproxy.ax: KsSynchronousDeviceControl

                            ( 0 exports )
                            0
                            1. Contributeur sécurité
                              tu fais parcourir

                              Tu trouve le fichier

                              Ouvrir

                              analyze le
                              0
                              1. Je n'arrive pas à faire le "coller sur le site" ni à le taper.
                                0
                                1. Contributeur sécurité
                                  salut

                                  ? Rends toi sur ce site :

                                  https://www.virustotal.com/gui/

                                  C:\WINDOWS\VM305_STI.EXE

                                  ? Copie/colle ceci à gauche (en gras) de " parcourir " :

                                  ? Clique sur Send File.

                                  ? Un rapport va s'élaborer ligne à ligne.

                                  ? Attends la fin. Il doit comprendre la taille du fichier envoyé.

                                  ? Sauvegarde le rapport avec le bloc-note.

                                  ? Copie le dans ta réponse.

                                  (!) Si VirusTotal indique que le fichier a déjà été analysé, cliquer sur le bouton Reanalyser le fichier maintenant
                                  0
                                  1. ca a l'air d'aller, mais j'ai toujours des lignes de hijackthis qui me paraissent douteuses.
                                    Si tu peux jeter un coup d'oeil
                                    merci

                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 08:00:52, on 30/01/2009
                                    Platform: Windows XP SP3 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\csrss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Tall Emu\Online Armor\oasrv.exe
                                    C:\WINDOWS\Explorer.EXE
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    C:\WINDOWS\RTHDCPL.EXE
                                    C:\WINDOWS\system32\RUNDLL32.EXE
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                    C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                                    C:\Program Files\iTunes\iTunesHelper.exe
                                    C:\Program Files\Java\jre6\bin\jusched.exe
                                    C:\WINDOWS\VM305_STI.EXE
                                    C:\Program Files\Tall Emu\Online Armor\oaui.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
                                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    C:\Program Files\Bonjour\mDNSResponder.exe
                                    C:\Program Files\Java\jre6\bin\jqs.exe
                                    C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\WINDOWS\system32\PSIService.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\iPod\bin\iPodService.exe
                                    C:\WINDOWS\system32\wbem\wmiapsrv.exe
                                    C:\WINDOWS\System32\alg.exe
                                    C:\Documents and Settings\Moi\Bureau\SmitfraudFix\Policies.exe
                                    C:\WINDOWS\notepad.exe
                                    C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                                    C:\PROGRA~1\Wanadoo\ComComp.exe
                                    C:\PROGRA~1\Wanadoo\Toaster.exe
                                    C:\PROGRA~1\Wanadoo\Inactivity.exe
                                    C:\PROGRA~1\Wanadoo\PollingModule.exe
                                    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                                    C:\PROGRA~1\Wanadoo\Watch.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    C:\Program Files\Trend Micro\HijackThis\monjack.exe
                                    C:\WINDOWS\system32\wbem\wmiprvse.exe

                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                                    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                                    O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\WINDOWS\RaidTool\xInsIDE.exe
                                    O4 - HKLM\..\Run: [36X Raid Configurer] C:\WINDOWS\system32\xRaidSetup.exe boot
                                    O4 - HKLM\..\Run: [Gainward] C:\Program Files\Vtune\TBPanel.exe /A
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
                                    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                                    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                                    O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera V
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                                    O4 - HKLM\..\Run: [OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
                                    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
                                    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                    O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                                    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                                    O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
                                    O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files\AGI\common\win32\PythonService.exe
                                    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                    O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
                                    O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                                    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                    O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
                                    O23 - Service: Online Armor (SvcOnlineArmor) - Tall Emu - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
                                    0
                                    1. Contributeur sécurité
                                      Salut

                                      Comment va le pc ?? encore des problème ??
                                      0
                                      • 1
                                      • 2
                                      • 3