Fichiers caché

Bonjour, voila j'ai mis mon disque dur externe chez un ami et j'ai eu un virus qui a rendu tous les fichiers en caché j'ai enlevé le virus mais voici le probleme:
http://img222.imageshack.us/img222/1074/cach.jpg

merci d'avance
Configuration: Windows Vista
Firefox 3.0.7
HD4870
core 2 duo E6550
4Go de Ram ddr2 800mhz

26 réponses

Résumé de la discussion

Un virus a rendu les fichiers du disque dur externe invisibles, et après sa suppression, l’utilisateur fait face à des fichiers marqués comme cachés sur Windows Vista. Des réponses préconisent des outils de sécurité comme RSIT et HijackThis pour diagnostiquer les infections et récupérer les logs utiles, notamment log.txt et info.txt. L’outline des procédures inclut le téléchargement et l’exécution de RSIT, la collecte des informations système et la remise des rapports dans le dossier C:\rsit pour analyse. En complément, l’ensemble des éléments affichés dans les logs, notamment les programmes désinstallés et les détails d’authentification, peut aider à évaluer l’impact réel et les actions à prévoir.

Bobot (l’IA à votre service)
  1. ========== FILES ==========
    File/Folder C:\Windows\system32\xxyvvsrO.dll not found.
    File/Folder C:\Windows\system32\cbXPjjHX.dll not found.
    File/Folder C:\Windows\system32\cbXRLeEx.dll not found.
    File/Folder C:\Windows\SysWow64\qoMeDtuT.dll not found.
    File/Folder C:\\Windows\\system32\\xxyvvsrO not found.
    ========== REGISTRY ==========
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Explorer\ShellExecuteHooks not found.

    OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03212009_143212

    ############################## [ FindyKill V4.720 ]

    # User : ABduX (Administrateurs) # PC-DE-ABDUX
    # Update on 19/03/09 by Chiquitine29
    # Start at: 14:34:16 | 21/03/2009

    # Intel(R) Core(TM)2 Duo CPU E6550 @ 2.33GHz
    # Microsoft® Windows Vista™ Édition Intégrale (6.0.6001 64-bit) # Service Pack 1
    # Internet Explorer 7.0.6001.18000
    # Windows Firewall Status : Disabled
    # AV : Kaspersky Internet Security 7.0.0.125 [ (!) Disabled | Updated ]
    # FW : Kaspersky Internet Security[ Enabled ]7.0.0.125

    # A:\ # Lecteur de disquettes 3 ½ pouces
    # C:\ # Disque fixe local # 41,69 Go (14,81 Go free) # NTFS
    # D:\ # Disque fixe local # 107,34 Go (1,19 Go free) # NTFS
    # E:\ # Disque fixe local # 149,05 Go (1,89 Go free) [ABduX] # NTFS
    # G:\ # Disque CD-ROM

    ############################## [ Processus actifs ]

    D:\Windows.old\Program Files\BitLord\BitLord.exe
    C:\Program Files (x86)\Internet Download Manager\IDMan.exe
    C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
    C:\Program Files (x86)\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
    C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
    C:\Program Files (x86)\Skype\Phone\Skype.exe
    C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Winamp\winamp.exe
    C:\Program Files (x86)\MyPhoneExplorer\MyPhoneExplorer.exe
    C:\Program Files (x86)\Google\Google Talk\googletalk.exe
    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files (x86)\MessengerDiscovery\MessengerDiscovery Live.exe
    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe

    ################## [ Fichiers / Dossiers infectieux C:\ ]

    ################## [ C:\Windows ]

    ################## [ C:\Windows\system32 ]

    ################## [ C:\Windows\system32\drivers ]

    ################## [ C:\.. Application Data ... ]

    ################## [ Registre / Clés infectieuses ]

    ################## [ Recherche dans supports amovibles]

    # Presence des fichiers :

    ################## [ Registre / Mountpoint2 ]

    # -> Not found !

    ################## [ ! Fin du rapport # FindyKill V4.720 ! ]
    1. Contributeur sécurité
      double-clique sur OTMoveIt.exe pour le lancer.
      copie la liste qui se trouve en citation ci-dessous,
      et colle-la dans le cadre de gauche de OTMoveIt :Paste List of Files/Folders to be moved.

      :files
      C:\Windows\system32\xxyvvsrO.dll
      C:\Windows\system32\cbXPjjHX.dll
      C:\Windows\system32\cbXRLeEx.dll
      C:\Windows\SysWow64\qoMeDtuT.dll
      C:\\Windows\\system32\\xxyvvsrO
      :reg
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
      "{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=-

      clique sur MoveIt! pour lancer la suppression.
      le résultat apparaitra dans le cadre "Results".
      clique sur Exit pour fermer.
      poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

      il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

      ____________________________

      Telecharge FindyKill sur ton bureau :

      --> http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

      --> Lance l installation avec les parametres par default

      --> Double clic sur le raccourci FindyKill sur ton bureau

      --> Au menu principal,choisi l option 1 (Recherche)

      --> Post le rapport FindyKill.txt

      Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
      1. Contributeur sécurité
        Télécharge RavAntivirus d'Evosla :
        http://ww25.evosla.com/compteur.php?soft=rav_antivirus

        # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
        # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
        # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
        # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
        # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
        # Retire tes disques amovibles et redémarrez votre ordinateur.
        # Poste le rapport, si infection!

        2/ Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe

        Double-clique sur l’icône.
        Les icônes vont disparaître. C’est normal.
        Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau, et poste le ensuite
        Redémarre ensuite le PC.
        1. là je ne vois meme plus les fichiers je ne peux les voir qu'avec winrar :s c'est trop bizzar tout ça
          1. Contributeur sécurité
            essaye sur les fichiers en quaestion de cliquer avec le bouton droit de la souris puis tu choisi proritété puis PARTAGE puis décoche caché et dans PARTAGE décoche rendre le dossier confidentiel
            1. euh je peux changer tout les fichier sof ces fichiers qui ont était touché par le virus
              1. Contributeur sécurité
                sous vista 64 combofix ne marche pas c'est bien dommage!

                essaye de reparer vista:
                http://www.vista-xp.fr/forum/topic428.html
                1. euuh kaspersky a enlevé tous les virus le seul problème c'est que je ne peux pas rendre les fishier en mode normal on dirait des fichiers system on ne peux leur enlevé le mode cacher
                  1. Logfile of random's system information tool 1.05 (written by random/random)
                    Run by ABduX at 2009-03-16 12:36:47
                    Microsoft® Windows Vista™ Édition Intégrale Service Pack 1
                    System drive C: has 13 GB (31%) free of 43 GB
                    Total RAM: 4094 MB (40% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 12:36:50, on 16/03/2009
                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                    Boot mode: Normal

                    Running processes:
                    C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
                    C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
                    D:\Windows.old\Program Files\BitLord\BitLord.exe
                    C:\Program Files (x86)\Internet Download Manager\IDMan.exe
                    C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
                    C:\Program Files (x86)\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                    C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
                    C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
                    C:\Program Files (x86)\Skype\Phone\Skype.exe
                    C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
                    C:\Users\ABduX\AppData\Local\eSupport.com\driveragent_270.exe
                    C:\Program Files (x86)\Frigate3\Frigate3.exe
                    E:\Steam\Steam.exe
                    E:\SBReV\SBReV.exe
                    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
                    C:\Users\ABduX\Desktop\RSIT.exe
                    C:\Program Files (x86)\trend micro\ABduX.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    O1 - Hosts: ::1 localhost
                    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                    O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                    O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files (x86)\Windows Live\Family Safety\fssbho.dll
                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
                    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files (x86)\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                    O4 - HKLM\..\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
                    O4 - HKCU\..\Run: [BitComet] "D:\Windows.old\Program Files\BitLord\BitLord.exe"
                    O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MI1933~1\Office12\EXCEL.EXE/3000
                    O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
                    O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
                    O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
                    O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
                    O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MI1933~1\Office12\REFIEBAR.DLL
                    O13 - Gopher Prefix:
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{45968CB4-5885-48B3-BFCF-A278BB7EF597}: NameServer = 192.168.10.31
                    O17 - HKLM\System\CS1\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
                    O17 - HKLM\System\CS2\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
                    O20 - AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0\adialhk.dll
                    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
                    O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
                    O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                    O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
                    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
                    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
                    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
                    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                    O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
                    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
                    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
                    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
                    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
                    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
                    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
                    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
                    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
                    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
                    1. ========== FILES ==========
                      File/Folder F:\lkwh.cmd not found.
                      File/Folder C:\Windows\SysWow64\qoMeDtuT.dll not found.
                      ========== REGISTRY ==========
                      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Explorer\ShellExecuteHooks not found.
                      Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2eeebd61-0e56-11de-8f52-000000000000}\\ deleted successfully.
                      ========== COMMANDS ==========
                      File delete failed. C:\Users\ABduX\AppData\Local\Temp\etilqs_78OTACeecc7fR7GAv6A3 scheduled to be deleted on reboot.
                      File delete failed. C:\Users\ABduX\AppData\Local\Temp\etilqs_yaQvBNwGQQM0knovgIee scheduled to be deleted on reboot.
                      File delete failed. C:\Users\ABduX\AppData\Local\Temp\etilqs_yaQvBNwGQQM0knovgIee-journal scheduled to be deleted on reboot.
                      File delete failed. C:\Users\ABduX\AppData\Local\Temp\FXSAPIDebugLogFile.txt scheduled to be deleted on reboot.
                      User's Temp folder emptied.
                      User's Temporary Internet Files folder emptied.
                      User's Internet Explorer cache folder emptied.
                      Local Service Temp folder emptied.
                      Local Service Temporary Internet Files folder emptied.
                      File delete failed. C:\Windows\temp\cch~20f631620.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~20f632c99.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~2100548e6.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~210056059.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~2122be281.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~2122bfa07.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~212317e08.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~21231a243.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~21521c112.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~21521d7d0.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~21523134a.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~2152329b3.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~215252393.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~215253a97.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~21525b32b.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~21525c993.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~215266569.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~215267c1b.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~21527cf4a.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~21527f092.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~21528c38b.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~21528d9ec.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~2152ae78e.htp scheduled to be deleted on reboot.
                      File delete failed. C:\Windows\temp\cch~2152b096f.htp scheduled to be deleted on reboot.
                      Windows Temp folder emptied.
                      File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\OfflineCache\index.sqlite scheduled to be deleted on reboot.
                      File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                      File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                      File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                      File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                      File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                      File delete failed. C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\XUL.mfl scheduled to be deleted on reboot.
                      FireFox cache emptied.
                      Temp folders emptied.
                      Explorer started successfully

                      OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03152009_161209

                      Files moved on Reboot...
                      File C:\Users\ABduX\AppData\Local\Temp\etilqs_78OTACeecc7fR7GAv6A3 not found!
                      File C:\Users\ABduX\AppData\Local\Temp\etilqs_yaQvBNwGQQM0knovgIee not found!
                      File C:\Users\ABduX\AppData\Local\Temp\etilqs_yaQvBNwGQQM0knovgIee-journal not found!
                      C:\Users\ABduX\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
                      File C:\Windows\temp\cch~20f631620.htp not found!
                      File C:\Windows\temp\cch~20f632c99.htp not found!
                      File C:\Windows\temp\cch~2100548e6.htp not found!
                      File C:\Windows\temp\cch~210056059.htp not found!
                      File C:\Windows\temp\cch~2122be281.htp not found!
                      File C:\Windows\temp\cch~2122bfa07.htp not found!
                      File C:\Windows\temp\cch~212317e08.htp not found!
                      File C:\Windows\temp\cch~21231a243.htp not found!
                      File C:\Windows\temp\cch~21521c112.htp not found!
                      File C:\Windows\temp\cch~21521d7d0.htp not found!
                      File C:\Windows\temp\cch~21523134a.htp not found!
                      File C:\Windows\temp\cch~2152329b3.htp not found!
                      File C:\Windows\temp\cch~215252393.htp not found!
                      File C:\Windows\temp\cch~215253a97.htp not found!
                      File C:\Windows\temp\cch~21525b32b.htp not found!
                      File C:\Windows\temp\cch~21525c993.htp not found!
                      File C:\Windows\temp\cch~215266569.htp not found!
                      File C:\Windows\temp\cch~215267c1b.htp not found!
                      File C:\Windows\temp\cch~21527cf4a.htp not found!
                      File C:\Windows\temp\cch~21527f092.htp not found!
                      File C:\Windows\temp\cch~21528c38b.htp not found!
                      File C:\Windows\temp\cch~21528d9ec.htp not found!
                      File C:\Windows\temp\cch~2152ae78e.htp not found!
                      File C:\Windows\temp\cch~2152b096f.htp not found!
                      C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\OfflineCache\index.sqlite moved successfully.
                      C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_001_ moved successfully.
                      C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_002_ moved successfully.
                      C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_003_ moved successfully.
                      C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\Cache\_CACHE_MAP_ moved successfully.
                      C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\urlclassifier3.sqlite moved successfully.
                      C:\Users\ABduX\AppData\Local\Mozilla\Firefox\Profiles\3blh0ht2.default\XUL.mfl moved successfully.
                      1. Contributeur sécurité
                        ok branche le disque F

                        puis

                        télécharge OTMoveIt
                        http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

                        double-clique sur OTMoveIt.exe pour le lancer.
                        copie la liste qui se trouve en citation ci-dessous,
                        et colle-la dans le cadre de gauche de OTMoveIt :Paste instruction for items to be moved.
                        (attention bien mettre :files)

                        :files
                        F:\lkwh.cmd
                        C:\Windows\SysWow64\qoMeDtuT.dll
                        :reg
                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                        "{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=-
                        [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2eeebd61-0e56-11de-8f52-000000000000}]
                        :commands
                        [purity]
                        [emptytemp]
                        [start explorer]

                        clique sur MoveIt! pour lancer la suppression.
                        le résultat apparaitra dans le cadre "Results".
                        clique sur Exit pour fermer.
                        poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

                        il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.
                        1. http://img502.imageshack.us/img502/9899/erreurs.jpg

                          voici une foto de l'erreur que jai quand je lance le premier truc en fesant ce que vous mavez demandé

                          2:
                          votre ordinateur est sain
                          1. Contributeur sécurité
                            Pour fusionner:

                            http://img.photobucket.com/albums/v666/sUBs/CFScript.gif

                            _______________

                            telecharge combofix:

                            http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                            Sauvegarde le sur ton bureau et pas ailleurs !

                            _________________

                            branche le disqpue F

                            puis

                            Ferme tous tes navigateurs (donc copie ou imprime les instructions avant)

                            Crée un nouveau document texte : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes :

                            File::
                            F:\lkwh.cmd
                            C:\Windows\SysWow64\qoMeDtuT.dll
                            Registry::
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                            "{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}"=-
                            [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2eeebd61-0e56-11de-8f52-000000000000}]

                            Enregistre ce fichier sous le nom CFscript

                            Fait un glisser/déposer de ce fichier CFscrïpt sur le fichier ComboFix.exe

                            Clique sur le fichier CFScript, maintient le doigt enfoncé et glisse la souris pour que l'icône du CFScript vienne recouvrir l'icône de Combofix. Relache la souris. Combofix va démarrer.

                            Une fenêtre bleue va apparaître: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.

                            Patiente le temps du scan.Le bureau va disparaître à plusieurs reprises: c'est normal!

                            Ne touche à rien tant que le scan n'est pas terminé.

                            Une fois le scan achevé, un rapport va s'afficher: poste son contenu.

                            Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                            __________

                            Télécharge RavAntivirus d'Evosla :
                            http://ww25.evosla.com/compteur.php?soft=rav_antivirus

                            # Si tu as une clé USB, disque dur externe, etc, branche-les sans les ouvrir avant de lancer ce FIX
                            # Fais un clic droit sur le fichier .ZIP > Extraire sur > le Bureau
                            # Doucle-clique sur >> RAV.exe << afin de lancer l'outil.
                            # Une fois RAV ANTIVIRUS lancé, laisse-le réagir , il scanne automatiquement tout les lecteurs (disques fixes et amovibles)
                            # Si infection > un log s'établira, sinon le soft affichera (très rapide) ==>Votre Ordinateur est sain .
                            # Retire tes disques amovibles et redémarrez votre ordinateur.
                            # Poste le rapport, si infection!

                            2/ Télécharge sur le bureau Flash Disinfector (de SUBS) à cette adresse : http://www.techsupportforum.com/sectools/sUBs/Flash_Disinfector.exe

                            Double-clique sur l’icône.
                            Les icônes vont disparaître. C’est normal.
                            Si un rapport est généré en cas d'infection, sauvegarde-le sur le bureau, et poste le ensuite
                            Redémarre ensuite le PC.
                            1. ========== FILES ==========
                              DllUnregisterServer procedure not found in C:\Windows\system32\xxyvvsrO.dll
                              C:\Windows\system32\xxyvvsrO.dll NOT unregistered.
                              C:\Windows\system32\xxyvvsrO.dll moved successfully.
                              DllUnregisterServer procedure not found in C:\Windows\system32\cbXPjjHX.dll
                              C:\Windows\system32\cbXPjjHX.dll NOT unregistered.
                              C:\Windows\system32\cbXPjjHX.dll moved successfully.
                              DllUnregisterServer procedure not found in C:\Windows\system32\cbXRLeEx.dll
                              C:\Windows\system32\cbXRLeEx.dll NOT unregistered.
                              C:\Windows\system32\cbXRLeEx.dll moved successfully.
                              File/Folder F:\lkwh.cmd not found.
                              ========== REGISTRY ==========
                              Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversio­­n\explorer\mountpoints2\{2eeebd61-0e56-11de-8f52-0000000000­0­0}\\ not found.

                              OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 03132009_082348

                              RSIT :

                              log :
                              Logfile of random's system information tool 1.05 (written by random/random)
                              Run by ABduX at 2009-03-13 21:37:46
                              Microsoft® Windows Vista™ Édition Intégrale Service Pack 1
                              System drive C: has 17 GB (40%) free of 43 GB
                              Total RAM: 4094 MB (55% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 21:38:31, on 13/03/2009
                              Platform: Windows Vista SP1 (WinNT 6.00.1905)
                              MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                              Boot mode: Normal

                              Running processes:
                              C:\Program Files (x86)\Windows Live\Family Safety\fsui.exe
                              C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
                              D:\Windows.old\Program Files\BitLord\BitLord.exe
                              C:\Program Files (x86)\Internet Download Manager\IDMan.exe
                              C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                              C:\Program Files (x86)\Common Files\Teleca Shared\Generic.exe
                              C:\Program Files (x86)\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
                              C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
                              C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
                              E:\Program Files\Steam\steam.exe
                              C:\Program Files (x86)\Hamachi\hamachi.exe
                              C:\Windows\SysWOW64\conime.exe
                              C:\Program Files (x86)\Skype\Phone\Skype.exe
                              C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
                              C:\Program Files (x86)\Mozilla Firefox\firefox.exe
                              C:\Users\ABduX\Documents\Downloads\Programs\RSIT.exe
                              C:\Program Files (x86)\trend micro\ABduX.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              F2 - REG:system.ini: UserInit=userinit.exe
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll
                              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                              O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                              O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files (x86)\Windows Live\Family Safety\fssbho.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O4 - HKLM\..\Run: [AVP] "C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
                              O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
                              O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files (x86)\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                              O4 - HKLM\..\Run: [googletalk] "C:\Program Files (x86)\Google\Google Talk\googletalk.exe" /autostart
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
                              O4 - HKCU\..\Run: [BitComet] "D:\Windows.old\Program Files\BitLord\BitLord.exe"
                              O4 - HKCU\..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MI1933~1\Office12\EXCEL.EXE/3000
                              O8 - Extra context menu item: Télécharger avec IDM - C:\Program Files (x86)\Internet Download Manager\IEExt.htm
                              O8 - Extra context menu item: Télécharger le contenu de video FLV avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetVL.htm
                              O8 - Extra context menu item: Télécharger tous les liens avec IDM - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm
                              O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
                              O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MI1933~1\Office12\REFIEBAR.DLL
                              O13 - Gopher Prefix:
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
                              O17 - HKLM\System\CCS\Services\Tcpip\..\{45968CB4-5885-48B3-BFCF-A278BB7EF597}: NameServer = 192.168.10.31
                              O17 - HKLM\System\CS1\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
                              O17 - HKLM\System\CS2\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
                              O17 - HKLM\System\CS13\Services\Tcpip\..\{11259140-E2B0-4DBE-9305-9439EB4440BD}: NameServer = 41.221.20.4 193.251.169.165
                              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
                              O20 - AppInit_DLLs: C:\PROGRA~2\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~2\KASPER~1\KASPER~1.0\adialhk.dll
                              O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
                              O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
                              O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                              O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
                              O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
                              O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                              O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
                              O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                              O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                              O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
                              O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
                              O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
                              O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
                              O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
                              O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
                              O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
                              O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
                              O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
                              O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
                              O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
                              O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
                              1. Contributeur sécurité
                                vire ce qui est dans moved files en allant dans poste de travail puis C puis otmovit

                                _______________

                                remets un rapport RSIT
                                • 1
                                • 2