Rapport RSIT

Résolu
Bonsoir,

Voila 2 rapports que j'ai fait avec RSIT pour voir si j'étais infecter par des rootkits:
Mais je ne sais pas les lire....

Logfile of random's system information tool 1.06 (written by random/random)
Run by kevin at 2009-08-23 20:25:19
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 2
System drive C: has 75 GB (66%) free of 115 GB
Total RAM: 3066 MB (64% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:25:46, on 23/08/2009
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\kevin\Desktop\RSIT.exe
C:\Program Files\trend micro\kevin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {9DF1C00D-8426-4337-972C-DC042D19A916} (FTMediaPlayer Class) - http://webtv.guidetv.orange.fr/resources/OCS_8971.cab
O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Service Google Update (gupdate1c9cb387e2085a7) (gupdate1c9cb387e2085a7) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe

--
End of file - 6508 bytes

======Scheduled tasks folder======

C:\Windows\tasks\GlaryInitialize.job
C:\Windows\tasks\Google Software Updater.job
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\User_Feed_Synchronization-{4FEB54DB-9D61-49A8-AB33-2D3870B644B6}.job

======Registry dump======

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre6\bin\ssv.dll [2009-07-25 321312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-06-14 668656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-25 41760]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-04-17 6111232]
"SynTPEnh"=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2007-10-26 1029416]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-07-26 13548064]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-07-26 92704]
"avgnt"=C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [2009-03-02 209153]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-25 149280]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2009-04-11 1233920]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-21 125952]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AGEIA PhysX SysTray]
C:\Program Files\AGEIA Technologies\TrayIcon.exe [2006-03-20 331776]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe []

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LightScribe Control Panel]
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2007-06-20 451872]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ORAHSSSessionManager]
C:\Program Files\OrangeHSS\SessionManager\SessionManager.exe [2008-06-10 107248]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-25 149280]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\XboxStat]
C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [2007-09-27 734264]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^BTTray.lnk]
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTTray.exe [2008-02-12 723496]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^kevin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk]
C:\PROGRA~1\OPENOF~1.ORG\program\QUICKS~1.EXE [2008-12-15 384000]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Users^kevin^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Registration Ghost Recon Advanced Warfighter.LNK]
C:\PROGRA~1\Ubisoft\GHOSTR~1\Support\Register\REGIST~1.EXE [2005-05-24 868352]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"EnableLUA"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe"="C:\Program Files\OrangeHSS\Connectivity\ConnectivityManager.exe:*:enabled:CSS"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{108cf705-3194-11de-b199-001377b6d3c3}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL kevin.ExE

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{dff01912-5d15-11de-9542-001377b6d3c3}]
shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL USER.exE

======File associations======

.js - edit - C:\Windows\System32\Notepad.exe %1
.js - open - C:\Windows\System32\WScript.exe "%1" %*

======List of files/folders created in the last 1 months======

2009-08-23 20:25:19 ----D---- C:\rsit
2009-08-23 20:25:19 ----D---- C:\Program Files\trend micro
2009-08-23 13:38:51 ----A---- C:\Windows\system32\javaws.exe
2009-08-23 13:38:51 ----A---- C:\Windows\system32\javaw.exe
2009-08-23 13:38:51 ----A---- C:\Windows\system32\java.exe
2009-08-20 17:55:29 ----A---- C:\Windows\ntbtlog.txt
2009-08-16 23:14:17 ----D---- C:\Users\kevin\AppData\Roaming\DeepBurner
2009-08-16 23:14:07 ----D---- C:\Program Files\Astonsoft
2009-08-15 19:36:46 ----D---- C:\ProgramData\LightScribe
2009-08-15 19:36:06 ----D---- C:\Program Files\Common Files\LightScribe
2009-08-15 19:32:08 ----D---- C:\Users\kevin\AppData\Roaming\Ahead
2009-08-15 19:26:52 ----D---- C:\ProgramData\Nero
2009-08-15 19:26:52 ----D---- C:\Program Files\Nero
2009-08-15 19:26:52 ----D---- C:\Program Files\Common Files\Ahead
2009-08-12 17:53:59 ----D---- C:\Program Files\Orange
2009-08-12 17:31:36 ----A---- C:\Windows\system32\wdigest.dll
2009-08-12 17:31:36 ----A---- C:\Windows\system32\schannel.dll
2009-08-12 17:31:36 ----A---- C:\Windows\system32\msv1_0.dll
2009-08-12 17:31:36 ----A---- C:\Windows\system32\kerberos.dll
2009-08-12 17:31:35 ----A---- C:\Windows\system32\secur32.dll
2009-08-12 17:31:35 ----A---- C:\Windows\system32\lsass.exe
2009-08-12 17:31:35 ----A---- C:\Windows\system32\lsasrv.dll
2009-08-12 17:31:26 ----A---- C:\Windows\system32\wmp.dll
2009-08-12 17:31:25 ----A---- C:\Windows\system32\wmpdxm.dll
2009-08-12 17:31:24 ----A---- C:\Windows\system32\wmploc.DLL
2009-08-12 17:31:24 ----A---- C:\Windows\system32\spwmp.dll
2009-08-12 17:31:24 ----A---- C:\Windows\system32\dxmasf.dll
2009-08-12 17:31:22 ----A---- C:\Windows\system32\mstscax.dll
2009-08-12 17:31:21 ----A---- C:\Windows\system32\avifil32.dll
2009-08-12 17:31:20 ----A---- C:\Windows\system32\wkssvc.dll
2009-08-12 17:31:19 ----A---- C:\Windows\system32\atl.dll
2009-08-11 12:47:49 ----D---- C:\Program Files\Securitoo
2009-08-11 12:47:09 ----A---- C:\Windows\system32\Autodial2000.dll
2009-08-11 12:46:59 ----D---- C:\Program Files\OrangeHSS
2009-08-11 12:44:09 ----D---- C:\Program Files\Common Files\France Telecom
2009-08-11 12:44:09 ----A---- C:\Windows\system32\MFC71.dll
2009-08-11 12:44:09 ----A---- C:\Windows\system32\atl71.dll
2009-08-09 12:55:57 ----D---- C:\Program Files\CCleaner
2009-08-09 12:25:40 ----D---- C:\Users\kevin\AppData\Roaming\InstallShield
2009-08-07 18:19:02 ----D---- C:\Program Files\Glary Utilities
2009-08-07 18:02:23 ----A---- C:\Windows\system32\mshtml.dll
2009-08-07 18:02:22 ----A---- C:\Windows\system32\iertutil.dll
2009-08-07 18:02:22 ----A---- C:\Windows\system32\ieframe.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\wininet.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\urlmon.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\occache.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\msfeedssync.exe
2009-08-07 18:02:21 ----A---- C:\Windows\system32\msfeedsbs.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\msfeeds.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\jsproxy.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\ieUnatt.exe
2009-08-07 18:02:21 ----A---- C:\Windows\system32\ieui.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\iesysprep.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\iesetup.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\iernonce.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\iepeers.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\iedkcs32.dll
2009-08-07 18:02:21 ----A---- C:\Windows\system32\ie4uinit.exe
2009-08-03 16:43:11 ----D---- C:\Program Files\EA GAMES
2009-07-31 13:09:51 ----D---- C:\Program Files\Microsoft Xbox 360 Accessories

======List of files/folders modified in the last 1 months======

2009-08-23 20:25:26 ----D---- C:\Windows\Temp
2009-08-23 20:25:19 ----RD---- C:\Program Files
2009-08-23 20:02:50 ----D---- C:\Windows\System32
2009-08-23 20:02:50 ----D---- C:\Windows\inf
2009-08-23 20:02:50 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-08-23 15:57:45 ----D---- C:\Windows\Tasks
2009-08-23 13:48:09 ----D---- C:\Windows\Prefetch
2009-08-23 13:46:07 ----SHD---- C:\Windows\Installer
2009-08-23 13:40:49 ----D---- C:\Program Files\Java
2009-08-23 13:40:49 ----D---- C:\Program Files\Common Files
2009-08-23 13:40:08 ----SHD---- C:\System Volume Information
2009-08-23 00:27:16 ----D---- C:\ProgramData\Google Updater
2009-08-22 01:24:20 ----D---- C:\Windows
2009-08-21 21:01:39 ----D---- C:\Users\kevin\AppData\Roaming\dvdcss
2009-08-20 17:55:58 ----D---- C:\ProgramData\Spybot - Search & Destroy
2009-08-17 17:07:12 ----D---- C:\Windows\system32\catroot2
2009-08-16 12:31:46 ----D---- C:\Program Files\Mozilla Firefox
2009-08-16 12:27:02 ----D---- C:\Windows\ehome
2009-08-15 19:36:46 ----HD---- C:\ProgramData
2009-08-14 12:29:51 ----SHD---- C:\Boot
2009-08-14 12:29:50 ----D---- C:\Windows\system32\config
2009-08-14 12:16:06 ----D---- C:\Windows\Debug
2009-08-12 17:55:32 ----SD---- C:\Windows\Downloaded Program Files
2009-08-12 17:46:50 ----D---- C:\Windows\winsxs
2009-08-12 17:34:31 ----D---- C:\Windows\system32\drivers
2009-08-12 17:34:31 ----D---- C:\Program Files\Windows Media Player
2009-08-12 17:33:39 ----D---- C:\Windows\system32\catroot
2009-08-12 17:33:35 ----D---- C:\Program Files\Windows Mail
2009-08-09 12:26:09 ----D---- C:\Windows\VMC302
2009-08-09 12:25:49 ----HD---- C:\Program Files\InstallShield Installation Information
2009-08-09 12:05:51 ----D---- C:\Windows\system32\Tasks
2009-08-08 17:30:37 ----D---- C:\Windows\system32\WDI
2009-08-07 18:08:57 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-08-07 18:07:01 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-08-07 18:04:31 ----D---- C:\Program Files\Microsoft Silverlight
2009-08-07 18:03:33 ----D---- C:\Windows\system32\migration
2009-08-07 18:03:33 ----D---- C:\Program Files\Internet Explorer
2009-08-03 16:41:45 ----D---- C:\Program Files\Common Files\InstallShield
2009-07-30 02:49:14 ----A---- C:\Windows\system32\mrt.exe
2009-07-25 05:23:00 ----A---- C:\Windows\system32\deploytk.dll

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir Desktop\avgio.sys [2009-02-13 11608]
R1 avipbb;avipbb; C:\Windows\system32\DRIVERS\avipbb.sys [2009-03-30 96104]
R1 ssmdrv;ssmdrv; C:\Windows\system32\DRIVERS\ssmdrv.sys [2009-07-13 28520]
R2 avgntflt;avgntflt; C:\Windows\system32\DRIVERS\avgntflt.sys [2009-08-18 55656]
R2 KMDFMEMIO;SAMSUNG Kernel Driver; C:\Windows\system32\DRIVERS\kmdfmemio.sys [2008-09-12 13312]
R3 CmBatt;Pilote pour Batterie à méthode de contrôle ACPI Microsoft; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-04-17 2098904]
R3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw5v32.sys [2008-09-25 3666432]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2009-06-26 66080]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-07-26 7548000]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-10-26 193456]
R3 VMC302;Vimicro Camera Service VMC302; C:\Windows\System32\Drivers\VMC302.sys [2009-01-23 243840]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2007-12-28 298496]
S3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\AGRSM.sys [2006-11-28 1161888]
S3 bcm4sbxp;Broadcom 440x 10/100 Integrated Controller XP Driver; C:\Windows\system32\DRIVERS\bcm4sbxp.sys [2006-11-02 45056]
S3 BthEnum;Pilote de bloc de demande Bluetooth; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-01-21 19456]
S3 BthPan;Périphérique Bluetooth (réseau personnel); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Pilote de port Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2008-04-29 220160]
S3 BTHUSB;Pilote USB radio Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-29 29184]
S3 btwaudio;Périphérique audio Bluetooth; C:\Windows\system32\drivers\btwaudio.sys [2008-02-14 80424]
S3 btwavdt;Bluetooth AVDT; C:\Windows\system32\drivers\btwavdt.sys [2007-07-16 80936]
S3 btwrchid;btwrchid; C:\Windows\system32\DRIVERS\btwrchid.sys [2007-07-16 16168]
S3 drmkaud;Filtre de décodeur DRM (Noyau Microsoft); C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Pilote de fonction UAA 1.1 Microsoft pour le service High Definition Audio; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 ialm;ialm; C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-10-19 1380864]
S3 MSKSSRV;Proxy de service de répartition Microsoft; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Proxy d'horloge de répartition Microsoft; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Proxy de gestion de qualité de répartition Microsoft; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Convertisseur en T/site-à-site de répartition Microsoft; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NETw3v32;Intel(R) PRO/Wireless 3945ABG Adapter Driver for Windows Vista 32 Bit; C:\Windows\system32\DRIVERS\NETw3v32.sys [2008-01-21 2225664]
S3 PCAMp50;PCAMp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCAMp50.sys [2006-11-28 28224]
S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\PCASp50.sys [2006-11-28 27072]
S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-02-21 50688]
S3 RTL8187B;TG123g USB Wireless Adapter; C:\Windows\system32\DRIVERS\RTL8187B.sys [2007-07-18 281088]
S3 USB_RNDIS;Inventel Gateway; C:\Windows\system32\DRIVERS\usb8023.sys [2009-04-11 15872]
S3 usbbus;LGE Mobile Composite USB Device; C:\Windows\system32\DRIVERS\lgusbbus.sys []
S3 UsbDiag;LGE Mobile USB Serial Port; C:\Windows\system32\DRIVERS\lgusbdiag.sys []
S3 USBModem;LGE Mobile USB Modem; C:\Windows\system32\DRIVERS\lgusbmodem.sys []
S3 usbvideo;Périphérique vidéo USB (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 xnacc;Contrôleur XBOX 360 pour le service de pilote Windows; C:\Windows\system32\DRIVERS\xnacc.sys [2008-01-21 521216]
S3 xusb21;Xbox 360 Wireless Receiver Driver Service 21; C:\Windows\system32\DRIVERS\xusb21.sys [2007-02-27 61984]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2008-01-21 11264]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R2 AntiVirSchedulerService;Avira AntiVir Planificateur; C:\Program Files\Avira\AntiVir Desktop\sched.exe [2009-07-13 108289]
R2 AntiVirService;Avira AntiVir Guard; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [2009-08-18 185089]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 FTRTSVC;France Telecom Routing Table Service; C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [2008-06-20 65536]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-06-28 79136]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-07-26 196608]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S2 gupdate1c9cb387e2085a7;Service Google Update (gupdate1c9cb387e2085a7); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-05-02 133104]
S2 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-06-14 183280]
S2 SQLWriter;Enregistreur VSS SQL Server; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe []

-----------------EOF-----------------
Configuration: Windows Vista home prenium SP1
Intel Core 2 Duo 2Ghz 4Go RAM
Nvidia Geforce 9600M GT

21 réponses

  1. [ Rapport ToolsCleaner version 2.3.10 (par A.Rothstein & dj QUIOU) ]

    --> Recherche:

    C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\UsbFix: trouvé !
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UsbFix: trouvé !
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programmes\UsbFix: trouvé !
    C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\UsbFix: trouvé !
    C:\Users\kevin\AppData\Local\VirtualStore\Program Files\Trend Micro\hijackthis.log: trouvé !
    C:\Users\kevin\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: trouvé !
    C:\Users\kevin\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
    C:\Users\kevin\Desktop\Logiciel-Setup\HJTInstall.exe: trouvé !
    C:\Users\kevin\Desktop\Logiciel-Setup\UsbFix.exe: trouvé !

    ---------------------------------
    --> Suppression:

    C:\Users\kevin\Desktop\Logiciel-Setup\HJTInstall.exe: supprimé !
    C:\Users\kevin\AppData\Local\VirtualStore\Program Files\Trend Micro\hijackthis.log: supprimé !
    C:\Users\kevin\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
    C:\Users\kevin\Desktop\Logiciel-Setup\UsbFix.exe: supprimé !
    C:\ProgramData\Microsoft\Windows\Start Menu\Programmes\UsbFix: ERREUR DE SUPPRESSION !!
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UsbFix: supprimé !
    C:\Users\kevin\AppData\Local\VirtualStore\Program Files\Trend Micro\HijackThis: supprimé !

    Point de restauration crée !
    Fichiers temporaires nettoyés !
    0
    1. Contributeur sécurité
      Bonjour,

      tu peux faire ceci pour terminer :

      Voici un excellent petit logiciel très utile qui te permettra de savoir les nouvelles mises à jour disponibles pour les différents logiciels installés sur ton PC :

      ▶ Télécharge Update Checker

      ▶ Installe le avec les paramètres par défaut en cliquant chaques fois sur Suivant.

      ▶ Une fois installé, patiente quelques secondes et tu verras apparaître une icône verte dans ta barre des tâches te signalant qu'il y a des mises à jour disponibles.

      ▶ Double-cliques sur l'icône pour être redirrigé sur le site de téléchargement des mises à jour.

      Un conseil : n'installe pas les BETA qui sont listées en dessous.

      ▶ Tu installes les mises à jour que tu désires, les plus importantes sont :

      ● Java

      ● Adobe Reader

      ● Adobe Flash Player

      ● Internet explorer

      Ensuite :

      Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

      ▶ Clique sur Démarrer puis sur panneau de configuration
      ▶ Double Clique sur l'icône "Comptes d'utilisateurs"
      ▶ Clique ensuite sur désactiver et valide.
      ▶ Redémarre le PC.

      Pour supprimer toutes les traces des logiciels qui ont servi à traiter les infections spécifiques :

      ▶ Télécharge Toolscleaner sur ton Bureau

      ▶ Fais un clic droit sur ToolsCleaner2.exe et sélectionne "Exécuter en tant qu'administrateur"
      ▶ Clique sur Recherche et laisse le scan se terminer.
      ▶ Clique sur Suppression pour finaliser.
      ▶ Tu peux, si tu le souhaites, te servir des Options facultatives.
      ▶ Clique sur Quitter, pour que le rapport puisse se créer.
      ▶ Le rapport (TCleaner.txt) se trouve à la racine de votre disque dur (C:\)...colle le dans ta réponse

      Désactive et réactive la Restauration du système :

      Le fait de faire cette manipulation va supprimer tous les virus qui auraient pu se loger dans les
      points de restauration que tu avais créé auparavant.. Il est donc recommandé de la faire :

      Voici un tutoriel qui t expliquera comment désactiver et réactiver la restauration du système.

      Tu peux mettre ton problème résolu !! Comment mettre résolu ??

      Ensuite vas réactiver le contrôle des comptes et créer un point de restauration !! IMPORTANT

      IMPORTANT : lire les quelques liens pour la prévention et la sécurité de votre PC qui se trouvent en bas de la page !!

      WOT - Extension pour ton navigateur internet :

      Voici une extension à télécharger qui te permettra, en faisant tes recherches sur google, de savoir si le site proposé lors de tes recherches est un site de confiance ou un site à éviter car il pourrait infecter ton PC :

      Pour Firefox : https://addons.mozilla.org/fr/firefox/addon/wot-safe-browsing-tool/

      Pour internet explorer : https://chrome.google.com/webstore/detail/wot-web-of-trust-website/bhmmomiinigofkjcapegjjndpbikblnp

      ==informations importantes==

      Si tu n'as pas regardé l'envoyé spécial diffusé sur France2, voici les vidéos parlant des hackers :

      https://www.dailymotion.com/video/x97v8f

      https://www.dailymotion.com/video/x982wr

      https://www.dailymotion.com/video/x97v6o
      0
      1. Ok lol, on a pas mal dévier de mon sujet, a la base j'ai juste posté 2 rapport de RSIT qui normalement me dise si je suis infecté ou pas par des rootkit. Mais je n'ai jamais eu de problème avec mon ordi.

        Je ne voulais pas d'un nettoyage complet, je connais déjà tout sa, j'ai ccleaner malwarebytes' spybot antivir Glary utilities, en ce qui concerne nettoyage je suis bien équipé. Je voulais juste savoir si j'étais ou pas infecté de rootkit.
        0
        1. Contributeur sécurité
          ▶ Télécharge CCleaner

          ▶ Tu auras un tutoriel pour l'installer et l'utiliser correctement.

          ▶ Fais le nettoyage et recherche les erreurs du registre comme expliqué en bas du tutoriel.

          Est-ce que tu as encore des problèmes ??
          0
          1. Voilà...

            Logfile of Trend Micro HijackThis v2.0.2
            Scan saved at 12:32:43, on 26/08/2009
            Platform: Windows Vista SP2 (WinNT 6.00.1906)
            MSIE: Internet Explorer v8.00 (8.00.6001.18813)
            Boot mode: Normal

            Running processes:
            C:\Windows\system32\Dwm.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\Explorer.EXE
            C:\Windows\system32\taskeng.exe
            C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
            C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
            C:\Program Files\Windows Defender\MSASCui.exe
            C:\Windows\RtHDVCpl.exe
            C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            C:\Windows\System32\rundll32.exe
            C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Windows\ehome\ehtray.exe
            C:\Program Files\Windows Sidebar\sidebar.exe
            C:\Windows\ehome\ehmsas.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
            C:\Program Files\Windows Live\Messenger\msnmsgr.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\Program Files\Mozilla Firefox\firefox.exe
            C:\Windows\system32\SearchFilterHost.exe
            C:\Users\kevin\Desktop\RSIT.exe
            C:\Program Files\trend micro\kevin.exe

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http:\\www.samsungcomputer.com
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
            R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\OrangeHSS\SearchURLHook\SearchPageURL.dll
            O1 - Hosts: ::1 localhost
            O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
            O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
            O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
            O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
            O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
            O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
            O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
            O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
            O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
            O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
            O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O13 - Gopher Prefix:
            O16 - DPF: {9DF1C00D-8426-4337-972C-DC042D19A916} (FTMediaPlayer Class) - http://webtv.guidetv.orange.fr/resources/OCS_8971.cab
            O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
            O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
            O23 - Service: Service Google Update (gupdate1c9cb387e2085a7) (gupdate1c9cb387e2085a7) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
            O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
            O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
            O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
            0
            1. Contributeur sécurité
              Bonjour,

              suit ce chemin et lance le fichier kevin.exe (le exe peut ne pas être présent) :

              C:\Program Files\trend micro\kevin.exe

              Clique sur Do a system scan & save a logfile

              Un rapport va s'afficher... Copie/colle-le dans ta prochaine réponse
              0
              1. Malwarebytes' Anti-Malware 1.40
                Version de la base de données: 2691
                Windows 6.0.6002 Service Pack 2

                24/08/2009 23:45:16
                mbam-log-2009-08-24 (23-45-16).txt

                Type de recherche: Examen complet (C:\|G:\|)
                Eléments examinés: 186640
                Temps écoulé: 42 minute(s), 7 second(s)

                Processus mémoire infecté(s): 0
                Module(s) mémoire infecté(s): 0
                Clé(s) du Registre infectée(s): 0
                Valeur(s) du Registre infectée(s): 0
                Elément(s) de données du Registre infecté(s): 0
                Dossier(s) infecté(s): 0
                Fichier(s) infecté(s): 0

                Processus mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Module(s) mémoire infecté(s):
                (Aucun élément nuisible détecté)

                Clé(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Valeur(s) du Registre infectée(s):
                (Aucun élément nuisible détecté)

                Elément(s) de données du Registre infecté(s):
                (Aucun élément nuisible détecté)

                Dossier(s) infecté(s):
                (Aucun élément nuisible détecté)

                Fichier(s) infecté(s):
                (Aucun élément nuisible détecté)
                0
                1. j'ai déjà ce logiciel, je fait une analyse et je te post le rapport au plus vite.
                  0
                  1. Contributeur sécurité
                    Ok maintenant fais ceci stp :

                    ▶ Télécharge malwarebyte's anti-malware

                    ▶ Un tutoriel sera à ta disposition pour l'installer et l'utiliser correctement.

                    ▶ Fais la mise à jour du logiciel (elle se fait normalement à l'installation)

                    ▶ Lance une analyse complète en cliquant sur "Exécuter un examen complet"

                    ▶ Sélectionnes les disques que tu veux analyser et cliques sur "Lancer l'examen"

                    ▶ L'analyse peut durer un bon moment.....

                    ▶ Une fois l'analyse terminée, cliques sur "OK" puis sur "Afficher les résultats"

                    ▶ Vérifies que tout est bien coché et cliques sur "Supprimer la sélection" => et ensuite sur "OK"

                    ▶ Un rapport va s'ouvrir dans le bloc note... Fais un copié/collé du rapport dans ta prochaine réponse sur le forum

                    * Il se pourrait que certains fichiers devront être supprimés au redémarrage du PC...
                    Faites le en cliquant sur "oui" à la question posée
                    0
                    1. je me perd dans les log je crois...., désolé.

                      ############################## | UsbFix V6.022 |

                      User : kevin (Administrateurs) # PC-DE-KEVIN
                      Update on 24/08/09 by Chiquitine29
                      Start at: 20:37:05 | 24/08/2009
                      Website : http://pagesperso-orange.fr/NosTools/index.html

                      Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
                      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                      Internet Explorer 8.0.6001.18813
                      Windows Firewall Status : Enabled

                      C:\ -> Disque fixe local # 111,88 Go (70,1 Go free) # NTFS
                      D:\ -> Disque fixe local # 111 Go (85,21 Go free) # NTFS
                      E:\ -> Disque CD-ROM
                      G:\ -> Disque fixe local # 298,01 Go (191,17 Go free) [DD 300GO] # FAT32

                      ################## | Vaccination |

                      # C:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                      # D:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.
                      # G:\autorun.inf ( # Not infected ) -> Folder created by UsbFix.

                      ################## | ! Fin du rapport # UsbFix V6.022 ! |
                      0
                      1. Contributeur sécurité
                        Option 3 !! (vaccination)
                        0
                        1. Voila le log:

                          ############################## | UsbFix V6.022 |

                          User : kevin (Administrateurs) # PC-DE-KEVIN
                          Update on 24/08/09 by Chiquitine29
                          Start at: 01:42:30 | 24/08/2009
                          Website : http://pagesperso-orange.fr/NosTools/index.html

                          Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
                          Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                          Internet Explorer 8.0.6001.18813
                          Windows Firewall Status : Enabled

                          C:\ -> Disque fixe local # 111,88 Go (73,35 Go free) # NTFS
                          D:\ -> Disque fixe local # 111 Go (85,21 Go free) # NTFS
                          E:\ -> Disque CD-ROM
                          G:\ -> Disque fixe local # 298,01 Go (191,17 Go free) [DD 300GO] # FAT32

                          ###################### | Listing des fichiers présents C:\ |

                          [18/09/2006 23:43|--a------|24] - C:\autoexec.bat
                          [11/04/2009 08:36|-rahs----|333257] - C:\bootmgr
                          [08/02/2008 11:31|-ra-s----|8192] - C:\BOOTSECT.BAK
                          [18/09/2006 23:43|--a------|10] - C:\config.sys
                          [30/03/2009 12:06|-rahs----|0] - C:\IO.SYS
                          [30/03/2009 12:06|-rahs----|0] - C:\MSDOS.SYS
                          [?|?|?] - C:\pagefile.sys
                          [12/09/2008 05:30|--a------|366] - C:\RHDSetup.log
                          [24/04/2009 12:14|--a------|86] - C:\Setup.log
                          [24/08/2009 01:42|--a------|1138] - C:\UsbFix.txt
                          [11/07/2009 13:34|--a------|45910] - C:\WirelessDiagLog.csv

                          ###################### | Listing des dossiers présents C:\ |

                          [24/08/2009 01:34|d--hs----|4096] - C:\$Recycle.Bin
                          [24/08/2009 01:41|drahs----|0] - C:\autorun.inf
                          [14/08/2009 12:29|d--hs----|4096] - C:\Boot
                          [02/11/2006 15:02|d--hs---l|0] - C:\Documents and Settings
                          [12/09/2008 05:25|d--------|0] - C:\Intel
                          [18/07/2009 00:10|d--------|0] - C:\PerfLogs
                          [24/08/2009 01:28|dr-------|24576] - C:\Program Files
                          [15/08/2009 19:36|d--h-----|8192] - C:\ProgramData
                          [18/07/2009 00:10|d--------|0] - C:\Sounds
                          [23/08/2009 13:40|d--hs----|20480] - C:\System Volume Information
                          [24/08/2009 01:42|d--------|4096] - C:\UsbFix
                          [24/04/2009 12:13|dr-------|4096] - C:\Users
                          [06/07/2009 20:10|d--------|0] - C:\Westwood
                          [24/08/2009 01:31|d--------|28672] - C:\Windows

                          ###################### | Listing des fichiers présents D:\ |

                          ###################### | Listing des dossiers présents D:\ |

                          [24/08/2009 01:34|d--hs----|0] - D:\$RECYCLE.BIN
                          [24/08/2009 01:41|drahs----|0] - D:\autorun.inf
                          [24/08/2009 01:54|d--------|4096] - D:\SamsungRecovery
                          [24/04/2009 12:33|d--hs----|0] - D:\System Volume Information

                          ###################### | Listing des fichiers présents G:\ |

                          [25/02/2008 10:30|-rahs----|54] - G:\autorun.in_2.org
                          [08/08/2009 19:44|--a------|733652992] - G:\Largo.Winch.avi
                          [15/08/2009 16:59|--a------|730642432] - G:\Le.Seminaire..avi
                          [17/08/2009 15:49|--a------|733153280] - G:\Les.Enfants.De.Timpelbach.FRENCH.DVDRiP.XViD-UNSKiLLED.By.Hadopix.[emule-island.com].avi
                          [15/08/2009 20:44|--a------|731549696] - G:\Envoyes.Tres.Speciaux.FRENCH.BDRiP.XViD-SURViVAL.By.Hadopix.[emule-island.com].avi
                          [16/08/2009 17:00|--a------|735354218] - G:\Knowing.FRENCH.DVDRiP.REPACK.1CD.XviD-FUCK.[emule-island.com].avi
                          [15/08/2009 15:20|--a------|734453760] - G:\Monster.In.Law..avi
                          [16/08/2009 14:19|--a------|732508160] - G:\Die Hard 4.avi
                          [17/08/2009 13:33|--a------|734912906] - G:\Harry.Potter.et.la.chambre.des.secrets.avi

                          ###################### | Listing des dossiers présents G:\ |

                          [10/07/2009 16:05|d--hs----|0] - G:\FOUND.000
                          [19/06/2009 23:20|d--hs----|0] - G:\$RECYCLE.BIN
                          [19/06/2009 23:20|d--------|0] - G:\Dossier WD
                          [14/07/2009 00:22|d--------|0] - G:\Musique2
                          [18/06/2009 21:30|d--------|0] - G:\Qlimax.2008.AC3.DVDRip.XviD-TRANCEZONE
                          [14/07/2009 01:32|d--------|0] - G:\Musique
                          [19/06/2009 23:51|d--------|0] - G:\Film
                          [26/04/2009 22:41|d--------|0] - G:\Malcom
                          [15/07/2009 19:29|d--------|0] - G:\Logiciel-Setup
                          [15/07/2009 22:36|d--------|0] - G:\Clips
                          [10/08/2009 13:12|d--hs----|0] - G:\Recycled
                          [10/08/2009 13:12|d--hs----|0] - G:\System Volume Information
                          [24/08/2009 01:41|drahs----|0] - G:\autorun.inf

                          ################## | ! Fin du rapport # UsbFix V6.022 ! |
                          0
                          1. Contributeur sécurité
                            Bonjour,

                            voilà, maintenant l'option 2 est passée :

                            ################## | Fichiers # Dossiers infectieux |

                            Supprimé ! C:\autorun.inf
                            Supprimé ! D:\autorun.inf
                            Supprimé ! G:\autorun.inf

                            Maintenant fais ceci pour vacciner tes supports amovibles :

                            Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptibles d avoir été infectés sans les ouvrir

                            ▶ Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisis "Exécuter en tant qu'administrateur" .

                            ▶ Choisis l'option 3 ( Vaccination )

                            ▶ Laisse travailler l'outil.

                            ▶ Ensuite poste le rapport UsbFix.txt qui apparaîtra.

                            * Note : Le rapport UsbFix.txt est sauvegardé à la racine du disque. ( C:\UsbFix.txt )

                            ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
                            0
                            1. Contributeur sécurité
                              Ecoute... je te dis que le rapport que tu m'as envoyé est le rapport créé après avoir effectuer la recherche avec l'option 1.

                              Si tu penses avoir fais l'option 2, alors poste le rapport... Au sinon fais l'option 2
                              1
                              1. 3ème fois que je post, on dirait que sa ne marche pas, enfin bref voici le bon log:

                                ############################## | UsbFix V6.022 |

                                User : kevin (Administrateurs) # PC-DE-KEVIN
                                Update on 24/08/09 by Chiquitine29
                                Start at: 01:31:52 | 24/08/2009
                                Website : http://pagesperso-orange.fr/NosTools/index.html

                                Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
                                Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                                Internet Explorer 8.0.6001.18813
                                Windows Firewall Status : Enabled

                                C:\ -> Disque fixe local # 111,88 Go (73,43 Go free) # NTFS
                                D:\ -> Disque fixe local # 111 Go (85,21 Go free) # NTFS
                                E:\ -> Disque CD-ROM
                                G:\ -> Disque fixe local # 298,01 Go (191,17 Go free) [DD 300GO] # FAT32

                                ############################## | Processus actifs |

                                C:\Windows\System32\smss.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\wininit.exe
                                C:\Windows\system32\csrss.exe
                                C:\Windows\system32\services.exe
                                C:\Windows\system32\lsass.exe
                                C:\Windows\system32\lsm.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\nvvsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\SLsvc.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\winlogon.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\system32\LogonUI.exe
                                C:\Windows\system32\rundll32.exe
                                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\lpksetup.exe
                                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                C:\Windows\system32\svchost.exe
                                C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                C:\Program Files\Google\Update\GoogleUpdate.exe
                                C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
                                C:\Windows\system32\svchost.exe
                                C:\Windows\System32\svchost.exe
                                C:\Windows\system32\SearchIndexer.exe
                                C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                C:\Windows\servicing\TrustedInstaller.exe
                                C:\Windows\system32\DllHost.exe
                                C:\Windows\system32\userinit.exe
                                C:\Windows\system32\Dwm.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\system32\taskeng.exe
                                C:\Windows\Explorer.EXE
                                C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
                                C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
                                C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
                                C:\Windows\system32\DllHost.exe
                                C:\Windows\system32\wbem\wmiprvse.exe
                                C:\Windows\system32\runonce.exe
                                C:\Windows\system32\conime.exe

                                ################## | Fichiers # Dossiers infectieux |

                                Supprimé ! C:\autorun.inf
                                Supprimé ! D:\autorun.inf
                                Supprimé ! G:\autorun.inf

                                ################## | Autres |

                                ################## | Suspect ! ... | https://www.virustotal.com/gui/ |

                                ################## | Registre # Clés Run infectieuses |

                                ################## | Registre # Mountpoints2 |

                                ################## | Listing des fichiers présent |

                                [18/09/2006 23:43|--a------|24] -> C:\autoexec.bat
                                [11/04/2009 08:36|-rahs----|333257] -> C:\bootmgr
                                [08/02/2008 11:31|-ra-s----|8192] -> C:\BOOTSECT.BAK
                                [18/09/2006 23:43|--a------|10] -> C:\config.sys
                                [30/03/2009 12:06|-rahs----|0] -> C:\IO.SYS
                                [30/03/2009 12:06|-rahs----|0] -> C:\MSDOS.SYS
                                [?|?|?] -> C:\pagefile.sys
                                [12/09/2008 05:30|--a------|366] -> C:\RHDSetup.log
                                [24/04/2009 12:14|--a------|86] -> C:\Setup.log
                                [24/08/2009 01:34|--a------|3425] -> C:\UsbFix.txt
                                [11/07/2009 13:34|--a------|45910] -> C:\WirelessDiagLog.csv
                                [25/02/2008 10:30|-rahs----|54] -> G:\autorun.in_2.org
                                [08/08/2009 19:44|--a------|733652992] -> G:\Largo.Winch.avi
                                [15/08/2009 16:59|--a------|730642432] -> G:\Le.Seminaire..avi
                                [17/08/2009 15:49|--a------|733153280] -> G:\Les.Enfants.De.Timpelbach.FRENCH.DVDRiP.XViD-UNSKiLLED.By.Hadopix.[emule-island.com].avi
                                [15/08/2009 20:44|--a------|731549696] -> G:\Envoyes.Tres.Speciaux.FRENCH.BDRiP.XViD-SURViVAL.By.Hadopix.[emule-island.com].avi
                                [16/08/2009 17:00|--a------|735354218] -> G:\Knowing.FRENCH.DVDRiP.REPACK.1CD.XviD-FUCK.[emule-island.com].avi
                                [15/08/2009 15:20|--a------|734453760] -> G:\Monster.In.Law..avi
                                [16/08/2009 14:19|--a------|732508160] -> G:\Die Hard 4.avi
                                [17/08/2009 13:33|--a------|734912906] -> G:\Harry.Potter.et.la.chambre.des.secrets.avi

                                ################## | Cracks / Keygens / Serials |
                                0
                            2. J'avais déjà fait l'option 2...je recommencerais demain.

                              Je vous tient au courant sur ce post, je dois m'en aller.

                              Merci de votre aide.
                              0
                              1. Contributeur sécurité
                                Non c'est une recherche avec l'option 1 que tu viens de faire :

                                ################## | Fichiers # Dossiers infectieux |

                                Présent ! C:\autorun.inf
                                Présent ! D:\autorun.inf
                                Présent ! G:\autorun.inf

                                Ils seront supprimés avec l'option 2 ;-)
                                1
                                1. Déja effectué ^^.

                                  j'ai suivi le Tuto de nettoyage. Le log que je t'ai envoyé correspond au log qui vient après le nettoyage.
                                  0
                                  1. Contributeur sécurité
                                    Maintenant tu vas faire le nettoyage ;-)

                                    ▶ tutoriel nettoyage

                                    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d avoir été infectés sans les ouvrir

                                    ▶ Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi "Exécuter en tant qu'administrateur" .

                                    ▶ choisi l'option 2 ( Suppression )

                                    ▶ Ton bureau disparaîtra et le pc redémarrera .

                                    ▶ Au redémarrage , UsbFix scannera ton pc , laisse travailler l'outil.

                                    ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra avec le bureau .

                                    ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

                                    ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                    ▶ /!\ UsbFix te proposera d'uploader un dossier compressé à cette adresse : https://www.androidworld.fr/

                                    ▶ Ce dossier a été créé par UsbFix et est enregistré sur ton bureau.

                                    ▶ Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

                                    ▶ Merci d'avance pour ta contribution !!
                                    0
                                    1. J'ai effectuer le nettoyage
                                      ############################## | UsbFix V6.021 |

                                      User : kevin (Administrateurs) # PC-DE-KEVIN
                                      Update on 22/08/09 by Chiquitine29
                                      Start at: 21:42:05 | 23/08/2009
                                      Website : http://pagesperso-orange.fr/NosTools/index.html

                                      Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
                                      Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6002 32-bit) # Service Pack 2
                                      Internet Explorer 8.0.6001.18813
                                      Windows Firewall Status : Enabled

                                      C:\ -> Disque fixe local # 111,88 Go (73,46 Go free) # NTFS
                                      D:\ -> Disque fixe local # 111 Go (85,21 Go free) # NTFS
                                      E:\ -> Disque CD-ROM
                                      G:\ -> Disque fixe local # 298,01 Go (191,17 Go free) [DD 300GO] # FAT32

                                      ############################## | Processus actifs |

                                      C:\Windows\System32\smss.exe
                                      C:\Windows\system32\csrss.exe
                                      C:\Windows\system32\wininit.exe
                                      C:\Windows\system32\csrss.exe
                                      C:\Windows\system32\services.exe
                                      C:\Windows\system32\lsass.exe
                                      C:\Windows\system32\lsm.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\nvvsvc.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\SLsvc.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\system32\winlogon.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                      C:\Program Files\Google\Update\1.2.183.7\GoogleCrashHandler.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\System32\svchost.exe
                                      C:\Windows\system32\SearchIndexer.exe
                                      C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                      C:\Windows\servicing\TrustedInstaller.exe
                                      C:\Windows\system32\taskeng.exe
                                      C:\Windows\system32\Dwm.exe
                                      C:\Program Files\Samsung\EBM\EasyBatteryMgr3.exe
                                      C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
                                      C:\Program Files\Samsung\Samsung Update Plus\SUPBackground.exe
                                      C:\Windows\system32\conime.exe
                                      C:\Windows\system32\svchost.exe
                                      C:\Windows\explorer.exe
                                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                                      C:\Windows\system32\wbem\wmiprvse.exe
                                      C:\Windows\system32\SearchProtocolHost.exe
                                      C:\Windows\system32\SearchFilterHost.exe
                                      C:\Windows\system32\wbem\wmiprvse.exe
                                      C:\Program Files\Mozilla Firefox\firefox.exe

                                      ################## | Fichiers # Dossiers infectieux |

                                      Présent ! C:\autorun.inf
                                      Présent ! D:\autorun.inf
                                      Présent ! G:\autorun.inf

                                      ################## | Suspect ! ... | https://www.virustotal.com/gui/ |

                                      ################## | Registre # Clés Run infectieuses |

                                      ################## | Registre # Mountpoints2 |

                                      ################## | Cracks / Keygens / Serials |

                                      ################## | ! Fin du rapport # UsbFix V6.021 ! |
                                      0
                                      1. Contributeur sécurité
                                        Bonsoir,

                                        Commence par faire ceci stp, tu as des infections par disques amovibles :

                                        ▶ Telecharge et installe UsbFix de C_XX & Chiquitine29

                                        ▶ tutoriel d'installation

                                        ▶ tutoriel recherche

                                        Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                                        ▶ Fais un clic droit sur le raccourci UsbFix présent sur ton bureau et choisi "Exécuter en tant qu'administrateur" .

                                        ▶ Choisi l'option 1 ( Recherche )

                                        ▶ Laisse travailler l'outil.

                                        ▶ Ensuite post le rapport UsbFix.txt qui apparaîtra.

                                        ▶ Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

                                        ( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                        * Note : "SniffC.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                        Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                        Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                                        0
                                        • 1
                                        • 2