[Virus] Win32.Gpcode.ak

Résolu
Hello !

Depuis hier soir mon PC semble infecté, en effet je reçoit des messages d'erreurs de mon Avast Antivirus toutes les 2 minutes, j'ai des icones d'erreurs partout en barre des tâches... Mon windows m'envoi des alertes de Security Center...

Bref j'ai lancé un scan avec Malwarebytes Anti'Maltiware , il n'a rien trouvé.

En revanche, j'ai lancé un second scan avec Ad-Aware qui lui a déjà trouvé 2 infections ( 7 minutes d'analyse pour l'instant ).

Voilà pouvez-vous m'aider ?

Je peux poster un rapport HijackThis ou autre si besoin.
Configuration: Windows Vista Edition Familiale NVIDIA GeForce 8500GT Mozilla Firefox / Internet Explorer 7.0 Avast! Antivirus

31 réponses

Résumé de la discussion

Des symptômes d’infection apparaissent sur le PC avec des messages d’erreur Avast et des alertes Security Center pendant que Malwarebytes ne détecte rien et Ad-Aware signale deux infections. Des solutions de détection et de suppression sont proposées, notamment HijackThis pour repérer les entrées potentiellement indésirables, USBfix pour les infections USB et Ad-Remover pour les programmes indésirables. En cas de persistance, des outils complémentaires comme Bitdefender en ligne et ZHPDiag (puis ZHPFix) permettent d’obtenir des rapports à poster ensuite. D’autres conseils incluent la sauvegarde des données et la vérification des programmes installés récemment pour éviter les réinfections après nettoyage.

Bobot (l’IA à votre service)
  1. N'ayant plus de réponses ni de messages d'erreurs anti-virus, je classe le dossier en résolu...
    Merci Xplode pour votre aide très généreuse et utile !

    Je repasserai si problèmes... Merci encore !
    0
    1. Salut Xplode,
      Je n'ai pas eu de réponse, je voulais savoir si on avait finit ou pas ?
      En tout cas merci pour le travail accomplit jusqu'à là !
      0
      1. Alors ça donne quoi s'il vous plait ?
        0
        1. Voilà le scan RSIT :

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Guiome at 2009-12-06 21:49:51
          Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
          System drive C: has 46 GB (20%) free of 233 GB
          Total RAM: 1023 MB (35% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 21:50:04, on 06/12/2009
          Platform: Windows Vista SP1 (WinNT 6.00.1905)
          MSIE: Internet Explorer v8.00 (8.00.6001.18702)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\Razer\razerhid.exe
          C:\WINDOWS\RtHDVCpl.exe
          C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HpqSRmon.exe
          C:\Program Files\Java\jre6\bin\jusched.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\Program Files\Steam\Steam.exe
          C:\Program Files\Skype\Phone\Skype.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Razer\razerofa.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Common Files\Teleca Shared\Generic.exe
          C:\Program Files\Skype\Plugin Manager\skypePM.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Live\Contacts\wlcomm.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
          C:\Windows\system32\wuauclt.exe
          C:\Windows\System32\mobsync.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Users\Guiome\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BHCS6D3N\RSIT[1].exe
          C:\Program Files\Trend Micro\HijackThis\Guiome.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
          R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O1 - Hosts: ::1 localhost
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
          O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
          O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
          O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
          O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
          O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
          O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
          O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
          O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
          O13 - Gopher Prefix:
          O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Service Google Update (gupdate1ca1c026c802290) (gupdate1ca1c026c802290) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
          O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
          O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
          O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
          O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
          O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
          O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
          O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
          0
          1. Contributeur sécurité
            Refais un RSIT stp
            1
            1. Nettoyage HijackThis effectué.

              Voilà le rapport USBFix :


              ############################## | UsbFix V6.059 |

              User : Guiome (Administrateurs) # PCBUREAU
              Update on 01/12/2009 by Chiquitine29, C_XX & Chimay8
              Start at: 14:39:25 | 06/12/2009
              Website : http://pagesperso-orange.fr/NosTools/index.html
              Contact : FindyKill.Contact@gmail.com

              Intel(R) Celeron(R) M CPU 430 @ 1.73GHz
              Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
              Internet Explorer 8.0.6001.18783
              Windows Firewall Status : Enabled
              AV : AntiMalware 1.0 [ Enabled | (!) Outdated ]
              AV : avast! antivirus 4.8.1296 [VPS 081218-0] 4.8.1296 [ Enabled | Updated ]

              C:\ -> Disque fixe local # 227,82 Go (44,37 Go free) [HP] # NTFS
              D:\ -> Disque fixe local # 5,06 Go (32,5 Mo free) [Recovery] # NTFS
              E:\ -> Disque CD-ROM # 727,56 Mo (0 Mo free) [Sims2_EP5_1] # UDF
              F:\ -> Disque amovible
              G:\ -> Disque amovible
              H:\ -> Disque amovible
              I:\ -> Disque amovible

              ############################## | Processus actifs |

              C:\Windows\System32\smss.exe 452
              C:\Windows\system32\csrss.exe 520
              C:\Windows\system32\wininit.exe 576
              C:\Windows\system32\csrss.exe 584
              C:\Windows\system32\services.exe 632
              C:\Windows\system32\lsass.exe 664
              C:\Windows\system32\lsm.exe 672
              C:\Windows\system32\winlogon.exe 680
              C:\Windows\system32\svchost.exe 848
              C:\Windows\system32\nvvsvc.exe 912
              C:\Windows\system32\svchost.exe 940
              C:\Windows\System32\svchost.exe 972
              C:\Windows\System32\svchost.exe 1076
              C:\Windows\System32\svchost.exe 1128
              C:\Windows\system32\svchost.exe 1144
              C:\Windows\system32\svchost.exe 1240
              C:\Windows\system32\SLsvc.exe 1256
              C:\Windows\system32\svchost.exe 1292
              C:\Windows\system32\svchost.exe 1400
              C:\Windows\system32\nvvsvc.exe 1420
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe 1592
              C:\Program Files\Alwil Software\Avast4\ashServ.exe 1604
              C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe 1632
              C:\Windows\System32\spoolsv.exe 1972
              C:\Windows\system32\svchost.exe 1996
              C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe 596
              C:\Program Files\Bonjour\mDNSResponder.exe 800
              C:\Windows\system32\svchost.exe 1352
              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe 1548
              c:\Program Files\Common Files\LightScribe\LSSrvc.exe 1780
              C:\Windows\System32\svchost.exe 1448
              C:\Windows\System32\svchost.exe 2060
              C:\Windows\system32\svchost.exe 2088
              C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 2112
              C:\Windows\system32\svchost.exe 2140
              C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe 2172
              C:\Windows\System32\svchost.exe 2220
              C:\Windows\system32\SearchIndexer.exe 2276
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe 2484
              C:\Windows\system32\WUDFHost.exe 2492
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe 2528
              C:\Windows\system32\wbem\unsecapp.exe 2792
              C:\Windows\system32\wbem\wmiprvse.exe 2956
              C:\Windows\system32\taskeng.exe 3476
              C:\Windows\system32\taskeng.exe 1380
              C:\Windows\system32\Dwm.exe 1308
              C:\Windows\Explorer.EXE 3800
              C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe 2676
              C:\Windows\system32\runonce.exe 3276
              C:\Windows\system32\conime.exe 3956
              C:\Windows\system32\wbem\wmiprvse.exe 4040

              ################## | Fichiers # Dossiers infectieux |

              Non supprimé ! E:\autorun.inf

              ################## | Spyware.OnlineGames |

              ################## | Registre # Clés infectieuses |

              ################## | Registre # Mountpoints2 |

              Supprimé ! HKCU\...\Explorer\MountPoints2\{fbfb3d8a-6548-11dd-b41f-806e6f6e6963}\Shell\AutoRun\Command

              ################## | Listing des fichiers présent |

              [27/12/2008 01:01|--a------|5960] C:\AD-report-Clean-27.12.2008.log
              [05/12/2009 15:43|--a------|8824] C:\Ad-Report-CLEAN[1].log
              [27/12/2008 00:44|--a------|6670] C:\AD-report-Scan-27.12.2008.log
              [18/09/2006 22:43|--a------|24] C:\autoexec.bat
              [19/01/2008 08:45|-rahs----|333203] C:\bootmgr
              [05/12/2006 17:49|-ra-s----|8192] C:\BOOTSECT.BAK
              [05/12/2009 23:15|--a------|1352] C:\cleannavi.txt
              [18/09/2006 22:43|--a------|10] C:\config.sys
              [08/08/2008 15:00|--a------|167653] C:\ExtractLog.txt
              [11/10/2009 19:40|--a------|34124] C:\fish.exe
              [27/12/2008 00:44|-rahs----|0] C:\IO.SYS
              [27/12/2008 00:44|-rahs----|0] C:\MSDOS.SYS
              [?|?|?] C:\pagefile.sys
              [05/12/2006 09:10|--a------|402] C:\RHDSetup.log
              [08/08/2008 14:57|--a------|159] C:\Setup.log
              [05/12/2009 16:01|--a------|2031] C:\TB.txt
              [06/12/2009 14:42|--a------|4409] C:\UsbFix.txt
              [05/12/2009 16:52|--a------|2606] C:\ZHPExportRegistry-05-12-2009-16-52-18.txt
              [28/07/2006 09:05|---hs----|432696] D:\bootmgr
              [13/10/2006 15:00|---hs----|1322] D:\Desktop.ini
              [08/08/2008 14:45|---hs----|0] D:\DRECOVERY
              [10/03/2007 17:11|---hs----|32] D:\HPCD.sys
              [10/03/2007 18:06|---hs----|306] D:\Master.log
              [12/10/2008 10:00|-ra------|528] D:\MediaID.bin
              [08/08/2008 14:13|--ah-----|487] D:\pcdr.ini
              [10/09/2002 13:58|---hs----|181616] D:\Protect.ed
              [10/03/2007 17:11|---hs----|26] D:\RCBoot.sys
              [05/12/2006 19:14|---hs----|44] D:\RESTORE.INI
              [18/10/2006 11:09|---hs----|34] D:\SystemRecovery.txt
              [26/01/2007 09:36|-r-------|20482048] E:\00000001.TMP
              [26/01/2007 09:36|-r-------|317440] E:\00000002.TMP
              [26/01/2007 09:41|-r-------|4] E:\_
              [26/01/2007 09:36|-r-------|700416] E:\AutoRun.exe
              [26/01/2007 09:40|-r-------|149] E:\autorun.inf
              [26/01/2007 08:06|-r-------|651264] E:\AutoRunGUI.dll
              [26/01/2007 09:40|-r-------|429] E:\common_filelist.txt
              [26/01/2007 09:40|-r-------|683500937] E:\compressed.zip
              [26/01/2007 09:40|-r-------|71178] E:\cs_compressed.zip
              [26/01/2007 09:40|-r-------|67844] E:\da_compressed.zip
              [26/01/2007 09:40|-r-------|74536] E:\de_compressed.zip
              [26/01/2007 09:36|-r-------|356352] E:\eauninstall.exe
              [26/01/2007 06:16|-r-------|10134] E:\eauninstall.ico
              [26/01/2007 09:40|-r-------|68390] E:\en-uk_compressed.zip
              [26/01/2007 09:40|-r-------|77170] E:\es_compressed.zip
              [26/01/2007 09:40|-r-------|73444] E:\fi_compressed.zip
              [26/01/2007 09:40|-r-------|75226] E:\fr-fr_compressed.zip
              [26/01/2007 09:40|-r-------|73260] E:\hu_compressed.zip
              [26/01/2007 09:40|-r-------|68390] E:\it_compressed.zip
              [26/01/2007 09:40|-r-------|85094] E:\nl_compressed.zip
              [26/01/2007 09:40|-r-------|69960] E:\no_compressed.zip
              [26/01/2007 09:40|-r-------|74516] E:\pl_compressed.zip
              [26/01/2007 09:40|-r-------|80596] E:\pt-br_compressed.zip
              [26/01/2007 09:40|-r-------|79730] E:\pt-pt_compressed.zip
              [26/01/2007 09:40|-r-------|70078] E:\ru_compressed.zip
              [26/01/2007 06:16|-r-------|10134] E:\Sims2EP5.ico
              [26/01/2007 08:07|-r-------|286720] E:\Sims2EP5_Uninst.exe
              [26/01/2007 09:40|-r-------|71674] E:\sv_compressed.zip

              ################## | Vaccination |

              # C:\autorun.inf -> Dossier créé par UsbFix.
              # D:\autorun.inf -> Dossier créé par UsbFix.

              ################## | Cracks / Keygens / Serials |
              0
              1. Contributeur sécurité
                -+-+-+-> Hijackthis <-+-+-+-

                [x] Lance hijackthis ( C:\Program Files\Trend Micro\Hijackthis.exe )

                [x] Clique sur " None of the above, just start the program " puis sur " Scan "

                [x] Coche les lignes en gras ci dessous :


                R3 - Default URLSearchHook is missing
                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                O4 - HKUS\S-1-5-21-3978070026-1512194447-919480873-1000\..\Run: [WinUsr] C:\Program Files\Winsudate\gibusr.exe (User 'Général')
                O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"


                [x] Clique ensuite sur " Fix checked "

                ====================================================================

                -+-+-+-> USBfix ( Infections USB ) <-+-+-+-

                [x] Télécharge USBfix ( de Chiquitine29 )

                [x] Un tutoriel est disponible ici

                [x] Installe le

                /!\ Branche tout tes médias amovibles ( clés USB, DD externe, Cartes SD ) /!\

                [x] Lance USBfix en cliquant sur l'icône qui est sur ton bureau ( Clique droit -> Executer en tant qu'administrateur pour vista )

                [x] Choisis l'option F ( pour français ) et valide en appuyant sur entrée.

                [x] Au menu principal, choisis l'option 2

                [x] Laisse l'outil travailler puis poste le rapport dans ton prochain message
                1
                1. Alors ça donne quoi ?

                  En apparence je ne voit plus de messages d'erreur...
                  0
                  1. Voilà le scan RSIT ( en revanche un seul fichier s'est ouvert : log.txt )

                    Logfile of random's system information tool 1.06 (written by random/random)
                    Run by Guiome at 2009-12-06 11:38:32
                    Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
                    System drive C: has 45 GB (19%) free of 233 GB
                    Total RAM: 1023 MB (17% free)

                    Logfile of Trend Micro HijackThis v2.0.2
                    Scan saved at 11:38:48, on 06/12/2009
                    Platform: Windows Vista SP1 (WinNT 6.00.1905)
                    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                    Boot mode: Normal

                    Running processes:
                    C:\Windows\system32\taskeng.exe
                    C:\Windows\system32\Dwm.exe
                    C:\Windows\Explorer.EXE
                    C:\Windows\system32\conime.exe
                    C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                    C:\Program Files\Razer\razerhid.exe
                    C:\WINDOWS\RtHDVCpl.exe
                    C:\Program Files\iTunes\iTunesHelper.exe
                    C:\Program Files\Hewlett-Packard\Digital Imaging\bin\HpqSRmon.exe
                    C:\Program Files\Java\jre6\bin\jusched.exe
                    C:\WINDOWS\ehome\ehtray.exe
                    C:\Program Files\Steam\Steam.exe
                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                    C:\Program Files\Skype\Phone\Skype.exe
                    C:\Program Files\Razer\razerofa.exe
                    C:\Windows\ehome\ehmsas.exe
                    C:\Program Files\Common Files\Teleca Shared\Generic.exe
                    C:\Program Files\Skype\Plugin Manager\skypePM.exe
                    C:\Windows\system32\igfxsrvc.exe
                    C:\Windows\system32\wuauclt.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Windows\system32\Macromed\Flash\FlashUtil10c.exe
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                    C:\Program Files\Windows Live\Contacts\wlcomm.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\Users\Guiome\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T0ZIO55E\RSIT[1].exe
                    C:\Program Files\Trend Micro\HijackThis\Guiome.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                    R3 - Default URLSearchHook is missing
                    O1 - Hosts: ::1 localhost
                    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
                    O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll
                    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                    O4 - HKLM\..\Run: [razer] C:\Program Files\Razer\razerhid.exe
                    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                    O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
                    O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
                    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpqSRMon.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
                    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                    O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
                    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                    O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
                    O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
                    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                    O4 - HKUS\S-1-5-21-3978070026-1512194447-919480873-1000\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun (User 'Général')
                    O4 - HKUS\S-1-5-21-3978070026-1512194447-919480873-1000\..\Run: [WinUsr] C:\Program Files\Winsudate\gibusr.exe (User 'Général')
                    O4 - HKUS\S-1-5-21-3978070026-1512194447-919480873-1000\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized (User 'Général')
                    O4 - S-1-5-21-3978070026-1512194447-919480873-1000 Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe (User 'Général')
                    O4 - S-1-5-21-3978070026-1512194447-919480873-1000 Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Général')
                    O4 - S-1-5-21-3978070026-1512194447-919480873-1000 User Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe (User 'Général')
                    O4 - S-1-5-21-3978070026-1512194447-919480873-1000 User Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe (User 'Général')
                    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                    O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
                    O13 - Gopher Prefix:
                    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - https://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cab
                    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/fr/scan8/oscan8.cab
                    O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
                    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
                    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                    O23 - Service: Service Google Update (gupdate1ca1c026c802290) (gupdate1ca1c026c802290) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
                    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                    O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
                    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                    O23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe
                    0
                    1. Contributeur sécurité
                      Bien, dernière vérif :

                      -+-+-+-> RSIT <-+-+-+-

                      [x] Télécharge Random's System Information Tool

                      [x] Double clique sur " RSIT.exe ".

                      [x] Clique sur " Continue ".

                      [x] Si hijackthis n'est pas présent il sera automatiquement téléchargé et tu devras accepter la license.

                      [x] Une fois l'analyse finie, deux fichiers ( info.txt & log.txt ) s'ouvriront.

                      [x] Copie/Colle leur contenu dans ton prochain message.
                      1
                      1. Voilà le rapport Bitdefender

                        BitDefender Online Scanner

                        Rapport d'analyse g�n�r� �: Sun, Dec 06, 2009 - 00:50:38

                        Voie d'analyse: C:\;D:\;E:\;F:\;G:\;H:\;I:\;

                        Statistiques

                        Temps
                        01:03:43

                        Fichiers
                        193429

                        Directoires
                        30668

                        Secteurs de boot
                        0

                        Archives
                        2824

                        Paquets programmes
                        22125

                        R�sultats

                        Virus identifi�s
                        1

                        Fichiers infect�s
                        1

                        Fichiers suspects
                        0

                        Avertissements
                        0

                        D�sinfect�s
                        0

                        Fichiers effac�s
                        1

                        Info sur les moteurs

                        D�finition virus
                        4695567

                        Version des moteurs
                        AVCORE v2.1 Windows/i386 11.0.0.26 (Oct 20 2009)

                        Analyse des plugins
                        17

                        Archive des plugins
                        44

                        Unpack des plugins
                        8

                        E-mail plugins
                        6

                        Syst�me plugins
                        4

                        Param�tres d'analyse

                        Premi�re action
                        Désinfecté

                        Seconde Action
                        Supprimés

                        Heuristique
                        Oui

                        Acceptez les avertissements
                        Oui

                        Extensions analys�es
                        exe;com;dll;ocx;scr;bin;dat;386;vxd;sys;wdm;cla;class;ovl;ole;hlp;doc;dot;xls;ppt;wbk;wiz;pot;ppa;xla;xlt;vbs;vbe;mdb;rtf;htm;hta;html;xml;xtp;php;asp;js;shs;chm;lnk;pif;prc;url;smm;pfd;msi;ini;csc;cmd;bas;

                        Excludez les extensions

                        Analyse d'emails
                        Oui

                        Analyse des Archives
                        Oui

                        Analyser paquets programmes
                        Oui

                        Analyse des fichiers
                        Oui

                        Analyse de boot
                        Oui

                        Fichier analys�
                        Statut

                        C:\Program Files\Navilog1\Backupnavi\cscko.exe
                        Détecté avec: Adware.NaviPromo.Gen.5

                        C:\Program Files\Navilog1\Backupnavi\cscko.exe
                        Echec de la désinfection

                        C:\Program Files\Navilog1\Backupnavi\cscko.exe
                        Supprimé
                        0
                        1. Voilà j'ai lancé le scan Bitdefender mais on m'estime 67 heures de scan c'est normal ? :D
                          0
                          1. Contributeur sécurité
                            -+-+-+-> Scan en ligne Bitdefender <-+-+-+-

                            [x] Suis le tutoriel disponible à cette adresse ( en image ) :

                            https://www.commentcamarche.net/faq/8872-scanner-en-ligne-avec-bitdefender
                            1
                            1. Voici le rapport Navilog1 :

                              Fix Navipromo version 4.0.5 commencé le 05/12/2009 22:57:09,66

                              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                              !!! Postez ce rapport sur le forum pour le faire analyser !!!

                              Outil exécuté depuis C:\Program Files\navilog1

                              Mise à jour le 10.11.2009 à 18h00 par IL-MAFIOSO

                              Microsoft® Windows Vista™ Édition Familiale Premium ( v6.0.6001 ) Service Pack 1
                              X86-based PC ( Multiprocessor Free : Intel(R) Celeron(R) M CPU 430 @ 1.73GHz )
                              BIOS : BIOS Date: 04/23/07 10:53:04 Ver: 08.00.12
                              USER : Guiome ( Not Administrator ! )
                              BOOT : Normal boot

                              Antivirus : avast! antivirus 4.8.1296 [VPS 081218-0] 4.8.1296 (Activated)

                              C:\ (Local Disk) - NTFS - Total:227 Go (Free:46 Go)
                              D:\ (Local Disk) - NTFS - Total:5 Go (Free:0 Go)
                              E:\ (CD or DVD) - UDF - Total:0 Go (Free:0 Go)
                              F:\ (USB)
                              G:\ (USB)
                              H:\ (USB)
                              I:\ (USB)

                              Recherche executée en mode normal

                              Nettoyage exécuté au redémarrage de l'ordinateur

                              C:\Users\GNRAL~1\AppData\Local\asnhzun.bat supprimé !

                              Nettoyage contenu C:\Windows\Temp effectué !
                              Nettoyage contenu C:\Users\Guiome\AppData\Local\Temp effectué !

                              *** Sauvegarde du Registre vers dossier Safebackup ***

                              sauvegarde du Registre réalisée avec succès !

                              *** Nettoyage Registre ***

                              Nettoyage Registre Ok

                              *** Scan terminé 05/12/2009 23:15:13,90 ***
                              0
                              1. Contributeur sécurité
                                Ca raconte qu'on a bientôt terminé :

                                -+-+-+-> Navilog <-+-+-+-

                                Ton PC est infecté par l'ad-aware Navipromo/Magic Control qui affiche des publicités intempestives.
                                Il s'installe via certains programmes, dont ceux-ci :

                                ● Funky Emoticons
                                ● go-astro
                                ● GoRecord
                                ● HotTVPlayer / HotTVPlayer & Paris Hilton
                                ● Live-Player
                                ● MailSkinner
                                ● Messenger Skinner
                                ● Instant Access
                                ● InternetGameBox
                                ● Officiale Emule (Version d'Emule modifiée)
                                ● Original Solitaire
                                ● SuperSexPlayer
                                ● Speed Downloading
                                ● Sudoplanet
                                ● Webmediaplayer

                                /!\ Fais attention de ne pas faire la même erreur, donc évite ces programmes /!\

                                [x] Télécharge Navilog ( de IL-MAFIOSO)

                                [x] Lance le en double cliquant dessus. ( Clic droit -> "Executer en tant qu'administrateur" sous vista )

                                [x] Laisse-toi guider par l'utilitaire. Choisis l'option n°1 puis valide.

                                [x] A l'écran principal, choisis l'option n°1 puis laisse l'outil scanner.

                                [x] Patiente jusqu'à l'apparition de ce message :

                                "*** Analyse Termine le ..... ***"

                                [x] Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste son contenu dans ton prochain message.

                                Nb : Le rapport se trouve également ici : C:\cleannavi.txt
                                1
                                1. Voilà le scan ZHPDiag :

                                  http://www.cijoint.fr/cjlink.php?file=cj200912/cijHlyYJX9.txt
                                  0
                                  1. Contributeur sécurité
                                    Bien, fais maintenant un nouveau rapport ZHPDiag
                                    1
                                    • 1
                                    • 2