Trojan Spy.gen2

Résolu
Bonjour,

Antivir a détecté un trojan sur mon PC :
C:\Documents and Settings\JEREMY\Local Settings\irdimar.bak Is the TR/Spy.Gen2 Trojan

et il n'arrive pas à m'en séparer :/

J'ai nettoyé avec CCleaner, essayé Malwarebyte, tuneUp, fait un scan en ligne avec Nod32 : tjrs pas de résultat, Antivir détecte tjrs Spy.gen2

A court de solutions, je suis preneur de toute aide pour me dépétrer de ce probleme :)

Jeremy

Ci-dessous mon log Hijackthis :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:17:31, on 17/01/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ntvdm.exe
C:\OPLIMIT\ocrawr32.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\system32\CSHelper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.noos.fr/abonnes.php
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = iexplore
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Barre RoboForm - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Enregistrer le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O8 - Extra context menu item: Personnaliser le menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
O8 - Extra context menu item: Remplir le formulaire - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1\bin\npjpi141.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.1\bin\npjpi141.dll
O9 - Extra button: Remplir - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra 'Tools' menuitem: Remplir le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
O9 - Extra button: Enregistrer - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra 'Tools' menuitem: Enregistrer le formulaire - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
O9 - Extra button: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra 'Tools' menuitem: Barre RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} (ITPPDiagIE Class) - http://data.jeuxclassiques.com/npwwg.cab
O16 - DPF: {512FC5A1-7DE1-43F1-BC0C-371622FCB409} (TotalScan Installer Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - http://download.eset.com/special/eos/OnlineScanner.cab
O16 - DPF: {8436FE12-31DB-48BF-83BF-FE682F9160B4} (NanoInstaller Class) - https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab
O16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) - http://game05.zylom.com/activex/zylomgamesplayer.cab
O16 - DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} (YYGInstantPlay Control) - http://www.yoyogames.com/downloads/activex/YoYo.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://3dlifeplayer.dl.3dvia.com/player/install/installer.exe
O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager.CacheManagerCtrl) - https://www.pch.com/games?source=candystand
O20 - AppInit_DLLs: winmm.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: CopySafe Helper Service (CSHelper) - Unknown owner - C:\WINDOWS\system32\CSHelper.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe
O23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe
O23 - Service: XlashServ (XlashSrv) - Unknown owner - C:\WINDOWS\xlash.exe (file missing)

--
End of file - 7857 bytes
Configuration: Windows XP, IE 7

28 réponses

Résumé de la discussion

Une détection par Antivir signale un trojan TR/Spy.Gen2 sur Windows XP SP2, lié au fichier irdimar.bak, et des tentatives de nettoyage qui échouent. Les logs relatent des essais de suppression via ComboFix et Malwarebytes, et des éléments suspects dans HijackThis, notamment des démarrages et des DLL injectées. Un balayage GMER signale des hooks dans winlogon.exe et d’autres processus critiques, avec le driver awtdypow.sys proche d’un rootkit. En l’absence d’un outil de réparation fiable, une réinstallation complète ou un formatage après sauvegarde des données pourrait s’imposer.

Bobot (l’IA à votre service)
  1. Merci pour ton aide et tes précieux conseils ! Je te suis infiniment reconnaissant pour la patience que tu as eue pour régler mes petites soucis informatiques :)

    Pour les mises à jour système, c'est vrai que je ne suis pas un pro. Je suis meilleur en mise à jour antivirus... parce qu'elle se fait tout seul ! Pour le reste, je suis assez prudent, mais on ne l'est jamais assez, preuve en est.

    Encore bravo pour ton travail !

    (et je vais valider en résolu)

    A très bientot ! (enfin, j'espère, pas trop vite)
    0
    1. Contributeur sécurité
      Salut kearny

      Si plus de souci, je te donne quelques consignes de sécurité :

      - Windows Update parfaitement à jour http://www.windowsupdate.com/windowsupdate/v6/default.aspx (catégories critique, Services Pack et Services Release)
      - pare-feu bien paramétré, je te conseil ZoneAlarm :
      https://www.malekal.com/tutoriel-zonealarm-firewall/
      - antivirus bien paramétré et mis à jour régulièrement (quotidiennement s'il le faut) avec un scan complet régulier (journalier s'il le faut).
      - une attitude prudente vis à vis de la navigation (pas de sites douteux : cracks, warez, sexe...) et vis à vis de la messagerie (fichiers joints aux messages doivent être scannés avant d'être ouverts)
      - pas de téléchargement illégal, qui est le principal facteur d’infection (µTorrent, BitTorrent, eMule, Limewire, etc..) http://forum.malekal.com/ftopic893.php
      - une attitude vigilante (être à l'affût d'un fonctionnement inhabituel de son système)
      - nettoyage hebdomadaire du système (suppression des fichiers inutiles, nettoyage de la base de registre, scandisk, defrag)
      - scan hebdomadaire antispyware, je conseil MalwareByte's Anti-Malware :
      https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
      - un contrôle régulier de la console JAVA pour s'assurer qu'elle est à jour :
      https://www.java.com/en/download/uninstalltool.jsp
      - faire régulièrement un scan de vulnérabilités afin de vérifier que tes logiciels soit à jour sans failles de sécurités :
      https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/

      De bonne lecture si tu veux en savoir plus sur la sécurité et le fonctionnement de Windows :
      http://www.malekal.com/menu_windows_general.php
      http://www.malekal.com/menu_windows_securite.php

      Si tu considères ton problème comme résolu, tu pourras mettre en résolu :
      https://www.commentcamarche.net/infos/25917-marquer-un-fil-de-discussion-comme-etant-resolu/

      Bonne journée/soirée et bon surf

      @++ :)
      0
      1. [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

        --> Recherche:

        C:\Combofix.txt: trouvé !
        C:\hijackthis.log: trouvé !
        C:\SDFIX: trouvé !
        C:\_OTM: trouvé !
        C:\Rsit: trouvé !
        C:\Backups\catchme.log: trouvé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
        C:\Documents and Settings\JEREMY\Bureau\HijackThis.lnk: trouvé !
        C:\Documents and Settings\JEREMY\Bureau\DiagHelp.zip: trouvé !
        C:\Documents and Settings\JEREMY\Bureau\OTM.exe: trouvé !
        C:\Documents and Settings\JEREMY\Bureau\ComboFix.exe: trouvé !
        C:\Documents and Settings\JEREMY\Bureau\OAD.exe: trouvé !
        C:\Documents and Settings\JEREMY\Bureau\DiagHelp: trouvé !
        C:\Documents and Settings\JEREMY\Bureau\DiagHelp\catchme.exe: trouvé !
        C:\Documents and Settings\JEREMY\Bureau\DiagHelp\mbr.exe: trouvé !
        C:\Documents and Settings\JEREMY\Mes documents\hijackthis.log: trouvé !
        C:\Downloaded Files\HijackThis.exe: trouvé !
        C:\Program Files\Trend Micro\HijackThis: trouvé !
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
        C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !
        C:\SDFix\catchme.exe: trouvé !
        C:\WINDOWS\mbr.exe: trouvé !

        ---------------------------------
        --> Suppression:

        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
        C:\Documents and Settings\JEREMY\Bureau\HijackThis.lnk: supprimé !
        C:\Documents and Settings\JEREMY\Bureau\DiagHelp.zip: supprimé !
        C:\Documents and Settings\JEREMY\Bureau\OTM.exe: supprimé !
        C:\Documents and Settings\JEREMY\Bureau\ComboFix.exe: ERREUR DE SUPPRESSION !!
        C:\Documents and Settings\JEREMY\Bureau\DiagHelp\catchme.exe: supprimé !
        C:\Downloaded Files\HijackThis.exe: supprimé !
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
        C:\SDFix\catchme.exe: supprimé !
        C:\Combofix.txt: supprimé !
        C:\hijackthis.log: supprimé !
        C:\Backups\catchme.log: supprimé !
        C:\Documents and Settings\JEREMY\Bureau\OAD.exe: supprimé !
        C:\Documents and Settings\JEREMY\Bureau\DiagHelp\mbr.exe: supprimé !
        C:\Documents and Settings\JEREMY\Mes documents\hijackthis.log: supprimé !
        C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
        C:\WINDOWS\mbr.exe: supprimé !
        C:\SDFIX: supprimé !
        C:\_OTM: supprimé !
        C:\Rsit: supprimé !
        C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
        C:\Documents and Settings\JEREMY\Bureau\DiagHelp: supprimé !
        C:\Program Files\Trend Micro\HijackThis: supprimé !

        Point de restauration crée !
        Corbeille vidée!
        Fichiers temporaires nettoyés !
        Sauvegarde du registre crée !

        Il reste quelques programmes sur le bureau, mais je le ferai manuellement (si ajout/suppression de programmes fonctionne bien) Et j'ai fait les mises à jour sur le système et le navigateur.
        0
        1. Contributeur sécurité
          Salut kearny

          Cela est bon, ton système n'est pas à jour et est vulnérable au infections.
          https://forum.malekal.com/viewtopic.php?f=45&t=3259

          Désactive la restauration système sur tous les lecteurs :

          - Clique droit sur le Poste de travail sur le bureau, dans propriété tu cliques sur l'onglet Restauration système

          - Coche la case désactiver la restauration et applique

          Redémarre l’ordinateur et réactive la restauration système.

          Tutoriel XP : http://www.libellules.ch/desactiver_restauration.php

          ----

          On va faire un ménage des outils téléchargés pour la désinfection, télécharge Tools Cleaner sur le bureau :

          http://pc-system.fr/

          - Double clique sur ToolsCleaner2.exe sur le bureau
          - Clique sur Recherche et laisse le scan agir.
          - Clique sur Suppression pour finaliser.
          - Tu peux, si tu le souhaites, te servir des Options facultatives.
          - Clique sur Quitter pour obtenir le rapport.
          - Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).
          - Si des outils restes après le passage de Tools Cleaner, tu pourras les supprimer manuellement ainsi que tous les rapports qui on été généré lors de la désinfection.

          -----

          Important de mettre à jour Windows et tes logiciels :
          Mettre Windows(catégories critique, Services Pack et Services Release) à jour : http://www.windowsupdate.com/windowsupdate/v6/default.aspx

          Faire un scan de vulnérabilités afin de vérifier que tes logiciels soit à jour sans failles de sécurités et mettre à jour :
          https://www.malekal.com/tester-la-vulnerabilite-de-son-systeme-2/

          Faire un ménage des fichiers inutiles et de la base de registre :
          https://www.malekal.com/tutoriel-ccleaner/

          Dis moi quand cela est fais où si tu as des soucis et on passe à la résolution du sujet par la suite.

          @++ :)
          0
          1. Le scan ne passait pas en mode sans échec, je l'ai fait en mode normal, et deux trojans ont été détectés et mis en quarantaine, voila le rapport :

            Avira AntiVir Personal
            Report file date: mardi 19 janvier 2010 01:00

            Scanning for 1566455 virus strains and unwanted programs.

            Licensed to: Avira AntiVir Personal - FREE Antivirus
            Serial number: 0000149996-ADJIE-0000001
            Platform: Windows XP
            Windows version: (Service Pack 3) [5.1.2600]
            Boot mode: Normally booted
            Username: SYSTEM
            Computer name: JEREMY

            Version information:
            BUILD.DAT : 8.2.0.354 17048 Bytes 23/10/2009 13:15:00
            AVSCAN.EXE : 8.1.4.10 315649 Bytes 26/11/2008 17:15:05
            AVSCAN.DLL : 8.1.4.0 40705 Bytes 17/07/2008 21:57:20
            LUKE.DLL : 8.1.4.5 164097 Bytes 17/07/2008 21:57:22
            LUKERES.DLL : 8.1.4.0 12033 Bytes 17/07/2008 21:57:22
            ANTIVIR0.VDF : 7.10.0.0 19875328 Bytes 06/11/2009 23:45:56
            ANTIVIR1.VDF : 7.10.1.11 1395568 Bytes 19/11/2009 23:46:06
            ANTIVIR2.VDF : 7.10.2.224 2514336 Bytes 18/01/2010 23:44:02
            ANTIVIR3.VDF : 7.10.2.226 172544 Bytes 18/01/2010 23:44:03
            Engineversion : 8.2.1.142
            AEVDF.DLL : 8.1.1.2 106867 Bytes 15/09/2009 18:54:51
            AESCRIPT.DLL : 8.1.3.7 594296 Bytes 16/01/2010 23:46:41
            AESCN.DLL : 8.1.3.1 127348 Bytes 16/01/2010 23:46:39
            AESBX.DLL : 8.1.1.1 246132 Bytes 16/01/2010 23:46:38
            AERDL.DLL : 8.1.3.4 479605 Bytes 16/01/2010 23:46:37
            AEPACK.DLL : 8.2.0.5 422262 Bytes 16/01/2010 23:46:35
            AEOFFICE.DLL : 8.1.0.38 196987 Bytes 17/06/2009 22:40:04
            AEHEUR.DLL : 8.1.0.195 2232695 Bytes 16/01/2010 23:46:33
            AEHELP.DLL : 8.1.10.0 237942 Bytes 16/01/2010 23:46:27
            AEGEN.DLL : 8.1.1.83 369014 Bytes 16/01/2010 23:46:26
            AEEMU.DLL : 8.1.1.0 393587 Bytes 03/10/2009 11:15:17
            AECORE.DLL : 8.1.9.5 184693 Bytes 16/01/2010 23:46:24
            AEBB.DLL : 8.1.0.3 53618 Bytes 18/10/2008 22:42:46
            AVWINLL.DLL : 1.0.0.12 15105 Bytes 17/07/2008 21:57:20
            AVPREF.DLL : 8.0.2.0 38657 Bytes 17/07/2008 21:57:20
            AVREP.DLL : 8.0.0.3 155688 Bytes 20/04/2009 18:54:43
            AVREG.DLL : 8.0.0.1 33537 Bytes 17/07/2008 21:57:20
            AVARKT.DLL : 1.0.0.23 307457 Bytes 15/04/2008 21:03:22
            AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 17/07/2008 21:57:20
            SQLITE3.DLL : 3.3.17.1 339968 Bytes 15/04/2008 21:03:23
            SMTPLIB.DLL : 1.2.0.23 28929 Bytes 17/07/2008 21:57:22
            NETNT.DLL : 8.0.0.1 7937 Bytes 15/04/2008 21:03:22
            RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 17/07/2008 21:57:14
            RCTEXT.DLL : 8.0.52.0 86273 Bytes 17/07/2008 21:57:14

            Configuration settings for the scan:
            Jobname..........................: Complete system scan
            Configuration file...............: c:\program files\antivir personaledition classic\sysscan.avp
            Logging..........................: low
            Primary action...................: interactive
            Secondary action.................: ignore
            Scan master boot sector..........: off
            Scan boot sector.................: on
            Boot sectors.....................: C:, D:,
            Process scan.....................: on
            Scan registry....................: on
            Search for rootkits..............: off
            Scan all files...................: Intelligent file selection
            Scan archives....................: on
            Recursion depth..................: 20
            Smart extensions.................: on
            Macro heuristic..................: on
            File heuristic...................: medium

            Start of the scan: mardi 19 janvier 2010 01:00

            The scan of running processes will be started
            Scan process 'OneClickStarter.exe' - '0' Module(s) have been scanned
            Scan process 'avscan.exe' - '1' Module(s) have been scanned
            Scan process 'avcenter.exe' - '1' Module(s) have been scanned
            Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
            Scan process 'alg.exe' - '1' Module(s) have been scanned
            Scan process 'wlcomm.exe' - '1' Module(s) have been scanned
            Scan process 'TuneUpUtilitiesApp32.exe' - '1' Module(s) have been scanned
            Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
            Scan process 'OCRAWR32.EXE' - '1' Module(s) have been scanned
            Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
            Scan process 'TuneUpUtilitiesService32.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'CSHelper.exe' - '1' Module(s) have been scanned
            Scan process 'sched.exe' - '1' Module(s) have been scanned
            Scan process 'ntvdm.exe' - '1' Module(s) have been scanned
            Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'avguard.exe' - '1' Module(s) have been scanned
            Scan process 'explorer.exe' - '1' Module(s) have been scanned
            Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'svchost.exe' - '1' Module(s) have been scanned
            Scan process 'lsass.exe' - '1' Module(s) have been scanned
            Scan process 'services.exe' - '1' Module(s) have been scanned
            Scan process 'winlogon.exe' - '1' Module(s) have been scanned
            Scan process 'csrss.exe' - '1' Module(s) have been scanned
            Scan process 'smss.exe' - '1' Module(s) have been scanned
            29 processes with 29 modules were scanned

            Start scanning boot sectors:
            Boot sector 'C:\'
            [INFO] No virus was found!
            Boot sector 'D:\'
            [INFO] No virus was found!

            Starting to scan the registry.
            The registry was scanned ( '54' files ).

            Starting the file scan:

            Begin scan in 'C:\' <SYSTEME>
            C:\hiberfil.sys
            [WARNING] The file could not be opened!
            C:\pagefile.sys
            [WARNING] The file could not be opened!
            C:\Documents and Settings\JEREMY\Menu Démarrer\Programmes\Internet Explorer.lnk
            [DETECTION] Is the TR/StartPage.KA.3 Trojan
            [NOTE] The file was moved to '4bc8f706.qua'!
            C:\System Volume Information\_restore{8C16EA5C-C499-4766-A24A-2E01D69CFE5F}\RP751\A0081262.lnk
            [DETECTION] Is the TR/StartPage.KA.3 Trojan
            [NOTE] The file was moved to '4b84fa3a.qua'!
            Begin scan in 'D:\' <DATA>

            End of the scan: mardi 19 janvier 2010 01:29
            Used time: 29:26 Minute(s)

            The scan has been done completely.

            5112 Scanning directories
            164943 Files were scanned
            2 viruses and/or unwanted programs were found
            0 Files were classified as suspicious:
            0 files were deleted
            0 files were repaired
            2 files were moved to quarantine
            0 files were renamed
            2 Files cannot be scanned
            164939 Files not concerned
            1024 Archives were scanned
            2 Warnings
            2 Notes
            0
            1. Contributeur sécurité
              Salut kearny

              Effectivement c'est la quarantaine de Combofix, supprime le dossier en gras et vide la corbeille :
              c:\Qoobox

              Mettre à jour Antivir, faire un scan en mode sans échec et poste le rapport après avoir démarré en mode normal.

              Aide : https://www.malekal.com/avira-free-security-antivirus-gratuit/

              @++ :)
              0
              1. ESETSmartInstaller@High as CAB hook log:
                OnlineScanner.ocx - registred OK
                # version=7
                # iexplore.exe=6.00.2900.5512 (xpsp.080413-2105)
                # OnlineScanner.ocx=1.0.0.6211
                # api_version=3.0.2
                # EOSSerial=f0f39f5acd579d428af598019122b98b
                # end=finished
                # remove_checked=true
                # archives_checked=true
                # unwanted_checked=true
                # unsafe_checked=false
                # antistealth_checked=true
                # utc_time=2010-01-18 02:29:35
                # local_time=2010-01-18 03:29:35 (+0100, Paris, Madrid)
                # country="France"
                # lang=1033
                # osver=5.1.2600 NT Service Pack 3
                # compatibility_mode=512 16777215 100 0 89360 89360 0 0
                # compatibility_mode=8192 67108863 100 0 10400 10400 0 0
                # compatibility_mode=9217 16777214 0 4 99541049 99541049 0 0
                # scanned=75140
                # found=0
                # cleaned=0
                # scan_time=5052

                Sinon, j'ai reçu encore des alertes Antivir, moins fréquentes cela dit, sur le fichier irdimar.bak (Spy.gen2) dans le dossier c:\Qoobox. Peut être un dossier de quarantaine créé par Combofix ?
                0
                1. Contributeur sécurité
                  Salut kearny

                  Faire un scan avec Nod32 en ligne (il faut utiliser Internet Explorer) ici :

                  https://www.eset.com/int/home/online-scanner/

                  (coche toutes les cases à chaque fois)
                  A la fin, colle le rapport : C:\Program Files\EsetOnlineScanner\log.txt

                  @++ :)
                  0
                  1. DaonolFix (15.04.09) by jpshortstuff
                    Log created at 11:21 on 18/01/2010 by JEREMY
                    Running from C:\Documents and Settings\JEREMY\Bureau\DaonolFix.exe

                    =====Find Daonol=====

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
                    "midi"="wdmaud.drv"
                    "midi1"="wdmaud.drv"
                    "midimapper"="midimap.dll"
                    "mixer"="wdmaud.drv"
                    "msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax"
                    "msacm.imaadpcm"="imaadp32.acm"
                    "msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm"
                    "msacm.msadpcm"="msadp32.acm"
                    "msacm.msaudio1"="msaud32.acm"
                    "msacm.msg711"="msg711.acm"
                    "msacm.msg723"="msg723.acm"
                    "msacm.msgsm610"="msgsm32.acm"
                    "msacm.siren"="sirenacm.dll"
                    "msacm.sl_anet"="sl_anet.acm"
                    "msacm.trspch"="tssoft32.acm"
                    "MSVideo8"="VfWWDM32.dll"
                    "vidc.cvid"="iccvid.dll"
                    "vidc.DIVX"="DivX.dll"
                    "VIDC.I420"="msh263.drv"
                    "vidc.iv31"="ir32_32.dll"
                    "vidc.iv32"="ir32_32.dll"
                    "vidc.iv41"="ir41_32.ax"
                    "vidc.iv50"="ir50_32.dll"
                    "VIDC.IYUV"="iyuv_32.dll"
                    "vidc.M261"="msh261.drv"
                    "vidc.M263"="msh263.drv"
                    "vidc.mrle"="msrle32.dll"
                    "vidc.msvc"="msvidc32.dll"
                    "VIDC.UYVY"="msyuv.dll"
                    "VIDC.YUY2"="msyuv.dll"
                    "vidc.yv12"="DivX.dll"
                    "VIDC.YVU9"="tsbyuv.dll"
                    "VIDC.YVYU"="msyuv.dll"
                    "wave"="wdmaud.drv"
                    "wavemapper"="msacm32.drv"

                    -=Daonol Files=-
                    (none found)

                    -=End Of File=-
                    0
                    1. ComboFix 10-01-16.04 - JEREMY 18/01/2010 10:49:25.2.1 - x86
                      Microsoft Windows XP Édition familiale 5.1.2600.3.1252.33.1036.18.383.231 [GMT 1:00]
                      Lancé depuis: c:\documents and settings\JEREMY\Bureau\ComboFix.exe
                      Commutateurs utilisés :: c:\documents and settings\JEREMY\Bureau\CFScript.txt
                      AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}

                      FILE ::
                      "c:\windows\system32\perfc00C.dat"
                      "c:\windows\system32\perfh00C.dat"
                      .

                      (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                      .

                      c:\windows\system32\perfc00C.dat
                      c:\windows\system32\perfh00C.dat

                      .
                      ((((((((((((((((((((((((((((( Fichiers créés du 2009-12-18 au 2010-01-18 ))))))))))))))))))))))))))))))))))))
                      .

                      2010-01-18 09:25 . 2010-01-18 09:25 -------- d-----w- c:\windows\system32\fr-fr
                      2010-01-18 09:25 . 2010-01-18 09:25 -------- d-----w- c:\windows\l2schemas
                      2010-01-18 09:24 . 2010-01-18 09:24 -------- d-----w- c:\windows\system32\fr
                      2010-01-18 09:24 . 2010-01-18 09:24 -------- d-----w- c:\windows\system32\bits
                      2010-01-18 09:14 . 2010-01-18 09:14 -------- d-----w- c:\windows\EHome
                      2010-01-18 00:29 . 2008-04-13 18:36 44672 ------w- c:\windows\system32\drivers\uagp35.sys
                      2010-01-18 00:28 . 2008-04-14 02:33 4274816 ------w- c:\windows\system32\nv4_disp.dll
                      2010-01-18 00:27 . 2008-04-14 02:33 37376 ------w- c:\windows\system32\l2gpstore.dll
                      2010-01-18 00:26 . 2008-04-14 02:33 9216 ------w- c:\windows\system32\dot3dlg.dll
                      2010-01-18 00:21 . 2010-01-18 09:21 -------- d-----w- c:\windows\ServicePackFiles
                      2010-01-17 23:35 . 2008-06-14 17:33 272768 -c----w- c:\windows\system32\dllcache\bthport.sys
                      2010-01-17 23:35 . 2008-06-14 17:33 272768 ------w- c:\windows\system32\drivers\bthport.sys
                      2010-01-17 23:34 . 2009-11-21 15:58 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
                      2010-01-17 23:27 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
                      2010-01-17 23:27 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
                      2010-01-17 23:27 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
                      2010-01-17 23:10 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
                      2010-01-17 23:09 . 2008-04-11 19:05 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
                      2010-01-17 23:07 . 2008-12-16 12:31 354304 -c----w- c:\windows\system32\dllcache\winhttp.dll
                      2010-01-17 23:07 . 2008-10-15 16:35 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
                      2010-01-17 23:06 . 2008-04-21 21:15 219136 -c----w- c:\windows\system32\dllcache\wordpad.exe
                      2010-01-17 21:55 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
                      2010-01-17 21:55 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
                      2010-01-17 18:31 . 2010-01-17 18:31 -------- d-----w- c:\windows\ERUNT
                      2010-01-17 18:26 . 2010-01-17 19:38 -------- d-----w- C:\SDFix
                      2010-01-17 15:22 . 2010-01-17 15:22 -------- d-----w- C:\_OTM
                      2010-01-17 14:34 . 2010-01-17 14:35 -------- d-----w- C:\rsit
                      2010-01-17 13:16 . 2010-01-17 13:16 -------- d-----w- c:\program files\Trend Micro
                      2010-01-17 11:46 . 2009-12-17 20:03 30536 ----a-w- c:\windows\system32\TURegOpt.exe
                      2010-01-17 11:46 . 2009-12-17 19:56 30024 ----a-w- c:\windows\system32\uxtuneup.dll
                      2010-01-17 11:46 . 2010-01-17 11:46 -------- d-----w- c:\documents and settings\JEREMY\Application Data\TuneUp Software
                      2010-01-17 11:46 . 2010-01-17 11:46 -------- d-----w- c:\program files\TuneUp Utilities 2010
                      2010-01-17 11:45 . 2010-01-17 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
                      2010-01-17 11:45 . 2010-01-17 11:45 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
                      2010-01-17 01:46 . 2010-01-17 01:46 -------- d-----w- c:\documents and settings\JEREMY\Application Data\Malwarebytes
                      2010-01-17 01:46 . 2010-01-17 01:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                      2010-01-17 01:46 . 2010-01-17 18:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                      2010-01-03 23:28 . 2010-01-03 23:28 -------- d-----w- c:\documents and settings\JEREMY\Application Data\Mozilla-Cache

                      .
                      (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      2010-01-18 09:58 . 2010-01-18 09:58 356120 ----a-w- c:\windows\system32\PerfStringBackup.TMP
                      2010-01-18 09:26 . 2006-11-22 09:22 76507 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat
                      2010-01-18 08:54 . 2009-09-16 07:37 -------- d-----w- c:\program files\Microsoft Silverlight
                      2010-01-18 00:12 . 2007-09-23 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition Classic
                      2010-01-17 23:32 . 2006-11-28 01:44 -------- d-----w- c:\program files\InstantTouch
                      2010-01-03 23:28 . 2006-12-20 21:37 -------- d-----w- c:\program files\PartyGaming.Net
                      2009-11-21 15:58 . 2004-08-05 12:00 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
                      2009-10-29 05:25 . 2004-08-05 12:00 671232 ----a-w- c:\windows\system32\wininet.dll
                      .

                      ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                      .
                      .
                      *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                      REGEDIT4

                      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                      "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
                      "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

                      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                      "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

                      c:\documents and settings\JEREMY\Menu D‚marrer\Programmes\D‚marrage\
                      ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-3-6 36864]
                      OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2006-11-30 51360]

                      c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                      Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-30 108544]
                      Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

                      [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
                      @="Service"

                      [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                      "AVG Anti-Spyware Guard"=2 (0x2)

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                      "%windir%\\system32\\sessmgr.exe"=
                      "c:\\Program Files\\Messenger\\msmsgs.exe"=
                      "c:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe"=
                      "c:\\Program Files\\eMule\\emule.exe"=
                      "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
                      "c:\\Program Files\\PeerTV\\PeerCast.exe"=
                      "c:\\UT2004\\System\\UT2004.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                      "%windir%\\Network Diagnostic\\xpnetdiag.exe"=

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                      "4662:TCP"= 4662:TCP:eMule TCP
                      "4672:UDP"= 4672:UDP:eMule UDP

                      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
                      "AllowInboundEchoRequest"= 1 (0x1)
                      "AllowOutboundDestinationUnreachable"= 1 (0x1)
                      "AllowOutboundSourceQuench"= 1 (0x1)
                      "AllowOutboundTimeExceeded"= 1 (0x1)
                      "AllowRedirect"= 1 (0x1)

                      R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [17/03/2009 11:40 266240]
                      R2 ScFBPNT;CanoScan FBP Port Driver;c:\windows\system32\drivers\SCFBPNT.SYS [30/11/2006 16:31 16288]
                      R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [17/12/2009 21:00 1044808]
                      R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14/10/2009 07:24 10064]
                      S2 FILESpy;FILESpy;\??\c:\program files\Softwin\BitDefender9\filespy.sys --> c:\program files\Softwin\BitDefender9\filespy.sys [?]
                      S3 ADM8511;Convertisseur USB vers Fast Ethernet ADMtek ADM8511/AN986;c:\windows\system32\drivers\ADM8511.SYS [22/11/2006 12:32 20160]
                      S3 DCamUSBDigitalCamera;Digital Camera;c:\windows\system32\drivers\MPIXVID.SYS [23/12/2006 04:47 104593]
                      S3 v800bus;Sony Ericsson V800-Vodafone 802SE driver (WDM);c:\windows\system32\drivers\v800bus.sys [04/09/2007 14:41 52416]
                      S3 v800mdfl;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Filter;c:\windows\system32\drivers\v800mdfl.sys [04/09/2007 14:41 6160]
                      S3 v800mdm;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Driver;c:\windows\system32\drivers\v800mdm.sys [04/09/2007 14:41 84544]
                      S3 v800mgmt;Sony Ericsson V800-Vodafone 802SE USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\v800mgmt.sys [04/09/2007 14:48 77760]

                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
                      UxTuneUp
                      .
                      Contenu du dossier 'Tâches planifiées'

                      2010-01-13 c:\windows\Tasks\AppleSoftwareUpdate.job
                      - c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 13:21]

                      2010-01-18 c:\windows\Tasks\Recherche de problèmes automatique.job
                      - c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-12-17 20:07]
                      .
                      .
                      ------- Examen supplémentaire -------
                      .
                      uStart Page = hxxp://www.noos.fr/abonnes.php
                      uInternet Connection Wizard,ShellNext = iexplore
                      IE: Barre RoboForm - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                      IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
                      IE: Enregistrer le formulaire - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                      IE: Personnaliser le menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
                      IE: Remplir le formulaire - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                      DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} - hxxp://data.jeuxclassiques.com/npwwg.cab
                      DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game05.zylom.com/activex/zylomgamesplayer.cab
                      DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
                      .

                      **************************************************************************

                      catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                      Rootkit scan 2010-01-18 10:56
                      Windows 5.1.2600 Service Pack 3 NTFS

                      Recherche de processus cachés ...

                      Recherche d'éléments en démarrage automatique cachés ...

                      Recherche de fichiers cachés ...

                      c:\windows\system32\PerfStringBackup.TMP 356120 bytes

                      Scan terminé avec succès
                      Fichiers cachés: 1

                      **************************************************************************
                      .
                      --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                      [HKEY_LOCAL_MACHINE\software\Swearware\backup\winsock2]
                      @DACL=(02 0000)
                      @SACL=
                      .
                      --------------------- DLLs chargées dans les processus actifs ---------------------

                      - - - - - - - > 'explorer.exe'(3612)
                      c:\oplimit\oahook32.dll
                      c:\windows\system32\eappprxy.dll
                      .
                      ------------------------ Autres processus actifs ------------------------
                      .
                      c:\program files\AntiVir PersonalEdition Classic\avguard.exe
                      c:\program files\AntiVir PersonalEdition Classic\sched.exe
                      c:\windows\system32\wdfmgr.exe
                      c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
                      c:\oplimit\ocrawr32.exe
                      .
                      **************************************************************************
                      .
                      Heure de fin: 2010-01-18 11:01:45 - La machine a redémarré
                      ComboFix-quarantined-files.txt 2010-01-18 10:01
                      ComboFix2.txt 2010-01-18 00:09

                      Avant-CF: 32 529 289 216 octets libres
                      Après-CF: 32 510 435 328 octets libres

                      - - End Of File - - AA9FBE6B5D736A7100EFB420322ADCD5
                      0
                      1. Contributeur sécurité
                        Salut kearny

                        - Clique sur le menu démarrer/Exécuter, tape notepad à l’invite de commande et OK.

                        - Copie/colle ce qui est en gras ci-dessous dans le Bloc-Notes :

                        KillAll::

                        File::
                        c:\windows\system32\perfc00C.dat
                        c:\windows\system32\perfh00C.dat

                        Registry::
                        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                        "midi9"=-


                        - Enregistre ce fichier sur le bureau (Impératif)

                        -Nom du fichier : CFScript.txt
                        -Type du fichier : tous les fichiers

                        - Clique sur Enregistrer et quitte le Bloc Notes

                        Important Désactive ton Antivirus et antispyware avant de faire le glisser/déposer

                        - Fait un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe sur le bureau, comme sur cette capture (l’icône est un lion) :

                        http://free0.hiboox.com/images/2409/9126d3b136f7db9ab6242ad715b44296.gif

                        * Patiente le temps du scan. Le bureau va disparaître à plusieurs reprises: c'est normal!
                        Ne touche à rien tant que le scan n'est pas terminé.
                        * Une fois le scan achevé, un rapport va s'afficher: poste son contenu.
                        * Si le fichier ne s'ouvre pas, il se trouve ici > C:\ComboFix.txt

                        -----

                        Télécharge DaonolFix sur le bureau ici :

                        http://jpshortstuff.247fixes.com/beta/DaonolFix.exe

                        Double clique sur DaonolFix.exe qui est sur le bureau pour l'exécuter
                        Choisir l'option 1. Find Daonol
                        Laisse le scan se dérouler et poste le contenu du rapport qui est sur le bureau DaonolFix.txt

                        @++ :)
                        0
                        1. Cette dernière intervention me semble pas mal.
                          Voila le rapport de l'opération :

                          ComboFix 10-01-16.04 - JEREMY 18/01/2010 0:56.1.1 - x86
                          Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.383.152 [GMT 1:00]
                          Lancé depuis: c:\documents and settings\JEREMY\Bureau\ComboFix.exe
                          AV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
                          .

                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                          .

                          c:\$recycle.bin\S-1-5-21-2397974594-337539203-1138793434-1001
                          C:\bold.log
                          c:\docume~1\JEREMY\LOCALS~1\irdimar.bak

                          .
                          ((((((((((((((((((((((((((((( Fichiers créés du 2009-12-18 au 2010-01-18 ))))))))))))))))))))))))))))))))))))
                          .

                          2010-01-17 21:55 . 2009-08-06 18:23 274288 ----a-w- c:\windows\system32\mucltui.dll
                          2010-01-17 21:55 . 2009-08-06 18:23 215920 ----a-w- c:\windows\system32\muweb.dll
                          2010-01-17 18:31 . 2010-01-17 18:31 -------- d-----w- c:\windows\ERUNT
                          2010-01-17 18:26 . 2010-01-17 19:38 -------- d-----w- C:\SDFix
                          2010-01-17 15:22 . 2010-01-17 15:22 -------- d-----w- C:\_OTM
                          2010-01-17 14:34 . 2010-01-17 14:35 -------- d-----w- C:\rsit
                          2010-01-17 13:16 . 2010-01-17 13:16 -------- d-----w- c:\program files\Trend Micro
                          2010-01-17 11:46 . 2009-12-17 20:03 30536 ----a-w- c:\windows\system32\TURegOpt.exe
                          2010-01-17 11:46 . 2009-12-17 19:56 30024 ----a-w- c:\windows\system32\uxtuneup.dll
                          2010-01-17 11:46 . 2010-01-17 11:46 -------- d-----w- c:\documents and settings\JEREMY\Application Data\TuneUp Software
                          2010-01-17 11:46 . 2010-01-17 11:46 -------- d-----w- c:\program files\TuneUp Utilities 2010
                          2010-01-17 11:45 . 2010-01-17 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\TuneUp Software
                          2010-01-17 11:45 . 2010-01-17 11:45 -------- d-sh--w- c:\documents and settings\All Users\Application Data\{D3742F82-1C1A-4DCC-ABBD-0E7C3C0185CC}
                          2010-01-17 01:46 . 2010-01-17 01:46 -------- d-----w- c:\documents and settings\JEREMY\Application Data\Malwarebytes
                          2010-01-17 01:46 . 2010-01-17 01:46 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
                          2010-01-17 01:46 . 2010-01-17 18:30 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
                          2010-01-03 23:28 . 2010-01-03 23:28 -------- d-----w- c:\documents and settings\JEREMY\Application Data\Mozilla-Cache
                          1601-01-01 00:00 . 1601-01-01 00:00 -------- d-----w- c:\windows\LastGood.Tmp

                          .
                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          2010-01-17 23:43 . 2007-09-23 22:49 -------- d-----w- c:\documents and settings\All Users\Application Data\AntiVir PersonalEdition Classic
                          2010-01-17 23:32 . 2006-11-28 01:44 -------- d-----w- c:\program files\InstantTouch
                          2010-01-03 23:28 . 2006-12-20 21:37 -------- d-----w- c:\program files\PartyGaming.Net
                          2009-10-25 04:53 . 2004-08-05 12:00 48856 ----a-w- c:\windows\system32\perfc00C.dat
                          2009-10-25 04:53 . 2004-08-05 12:00 368076 ----a-w- c:\windows\system32\perfh00C.dat
                          .

                          ------- Sigcheck -------

                          [-] 2008-06-20 . AD978A1B783B5719720CFF204B666C8E . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp3qfe\tcpip.sys
                          [-] 2008-06-20 . 9AEFA14BD6B182D61E3119FA5F436D3D . 361600 . . [5.1.2600.5625] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp3gdr\tcpip.sys
                          [-] 2008-06-20 . 2A5554FC5B1E04E131230E3CE035C3F9 . 360320 . . [5.1.2600.3394] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp2gdr\tcpip.sys
                          [-] 2008-06-20 . 744E57C99232201AE98C49168B918F48 . 360960 . . [5.1.2600.3394] . . c:\windows\SoftwareDistribution\Download\7b6e084e897a416dad6204fec54d1e00\sp2qfe\tcpip.sys
                          [-] 2006-11-30 . 6A603809F598332DBEDD535BDBCE313E . 359040 . . [5.1.2600.2180] . . c:\windows\system32\drivers\TCPIP.SYS
                          [-] 2006-11-30 . 6A603809F598332DBEDD535BDBCE313E . 359040 . . [5.1.2600.2180] . . c:\windows\system32\dllcache\TCPIP.SYS
                          .
                          ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                          .
                          .
                          *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                          REGEDIT4

                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                          "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
                          "updateMgr"="c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 313472]

                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                          "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-05 15360]

                          c:\documents and settings\JEREMY\Menu D‚marrer\Programmes\D‚marrage\
                          ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-3-6 36864]
                          OCRAWARE.lnk - c:\oplimit\OCRAWARE.EXE [2006-11-30 51360]

                          c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
                          Adobe Gamma Loader.exe.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2009-6-30 108544]
                          Lancement rapide d'Adobe Reader.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                          "midi9"=c:\docume~1\JEREMY\LOCALS~1\irdimar.bak 2yKAHJNFFL

                          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\AVG Anti-Spyware Guard]
                          @="Service"

                          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
                          "AVG Anti-Spyware Guard"=2 (0x2)

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
                          "EnableFirewall"= 0 (0x0)

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                          "%windir%\\system32\\sessmgr.exe"=
                          "c:\\Program Files\\Messenger\\msmsgs.exe"=
                          "c:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe"=
                          "c:\\Program Files\\eMule\\emule.exe"=
                          "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
                          "c:\\Program Files\\PeerTV\\PeerCast.exe"=
                          "c:\\UT2004\\System\\UT2004.exe"=
                          "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
                          "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
                          "4662:TCP"= 4662:TCP:eMule TCP
                          "4672:UDP"= 4672:UDP:eMule UDP

                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
                          "AllowInboundEchoRequest"= 1 (0x1)
                          "AllowOutboundDestinationUnreachable"= 1 (0x1)
                          "AllowOutboundSourceQuench"= 1 (0x1)
                          "AllowOutboundTimeExceeded"= 1 (0x1)
                          "AllowRedirect"= 1 (0x1)

                          R2 CSHelper;CopySafe Helper Service;c:\windows\system32\CSHelper.exe [17/03/2009 11:40 266240]
                          R2 ScFBPNT;CanoScan FBP Port Driver;c:\windows\system32\drivers\SCFBPNT.SYS [30/11/2006 16:31 16288]
                          R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [17/12/2009 21:00 1044808]
                          R3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [14/10/2009 07:24 10064]
                          S2 FILESpy;FILESpy;\??\c:\program files\Softwin\BitDefender9\filespy.sys --> c:\program files\Softwin\BitDefender9\filespy.sys [?]
                          S3 ADM8511;Convertisseur USB vers Fast Ethernet ADMtek ADM8511/AN986;c:\windows\system32\drivers\ADM8511.SYS [22/11/2006 12:32 20160]
                          S3 DCamUSBDigitalCamera;Digital Camera;c:\windows\system32\drivers\MPIXVID.SYS [23/12/2006 04:47 104593]
                          S3 v800bus;Sony Ericsson V800-Vodafone 802SE driver (WDM);c:\windows\system32\drivers\v800bus.sys [04/09/2007 14:41 52416]
                          S3 v800mdfl;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Filter;c:\windows\system32\drivers\v800mdfl.sys [04/09/2007 14:41 6160]
                          S3 v800mdm;Sony Ericsson V800-Vodafone 802SE USB WMC Modem Driver;c:\windows\system32\drivers\v800mdm.sys [04/09/2007 14:41 84544]
                          S3 v800mgmt;Sony Ericsson V800-Vodafone 802SE USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\v800mgmt.sys [04/09/2007 14:48 77760]

                          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
                          UxTuneUp
                          .
                          Contenu du dossier 'Tâches planifiées'

                          2010-01-13 c:\windows\Tasks\AppleSoftwareUpdate.job
                          - c:\program files\Apple Software Update\SoftwareUpdate.exe [2006-08-29 13:21]

                          2010-01-18 c:\windows\Tasks\Recherche de problèmes automatique.job
                          - c:\program files\TuneUp Utilities 2010\TuneUpSystemStatusCheck.exe [2009-12-17 20:07]
                          .
                          .
                          ------- Examen supplémentaire -------
                          .
                          uStart Page = hxxp://www.noos.fr/abonnes.php
                          uInternet Connection Wizard,ShellNext = iexplore
                          IE: Barre RoboForm - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html
                          IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
                          IE: Enregistrer le formulaire - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComSavePass.html
                          IE: Personnaliser le menu - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html
                          IE: Remplir le formulaire - file://c:\program files\Siber Systems\AI RoboForm\RoboFormComFillForms.html
                          DPF: {084DAC27-6FA3-4F55-9005-033F2F102F5C} - hxxp://data.jeuxclassiques.com/npwwg.cab
                          DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} - hxxp://game05.zylom.com/activex/zylomgamesplayer.cab
                          DPF: {C49134CC-B5EF-458C-A442-E8DFE7B4645F} - hxxp://www.yoyogames.com/downloads/activex/YoYo.cab
                          .
                          - - - - ORPHELINS SUPPRIMES - - - -

                          SafeBoot-AVG Anti-Spyware Driver
                          AddRemove-HijackThis - c:\docume~1\JEREMY\LOCALS~1\Temp\Rar$EX01.324\HijackThis.exe
                          AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\program files\DivX\DivXCodecUninstall.exe

                          **************************************************************************

                          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                          Rootkit scan 2010-01-18 01:04
                          Windows 5.1.2600 Service Pack 2 NTFS

                          Recherche de processus cachés ...

                          Recherche d'éléments en démarrage automatique cachés ...

                          Recherche de fichiers cachés ...

                          Scan terminé avec succès
                          Fichiers cachés: 0

                          **************************************************************************
                          .
                          --------------------- CLES DE REGISTRE BLOQUEES ---------------------

                          [HKEY_LOCAL_MACHINE\software\Swearware\backup\winsock2]
                          @DACL=(02 0000)
                          @SACL=
                          .
                          --------------------- DLLs chargées dans les processus actifs ---------------------

                          - - - - - - - > 'explorer.exe'(2616)
                          c:\oplimit\oahook32.dll
                          c:\windows\system32\msi.dll
                          .
                          ------------------------ Autres processus actifs ------------------------
                          .
                          c:\program files\AntiVir PersonalEdition Classic\avguard.exe
                          c:\program files\AntiVir PersonalEdition Classic\sched.exe
                          c:\windows\system32\wdfmgr.exe
                          c:\oplimit\ocrawr32.exe
                          c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exe
                          c:\windows\system32\wscntfy.exe
                          .
                          **************************************************************************
                          .
                          Heure de fin: 2010-01-18 01:09:22 - La machine a redémarré
                          ComboFix-quarantined-files.txt 2010-01-18 00:09

                          Avant-CF: 34 511 286 272 octets libres
                          Après-CF: 34 620 452 864 octets libres

                          WindowsXP-KB310994-SP2-Home-BootDisk-FRA.exe
                          [boot loader]
                          timeout=2
                          default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
                          [operating systems]
                          c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
                          multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP dition familiale" /noexecute=optin /fastdetect

                          - - End Of File - - 1BD03498FEA729D2CD0312ED1EE699D1
                          0
                          1. Contributeur sécurité
                            Salut kearny

                            Télécharge combofix.exe (de sUBs) sur le bureau :

                            http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                            http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

                            Important Désactive ton Antivirus, antispyware et Pare feu avant le scan avec Combofix :
                            https://forum.pcastuces.com/default.asp
                            https://www.bleepingcomputer.com/forums/t/114351/how-to-temporarily-disable-your-anti-virus-firewall-and-anti-malware-programs/

                            ==> Sauvegarde ton travail et ferme toutes les fenêtres actives, il peut y avoir un redémarrage du PC. Ne lance aucun programme tant que Combofix n’est pas fini. <==

                            Double clique sur combofix.exe, clique sur OUI et valide par Entrée

                            Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                            NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                            Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure

                            @++ :)
                            0
                            1. ah oui ! pas bête :)

                              le rapport :

                              GMER 1.0.15.15281 - http://www.gmer.net
                              Rootkit scan 2010-01-17 23:48:02
                              Windows 5.1.2600 Service Pack 2
                              Running: 2cb649ee.exe; Driver: C:\DOCUME~1\JEREMY\LOCALS~1\Temp\awtdypow.sys

                              ---- User code sections - GMER 1.0.15 ----

                              .text C:\WINDOWS\system32\winlogon.exe[208] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
                              .text C:\WINDOWS\system32\winlogon.exe[208] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
                              .text C:\WINDOWS\system32\winlogon.exe[208] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
                              .text C:\WINDOWS\system32\winlogon.exe[208] WS2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
                              .text C:\WINDOWS\system32\winlogon.exe[208] WS2_32.dll!send 719F428A 5 Bytes JMP 10003260
                              .text C:\WINDOWS\system32\winlogon.exe[208] WS2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
                              .text C:\WINDOWS\system32\winlogon.exe[208] WS2_32.dll!recv 719F615A 5 Bytes JMP 10002788
                              .text C:\WINDOWS\system32\winlogon.exe[208] WS2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
                              .text C:\WINDOWS\system32\services.exe[256] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
                              .text C:\WINDOWS\system32\services.exe[256] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
                              .text C:\WINDOWS\system32\services.exe[256] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
                              .text C:\WINDOWS\system32\services.exe[256] ws2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
                              .text C:\WINDOWS\system32\services.exe[256] ws2_32.dll!send 719F428A 5 Bytes JMP 10003260
                              .text C:\WINDOWS\system32\services.exe[256] ws2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
                              .text C:\WINDOWS\system32\services.exe[256] ws2_32.dll!recv 719F615A 5 Bytes JMP 10002788
                              .text C:\WINDOWS\system32\services.exe[256] ws2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
                              .text C:\WINDOWS\system32\lsass.exe[268] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
                              .text C:\WINDOWS\system32\lsass.exe[268] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
                              .text C:\WINDOWS\system32\lsass.exe[268] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
                              .text C:\WINDOWS\system32\lsass.exe[268] WS2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
                              .text C:\WINDOWS\system32\lsass.exe[268] WS2_32.dll!send 719F428A 5 Bytes JMP 10003260
                              .text C:\WINDOWS\system32\lsass.exe[268] WS2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
                              .text C:\WINDOWS\system32\lsass.exe[268] WS2_32.dll!recv 719F615A 5 Bytes JMP 10002788
                              .text C:\WINDOWS\system32\lsass.exe[268] WS2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
                              .text C:\WINDOWS\system32\svchost.exe[428] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
                              .text C:\WINDOWS\system32\svchost.exe[428] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
                              .text C:\WINDOWS\system32\svchost.exe[428] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
                              .text C:\WINDOWS\system32\svchost.exe[428] ws2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
                              .text C:\WINDOWS\system32\svchost.exe[428] ws2_32.dll!send 719F428A 5 Bytes JMP 10003260
                              .text C:\WINDOWS\system32\svchost.exe[428] ws2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
                              .text C:\WINDOWS\system32\svchost.exe[428] ws2_32.dll!recv 719F615A 5 Bytes JMP 10002788
                              .text C:\WINDOWS\system32\svchost.exe[428] ws2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
                              .text C:\WINDOWS\system32\svchost.exe[496] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
                              .text C:\WINDOWS\system32\svchost.exe[496] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
                              .text C:\WINDOWS\system32\svchost.exe[496] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
                              .text C:\WINDOWS\system32\svchost.exe[496] ws2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
                              .text C:\WINDOWS\system32\svchost.exe[496] ws2_32.dll!send 719F428A 5 Bytes JMP 10003260
                              .text C:\WINDOWS\system32\svchost.exe[496] ws2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
                              .text C:\WINDOWS\system32\svchost.exe[496] ws2_32.dll!recv 719F615A 5 Bytes JMP 10002788
                              .text C:\WINDOWS\system32\svchost.exe[496] ws2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
                              .text C:\WINDOWS\system32\svchost.exe[556] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
                              .text C:\WINDOWS\system32\svchost.exe[556] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
                              .text C:\WINDOWS\system32\svchost.exe[556] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
                              .text C:\WINDOWS\system32\svchost.exe[556] ws2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
                              .text C:\WINDOWS\system32\svchost.exe[556] ws2_32.dll!send 719F428A 5 Bytes JMP 10003260
                              .text C:\WINDOWS\system32\svchost.exe[556] ws2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
                              .text C:\WINDOWS\system32\svchost.exe[556] ws2_32.dll!recv 719F615A 5 Bytes JMP 10002788
                              .text C:\WINDOWS\system32\svchost.exe[556] ws2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98
                              .text C:\WINDOWS\Explorer.EXE[780] ntdll.dll!NtOpenKey 7C91DD3C 5 Bytes JMP 10003DF0
                              .text C:\WINDOWS\Explorer.EXE[780] kernel32.dll!CreateProcessW 7C802332 5 Bytes JMP 10003C38
                              .text C:\WINDOWS\Explorer.EXE[780] kernel32.dll!ExitProcess 7C81CAA2 5 Bytes JMP 10003E74
                              .text C:\WINDOWS\Explorer.EXE[780] ws2_32.dll!connect 719F406A 5 Bytes JMP 10003AEC
                              .text C:\WINDOWS\Explorer.EXE[780] ws2_32.dll!send 719F428A 5 Bytes JMP 10003260
                              .text C:\WINDOWS\Explorer.EXE[780] ws2_32.dll!WSARecv 719F4318 5 Bytes JMP 100027F4
                              .text C:\WINDOWS\Explorer.EXE[780] ws2_32.dll!recv 719F615A 5 Bytes JMP 10002788
                              .text C:\WINDOWS\Explorer.EXE[780] ws2_32.dll!WSASend 719F6233 5 Bytes JMP 10003A98

                              ---- EOF - GMER 1.0.15 ----
                              0
                              1. Contributeur sécurité
                                Salut kearny

                                Voir en mode sans échec :

                                Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur

                                @++ :)
                                0
                                1. Le scan commence, mais à la moitié du scan, l'application se ferme.
                                  J'ai essayé toutes les situations, avec ou sans internet, avec ou sans antivirus, à chaque fois, l'application se ferme sans avertissement.
                                  0
                                  1. Contributeur sécurité
                                    Salut kearny

                                    Télécharge Gmer et enregistre-le sur ton bureau.
                                    http://www2.gmer.net/download.php

                                    Note : l'application portera un nom aléatoire. Indique-le moi dans ton prochain message.

                                    - Déconnecte toi d'internet si possible et ferme tous les programmes, puis lance l'outil.
                                    - Clique sur le bouton "Scan" sur la droite.

                                    - Lorsque le scan est terminé, clic sur "Copy".
                                    - Ouvre le bloc-note et clic sur le Menu Edition / Coller
                                    - Le rapport doit alors apparaître.

                                    - Enregistre le fichier sur ton bureau et copie/colle le contenu ici.

                                    @++ :)
                                    0
                                    1. J'ai lancé runthis en mode sans échec, je l'ai laissé faire jusqu'au redémarrage automatique.
                                      A partir de là, sur le mode normal, il a bloqué pdt 1h (j'avais replacé antivir - alors je l'ai désactivé à nouveau)
                                      et ca s'est débloqué et le report est le suivant :

                                      [b]SDFix: Version 1.240 [/b]
                                      Run by JEREMY on 17/01/2010 at 19:34

                                      Microsoft Windows XP [version 5.1.2600]
                                      Running From: C:\SDFix

                                      [b]Checking Services [/b]:

                                      Restoring Default Security Values
                                      Restoring Default Hosts File

                                      Rebooting

                                      [b]Checking Files [/b]:

                                      No Trojan Files Found

                                      Removing Temp Files

                                      [b]ADS Check [/b]:

                                      [b]Final Check [/b]:

                                      catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                      Rootkit scan 2010-01-17 20:37:35
                                      Windows 5.1.2600 Service Pack 2 NTFS

                                      scanning hidden processes ...

                                      scanning hidden services & system hive ...

                                      scanning hidden registry entries ...

                                      scanning hidden files ...

                                      scan completed successfully
                                      hidden processes: 0
                                      hidden services: 0
                                      hidden files: 0

                                      [b]Remaining Services [/b]:

                                      Authorized Application Key Export:

                                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                                      "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
                                      "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
                                      "C:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe"="C:\\Program Files\\InstantTouch\\bin\\CmCenterV2.exe:*:Enabled:CmCenter Module"
                                      "C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"
                                      "C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
                                      "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                                      "C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"="C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE:*:Enabled:Internet Explorer"
                                      "C:\\Program Files\\PeerTV\\PeerCast.exe"="C:\\Program Files\\PeerTV\\PeerCast.exe:*:Enabled:PeerCast"
                                      "C:\\Program Files\\PeerCast\\PeerCast.exe"="C:\\Program Files\\PeerCast\\PeerCast.exe:*:Enabled:PeerCast"
                                      "C:\\UT2004\\System\\UT2004.exe"="C:\\UT2004\\System\\UT2004.exe:*:Enabled:UT2004"
                                      "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
                                      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                                      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                                      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                                      "C:\\Program Files\\MSN Messenger\\msncall.exe"="C:\\Program Files\\MSN Messenger\\msncall.exe:*:Enabled:Windows Live Messenger 8.0 (Phone)"
                                      "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
                                      "C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"="C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe:*:Enabled:Windows Live Call"
                                      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

                                      [b]Remaining Files [/b]:

                                      [b]Files with Hidden Attributes [/b]:

                                      Thu 7 Dec 2006 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
                                      Thu 7 Dec 2006 4,348 A..H. --- "C:\Documents and Settings\JEREMY\Mes documents\Ma musique\Sauvegarde de la licence\drmv1key.bak"
                                      Wed 4 Apr 2007 20 A..H. --- "C:\Documents and Settings\JEREMY\Mes documents\Ma musique\Sauvegarde de la licence\drmv1lic.bak"
                                      Thu 7 Dec 2006 9,655 A.SH. --- "C:\Documents and Settings\JEREMY\Mes documents\Ma musique\Sauvegarde de la licence\drmv2key.bak"
                                      Sat 28 Mar 2009 112,703,975 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\c7335f2b91892ece82339556ae30331d\download\BIT35.tmp"

                                      [b]Finished![/b]

                                      Tu y vois un peu plus clair ? :)
                                      0
                                      1. Contributeur sécurité
                                        Salut kearny

                                        Télécharge SDFix par AndyManchesta sur le Bureau :

                                        http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

                                        Double clic sur sdfix.exe sur le bureau et clic sur Install , un dossier sera créer a la racine du disque C:\SDFix

                                        Redémarre ton PC en mode sans échec :

                                        Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur.

                                        Ouvre le dossier SDFix et double clique sur RunThis.bat, appuie sur Y pour lancer le nettoyage.

                                        Il y aura redémarrage, quand Finished s’affichera appuie sur un touche pour terminer.

                                        Poste le rapport qui se trouve dans le dossier SDFix sous le nom de Report.txt dans ta prochaine réponse.

                                        @++ :)
                                        0
                                        • 1
                                        • 2