Rootkit

Bonjour,
j'ai "chopé" un rootkit
comment le détecter ? rapport hijackthis ? et le supprimer
merci de vos lumieres

52 réponses

Résumé de la discussion

Rootkit détecté sur un PC Windows XP avec Firefox déclenche l'examen des méthodes de détection et de suppression utilisant des outils spécialisés comme GMER pour identifier les drivers et les processus malveillants. Des tutoriels et rapports GMER expliquent comment lancer le balayage, activer l’onglet rootkit et copier le rapport dans un fichier texte pour consultation ultérieure, par exemple en cas de doute. D'autres échanges évoquent la possibilité de faux positifs et les limites des outils, couvrant des questions sur la restauration système, les risques d'alerte antivirus et les signes de latence ou d'instabilité. En cas d'incrustation persistante ou de soupçon d'infection au BIOS ou à la MBR, une réinstallation propre et, si nécessaire, une réinitialisation des composants peut être nécessaire.

Bobot (l’IA à votre service)
  1. je n'utilise jamais IE ... toujours FF
    0
    1. et bien c'est le moment d'essayer
      0
  2. je ne connait pas de virus sur routeur
    tes lenteurs ? tu les a aussi avec explorer ? ou seulement avec firefox ?
    0
    1. re
      comme les antivir ne détecte à priori rien ni sur le PC filaire ni sur le portable wifi .. les 2 étant en réseau sur un modem routeur netgear .... pourrait t'il s'agir d'une infection sur le routeur ?
      par ailleurs il semble que sur le pc fixe ... les freeze et lenteurs n'apparaissent qu'avec Firefox en service !
      0
      1. Malwarebytes' Anti-Malware 1.46
        www.malwarebytes.org

        Version de la base de données: 4275

        Windows 6.0.6002 Service Pack 2
        Internet Explorer 8.0.6001.18928

        05/07/2010 02:03:36
        mbam-log-2010-07-05 (02-03-36).txt

        Type d'examen: Examen rapide
        Elément(s) analysé(s): 136265
        Temps écoulé: 10 minute(s), 18 seconde(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 0
        Valeur(s) du Registre infectée(s): 0
        Elément(s) de données du Registre infecté(s): 0
        Dossier(s) infecté(s): 0
        Fichier(s) infecté(s): 0

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Valeur(s) du Registre infectée(s):
        (Aucun élément nuisible détecté)

        Elément(s) de données du Registre infecté(s):
        (Aucun élément nuisible détecté)

        Dossier(s) infecté(s):
        (Aucun élément nuisible détecté)

        Fichier(s) infecté(s):
        (Aucun élément nuisible détecté)
        0
        1. télécharge Malwarebyte's ici http://www.malwarebytes.org/mbam/program/mbam-setup.exe
          le programme va se mettre automatiquement a jour.
          S'il manque le fichier COMCTL32.OCX, vous pourrez le télécharger ici
          https://www.malekal.com/tutorial-aboutbuster/
          Une fois a jour, le programme va se lancer; click sur l'onglet paramètre, et coche la case : "Arrêter internet explorer pendant la suppression".

          Click maintenant sur l'onglet recherche et coche la case : "executer un examen rapide".

          Puis click sur "rechercher".

          Laisse le scanner le pc...

          Si des éléments on été trouvés > click sur supprimer la sélection.

          si il t'es demandé de redémarrer > click sur "yes".

          A la fin un rapport va s'ouvrir; sauvegarde le de manière a le retrouver en vu de le poster sur le forum.

          Copie et colle le rapport stp.

          PS : les rapport sont aussi rangé dans l onglet rapport/log
          0
          1. la suite

            -----------\\ ToolBar S&D 1.2.9 XP/Vista

            Microsoft® Windows Vista(TM) Édition Familiale Premium ( v6.0.6002 ) Service Pack 2
            X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) Dual CPU T2390 @ 1.86GHz )
            BIOS : Ver 1.00PARTTBL
            USER : col ( Administrator )
            BOOT : Normal boot
            Antivirus : AntiVir Desktop 9.0.1.32 (Not Activated)
            C:\ (Local Disk) - NTFS - Total:137 Go (Free:17 Go)
            D:\ (CD or DVD)

            "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
            Option : [1] ( 02/07/2010|12:07 )

            [ UAC => 0 ]

            -----------\\ Recherche de Fichiers / Dossiers ...

            -----------\\ [..\Internet Explorer\Main]

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
            "Local Page"="C:\\Windows\\system32\\blank.htm"
            "Search Page"="http://www.durable.com/recherche"
            "Start Page"="http://www.durable.com/recherche"
            "Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
            "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
            "Default_Search_URL"="http://www.durable.com/recherche"
            "SearchMigratedDefaultURL"="http://www.durable.com/...{searchTerms}"
            "Url"="http://go.microsoft.com/fwlink/?LinkId=75720"

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
            "Start Page"="http://www.durable.com/recherche"
            "Default_Page_URL"="http://go.microsoft.com/fwlink/?LinkId=69157"
            "Default_Search_URL"="http://go.microsoft.com/fwlink/?LinkId=54896"
            "Search Page"="http://www.durable.com/recherche"
            "Local Page"="C:\\Windows\\System32\\blank.htm"

            --------------------\\ Recherche d'autres infections

            Aucune autre infection trouvée !

            [ UAC => 1 ]

            1 - "C:\ToolBar SD\TB_1.txt" - 02/07/2010|12:07 - Option : [1]

            -----------\\ Fin du rapport a 12:07:37,35
            0
            1. HJ ok : j'ai fixé les lignes demandes
              rapport AD :

              ======= RAPPORT D'AD-REMOVER 2.0.0.1,C | UNIQUEMENT XP/VISTA/7 =======

              Mis à jour par C_XX le 23/06/10 à 19:20
              Contact: AdRemover.contact@gmail.com
              Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html

              C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 11:51:49 le 02/07/2010, Mode normal

              Microsoft® Windows Vista(TM) Édition Familiale Premium Service Pack 2 (X86)
              col@PC-PORT (Packard Bell BV EasyNote MB65)

              ============== RECHERCHE ==============

              ============== SCAN ADDITIONNEL ==============

              ** Mozilla Firefox Version [3.6.6 (fr)] **

              -- C:\Users\col\AppData\Roaming\Mozilla\FireFox\Profiles\ybxe19rq.default\Prefs.js --
              browser.download.lastDir, C:\\divers
              browser.startup.homepage, hxxp://www.olweb.fr/
              browser.startup.homepage_override.mstone, rv:1.9.2.6

              ========================================

              ** Internet Explorer Version [8.0.6001.18928] **

              [HKCU\Software\Microsoft\Internet Explorer\Main]
              AutoHide: yes
              Default_Page_URL: hxxp://go.packardbell.com/?id=9136
              Default_Search_URL: hxxp://www.durable.com/recherche
              Do404Search: 0x01000000
              Enable Browser Extensions: yes
              Local Page: C:\Windows\system32\blank.htm
              Search bar: hxxp://www.google.com/ie
              Search Page: hxxp://www.durable.com/recherche
              Show_ToolBar: yes
              Start Page: hxxp://www.durable.com/recherche
              Use Search Asst: no

              [HKLM\Software\Microsoft\Internet Explorer\Main]
              AutoHide: yes
              Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
              Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
              Delete_Temp_Files_On_Exit: yes
              Local Page: C:\Windows\System32\blank.htm
              Search Page: hxxp://www.durable.com/recherche
              Start Page: hxxp://www.durable.com/recherche

              [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
              Tabs: hxxp://www.durable.com/recherche
              Blank: res://mshtml.dll/blank.htm

              ========================================

              C:\Program Files\Ad-Remover\Quarantine: 2 Fichier(s)
              C:\Program Files\Ad-Remover\Backup: 2 Fichier(s)

              C:\Ad-Report-SCAN[1].txt - 02/07/2010 (2008 Octet(s))

              Fin à: 11:55:36, 02/07/2010

              ============== E.O.F ==============

              le reste suivra
              0
              1. si ce n'est pas deja fait
                Désactivez le Contrôle d'Accès Utilisateur VISTA

                Pour cela,
                --> déroulez le menu Vista,
                -->choisirPanneau de configuration,
                -->clique sur Comptes d'utilisateurs et protection des utilisateurs
                -->puis sur Comptes d'utilisateur.
                Clique sur la mention Activer ou désactiver le contrôle des comptes utilisateurs.
                -->Clique une dernière fois sur Continuer pour confirmer.
                -->Décoche Utiliser le contrôle des comptes utilisateurs pour vous aider à protéger votre ordinateur,
                -->clique sur OK puis sur le bouton Redémarrer maintenant.
                ------------------------------------------------------------------------------
                relance hijackthis

                coche ces lignes

                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

                O3 - Toolbar: WalterShop - {9ec204df-0e48-4c32-816e-2e928a4fd9c2} - mscoree.dll (file missing)

                et clic sur Fix checked

                -----------------------------------------------------------------------------
                Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
                http://pagesperso-orange.fr/NosTools/ad_remover.html

                /!\ Déconnectes toi et fermes toutes applications en cours

                ? Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
                ? Double clique sur l'icône Ad-remover située sur ton bureau
                ? Au menu principal choisi l'option "SCAN"
                ? Postes le rapport qui apparait à la fin .

                ( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

                (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                ------------------------------
                Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
                https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cpVobGk5bHnxrhQ4yaoEUDJvOYNnEGyYjgqHZz5GqZLfutR3fMFPlsC3-CGIilfupPAguYATNyua3csodN_frdMK8sSzUpit10Yac-QJCOkMqJKkbdKcP6ySs8trWPgoNVIq4TGGWCe6o0txXQv-ZueJF9vZzw3RXsGwFYIqN2lvF2LPdQzS8mE1d5kWOVOz6EMzQuE5-lClSJM869uq3oc7-t7yg%3D%3D&attredirects=3

                * Lance l'installation du programme en exécutant le fichier téléchargé.
                * Double-clique maintenant sur le raccourci de Toolbar-S&D.
                * Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
                * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                * Poste le rapport généré. (C:\TB.txt)
                0
                1. bsr
                  pour mon portable voila un rapport HJ ;

                  Logfile of Trend Micro HijackThis v2.0.2
                  Scan saved at 22:21:38, on 01/07/2010
                  Platform: Windows Vista SP2 (WinNT 6.00.1906)
                  MSIE: Internet Explorer v8.00 (8.00.6001.18928)
                  Boot mode: Normal

                  Running processes:
                  C:\Windows\system32\Dwm.exe
                  C:\Windows\Explorer.EXE
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Windows Defender\MSASCui.exe
                  C:\Windows\System32\mobsync.exe
                  C:\Program Files\Windows Media Player\wmpnscfg.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\Windows\System32\rundll32.exe
                  C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                  C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                  C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                  C:\Program Files\Common Files\Java\Java Update\jusched.exe
                  C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                  C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  C:\Program Files\OpenOffice.org 3\program\soffice.exe
                  C:\Program Files\OpenOffice.org 3\program\soffice.bin
                  C:\Windows\system32\taskeng.exe
                  C:\Program Files\Mozilla Firefox\firefox.exe
                  C:\Program Files\Mozilla Firefox\plugin-container.exe
                  C:\Users\col\Downloads\HiJackThis.exe
                  C:\Windows\system32\SearchFilterHost.exe
                  C:\Windows\explorer.exe
                  C:\Users\col\Downloads\HiJackThis(2).exe

                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.google.com/?gws_rd=ssl
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.durable.com/recherche
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.durable.com/recherche
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.durable.com/recherche
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.durable.com/recherche
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.durable.com/recherche
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.durable.com/recherche
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.durable.com/recherche
                  R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                  R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.durable.com/recherche
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                  O1 - Hosts: ::1 localhost
                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
                  O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                  O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                  O3 - Toolbar: WalterShop - {9ec204df-0e48-4c32-816e-2e928a4fd9c2} - mscoree.dll (file missing)
                  O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                  O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
                  O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
                  O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
                  O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
                  O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                  O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                  O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
                  O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
                  O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
                  O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                  O4 - Startup: OpenOffice.org 3.1.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
                  O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                  O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                  O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
                  O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                  O9 - Extra button: Sélection intelligente HP - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                  O13 - Gopher Prefix:
                  O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
                  O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{426F8FF1-70CA-4327-B5DE-2A373C76153B}: NameServer = 80.10.246.1,80.10.246.132
                  O17 - HKLM\System\CCS\Services\Tcpip\..\{A6904922-902B-46E8-8AA2-7CE3615DF40D}: NameServer = 80.10.246.1,80.10.246.132
                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                  O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                  O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                  O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
                  O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe
                  O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                  O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                  O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
                  O23 - Service: Google Desktop Manager 5.9.1005.12335 (GoogleDesktopManager-051210-111108) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                  O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                  O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
                  O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
                  O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                  O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
                  0
                  1. toujours des pbs
                    par exemple il y a qqs minutes impossible d'ouvrir les marques pges de firefox ... la souris se déplace mais le clic est inopérant
                    dans le gestionnaire de progr ; UC utilisée à 100% et processus firefox.exe à 99%
                    ça dure qqs secondes ou au pire 30 secondes et tout redevient normal
                    qu'en penses tu ?
                    0
                    1. bien sur met moi un rapport hijackthis
                      0
                      1. il semble (????) que ça va mieux ... mais à voir dans le temps !
                        par contre mon portable (relié en wifi au modem routeur de mon réseau) rame aussi
                        pourrait on également le contrôler ?
                        0
                        1. rapport demandé :

                          ############################## | UsbFix 7.013 | [Suppression]

                          Utilisateur: bob (Administrateur) # BOB-97118BA7D2D [ ]
                          Mis à jour le 21/06/10 par El Desaparecido / C_XX
                          Lancé à 19:31:30 | 30/06/2010
                          Site Web: http://pagesperso-orange.fr/NosTools/index.html
                          Contact: FindyKill.Contact@gmail.com

                          CPU: AMD Athlon(tm) 64 Processor 3000+
                          Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 2
                          Internet Explorer 6.0.2900.2180

                          Pare-feu Windows: Activé
                          Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
                          RAM -> 990 Mo
                          C:\ (%systemdrive%) -> Disque fixe # 39 Go (27 Go libre(s) - 69%) [] # NTFS
                          D:\ -> Disque fixe # 110 Go (75 Go libre(s) - 68%) [] # NTFS
                          E:\ -> CD-ROM

                          ################## | Éléments infectieux |

                          ################## | Registre |

                          Supprimé! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

                          ################## | Mountpoints2 |

                          ################## | Listing |

                          [26/03/2010 - 03:52:05 | A | 0] C:\AUTOEXEC.BAT
                          [07/06/2010 - 15:57:54 | D ] C:\avira_anti rootkit
                          [05/04/2010 - 21:36:44 | A | 212] C:\Boot.bak
                          [14/06/2010 - 00:35:29 | RASH | 282] C:\boot.ini
                          [28/08/2001 - 14:00:00 | RASH | 4952] C:\Bootfont.bin
                          [12/06/2010 - 12:30:24 | RASHD ] C:\cmdcons
                          [03/08/2004 - 23:00:08 | A | 263488] C:\cmldr
                          [21/06/2010 - 08:11:25 | D ] C:\Config.Msi
                          [26/03/2010 - 03:52:05 | A | 0] C:\CONFIG.SYS
                          [06/04/2010 - 14:38:14 | D ] C:\DD
                          [26/03/2010 - 04:02:07 | D ] C:\Documents and Settings
                          [28/03/2010 - 00:57:09 | D ] C:\drivers
                          [27/03/2010 - 19:04:41 | A | 398848] C:\drivers_etats.doc
                          [07/04/2010 - 15:26:00 | A | 871347] C:\erreur_lors_sauvegarde.jpg
                          [28/07/2006 - 08:32:44 | A | 7005] C:\Eula.txt
                          [22/06/2010 - 22:59:28 | D ] C:\fond_ecran
                          [26/03/2010 - 03:52:05 | RASH | 0] C:\IO.SYS
                          [19/05/2010 - 14:41:05 | D ] C:\logiciels_ordi
                          [06/05/2010 - 10:15:52 | A | 127] C:\mbam-error.txt
                          [26/03/2010 - 03:52:05 | RASH | 0] C:\MSDOS.SYS
                          [03/08/2004 - 22:38:34 | RASH | 47564] C:\NTDETECT.COM
                          [03/08/2004 - 22:59:44 | RASH | 251712] C:\ntldr
                          [26/03/2010 - 16:21:58 | D ] C:\NVIDIA
                          [30/06/2010 - 09:08:46 | ASH | 1560281088] C:\pagefile.sys
                          [26/03/2010 - 11:52:58 | D ] C:\pnp
                          [14/06/2010 - 00:44:33 | RD ] C:\Program Files
                          [22/06/2010 - 12:31:10 | A | 2167] C:\rapport.txt
                          [29/06/2010 - 23:59:24 | D ] C:\rapports_antivir
                          [30/06/2010 - 19:32:15 | SHD ] C:\RECYCLER
                          [16/06/2010 - 23:57:20 | D ] C:\Rooter$
                          [18/06/2010 - 18:49:33 | SHD ] C:\System Volume Information
                          [14/06/2010 - 00:32:53 | A | 2851] C:\TCleaner.txt
                          [16/03/2009 - 12:16:58 | A | 150888] C:\Tcpvcon.exe
                          [30/10/2006 - 09:32:50 | A | 40016] C:\tcpview.chm
                          [16/03/2009 - 12:16:58 | A | 198504] C:\Tcpview.exe
                          [18/05/2010 - 22:05:18 | D ] C:\TEMP
                          [30/06/2010 - 19:32:15 | D ] C:\UsbFix
                          [30/06/2010 - 19:32:15 | A | 787] C:\UsbFix.txt
                          [22/06/2010 - 12:26:49 | D ] C:\WINDOWS
                          [23/06/2010 - 17:03:08 | A | 18750] D:\20100616-AROMAN-162298@.txt
                          [23/06/2010 - 17:11:15 | A | 52736] D:\20100616-AROMAN-162298@.xls
                          [21/06/2010 - 00:06:52 | A | 1264997795] D:\2010_06_20_sauv_thunderbird.pcv
                          [14/06/2010 - 11:10:10 | A | 858807] D:\4m3h FP2006.pdf
                          [18/05/2010 - 16:49:39 | A | 97280] D:\ann1Note-pratiqueIS-IFA2006.doc
                          [27/04/2010 - 16:05:10 | A | 20480] D:\Annonces bon coin.doc
                          [01/06/2010 - 15:57:18 | D ] D:\BUDGET
                          [28/05/2010 - 09:21:09 | D ] D:\cap_agde_scrap
                          [30/06/2010 - 14:55:16 | D ] D:\colette
                          [30/06/2010 - 09:10:53 | D ] D:\colette_bis
                          [07/04/2010 - 11:37:01 | D ] D:\colette_XP
                          [29/03/2010 - 16:50:03 | D ] D:\fichier_françois
                          [12/06/2010 - 11:39:50 | A | 6052963] D:\hp cue status.psd
                          [15/06/2010 - 19:51:08 | A | 25600] D:\impr_scan_bon_coin.doc
                          [15/06/2010 - 21:28:27 | D ] D:\mes_images
                          [27/05/2010 - 10:03:37 | D ] D:\modeles_scrap
                          [18/06/2010 - 00:16:59 | D ] D:\numerisations_temporaires
                          [25/05/2010 - 21:45:32 | D ] D:\photos_H_redimensionnées
                          [19/05/2010 - 14:42:53 | D ] D:\PHOTOS_ROME
                          [25/05/2010 - 21:48:24 | D ] D:\photos_V_redimensionnées
                          [20/06/2010 - 20:49:25 | D ] D:\PJ_thunderbird
                          [21/06/2010 - 19:55:02 | D ] D:\pour_mail
                          [18/06/2010 - 23:35:13 | A | 23040] D:\programme_peruvien.doc
                          [03/04/2010 - 14:19:10 | A | 357] D:\Raccourci vers BUDGET.lnk
                          [01/04/2010 - 00:40:14 | A | 429] D:\Raccourci vers mes_images.lnk
                          [30/06/2010 - 19:32:15 | SHD ] D:\RECYCLER
                          [17/06/2010 - 12:42:02 | A | 1215954] D:\Sans titre.bmp
                          [19/05/2010 - 14:41:46 | D ] D:\sauvegarde_thunderbird
                          [28/04/2010 - 21:26:18 | D ] D:\sauv_AdM
                          [25/05/2010 - 19:53:33 | D ] D:\sport
                          [18/06/2010 - 18:49:02 | SHD ] D:\System Volume Information
                          [09/06/2010 - 08:14:11 | A | 1139101413] D:\Thunderbird 3.0.3 (fr) - 2010-06-09.pcv
                          [09/06/2010 - 07:45:56 | A | 1401797896] D:\Thunderbird 3.0.3 (fr) - 2010-06-09_mat.pcv

                          ################## | Vaccin |

                          C:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)
                          D:\Autorun.inf -> Dossier créé par UsbFix (El Desaparecido & C_XX)

                          ################## | E.O.F |
                          0
                          1. relance usbfix
                            et cette fois fait l'option suppression

                            --> Le pc va redémarer

                            -->Après redémarrage poste le rapport UsbFix.txt

                            Note : le rapport UsbFix.txt est sauvegardé à la racine du disque
                            Note : Si le Bureau ne réapparait pas presse Ctrl + Alt + Suppr , Onglet "Fichier" , "Nouvelle tâche" , tape explorer.exe et valide!
                            0
                            1. voila le rapport demandé

                              ############################## | UsbFix 7.013 | [Recherche]

                              Utilisateur: bob (Administrateur) # BOB-97118BA7D2D [ ]
                              Mis à jour le 21/06/10 par El Desaparecido / C_XX
                              Lancé à 23:52:07 | 29/06/2010
                              Site Web: http://pagesperso-orange.fr/NosTools/index.html
                              Contact: FindyKill.Contact@gmail.com

                              CPU: AMD Athlon(tm) 64 Processor 3000+
                              Microsoft Windows XP Professionnel (5.1.2600 32-Bit) # Service Pack 2
                              Internet Explorer 6.0.2900.2180

                              Pare-feu Windows: Activé
                              Antivirus: AntiVir Desktop 9.0.1.32 [Enabled | Updated]
                              RAM -> 990 Mo
                              C:\ (%systemdrive%) -> Disque fixe # 39 Go (27 Go libre(s) - 69%) [] # NTFS
                              D:\ -> Disque fixe # 110 Go (75 Go libre(s) - 68%) [] # NTFS
                              E:\ -> CD-ROM

                              ################## | Éléments infectieux |

                              ################## | Registre |

                              Présent! HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\explorer|NoDrives

                              ################## | Mountpoints2 |

                              ################## | Vaccin |

                              (!) Cet ordinateur n'est pas vacciné!

                              ################## | E.O.F |
                              0
                              1. non c'est moi qui suis pas a jour
                                tu telecharge usbfix et tu fait le scan en cliquant sur le bouton recherche
                                0
                                1. quand j'ouvre le fichier usbfix que j'ai téléchargé .. j'ai une fenêtre avec 7 boutons ... mais pas d'installation
                                  y a t'il qq chose que je ne fais pas correctement ?
                                  0
                                  1. Télécharge UsbFix (de Chiquitine29) sur ton bureau
                                    http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe

                                    --> Lance l'installation avec les paramêtres par défaut

                                    Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptibles d avoir été infectés sans les ouvrir

                                    --> Double clic sur le raccourci UsbFix sur ton bureau

                                    Cliquez sur le bouton 3 fois sur Suivant pour passer à l'étape suivante
                                    puis Cliquez sur le bouton Démarrer et enfin Quitter

                                    Une nouvelle icône sur le bureau te permet de démarrer le programme. Double-clique dessus.
                                    Là tu fait L'option 1 Recherche

                                    connecte clés usb,,disque dur externe,,

                                    appuyez sur une touche

                                    et ne touche plus a rien pendant le scan

                                    Une fois l'analyse terminée, un rapport de scan est proposé... appuye sur une touche pour ouvrir ce rapport.
                                    copier/coller ce rapport dans ta prochaine réponse
                                    Note : le rapport UsbFix.txt est sauvegardé à la racine du disque
                                    http://pagesperso-orange.fr/NosTools/usb-1-fr.html
                                    0
                                    • 1
                                    • 2
                                    • 3