Rogue "security servise" rkill ne marche pas

Résolu
Bonjour,
Comme vous pouvez le constater j'ai choppé un rogue. Mon seul navigateur qui marche est firefox (je ne sais pas pourquoi...). Avant de poster je me suis renseigné sur les rogue et j'ai trouvé le moyen de les enlever seulement rkill ne marche pas sur mon pc donc je suis bloqué, que pui-je faire ?
quelqu'un peut-il m'aider? D'avance merci.

34 réponses

Résumé de la discussion

Le problème central est l'infection par un rogue sur Windows XP, où seul Firefox reste fonctionnel et où RKill ne semble pas suffisant pour désactiver l'infection. Des réponses proposent des méthodes concrètes: désinstaller puis redémarrer en mode sans échec, désactiver un proxy potentiellement installé, puis lancer RKill renommé et divers outils de désinfection. Les solutions recommandées incluent Malwarebytes Anti-Malware, ZHPDiag et ZHPFix pour diagnostiquer et nettoyer les traces enregistrées et fichiers, avec des rapports à partager ensuite ultérieurement. En cas de doute, des rapports techniques et des vérifications complémentaires sont évoqués, notamment pour vérifier le proxy et l'intégrité des postes avant de poursuivre la désinfection.

Bobot (l’IA à votre service)
  1. Contributeur
    Bonjour,

    Ok, maintenant :

    <|> Pour supprimer tout les outils :

    ¤ Relancer ZHPDiag et générer un rapport en appuyant sur la loupe en haut à gauche.
    ¤ A la fin du chargement, cliquer en haut à droite sur l'icône du bouclier vert pour lancer ZHPfix.
    ¤ Appuyer maintenant sur le A rouge en haut pour lancer la suppression des outils.
    ¤ Sélectionner tout les outils en appuyant sur "Tous" (tous les outils sont cochés par défaut) et cliquer ensuite sur "Nettoyer".
    ¤ Redémarrer à la demande.

    <|> Un petit coup de Ccleaner :

    Utilise ce programme pour optimiser ton ordinateur :

    ¤ Télécharge CCleaner Slim.
    ¤ Installe le puis lance le.
    ¤ Clique sur Nettoyeur > Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s'affiche.
    ¤ Enfin, clique sur Registre > corrige toutes les erreurs et recommence jusqu'à ce que CCleaner ne trouve plus d'erreurs.

    Tu peux garder ce programme et l'utiliser régulièrement (une fois par mois).

    <|> La restauration du système a peut être été touchée, le mieux est de la purger (la désactiver et la réactiver) :

    ¤ Sous XP :
    o Aller au menu démarrer et cliquer droit sur "Poste de travail" et sélectionner "Propriétés"
    o Dans l'onglet "Restauration du système", cocher "Désactiver la restauration du système sur tout les lecteurs"
    o Cliquer sur appliquer et confirmer (tout les points de restauration sont supprimés).
    o Décocher la case "Désactiver la restauration du système sur tout les lecteurs" et cliquer sur Appliquer pour réactiver la restauration du système.

    ¤ Sous Vista/Seven :
    o Aller au menu démarrer et cliquer droit sur "Ordinateur" puis sélectionner "Propriétés"
    o Cliquer sur "Protection du système"
    o Décocher la case du ou des disques pour lesquels on veut désactiver la restauration du système
    o Cliquer sur OK et confirmer (tout les points de restauration sont supprimés).
    o Recocher la case des disques pour lesquels on veut réactiver la restauration du système et valider.

    Créer un point de restauration propre pour finir :

    ¤ Sous XP :
    o Aller au menu demarrer
    o Dans "Tous les programmes"
    o Dans "Accessoires"
    o Dans "outils système"
    o Cliquer sur "restauration du système"
    o Cocher "Créer un point de restauration" et cliquer sur "Suivant"
    o Entrer une description n'importe du point de restauration puis cliquer sur "Créer"
    o Le point se crée, cliquer sur fermer pour quitter la restauration du système

    ¤ Sous Vista :
    o Dans le menu démarrer, puis "Rechercher", taper "restauration", puis cliquer sur "Centre de sauvegarde et de restauration"
    o Puis sur le volet de gauche, cliquer sur "Créer un point de restauration ou modifier les paramètres"
    o L'onglet Protection du système s'ouvre, vérifier que votre disque soit bien coché, puis cliquer sur "Créer"
    o Entrer une description pour identifier facilement le point de restauration, puis cliquer sur Créer
    o Le point de restauration se crée, un message de réussite apparaît : le point a été créé, refermer les fenêtres.

    ¤ Sous Seven :
    o Dans Démarrer, puis "Rechercher", taper "restauration", puis cliquer sur "Créer un point de restauration"
    o L'onglet Protection du système s'ouvre, vérifier que la protection sur votre disque soit bien activée, puis cliquer sur "Créer"
    o Entrer une description pour identifier facilement le point de restauration, puis cliquer sur "Créer"
    o Le point de restauration se crée, un message de réussite apparaît : le point a été créé, refermer les fenêtres.

    <|> Pour garder un PC propre, il faut tout d'abord installer une protection, ce qui veut dire, installer un antivirus, un antispyware et un pare feu, voila quelques conseils :
    Antivirus payant -> Kaspersky, Antivirus gratuit -> Avira antivir / Avast
    Antispyware payant -> Malwarebytes Antimalware, Antispyware gratuit -> SuperAntispyware
    Pare feu payant -> ZoneAlarm, Pare feu gratuit -> COMODO.>>> Tuto COMODO
    Toute fois, on est jamais assez prudent, il faut faire attention à son comportement sur le net, les cracks les keygens la P2P sont tous à bannir.
    Une autre précaution à prendre, les mises à jour, celles ci sont contrairement à ce que la plupart des gens pensent très très importantes, les application les plus importantes à mettre à jour sont : Adobe Reader, Java, Flash player et les mises à jour windows, voilà un logiciel très léger et utile pour les mises à jour (éviter les bêtas) > File Hippo Update Cheker

    Voilà aussi quelques liens utiles
    Les mises à jour Windows
    Les mises de Adobe Reader et Java et Flash player
    Le danger des cracks
    Les toolbars
    Comparatif Antivirus
    Comparatif Antivirus
    Les infections USB

    Et bon surf ;)

    ++
    Karel
    0
    1. Contributeur
      Tu peut mettre le sujet en résolu ;)
      0
  2. voila le scan

    Rapport de ZHPFix v1.12.3135 par Nicolas Coolman, Update du 18/08/2010
    Fichier d'export Registre : C:\ZHPExportRegistry-21-08-2010-15-52-30.txt
    Run by HP_Propriétaire at 21/08/2010 15:52:30
    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
    Contact : nicolascoolman@yahoo.fr

    ========== Clé(s) du Registre ==========
    HKCU\Software\wnxmal => Clé supprimée avec succès

    ========== Récapitulatif ==========
    1 : Clé(s) du Registre

    End of the scan
    0
    1. Contributeur
      Bonjour,

      Le rapport est clean, reste seulement une clé du registre récalcitrante que nous devons éliminer :

      ¤ Lance ZHPFix (soit via le raccourci sur ton Bureau, soit via ZHPDiag) (Sous Vista/Seven, clique droit "Executer en tant qu'administrateur")
      ¤ Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
      ¤ Copie/colle les lignes suivantes et place les dans ZHPFix :

      ______________________________________________
      [HKCU\Software\wnxmal]
      ______________________________________________


      ¤ Clique sur « Tous », puis sur « Nettoyer »
      ¤ Copie/colle la totalité du rapport dans ta prochaine réponse

      ++
      Karel
      0
      1. voici le dernier scan

        http://www.cijoint.fr/cjlink.php?file=cj201008/cijuFTNbMZ.txt
        0
        1. Contributeur
          Bonjour,

          Très bien pour OTM.
          Pour ZHPfix, je crois que tu as par faute ajouté des lignes du rapport d'OTM, l'outil ne les a pas reconnues, il n'a donc heureusement rien fait, fait plus attention la prochaine fois car tu risque de mettre le bon fonctionnement de ton PC en danger.
          Pour MBAM, il a fait du bon travail, il a éliminé le rogue, maintenant, poste un autre rapport ZHPDiag pour voir ;) (n'oublie pas de le mettre sur cijoint)

          ++
          Karel
          0
          1. visiblement le rogue est parti je te remercie :)
            0
            1. voila le rapport
              Malwarebytes' Anti-Malware 1.46
              www.malwarebytes.org

              Version de la base de données: 4450

              Windows 5.1.2600 Service Pack 2
              Internet Explorer 7.0.5730.11

              20/08/2010 02:24:38
              mbam-log-2010-08-20 (02-24-38).txt

              Type d'examen: Examen complet (C:\|D:\|)
              Elément(s) analysé(s): 200409
              Temps écoulé: 54 minute(s), 52 seconde(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 4
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 4
              Fichier(s) infecté(s): 12

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bhgvvtyj (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\bhgvvtyj (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
              HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wviofgko (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wviofgko (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997} (Adware.ResultDns) -> Delete on reboot.
              C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\chrome (Adware.ResultDns) -> Delete on reboot.
              C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\defaults (Adware.ResultDns) -> Quarantined and deleted successfully.
              C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\defaults\preferences (Adware.ResultDns) -> Quarantined and deleted successfully.

              Fichier(s) infecté(s):
              C:\Documents and Settings\HP_Propriétaire\Application Data\kahmbiisi\xfaocaoshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
              C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\imcmbavkv\xnoijdqshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
              C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\kahmbiisi\xfaocaoshdw.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP21\A0003063.exe (Adware.ResultDns) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP22\A0003165.exe (Adware.ResultDns) -> Quarantined and deleted successfully.
              C:\System Volume Information\_restore{86E11626-5203-4B6B-99A3-889F6E4C5699}\RP22\A0003172.exe (Adware.ResultDns) -> Quarantined and deleted successfully.
              C:\_OTM\MovedFiles\08202010_005902\C_Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe (Adware.ResultDns) -> Quarantined and deleted successfully.
              C:\_OTM\MovedFiles\08202010_005902\C_Program Files\ResultDns\resultdns.exe (Adware.ResultDns) -> Quarantined and deleted successfully.
              C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\chrome.manifest (Adware.ResultDns) -> Quarantined and deleted successfully.
              C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\install.rdf (Adware.ResultDns) -> Quarantined and deleted successfully.
              C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\chrome\resultdns.jar (Adware.ResultDns) -> Delete on reboot.
              C:\Program Files\Mozilla Firefox\extensions\{1A615EA8-4C56-49EE-BE83-F9A264B79997}\defaults\preferences\prefs.js (Adware.ResultDns) -> Quarantined and deleted successfully.
              0
              1. sinon je ne sais pas si il y un rapport mais mon antivirus (avira) m'affiche un message d'alerte comme quoi un fichier contient le cheval de troie

                TR/Crypt.XPACK.Gen
                0
                1. je viens de lancer MBAM ......
                  0
                  1. Rapport de ZHPFix v1.12.3135 par Nicolas Coolman, Update du 18/08/2010
                    Fichier d'export Registre : C:\ZHPExportRegistry-20-08-2010-01-11-45.txt
                    Run by HP_Propriétaire at 20/08/2010 01:11:45
                    Web site : http://www.premiumorange.com/zeb-help-process/zhpfix.html
                    Contact : nicolascoolman@yahoo.fr

                    ========== Processus mémoire ==========
                    C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe moved successfully. => Fichier absent
                    C:\Program Files\ResultDns\resultdns.exe moved successfully. => Fichier absent

                    ========== Clé(s) du Registre ==========
                    O42 - Logiciel: ResultDns 1.0 build 113 - (.Pas de propriétaire.) [HKLM] -- ResultDns => Clé supprimée avec succès
                    O23 - Service: ResultDns Service (ResultDns Service) . (.Pas de propriétaire - Pas de description.) - C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe => Clé supprimée avec succès
                    O64 - Services: CurCS - C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe - ResultDns Service (ResultDns Service) .(.Pas de propriétaire - Pas de description.) - LEGACY_RESULTDNS_SERVICE => Clé supprimée avec succès

                    ========== Valeur(s) du Registre ==========
                    O4 - HKUS\S-1-5-21-1282220339-793324306-1302408614-1007\..\Run: [GabPath] C:\Documents and Settings\HP_Propriétaire\Application Data\GabPath\gabpath.exe (.not file.) => Valeur supprimée avec succès
                    O4 - HKCU\..\Run: [GabPath] C:\Documents and Settings\HP_Propriétaire\Application Data\GabPath\gabpath.exe (.not file.) => Valeur absente

                    ========== Dossier(s) ==========
                    C:\Program Files\ResultDns => Supprimé et mis en quarantaine

                    ========== Logiciel(s) ==========
                    O42 - Logiciel: ResultDns 1.0 build 113 - (.Pas de propriétaire.) [HKLM] -- ResultDns => Logiciel non supprimé

                    ========== Autre ==========
                    All processes killed => Format Non supporté
                    ========== FILES ========== => Format Non supporté
                    ========== COMMANDS ========== => Format Non supporté
                    [EMPTYTEMP] => Format Non supporté
                    User: Administrateur => Format Non supporté
                    ->Temp folder emptied: 70231 bytes => Format Non supporté
                    ->Temporary Internet Files folder emptied: 32902 bytes => Format Non supporté
                    ->FireFox cache emptied: 3355436 bytes => Format Non supporté
                    User: All Users => Format Non supporté
                    User: Default User => Format Non supporté
                    ->Temp folder emptied: 70231 bytes => Format Non supporté
                    ->Temporary Internet Files folder emptied: 32768 bytes => Format Non supporté
                    User: HP_Propriétaire => Format Non supporté
                    ->Temp folder emptied: 38233980 bytes => Format Non supporté
                    ->Temporary Internet Files folder emptied: 113476 bytes => Format Non supporté
                    ->Java cache emptied: 0 bytes => Format Non supporté
                    ->FireFox cache emptied: 40317021 bytes => Format Non supporté
                    ->Google Chrome cache emptied: 0 bytes => Format Non supporté
                    ->Flash cache emptied: 834 bytes => Format Non supporté
                    User: LocalService => Format Non supporté
                    ->Temp folder emptied: 115616 bytes => Format Non supporté
                    ->Temporary Internet Files folder emptied: 4456833 bytes => Format Non supporté
                    User: NetworkService => Format Non supporté
                    ->Temp folder emptied: 0 bytes => Format Non supporté
                    ->Temporary Internet Files folder emptied: 33170 bytes => Format Non supporté
                    %systemdrive% .tmp files removed: 0 bytes => Format Non supporté
                    %systemroot% .tmp files removed: 0 bytes => Format Non supporté
                    %systemroot%\System32 .tmp files removed: 3072 bytes => Format Non supporté
                    %systemroot%\System32\dllcache .tmp files removed: 0 bytes => Format Non supporté
                    %systemroot%\System32\drivers .tmp files removed: 0 bytes => Format Non supporté
                    Windows Temp folder emptied: 1328744 bytes => Format Non supporté
                    %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 70231 bytes => Format Non supporté
                    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes => Format Non supporté
                    RecycleBin emptied: 0 bytes => Format Non supporté
                    Total Files Cleaned = 84,00 mb => Format Non supporté
                    OTM by OldTimer - Version 3.1.15.0 log created on 08202010_005902 => Format Non supporté
                    Files moved on Reboot... => Format Non supporté

                    ========== Récapitulatif ==========
                    2 : Processus mémoire
                    3 : Clé(s) du Registre
                    2 : Valeur(s) du Registre
                    1 : Dossier(s)
                    1 : Logiciel(s)
                    37 : Autre

                    End of the scan
                    0
                    1. voila le rapport de OTM

                      All processes killed
                      ========== FILES ==========
                      C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe moved successfully.
                      C:\Program Files\ResultDns\resultdns.exe moved successfully.
                      ========== COMMANDS ==========

                      [EMPTYTEMP]

                      User: Administrateur
                      ->Temp folder emptied: 70231 bytes
                      ->Temporary Internet Files folder emptied: 32902 bytes
                      ->FireFox cache emptied: 3355436 bytes

                      User: All Users

                      User: Default User
                      ->Temp folder emptied: 70231 bytes
                      ->Temporary Internet Files folder emptied: 32768 bytes

                      User: HP_Propriétaire
                      ->Temp folder emptied: 38233980 bytes
                      ->Temporary Internet Files folder emptied: 113476 bytes
                      ->Java cache emptied: 0 bytes
                      ->FireFox cache emptied: 40317021 bytes
                      ->Google Chrome cache emptied: 0 bytes
                      ->Flash cache emptied: 834 bytes

                      User: LocalService
                      ->Temp folder emptied: 115616 bytes
                      ->Temporary Internet Files folder emptied: 4456833 bytes

                      User: NetworkService
                      ->Temp folder emptied: 0 bytes
                      ->Temporary Internet Files folder emptied: 33170 bytes

                      %systemdrive% .tmp files removed: 0 bytes
                      %systemroot% .tmp files removed: 0 bytes
                      %systemroot%\System32 .tmp files removed: 3072 bytes
                      %systemroot%\System32\dllcache .tmp files removed: 0 bytes
                      %systemroot%\System32\drivers .tmp files removed: 0 bytes
                      Windows Temp folder emptied: 1328744 bytes
                      %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 70231 bytes
                      %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
                      RecycleBin emptied: 0 bytes

                      Total Files Cleaned = 84,00 mb

                      OTM by OldTimer - Version 3.1.15.0 log created on 08202010_005902

                      Files moved on Reboot...

                      Registry entries deleted on Reboot...
                      0
                      1. Contributeur
                        Ce n'est pas AD-R
                        qui devrait éliminer le rogue mais des Adwares, c'est sa specialité, nous allons maintenant nous occuper de notre rogue, comme ceci ;) :

                        ¤ Télécharge OTM (OtmoveIT de Old_Timer) sur ton Bureau
                        ¤ Double-clique sur OTM.exe pour le lancer.
                        ¤ Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTM sous Paste Instructions for Items to be Moved.

                        -----------------------------
                        :files
                        C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe
                        C:\Program Files\ResultDns\resultdns.exe
                        :commands
                        [purity]
                        [emptytemp]
                        -----------------------------

                        ¤ Clique sur MoveIt! puis ferme OTM.
                        ¤ Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                        ¤ Accepte en cliquant sur YES.
                        ¤ Poste le rapport situé dans C:\_OTM\MovedFiles.
                        ¤ Le nom du rapport correspond au moment de sa création : date_heure.log

                        Ensuite :

                        ¤ Lance ZHPFix (soit via le raccourci sur ton Bureau, soit via ZHPDiag) (Sous Vista/Seven, clique droit "Executer en tant qu'administrateur")
                        ¤ Clique sur l'icone représentant la lettre H (« coller les lignes Helper »)
                        ¤ Copie/colle les lignes suivantes et place les dans ZHPFix :

                        ----------------------------------------------------------
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = <local>
                        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6522
                        O4 - HKUS\S-1-5-21-1282220339-793324306-1302408614-1007\..\Run: [GabPath] C:\Documents and Settings\HP_Propriétaire\Application Data\GabPath\gabpath.exe (.not file.)
                        O4 - HKCU\..\Run: [GabPath] C:\Documents and Settings\HP_Propriétaire\Application Data\GabPath\gabpath.exe (.not file.)
                        O23 - Service: ResultDns Service (ResultDns Service) . (.Pas de propriétaire - Pas de description.) - C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe
                        O42 - Logiciel: ResultDns 1.0 build 113 - (.Pas de propriétaire.) [HKLM] -- ResultDns
                        O43 - CFD:Common File Directory ----D- C:\Program Files\ResultDns
                        O64 - Services: CurCS - C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe - ResultDns Service (ResultDns Service) .(.Pas de propriétaire - Pas de description.) - LEGACY_RESULTDNS_SERVICE
                        ----------------------------------------------------------

                        ¤ Clique sur « Tous », puis sur « Nettoyer »
                        ¤ Copie/colle la totalité du rapport dans ta prochaine réponse

                        Après avoir fait tout ceci, essaye d'utiliser Malwarebytes et cette fois, retélécharge le et renomme le par ton nom par exemple avant de l'executer

                        ++
                        Karel
                        0
                        1. j'ai fait nettoyer avec AD-R on m'a conseillé de redémarer l'ordi pour finir le nettoyage je l'ai fait et le rogue était toujours la. du coup j'ai réactivé Rkill. Il est coriace !!
                          0
                          1. tient voila le rapport de ZFPFix

                            http://www.cijoint.fr/cjlink.php?file=cj201008/cijjTWXbHb.txt
                            0
                            1. Contributeur
                              Re,

                              je crois qu'il n'a rien trouvé d'anormal ... non?

                              Si, il en a trouvé, tu doit le relancer et cliquer cette fois sur "nettoyer" car tu as fait un scan
                              Et n'oublie pas le rapport ZHPDiag ;), celui ci nous donnera toute les informations nécessaires pour te désinfecter ;)
                              0
                              1. ======= RAPPORT D'AD-REMOVER 2.0.0.1,D | UNIQUEMENT XP/VISTA/7 =======

                                Mis à jour par C_XX le 26/07/10 à 12:00
                                Contact: AdRemover.contact[AT]gmail.com
                                Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html

                                C:\Program Files\Ad-Remover\main.exe (SCAN [1]) -> Lancé à 22:49:42 le 19/08/2010, Mode normal

                                Microsoft Windows XP Édition familiale Service Pack 2 (X86)
                                HP_Propriétaire@NOM-641695C7437 ( )

                                ============== RECHERCHE ==============

                                0,Dossier trouvé: C:\WINDOWS\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE}
                                0,Fichier trouvé: C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
                                0,Dossier trouvé: C:\Program Files\Ask.com
                                0,Dossier trouvé: C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\AskToolbar
                                0,Dossier trouvé: C:\Documents and Settings\HP_Propriétaire\Local Settings\Application Data\Conduit
                                0,Dossier trouvé: C:\Program Files\Conduit
                                0,Dossier trouvé: C:\Documents and Settings\HP_Propriétaire\Application Data\GabPath
                                3,Fichier trouvé: C:\WINDOWS\Installer\1bf7b0.msi

                                -- Fichier ouvert: C:\Documents and Settings\HP_Propriétaire\Application Data\Mozilla\FireFox\Profiles\uj0wmv2q.default\Prefs.js --
                                Ligne trouvée: user_pref("browser.startup.homepage", "hxxp://search.conduit.com/?SearchSource=10&ctid=CT1750559");
                                -- Fichier Fermé --

                                1,Clé trouvée: HKLM\Software\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC}
                                1,Clé trouvée: HKLM\Software\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}
                                1,Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}
                                1,Clé trouvée: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
                                1,Clé trouvée: HKLM\Software\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456}
                                1,Clé trouvée: HKLM\Software\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92}
                                1,Clé trouvée: HKLM\Software\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E}
                                1,Clé trouvée: HKLM\Software\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}
                                0,Clé trouvée: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd
                                0,Clé trouvée: HKLM\Software\Classes\GenericAskToolbar.ToolbarWnd.1
                                0,Clé trouvée: HKLM\Software\Classes\Toolbar.CT1750559
                                0,Clé trouvée: HKLM\Software\Classes\AppID\GenericAskToolbar.DLL
                                1,Clé trouvée: HKLM\Software\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874}
                                0,Clé trouvée: HKLM\Software\Conduit
                                0,Clé trouvée: HKCU\Software\Ask.com
                                0,Clé trouvée: HKCU\Software\AskToolbar
                                0,Clé trouvée: HKCU\Software\Conduit
                                0,Clé trouvée: HKCU\Software\AppDataLow\AskToolbarInfo
                                0,Clé trouvée: HKU\.DEFAULT\Software\AskToolbar
                                0,Clé trouvée: HKU\.DEFAULT\Software\Conduit
                                0,Clé trouvée: HKU\S-1-5-18\Software\AskToolbar
                                0,Clé trouvée: HKU\S-1-5-18\Software\Conduit
                                3,Clé trouvée: HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
                                3,Clé trouvée: HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A}
                                0,Clé trouvée: HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE}

                                0,Valeur trouvée: HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks|{00000000-6E41-4FD3-8538-502F5495E5FC}
                                0,Valeur trouvée: HKLM\Software\Microsoft\Internet Explorer\Toolbar|{D4027C7F-154A-4066-A1AD-4243D8127440}
                                0,Valeur trouvée: HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser|{D4027C7F-154A-4066-A1AD-4243D8127440}

                                ============== SCAN ADDITIONNEL ==============

                                ** Mozilla Firefox Version [3.5.11 (fr)] **

                                -- C:\Documents and Settings\HP_Propriétaire\Application Data\Mozilla\FireFox\Profiles\uj0wmv2q.default\Prefs.js --
                                browser.startup.homepage, hxxp://search.conduit.com/?SearchSource=10&ctid=CT1750559
                                browser.startup.homepage_override.mstone, rv:1.9.1.11

                                -- C:\Documents and Settings\Administrateur\Application Data\Mozilla\FireFox\Profiles\c9bogv4y.default\Prefs.js --
                                browser.startup.homepage_override.mstone, rv:1.9.1.11

                                ========================================

                                ** Internet Explorer Version [7.0.5730.11] **

                                [HKCU\Software\Microsoft\Internet Explorer\Main]
                                Default_Page_URL: hxxp://www.01net.com/telecharger/
                                Default_Search_URL: hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                                Do404Search: 0x01000000
                                Enable Browser Extensions: yes
                                Local Page: C:\WINDOWS\system32\blank.htm
                                Search Page: hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                                Show_ToolBar: yes
                                Start Page: hxxp://www.google.com/
                                Use Search Asst: no

                                [HKLM\Software\Microsoft\Internet Explorer\Main]
                                Default_Page_URL: hxxp://www.01net.com/telecharger/
                                Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                                Delete_Temp_Files_On_Exit: yes
                                Local Page: C:\WINDOWS\system32\blank.htm
                                Search bar: hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=FR_FR&c=Q404&bd=pavilion&pf=desktop
                                Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
                                Start Page: hxxp://www.01net.com/telecharger/

                                [HKLM\Software\Microsoft\Internet Explorer\ABOUTURLS]
                                Tabs: res://ieframe.dll/tabswelcome.htm
                                Blank: res://mshtml.dll/blank.htm

                                ========================================

                                C:\Program Files\Ad-Remover\Quarantine: 0 Fichier(s)
                                C:\Program Files\Ad-Remover\Backup: 1 Fichier(s)

                                C:\Ad-Report-SCAN[1].txt - 19/08/2010 (5415 Octet(s))

                                Fin à: 22:53:13, 19/08/2010

                                ============== E.O.F ==============

                                je crois qu'il n'a rien trouvé d'anormal ... non?
                                0
                                1. Contributeur
                                  Re,

                                  a la fin du rapport de ZHPDiag ecrit ceci
                                  
                                  ---\\ Infection BT - BHO/Toolbar (Possible)
                                  R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} . (.Ask.com - Ask.com Toolbar.) (5.6.9.135) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
                                  O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} . (.Ask.com - Ask.com Toolbar.) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
                                  O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} . (.Ask.com - Ask.com Toolbar.) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
                                  O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM] -- {86D4B82A-ABED-442A-BE86-96357B70F4FE}
                                  [HKCU\Software\Ask.com] 


                                  Ok, nous avons des infections mais pourquoi est ce que tu n'as pas posté le rapport complet ?? note qu'il est trop long donc tu le met sur cijoint ;)
                                  Pour traiter les infections :

                                  ¤ Télécharge AD-Remover (de C_XX) sur ton Bureau.
                                  /!\ Déconnecte toi et ferme toutes les applications en cours /!\
                                  ¤ Double-clique sur l'icône AD-Remover
                                  ¤ Au menu principal, clique sur "Nettoyer"
                                  ¤ Confirme le lancement de l'analyse et laisse l'outil travailler
                                  ¤ Poste le rapport qui apparait à la fin (il est aussi sauvegardé sous C:\Ad-report-CLEAN.txt )

                                  (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

                                  ++
                                  Karel
                                  0
                                  1. voila le premeier rapport

                                    0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
                                    File name:
                                    GoogleUpdate.exe
                                    Submission date:
                                    2010-08-19 19:52:10 (UTC)
                                    Current status:
                                    finished
                                    Result:
                                    0 /41 (0.0%)

                                    VT Community

                                    not reviewed
                                    Safety score: -
                                    Compact
                                    Print results
                                    Antivirus Version Last Update Result
                                    AhnLab-V3 2010.08.19.01 2010.08.19 -
                                    AntiVir 8.2.4.38 2010.08.19 -
                                    Antiy-AVL 2.0.3.7 2010.08.16 -
                                    Authentium 5.2.0.5 2010.08.19 -
                                    Avast 4.8.1351.0 2010.08.19 -
                                    Avast5 5.0.332.0 2010.08.19 -
                                    AVG 9.0.0.851 2010.08.19 -
                                    BitDefender 7.2 2010.08.19 -
                                    CAT-QuickHeal 11.00 2010.08.19 -
                                    ClamAV 0.96.2.0-git 2010.08.19 -
                                    Comodo 5786 2010.08.19 -
                                    DrWeb 5.0.2.03300 2010.08.19 -
                                    Emsisoft 5.0.0.37 2010.08.19 -
                                    eSafe 7.0.17.0 2010.08.19 -
                                    eTrust-Vet 36.1.7801 2010.08.19 -
                                    F-Prot 4.6.1.107 2010.08.19 -
                                    F-Secure 9.0.15370.0 2010.08.19 -
                                    Fortinet 4.1.143.0 2010.08.19 -
                                    GData 21 2010.08.19 -
                                    Ikarus T3.1.1.88.0 2010.08.19 -
                                    Jiangmin 13.0.900 2010.08.19 -
                                    Kaspersky 7.0.0.125 2010.08.19 -
                                    McAfee 5.400.0.1158 2010.08.19 -
                                    McAfee-GW-Edition 2010.1B 2010.08.19 -
                                    Microsoft 1.6004 2010.08.19 -
                                    NOD32 5380 2010.08.19 -
                                    Norman 6.05.11 2010.08.19 -
                                    nProtect 2010-08-19.01 2010.08.19 -
                                    Panda 10.0.2.7 2010.08.19 -
                                    PCTools 7.0.3.5 2010.08.19 -
                                    Prevx 3.0 2010.08.19 -
                                    Rising 22.61.03.04 2010.08.19 -
                                    Sophos 4.56.0 2010.08.19 -
                                    Sunbelt 6762 2010.08.19 -
                                    SUPERAntiSpyware 4.40.0.1006 2010.08.19 -
                                    Symantec 20101.1.1.7 2010.08.19 -
                                    TheHacker 6.5.2.1.351 2010.08.19 -
                                    TrendMicro 9.120.0.1004 2010.08.19 -
                                    TrendMicro-HouseCall 9.120.0.1004 2010.08.19 -
                                    ViRobot 2010.8.16.3990 2010.08.19 -
                                    VirusBuster 5.0.27.0 2010.08.19 -
                                    Additional information
                                    Show all
                                    MD5 : 8f0de4fef8201e306f9938b0905ac96a
                                    SHA1 : d2e2915087427be8ea88b4a174c334c578208e78
                                    SHA256: ca7153fe0c037d79fbf7ce0e090d741fb52bccbbbd4ca505ef4849a0c4199f72
                                    ssdeep: 3072:EK5b1edk0bT5ni+lRd4ESGf4Fv5NR2OnCW8DCUck/CJcd+F9UK/r1F2aTwXZg0bQ:EK5bZ
                                    yNi+RS
                                    File size : 135664 bytes
                                    First seen: 2009-10-28 01:12:22
                                    Last seen : 2010-08-19 19:52:10
                                    Magic: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
                                    TrID:
                                    Win64 Executable Generic (59.6%)
                                    Win32 Executable MS Visual C++ (generic) (26.2%)
                                    Win32 Executable Generic (5.9%)
                                    Win32 Dynamic Link Library (generic) (5.2%)
                                    Generic Win/DOS Executable (1.3%)
                                    sigcheck:
                                    publisher....: Google Inc.
                                    copyright....: Copyright 2007-2009 Google Inc.
                                    product......: Google Update
                                    description..: Google Installer
                                    original name: GoogleUpdate.exe
                                    internal name: Google Update
                                    file version.: 1.2.183.9
                                    comments.....: n/a
                                    signers......: Google Inc
                                    VeriSign Class 3 Code Signing 2004 CA
                                    Class 3 Public Primary Certification Authority
                                    signing date.: 12:04 AM 10/14/2009
                                    verified.....: -
                                    PEiD: -
                                    PEInfo: PE structure information

                                    [[ basic data ]]
                                    entrypointaddress: 0x50CE
                                    timedatestamp....: 0x4AD50798 (Tue Oct 13 23:04:56 2009)
                                    machinetype......: 0x14C (Intel I386)

                                    [[ 4 section(s) ]]
                                    name, viradd, virsiz, rawdsiz, ntropy, md5
                                    .text, 0x1000, 0xD00B, 0xD200, 6.64, a3b9b6e46995b81015b176e0de2b1fa6
                                    .data, 0xF000, 0x2EA8, 0x1200, 2.41, 23bda919485d01c8e04b1f0f502dcff1
                                    .text_DE, 0x12000, 0x318E, 0x3200, 5.36, 7c96b0385c61b0fee276d13b535c06aa
                                    .rsrc, 0x16000, 0xE0F8, 0xE200, 4.22, 1f2935791db10c014809279836295dbb

                                    [[ 3 import(s) ]]
                                    advapi32.dll: GetTokenInformation, OpenProcessToken, RegOpenKeyExW
                                    kernel32.dll: GetCurrentProcess, GetProcAddress, SizeofResource, lstrlenW, FindResourceExW, FindResourceW, CloseHandle, FreeLibrary, GetCommandLineW, GetModuleFileNameW, RaiseException, LoadResource, GetModuleHandleW, LockResource, GetFileAttributesExW, VerifyVersionInfoW, LoadLibraryExW, VerSetConditionMask, GetLastError, SetLastError, LocalAlloc, SetStdHandle, SetFilePointer, InterlockedExchange, LoadLibraryA, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, GetVersionExA, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, GetCurrentThreadId, InterlockedDecrement, WideCharToMultiByte, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsA, MultiByteToWideChar, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, SetHandleCount, GetFileType, GetStartupInfoA, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, VirtualAlloc, RtlUnwind, Sleep, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, GetLocaleInfoA, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, GetConsoleCP, GetConsoleMode, FlushFileBuffers, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA
                                    ole32.dll: CoCreateGuid

                                    VT Community

                                    0

                                    This file has never been reviewed by any VT Community member. Be the first one to comment on it!

                                    VirusTotal Team

                                    et voila le deuxieme

                                    0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
                                    File name:
                                    resultdns113.exe
                                    Submission date:
                                    2010-08-19 19:57:19 (UTC)
                                    Current status:
                                    finished
                                    Result:
                                    3 /42 (7.1%)

                                    VT Community

                                    not reviewed
                                    Safety score: -
                                    Compact
                                    Print results
                                    Antivirus Version Last Update Result
                                    AhnLab-V3 2010.08.19.01 2010.08.19 -
                                    AntiVir 8.2.4.38 2010.08.19 -
                                    Antiy-AVL 2.0.3.7 2010.08.16 -
                                    Authentium 5.2.0.5 2010.08.19 -
                                    Avast 4.8.1351.0 2010.08.19 -
                                    Avast5 5.0.332.0 2010.08.19 -
                                    AVG 9.0.0.851 2010.08.19 -
                                    BitDefender 7.2 2010.08.19 -
                                    CAT-QuickHeal 11.00 2010.08.19 -
                                    ClamAV 0.96.2.0-git 2010.08.19 -
                                    Comodo 5786 2010.08.19 -
                                    DrWeb 5.0.2.03300 2010.08.19 -
                                    Emsisoft 5.0.0.37 2010.08.19 -
                                    eSafe 7.0.17.0 2010.08.19 -
                                    eTrust-Vet 36.1.7801 2010.08.19 -
                                    F-Prot 4.6.1.107 2010.08.19 -
                                    F-Secure 9.0.15370.0 2010.08.19 -
                                    Fortinet 4.1.143.0 2010.08.19 -
                                    GData 21 2010.08.19 -
                                    Ikarus T3.1.1.88.0 2010.08.19 -
                                    Jiangmin 13.0.900 2010.08.19 -
                                    Kaspersky 7.0.0.125 2010.08.19 -
                                    McAfee 5.400.0.1158 2010.08.19 -
                                    McAfee-GW-Edition 2010.1B 2010.08.19 -
                                    Microsoft 1.6004 2010.08.19 BrowserModifier:Win32/Zwangi
                                    NOD32 5380 2010.08.19 -
                                    Norman 6.05.11 2010.08.19 -
                                    nProtect 2010-08-19.01 2010.08.19 -
                                    Panda 10.0.2.7 2010.08.19 Suspicious file
                                    PCTools 7.0.3.5 2010.08.19 -
                                    Prevx 3.0 2010.08.19 Low Risk Adware
                                    Rising 22.61.03.04 2010.08.19 -
                                    Sophos 4.56.0 2010.08.19 -
                                    Sunbelt 6762 2010.08.19 -
                                    SUPERAntiSpyware 4.40.0.1006 2010.08.19 -
                                    Symantec 20101.1.1.7 2010.08.19 -
                                    TheHacker 6.5.2.1.351 2010.08.19 -
                                    TrendMicro 9.120.0.1004 2010.08.19 -
                                    TrendMicro-HouseCall 9.120.0.1004 2010.08.19 -
                                    VBA32 3.12.14.0 2010.08.19 -
                                    ViRobot 2010.8.16.3990 2010.08.19 -
                                    VirusBuster 5.0.27.0 2010.08.19 -
                                    Additional information
                                    Show all
                                    MD5 : c60fd7fd11cbd84ad592303431814cb4
                                    SHA1 : 65f190e0d14794508c42f7661af3d880bab5f6c7
                                    SHA256: 3b8b1bb34733a7bacd99f9bbaaa4155f5792de3b6febafe9671c84cf92ca0418
                                    ssdeep: 1536:+3gqKITX5yi+0MERmFph6WYpm5SmlUBCYSVDNycn:DyJy10YC9HMDN7
                                    File size : 57608 bytes
                                    First seen: 2010-08-19 19:57:19
                                    Last seen : 2010-08-19 19:57:19
                                    Magic: PE32 executable for MS Windows (GUI) Intel 80386 32-bit
                                    TrID:
                                    Win32 Executable MS Visual C++ (generic) (65.2%)
                                    Win32 Executable Generic (14.7%)
                                    Win32 Dynamic Link Library (generic) (13.1%)
                                    Generic Win/DOS Executable (3.4%)
                                    DOS Executable Generic (3.4%)
                                    sigcheck:
                                    publisher....: n/a
                                    copyright....: n/a
                                    product......: n/a
                                    description..: n/a
                                    original name: n/a
                                    internal name: n/a
                                    file version.: n/a
                                    comments.....: n/a
                                    signers......: ResultDns.com
                                    UTN-USERFirst-Object
                                    signing date.: 7:06 AM 8/19/2010
                                    verified.....: -
                                    PEiD: -
                                    PEInfo: PE structure information

                                    [[ basic data ]]
                                    entrypointaddress: 0x5E62
                                    timedatestamp....: 0x4C6CBBBC (Thu Aug 19 05:06:04 2010)
                                    machinetype......: 0x14C (Intel I386)

                                    [[ 3 section(s) ]]
                                    name, viradd, virsiz, rawdsiz, ntropy, md5
                                    .text, 0x1000, 0x8F46, 0x9000, 6.55, ecdf81b181b2dd1feb9b08b7a7d5642e
                                    .rdata, 0xA000, 0x18DE, 0x2000, 3.96, 65388aa02a36b3b86519fa522c727ebd
                                    .data, 0xC000, 0x958, 0x1000, 1.03, 342e1f4d3bcbc47ffeaee0a3b118ae25

                                    [[ 1 import(s) ]]
                                    kernel32.dll: GetProcAddress, LoadLibraryExA, lstrcmpA, CreateFileA, lstrcpyA, lstrlenA, RtlUnwind, RaiseException, GetSystemTimeAsFileTime, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersionExA, HeapAlloc, SetUnhandledExceptionFilter, HeapFree, ExitProcess, TerminateProcess, GetCurrentProcess, WriteFile, GetStdHandle, GetModuleFileNameA, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetLastError, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, IsBadWritePtr, HeapSize, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, GetACP, GetOEMCP, GetCPInfo, IsBadReadPtr, IsBadCodePtr, LoadLibraryA, InterlockedExchange, VirtualQuery, GetLocaleInfoA, VirtualProtect, GetSystemInfo, LCMapStringA, LCMapStringW, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId
                                    Prevx Info:
                                    http://info.prevx.com/aboutprogramtext.asp?PX5=9EFE9CA4087C3A35E13B004CEC656900E46FBE4F
                                    Symantec reputation:Suspicious.Insight

                                    VT Community

                                    0

                                    This file has never been reviewed by any VT Community member. Be the first one to comment on it!

                                    VirusTotal Team

                                    celui la a l'aire plus suspect...
                                    0
                                    1. a la fin du rapport de ZHPDiag ecrit ceci

                                      ---\\ Infection BT - BHO/Toolbar (Possible)
                                      R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} . (.Ask.com - Ask.com Toolbar.) (5.6.9.135) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
                                      O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} . (.Ask.com - Ask.com Toolbar.) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
                                      O3 - Toolbar: LimeWire Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} . (.Ask.com - Ask.com Toolbar.) -- C:\Program Files\Ask.com\GenericAskToolbar.dll
                                      O42 - Logiciel: Ask Toolbar - (.Ask.com.) [HKLM] -- {86D4B82A-ABED-442A-BE86-96357B70F4FE}
                                      [HKCU\Software\Ask.com]

                                      pour le premier fichier avec virus total
                                      0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
                                      File name:
                                      GoogleUpdate.exe
                                      Submission date:
                                      2010-08-19 19:52:10 (UTC)
                                      Current status:
                                      queued queued analysing finished
                                      Result:
                                      0/ 41 (0.0%)

                                      VT Community

                                      not reviewed
                                      Safety score: -
                                      Compact
                                      Print results
                                      Antivirus Version Last Update Result
                                      AhnLab-V3 2010.08.19.01 2010.08.19 -
                                      AntiVir 8.2.4.38 2010.08.19 -
                                      Antiy-AVL 2.0.3.7 2010.08.16 -
                                      Authentium 5.2.0.5 2010.08.19 -
                                      Avast 4.8.1351.0 2010.08.19 -
                                      Avast5 5.0.332.0 2010.08.19 -
                                      AVG 9.0.0.851 2010.08.19 -
                                      BitDefender 7.2 2010.08.19 -
                                      CAT-QuickHeal 11.00 2010.08.19 -
                                      ClamAV 0.96.2.0-git 2010.08.19 -
                                      Comodo 5786 2010.08.19 -
                                      DrWeb 5.0.2.03300 2010.08.19 -
                                      Emsisoft 5.0.0.37 2010.08.19 -
                                      eSafe 7.0.17.0 2010.08.19 -
                                      eTrust-Vet 36.1.7801 2010.08.19 -
                                      F-Prot 4.6.1.107 2010.08.19 -
                                      F-Secure 9.0.15370.0 2010.08.19 -
                                      Fortinet 4.1.143.0 2010.08.19 -
                                      GData 21 2010.08.19 -
                                      Ikarus T3.1.1.88.0 2010.08.19 -
                                      Jiangmin 13.0.900 2010.08.19 -
                                      Kaspersky 7.0.0.125 2010.08.19 -
                                      McAfee 5.400.0.1158 2010.08.19 -
                                      McAfee-GW-Edition 2010.1B 2010.08.19 -
                                      Microsoft 1.6004 2010.08.19 -
                                      NOD32 5380 2010.08.19 -
                                      Norman 6.05.11 2010.08.19 -
                                      nProtect 2010-08-19.01 2010.08.19 -
                                      Panda 10.0.2.7 2010.08.19 -
                                      PCTools 7.0.3.5 2010.08.19 -
                                      Prevx 3.0 2010.08.19 -
                                      Rising 22.61.03.04 2010.08.19 -
                                      Sophos 4.56.0 2010.08.19 -
                                      Sunbelt 6762 2010.08.19 -
                                      SUPERAntiSpyware 4.40.0.1006 2010.08.19 -
                                      Symantec 20101.1.1.7 2010.08.19 -
                                      TheHacker 6.5.2.1.351 2010.08.19 -
                                      TrendMicro 9.120.0.1004 2010.08.19 -
                                      TrendMicro-HouseCall 9.120.0.1004 2010.08.19 -
                                      ViRobot 2010.8.16.3990 2010.08.19 -
                                      VirusBuster 5.0.27.0 2010.08.19 -
                                      Additional information
                                      Show all
                                      MD5 : 8f0de4fef8201e306f9938b0905ac96a
                                      SHA1 : d2e2915087427be8ea88b4a174c334c578208e78
                                      SHA256: ca7153fe0c037d79fbf7ce0e090d741fb52bccbbbd4ca505ef4849a0c4199f72
                                      ssdeep: 3072:EK5b1edk0bT5ni+lRd4ESGf4Fv5NR2OnCW8DCUck/CJcd+F9UK/r1F2aTwXZg0bQ:EK5bZ
                                      yNi+RS
                                      File size : 135664 bytes
                                      First seen: 2009-10-28 01:12:22
                                      Last seen : 2010-08-19 19:52:10
                                      TrID:
                                      Win64 Executable Generic (59.6%)
                                      Win32 Executable MS Visual C++ (generic) (26.2%)
                                      Win32 Executable Generic (5.9%)
                                      Win32 Dynamic Link Library (generic) (5.2%)
                                      Generic Win/DOS Executable (1.3%)
                                      sigcheck:
                                      publisher....: Google Inc.
                                      copyright....: Copyright 2007-2009 Google Inc.
                                      product......: Google Update
                                      description..: Google Installer
                                      original name: GoogleUpdate.exe
                                      internal name: Google Update
                                      file version.: 1.2.183.9
                                      comments.....: n/a
                                      signers......: Google Inc
                                      VeriSign Class 3 Code Signing 2004 CA
                                      Class 3 Public Primary Certification Authority
                                      signing date.: 1:04 AM 10/14/2009
                                      verified.....: -
                                      PEInfo: PE structure information

                                      [[ basic data ]]
                                      entrypointaddress: 0x50CE
                                      timedatestamp....: 0x4AD50798 (Tue Oct 13 23:04:56 2009)
                                      machinetype......: 0x14c (I386)

                                      [[ 4 section(s) ]]
                                      name, viradd, virsiz, rawdsiz, ntropy, md5
                                      .text, 0x1000, 0xD00B, 0xD200, 6.64, a3b9b6e46995b81015b176e0de2b1fa6
                                      .data, 0xF000, 0x2EA8, 0x1200, 2.41, 23bda919485d01c8e04b1f0f502dcff1
                                      .text_DE, 0x12000, 0x318E, 0x3200, 5.36, 7c96b0385c61b0fee276d13b535c06aa
                                      .rsrc, 0x16000, 0xE0F8, 0xE200, 4.22, 1f2935791db10c014809279836295dbb

                                      [[ 3 import(s) ]]
                                      ADVAPI32.dll: GetTokenInformation, OpenProcessToken, RegOpenKeyExW
                                      KERNEL32.dll: GetCurrentProcess, GetProcAddress, SizeofResource, lstrlenW, FindResourceExW, FindResourceW, CloseHandle, FreeLibrary, GetCommandLineW, GetModuleFileNameW, RaiseException, LoadResource, GetModuleHandleW, LockResource, GetFileAttributesExW, VerifyVersionInfoW, LoadLibraryExW, VerSetConditionMask, GetLastError, SetLastError, LocalAlloc, SetStdHandle, SetFilePointer, InterlockedExchange, LoadLibraryA, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, GetVersionExA, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetStartupInfoW, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, GetCurrentThreadId, InterlockedDecrement, WideCharToMultiByte, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsA, MultiByteToWideChar, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, SetHandleCount, GetFileType, GetStartupInfoA, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, VirtualAlloc, RtlUnwind, Sleep, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, GetLocaleInfoA, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, GetConsoleCP, GetConsoleMode, FlushFileBuffers, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA
                                      ole32.dll: CoCreateGuid

                                      VT Community

                                      0

                                      This file has never been reviewed by any VT Community member. Be the first one to comment on it!

                                      VirusTotal Team

                                      et pout le deuxieme

                                      0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
                                      File name:
                                      resultdns113.exe
                                      Submission date:
                                      2010-08-19 19:57:19 (UTC)
                                      Current status:
                                      queued queued analysing finished
                                      Result:
                                      3/ 42 (7.1%)

                                      VT Community

                                      not reviewed
                                      Safety score: -
                                      Compact
                                      Print results
                                      Antivirus Version Last Update Result
                                      AhnLab-V3 2010.08.19.01 2010.08.19 -
                                      AntiVir 8.2.4.38 2010.08.19 -
                                      Antiy-AVL 2.0.3.7 2010.08.16 -
                                      Authentium 5.2.0.5 2010.08.19 -
                                      Avast 4.8.1351.0 2010.08.19 -
                                      Avast5 5.0.332.0 2010.08.19 -
                                      AVG 9.0.0.851 2010.08.19 -
                                      BitDefender 7.2 2010.08.19 -
                                      CAT-QuickHeal 11.00 2010.08.19 -
                                      ClamAV 0.96.2.0-git 2010.08.19 -
                                      Comodo 5786 2010.08.19 -
                                      DrWeb 5.0.2.03300 2010.08.19 -
                                      Emsisoft 5.0.0.37 2010.08.19 -
                                      eSafe 7.0.17.0 2010.08.19 -
                                      eTrust-Vet 36.1.7801 2010.08.19 -
                                      F-Prot 4.6.1.107 2010.08.19 -
                                      F-Secure 9.0.15370.0 2010.08.19 -
                                      Fortinet 4.1.143.0 2010.08.19 -
                                      GData 21 2010.08.19 -
                                      Ikarus T3.1.1.88.0 2010.08.19 -
                                      Jiangmin 13.0.900 2010.08.19 -
                                      Kaspersky 7.0.0.125 2010.08.19 -
                                      McAfee 5.400.0.1158 2010.08.19 -
                                      McAfee-GW-Edition 2010.1B 2010.08.19 -
                                      Microsoft 1.6004 2010.08.19 BrowserModifier:Win32/Zwangi
                                      NOD32 5380 2010.08.19 -
                                      Norman 6.05.11 2010.08.19 -
                                      nProtect 2010-08-19.01 2010.08.19 -
                                      Panda 10.0.2.7 2010.08.19 Suspicious file
                                      PCTools 7.0.3.5 2010.08.19 -
                                      Prevx 3.0 2010.08.19 Low Risk Adware
                                      Rising 22.61.03.04 2010.08.19 -
                                      Sophos 4.56.0 2010.08.19 -
                                      Sunbelt 6762 2010.08.19 -
                                      SUPERAntiSpyware 4.40.0.1006 2010.08.19 -
                                      Symantec 20101.1.1.7 2010.08.19 -
                                      TheHacker 6.5.2.1.351 2010.08.19 -
                                      TrendMicro 9.120.0.1004 2010.08.19 -
                                      TrendMicro-HouseCall 9.120.0.1004 2010.08.19 -
                                      VBA32 3.12.14.0 2010.08.19 -
                                      ViRobot 2010.8.16.3990 2010.08.19 -
                                      VirusBuster 5.0.27.0 2010.08.19 -
                                      Additional information
                                      Show all
                                      MD5 : c60fd7fd11cbd84ad592303431814cb4
                                      SHA1 : 65f190e0d14794508c42f7661af3d880bab5f6c7
                                      SHA256: 3b8b1bb34733a7bacd99f9bbaaa4155f5792de3b6febafe9671c84cf92ca0418
                                      ssdeep: 1536:+3gqKITX5yi+0MERmFph6WYpm5SmlUBCYSVDNycn:DyJy10YC9HMDN7
                                      File size : 57608 bytes
                                      First seen: 2010-08-19 19:57:19
                                      Last seen : 2010-08-19 19:57:19
                                      TrID:
                                      Win32 Executable MS Visual C++ (generic) (65.2%)
                                      Win32 Executable Generic (14.7%)
                                      Win32 Dynamic Link Library (generic) (13.1%)
                                      Generic Win/DOS Executable (3.4%)
                                      DOS Executable Generic (3.4%)
                                      sigcheck:
                                      publisher....: n/a
                                      copyright....: n/a
                                      product......: n/a
                                      description..: n/a
                                      original name: n/a
                                      internal name: n/a
                                      file version.: n/a
                                      comments.....: n/a
                                      signers......: ResultDns.com
                                      UTN-USERFirst-Object
                                      signing date.: 7:06 AM 8/19/2010
                                      verified.....: -
                                      PEInfo: PE structure information

                                      [[ basic data ]]
                                      entrypointaddress: 0x5E62
                                      timedatestamp....: 0x4C6CBBBC (Thu Aug 19 05:06:04 2010)
                                      machinetype......: 0x14c (I386)

                                      [[ 3 section(s) ]]
                                      name, viradd, virsiz, rawdsiz, ntropy, md5
                                      .text, 0x1000, 0x8F46, 0x9000, 6.55, ecdf81b181b2dd1feb9b08b7a7d5642e
                                      .rdata, 0xA000, 0x18DE, 0x2000, 3.96, 65388aa02a36b3b86519fa522c727ebd
                                      .data, 0xC000, 0x958, 0x1000, 1.03, 342e1f4d3bcbc47ffeaee0a3b118ae25

                                      [[ 1 import(s) ]]
                                      KERNEL32.dll: GetProcAddress, LoadLibraryExA, lstrcmpA, CreateFileA, lstrcpyA, lstrlenA, RtlUnwind, RaiseException, GetSystemTimeAsFileTime, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersionExA, HeapAlloc, SetUnhandledExceptionFilter, HeapFree, ExitProcess, TerminateProcess, GetCurrentProcess, WriteFile, GetStdHandle, GetModuleFileNameA, UnhandledExceptionFilter, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetLastError, GetEnvironmentStringsW, SetHandleCount, GetFileType, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, IsBadWritePtr, HeapSize, GetStringTypeA, MultiByteToWideChar, GetStringTypeW, GetACP, GetOEMCP, GetCPInfo, IsBadReadPtr, IsBadCodePtr, LoadLibraryA, InterlockedExchange, VirtualQuery, GetLocaleInfoA, VirtualProtect, GetSystemInfo, LCMapStringA, LCMapStringW, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId
                                      Prevx Info:
                                      http://info.prevx.com/aboutprogramtext.asp?PX5=9EFE9CA4087C3A35E13B004CEC656900E46FBE4F
                                      Symantec reputation:Suspicious.Insight

                                      VT Community

                                      0

                                      This file has never been reviewed by any VT Community member. Be the first one to comment on it!

                                      VirusTotal Team

                                      voila les rapports
                                      0
                                      1. Contributeur
                                        Ok, passons a autre chose, essaye d'utiliser ZHPDiag comme indiqué dans mon premier message mais utilise ce lien pour le telecharger car l'autre ne fonctionne pas (au cas où ZHPDiag ne fonctionne pas aussi essaye le mode sans echec ou OTH)
                                        Ensuite :

                                        ¤ Rend toi sur Virus Total
                                        ¤ Clique sur "Parcourir..."
                                        ¤ Dans la nouvelle fenêtre, dans le champ "Nom du Fichier", copie/colle ceci >>> C:\Program Files\Google\Update\GoogleUpdate.exe <<<
                                        ¤ Clique sur "Ouvrir"
                                        ¤ De retour sur Virus Total, clique sur "Envoyer le fichier"
                                        ¤ Un scan du fichier se fera et les résultat seront proposés sous forme de tableau, copie/colle l'adresse de la page des résultats dans ta prochaine réponse

                                        Et fait de même pour ceci >>> C:\Documents and Settings\All Users\Application Data\ResultDns\resultdns113.exe <<<

                                        ++
                                        Karel
                                        0
                                        • 1
                                        • 2