[Trojan] Adloader

Bonsoir et meilleurs voeux à toutes et tous :)

Je commence fort l'année puisque je viens de choper un trojan qui me donne du mal.

Ca a commencé hier soir, dès que je me connecte avast détecte adloader.exe et a du mal à le mettre en quarantaine.
Quand il y arrive et que je le supprime, il répparait aussitot à la connexion suivante soit au meme endroit, soit à la racine de C.

Sous le nom de adloader dans un fichier qui s appelle drsmartload.exe ou drsmartloader.exe, ca depend.

L'emplacement d'origine est C\Documentsetsettings\moncompte\localsettings\temp
la fois d'après c'etait juste dans C:\

En voulant le supprimer en mode sans echec j'ai vu qu'il venait du site
//promo.dollarrevenue.com/bundle/drsmartload.exe...sur lequel je ne suis jamais allé...
J'ai supprimé les fichiers temp, puis l'entrée dans la base de registre mais en me reconnectant il est réapparu aussitôt, et j'ai fait çà 4 fois, ca me desespere un peu.
Je n'ai vu aucune trace dans le log d'hijack et ni adaware ni spybot ne semblent le détecter. Aucune piste sur internet non plus c'est pourquoi je reviens si vite poster ici, en espérant que quelqu'un puisse m'aider.

Meilleurs voeux quand même pour 2006 (sauf aux pirates:)

a+

26 réponses

Résumé de la discussion

Un trojan persistant, associé à adloader, est détecté par Avast à chaque connexion et réapparaît après suppression, se plaçant dans C:\ et sous des noms tels que drsmartload.exe. Les emplacements et noms de fichiers varient, et l’origine semble être un site promo.dollarrevenue.com, ce qui rend les tentatives de suppression et de quarantaine inefficaces. Des intervenants recommandent des outils et méthodes comme SmitfraudFix, VirtumundoBeGone, des analyses en ligne et des scans avec Ewido ou Bitdefender, en mode sans échec. En cas de réapparition persistante, la discussion insiste sur l’usage des journaux et rapports (HijackThis, Ewido) et sur l’optimisation des programmes au démarrage.

Bobot (l’IA à votre service)
  1. salut,

    merci de venir m'aider.
    avant tout, 2 précisions :

    * cette nuit je n'ai pas éteint mon pc (déconnecté d'internet mais pas resté allumé) et depuis que je me suis connecté aujourd'hui, aucune alerte de virus, même après le redémarrage que je viens de faire.
    ceci dit je ne suis pas plus rassuré que cà car il y a toujours des mauvaises lignes dans hijack.

    **sais pas si ca compte mais je n'ai pas vu le message "erreur fatale" en utilisant virtumundo, par contre en voulant ouvrir le rapport pour le coller ici...impossible d'ouvrir bloc notes ou quoi que ce soit, j'avais le sablier ...obligé de reboot.

    voici le rapport :

    [01/08/2006, 17:43:51] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Administrateur\Bureau\VirtumundoBeGone.exe" )
    [01/08/2006, 17:44:03] - Detected System Information:
    [01/08/2006, 17:44:03] - Windows Version: 5.0.2195, Service Pack 4
    [01/08/2006, 17:44:03] - Current Username: Administrateur (Admin)
    [01/08/2006, 17:44:03] - Windows is in NORMAL mode.
    [01/08/2006, 17:44:03] - Searching for Browser Helper Objects:
    [01/08/2006, 17:44:03] - BHO 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} ()
    [01/08/2006, 17:44:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
    [01/08/2006, 17:44:03] - Checking for HKLM\...\Winlogon\Notify\pmkjk
    [01/08/2006, 17:44:03] - Found: HKLM\...\Winlogon\Notify\pmkjk - This is probably Virtumundo.
    [01/08/2006, 17:44:03] - Assigning {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} MSEvents Object
    [01/08/2006, 17:44:03] - BHO list has been changed! Starting over...
    [01/08/2006, 17:44:03] - BHO 1: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} (MSEvents Object)
    [01/08/2006, 17:44:03] - ALERT: Found MSEvents Object!
    [01/08/2006, 17:44:03] - BHO 2: {0A87E45F-537A-40B4-B812-E2544C21A09F} (SpywareBlock Class)
    [01/08/2006, 17:44:03] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
    [01/08/2006, 17:44:03] - WARNING: BHO has no default name. Checking for Winlogon reference.
    [01/08/2006, 17:44:03] - Checking for HKLM\...\Winlogon\Notify\SDHelper
    [01/08/2006, 17:44:03] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
    [01/08/2006, 17:44:03] - Finished Searching Browser Helper Objects
    [01/08/2006, 17:44:03] - *** Detected MSEvents Object
    [01/08/2006, 17:44:03] - Trying to remove MSEvents Object...
    [01/08/2006, 17:44:04] - Terminating Process: IEXPLORE.EXE
    [01/08/2006, 17:44:04] - Terminating Process: RUNDLL32.EXE
    [01/08/2006, 17:44:04] - Disabling Automatic Shell Restart
    [01/08/2006, 17:44:04] - Terminating Process: EXPLORER.EXE
    [01/08/2006, 17:44:05] - Suspending the NT Session Manager System Service
    [01/08/2006, 17:44:05] - Terminating Windows NT Logon/Logoff Manager
    [01/08/2006, 17:44:05] - Re-enabling Automatic Shell Restart
    [01/08/2006, 17:44:05] - File to disable: C:\WINNT\system32\pmkjk.dll
    [01/08/2006, 17:44:05] - Removing HKLM\...\Browser Helper Objects\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
    [01/08/2006, 17:44:05] - Removing HKCR\CLSID\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
    [01/08/2006, 17:44:05] - Adding Kill Bit for ActiveX for GUID: {00DBDAC8-4691-4797-8E6A-7C6AB89BC441}
    [01/08/2006, 17:44:05] - Deleting ATLEvents/MSEvents Registry entries
    [01/08/2006, 17:44:05] - Removing HKLM\...\Winlogon\Notify\pmkjk
    [01/08/2006, 17:44:05] - Searching for Browser Helper Objects:
    [01/08/2006, 17:44:05] - BHO 1: {0A87E45F-537A-40B4-B812-E2544C21A09F} (SpywareBlock Class)
    [01/08/2006, 17:44:05] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
    [01/08/2006, 17:44:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
    [01/08/2006, 17:44:05] - Checking for HKLM\...\Winlogon\Notify\SDHelper
    [01/08/2006, 17:44:05] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
    [01/08/2006, 17:44:05] - Finished Searching Browser Helper Objects
    [01/08/2006, 17:44:05] - Finishing up...
    [01/08/2006, 17:44:05] - A restart is needed.
    [01/08/2006, 17:44:15] - Attempting to Restart via STOP error (Blue Screen!)

    et le log hijack :

    Logfile of HijackThis v1.99.1
    Scan saved at 17:47:29, on 08/01/2006
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    C:\Program Files\Alwil Software\Avast4\ashServ.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\ewido anti-malware\ewidoctrl.exe
    C:\WINNT\system32\hidserv.exe
    C:\WINNT\system32\nvsvc32.exe
    C:\Program Files\Tiny Personal Firewall\persfw.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\system32\mspmspsv.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\soundman.exe
    C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
    C:\PROGRA~1\Wanadoo\taskbaricon.exe
    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\Microsoft Office\Office\OSA.EXE
    C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
    C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
    C:\Program Files\Alwil Software\Avast4\setup\avast.setup
    C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
    C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
    C:\Hijackthis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SoundMan] soundman.exe
    O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
    O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\watch.exe
    O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\taskbaricon.exe
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
    O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
    O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
    O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - www.wanadoo.fr (file missing) (HKCU)
    O13 - DefaultPrefix:
    O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
    O20 - AppInit_DLLs: interceptor.dll
    O20 - Winlogon Notify: jkhfd - jkhfd.dll (file missing)
    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
    O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
    O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
    O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
    O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
    O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe

    a +
    0
    1. re,

      Et le log Hijack pour finir la série de tests :

      Logfile of HijackThis v1.99.1
      Scan saved at 22:53:21, on 07/01/2006
      Platform: Windows 2000 SP4 (WinNT 5.00.2195)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINNT\System32\smss.exe
      C:\WINNT\system32\winlogon.exe
      C:\WINNT\system32\services.exe
      C:\WINNT\system32\lsass.exe
      C:\WINNT\system32\svchost.exe
      C:\WINNT\system32\spoolsv.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINNT\System32\svchost.exe
      C:\Program Files\ewido anti-malware\ewidoctrl.exe
      C:\WINNT\system32\hidserv.exe
      C:\WINNT\system32\nvsvc32.exe
      C:\Program Files\Tiny Personal Firewall\persfw.exe
      C:\WINNT\system32\MSTask.exe
      C:\WINNT\system32\stisvc.exe
      C:\WINNT\System32\WBEM\WinMgmt.exe
      C:\WINNT\system32\mspmspsv.exe
      C:\WINNT\Explorer.EXE
      C:\WINNT\soundman.exe
      C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
      C:\PROGRA~1\Wanadoo\taskbaricon.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\WinZip\WZQKPICK.EXE
      C:\Program Files\Microsoft Office\Office\OSA.EXE
      C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
      C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
      C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\WINNT\system32\cmd.exe
      C:\WINNT\system32\rundll32.exe
      C:\Hijackthis\HijackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINNT\system32\pmkjk.dll (file missing)
      O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
      O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SoundMan] soundman.exe
      O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\taskbaricon.exe
      O4 - HKLM\..\Run: [LoadQM] loadqm.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
      O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
      O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
      O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
      O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
      O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
      O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - www.wanadoo.fr (file missing) (HKCU)
      O13 - DefaultPrefix:
      O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{D4F1A94C-9D94-44E8-B5A0-EB63D8237C03}: NameServer = 80.10.246.130 80.10.246.3
      O20 - AppInit_DLLs: interceptor.dll
      O20 - Winlogon Notify: jkhfd - jkhfd.dll (file missing)
      O20 - Winlogon Notify: pmkjk - pmkjk.dll (file missing)
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
      O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
      O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
      O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
      O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe

      Voila, que pensez vous de tout ca ? (hijack, l2mfix et lopxp)
      Les problemes continuent toujours a chaque connection, detection de adloader par avast et tjrs les memes lignes nefastes (013 entre autres)...
      Je ne sais pas quoi faire.

      a+
      0
      1. Salut,

        Télécharge VirtumundoBegone sur le bureau:
        http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe

        Double clique ensuite sur VirtumundoBeGone.exe et suis les instructions.
        Une fois terminé, redémarre et poste le rapport VBG.TXT créé sur le bureau dans ta prochaine réponse avec un nouveau rapport HijackThis.
        Ne t'inquiète pas si tu vois un message Ecran bleu "Erreur fatale", c'est normal et attendu.
        0
    2. re,

      et voici le deuxieme log l2mfix :

      Setting Directory
      C:\
      C:\
      System Rebooted!

      Running From:
      C:\

      killing explorer and rundll32.exe

      Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
      Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
      Killing PID 1216 'explorer.exe'

      Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
      Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
      Error, Cannot find a process with an image name of rundll32.exe

      Scanning First Pass. Please Wait!

      First Pass Completed

      Second Pass Scanning

      Second pass Completed!

      Zipping up files for submission:
      adding: clear.reg (92 bytes security) (deflated 2%)
      adding: fix.reg (92 bytes security) (deflated 30%)
      adding: trial_setup.ini (92 bytes security) (deflated 44%)
      adding: battisti.txt (92 bytes security) (deflated 51%)
      adding: dezonagethompson.txt (92 bytes security) (deflated 45%)
      adding: install_comp.txt (92 bytes security) (deflated 84%)
      adding: lo2.txt (92 bytes security) (deflated 57%)
      adding: lop.txt (92 bytes security) (deflated 74%)
      adding: openpdf.txt (92 bytes security) (stored 0%)
      adding: rapport.txt (92 bytes security) (deflated 58%)
      adding: test.txt (92 bytes security) (stored 0%)
      adding: test2.txt (92 bytes security) (stored 0%)
      adding: test3.txt (92 bytes security) (stored 0%)
      adding: test5.txt (92 bytes security) (stored 0%)
      adding: tracert.txt (92 bytes security) (deflated 55%)
      adding: xscan.txt (92 bytes security) (deflated 93%)

      Restoring Registry Permissions:

      RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
      Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
      This program is Freeware, use it on your own risk!

      Revoking access for predefined group "Administrators"
      Inherited ACE can not be revoked here!
      Inherited ACE can not be revoked here!

      Registry permissions set too:

      RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
      Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
      This program is Freeware, use it on your own risk!

      Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
      (ID-NI) ALLOW Read BUILTIN\Utilisateurs
      (ID-IO) ALLOW Read BUILTIN\Utilisateurs
      (ID-NI) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
      (ID-IO) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
      (ID-NI) ALLOW Full access BUILTIN\Administrateurs
      (ID-IO) ALLOW Full access BUILTIN\Administrateurs
      (ID-NI) ALLOW Full access AUTORITE NT\SYSTEM
      (ID-IO) ALLOW Full access AUTORITE NT\SYSTEM
      (ID-IO) ALLOW Full access CREATEUR PROPRIETAIRE

      Restoring Sedebugprivilege:

      Granting SeDebugPrivilege to Administrators ... failed (GetAccountSid(Administrators)=1332

      Restoring Windows Update Certificates.:

      The following Is the Current Export of the Winlogon notify key:
      ****************************************************************************
      Windows Registry Editor Version 5.00

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
      "Asynchronous"=dword:00000000
      "Impersonate"=dword:00000000
      "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
      6c,00,00,00
      "Logoff"="ChainWlxLogoffEvent"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
      "Asynchronous"=dword:00000000
      "Impersonate"=dword:00000000
      "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
      6c,00,6c,00,00,00
      "Logoff"="CryptnetWlxLogoffEvent"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
      "DLLName"="cscdll.dll"
      "Logon"="WinlogonLogonEvent"
      "Logoff"="WinlogonLogoffEvent"
      "ScreenSaver"="WinlogonScreenSaverEvent"
      "Startup"="WinlogonStartupEvent"
      "Shutdown"="WinlogonShutdownEvent"
      "StartShell"="WinlogonStartShellEvent"
      "Impersonate"=dword:00000000
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhfd]
      "Asynchronous"=dword:00000001
      "DllName"="jkhfd.dll"
      "Impersonate"=dword:00000000
      "Logon"="Logon"
      "Logoff"="Logoff"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkjk]
      "Asynchronous"=dword:00000001
      "DllName"="pmkjk.dll"
      "Impersonate"=dword:00000000
      "Logon"="Logon"
      "Logoff"="Logoff"

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
      "Logoff"="WLEventLogoff"
      "Impersonate"=dword:00000000
      "Asynchronous"=dword:00000001
      "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
      6c,00,6c,00,00,00

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
      "DLLName"="WlNotify.dll"
      "Lock"="SensLockEvent"
      "Logon"="SensLogonEvent"
      "Logoff"="SensLogoffEvent"
      "Safe"=dword:00000001
      "MaxWait"=dword:00000258
      "StartScreenSaver"="SensStartScreenSaverEvent"
      "StopScreenSaver"="SensStopScreenSaverEvent"
      "Startup"="SensStartupEvent"
      "Shutdown"="SensShutdownEvent"
      "StartShell"="SensStartShellEvent"
      "Unlock"="SensUnlockEvent"
      "Impersonate"=dword:00000001
      "Asynchronous"=dword:00000001

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
      "DLLName"="wzcdlg.dll"
      "Logon"="WZCEventLogon"
      "Logoff"="WZCEventLogoff"
      "Impersonate"=dword:00000000
      "Asynchronous"=dword:00000000

      The following are the files found:
      ****************************************************************************

      Registry Entries that were Deleted:
      Please verify that the listing looks ok.
      If there was something deleted wrongly there are backups in the backreg folder.
      ****************************************************************************
      REGEDIT4

      [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
      REGEDIT4

      [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
      ****************************************************************************
      Desktop.ini Contents:
      ****************************************************************************
      ****************************************************************************

      Un log hijack suit

      a+
      0
      1. re,

        et voici le deuxieme log l2mfix :

        Setting Directory
        C:\
        C:\
        System Rebooted!

        Running From:
        C:\

        killing explorer and rundll32.exe

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
        Killing PID 1216 'explorer.exe'

        Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
        Copyright(C) 2002-2003 Craig.Peacock@beyondlogic.org
        Error, Cannot find a process with an image name of rundll32.exe

        Scanning First Pass. Please Wait!

        First Pass Completed

        Second Pass Scanning

        Second pass Completed!

        Zipping up files for submission:
        adding: clear.reg (92 bytes security) (deflated 2%)
        adding: fix.reg (92 bytes security) (deflated 30%)
        adding: trial_setup.ini (92 bytes security) (deflated 44%)
        adding: battisti.txt (92 bytes security) (deflated 51%)
        adding: dezonagethompson.txt (92 bytes security) (deflated 45%)
        adding: install_comp.txt (92 bytes security) (deflated 84%)
        adding: lo2.txt (92 bytes security) (deflated 57%)
        adding: lop.txt (92 bytes security) (deflated 74%)
        adding: openpdf.txt (92 bytes security) (stored 0%)
        adding: rapport.txt (92 bytes security) (deflated 58%)
        adding: test.txt (92 bytes security) (stored 0%)
        adding: test2.txt (92 bytes security) (stored 0%)
        adding: test3.txt (92 bytes security) (stored 0%)
        adding: test5.txt (92 bytes security) (stored 0%)
        adding: tracert.txt (92 bytes security) (deflated 55%)
        adding: xscan.txt (92 bytes security) (deflated 93%)

        Restoring Registry Permissions:

        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!

        Revoking access for predefined group "Administrators"
        Inherited ACE can not be revoked here!
        Inherited ACE can not be revoked here!

        Registry permissions set too:

        RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
        Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
        This program is Freeware, use it on your own risk!

        Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
        (ID-NI) ALLOW Read BUILTIN\Utilisateurs
        (ID-IO) ALLOW Read BUILTIN\Utilisateurs
        (ID-NI) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
        (ID-IO) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
        (ID-NI) ALLOW Full access BUILTIN\Administrateurs
        (ID-IO) ALLOW Full access BUILTIN\Administrateurs
        (ID-NI) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-IO) ALLOW Full access AUTORITE NT\SYSTEM
        (ID-IO) ALLOW Full access CREATEUR PROPRIETAIRE

        Restoring Sedebugprivilege:

        Granting SeDebugPrivilege to Administrators ... failed (GetAccountSid(Administrators)=1332

        Restoring Windows Update Certificates.:

        The following Is the Current Export of the Winlogon notify key:
        ****************************************************************************
        Windows Registry Editor Version 5.00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
        6c,00,00,00
        "Logoff"="ChainWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
        "Asynchronous"=dword:00000000
        "Impersonate"=dword:00000000
        "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
        6c,00,6c,00,00,00
        "Logoff"="CryptnetWlxLogoffEvent"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
        "DLLName"="cscdll.dll"
        "Logon"="WinlogonLogonEvent"
        "Logoff"="WinlogonLogoffEvent"
        "ScreenSaver"="WinlogonScreenSaverEvent"
        "Startup"="WinlogonStartupEvent"
        "Shutdown"="WinlogonShutdownEvent"
        "StartShell"="WinlogonStartShellEvent"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhfd]
        "Asynchronous"=dword:00000001
        "DllName"="jkhfd.dll"
        "Impersonate"=dword:00000000
        "Logon"="Logon"
        "Logoff"="Logoff"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkjk]
        "Asynchronous"=dword:00000001
        "DllName"="pmkjk.dll"
        "Impersonate"=dword:00000000
        "Logon"="Logon"
        "Logoff"="Logoff"

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
        "Logoff"="WLEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000001
        "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
        6c,00,6c,00,00,00

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
        "DLLName"="WlNotify.dll"
        "Lock"="SensLockEvent"
        "Logon"="SensLogonEvent"
        "Logoff"="SensLogoffEvent"
        "Safe"=dword:00000001
        "MaxWait"=dword:00000258
        "StartScreenSaver"="SensStartScreenSaverEvent"
        "StopScreenSaver"="SensStopScreenSaverEvent"
        "Startup"="SensStartupEvent"
        "Shutdown"="SensShutdownEvent"
        "StartShell"="SensStartShellEvent"
        "Unlock"="SensUnlockEvent"
        "Impersonate"=dword:00000001
        "Asynchronous"=dword:00000001

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
        "DLLName"="wzcdlg.dll"
        "Logon"="WZCEventLogon"
        "Logoff"="WZCEventLogoff"
        "Impersonate"=dword:00000000
        "Asynchronous"=dword:00000000

        The following are the files found:
        ****************************************************************************

        Registry Entries that were Deleted:
        Please verify that the listing looks ok.
        If there was something deleted wrongly there are backups in the backreg folder.
        ****************************************************************************
        REGEDIT4

        [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
        REGEDIT4

        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
        ****************************************************************************
        Desktop.ini Contents:
        ****************************************************************************
        ****************************************************************************

        Un log hijack suit

        a+
        0
        1. Re,

          voici le premier log l2mfix (option1):

          L2MFIX find log 1.04a
          These are the registry keys present
          **********************************************************************************
          Winlogon/notify:
          Windows Registry Editor Version 5.00

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt32chain]
          "Asynchronous"=dword:00000000
          "Impersonate"=dword:00000000
          "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,33,00,32,00,2e,00,64,00,6c,00,\
          6c,00,00,00
          "Logoff"="ChainWlxLogoffEvent"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cryptnet]
          "Asynchronous"=dword:00000000
          "Impersonate"=dword:00000000
          "DllName"=hex(2):63,00,72,00,79,00,70,00,74,00,6e,00,65,00,74,00,2e,00,64,00,\
          6c,00,6c,00,00,00
          "Logoff"="CryptnetWlxLogoffEvent"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\cscdll]
          "DLLName"="cscdll.dll"
          "Logon"="WinlogonLogonEvent"
          "Logoff"="WinlogonLogoffEvent"
          "ScreenSaver"="WinlogonScreenSaverEvent"
          "Startup"="WinlogonStartupEvent"
          "Shutdown"="WinlogonShutdownEvent"
          "StartShell"="WinlogonStartShellEvent"
          "Impersonate"=dword:00000000
          "Asynchronous"=dword:00000001

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkhfd]
          "Asynchronous"=dword:00000001
          "DllName"="jkhfd.dll"
          "Impersonate"=dword:00000000
          "Logon"="Logon"
          "Logoff"="Logoff"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\pmkjk]
          "Asynchronous"=dword:00000001
          "DllName"="pmkjk.dll"
          "Impersonate"=dword:00000000
          "Logon"="Logon"
          "Logoff"="Logoff"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\sclgntfy]
          "Logoff"="WLEventLogoff"
          "Impersonate"=dword:00000000
          "Asynchronous"=dword:00000001
          "DllName"=hex(2):73,00,63,00,6c,00,67,00,6e,00,74,00,66,00,79,00,2e,00,64,00,\
          6c,00,6c,00,00,00

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SensLogn]
          "DLLName"="WlNotify.dll"
          "Lock"="SensLockEvent"
          "Logon"="SensLogonEvent"
          "Logoff"="SensLogoffEvent"
          "Safe"=dword:00000001
          "MaxWait"=dword:00000258
          "StartScreenSaver"="SensStartScreenSaverEvent"
          "StopScreenSaver"="SensStopScreenSaverEvent"
          "Startup"="SensStartupEvent"
          "Shutdown"="SensShutdownEvent"
          "StartShell"="SensStartShellEvent"
          "Unlock"="SensUnlockEvent"
          "Impersonate"=dword:00000001
          "Asynchronous"=dword:00000001

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wzcnotif]
          "DLLName"="wzcdlg.dll"
          "Logon"="WZCEventLogon"
          "Logoff"="WZCEventLogoff"
          "Impersonate"=dword:00000000
          "Asynchronous"=dword:00000000

          RegDACL 5.1 - Permissions Manager for Registry keys for Windows NT 4 and above
          Copyright (c) 1999-2001 Frank Heyne Software (http://www.heysoft.de)
          This program is Freeware, use it on your own risk!

          Access Control List for Registry key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify:
          (ID-NI) ALLOW Read BUILTIN\Utilisateurs
          (ID-IO) ALLOW Read BUILTIN\Utilisateurs
          (ID-NI) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
          (ID-IO) ALLOW Read BUILTIN\Utilisateurs avec pouvoir
          (ID-NI) ALLOW Full access BUILTIN\Administrateurs
          (ID-IO) ALLOW Full access BUILTIN\Administrateurs
          (ID-NI) ALLOW Full access AUTORITE NT\SYSTEM
          (ID-IO) ALLOW Full access AUTORITE NT\SYSTEM
          (ID-IO) ALLOW Full access CREATEUR PROPRIETAIRE

          **********************************************************************************
          useragent:
          Windows Registry Editor Version 5.00

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
          "Wanadoo 5.3"="IEAKFTI"
          "iebar"=" "
          "acc=onekill"=" "
          "acc=none"=" "

          **********************************************************************************
          Shell Extension key:
          Windows Registry Editor Version 5.00

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
          "{00022613-0000-0000-C000-000000000046}"="Feuille de propri‚t‚s du fichier multim‚dia"
          "{176d6597-26d3-11d1-b350-080036a75b03}"="Gestion de scanneur ICM"
          "{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="Page de s‚curit‚ NTFS"
          "{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="Page des propri‚t‚s de OLE DocFile"
          "{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Extensions de l'interpr‚teur de commandes pour le partage"
          "{41E300E0-78B6-11ce-849B-444553540000}"="Extension du Panneau de configuration PlusPack"
          "{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Carte du Panneau de configuration"
          "{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage cran du Panneau de configuration"
          "{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Extension Affichage Panorama du Panneau de configuration"
          "{4E40F770-369C-11d0-8922-00A024AB2DBB}"="Page de s‚curit‚ DS"
          "{56117100-C0CD-101B-81E2-00AA004AE837}"="Gestionnaire de donn‚es endommag‚es de l'interpr‚teur de commandes"
          "{59099400-57FF-11CE-BD94-0020AF85B590}"="Extension copie de disquette"
          "{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Extensions de l'interpr‚teur de commandes pour les objets Microsoft Windows Network"
          "{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="Gestion d'‚cran ICM"
          "{675F097E-4C4D-11D0-B6C1-0800091AA605}"="Gestion d'imprimante ICM"
          "{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Extensions de l'interpr‚teur de commandes pour la compression de fichiers"
          "{77597368-7b15-11d0-a0c2-080036af3f03}"="Extension du shell d'imprimante Web"
          "{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
          "{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Menu contextuel de cryptage"
          "{85BBD920-42A0-1069-A2E4-08002B30309D}"="Porte-documents"
          "{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
          "{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
          "{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="Profil ICC"
          "{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Page de s‚curit‚ des imprimantes"
          "{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Extensions de l'interpr‚teur de commandes pour le partage"
          "{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
          "{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Extension de l'interpr‚teur de commande pour Windows Script Host"
          "{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie PKO"
          "{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Extension de cryptographie Sign"
          "{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Connexions r‚seau et accŠs … distance"
          "{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
          "{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
          "{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Tƒches planifi‚es"
          "{1A9BA3A0-143A-11CF-8350-444553540000}"="Dossier favori du shell"
          "{20D04FE0-3AEA-1069-A2D8-08002B30309D}"="Poste de travail"
          "{86747AC0-42A0-1069-A2E6-08002B30309D}"="Porte-documents"
          "{0AFACED1-E828-11D1-9187-B532F1E9575D}"="Raccourci vers le dossier"
          "{12518493-00B2-11d2-9FA5-9E3420524153}"="Volume mont‚"
          "{21B22460-3AEA-1069-A2DC-08002B30309D}"="Extension de la page de propri‚t‚s des fichiers"
          "{B091E540-83E3-11CF-A713-0020AFD79762}"="Page des types de fichiers"
          "{FBF23B41-E3F0-101B-8488-00AA003E56F8}"="Gestionnaire des types de fichiers MIME"
          "{C2FBB630-2971-11d1-A18C-00C04FD75D13}"="Service Copier vers Microsoft"
          "{C2FBB631-2971-11d1-A18C-00C04FD75D13}"="Service D‚placer vers Microsoft"
          "{13709620-C279-11CE-A49E-444553540000}"="Service d'automatisation de l'interface"
          "{62112AA1-EBE4-11cf-A5FB-0020AFE7292D}"="Shell Automation Folder View"
          "{4622AD11-FF23-11d0-8D34-00A0C90F2719}"="Menu D‚marrer"
          "{7BA4C740-9E81-11CF-99D3-00AA004AE837}"="Service SendTo Microsoft"
          "{D969A300-E7FF-11d0-A93B-00A0C90F2719}"="Service Nouvel objet Microsoft"
          "{09799AFB-AD67-11d1-ABCD-00C04FC30936}"="Ouvrir avec le gestionnaire de menu contextuel"
          "{3FC0B520-68A9-11D0-8D77-00C04FD70822}"="Afficher les extensions HTML du Panneau de configuration"
          "{75048700-EF1F-11D0-9888-006097DEACF9}"="ActiveDesktop"
          "{6D5313C0-8C62-11D1-B2CD-006097DF8C11}"="Extension de la page de propri‚t‚s des options des dossiers"
          "{57651662-CE3E-11D0-8D77-00C04FC99D61}"="CmdFileIcon"
          "{4657278A-411B-11d2-839A-00C04FD918D0}"="Application d'aide du systŠme pour le glisser-d‚placer"
          "{A470F8CF-A1E8-4f65-8335-227475AA5C46}"="Ajouter l'‚l‚ment de cryptage dans les menus contextuels de l'Explorateur"
          "{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Barre d'outils Internet Microsoft"
          "{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="tat du t‚l‚chargement"
          "{568804CA-CBD7-11d0-9816-00C04FD91972}"="Menu Dossier Bureau"
          "{5b4dae26-b807-11d0-9815-00c04fd91972}"="Bande de menus"
          "{8278F931-2A3E-11d2-838F-00C04FD918D0}"="Suivi du menu Shell"
          "{E13EF4E4-D2F2-11d0-9816-00C04FD91972}"="Menu Site"
          "{ECD4FC4F-521C-11D0-B792-00A0C90312E1}"="Menu Barre du Bureau"
          "{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Dossier Bureau ‚tendu"
          "{6413BA2C-B461-11d1-A18A-080036B11A03}"="Dossier du shell augment‚"
          "{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
          "{D82BE2B0-5764-11D0-A96E-00C04FD705A2}"="IShellFolderBand"
          "{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Bande du navigateur Microsoft"
          "{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Bande de recherche"
          "{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="Volet int‚gr‚ de recherche"
          "{07798131-AF23-11d1-9111-00A0C98BA67D}"="Recherche Web"
          "{0E5CBF21-D15F-11d0-8301-00AA005B4383}"="&Liens"
          "{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Utilitaire des options de l'arborescence du Registre"
          "{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Adresse"
          "{A08C11D2-A228-11d0-825B-00AA005B4383}"="BoŒte d'entr‚e de l'adresse"
          "{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Saisie semi-automatique Microsoft"
          "{7487cd30-f71a-11d0-9ea7-00805f714772}"="Image miniature"
          "{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
          "{6756A641-DE71-11d0-831B-00AA005B4383}"="Liste de saisie semi-automatique MRU"
          "{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Liste de saisie semi-automatique de l'historique Microsoft"
          "{03C036F1-A186-11D0-824A-00AA005B4383}"="Liste de saisie semi-automatique du dossier Shell Microsoft"
          "{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Conteneur de la liste de saisie semi-automatique multiple Microsoft"
          "{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Menu Site de bandes"
          "{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
          "{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Barre du Bureau"
          "{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
          "{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="Assistance utilisateur"
          "{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="ParamŠtres du dossier global"
          "{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
          "{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
          "{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
          "{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
          "{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
          "{FF393560-C2A7-11CF-BFF4-444553540000}"="Historique"
          "{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
          "{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
          "{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="Image de d‚marrage de la Suite IE4"
          "{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
          "{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
          "{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
          "{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="Internet"
          "{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
          "{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
          "{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
          "{88C6C381-2E85-11D0-94DE-444553540000}"="Dossier ActiveX Cache"
          "{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
          "{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
          "{F5175861-2688-11d0-9C5E-00AA00A45957}"="Dossier Inscription"
          "{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
          "{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
          "{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
          "{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
          "{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
          "{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
          "{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
          "{8BEBB290-52D0-11D0-B7F4-00C04FD706EC}"="Miniatures"
          "{EAB841A0-9550-11CF-8C16-00805F1408F3}"="Extracteur de miniatures HTML"
          "{1AEB1360-5AFC-11D0-B806-00C04FD706EC}"="Extracteur de miniatures des filtres graphiques Office"
          "{9DBD2C50-62AD-11D0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
          "{500202A0-731E-11D0-B829-00C04FD706EC}"="LNK file thumbnail interface delegator"
          "{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Gestionnaire d'application du shell"
          "{0B124F8C-91F0-11D1-B8B5-006008059382}"="num‚rateur d'applications install‚es"
          "{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
          "{fe1290f0-cfbd-11cf-a330-00aa00c16e65}"="Directory Namespace"
          "{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
          "{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
          "{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
          "{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
          "{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
          "{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
          "{450D8FBA-AD25-11D0-98A8-0800361B1103}"="MyDocs Folder"
          "{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
          "{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
          "{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
          "{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Menu Fichiers hors connexion"
          "{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Options du dossier Fichiers hors connexion"
          "{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Dossier Fichiers hors connexion"
          "{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
          "{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
          "{1CDB2949-8F65-4355-8456-263E7C208A5D}"="Desktop Explorer"
          "{1E9B04FB-F9E5-4718-997B-B8DA88302A47}"="Desktop Explorer Menu"
          "{1E9B04FB-F9E5-4718-997B-B8DA88302A48}"="nView Desktop Context Menu"
          "{E0D79304-84BE-11CE-9641-444553540000}"="WinZip"
          "{E0D79305-84BE-11CE-9641-444553540000}"="WinZip"
          "{E0D79306-84BE-11CE-9641-444553540000}"="WinZip"
          "{E0D79307-84BE-11CE-9641-444553540000}"="WinZip"
          "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"="WinRAR shell extension"
          "{57C51AF9-DEF7-11D3-A801-00C04F163490}"="Ghost Shell Extension"
          "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"="Multiscan"
          "{FED7043D-346A-414D-ACD7-550D052499A7}"="dBpowerAMP Music Converter 1"
          "{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5}"="dBpowerAMP Music Converter"
          "{BB7DF450-F119-11CD-8465-00AA00425D90}"="Microsoft Access Custom Icon Handler"
          "{59850401-6664-101B-B21C-00AA004BA90B}"="S‚parateur du Classeur Microsoft Office"
          "{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
          "{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Liste de saisie semi-automatique personnalis‚e MRU"
          "{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
          "{acf35015-526e-4230-9596-becbe19f0ac9}"="Barre de progrŠs auto-ouvrante"
          "{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Analyseur de la barre d'adresses"
          "{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
          "{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
          "{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
          "{32714800-2E5F-11d0-8B85-00AA0044F941}"="Des &personnes..."
          "{AB77609F-2178-4E6F-9C4B-44AC179D937A}"="aý Context Menu Shell Extension"
          "{B8323370-FF27-11D2-97B6-204C4F4F5020}"="SmartFTP Shell Extension DLL"
          "{472083B0-C522-11CF-8763-00608CC02F24}"="avast"
          "{B6122A50-EAB5-11D3-9E7F-EBF4F0595714}"="Tauscan Menu"
          "{52B87208-9CCF-42C9-B88E-069281105805}"="Trojan Remover Shell Extension"
          "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}"="Shell Extensions for RealOne Player"
          "{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Fichier de chaŒne"
          "{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Raccourci de chaŒne"
          "{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
          "{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
          "{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
          "{32020A01-506E-484D-A2A8-BE3CF17601C3}"="AlcoholShellEx"
          "{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}"="OpenOffice.org Column Handler"
          "{087B3AE3-E237-4467-B8DB-5A38AB959AC9}"="OpenOffice.org Infotip Handler"
          "{63542C48-9552-494A-84F7-73AA6A7C99C1}"="OpenOffice.org Property Sheet Handler"
          "{3B092F0C-7696-40E3-A80F-68D74DA84210}"="OpenOffice.org Thumbnail Viewer"

          **********************************************************************************
          HKEY ROOT CLASSIDS:
          **********************************************************************************
          Files Found are not all bad files:

          C:\WINNT\SYSTEM32\
          archlib.dll Wed 12 Oct 2005 22:10:16 A.S.. 180 224 176,00 K
          awvvs.dll Thu 5 Jan 2006 21:15:44 ..SH. 27 661 27,01 K
          cmdlin~1.dll Tue 3 Jan 2006 19:23:56 A.... 43 520 42,50 K
          gebcd.dll Wed 4 Jan 2006 20:17:02 ..SH. 27 661 27,01 K
          interc~1.dll Tue 25 Oct 2005 12:49:18 A.S.. 176 128 172,00 K
          interc~2.dll Tue 25 Oct 2005 12:49:14 A.S.. 307 200 300,00 K
          jbi32.dll Wed 4 Jan 2006 20:11:04 ..SH. 49 452 48,29 K
          pmkjh.dll Thu 5 Jan 2006 19:29:00 ..SH. 27 661 27,01 K
          pmnno.dll Fri 6 Jan 2006 21:18:28 ..SH. 27 661 27,01 K
          scvhos~1.dll Fri 6 Jan 2006 21:19:18 ..SH. 49 484 48,32 K
          svchos~1.dll Sat 31 Dec 2005 11:54:56 ..SH. 47 700 46,58 K
          vturo.dll Wed 4 Jan 2006 20:11:54 ..SH. 27 661 27,01 K
          w.dll Sat 31 Dec 2005 22:26:48 A.... 62 0,06 K

          13 items found: 13 files (11 H/S), 0 directories.
          Total of file sizes: 992 075 bytes 968,82 K
          Locate .tmp files:

          No matches found.
          **********************************************************************************
          Directory Listing of system files:
          Le volume dans le lecteur C n'a pas de nom.
          Le num‚ro de s‚rie du volume est EC71-97DB

          R‚pertoire de C:\WINNT\System32

          06/01/2006 21:19 49ÿ484 scvhost32.dll
          06/01/2006 21:18 27ÿ661 pmnno.dll
          05/01/2006 21:15 27ÿ661 awvvs.dll
          05/01/2006 19:28 27ÿ661 pmkjh.dll
          04/01/2006 20:17 27ÿ661 gebcd.dll
          04/01/2006 20:11 27ÿ661 vturo.dll
          04/01/2006 20:11 49ÿ452 jbi32.dll
          01/01/2006 15:35 <DIR> dllcache
          31/12/2005 11:54 47ÿ700 svchost32.dll
          25/10/2005 12:49 176ÿ128 Interceptor.dll
          25/10/2005 12:49 307ÿ200 InterceptHelper.dll
          12/10/2005 22:10 180ÿ224 archlib.dll
          11 fichier(s) 948ÿ493 octets
          1 R‚p(s) 4ÿ017ÿ197ÿ056 octets libres

          je vais faire le second

          a+
          0
          1. Re,

            Le rapport lopxp :

            Rapport fait à 22:09:17,50 le sam. 07/01/2006

            Le volume dans le lecteur C n'a pas de nom.
            Le num‚ro de s‚rie du volume est EC71-97DB

            R‚pertoire de C:\Documents and Settings\Administrateur\Application Data

            17/11/2005 23:17 <DIR> OpenOffice.org2
            08/10/2005 16:53 <DIR> Lavasoft
            07/10/2005 21:23 <DIR> Talkback
            01/09/2005 20:15 <DIR> Google
            16/08/2005 16:22 <DIR> ACD Systems
            17/07/2005 01:34 <DIR> Real
            17/06/2005 13:48 28394 Applist.txt
            17/06/2005 13:48 <DIR> EAST Technologies
            16/02/2005 19:23 <DIR> Mozilla
            03/02/2005 15:37 <DIR> AdobeUM
            03/02/2005 14:21 0 dm.ini
            11/01/2005 00:43 <DIR> SmartFTP
            19/12/2004 22:03 <DIR> Adobe
            19/12/2004 22:03 <DIR> InterTrust
            28/11/2004 21:05 <DIR> Macromedia
            28/11/2004 19:04 <DIR> Help
            28/11/2004 18:28 <DIR> Symantec
            28/11/2004 15:35 <DIR> Identities
            28/11/2004 15:35 <DIR> .
            28/11/2004 15:35 <DIR> ..
            28/11/2004 15:35 <DIR> Microsoft
            2 fichier(s) 28394 octets
            19 R‚p(s) 4020072448 octets libres
            Le volume dans le lecteur C n'a pas de nom.
            Le num‚ro de s‚rie du volume est EC71-97DB

            R‚pertoire de C:\Documents and Settings\All Users\Application Data

            01/01/2006 15:47 <DIR> Tenebril
            08/10/2005 21:17 <DIR> Kaspersky Anti-Virus Personal
            16/08/2005 16:13 <DIR> ACD Systems
            16/08/2005 16:10 <DIR> QuickTime
            14/02/2005 18:34 <DIR> MSN Messenger 6.2.0205
            03/02/2005 14:26 <DIR> Adobe
            29/12/2004 13:06 <DIR> Spybot - Search & Destroy
            08/12/2004 20:06 <DIR> nView_Profiles
            28/11/2004 18:28 <DIR> Symantec
            28/11/2004 15:28 <DIR> Microsoft
            28/11/2004 15:21 <DIR> ..
            28/11/2004 15:21 <DIR> .
            0 fichier(s) 0 octets
            12 R‚p(s) 4020072448 octets libres
            Le volume dans le lecteur C n'a pas de nom.
            Le num‚ro de s‚rie du volume est EC71-97DB

            R‚pertoire de C:\Documents and Settings\Default User\Application Data

            28/09/2005 18:45 <DIR> Mozilla
            28/09/2005 18:45 <DIR> Real
            28/09/2005 18:44 <DIR> Identities
            28/11/2004 15:31 <DIR> Microsoft
            28/11/2004 15:21 <DIR> ..
            28/11/2004 15:21 <DIR> .
            0 fichier(s) 0 octets
            6 R‚p(s) 4020072448 octets libres
            ******************************************
            Recherche des taches planifiées dans C:\WINNT\tasks

            Le volume dans le lecteur C n'a pas de nom.
            Le num‚ro de s‚rie du volume est EC71-97DB

            R‚pertoire de C:\WINNT\Tasks

            28/11/2004 15:31 6 SA.DAT
            28/11/2004 15:30 65 desktop.ini
            28/11/2004 15:30 <DIR> ..
            28/11/2004 15:30 <DIR> .
            2 fichier(s) 71 octets
            2 R‚p(s) 4ÿ020ÿ072ÿ448 octets libres

            ******************************************
            Recherche dans Program files

            Le dossier C:\Program Files\C2Media n'existe pas

            *************** Fin du rapport ****************

            Je continue par lm2fix,

            a+

            PS: Fallait faire ce log avec fichiers masqués ou démasqués ?
            0
            1. Bonsoir,

              Merci de prendre la relève :)

              Je suis enfin arrivé à me reconnecter (j'avais message : "Erreur du programme : LSASS.exe a généré des erreurs...etc.." et je ne pouvais lancer aucun programme).
              C'etait à chaque connection internet.
              J'ai donc passé beaucoup de temps à essayer de nettoyer...

              Je fais ce soir ce que vous me dites plus haut (posts 16 et 17) et je reviens.

              a+
              0
              1. Bonjour,

                Peux-tu me dire comment tu as fait pour te débarrasser de ce message d'erreur car moi ça fait trois jours que j'essaye sans succès !!!

                Merci
                0
            2. Contributeur
              Ah non alors !

              Ce n'est pas le travail qui manque !

              A++

              0
              1. Contributeur
                Suis les consignes de Bernie, que je salue au passage.

                A+

                0
                1. oui salut à toi
                  sacrée soirée, lol
                  on chôme pas
                  a+
                  0
              2. salut vous deux
                en complément des autres, fixer aussi
                O4 - HKLM\..\Run: [WinDLL (svchost32.dll)] rundll32.exe C:\WINNT\system32\svchost32.dll,start
                O4 - HKLM\..\Run: [WinDLL (jbi32.dll)] rundll32.exe C:\WINNT\system32\jbi32.dll,start

                et lancer l2mfix http://users.skynet.be/BernieClub/#l2mfix
                a+
                0
                1. Re,

                  (Je venais poster en réponse à ton post 14 et je viens juste de voir ton post 13...j'étais trop pressé et j'avais pas relu le fil....désolé... et là je n'ai plus le temps pour ce soir de tout refaire, je referai tout dans l'ordre demain soir à partir de défrag et tout le reste).

                  Voici quand même les réponses à ton post n°14 :

                  ***"O13 - DefaultPrefix " => impossible à fixer (je le fais mais elle ne disparait jamais)

                  ***"C:\WINNT\SYSTEM32\jkhfd.dll
                  et supprime le dossier "jkhfd.dll " - que le dossier !! "


                  ===> impossible, message :"Le fichier spécifié est utilisé par Windows"

                  ***"fais fonctionner ton antivirus+spybot+ad-aware+ewido+spycatcher+cleanup40"

                  ===> spybot détecte toujours le malware Azesearch (risque élévé) mais ne peut jamais le supprimer.
                  Emplacement :
                  Hkeylocalmachine\software\classes\ztoolbar.stockbar.1
                  Hkeylocalmachine\software\classes\ztoolbar.stockbar
                  Hkeylocalmachine\software\classes\ztoolbar.ParamWr.1
                  Hkeylocalmachine\software\classes\ztoolbar.ParamWr
                  Hkeylocalmachine\software\classes\ztoolbar.activator.1
                  Hkeylocalmachine\software\classes\ztoolbar.activator

                  A la connection j'ai encore eu les alertes Avast, ca donne ca :

                  C\documentsandsettings\administrateur\localsettings\temporaryinternetfiles\contentIE5\S5M7CPMR\drsmartload.exe
                  ===> Avast recommande la quarantaine mais ne peut pas le faire, alors je clique sur supprimer et j'ai alors cette alerte virus:

                  C\drsmartload1.exe
                  ===>idem, quarantaine impossible j'ai cliqué sur supprimer.

                  Ca se passe comme ca à chaque connexion internet.
                  De plus cette fois j'ai eu C\winnt\system32\IEXPLORE.exe
                  ===>quarantaine puis suppression définitive et vidage corbeille.

                  Le rapport Smitfraud :
                  SmitFraudFix v2.10

                  Rapport fait à 21:05:40,71 le jeu. 05/01/2006
                  Executé à partir de C:\SmitfraudFix
                  OS: Microsoft Windows 2000 [Version 5.00.2195]

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINNT

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINNT\system

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINNT\Web

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINNT\system32

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Administrateur\Application Data

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                  "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
                  "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

                  Log Hijack :

                  Logfile of HijackThis v1.99.1
                  Scan saved at 21:06:15, on 05/01/2006
                  Platform: Windows 2000 SP4 (WinNT 5.00.2195)
                  MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                  Running processes:
                  C:\WINNT\System32\smss.exe
                  C:\WINNT\system32\winlogon.exe
                  C:\WINNT\system32\services.exe
                  C:\WINNT\system32\lsass.exe
                  C:\WINNT\system32\svchost.exe
                  C:\WINNT\system32\spoolsv.exe
                  C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  C:\WINNT\System32\svchost.exe
                  C:\Program Files\ewido anti-malware\ewidoctrl.exe
                  C:\WINNT\system32\hidserv.exe
                  C:\WINNT\system32\nvsvc32.exe
                  C:\Program Files\Tiny Personal Firewall\persfw.exe
                  C:\WINNT\system32\MSTask.exe
                  C:\WINNT\system32\stisvc.exe
                  C:\WINNT\System32\WBEM\WinMgmt.exe
                  C:\WINNT\system32\mspmspsv.exe
                  C:\WINNT\Explorer.EXE
                  C:\WINNT\soundman.exe
                  C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
                  C:\PROGRA~1\Wanadoo\taskbaricon.exe
                  C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\WINNT\system32\rundll32.exe
                  C:\WINNT\system32\rundll32.exe
                  C:\Program Files\MSN Messenger\msnmsgr.exe
                  C:\Program Files\WinZip\WZQKPICK.EXE
                  C:\Program Files\Microsoft Office\Office\OSA.EXE
                  C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
                  C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
                  C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
                  C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                  C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                  C:\Hijackthis\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINNT\system32\jkhfd.dll (file missing)
                  O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll
                  O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                  O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                  O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
                  O4 - HKLM\..\Run: [SoundMan] soundman.exe
                  O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
                  O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\watch.exe
                  O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\taskbaricon.exe
                  O4 - HKLM\..\Run: [LoadQM] loadqm.exe
                  O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
                  O4 - HKLM\..\Run: [WinDLL (svchost32.dll)] rundll32.exe C:\WINNT\system32\svchost32.dll,start
                  O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
                  O4 - HKLM\..\Run: [WinDLL (jbi32.dll)] rundll32.exe C:\WINNT\system32\jbi32.dll,start
                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                  O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                  O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
                  O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
                  O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
                  O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
                  O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                  O13 - DefaultPrefix:
                  O20 - AppInit_DLLs: interceptor.dll
                  O20 - Winlogon Notify: jkhfd - jkhfd.dll (file missing)
                  O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                  O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                  O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                  O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                  O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                  O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
                  O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe

                  Les lignes 020 sont toujours là et se multiplient on dirait...

                  Voilà, encore désolé d'avoir lu trop vite ton dernier post et pas le précédent, demain soir j'aurai j'espère le temps de tout faire dans l'ordre.

                  Bonne soirée,
                  a+

                  PS : Je viens qd même de faire le scan BitDefender : Aucun virus trouvé.
                  0
                  1. Contributeur
                    re
                    1.redémarre en mode sans échec (redéemarrage + tapote sans arrêt sur F8 (ou f5 suivant type ordi) dés que l'ordi s'allume)

                    3. affiche les fichiers cachés comme ceci :
                    clic sur démarrer/panno config/options des dossiers/affichage
                    Coche " afficher les dossiers cachés"
                    Décoche la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"
                    Decoche " masquer les extentions dont le type est connu"
                    puis fais «Ok» pour valider les changements.

                    4 - hijac
                    fixe
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                    O13 - DefaultPrefix:
                    O20 - Winlogon Notify: jkhfd - C:\WINNT\SYSTEM32\jkhfd.dll

                    5 - cherche
                    C:\WINNT\SYSTEM32\jkhfd.dll
                    et supprime le dossier "jkhfd.dll " - que le dossier !!

                    6- fais fonctionner ton antivirus+spybot+ad-aware+ewido+spycatcher+cleanup40, enfin tous tes outils de nettoyage
                    vide ttes les quarantaines
                    vide la poubelle

                    7 - reviens en mode normal et fais en sens inverse le paragraphe "3"

                    8 - refais un smitfraud avec rapports

                    9 - poste un hijac

                    0
                    1. Contributeur
                      bsr
                      fais un scan online avec
                      http://www.bitdefender.fr/bd/site/search.php#
                      et colle rapport
                      --------
                      fais une défragmentation - pour mémoire , elle doit être faite quand les dossiers fragmentés atteignent 10%
                      ------------
                      diminue le nbre de log au démarrage:
                      pour faire,
                      démarrer+exécuter+tape msconfig+ok+va dans onglet démarrage+supprime tout sauf antivirus et pare-feu(si tu as un doute,tu laisses+un redémarrage sera demandé, lis bien les indications
                      -------
                      mets à jour spybot,ad-aware,ewido,spycatcher - vide leur quarantaine - vont servir
                      ---------
                      si tu n'as pas de de nettoyeur de registre télécharge RegCleaner, logiciel sur
                      http://www.01net.com/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/4894.html

                      fonctionnement:
                      -dans barre menu+outils+nettoyer registre+tout faire+cocher ttes les lignes+supprime (toutes les lignes seront en sauvegard
                      -en-dessous barre menu, clic sur types de fichiers+coche tous les N/A+supprimer(les lignes seront en sauvegarde)
                      ----------
                      ce log va être utile aussi,CleanUp40
                      il nettoie les cookies,temps,tempos,historique,etc.....
                      http://pageperso.aol.fr/Balltrap34/CleanUp40.exe
                      http://pageperso.aol.fr/balltrap34/democleanup.htm
                      ------------
                      je te prépare un tuto pour la suite

                      à +

                      0
                      1. Re,

                        Dernière minute, je viens de faire un log Hujack et c'est très infecté, voir notamment ligne 020:

                        Logfile of HijackThis v1.99.1
                        Scan saved at 22:18:33, on 04/01/2006
                        Platform: Windows 2000 SP4 (WinNT 5.00.2195)
                        MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

                        Running processes:
                        C:\WINNT\System32\smss.exe
                        C:\WINNT\system32\winlogon.exe
                        C:\WINNT\system32\services.exe
                        C:\WINNT\system32\lsass.exe
                        C:\WINNT\system32\svchost.exe
                        C:\WINNT\system32\spoolsv.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\WINNT\System32\svchost.exe
                        C:\Program Files\ewido anti-malware\ewidoctrl.exe
                        C:\WINNT\system32\hidserv.exe
                        C:\WINNT\system32\nvsvc32.exe
                        C:\Program Files\Tiny Personal Firewall\persfw.exe
                        C:\WINNT\system32\MSTask.exe
                        C:\WINNT\system32\stisvc.exe
                        C:\WINNT\System32\WBEM\WinMgmt.exe
                        C:\WINNT\system32\mspmspsv.exe
                        C:\WINNT\Explorer.EXE
                        C:\WINNT\soundman.exe
                        C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
                        C:\PROGRA~1\Wanadoo\taskbaricon.exe
                        C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\WINNT\system32\rundll32.exe
                        C:\WINNT\system32\rundll32.exe
                        C:\Program Files\MSN Messenger\msnmsgr.exe
                        C:\Program Files\WinZip\WZQKPICK.EXE
                        C:\Program Files\Microsoft Office\Office\OSA.EXE
                        C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
                        C:\Program Files\OpenOffice.org 2.0\program\soffice.exe
                        C:\Program Files\OpenOffice.org 2.0\program\soffice.BIN
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
                        C:\PROGRA~1\Wanadoo\ComComp.exe
                        C:\PROGRA~1\Wanadoo\Watch.exe
                        C:\WINNT\system32\cmd.exe
                        C:\Program Files\Internet Explorer\iexplore.exe
                        C:\Hijackthis\HijackThis.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.wanadoo.fr/go/page_recherche/
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wanadoo.fr
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: SpywareBlock Class - {0A87E45F-537A-40B4-B812-E2544C21A09F} - C:\Program Files\SpyCatcher 2006\SCActiveBlock.dll
                        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
                        O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
                        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
                        O4 - HKLM\..\Run: [SoundMan] soundman.exe
                        O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
                        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\watch.exe
                        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\taskbaricon.exe
                        O4 - HKLM\..\Run: [LoadQM] loadqm.exe
                        O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
                        O4 - HKLM\..\Run: [WinDLL (svchost32.dll)] rundll32.exe C:\WINNT\system32\svchost32.dll,start
                        O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
                        O4 - HKLM\..\Run: [WinDLL (jbi32.dll)] rundll32.exe C:\WINNT\system32\jbi32.dll,start
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                        O4 - Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                        O4 - Startup: Démarrage d'Office.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXE
                        O4 - Startup: Microsoft Recherche accélérée.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
                        O4 - Startup: OpenOffice.org 2.0.lnk = C:\Program Files\OpenOffice.org 2.0\program\quickstart.exe
                        O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
                        O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
                        O13 - DefaultPrefix:
                        O17 - HKLM\System\CCS\Services\Tcpip\..\{D4F1A94C-9D94-44E8-B5A0-EB63D8237C03}: NameServer = 80.10.246.1 80.10.246.132
                        O20 - AppInit_DLLs: interceptor.dll
                        O20 - Winlogon Notify: jkhfd - C:\WINNT\SYSTEM32\jkhfd.dll
                        O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                        O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                        O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
                        O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
                        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
                        O23 - Service: Tiny Personal Firewall (PersFw) - Tiny Software - C:\Program Files\Tiny Personal Firewall\persfw.exe

                        J'ai fait analyser C:\WINNT\SYSTEM32\jkhfd.dll par Virus total ca donne ca :

                        This is a report processed by VirusTotal on 01/04/2006 at 22:18:00 (CET) after scanning the file "jkhfd.dll" file.
                        Antivirus Version Update Result
                        AntiVir 6.33.0.74 01.04.2006 TR/Dldr.ConHook.Q.2
                        Avast 4.6.695.0 01.03.2006 no virus found
                        AVG 718 01.04.2006 no virus found
                        Avira 6.33.0.74 01.04.2006 TR/Dldr.ConHook.Q.2
                        BitDefender 7.2 01.04.2006 no virus found
                        CAT-QuickHeal 8.00 01.04.2006 no virus found
                        ClamAV devel-20051123 01.04.2006 no virus found
                        DrWeb 4.33 01.04.2006 Trojan.DownLoader.4412
                        eTrust-Iris 7.1.194.0 01.04.2006 no virus found
                        eTrust-Vet 12.4.1.0 01.04.2006 Win32/Chisyne.T
                        Ewido 3.5 01.03.2006 no virus found
                        Fortinet 2.54.0.0 01.04.2006 suspicious
                        F-Prot 3.16c 01.04.2006 no virus found
                        Ikarus 0.2.59.0 01.04.2006 no virus found
                        Kaspersky 4.0.2.24 01.04.2006 no virus found
                        McAfee 4667 01.04.2006 no virus found
                        NOD32v2 1.1352 01.04.2006 a variant of Win32/TrojanDownloader.ConHook
                        Norman 5.70.10 12.31.2006 no virus found
                        Panda 9.0.0.4 01.04.2006 Spyware/Virtumonde
                        Sophos 4.01.0 01.04.2006 no virus found
                        Symantec 8.0 01.04.2006 no virus found
                        TheHacker 5.9.2.067 01.02.2006 no virus found
                        UNA 1.83 01.04.2006 no virus found
                        VBA32 3.10.5 01.04.2006 Trojan.DownLoader.4412

                        Voilà...:(

                        a+
                        0
                        1. Re,

                          Rapport d'E wido :

                          ---------------------------------------------------------
                          ewido anti-malware - Rapport de scan
                          ---------------------------------------------------------

                          + Créé le: 21:45:44, 04/01/2006
                          + Somme de contrôle: 8BB6548

                          + Résultats du scan:

                          HKLM\SOFTWARE\Classes\ZToolbar.activator -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.activator\CLSID -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.activator\CurVer -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.activator.1 -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.ParamWr -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.ParamWr\CLSID -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.ParamWr\CurVer -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.ParamWr.1 -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.StockBar -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.StockBar\CLSID -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.StockBar\CurVer -> Spyware.Azsearch : Erreur durant le nettoyage
                          HKLM\SOFTWARE\Classes\ZToolbar.StockBar.1 -> Spyware.Azsearch : Erreur durant le nettoyage
                          [1124] C:\WINNT\system32\jkhfd.dll -> Downloader.ConHook.v : Nettoyer et sauvegarder
                          C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\4T638LYJ\drsmartload[1].exe -> Downloader.Adload.l : Nettoyer et sauvegarder
                          C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\S167C1YZ\dollar[1].zip -> Downloader.Adload.j : Nettoyer et sauvegarder
                          C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\S167C1YZ\raser[1].zip -> Downloader.ConHook.n : Nettoyer et sauvegarder
                          C:\dr32.exe -> Downloader.Adload.j : Nettoyer et sauvegarder

                          ::Fin du rapport

                          Pour finir je dois dire que mon Pc est redevenu très très lent...

                          a+
                          0
                          1. Re,

                            Réponse au Post 7 (fin) :
                            rapport Smitfraudfix mode normal, option 2 :

                            SmitFraudFix v2.10

                            Rapport fait à 21:27:56,71 le mer. 04/01/2006
                            Executé à partir de C:\SmitfraudFix
                            OS: Microsoft Windows 2000 [Version 5.00.2195]

                            »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                            »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                            C:\WINNT\blank.mht supprimé

                            »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                            Nettoyage terminé.

                            »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

                            Voilà, pour finir je colle le dernier rapport d'Ewido dans le post suivant

                            a+
                            0
                            1. Re,

                              Pour répondre au post 7 (suite) :

                              Rapport smitfraudfix option1 :

                              SmitFraudFix v2.10

                              Rapport fait à 21:19:14,20 le mer. 04/01/2006
                              Executé à partir de C:\SmitfraudFix
                              OS: Microsoft Windows 2000 [Version 5.00.2195]

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINNT

                              C:\WINNT\blank.mht PRESENT !

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINNT\system

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINNT\Web

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\WINNT\system32

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Documents and Settings\Administrateur\Application Data

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche Menu Démarrer

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche Bureau

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche C:\Program Files

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche présence de clés corrompues

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche éléments du bureau

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                              "Source"="About:Home"
                              "SubscribedURL"="About:Home"
                              "FriendlyName"="Ma page d'accueil"

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche Sharedtaskscheduler

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                              "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Pr‚-chargeur Browseui"
                              "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="D‚mon de cache des cat‚gories de composant"

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                              »»»»»»»»»»»»»»»»»»»»»»»» Fin du rapport

                              (rapport n° 2 dans le post suivant)

                              a+
                              0
                              1. Bonsoir,

                                J'ai mis du temps à répondre car les infections que je supprimais revenaient dès la connexion d'après, un vrai bazar, et j'ai essayé de tout bien noter pour que ce soit clair....mais y a eu tellement de choses que j'en oublie peut-être...en tout cas Ewido supprime beaucoup de choses à chaque fois, mais elles reviennent toujours.

                                (Il y a 5 minutes nouvelles alertes, je colle le dernier rapport d'Ewido dans un post suivant)

                                Bref, pour répondre à :

                                Post 06 :

                                **O13 - DefaultPrefix: =====> impossible à fixer : en mode normal ou sans échec ca ne marche pas.

                                **016 ===> toutes fixées, OK

                                Post 07 :

                                **C:\WINNT\System32\msdxm.ocx ====> analysé par VirusTotal, aucun virus trouvé.

                                **020 ===> suis allé sur http://www.all-nettools.com/toolbox/
                                mais pas compris ce que je devais faire.

                                Je colle les rapports smitfraudfix dans le post suivant,

                                a+
                                0
                                1. Contributeur
                                  re

                                  pour la 020: RAS à moins que tu ne connaisse un blem particulier, dans ce cas à découvrir - analyse possible au
                                  http://www.all-nettools.com/toolbox/

                                  pour la 03 faire analyse par
                                  http://www.virustotal.com/flash/index_en.html
                                  de cette ligne
                                  C:\WINNT\System32\msdxm.ocx
                                  et coller résultat
                                  ------
                                  fais ceci aussi, pour être sur
                                  Télécharge ceci: (merci a S!RI pour ce petit programme).
                                  http://siri.urz.free.fr/Fix/SmitfraudFix.zip
                                  Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport
                                  Copie/colle le sur le poste stp.
                                  ----------------------------------------------------------------------------
                                  Démarre en mode sans échec :
                                  Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                                  Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                                  Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                                  (Si F8 ne marche pas utilise la touche F5).
                                  ----------------------------------------------------------------------------
                                  Relance le programme Smitfraud,
                                  Cette fois choisit l’option 2, répond oui a tous ;
                                  Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum

                                  0
                                  • 1
                                  • 2