Virus récalcitrant...

Bonjour,

J'ai depuios deux jours un virus actif sur mon PC. Après avoir fait tourner différents anti-virus (dans un ordre un peu aléatoire...) ça va un peu mieux mais le virus se réactive dès que j'essaye d'accéder à une page web spécifique (Forum VeloVert).

J'aurai donc bien besoin d'un avis d'expert pour m'aider à m'en sortir.

D'avance Merci.

Pour commencer j'ai fait tourner ZHPDiag, voici le rapport: http://www.cijoint.fr/cjlink.php?file=cj201110/cijJ5Z9Ua1.txt

Je continue la procédure et poste les rapports suivants MalwareBytes Anti-Malware et Kaspersky.

A Bientôt.

Vincent

37 réponses

Résumé de la discussion

Infection détectée sur un PC Windows 7 où le virus se réactive lors de l'accès à une page web précise, malgré le passage de plusieurs antivirus dans un ordre variable. Plusieurs outils spécialisés ont été utilisés, tels ZHPDiag, Trojan Killer, OTM et RogueKiller, et des éléments malveillants comme unacev2.dll ont été localisés dans System32 et dans le dossier WinRAR, avec des rapports détaillés. Les démarches ont inclus la désactivation puis la réactivation de la restauration système, la suppression des points et des fichiers suspects via MoveIt et scripts, et des vérifications répétées qui ont conduit à une amélioration notable.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    tu peux

    vérifie avec ton antivirus que tout est ok

    bonne suite
    0
    1. Super, faut il que je passe le sujet en résolu?

      Bonne soirée.

      Vincent
      0
      1. Contributeur sécurité
        pour supprimer ce qui a été utilisé:

        http://www.commentcamarche.net/faq/24877-supprimer-les-logiciels-de-desinfection
        0
        1. Salut,

          Voici le rapport: http://www.cijoint.fr/cjlink.php?file=cj201111/cijv9TIbnN.txt

          Le PC semble aller correctement. Mon pb de fichiers et raccourci était en faite des paramétres que j'avais changer pour tenter de résoudre le pb de virus.

          Il faut maintenant que je fasse un peu le ménage de tous les utilitaires que j'ai téléchargé!

          a+ et merci encore une fois!

          Vincent
          0
          1. Contributeur sécurité
            je veux bien le rapport préscan (faire passer par le site cijoint)

            sinon comment va le pc ? quels problèmes actuellement?)
            0
            1. Salut,

              J'ai fait tourner tout ce que tu m'as dit et ça semble aller beaucoup mieux, encore une fois: MERCI!!

              As tu besoin du rapport de pre_scan? car il est super long.

              Voici le rapport de pre_script:

              a+

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Pre_Script | 1.0.2.96 ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

              ¤¤¤¤¤ XP | Vista | Seven - 32/64 bits ¤¤¤¤¤

              Mise à jour : 17/10/2011 | 00.40 Par g3n-h@ckm@n
              Utilisateur : Vincent (Administrateurs)
              Système d'exploitation : Windows 7 Home Premium (64 bits)
              Internet Explorer : 8.0.7600.16385
              Mozilla Firefox :

              Switchs possibles :

              processes:: | file:: | folder:: | Registry::
              Driver:: | replace:: | DNS:: | Command::
              attrib:: | txt:: | Host:: | NsLook::
              list:: | IP:: | ADS:: | Kill:: | clean::

              Script : 20:06:31

              ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤

              Disques externes : 4 Objets réattribués
              Disque Local : 5 Objets réattribués
              Utilisateurs : 1 Objets réattribués
              ProgramFiles : 12 Objets réattribués
              Music : 151 Objets réattribués
              Pictures : 0 Objets réattribués
              Videos : 0 Objets réattribués
              Downloads : 0 Objets réattribués
              Desktop : 2 Objets réattribués
              Links : 0 Objets réattribués
              Searches : 0 Objets réattribués
              Contacts : 0 Objets réattribués
              Saved Games : 0 Objets réattribués
              Favorites : 0 Objets réattribués
              Documents : 15 Objets réattribués
              Windows : 100 Objets réattribués
              StartMenu : 2 Objets réattribués
              Librairies : 0 Objets réattribués
              Quick Launch : 0 Objets réattribués
              %AppData% : 5 Objets réattribués

              ¤

              Fin : 20:07:21

              ¤¤¤¤¤¤¤¤¤¤ ( EOF ) ¤¤¤¤¤¤¤¤¤¤
              0
              1. Contributeur sécurité
                Désactivez vos protections puis enregistrez ceci sur votre bureau
                Téléchargez Pre_Scan ici: http://dl.dropbox.com/u/21363431/Pre_scan.exe

                ou mirroir :

                http://www.archive-host.com

                Transférez le logiciel sur le bureau si il n'a pas été enregistré sur votre bureau

                Avertissement: Il y aura une extinction courte du bureau --> pas de panique.

                une fois téléchargé sur le bureau, lancez-le , laissez faire l'analyse jusqu'à l'apparition de "Pre_scan.txt" sur le bureau. Faîtes passer le rapport sur le forum si vous vous faîtes aider.

                rq: Il se peut que l'outil soit un peu long sur l'attribution des fichiers (tout dépend du nombre que vous avez) , laissez-le travailler jusqu'au bout.

                Faites glisser une icône du bureau sur l'icône Pre_Scan : Pre_Script va apparaître.
                Dans le fichier bloc note qui s'ouvre coller la ligne suivante:


                attrib::


                Fichier>Enregistrer le fichier
                Fermer le bloc note
                0
                1. J'ai essayé de relancer rogue killer mais celà n'a pas d'effet sur les pb que j'ai cité.

                  voici le rapport:

                  RogueKiller V6.1.4 [22/10/2011] par Tigzy
                  contact sur http://www.sur-la-toile.com
                  mail: tigzyRK<at>gmail<dot>com
                  Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
                  Blog: http://tigzyrk.blogspot.com

                  Systeme d'exploitation: Windows 7 (6.1.7600 ) 64 bits version
                  Demarrage : Mode normal
                  Utilisateur: Vincent [Droits d'admin]
                  Mode: Raccourcis RAZ -- Date : 01/11/2011 07:26:10

                  Processus malicieux: 0

                  Driver: [NOT LOADED]

                  Attributs de fichiers restaures:
                  Bureau: Success 0 / Fail 0
                  Lancement rapide: Success 0 / Fail 0
                  Programmes: Success 0 / Fail 0
                  Menu demarrer: Success 0 / Fail 0
                  Dossier utilisateur: Success 39 / Fail 0
                  Mes documents: Success 0 / Fail 0
                  Mes favoris: Success 0 / Fail 0
                  Mes images: Success 0 / Fail 0
                  Ma musique: Success 0 / Fail 0
                  Mes videos: Success 0 / Fail 0
                  Disques locaux: Success 12 / Fail 0
                  Sauvegarde: [NOT FOUND]

                  Lecteurs:
                  [C:] \Device\HarddiskVolume2 -- 0x3 --> Restored
                  [D:] \Device\HarddiskVolume3 -- 0x3 --> Restored
                  [E:] \Device\CdRom0 -- 0x5 --> Skipped

                  Termine : << RKreport[2].txt >>
                  RKreport[1].txt ; RKreport[2].txt

                  a+
                  0
                  1. Contributeur sécurité
                    Téléchargez sur le bureau RogueKiller
                    Quittez tous les programmes en cours
                    Sous Vista/Seven , clic droit -> lancez en tant qu'administrateur
                    Sinon lancez simplement RogueKiller.exe
                    Lorsque cela est demandé, tapez 6 et validez
                    Un rapport à dû s'ouvrir (RKreport.txt se trouve également à côté de l'exécutable), donnez son contenu à la personne qui vous aide sur le forum
                    Si le programme a été bloqué, ne pas hésiter à essayer plusieurs fois. Si vraiment cela ne passe pas (ça peut arriver), le renommer en winlogon.exe

                    ensuite dis nous comment va ton pc
                    0
                    1. Bon je ne comprends toujours pas pourquoi je n'arrive pas à visualiser mes posts sur le forum, mais j'ai lu tes réponses dans mes mails...
                      J'ai donc supprimer le fichier que tu m'as indiqué manuellement et refais tourner trojan killer et.... tout est clean maintenant: MERCI!

                      Cependant j'ai encore quelques questions, suite à l'infection et à tout les manip':

                      - je n'ai plus rien dans les barres de lancement rapides, et dans le menu démarrer j'ai un menu "blanc".
                      - ensuite dans "Mes documents", j'ai des dossiers sécurisés qui se sont créés type MyMusic, MaMusique, la même pour les images etc...

                      Est ce grave docteur?
                      0
                      1. Je viens de poster à deux reprises les autres rapport mais je ne les vois pas sur le forum.... je ne comprends pas
                        0
                        1. Mais.... trojan killer n'est toujours pas content :

                          GridinSoft Trojan Killer v.2.1.1.0
                          Report file date: 31/10/2011 18:45:31

                          Scanning for 431061 virus strains and unwanted programs.

                          Licensed: UNREGISTERED
                          Windows version: Windows 7 Home Premium (version 6.1)
                          Username: Vincent

                          Starting the file scan:

                          Startup collected
                          BHO plugins collected
                          Service collected
                          ActiveX collected
                          Files collected
                          Scanning process...
                          ----- C:\Users\Vincent\AppData\Roaming\microsoft\internet explorer\quick launch\system restore.lnk ---- General
                          Rogue.FakeAV.Win32h.SystemRestore
                          MD5: B1DE2E77EB7214B3C301BEE0F34BC623:688
                          EP: 00
                          SEC:

                          Scan completed!

                          Scan result: 1 detected items
                          Scan completed in: Scan completed in 7 minute(s) 44 sec.
                          Files were scanned: 12150
                          0
                          1. Et le rapport de OTM:

                            All processes killed
                            ========== PROCESSES ==========
                            No active process named explorer.exe was found!
                            ========== FILES ==========
                            File/Folder C:\Users\Vincent\AppData\Roaming\microsoft\internet explorer\quick launch\system restore.lnk :commands not found.
                            File/Folder [purity] not found.
                            File/Folder [emptytemp] not found.
                            File/Folder [start explorer] not found.

                            OTM by OldTimer - Version 3.1.19.0 log created on 10312011_182956
                            0
                            1. Contributeur sécurité
                              ok fais la suite

                              a plus
                              0
                              1. Et pour finir le rapport de OTM:

                                All processes killed
                                ========== PROCESSES ==========
                                No active process named explorer.exe was found!
                                ========== FILES ==========
                                File/Folder C:\Users\Vincent\AppData\Roaming\microsoft\internet explorer\quick launch\system restore.lnk :commands not found.
                                File/Folder [purity] not found.
                                File/Folder [emptytemp] not found.
                                File/Folder [start explorer] not found.

                                OTM by OldTimer - Version 3.1.19.0 log created on 10312011_182956
                                0
                                1. Voici le rapport de rogue killer "option 2":

                                  RogueKiller V6.1.4 [22/10/2011] par Tigzy
                                  contact sur http://www.sur-la-toile.com
                                  mail: tigzyRK<at>gmail<dot>com
                                  Remontees: http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
                                  Blog: http://tigzyrk.blogspot.com

                                  Systeme d'exploitation: Windows 7 (6.1.7600 ) 64 bits version
                                  Demarrage : Mode normal
                                  Utilisateur: Vincent [Droits d'admin]
                                  Mode: Suppression -- Date : 31/10/2011 18:27:09

                                  Processus malicieux: 1
                                  [HJ NAME] ctfmon.exe -- c:\windows\syswow64\ctfmon.exe -> KILLED [TermProc]

                                  Entrees de registre: 1
                                  [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> REPLACED ()

                                  Fichiers / Dossiers particuliers:

                                  Driver: [NOT LOADED]

                                  Fichier HOSTS:
                                  127.0.0.1 localhost

                                  Termine : << RKreport[1].txt >>
                                  RKreport[1].txt
                                  0
                                  1. Voici le rapport complet de combofix, enfin je pense:

                                    ComboFix 11-10-30.03 - Vincent 31/10/2011 16:43:46.1.2 - x64
                                    Microsoft Windows 7 Édition Familiale Premium 6.1.7600.0.1252.33.1036.18.4061.2721 [GMT 1:00]
                                    Lancé depuis: c:\users\Vincent\Desktop\ComboFix.exe
                                    AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
                                    SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
                                    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
                                    * Un nouveau point de restauration a été créé
                                    .
                                    .
                                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    c:\users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore
                                    c:\users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore\System Restore.lnk
                                    c:\users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Restore\Uninstall System Restore.lnk
                                    .
                                    .
                                    ((((((((((((((((((((((((((((( Fichiers créés du 2011-09-28 au 2011-10-31 ))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    2011-10-31 15:51 . 2011-10-31 15:51 69000 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4B9BE15C-F1BB-4858-921A-10EF335CC48E}\offreg.dll
                                    2011-10-31 15:49 . 2011-10-31 15:49 -------- d-----w- c:\users\Default\AppData\Local\temp
                                    2011-10-31 07:59 . 2011-10-31 08:22 -------- d-----w- c:\windows\89A072791DB3485AB1DF584DF86774B9.TMP
                                    2011-10-30 08:06 . 2011-10-30 10:25 -------- d-----w- c:\program files (x86)\ESET
                                    2011-10-30 07:26 . 2011-10-31 08:22 -------- d-----w- C:\sh4ldr
                                    2011-10-30 07:26 . 2011-10-30 07:26 -------- d-----w- c:\program files\Enigma Software Group
                                    2011-10-28 22:23 . 2011-10-28 22:23 -------- d-----w- c:\users\Vincent\AppData\Roaming\thecleaner
                                    2011-10-28 22:22 . 2011-10-28 22:24 -------- d-----w- c:\program files (x86)\The Cleaner
                                    2011-10-28 22:09 . 2006-06-19 11:01 69632 ----a-w- c:\windows\SysWow64\ztvcabinet.dll
                                    2011-10-28 22:09 . 2006-05-25 13:52 162304 ----a-w- c:\windows\SysWow64\ztvunrar36.dll
                                    2011-10-28 22:09 . 2005-08-25 23:50 77312 ----a-w- c:\windows\SysWow64\ztvunace26.dll
                                    2011-10-28 22:09 . 2003-02-02 18:06 153088 ----a-w- c:\windows\SysWow64\UNRAR3.dll
                                    2011-10-28 22:08 . 2011-10-28 22:09 -------- d-----w- c:\program files (x86)\Trojan Remover
                                    2011-10-28 22:08 . 2011-10-28 22:08 -------- d-----w- c:\users\Vincent\AppData\Roaming\Simply Super Software
                                    2011-10-28 22:08 . 2011-10-28 22:08 -------- d-----w- c:\programdata\Simply Super Software
                                    2011-10-28 21:46 . 2011-10-31 08:37 -------- d-----w- c:\program files (x86)\GridinSoft Trojan Killer
                                    2011-10-28 21:06 . 2011-10-28 21:06 -------- d-----w- c:\program files\CCleaner
                                    2011-10-28 20:49 . 2011-10-28 20:50 -------- d-----w- C:\ZHP
                                    2011-10-28 17:58 . 2011-10-07 04:16 8570192 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{4B9BE15C-F1BB-4858-921A-10EF335CC48E}\mpengine.dll
                                    2011-10-27 21:47 . 2009-06-30 08:37 33800 ----a-w- c:\windows\system32\drivers\pavboot64.sys
                                    2011-10-27 21:47 . 2011-10-27 21:47 -------- d-----w- c:\program files (x86)\Panda Security
                                    2011-10-27 21:41 . 2011-10-27 21:41 -------- d-----w- c:\users\Vincent\AppData\Roaming\vlc
                                    2011-10-27 21:41 . 2011-10-27 21:41 -------- d-----w- c:\users\Vincent\AppData\Local\Ilivid Player
                                    2011-10-27 20:55 . 2011-10-27 20:55 -------- d-----w- c:\users\Vincent\AppData\Local\PackageAware
                                    2011-10-27 19:35 . 2011-08-31 15:00 25416 ----a-w- c:\windows\system32\drivers\mbam.sys
                                    2011-10-26 20:52 . 2011-10-26 20:52 -------- d-----w- c:\users\Vincent\AppData\Roaming\Malwarebytes
                                    2011-10-26 20:52 . 2011-10-26 20:52 -------- d-----w- c:\programdata\Malwarebytes
                                    2011-10-26 20:52 . 2011-10-27 19:35 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
                                    2011-10-25 18:47 . 2011-08-15 05:08 6144 ----a-w- c:\program files\Internet Explorer\iecompat.dll
                                    2011-10-25 18:47 . 2011-08-15 04:25 6144 ----a-w- c:\program files (x86)\Internet Explorer\iecompat.dll
                                    .
                                    .
                                    .
                                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    2011-09-06 20:45 . 2011-03-25 06:03 41184 ----a-w- c:\windows\avastSS.scr
                                    2011-09-06 20:45 . 2010-01-03 15:23 199304 ----a-w- c:\windows\SysWow64\aswBoot.exe
                                    .
                                    .
                                    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
                                    .
                                    .
                                    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
                                    REGEDIT4
                                    .
                                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-08-12 6203296]
                                    "tcactive"="c:\program files (x86)\The Cleaner\tcap.exe" [2011-09-13 4768848]
                                    .
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
                                    "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2009-08-17 1294136]
                                    "TRCMan"="c:\program files (x86)\TOSHIBA\TRCMan\TRCMan.exe" [2009-07-21 701752]
                                    "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
                                    "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-21 932288]
                                    "TkBellExe"="c:\program files (x86)\Common Files\Real\Update_OB\realsched.exe" [2010-05-11 202256]
                                    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]
                                    "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2011-02-23 3451496]
                                    "iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2011-04-14 421160]
                                    "TrojanScanner"="c:\program files (x86)\Trojan Remover\Trjscan.exe" [2011-05-18 1233856]
                                    .
                                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                    "TOSHIBA Online Product Information"="c:\program files (x86)\TOSHIBA\Toshiba Online Product Information\topi.exe" [2009-08-12 6203296]
                                    .
                                    c:\users\Vincent\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                                    TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
                                    .
                                    c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
                                    TRDCReminder.lnk - c:\program files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe [2009-9-1 481184]
                                    .
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                    "ConsentPromptBehaviorAdmin"= 0 (0x0)
                                    "ConsentPromptBehaviorUser"= 3 (0x3)
                                    "EnableLUA"= 0 (0x0)
                                    "EnableUIADesktopToggle"= 0 (0x0)
                                    "PromptOnSecureDesktop"= 0 (0x0)
                                    .
                                    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
                                    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
                                    R2 gupdate;Service Google Update (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-17 135664]
                                    R3 esgiguard;esgiguard;c:\program files\Enigma Software Group\SpyHunter\esgiguard.sys [x]
                                    R3 gupdatem;Service Google Update (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-17 135664]
                                    R3 nmwcdx64;Nokia USB Phone Parent;c:\windows\system32\drivers\ccdcmbx64.sys [x]
                                    R3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [2009-08-17 51512]
                                    R3 WatAdminSvc;Service Windows Activation Technologies;c:\windows\system32\Wat\WatAdminSvc.exe [x]
                                    S0 pavboot;pavboot;c:\windows\system32\drivers\pavboot64.sys [x]
                                    S0 Thpdrv;TOSHIBA HDD Protection Driver;c:\windows\system32\DRIVERS\thpdrv.sys [x]
                                    S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x]
                                    S0 tos_sps64;TOSHIBA tos_sps64 Service;c:\windows\system32\DRIVERS\tos_sps64.sys [x]
                                    S1 aswSnx;aswSnx; [x]
                                    S1 aswSP;aswSP; [x]
                                    S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
                                    S2 aswFsBlk;aswFsBlk; [x]
                                    S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [x]
                                    S2 cfWiMAXService;ConfigFree WiMAX Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe [2009-08-10 248688]
                                    S2 ConfigFree Gadget Service;ConfigFree Gadget Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFProcSRVC.exe [2009-07-14 42368]
                                    S2 ConfigFree Service;ConfigFree Service;c:\program files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe [2009-03-10 46448]
                                    S2 TemproMonitoringService;Notebook Performance Tuning Service (TEMPRO);c:\program files (x86)\Toshiba TEMPRO\TemproSvc.exe [2009-08-25 116104]
                                    S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe [2009-08-27 251760]
                                    S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys [x]
                                    S3 hidshim;Service for HID-KMDF Shim layer;c:\windows\system32\DRIVERS\hidshim.sys [x]
                                    S3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys [x]
                                    S3 nuvotoncir;Nuvoton IR Transceiver;c:\windows\system32\DRIVERS\nuvotoncir.sys [x]
                                    S3 nuvotonhidcir;Nuvoton HID CIR Receiver;c:\windows\system32\DRIVERS\nuvotonhidcir.sys [x]
                                    S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [x]
                                    S3 O2MDGRDR;O2MDGRDR;c:\windows\system32\DRIVERS\o2mdgx64.sys [x]
                                    S3 O2SDGRDR;O2SDGRDR;c:\windows\system32\DRIVERS\o2sdgx64.sys [x]
                                    S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys [x]
                                    S3 QIOMem;Generic IO & Memory Access;c:\windows\system32\DRIVERS\QIOMem.sys [x]
                                    S3 rtl8192se;Realtek Wireless LAN 802.11n PCI-E NIC NT Driver;c:\windows\system32\DRIVERS\rtl8192se.sys [x]
                                    S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [2009-08-03 137560]
                                    S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [2009-08-04 826224]
                                    .
                                    .
                                    Contenu du dossier 'Tâches planifiées'
                                    .
                                    2011-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
                                    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-17 02:22]
                                    .
                                    2011-10-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
                                    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-01-17 02:22]
                                    .
                                    .
                                    --------- x86-64 -----------
                                    .
                                    .
                                    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
                                    @="{472083B0-C522-11CF-8763-00608CC02F24}"
                                    [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
                                    2011-02-23 15:04 134384 ------w- c:\program files\AVAST Software\Avast\ashShA64.dll
                                    .
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                    "ThpSrv"="c:\windows\system32\thpsrv" [X]
                                    "Toshiba TEMPRO"="c:\program files (x86)\Toshiba TEMPRO\TemproTray.exe" [2009-08-25 1050000]
                                    "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-23 16334368]
                                    "cAudioFilterAgent"="c:\program files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe" [2009-07-20 503864]
                                    "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2009-08-03 709976]
                                    "Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaReminder.exe" [2009-09-10 134032]
                                    .
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                    "LoadAppInit_DLLs"=0x1
                                    .
                                    ------- Examen supplémentaire -------
                                    .
                                    uLocal Page = c:\windows\SysWOW64\blank.htm
                                    uStart Page = hxxp://www.google.com/
                                    mLocal Page = c:\windows\SysWOW64\blank.htm
                                    uInternet Settings,ProxyOverride = *.local
                                    IE: E&xporter vers Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
                                    IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_950DF09FAB501E03.dll/cmsidewiki.html
                                    TCP: DhcpNameServer = 212.27.40.240 212.27.40.241
                                    DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/2.9.2.0/GarminAxControl.CAB
                                    DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://109.2.227.210:4000/activex/AMC.cab
                                    .
                                    - - - - ORPHELINS SUPPRIMES - - - -
                                    .
                                    Toolbar-10 - (no file)
                                    Wow6432Node-HKLM-Run-TUSBSleepChargeSrv - %ProgramFiles(x86)%\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
                                    SafeBoot-mcmscsvc
                                    SafeBoot-MCODS
                                    Toolbar-10 - (no file)
                                    HKLM-Run-SmoothView - c:\program files (x86)\Toshiba\SmoothView\SmoothView.exe
                                    HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
                                    HKLM-Run-HSON - c:\program files (x86)\TOSHIBA\TBS\HSON.exe
                                    HKLM-Run-00TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
                                    HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
                                    HKLM-Run-SmartFaceVWatcher - c:\program files (x86)\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
                                    HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
                                    HKLM-Run-HDMICtrlMan - c:\program files (x86)\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe
                                    HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
                                    HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
                                    HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
                                    AddRemove-Ad-Remover - c:\program files (x86)\Ad-Remover\Uninstal.exe
                                    .
                                    .
                                    .
                                    --------------------- CLES DE REGISTRE BLOQUEES ---------------------
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
                                    @Denied: (A 2) (Everyone)
                                    @="FlashBroker"
                                    "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe,-101"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
                                    "Enabled"=dword:00000001
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
                                    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10n_ActiveX.exe"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
                                    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
                                    @Denied: (A 2) (Everyone)
                                    @="Shockwave Flash Object"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
                                    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
                                    "ThreadingModel"="Apartment"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
                                    @="0"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
                                    @="ShockwaveFlash.ShockwaveFlash.10"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                                    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
                                    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
                                    @="1.0"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                                    @="ShockwaveFlash.ShockwaveFlash"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
                                    @Denied: (A 2) (Everyone)
                                    @="Macromedia Flash Factory Object"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
                                    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx"
                                    "ThreadingModel"="Apartment"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
                                    @="FlashFactory.FlashFactory.1"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
                                    @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10n.ocx, 1"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
                                    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
                                    @="1.0"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
                                    @="FlashFactory.FlashFactory"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
                                    @Denied: (A 2) (Everyone)
                                    @="IFlashBroker4"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
                                    @="{00020424-0000-0000-C000-000000000046}"
                                    .
                                    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
                                    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
                                    "Version"="1.0"
                                    .
                                    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
                                    @Denied: (Full) (Everyone)
                                    .
                                    ------------------------ Autres processus actifs ------------------------
                                    .
                                    c:\program files\AVAST Software\Avast\AvastSvc.exe
                                    c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
                                    c:\program files (x86)\Bonjour\mDNSResponder.exe
                                    c:\windows\system32\DRIVERS\o2flash.exe
                                    c:\program files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
                                    c:\program files (x86)\TOSHIBA\TOSHIBA USB Sleep and Charge Utility\TUSBSleepChargeSrv.exe
                                    c:\program files\TOSHIBA\HDMICtrlMan\HCMSoundChanger.exe
                                    .
                                    **************************************************************************
                                    .
                                    Heure de fin: 2011-10-31 16:58:37 - La machine a redémarré
                                    ComboFix-quarantined-files.txt 2011-10-31 15:58
                                    .
                                    Avant-CF: 185 958 817 792 octets libres
                                    Après-CF: 185 832 067 072 octets libres
                                    .
                                    - - End Of File - - 3027F51DF8F72F0C598F9EF0F33408C6
                                    0
                                    1. j'ai eu exactement le même souci avec les mêmes symtomes: à partir de l'accès à velovert, virus très méchant qui m'a tué le MBR et le registre sur 2 ordis différents, l'un est reparti comme en 14 grace à la restauration Vista, mais l'autre sous Xp a nécessité 2 jours de boulot et n'est toujours pas sécurisé à 100% , je sais pas ce que c'est que cette merde, mais elle est bien méchante
                                      0
                                      1. Je ne te le fait pas dire!!

                                        Ca fait presque une semaine que je galère... J'ai commencé par suivre les instructions d'un post de ce forum... sans le suivre jusqu'au bout parce que tout semblait être revenu comme avant.Mais il a suffit que j'essaye d'accéder à nouveau à vélovert et là..... tout c'est emballé, avast m'a bien signalé qu'il y avait un problème mais n'a pas pu le contenir!

                                        Heureusement qu'il y a des forums comme celui-ci (que je découvre d'ailleurs), car pour un novice comme moi, se dépatouiller d'un pb comme celui là c'est mission impossible!
                                        0
                                    2. Contributeur sécurité
                                      il faudrait le rapport entier de combofix

                                      puis

                                      colle un rapport avec rogue killer option 2

                                      puis

                                      télécharge OTM
                                      http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/
                                      http://oldtimer.geekstogo.com/OTMoveIt3.exe (de Old_Timer) sur ton Bureau.

                                      double-clique sur OTM.exe pour le lancer.
                                      copie la liste qui se trouve en citation ci-dessous,
                                      et colle-la dans le cadre de gauche de OTM :Paste instruction for items to be moved.

                                      :processes
                                      explorer.exe
                                      :files
                                      C:\Users\Vincent\AppData\Roaming\microsoft\internet explorer\quick launch\system restore.lnk :commands
                                      [purity]
                                      [emptytemp]
                                      [start explorer]

                                      clique sur MoveIt! pour lancer la suppression.
                                      le résultat apparaitra dans le cadre "Results".
                                      clique sur Exit pour fermer.
                                      poste le rapport situé dans C:\_OTM\MovedFiles.

                                      il te sera peut-être demander de redémarrer le pc pour achever la suppression.si c'est le cas accepte par Yes.

                                      ____________________

                                      A Plus
                                      0
                                      • 1
                                      • 2