Trojan win32.small-lx

Résolu
Bonjour à vous,
voila en defragmentant mon disque, je lis le rapport qui me signale que certains fichiers ne peuvent etre defragmentés.
parmi eux je remarque (par sa taille : 1,4 Go) un fichier 493.tmp sous c:\
je fais une analyse avast qui m'informe qu'il est infecté par le virus Win32:Small-LX [Trj]
Impossible de le supprimer ou mettre en quarantaine.
J'ai forcé le déplacement et le fichier est actuellement sous C:\Program Files\Alwil Software\Avast4\DATA\moved.

voila mon log hijack.
Merci de votre aide.

Logfile of HijackThis v1.99.1
Scan saved at 15:15:12, on 24/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\acer\epm\epm-dm.exe
C:\Program Files\Launch Manager\QtZgAcer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Winamp\winampa.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Fichiers communs\Logitech\KHAL\KHALMNPR.EXE
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Acer\eManager\anbmServ.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\acer\eRecovery\Monitor.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\LOUBEAU\Bureau\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [LaunchApp] Alaunch
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Raccourci vers la page des propriétés de High Definition Audio] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [EPM-DM] c:\acer\epm\epm-dm.exe
O4 - HKLM\..\Run: [ePowerManagement] C:\Acer\ePM\ePM.exe boot
O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE
O4 - HKLM\..\Run: [eRecoveryService] C:\Windows\System32\Check.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [RegSvr32] C:\WINDOWS\system32\msmsgs.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Notebook Manager Service (anbmService) - OSA Technologies Inc. - C:\Acer\eManager\anbmServ.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Configuration: Avast
A2 free
Spybot
Ccleaner
Fixwareout
Windows XP
Internet Explorer 7.0

26 réponses

Résumé de la discussion

Le fil aborde un problème de défragmentation révélant un fichier 493.tmp sur C:\ qui, après analyse Avast, est identifié comme Win32:Small-LX [Trj] et déplacé dans le répertoire moved. Le message comprend un log HijackThis détaillé et montre de nombreuses entrées de démarrage, des barres d'outils et des composants susceptibles d'être associés à des logiciels malveillants. Parmi les solutions proposées, l'outil SDFix est préconisé pour supprimer les trojans et nettoyer le registre, avec redémarrage en mode sans échec et rapport à coller dans la discussion. En cas de perceptions contradictoires, certains échanges mentionnent des scans antivirus négatifs et des vérifications complémentaires, avant qu'une étape finale de nettoyage ne confirme potentiellement la levée de l'infection.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut

    Cool :)
    Non lol , juste par rapport aux rapports que tu m as donné :)

    Bonne continuation
    0
    1. ecoute je pense que c bon.
      je n'ai plus rien ds moved.
      tout parait ok.
      c cool
      merci bcp.
      comment tu savais que c'etait ces fichiers ?
      tu peux acceder a mon pc ?
      merci encore !
      a + (j'espere pas ! mdr)
      0
      1. Contributeur sécurité
        Salut

        Moved correspond a la quarantaine de Avast :)

        Dis moi ce que je peux pour toi ?!

        A+
        0
        1. salut,
          en fait je peux pas dire que j'ai de gros soucis.
          parfois, lorsque je n'ai plus accès à internet sans fil, ça me marque "aucun dispositif" qd j'appuie sur le bouton (au lieu de wireless lan activé ou désactivé).
          Hier, ça me l'a fait après avoir lancé fixwareout.
          Alors, j'éteins mon pc, si je redémarre tout de suite, en général, je ne peux tjs pas me connecter. mais qq heures apres, c bon.
          Alors, j'ai tjs ce fichier infecté par trojan win32 small lx dans le repertoire moved d'avast...
          C space, je viens de m'apercevoir qu'il n'y ait plus alors qu'hier il y était encore (c pê fixwareout).
          Il faut que je défragmente mon pc.
          0
          1. Contributeur sécurité
            Salut

            redemarre et dis moi ou en sont tes soucis?

            A+
            0
            1. re,
              c fait
              et maintenant ?
              que faut il faire ?
              mon pc est clean ?
              a+
              0
              1. Contributeur sécurité
                Ok pas grave.

                Supprime:
                C:\WINDOWS\x74ca5e40.tmp

                A+
                0
                1. ça me marque à chq fois ça sur le 1er lien :
                  Cette erreur (HTTP 500 Erreur interne au serveur) signifie que le site Web que vous visitez a rencontré un problème de serveur qui a empêché l’affichage de la page Web.
                  0
                  1. Contributeur sécurité
                    Salut

                    prkoi le 1er n'a pas marché?

                    Il pese combien?

                    A+
                    0
                    1. sans oublier le fichier de 1,4 Go que j'ai déplacé dans le répertoire moved d'avast (cf mon premier message)
                      0
                      1. salut
                        ça n'a pas marché le premier lien..
                        0
                        1. Contributeur sécurité
                          Salut

                          Tu as une nouvelle infection intéressante sur ton ordinateur.

                          Contrôle des données :

                          Peux-tu afficher tous les fichiers sur ton ordinateur ? Vérifie ton paramétrage :

                          dans Windows Explorer :
                          >Outils > Options des dossiers > onglet "Affichage" > Fichiers et dossiers cachés > activer "Afficher les fichiers et dossiers cachés" > décocher Masquer les extensions des fichiers dont le type est connu > décocher "Masquer les fichiers du système d'exploitation (recommandé) > Appliquer > Appliquer à tous les dossiers et confirmer par OK > OK pour quitter

                          S'il te plaît, télécharge ces fichiers

                          C:\WINDOWS\x74ca5e40.tmp

                          1. -> S!Ri -remontée des fichiers (*). http://siri.urz.free.fr/upload/

                          et ensuite:

                          Sur cette page:
                          http://secubox.gateweb.org/mad.php

                          Merci, et confirme moi que les 2 upload ont fonctionné.

                          A+
                          0
                          1. je mets le rapport du dernier scan spybot que je viens de faire.
                            J'ai réglé en priorité du scan absolue. Il me met "aucun mouchard détecte". mais il met ensuite pas mal de truc en vert mais je sais pas si je dois les cocher et les supprimer...

                            --- Search result list ---
                            Common Dialogs: History (12 files) (Clé du registre, nothing done)
                            HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSaveMRU

                            MS Office 9.0: Recently used files (116 files) (Répertoire, nothing done)
                            C:\Documents and Settings\LOUBEAU\Application Data\Microsoft\Office\Récents\

                            Log: Activity: SchedLgU.Txt (Sauver le fichier, nothing done)
                            C:\WINDOWS\SchedLgU.Txt

                            Log: Shutdown: System32\wbem\logs\wbemess.log (Sauver le fichier, nothing done)
                            C:\WINDOWS\System32\wbem\logs\wbemess.log

                            Log: Shutdown: System32\wbem\logs\wmiprov.log (Sauver le fichier, nothing done)
                            C:\WINDOWS\System32\wbem\logs\wmiprov.log

                            Adobe Acrobat Reader 6: Recent file #1 (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Adobe\Acrobat Reader\6.0\AVGeneral\cRecentFiles\c1

                            Alcohol 120%: Last search path (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Alcohol Soft\Alcohol 120%\Basic\Image Finder\Current Dir!=

                            Alcohol 120%: Images history (8 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Alcohol Soft\Alcohol 120%\Images

                            Alcohol 120%: Image location history (7 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Alcohol Soft\Alcohol 120%\Images\Location

                            Ahead Nero Burning Rom: Last encoding directory (Modification du registre, nothing done)
                            HKEY_LOCAL_MACHINE\Software\Ahead\Nero - Burning Rom\Settings\EncodingLastDir!=

                            Ahead Nero Burning Rom: Compilation directory (Modification du registre, nothing done)
                            HKEY_LOCAL_MACHINE\Software\Ahead\Nero - Burning Rom\Settings\NeroCompilation!=

                            Ahead Nero Burning Rom: Save tracks directory (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Ahead\Nero - Burning Rom\SaveTrackOptions\Stdflist!=B=

                            Ahead Nero Burning Rom: Last encoding directory (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Ahead\Nero - Burning Rom\Settings\EncodingLastDir!=

                            Ahead Nero Burning Rom: Compilation directory (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Ahead\Nero - Burning Rom\Settings\NeroCompilation!=

                            Ahead Nero Wave Editor: Last open file type (Valeur du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Ahead\Nero Wave Editor\General\LastOpenFilter

                            Internet Explorer: Typed URL list (1 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Internet Explorer\TypedURLs

                            Internet Explorer: User agent (Modification du registre, nothing done)
                            HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)

                            Internet Explorer: User agent (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)

                            Internet Explorer: User agent (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)

                            Internet Explorer: User agent (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)

                            Internet Explorer: User agent (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)

                            MS Media Player: Search terms history (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\MediaPlayer\AutoComplete\MediaSearch

                            MS Media Player: Last selected node (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\MediaPlayer\MediaLibraryUI\MLLastSelectedNode!=

                            MS Media Player: Client ID (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=

                            MS Media Player: Anonymous ID (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\MediaPlayer\Preferences\SendUserGUID!=B=0

                            MS Direct3D: Most recent application (Modification du registre, nothing done)
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name!=

                            MS DirectDraw: Most recent application (Modification du registre, nothing done)
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name!=

                            MS DirectInput: Most recent application (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\DirectInput\MostRecentApplication\Name!=

                            MS DirectInput: Most recent application ID (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\DirectInput\MostRecentApplication\Id!=

                            MS Office 9.0: Internet history (Valeur du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\Common\Internet\LocationOfComponents

                            MS Office 9.0: Internet history (Valeur du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\Common\Internet\UseRWHlinkNavigation

                            MS Office 9.0: Access recent file (5 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\Access\Settings

                            MS Office 9.0 (Word): Recently used file list (Valeur du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\Word\Data\Settings

                            MS Office 9.0 (Excel): Recent files (4 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\Excel\Recent Files

                            MS Office 9.0 (PowerPoint): Recent file list (9 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Office\9.0\PowerPoint\Recent File List

                            MS Search Assistant: Typed search terms history (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Search Assistant\ACMru

                            Windows: Drivers installation paths (Modification du registre, nothing done)
                            HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Installation Sources!=

                            Windows.OpenWith: Open with list - .ACE extension (2 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ACE\OpenWithList

                            Windows.OpenWith: Open with list - .ASF extension (3 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ASF\OpenWithList

                            Windows.OpenWith: Open with list - .ASX extension (3 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ASX\OpenWithList

                            Windows.OpenWith: Open with list - .AVI extension (6 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.AVI\OpenWithList

                            Windows.OpenWith: Open with list - .BAK extension (2 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BAK\OpenWithList

                            Windows.OpenWith: Open with list - .BIN extension (2 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BIN\OpenWithList

                            Windows.OpenWith: Open with list - .BMP extension (2 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\OpenWithList

                            Windows.OpenWith: Open with list - .CAB extension (2 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CAB\OpenWithList

                            Windows.OpenWith: Open with list - .CDA extension (4 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDA\OpenWithList

                            Windows.OpenWith: Open with list - .CDM extension (2 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CDM\OpenWithList

                            Windows.OpenWith: Open with list - .CHM extension (2 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CHM\OpenWithList

                            Windows.OpenWith: Open with list - .CUE extension (2 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.CUE\OpenWithList

                            Windows Explorer: Recent wallpaper list (501 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU

                            Windows Explorer: Stream history (151 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU

                            Windows Explorer: User Assistant history IE (142 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count

                            Windows Explorer: User Assistant history files (282 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count

                            Windows Explorer: Last visited history (2 fichiers) (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\LastVisitedMRU

                            Windows Explorer: Recent file global history (Clé du registre, nothing done)
                            HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

                            Windows Explorer: Recent file global history (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

                            Windows Explorer: Recent file global history (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

                            Windows Explorer: Recent file global history (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

                            Windows Explorer: Recent file global history (Clé du registre, nothing done)
                            HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Explorer\RecentDocs

                            Windows Explorer: Last Copy/MoveTo folder (Valeur du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CopyMoveTo\LastFolder

                            Windows Media SDK: Computer name (Modification du registre, nothing done)
                            HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName

                            Windows Media SDK: Computer name (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName

                            Windows Media SDK: Computer name (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName

                            Windows Media SDK: Unique ID (Modification du registre, nothing done)
                            HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}

                            Windows Media SDK: Unique ID (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}

                            Windows Media SDK: Unique ID (Modification du registre, nothing done)
                            HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!={00000000-0000-0000-0000-000000000000}

                            Windows Media SDK: Volume serial number (Valeur du registre, nothing done)
                            HKEY_USERS\.DEFAULT\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

                            Windows Media SDK: Volume serial number (Valeur du registre, nothing done)
                            HKEY_USERS\S-1-5-21-18371474-2989181903-1813247639-1004\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

                            Windows Media SDK: Volume serial number (Valeur du registre, nothing done)
                            HKEY_USERS\S-1-5-18\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

                            Cookie: Cookie (29) (Cookie, nothing done)

                            Cache: Cache (538) (Cache, nothing done)

                            Félicitations!: Aucun mouchard n'a été trouvé. ()
                            0
                            1. donc :
                              C:\WINDOWS\x74ca5e40.tmp
                              est infecté :
                              BitDefender Found Adware.Psguard.A, Adware.Winhound.B
                              NOD32 Found Win32/Adware.PSGuard application
                              0
                              1. Contributeur sécurité
                                S'il trouve nothing a tous, pas la peine de me montrer mais fais bien un scan des 3 autres aussi:

                                C:\WINDOWS\MOTA113.exe
                                C:\WINDOWS\system32\x.264.exe
                                C:\WINDOWS\x74ca5e40.tmp
                                0
                                1. je ne te mets pas ce qu'il y a ds le tableau statistics ?
                                  sinon, l'analyse a foundé nothing pour meta4.exe (dans scanner results)
                                  merci encore regis59 !
                                  0
                                  1. Contributeur sécurité
                                    Il est ok, tu peux faire les autres?

                                    A+
                                    0
                                    1. hello
                                      je te colle ceci (fait pour x2.64.exe) ?

                                      Scanner results
                                      Scan taken on 26 Mar 2007 17:38:11 (GMT)
                                      AntiVir Found nothing
                                      ArcaVir Found nothing
                                      Avast Found nothing
                                      AVG Antivirus Found nothing
                                      BitDefender Found nothing
                                      ClamAV Found nothing
                                      Dr.Web Found nothing
                                      F-Prot Antivirus Found nothing
                                      F-Secure Anti-Virus Found nothing
                                      Fortinet Found nothing
                                      Kaspersky Anti-Virus Found nothing
                                      NOD32 Found nothing
                                      Norman Virus Control Found nothing
                                      Panda Antivirus Found nothing
                                      VirusBuster Found nothing
                                      VBA32 Found nothing
                                      0
                                      1. Contributeur sécurité
                                        Salut,

                                        Voici la liste:

                                        C:\WINDOWS\x2.64.exe
                                        C:\WINDOWS\meta4.exe
                                        C:\WINDOWS\MOTA113.exe
                                        C:\WINDOWS\system32\x.264.exe
                                        C:\WINDOWS\x74ca5e40.tmp

                                        Vas sur le site https://virusscan.jotti.org/
                                        - Clic en haut à droite sur "Parcourir", navigue dans les dossiers et sélectionne un fichier de la liste.
                                        - Clic sur submit toujours en haut à droite
                                        - Le scan va se lancer, ça va prendre un petit instant
                                        - En bas, tu as le résultat du scan, copie/colle le résultat complet du scan ici.
                                        Aide : https://www.malekal.com/scan-antivirus-ligne-nod32/#mozTocId662799

                                        Puis fais l'analyse pour chaque fichier.
                                        0
                                        • 1
                                        • 2