Problèmes de ralentissements + pubs

Résolu
Bonjour tout le monde,
j'ai depuis quelques mois quelques gros ralentissements sur mon PC, tant au niveau internet qu'au niveau jeux...
Je reçois également énormément de pub en navigant sur internet (une page de pub pour 2 pages ouvertes...).

Si quelqu'un aurait la gentillesse de donner un peu de temps à un autre quelqu'un un peu découragé... Ca serait très sympa.

Merci d'avance.
Configuration: Windows XP
Firefox 2.0.0.11

52 réponses

Résumé de la discussion

Ralentissements importants sur le PC et affichage excessif de publicités lors de la navigation, sur une configuration Windows XP et Firefox 2.0.0.11, sont les symptômes décrits. Des éléments de réponse proposent des scans en mode sans échec et l’utilisation d’outils dédiés comme VundoFix, VirtumundoBeGone, ComboFix, HijackThis et ADS Spy pour détecter et supprimer les malwares. Les procédures incluent ensuite le redémarrage, l’obtention de rapports de scan (vundofix.txt, Combofix.txt ou logs HijackThis) et la publication des résultats pour identifier les éléments à retirer. En parallèle, certains messages suggèrent des étapes complémentaires et des vérifications liées aux extensions et BHO susceptibles d’aggraver les pubs, sans conclure sur une solution unique.

Bobot (l’IA à votre service)
  1. Eh ben merci beaucoup! Et à bientôt ;-)
    0
    1. Modérateur
      Salut

      c'est tout bon ;-)

      ++
      0
      1. Voila...
        http://krambeul.free.fr/hijackthis%203.log
        0
        1. Modérateur
          Salut

          poste un nouveau rapport hijackthis stp

          ++
          0
          1. Me revoila... Je ne sais pas trop s'il reste des choses à faire (l'état de mon ordinateur s'est déjà bien amélioré), mais si oui, je suis prêt!
            0
            1. Modérateur
              bon voyage ! :)

              ++
              0
              1. Désolé de ne pas avoir répondu plus tôt, je n'étais pas chez moi...
                Donc une fois qu'on a tout supprimer, on ne peux pas enregistrer de rapport (mais il n'y a plus rien)

                Je repart en Australie demain, jusqu'à mercredi dans 10 jours... Je ne pourrais donc pas trop effectuer tout ce qu'il y a à effectuer ! ;-)

                Bonne semaine (et encore merci)
                0
                1. Modérateur
                  comme tu veux, as toi de voir !

                  ++
                  0
                  1. Faut-il décocher la case quick scan?
                    0
                    1. Modérateur
                      ok,

                      HijackThis, clique sur "Open the misc tools section" -> "Open ADS Spy..." -> "Scan" -> Coche tout -> Clique sur "Remove selected".

                      ensuite, refais ceci :

                      Exécute hijackthis et clique sur "Open the misc tools section" -> "Open ADS Spy..." -> "Scan" -> "Save log..." -> Copie/colle ici le texte ouvert avec le bloc note.

                      ++
                      0
                      1. Voila pour le rapport HJT:http://krambeul.free.fr/hijackthis%202.log
                        0
                        1. Donc, j'ai renommé l'éxécutable, décoché la case quick scan, et obtenu plein de fichiers (des favoris internets, principalement...)
                          Log : http://krambeul.free.fr/adsspy.txt
                          0
                          1. J'ai fait le scan en laissant hijackthis nommé en scanner, il n'a rien trouvé... Je le renomme en HijackThis.exe? Et je trouve pas le log une fois sauvegardé... C'est la suite de Hijackthis.log?
                            0
                            1. Modérateur
                              oups ! pas tout à fait, je parlais de hijackthis ! :)

                              ++
                              0
                              1. ComboFix 08-01-16.4 - xxx 2008-01-17 17:07:29.2 - NTFSx86
                                Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.446 [GMT 1:00]
                                Running from: C:\Documents and Settings\xxx\Bureau\ComboFix.exe
                                Command switches used :: C:\Documents and Settings\xxx\Bureau\CFScript.txt
                                * Created a new restore point

                                [color=red][b]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/b][/color]
                                .

                                ((((((((((((((((((((((((((((( Fichiers créés 2007-12-17 to 2008-01-17 ))))))))))))))))))))))))))))))))))))
                                .

                                2008-01-17 18:17 . 2008-01-17 18:19 1,374 --a------ C:\WINDOWS\imsins.BAK
                                2008-01-17 17:38 . 2008-01-17 17:38 1,291,102 --a------ C:\upload_moi_DARLING.tar.gz
                                2008-01-17 14:22 . 2008-01-16 22:23 2,115,616 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
                                2008-01-17 14:22 . 2008-01-16 19:02 17,636 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
                                2008-01-17 14:05 . 2008-01-17 14:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\MailFrontier
                                2008-01-17 14:05 . 2007-12-13 19:27 42,384 --a------ C:\WINDOWS\zllsputility_loc040c.dll
                                2008-01-17 14:05 . 2007-12-13 19:27 21,904 --a------ C:\WINDOWS\system32\imsinstall_loc040c.dll
                                2008-01-17 14:05 . 2007-12-13 19:27 17,808 --a------ C:\WINDOWS\system32\imslsp_install_loc040c.dll
                                2008-01-17 14:04 . 2007-12-13 19:27 75,248 --a------ C:\WINDOWS\zllsputility.exe
                                2008-01-17 14:04 . 2004-04-27 04:40 11,264 --a------ C:\WINDOWS\system32\SpOrder.dll
                                2008-01-17 14:03 . 2007-12-13 19:27 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
                                2008-01-17 13:15 . 2008-01-17 17:10 54,156 --ah----- C:\WINDOWS\QTFont.qfn
                                2008-01-17 13:15 . 2008-01-17 13:15 1,409 --a------ C:\WINDOWS\QTFont.for
                                2008-01-16 20:51 . 2008-01-16 20:53 <REP> d-------- C:\Program Files\Dofus
                                2008-01-16 19:04 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe
                                2008-01-16 18:15 . 2008-01-16 18:15 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
                                2008-01-16 17:22 . 2008-01-16 18:14 <REP> d-------- C:\VundoFix Backups
                                2008-01-15 18:47 . 2008-01-16 07:09 <REP> d-------- C:\WINDOWS\BDOSCAN8
                                2008-01-15 18:25 . 2008-01-15 18:25 <REP> d-------- C:\Program Files\Trend Micro
                                2008-01-14 18:36 . 2008-01-14 18:36 <REP> d-------- C:\Documents and Settings\xxx\Application Data\ubi.com
                                2008-01-13 16:21 . 2008-01-16 21:46 <REP> d-------- C:\Documents and Settings\xxxx\Application Data\BitTorrent
                                2008-01-09 13:00 . 2008-01-09 13:00 <REP> d-------- C:\Program Files\NAMCO BANDAI Games
                                2008-01-09 12:18 . 2008-01-09 12:18 20,480 --a------ C:\WINDOWS\system32\H@tKeysH@@k.DLL
                                2008-01-09 12:06 . 2008-01-09 12:06 <REP> d-------- C:\Program Files\DNA
                                2008-01-09 12:06 . 2008-01-09 12:06 <REP> d-------- C:\Program Files\BitTorrent
                                2008-01-09 12:06 . 2008-01-17 17:19 <REP> d-------- C:\Documents and Settings\xxx\Application Data\DNA
                                2008-01-09 12:06 . 2008-01-17 17:16 <REP> d-------- C:\Documents and Settings\xxx\Application Data\BitTorrent
                                2008-01-02 11:24 . 2008-01-02 11:24 <REP> d-------- C:\Documents and Settings\xxxx\Application Data\Apple Computer
                                2008-01-02 11:23 . 2008-01-02 11:23 <REP> d-------- C:\Program Files\iTunes
                                2008-01-02 11:23 . 2008-01-02 11:23 <REP> d-------- C:\Program Files\iPod
                                2008-01-02 11:20 . 2008-01-02 11:20 <REP> d-------- C:\Program Files\Fichiers communs\Apple
                                2008-01-02 11:20 . 2008-01-02 11:20 <REP> d-------- C:\Program Files\Apple Software Update
                                2008-01-02 11:20 . 2008-01-02 11:20 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Apple
                                2008-01-02 11:20 . 2007-10-31 14:09 30,464 --a------ C:\WINDOWS\system32\drivers\usbaapl.sys
                                2007-12-24 23:44 . 2008-01-16 15:47 65 --a------ C:\WINDOWS\FISHUI.INI
                                2007-12-24 21:37 . 2007-12-24 21:37 <REP> d-------- C:\Documents and Settings\xxx\Application Data\DataCast
                                2007-12-24 21:36 . 2007-08-23 21:06 110,592 --a------ C:\WINDOWS\system32\TG_DUMP0708.DLL
                                2007-12-24 21:34 . 2007-12-24 21:34 <REP> d-------- C:\Program Files\Lame MP3 Codec
                                2007-12-24 21:34 . 2002-12-03 22:13 1,048,576 --a------ C:\WINDOWS\system32\lameACM.acm
                                2007-12-24 21:34 . 2005-05-03 09:33 299,008 --a------ C:\WINDOWS\system32\LAME_MP3.dll
                                2007-12-24 21:34 . 2004-12-10 21:29 401 --a------ C:\WINDOWS\system32\lame_acm.xml
                                2007-12-24 21:33 . 2007-12-24 21:33 <REP> d-------- C:\Program Files\XviD
                                2007-12-24 21:33 . 2007-12-24 21:33 65,024 --a------ C:\WINDOWS\IFinst26.exe
                                2007-12-24 21:32 . 2007-12-24 21:32 <REP> d-------- C:\Program Files\Samsung
                                2007-12-24 21:32 . 2007-12-24 21:32 <REP> d-------- C:\Program Files\MarkAny
                                2007-12-24 21:31 . 2007-12-24 21:31 <REP> d-------- C:\Documents and Settings\xxx\Application Data\InstallShield
                                2007-12-24 15:52 . 2007-12-24 15:52 1,409 --a------ C:\WINDOWS\system32\tmpC444F.FOT
                                2007-12-24 15:52 . 2007-12-24 15:52 1,409 --a------ C:\WINDOWS\system32\tmp9774F.FOT
                                2007-12-24 15:52 . 2007-12-24 15:52 1,409 --a------ C:\WINDOWS\system32\tmp5084F.FOT
                                2007-12-24 15:51 . 2007-12-24 15:51 96,864 --a------ C:\WINDOWS\~GLC0000.TMP
                                2007-12-19 18:01 . 2007-12-19 18:01 <REP> d-------- C:\Documents and Settings\xxxx\Application Data\Sites
                                2007-12-19 18:01 . 2007-12-19 18:01 <REP> d-------- C:\Documents and Settings\xxxx\Application Data\Dynamique
                                2007-12-19 18:01 . 2007-12-19 18:02 <REP> d-------- C:\Documents and Settings\xxxx\Application Data\Classes de site

                                .
                                (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                2008-01-17 17:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
                                2008-01-17 16:15 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
                                2008-01-17 15:58 --------- d-----w C:\Program Files\Intel
                                2008-01-17 13:41 --------- d-----w C:\Program Files\Microsoft Games
                                2008-01-15 18:31 --------- d-----w C:\Documents and Settings\xxx\Application Data\Apple Computer
                                2008-01-15 15:05 --------- d-----w C:\Program Files\Black Thorn
                                2008-01-13 15:38 --------- dcsh--w C:\Program Files\Fichiers communs\WindowsLiveInstaller
                                2008-01-13 15:17 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
                                2008-01-09 11:59 --------- d--h--w C:\Program Files\InstallShield Installation Information
                                2008-01-09 11:57 --------- d-----w C:\Program Files\Ubisoft
                                2008-01-09 11:26 --------- d-----w C:\Program Files\THQ
                                2008-01-09 11:08 --------- d-----w C:\Program Files\uTorrent
                                2008-01-09 11:07 --------- d-----w C:\Documents and Settings\xxx\Application Data\uTorrent
                                2008-01-02 10:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
                                2008-01-02 10:22 --------- d-----w C:\Program Files\QuickTime
                                2007-12-24 15:06 --------- d-----w C:\Program Files\Papyrus
                                2007-12-24 14:51 96,864 ----a-w C:\WINDOWS\~GLC0000.TMP
                                2007-12-19 14:34 --------- d-----w C:\Documents and Settings\xxx\Application Data\foobar2000
                                2007-12-19 14:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                                2007-12-19 14:25 --------- d-----w C:\Documents and Settings\xxx\Application Data\Free Download Manager
                                2007-12-14 16:19 40,960 ------w C:\WINDOWS\system32\MAMACExtract.dll
                                2007-12-13 18:27 54,672 ----a-w C:\WINDOWS\system32\vsutil_loc040c.dll
                                2007-12-12 17:23 --------- d-----w C:\Documents and Settings\xxx\Application Data\Sites
                                2007-12-12 17:23 --------- d-----w C:\Documents and Settings\xxx\Application Data\Classes de site
                                2007-12-08 21:00 --------- d-----w C:\Program Files\Fraps
                                2007-12-08 13:17 --------- d-----w C:\Program Files\Codemasters
                                2007-12-06 19:53 --------- d-----w C:\Documents and Settings\xxx\Application Data\Creative
                                2007-12-06 19:00 --------- d-----w C:\Program Files\Creative
                                2007-12-06 15:58 --------- d-----w C:\Program Files\Avast4
                                2007-12-05 19:41 --------- d-----w C:\Program Files\TrackMania Nations ESWC
                                2007-12-04 14:56 93,264 ----a-w C:\WINDOWS\system32\drivers\aswmon.sys
                                2007-12-04 14:55 94,544 ----a-w C:\WINDOWS\system32\drivers\aswmon2.sys
                                2007-12-04 14:53 23,152 ----a-w C:\WINDOWS\system32\drivers\aswRdr.sys
                                2007-12-04 14:51 42,912 ----a-w C:\WINDOWS\system32\drivers\aswTdi.sys
                                2007-12-04 14:49 26,624 ----a-w C:\WINDOWS\system32\drivers\aavmker4.sys
                                2007-12-04 13:04 837,496 ----a-w C:\WINDOWS\system32\aswBoot.exe
                                2007-12-04 12:54 95,608 ----a-w C:\WINDOWS\system32\AvastSS.scr
                                2007-11-28 19:30 --------- d-----w C:\Documents and Settings\xxxx\Application Data\DivX
                                2007-11-27 20:30 --------- d-----w C:\Program Files\Flac
                                2007-11-27 20:18 --------- d-----w C:\Program Files\foobar2000
                                2007-11-27 20:05 --------- d-----w C:\Documents and Settings\xxx\Application Data\F4
                                2007-11-27 20:00 409,600 ----a-w C:\WINDOWS\system32\wrap_oal.dll
                                2007-11-27 20:00 114,688 ----a-w C:\WINDOWS\system32\OpenAL32.dll
                                2007-11-27 14:33 684,313 ----a-w C:\WINDOWS\unins000.exe
                                2007-11-27 12:49 --------- d-----w C:\Documents and Settings\xxx\Application Data\DivX
                                2007-11-27 12:35 --------- d-----w C:\Program Files\Free Download Manager
                                2007-11-27 12:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG
                                2007-11-26 18:05 --------- d-----w C:\Program Files\DivX
                                2007-11-26 17:59 13,146 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
                                2007-11-26 17:33 --------- d-----w C:\Program Files\Java
                                2007-11-25 13:32 --------- d-----w C:\Program Files\Virtual Dub
                                2007-11-25 11:09 --------- d-----w C:\Program Files\Fantastic Flame Screensaver
                                2007-11-24 21:41 --------- d-----w C:\Program Files\GameSpy Arcade
                                2007-11-23 21:07 --------- d-----w C:\Program Files\ThiWeb Live 2
                                2007-11-23 20:48 --------- d-----w C:\Program Files\MilkShape 3D 1.7.7a
                                2007-11-23 19:54 --------- d-----w C:\Program Files\Half-Life Model Viewer
                                2007-11-20 14:36 118,784 ----a-w C:\WINDOWS\system32\MaDRM.dll
                                2007-11-09 17:24 103,736 ----a-w C:\WINDOWS\system32\PnkBstrB.exe
                                2007-11-07 12:49 108,144 ----a-w C:\WINDOWS\system32\CmdLineExt.dll
                                2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\lsasrv.dll
                                2007-11-07 09:28 728,576 ----a-w C:\WINDOWS\system32\dllcache\lsasrv.dll
                                2007-10-30 17:20 360,064 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
                                2007-10-29 22:36 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
                                2007-10-29 22:36 1,293,824 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
                                2007-10-25 16:43 8,516,608 ----a-w C:\WINDOWS\system32\dllcache\shell32.dll
                                2007-10-25 09:26 53,248 ----a-w C:\WINDOWS\bdoscandel.exe
                                2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\wmasf.dll
                                2007-10-25 08:28 222,720 ----a-w C:\WINDOWS\system32\dllcache\wmasf.dll
                                2007-10-20 00:56 524,288 ----a-w C:\WINDOWS\system32\DivXsm.exe
                                2007-10-20 00:56 3,596,288 ----a-w C:\WINDOWS\system32\qt-dx331.dll
                                2007-10-20 00:56 200,704 ----a-w C:\WINDOWS\system32\ssldivx.dll
                                2007-10-20 00:56 129,784 ------w C:\WINDOWS\system32\pxafs.dll
                                2007-10-20 00:56 120,056 ------w C:\WINDOWS\system32\pxcpyi64.exe
                                2007-10-20 00:56 118,520 ------w C:\WINDOWS\system32\pxinsi64.exe
                                2007-10-20 00:56 1,044,480 ----a-w C:\WINDOWS\system32\libdivx.dll
                                2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx0c.dll
                                2007-10-20 00:54 823,296 ----a-w C:\WINDOWS\system32\divx_xx07.dll
                                2007-10-20 00:54 81,920 ----a-w C:\WINDOWS\system32\dpl100.dll
                                2007-10-20 00:54 802,816 ----a-w C:\WINDOWS\system32\divx_xx11.dll
                                2007-10-20 00:54 739,840 ----a-w C:\WINDOWS\system32\DivX.dll
                                2007-10-20 00:54 196,608 ----a-w C:\WINDOWS\system32\dtu100.dll
                                2007-10-18 10:31 51,224 ----a-w C:\WINDOWS\system32\sirenacm.dll
                                2007-10-18 09:06 156,992 ----a-w C:\WINDOWS\system32\DivXCodecVersionChecker.exe
                                2007-10-18 09:03 593,920 ----a-w C:\WINDOWS\system32\dpuGUI11.dll
                                2007-10-18 09:03 57,344 ----a-w C:\WINDOWS\system32\dpv11.dll
                                2007-10-18 09:03 53,248 ----a-w C:\WINDOWS\system32\dpuGUI10.dll
                                2007-10-18 09:03 344,064 ----a-w C:\WINDOWS\system32\dpus11.dll
                                2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu11.dll
                                2007-10-18 09:03 294,912 ----a-w C:\WINDOWS\system32\dpu10.dll
                                2007-10-18 09:02 12,288 ----a-w C:\WINDOWS\system32\DivXWMPExtType.dll
                                2007-05-16 05:36 579,826 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
                                2007-05-14 19:27 17,644 -c--a-w C:\Documents and Settings\xxxx\Application Data\wklnhst.dat
                                2007-05-01 11:46 1,488 -c--a-w C:\Documents and Settings\xxxx\Application Data\wklnhst.dat
                                2007-04-25 10:29 3,330 -c--a-w C:\Documents and Settings\xxxx\Application Data\wklnhst.dat
                                2006-02-19 08:28 12,288 ----a-w C:\WINDOWS\Fonts\RandFont.dll
                                .

                                ((((((((((((((((((((((((((((( snapshot@2008-01-16_19.33.43.75 )))))))))))))))))))))))))))))))))))))))))
                                .
                                - 2008-01-16 18:05:26 1,396,736 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000001\NTUSER.DAT
                                + 2008-01-17 16:06:26 1,396,736 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000001\NTUSER.DAT
                                - 2008-01-16 18:05:26 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000002\UsrClass.dat
                                + 2008-01-17 16:06:26 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000002\UsrClass.dat
                                - 2008-01-16 18:05:27 7,745,536 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000003\NTUSER.DAT
                                + 2008-01-17 16:06:26 1,396,736 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000003\NTUSER.DAT
                                - 2008-01-16 18:05:27 307,200 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000004\UsrClass.dat
                                + 2008-01-17 16:06:26 8,192 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000004\UsrClass.dat
                                + 2008-01-17 16:06:27 7,766,016 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000005\NTUSER.DAT
                                + 2008-01-17 16:06:27 307,200 ----a-w C:\WINDOWS\erdnt\Hiv-backup\Users\[u]0[/u]0000006\UsrClass.dat
                                + 2008-01-17 15:57:57 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_1f4.dat
                                .
                                ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                .
                                .
                                REGEDIT4
                                *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

                                [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 12:00 15360]
                                "µTorrent"="C:\Program Files\uTorrent\utorrent.exe" [ ]
                                "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Fichiers communs\Ahead\Lib\NMBgMonitor.exe" [2007-06-27 18:03 152872]
                                "Free Uploader Oe Integration"="C:\Program Files\Free Download Manager\FUM\fumoei.exe" [2007-06-10 18:02 40960]
                                "Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 18:23 102400]
                                "BitTorrent DNA"="C:\Program Files\DNA\btdna.exe" [2008-01-09 12:06 290112]
                                "BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-11-27 23:45 588080]

                                [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-10-04 17:14 8491008]
                                "SsAAD.exe"="C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe" [2005-06-03 07:16 81920]
                                "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-09-19 05:19 180269]
                                "RTHDCPL"="RTHDCPL.EXE" [2006-07-22 00:56 16261632 C:\WINDOWS\RTHDCPL.EXE]
                                "nwiz"="nwiz.exe" [2007-10-04 17:14 1626112 C:\WINDOWS\system32\nwiz.exe]
                                "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-22 01:59 143360]
                                "HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-15 21:34 249856]
                                "HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-02-17 05:11 49152]
                                "ftutil2"="ftutil2.dll" [2004-06-07 13:05 106496 C:\WINDOWS\system32\ftutil2.dll]
                                "DMAScheduler"="c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 08:05 90112]
                                "HPDJ Taskbar Utility"="C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-29 20:50 196608]
                                "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
                                "avast!"="C:\PROGRA~1\Avast4\ashDisp.exe" [2007-12-04 14:00 79224]
                                "SPC500NC_Monitor"="C:\WINDOWS\Philips\SPC500NC\Monitor.exe" [2006-11-03 10:01 319488]
                                "NeroFilterCheck"="C:\Program Files\Fichiers communs\Ahead\Lib\NeroCheck.exe" [2007-03-01 14:57 153136]
                                "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 19:34 64512]
                                "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 01:11 132496]
                                "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-10-04 17:14 81920]
                                "SMSTray"="C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe" [2007-09-20 08:23 132624]
                                "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-12-11 10:56 286720]
                                "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 19:27 919016]

                                [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 12:00 15360]

                                C:\Documents and Settings\xxxx\Menu D‚marrer\Programmes\D‚marrage\
                                Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-09-19 04:47:45]
                                PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-09-19 04:47:45]

                                C:\Documents and Settings\xxxx\Menu D‚marrer\Programmes\D‚marrage\
                                Pin.lnk - C:\hp\bin\CLOAKER.EXE [2006-09-19 04:47:45]
                                PinMcLnk.lnk - C:\hp\bin\cloaker.exe [2006-09-19 04:47:45]

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
                                "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

                                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
                                "NoSetFolders"= 0 (0x0)
                                "NoFavoritesMenu"= 0 (0x0)
                                "NoSimpleStartMenu"= 0 (0x0)
                                "NoUserNameInStartMenu"= 0 (0x0)
                                "NoStartMenuPinnedList"= 0 (0x0)
                                "NoStartMenuMFUprogramsList"= 0 (0x0)
                                "NoSMMyPictures"= 0 (0x0)
                                "NoStartMenuMyMusic"= 0 (0x0)

                                [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
                                "{88485281-8b4b-4f8d-9ede-82e29a064277}"= C:\PROGRA~1\MarkAny\CONTEN~1\MACSMA~1.DLL [2004-11-23 16:51 192512]

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
                                "UIHost"="LogonUI.EXE"

                                [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                                "NI.UWAS6V_0001_N91M2208"="c:\documents and settings\guillaume\application data\winantispyware2006freeinstall_fr[1].exe" -nag
                                "PCDrProfiler"=
                                "Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.0\Apps\apdproxy.exe"
                                "DriveCleaner Free"="C:\Program Files\DriveCleaner Free\UDC.exe" /min
                                "ehTray"=C:\WINDOWS\ehome\ehtray.exe
                                "Zone Labs Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

                                R1 oreans32;oreans32;C:\WINDOWS\system32\drivers\oreans32.sys [2007-09-13 16:55]
                                R2 RPCHED;Remote Procedure CallD (RPCE);C:\Program Files\Intel\Intell.exe [2002-01-09 17:19]
                                R3 fbxusb;Carte réseau virtuelle FreeBox USB;C:\WINDOWS\system32\DRIVERS\fbxusb32.sys [2004-10-20 14:23]
                                R3 usbstor;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-10 12:00]
                                S3 SPC500NC;SPC 500NC Laptop Camera;C:\WINDOWS\system32\DRIVERS\SPC610NC.SYS [2007-01-19 16:14]
                                S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]

                                [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E]
                                \Shell\AutoRun\command - E:\setup.exe
                                \Shell\directx\command - E:\DirectX\dxsetup.exe
                                \Shell\setup\command - E:\setup.exe

                                *Newly Created Service* - PROCEXP90
                                .
                                Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
                                "2007-12-28 16:15:00 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
                                - C:\Program Files\TuneUp Utilities 2007\SystemOptimizer.exe
                                "2008-01-17 16:00:00 C:\WINDOWS\Tasks\Spybot - Search & Destroy - Scheduled Task.job"
                                - C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
                                .
                                **************************************************************************

                                catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                Rootkit scan 2008-01-17 17:25:32
                                Windows 5.1.2600 Service Pack 2 NTFS

                                scanning hidden processes ...

                                scanning hidden autostart entries ...

                                scanning hidden files ...

                                scan completed successfully
                                hidden files: 0

                                **************************************************************************
                                .
                                Completion time: 2008-01-17 17:29:23
                                ComboFix-quarantined-files.txt 2008-01-17 16:29:12
                                ComboFix2.txt 2008-01-16 18:34:42
                                .
                                2008-01-17 17:21:26 --- E O F ---

                                C'est bon?
                                Quand tu dis Exécute le... tu parle de quoi? ComboFix?
                                0
                                1. Modérateur
                                  c'est parti !

                                  Crée un nouveau document texte et nomme le CFScript.txt ( attention très important ! ) : clic droit de souris sur le bureau > Nouveau > Document Texte, et copie dedans les lignes suivantes en gras :



                                  File ::

                                  C:\WINDOWS\~GLC0000.TMP
                                  C:\WINDOWS\system32\tmpC444F.FOT
                                  C:\WINDOWS\system32\tmp9774F.FOT
                                  C:\WINDOWS\system32\tmp5084F.FOT
                                  C:\WINDOWS\IFinst26.exe
                                  C:\upload_moi_DARLING.tar.gz
                                  C:\WINDOWS\imsins.BAK
                                  C:\WINDOWS\system32\drivers\oreans32.sys

                                  Folder ::

                                  C:\Program Files\DriveCleaner Free

                                  Driver ::

                                  oreans32

                                  Registry::

                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0785D7B3-75D1-449C-8764-B7F34CACB9D1}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{183DAFA3-28F8-402D-9B71-70FB514D5BC2}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{23B28C7D-CFB4-4DC5-B5FF-BD9E9F41A04D}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30266CAA-B742-4380-9228-5E42C1C047E3}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6E3D2E1D-7B23-41c8-8A6C-13012A889F99}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{82A94863-7169-45E5-83A9-C9B6D1552051}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{874EE138-DC4F-41E0-AD02-C71A9ABEFFDC}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{881E8220-FF74-49B5-A14B-E3BDA5DC95FC}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8E6CEAAA-5821-4482-B893-5E01B46A62F5}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8F15DB30-0F2C-4DC0-8109-55F905F7F95F}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{980682F0-8794-4A1E-804C-77B45606DEC8}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9BFE63B9-F62C-487A-B890-DFD9FE6675AE}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A4D51FEC-F3AB-4207-88C8-BA4B2F669E56}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A74364D3-8A44-42EA-BC8A-C02131BBEAD4}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BB05CEDD-8A90-4994-B5A5-0FE52101411d}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BC890CB2-9C59-4E90-97F2-CB47D1B2B200}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C1F74180-ADD5-47A4-AA34-4BA4B2F3E73C}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB417852-6BFC-46D6-83DA-BCF80BDAD918}]
                                  [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{ED8FB9E5-6430-44BE-B970-AD34DD9DB3D6}]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awtsq]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvtr]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\awvtu]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\gebcb]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geeba]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geebc]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geebx]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\geede]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\jkkjh]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\mljkhhf]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkjk]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqpn]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\ssqromm]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\vtutt]
                                  [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winemx32]
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
                                  "NI.UWAS6V_0001_N91M2208"="-
                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
                                  "UIHost"="-


                                  ensuite fais glisser le fichier texte sur combo.exe comme sur l'animation : http://img.photobucket.com/albums/v666/sUBs/CFScript.gif

                                  Dans la fenêtre qui suit, choisie l'option 1 puis valide
                                  Patiente un peu, si le bureau disparait parfois durant le scan : c'est normal !
                                  A la fin du scan, un rapport va s'afficher : poste le stp ( sinon il se situe dans ici : C:\ComboFix.txt )

                                  puis, fais ceci stp :

                                  Exécute le et clique sur "Open the misc tools section" -> "Open ADS Spy..." -> "Scan" -> "Save log..." -> Copie/colle ici le texte ouvert avec le bloc note.

                                  @+
                                  0
                                  1. Contributeur sécurité
                                    bonne nuit ,a demain !
                                    1
                                    1. Je vais me coucher, je me lève tôt demain (4h :-( )... Je reviens vers 17h.

                                      A+
                                      0
                                      1. Modérateur
                                        ça s'appelle une erreur de frappe ! :))

                                        je te prépare la manip !

                                        oui, c'est vraiment pas triste !

                                        @+
                                        0
                                        • 1
                                        • 2
                                        • 3