Virus ?

Bonjour,
depuis quelques jours mon pc tourné au ralenti, j'ai tout de suite penser à un virus, kaspersky ne detecte rien, quand je lance spybot ou ad aware non plus, j'ai supprimé le contenu du dossier temp (j'ai fait ça a totu hasard, je savais meme pas si c'était risqué :/ ) , depuis l'ordinateur tourne beaucoup plus vite rien que pour le démarrage mais lorsque je l'allume j'ai immédiatement sur le bureau un message " erreur de chargement de "C:\...\temp\hggec.dll", j'ai essayer de regarder sur internet et je le vois que dans des sujets où ça parle de virus, je suis pas trés doué et j'aimerai bien savoir si c'est un virus ou un spyware, comment l'enlever ou au moins le message qui apparait a chaque démarrage :x
j'ai vu qu'il fallait souvent le rapport hijack this je le met donc directement au cas où :

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:39:00, on 14/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Windows Sidebar\sidebar.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\Windows Mail\WinMail.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Users\TOSHIBA\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.atoutsweb.com/index.php?forum=ggenty
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BitTorrent DNA] "C:\Users\TOSHIBA\Program Files\BitTorrent_DNA\dna.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\TOSHIBA\AppData\Local\Temp\hggec.dll,c
O4 - Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
O9 - Extra button: Amazon.fr - {8A918C1D-E123-4E36-B562-5C1519E434CE} - https://www.amazon.fr/exec/obidos/subst/home/home.html/262-6263521-6325360?_encoding=UTF8&link_code=hom&tag=Toshibafrbholink-21 (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {861FDA2A-2B57-4BDA-8B8B-305C9D5D8604} (_Multimedia Player) - http://stream.pussyharem.com/stream/mmp2.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

--
End of file - 10385 bytes

Voila, si quelqu'un a le temps de regarder ça merci beaucoup
Configuration: Windows Vista
Opera 9.25

31 réponses

Résumé de la discussion

Un utilisateur signale un PC lent et une erreur au démarrage relative à C:\...\temp\hggec.dll, s'interrogeant sur une infection virale ou spyware malgré des scans qui ne détectent rien. La réponse principale propose d'exécuter Zeb restore et d'analyser le rapport HijackThis, qui détaille les processus actifs et les entrées de démarrage soupçonnées. En parallèle, une autre intervention évoque que l'infection pourrait provenir de sites pornographiques, reflétant une association parfois présentée dans ce type de discussions et soulignant la nécessité d'une vigilance accrue. La discussion illustre l'utilisation d'outils d'analyse comme HijackThis pour diagnostiquer les entrées de démarrage et les DLL associées, utile pour guider les prochaines étapes de nettoyage et de sécurisation du système.

Bobot (l’IA à votre service)
  1. Ok,
    essaye ici :
    > Scanne ton PC avec BitDefender en ligne http://www.bitdefender.comscan8ie.html (uniquement sous Internet Explorer)
    - Clique sur J'accepte puis accepte également l'ActiveX bloqué par la barre anti-popup du SP2 qui clignotera en haut et installe le.
    - Ensuite, clique sur Cliquez ici pour scanner.
    - Patiente jusqu'à la fin du scan qui peut durer assez longtemps...
    - Poste le rapport une fois terminé stp.

    ou là...... :

    > Fais un scan en ligne Panda sous Internet Explorer : https://www.pandasecurity.com/en/homeusers/online-antivirus/?ref=activescan (tuto ici ou là si tu as besoin)
    - Clique sur " Analyser maintenant"
    - Ensuite sur " Analyse complète " puis " Analyser maintenant "
    - Suis les instructions..
    - Poste le rapport en fin d'analyse stp

    A+

    :)

    PS : oui c'est bientôt (normalement) la fin...
    1. re, j'ai effectivement un problème mais c'est avec vista :s, quand je vais dessus voila ce qu'il m'indique
      "Compatibilité avec Windows Vista en cours de développement.
      Bientôt disponible..."
      si je clique sur demarrer "online-scanner" il ne se passe rien.
      ça sent la fin :)

      A+
      1. Bon, très bien...
        Finissons sans être molisson... :))
        Pendant que je me renseigne sur ebay...

        > Fais un scan en ligne avec Kaspersky : https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
        - Sous Démonstration en ligne, on t'explique la marche à suivre, et pour lancer le scan il faut sélectionner < Exécuter l'analyse en ligne >.
        Le scan ne marche que sous Internet Explorer.
        - On va te demander de télécharger un contôle active x, accepte .
        - Dans le menu Choisissez la cible de l'analyse, sélectionne Poste de travail. Le scan va commencer.
        - Poste le rapport qui sera généré stp.
        S'il y a un problème, assure toi que les contrôles active x sont bien configurés dans les options internet comme décrit sur ce lien : http://www.inoculer.com/activex.php3
        Rappel : le scan est à faire sous Internet Explorer

        > As-tu encore des problèmes avec ton PC ?

        A+

        ;)
        1. voila le rapport hijack this :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 17:23:52, on 16/02/2008
          Platform: Windows Vista (WinNT 6.00.1904)
          MSIE: Internet Explorer v7.00 (7.00.6000.16609)
          Boot mode: Normal

          Running processes:
          C:\Windows\system32\Dwm.exe
          C:\Windows\Explorer.EXE
          C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
          C:\Windows\system32\taskeng.exe
          C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
          C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
          C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
          C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe
          C:\Windows\System32\igfxtray.exe
          C:\Windows\System32\hkcmd.exe
          C:\Windows\System32\igfxpers.exe
          C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
          C:\Program Files\Synaptics\SynTP\SynToshiba.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
          C:\Windows\system32\igfxsrvc.exe
          C:\Program Files\Microsoft IntelliPoint\ipoint.exe
          C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
          C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe
          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
          C:\Program Files\Last.fm\LastFMHelper.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
          c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
          c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
          C:\Windows\System32\mobsync.exe
          C:\Program Files\Windows Mail\WinMail.exe
          C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Users\TOSHIBA\Desktop\HijackThis.exe
          C:\Program Files\Opera\Opera.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
          O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
          O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
          O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
          O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
          O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
          O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
          O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
          O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
          O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
          O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
          O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
          O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
          O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
          O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
          O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
          O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
          O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
          O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
          O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
          O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          O4 - HKCU\..\Run: [cmds] rundll32.exe C:\Users\TOSHIBA\AppData\Local\Temp\hggec.dll,c
          O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
          O4 - Global Startup: Bluetooth Manager.lnk = ?
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
          O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
          O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
          O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
          O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
          O13 - Gopher Prefix:
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
          O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
          O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
          O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
          O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
          O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
          O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
          O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
          O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
          O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
          O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
          O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
          1. Ok,
            super....il est légitime, pas de soucis.

            Pour la 09 abay => file missing => donc pas de sushis non plus...

            Par contre ton rapport HiJackT doit toujours être fait en mode normal. Peux tu en reposter un stp ?

            A+
            1. je sais pas si c'est normal mais le O9 ebay même si je le fix il est toujours là

              le fichier est analysé je met juste l'en tête mais sinon il n'a rien eu dans la case résultat je sais pas si c'estutile de tout copié collé :

              Fichier wininit.exe reçu le 2008.02.16 17:00:50 (CET)
              Situation actuelle: terminé
              Résultat: 0/32 (0%)
              1. re,
                ok merci, bizarre un virus sous xp qui est sain sous vista ...
                en attendant lanalyse de wininit voici le rapport hijackthis :

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 17:01:18, on 16/02/2008
                Platform: Windows Vista (WinNT 6.00.1904)
                MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                Boot mode: Safe mode with network support

                Running processes:
                C:\Program Files\Opera\Opera.exe
                C:\Windows\explorer.exe
                C:\Users\TOSHIBA\Desktop\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
                O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
                O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
                O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                O4 - Global Startup: Bluetooth Manager.lnk = ?
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
                O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
                O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O13 - Gopher Prefix:
                O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
                O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
                O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                1. Re,

                  Bon ok : la suite : :)))

                  > Rends toi ensuite sur ce site virustotal et fais analyser le fichier suivant stp :
                  (Si problème : http://pageperso.aol.fr/loraline60/virus_total.htm )

                  C:\Windows\system32\wininit.exe

                  et poste le resultat par copier/coller stp.

                  > poste aussi un nouveau rapport HiJackT stp

                  A+
                  1. re,
                    merci de ta patience :) et de ton efficacité :)

                    voila le premier rapport je pense que c'est ça pour le prog otmoveit:
                    File move failed. C:\Windows\system32\wininit.exe scheduled to be moved on reboot.

                    OTMoveIt2 v1.0.20 log created on 02162008_162511

                    ensuite le rapport smit fraudfix :
                    SmitFraudFix v2.289

                    Scan done at 16:36:37,23, 16/02/2008
                    Run from C:\Users\TOSHIBA\Desktop\SmitfraudFix
                    OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                    The filesystem type is NTFS
                    Fix run in safe mode

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                    !!!Attention, following keys are not inevitably infected!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                    127.0.0.1 localhost

                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                    VACFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                    S!Ri's WS2Fix: LSP not Found.

                    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                    GenericRenosFix by S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                    IEDFix
                    Credits: Malware Analysis & Diagnostic
                    Code: S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                    Description: Intel(R) PRO/Wireless 3945ABG Network Connection
                    DNS Server Search Order: 192.168.1.1

                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{0A8AF5DC-2C1A-4891-9D6A-62CC93926FA9}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\..\{0A8AF5DC-2C1A-4891-9D6A-62CC93926FA9}: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                    !!!Attention, following keys are not inevitably infected!!!

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                    Registry Cleaning done.

                    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                    !!!Attention, following keys are not inevitably infected!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» End
                    1. Re,

                      bon ok,

                      Il faut que tu te débarrasse de cette crasse : wininit.exe

                      Alors 2 solutions (fais les deux stp) :

                      > Télécharge OTMoveIT (de Old_Timer) : http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe sur ton bureau...
                      - Double-clique sur OTMoveIt.exe pour le lancer.
                      - Assure toi que la case "Unregister Dll's and Ocx's" est bien cochée !!!
                      - Copie le texte qui se trouve ci-dessous et colle-le dans le cadre de gauche de OTMoveIt nommé <Paste standard List of Files/Folders to be moved>.

                      C:\Windows\system32\wininit.exe

                      - Clique sur < MoveIt! > pour lancer la suppression.
                      - Lorsqu'un résultat apparaît dans le cadre Results clique sur Exit
                      N.B :Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer. Accepte en cliquant sur YES.
                      Un rapport est créé dans %SYSTEMDRIVE%\_OTMoveIt\MovedFiles\date du jour, copie-colle-le dans ta réponse suivante stp.

                      Ensuite,
                      > Démarre en mode sans échec : (image). Si problème : tuto ici
                      - Dans le dossier "SmitfraudFix" ouvre "Smitfraudfix.cmd" puis choisit l 'option 2 et tape "oui" pour toutes les questions.
                      - Enregistre le rapport puis envoie le dans ton prochain poste.

                      A+

                      Bon courage.

                      A+
                      1. j'ai rien dit le rapport vien de tombé et il m'a rien trouvé (je sais pas si je doit m'en réjouir ou pas :/)

                        le voici (j'ai fais l'analyse en mode sans échec au cas où je peux la relancer en mode normal) :

                        MSNFix 1.661

                        C:\Users\TOSHIBA\Desktop\MSNFix
                        Fix exécuté le 16/02/2008 - 15:43:33,57 By TOSHIBA
                        mode sans échec

                        ************************ Recherche les fichiers présents

                        ... C:\Windows\system32\tmp.txt

                        ************************ Recherche les dossiers présents

                        ... C:\Users\TOSHIBA\AppData\Local\TEMP\

                        ************************ Suppression des fichiers

                        .. OK ... C:\Windows\system32\tmp.txt

                        ************************ Suppression des dossiers

                        /!\ ... C:\Users\TOSHIBA\AppData\Local\TEMP\

                        ************************ Nettoyage du registre

                        ************************ Fichiers suspects

                        Aucun Fichier trouvé

                        Les fichiers et clés de registre supprimés ont été sauvegardés dans le fichier 16022008_16124433.zip

                        ------------------------------------------------------------------------
                        Auteur : !aur3n7 Contact: https://www.ionos.fr/
                        ------------------------------------------------------------------------

                        --------------------------------------------- END ---------------------------------------------
                        1. en fait même en mode normal ça marche pas :s,

                          Quand je lance msnfix et que j'appuie sur R il doit afficher quelquechose lord de la recherche de virus parceque pour l'instant j'ai fait R j'ai validé et j'ai l'impression qu'il ne se passe rien.
                          1. Re,
                            Ok, en mode sans échec normalement....essaye en mode normal sinon.

                            Si tu as des problèmes : passe à la suite stp.

                            A°°¨¨
                            1. bonjour,

                              le premiere rapport info sat donne ceci :

                              Sat Feb 16 14:26:02 2008
                              EliBagle v11.00 (c)2008 S.G.H. / Satinfo S.L.
                              ----------------------------------------------
                              Lista de Acciones (por Acción Directa):

                              Sat Feb 16 14:26:11 2008
                              EliBagle v11.00 (c)2008 S.G.H. / Satinfo S.L.
                              ----------------------------------------------
                              Lista de Acciones (por Exploración):
                              Explorando Unidad C:\

                              Nº Total de Directorios: 6592
                              Nº Total de Ficheros: 51292
                              Nº de Ficheros Analizados: 8185
                              Nº de Ficheros Infectados: 0
                              Nº de Ficheros Limpiados: 0
                              Exploración Detenida por el Usuario.

                              Sat Feb 16 14:29:49 2008
                              EliBagle v11.00 (c)2008 S.G.H. / Satinfo S.L.
                              ----------------------------------------------
                              Lista de Acciones (por Acción Directa):

                              Sat Feb 16 14:29:52 2008
                              EliBagle v11.00 (c)2008 S.G.H. / Satinfo S.L.
                              ----------------------------------------------
                              Lista de Acciones (por Exploración):
                              Explorando Unidad C:\

                              Nº Total de Directorios: 12976
                              Nº Total de Ficheros: 85154
                              Nº de Ficheros Analizados: 13772
                              Nº de Ficheros Infectados: 0
                              Nº de Ficheros Limpiados: 0

                              pour le site virustotal le rapport est celui ci :

                              Antivirus Version Dernière mise à jour Résultat
                              AhnLab-V3 2008.2.16.10 2008.02.15 -
                              AntiVir 7.6.0.67 2008.02.15 -
                              Authentium 4.93.8 2008.02.15 -
                              Avast 4.7.1098.0 2008.02.15 -
                              AVG 7.5.0.516 2008.02.15 -
                              BitDefender 7.2 2008.02.16 -
                              CAT-QuickHeal None 2008.02.16 -
                              ClamAV 0.92.1 2008.02.15 -
                              DrWeb 4.44.0.09170 2008.02.16 -
                              eSafe 7.0.15.0 2008.02.14 -
                              eTrust-Vet 31.3.5541 2008.02.15 -
                              Ewido 4.0 2008.02.16 -
                              FileAdvisor 1 2008.02.16 -
                              Fortinet 3.14.0.0 2008.02.16 -
                              F-Prot 4.4.2.54 2008.02.15 -
                              F-Secure 6.70.13260.0 2008.02.15 -
                              Ikarus T3.1.1.20 2008.02.16 -
                              Kaspersky 7.0.0.125 2008.02.16 -
                              McAfee 5231 2008.02.15 -
                              Microsoft 1.3204 2008.02.16 -
                              NOD32v2 2880 2008.02.15 -
                              Norman 5.80.02 2008.02.15 -
                              Panda 9.0.0.4 2008.02.16 Suspicious file
                              Prevx1 V2 2008.02.16 -
                              Rising 20.31.50.00 2008.02.16 -
                              Sophos 4.26.0 2008.02.16 -
                              Sunbelt 2.2.907.0 2008.02.14 -
                              Symantec 10 2008.02.16 -
                              TheHacker 6.2.9.221 2008.02.15 -
                              VBA32 3.12.6.1 2008.02.14 -
                              VirusBuster 4.3.26:9 2008.02.15 -
                              Webwasher-Gateway 6.6.2 2008.02.15 -

                              Information additionnelle
                              File size: 1507328 bytes
                              MD5: 5f5764e4046019031c7445541d728721
                              SHA1: 5eb3c487903d600ab1a25a8d3c9deb1b005e0e8a
                              PEiD: -

                              Le rapport clean :

                              Script executed in Safe Mode
                              Rapport clean par Malekal_morte - http://www.malekal.com
                              Script executed in Safe Mode 16/02/2008 a 14:51:23,00

                              Microsoft Windows [version 6.0.6000]

                              *** Suppression C:

                              *** Suppression C:\Windows\

                              *** Suppression C:\Windows\system32
                              tentative de suppression de C:\Windows\system32\wininit.exe
                              Impossible de supprimer C:\Windows\system32\wininit.exe
                              tentative de suppression de C:\Windows\system32\wininit.exe
                              Impossible de supprimer C:\Windows\system32\wininit.exe

                              *** Suppression C:\Program Files

                              *** Deletion of the registry keys successful..

                              Sd fix doit forcément être lancer en mode sans echec ? quand je le lance en mode normal il marche mais en mode sans echec la fenêtre ne fait qu'apparaitre deux secondes .
                              1. Coucou,
                                ok, très bien on avance.

                                > Tu possède une version beta des maj de Kaspersky. Je ne te le recommande pas parce que même si il s'agit d'une avancée dans la base antivirus, elle ^peut présenter des dysfonctionnements possibles...
                                Info : http://www.kaspersky.com/beta?product=165219909

                                > Télécharge sur ton bureau ELIBAGLA en bas de la page : httpwww.zonavirus.comdatosdescargas95elibagla.asp (clique sur le bouton Descargar Elibagla)
                                - Lance le programme, si possible en mode sans échec, puis patiente le temps du scan.
                                - Poste le contenu du fichier infoSat.txt qui se trouve dans C:/ stp.

                                > Rends toi ensuite sur ce site virustotal et fais analyser les fichiers suivants stp :
                                (Si problème : http://pageperso.aol.fr/loraline60/virus_total.htm )

                                C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe


                                et poste les resultats par copier/coller stp.

                                > Redemarre en mode sans échec et essyae à nouveau de lancer SDFix stp.

                                > Idem (mode sans échec) pour Clean option 2

                                > Télécharge, puis installe MSNFix : http://sosvirus.changelog.fr/MSNFix.zip , tuto de Malekal : [https://www.malekal.com/supprimer-virus-desinfecter-pc/ (si tu as besion).
                                - Décompresse donc le dossier zip MSNFix et lance le fichier "MSNFix.bat". Une fenêtre bleue doit apparaitre.
                                - Mets l'interface en français en appuyant sur la touche F puis sur Entrée.
                                - Lance la recherche de virus en appuyant sur la touche R puis sur Entrée.
                                Si un virus est détecté, il te sera alors demandé de nettoyer l'ordinateur.
                                Un message d'erreur concernant la suppression impossible d'un fichier sera résolu par un redémarrage.
                                Après le nettoyage, la barre "Démarrer" s'efface puis réapparait, cela fait partie de la procédure de nettoyage.
                                - Poste le rapport qui s'ouvre en fin de nettoyage sur le forum stp.

                                Si ta barre "Démarrer" ne s'affiche toujours pas, il suffit de faire :
                                Ctrl + Alt + Suppr (sous Windows XP), ou Ctrl + Maj + Echap (sous Windows Vista) pour ouvrir le Gestionnaire de tâches Windows.
                                - Fais ensuite "Fichier", puis "Nouvelle tâche" et entre explorer.exe dans la fenêtre qui apparait et finis par "OK".

                                - redémarre ton ordinateur pour achever le nettoyage !

                                > Fixe cette ligne dans HiJackT stp :

                                O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)

                                > Renvoie aussi un rapport HiJAckT stp.

                                > On arrive à la fin :))

                                Bon courage,

                                Dl.

                                :)
                                1. Bonjour,

                                  Voila, j'ai bien exécuter Zeb restore, voila le rapport hijack this

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 09:18:26, on 16/02/2008
                                  Platform: Windows Vista (WinNT 6.00.1904)
                                  MSIE: Internet Explorer v7.00 (7.00.6000.16609)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\Explorer.EXE
                                  C:\Windows\system32\taskeng.exe
                                  C:\Program Files\Windows Defender\MSASCui.exe
                                  C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
                                  C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
                                  C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
                                  C:\Windows\RtHDVCpl.exe
                                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
                                  C:\Program Files\Synaptics\SynTP\SynToshiba.exe
                                  C:\Program Files\TOSHIBA\Toshiba Online Product Information\TOPI.exe
                                  C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe
                                  C:\Windows\System32\igfxtray.exe
                                  C:\Windows\System32\hkcmd.exe
                                  C:\Windows\System32\igfxpers.exe
                                  C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe
                                  C:\Windows\system32\igfxsrvc.exe
                                  C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                  C:\Program Files\Microsoft IntelliPoint\ipoint.exe
                                  C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
                                  C:\Windows\ehome\ehtray.exe
                                  C:\Windows\ehome\ehmsas.exe
                                  C:\Program Files\Camera Assistant Software for Toshiba\CEC_MAIN.exe
                                  C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
                                  C:\Program Files\Windows Sidebar\sidebar.exe
                                  c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
                                  C:\Program Files\Windows Mail\WinMail.exe
                                  c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
                                  c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
                                  C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\SearchFilterHost.exe
                                  C:\Users\TOSHIBA\Desktop\HijackThis.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                  O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                  O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                  O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
                                  O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe
                                  O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
                                  O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
                                  O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                                  O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe
                                  O4 - HKLM\..\Run: [topi] C:\Program Files\TOSHIBA\Toshiba Online Product Information\topi.exe -startup
                                  O4 - HKLM\..\Run: [Desktop SMS] C:\Program Files\IDM\Desktop SMS\DesktopSMS.exe /auto
                                  O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
                                  O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
                                  O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
                                  O4 - HKLM\..\Run: [Camera Assistant Software] "C:\Program Files\Camera Assistant Software for Toshiba\traybar.exe"
                                  O4 - HKLM\..\Run: [Toshiba Registration] C:\Program Files\Toshiba\Registration\ToshibaRegistration.exe
                                  O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                                  O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
                                  O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
                                  O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
                                  O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                  O4 - HKCU\..\Run: [TOSCDSPD] TOSCDSPD.EXE
                                  O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
                                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                  O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                  O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                  O4 - Global Startup: Bluetooth Manager.lnk = ?
                                  O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                  O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
                                  O9 - Extra button: eBay - Achetez, Vendez - {76577871-04EC-495E-A12B-91F7C3600AFA} - https://www.ebay.fr (file missing)
                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                  O13 - Gopher Prefix:
                                  O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                  O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
                                  O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
                                  O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe
                                  O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                  O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                                  O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
                                  O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                                  O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                                  O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                                  O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
                                  O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                                  O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                  O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe
                                  O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
                                  O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
                                  O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - c:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                                  O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
                                  1. Bonsoir,

                                    oui...c'est celui là... :)))

                                    > Télécharge Zeb-Restore : http://telechargement.zebulon.fr/zeb-restore.html
                                    - Mets le dans un dossier, sur ton bureau par exemple.
                                    - Lance Zebrestore et coche les cases suivantes :

                                    Réinitialiser Fichier Hosts

                                    - Clique sur le bouton Restaurer.
                                    - Quitte le programme puis renvoie un log HiJack,

                                    > Reposte un rapport HiJackT stp après.

                                    Merci,
                                    A+

                                    :)
                                    • 1
                                    • 2