Help cafards....

Bonjour, j'ai aussi ces espèces de sales bêtes qui envahissent mon écran; problème: je suis une vraie pipe en informatique donc je ne comprends rien à vos messages précédents, les rapports, les scan.... c'est du chinois pour moi! Si une bonne âme voulait bien me venir en aide....
Merci merci merci merci d'avance
Caro
Configuration: Windows XP
Internet Explorer 6.0

29 réponses

Résumé de la discussion

Plusieurs utilisateurs confrontent une infection par malware sur Windows XP et Internet Explorer 6 et peinent à comprendre les rapports, les scans et les tutoriels techniques qui circulent dans la discussion. Des solutions pratiques sont proposées, notamment l'utilisation de HijackThis et de ComboFix, avec des tutoriels pas-à-pas et des rapports à transmettre pour guider la désinfection. En cas de procédure, il est conseillé de désactiver antivirus et antispyware pendant l'exécution de l'outil, puis de réactiver la protection et de ne pas interagir dans la fenêtre. D'autres éléments variables, tels que les rapports contenant des chemins système, des noms de services ou des modules légitimes, peuvent induire des confusions et nécessitent une vérification croisée lors de la désinfection.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    télécharge et installe le logiciel Hijack This
    https://www.pcastuces.com/logitheque/hijackthis.htm
    tuto pour l’utiliser
    regarde ici c'est parfaitement expliqué en images
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm
    poste le rapport obtenu
    4
    1. Contributeur sécurité
      je serai absent aujourd'hui, déplacement professionnel, donc si tu as réussi à passer ComboFix, tu me postes le rapport
      tu me dis également comment se comporte ton PC

      ensuite tu fais ceci
      si tu ne l'as pas...tu le télécharges, si tu l'as, tu le mets à jour avant utilisation!
      Télécharge MalwareByte
      http://www.malwarebytes.org/mbam/program/mbam-setup.exe
      Installe-le
      Dans l'onglet Recherche, clique sur Exécuter un examen complet puis sur Rechercher.
      Sélectionne ton (tes) disques durs.
      Lancer l'examen
      supprime tout ce qu'il trouve!
      Clique sur Enregistrer le rapport et choisis ton Bureau
      à ce soir ...
      0
      1. Désolée je n'ai pas pu me connecter avant!est ce que je dois encore t'envoyer des rapports? si oui, quoi omment??
        merci
        caro
        0
        1. Contributeur sécurité
          essaie de retirer tous les périphériques externes et de redémarrer...tu les remettras avant de scanner avec ComboFix
          0
          1. Le probléme c'est quand tu veux installer un antispyware il doit faire une mise à jour et moi je n'ai plus internet donc pas de mise à jour donc pas d'installations donc toujours bloqué.
            0
            1. désolée aymeu mais je ne suis pas très bien ce que tu m'expliques; j'ai bien internet, je veux juste rallumer mon pc...
              j'ai mal aux cheveux!
              0
          2. 1ère étape ok sauf que mon pc ne se rallume pas....
            même avec F8....
            0
            1. Contributeur sécurité
              on continue
              ComboFix a débusqué une infection par périphériques externes
              donc tu vas faire ceci dans un 1er temps
              une infection qui se propage par les périphériques externes, donc si tu désinfectes ton Pc mais pas tes périphériques - clé USB, DD externe, tout périphérique qui se connecte sur ton PC, etc... cela se relance..
              Tu vas faire ceci dans un 1er temps
              Si tu as une clé USB, disque dur externe, etc., branche-les sans les ouvrir avant de lancer ce FIX
              Télécharge Rav Antivirus: http://ww25.evosla.com/compteur.php?soft=rav_antivirus
              · Clique droit sur le fichier .ZIP > Extraire sur > le Bureau
              · Double clique sur >> RAV.exe << afin de lancer l'outil.
              · Une fois RAV ANTIVIRUS lancé, laisse-le réagir, il Scanne automatiquement tous les lecteurs (disques fixes et amovibles)
              · Si infection > un rapport s'établira, sinon s'affichera (très rapide) ==>Votre Ordinateur est sain.
              · redémarre ton ordinateur.
              Poste le rapport, si infection!

              laisse tes périphériques branchés
              Rappel : une fois que ComboFix est lancé, il ne faut pas cliquer dans la fenêtre de ComboFix car cela pourrait entraîner un plantage du programme.
              Il est recommandé de laisser l'outil analyser et nettoyer le PC sans utiliser quoi que ce soit d'autre...

              Sélectionne le texte suivant (Ctrl+A):
              File::
              C:\WINDOWS\index.exe
              C:\WINDOWS\7ujkn.exe
              C:\WINDOWS\system32\kcopt.dll
              C:\WINDOWS\system32\ctfmonb.bmp
              C:\WINDOWS\system32\ntpl.bin
              C:\WINDOWS\system32\ho.ln
              C:\WINDOWS\system32\ko.o
              C:\WINDOWS\system32\sysrest32.exe
              C:\Documents and Settings\portablenec\Application Data\install_fr[1].exe
              C:\Documents and Settings\portablenec\Application Data\setup_fr[1].exe
              
              Folder::
              C:\Program Files\AXPFixer
              C:\Documents and Settings\portablenec\Application Data\AXPFixer
              
              Registry::
              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
              "AXPFixer"=- 
              "sysrest32.exe"=-

              Copie le texte sélectionné (CTRL+C).
              Ouvre le Bloc-notes (Démarrer/Tous les programmes/Accessoires/Bloc-notes).
              Colle le texte copié dans ce Bloc-notes (CTRL+V).
              Sauvegarde ce fichier sur ton Bureau sous le nom de CFScript.txt (CFScript)
              http://img.photobucket.com/albums/v666/sUBs/CFScript.gif
              Comme l'image le montre, fait glisser CFScript.txt sur ComboFix.exe(ComboFix)
              Une fenêtre à fond bleu va s'ouvrir: au message qui apparaît ( Type 1 to continue, or 2 to abort) , tape 1 puis valide.
              Laisse ComboFix travailler
              Patiente le temps de l'analyse. Le Bureau va disparaître à plusieurs reprises: c'est normal!
              Ne touche à rien tant que le nettoyage n'est pas terminé.
              Un rapport va s'afficher: poste son contenu.
              Si le fichier ne s'ouvre pas, tu le trouves ici, à la racine de ton Système, en principe : C:\ComboFix.txt (C:\ComboFix)

              poste aussi un rapport hijack this et dis moi comment se comporte ton PC
              0
              1. Contributeur sécurité
                rapport en examen
                une petite question ce programme c'est toi qui l'a installé?
                AXPFixer
                si oui, je te conseille de le supprimer par ajout suppression de programmes
                si non tu le supprimes, si tu n'y arrives pas (c'est possible) tu me le dis!
                0
                1. ahaha j'ai réussi!!!
                  et maintenant je fais quoi papyber??
                  0
              2. tu m'as abandonnée papyber? t'en peux plus de moi?!!!! reviens s'il te plaît:-)
                0
                1. Contributeur sécurité
                  il n'y a pas à le renommer!
                  supprime tout et recommence
                  t'inquiète pas tu vas y arriver
                  lis le tuto que je t'ai fourni et suis bien les consignes
                  Tutoriel officiel de ComboFix, afin de l’utiliser correctement
                  https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                  prends ton temps, on n'est pas aux pièces...
                  0
                  1. voilà! mais ça me marque encore et toujours "advance xp fixer scan report 117 threats located"
                    Comment tu fais pour garder ton calme??? arhhhhhh

                    ComboFix 08-05-25.5 - portablenec 2008-05-26 17:25:29.1 - NTFSx86
                    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.1485 [GMT 2:00]
                    Endroit: C:\Documents and Settings\portablenec\Bureau\ComboFix.exe
                    * Création d'un nouveau point de restauration
                    .

                    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    C:\Autorun.inf
                    C:\Documents and Settings\portablenec\ResErrors.log
                    C:\WINDOWS\48201.exe
                    C:\WINDOWS\backinf.tab
                    C:\WINDOWS\g32.txt
                    C:\WINDOWS\s32.txt
                    C:\WINDOWS\system32\Dll.dll
                    C:\WINDOWS\system32\filekan.exe
                    C:\WINDOWS\system32\icqmlib.exe
                    C:\WINDOWS\system32\iepref32.dll
                    C:\WINDOWS\system32\ierplc.dll
                    C:\WINDOWS\system32\ips.dll
                    C:\WINDOWS\system32\KernelDrv.exe
                    C:\WINDOWS\system32\ksvcl.dll
                    C:\WINDOWS\system32\lanmandrv.sys
                    C:\WINDOWS\system32\lanmanwrk.exe
                    C:\WINDOWS\system32\laprxy.dllexe
                    C:\WINDOWS\system32\mdm.exe
                    C:\WINDOWS\system32\nvrsma.dll
                    C:\WINDOWS\system32\ocxapi.dll
                    C:\WINDOWS\system32\ocxloader.exe
                    C:\WINDOWS\system32\qmopt.dll
                    C:\WINDOWS\ufdata2000.log
                    C:\WINDOWS\ws386.ini

                    .
                    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
                    .

                    -------\Legacy_ASPIMGR
                    -------\Legacy_DHLP
                    -------\Legacy_LANMANDRV
                    -------\Legacy_SYSREST.SYS
                    -------\Service_aspimgr
                    -------\Service_lanmandrv
                    -------\Service_sysrest.sys

                    ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-04-26 to 2008-05-26 ))))))))))))))))))))))))))))))))))))
                    .

                    2008-05-26 16:05 . 2008-05-26 16:05 <REP> d-------- C:\Program Files\Avira
                    2008-05-26 16:05 . 2008-05-26 16:05 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
                    2008-05-26 13:03 . 2008-05-26 13:03 <REP> d-------- C:\WINDOWS\ERUNT
                    2008-05-26 12:43 . 2008-05-26 15:23 <REP> d-------- C:\SDFix
                    2008-05-26 12:35 . 2008-05-26 12:41 4,988 --a------ C:\WINDOWS\system32\tmp.reg
                    2008-05-26 12:34 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
                    2008-05-26 12:34 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
                    2008-05-26 12:34 . 2008-05-15 23:22 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
                    2008-05-26 12:34 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
                    2008-05-26 12:34 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\404Fix.exe
                    2008-05-26 12:34 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
                    2008-05-26 12:34 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
                    2008-05-26 12:34 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
                    2008-05-26 10:36 . 2008-05-26 13:30 96,256 --a------ C:\WINDOWS\index.exe
                    2008-05-26 10:22 . 2008-05-26 10:22 4,608 --ahs---- C:\WINDOWS\system32\Thumbs.db
                    2008-05-25 20:36 . 2008-05-25 20:36 96,256 --a------ C:\WINDOWS\7ujkn.exe
                    2008-05-25 20:34 . 2008-05-26 17:06 27,325 --a------ C:\WINDOWS\system32\kcopt.dll
                    2008-05-25 20:30 . 2008-05-25 20:30 <REP> d-------- C:\Program Files\AXPFixer
                    2008-05-25 20:30 . 2008-05-25 20:30 <REP> d-------- C:\Documents and Settings\portablenec\Application Data\AXPFixer
                    2008-05-25 20:30 . 2008-05-26 11:39 269,334 --a------ C:\WINDOWS\system32\ctfmonb.bmp
                    2008-05-25 20:30 . 2008-05-25 20:30 66,048 --a------ C:\WINDOWS\system32\ntpl.bin
                    2008-05-25 20:30 . 2008-05-26 13:09 63,488 --a------ C:\WINDOWS\system32\ho.ln
                    2008-05-25 20:30 . 2008-05-26 13:09 28,672 --a------ C:\WINDOWS\system32\ko.o
                    2008-05-24 16:38 . 2008-05-25 20:30 54,156 --ah----- C:\WINDOWS\QTFont.qfn
                    2008-05-24 16:38 . 2008-05-24 16:38 1,409 --a------ C:\WINDOWS\QTFont.for
                    2008-05-16 23:12 . 2008-05-16 23:12 <REP> d-------- C:\Poker

                    .
                    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    2008-05-25 18:30 578,560 ----a-w C:\WINDOWS\system32\user32.DLL
                    2008-05-25 18:30 578,560 ----a-w C:\WINDOWS\system32\dllcache\user32.dll
                    2008-04-08 18:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\ScanSoft
                    2008-03-31 15:44 --------- d-----w C:\Program Files\Orange
                    2008-03-31 15:43 --------- d-----w C:\Program Files\Fichiers communs\France Telecom
                    2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll
                    2008-03-25 04:51 621,344 ------w C:\WINDOWS\system32\dllcache\mswstr10.dll
                    2008-03-25 04:51 194,144 ----a-w C:\WINDOWS\system32\msjint40.dll
                    2008-03-25 04:51 194,144 ------w C:\WINDOWS\system32\dllcache\msjint40.dll
                    2008-03-20 08:09 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys
                    2008-03-20 08:09 1,845,376 ------w C:\WINDOWS\system32\dllcache\win32k.sys
                    2008-01-19 22:32 191,512 ----a-w C:\Documents and Settings\portablenec\Application Data\install_fr[1].exe
                    2008-01-19 22:26 260,632 ----a-w C:\Documents and Settings\portablenec\Application Data\setup_fr[1].exe
                    1999-04-06 12:27 99,840 ----a-w C:\Program Files\Fichiers communs\IRAABOUT.DLL
                    1998-12-09 02:53 70,144 ----a-w C:\Program Files\Fichiers communs\IRAMDMTR.DLL
                    1998-12-09 02:53 48,640 ----a-w C:\Program Files\Fichiers communs\IRALPTTR.DLL
                    1998-12-09 02:53 31,744 ----a-w C:\Program Files\Fichiers communs\IRAWEBTR.DLL
                    1998-12-09 02:53 186,368 ----a-w C:\Program Files\Fichiers communs\IRAREG.DLL
                    1998-12-09 02:53 17,920 ----a-w C:\Program Files\Fichiers communs\IRASRIAL.DLL
                    .
                    [color=blue]Infected C:\WINDOWS\system32\user32.dll hex repaired/color

                    ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                    .
                    .
                    REGEDIT4
                    *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "WOOKIT"="C:\PROGRA~1\Wanadoo\Shell.exe" [ ]
                    "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.exe" [2007-10-18 12:34 5724184]
                    "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]
                    "OM2_Monitor"="C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe" [2007-02-08 21:43 95800]
                    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-21 20:08 68856]

                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-05 14:00 208952]
                    "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
                    "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-05 14:00 455168]
                    "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-28 15:13 766041]
                    "RTHDCPL"="RTHDCPL.EXE" [2006-03-14 10:01 16010752 C:\WINDOWS\RTHDCPL.exe]
                    "igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2006-03-23 04:17 94208]
                    "igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2006-03-23 04:13 77824]
                    "igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2006-03-23 04:17 118784]
                    "AGRSMMSG"="AGRSMMSG.exe" [2005-12-13 06:50 88204 C:\WINDOWS\AGRSMMSG.exe]
                    "SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe" [2005-06-03 03:52 36975]
                    "PCMService"="c:\Apps\Powercinema\PCMService.exe" [2005-05-11 13:48 127118]
                    "OpwareSE2"="C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 12:00 49152]
                    "VX1000"="C:\WINDOWS\vVX1000.exe" [2007-04-10 23:46 709992]
                    "LifeCam"="C:\Program Files\Microsoft LifeCam\LifeExp.exe" [2007-05-17 23:45 279912]
                    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 16:57 282624]
                    "TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2008-01-20 00:33 185896]
                    "SystrayORAHSS"="C:\Program Files\Orange\Systray\SystrayApp.exe" [2007-09-25 20:08 94208]
                    "ORAHSSSessionManager"="C:\Program Files\Orange\SessionManager\SessionManager.exe" [2007-09-25 19:10 102400]
                    "AXPFixer"="C:\Program Files\AXPFixer\AXPFixer.exe" [2008-05-19 20:03 1564672]
                    "sysrest32.exe"="C:\WINDOWS\system32\sysrest32.exe" [ ]
                    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-02-12 10:06 262401]

                    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                    "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

                    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                    "%windir%\\system32\\sessmgr.exe"=
                    "C:\\APPS\\Powercinema\\PowerCinema.exe"=
                    "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                    "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                    "C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
                    "C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
                    "C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
                    "C:\\Program Files\\NetMeeting\\conf.exe"=
                    "C:\\Program Files\\Messenger\\msmsgs.exe"=
                    "C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"=

                    R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2007-05-17 23:45]
                    S3 usbscan;Pilote de scanneur USB;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 22:58]
                    S3 USBSTOR;Pilote de stockage de masse USB;C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 23:08]
                    S3 VX1000;VX-1000;C:\WINDOWS\system32\DRIVERS\VX1000.sys [2007-04-10 23:46]

                    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0f38d748-acc7-11dc-8194-000df0390f54}]
                    \Shell\AutoRun\command - E:\setupSNK.exe

                    .
                    Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'
                    "2007-12-14 19:06:44 C:\WINDOWS\Tasks\Microsoft_Hardware_Launch_setup_exe.job"
                    - D:\setup.exe
                    .
                    **************************************************************************

                    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                    Rootkit scan 2008-05-26 17:28:50
                    Windows 5.1.2600 Service Pack 2 NTFS

                    Balayage processus cach‚s ...

                    Balayage cach‚ autostart entries ...

                    Balayage des fichiers cach‚s ...

                    Scan termin‚ avec succŠs
                    Les fichiers cach‚s: 0

                    **************************************************************************
                    .
                    ------------------------ Other Running Processes ------------------------
                    .
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                    C:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                    C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\[u]0/u\FTRTSVC.exe
                    C:\APPS\HIDSERVICE\HidService.exe
                    C:\APPS\Powercinema\Kernel\TV\CLSched.exe
                    C:\Program Files\Orange\Launcher\Launcher.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\[u]0/u\AlertModule.exe
                    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                    C:\Program Files\RALINK\Common\RaUI.exe
                    C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
                    C:\WINDOWS\system32\wscntfy.exe
                    C:\Program Files\Orange\Connectivity\ConnectivityManager.exe
                    C:\Program Files\Orange\Connectivity\corecom\CoreCom.exe
                    C:\Program Files\Orange\Connectivity\corecom\OraConfigRecover.exe
                    C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\[u]0/u\FTCOMModule.exe
                    .
                    **************************************************************************
                    .
                    Temps d'accomplissement: 2008-05-26 17:31:25 - machine was rebooted
                    ComboFix-quarantined-files.txt 2008-05-26 15:31:22

                    Pre-Run: 102,069,407,744 octets libres
                    Post-Run: 102,468,235,264 octets libres

                    188 --- E O F --- 2008-05-14 20:20:19
                    0
                2. Contributeur sécurité
                  Télécharge ComboFix.exe (par sUBs) sur ton Bureau
                  http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                  Tutoriel officiel de ComboFix, afin de l’utiliser correctement
                  https://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
                  Désactive ton antivirus, antispyware, et Spybot-S&D (résident) durant l'utilisation de ComboFix. Merci. Tu le réactiveras ensuite, en fin de désinfection.
                  Voir ici comment désactiver tes protections
                  https://forum.pcastuces.com/default.asp
                  Double clique sur ComboFix.exe (ComboFix)
                  Tape 1 puis tape sur Entrée
                  A noter: une fois que ComboFix est lancé, il ne faut pas cliquer dans la fenêtre de ComboFix car cela pourrait entraîner un plantage du programme.
                  Il est recommandé de laisser l'outil analyser et nettoyer le PC sans utiliser quoi que ce soit d'autre...

                  A la fin de l’analyse, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse
                  Si le rapport n'apparaît pas, tu le trouves ici, à la racine de ton Système, en principe : C:\ComboFix.txt (C:\ComboFix)

                  0
                  1. encore un efois désolée mais ça me dit "you cannot rename combofix as combofix [1] please use another name preferbaly made up of alphanumeric characters"
                    0
                3. oh p...... ça me bourre, j'suis une vraie quiche!
                  Dès que j'allume mon PC ça me dit "advance XP Fixer scan report 113 threats located"; en plus d'être une pipe en infor je ne comprends pas l'anglais....
                  Désolée papyber!

                  Logfile of HijackThis v1.99.1
                  Scan saved at 16:39:58, on 26/05/2008
                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                  MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                  Running processes:
                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\savedump.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\WINDOWS\Explorer.EXE
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  C:\WINDOWS\RTHDCPL.EXE
                  C:\WINDOWS\system32\igfxtray.exe
                  C:\WINDOWS\system32\hkcmd.exe
                  C:\WINDOWS\system32\igfxpers.exe
                  C:\WINDOWS\AGRSMMSG.exe
                  C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
                  C:\Apps\Powercinema\PCMService.exe
                  C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
                  C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE
                  C:\WINDOWS\vVX1000.exe
                  C:\Program Files\QuickTime\qttask.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\Program Files\Orange\Systray\SystrayApp.exe
                  C:\Program Files\AXPFixer\AXPFixer.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                  C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                  C:\Program Files\Messenger\msmsgs.exe
                  C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                  C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                  C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                  C:\Program Files\Orange\Launcher\Launcher.exe
                  C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                  C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                  c:\APPS\HIDSERVICE\HIDSERVICE.exe
                  C:\Program Files\RALINK\Common\RaUI.exe
                  C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
                  C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Orange\Deskboard\deskboard.exe
                  C:\Program Files\Orange\connectivity\connectivitymanager.exe
                  C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
                  c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                  C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
                  C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\Program Files\Internet Explorer\iexplore.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\WINDOWS\system32\wuauclt.exe
                  C:\DOCUME~1\PORTAB~1\LOCALS~1\Temp\Répertoire temporaire 3 pour hijackthis[1].zip\HijackThis.exe

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                  R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
                  O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                  O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                  O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                  O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                  O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                  O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                  O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                  O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                  O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                  O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                  O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                  O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                  O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                  O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
                  O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                  O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
                  O4 - HKLM\..\Run: [EPSON Stylus DX6000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE /FU "C:\WINDOWS\TEMP\E_S91.tmp" /EF "HKLM"
                  O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
                  O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                  O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                  O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                  O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
                  O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
                  O4 - HKLM\..\Run: [AXPFixer] C:\Program Files\AXPFixer\AXPFixer.exe
                  O4 - HKLM\..\Run: [lanmanwrk.exe clean] C:\WINDOWS\System32\lanmanwrk.exe clean
                  O4 - HKLM\..\Run: [KernelDrv.exe clean] C:\WINDOWS\System32\KernelDrv.exe clean
                  O4 - HKLM\..\Run: [sysrest32.exe] C:\WINDOWS\system32\sysrest32.exe
                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                  O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                  O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                  O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                  O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                  O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                  O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
                  O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                  O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                  O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                  O15 - Trusted Zone: https://www.orange.fr/portail
                  O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                  O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                  O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
                  O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                  O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                  O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                  O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe (file missing)
                  O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                  O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                  O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                  O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                  0
                  1. Contributeur sécurité
                    delete
                    0
                    1. Heureusement que ce n'est pas une recette de cuisine. La mayonaise aurait tourné.

                      Blaque à part. Bravo !
                      0
                  2. Contributeur sécurité
                    ton antivirus c'est quoi? je n'en vois pas....
                    si tu n'en as pas, de toute urgence télécharge Antivir
                    https://www.pcastuces.com/logitheque/antivir.htm

                    installe Antivir et Scanne le PC en mode sans échec
                    Comment aller en Mode sans échec:
                    1) Redémarre ton ordi
                    2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
                    3) Tu verras un écran avec options de démarrage apparaître
                    4) Choisis la première option : Sans Échec, et valide avec "Entrée"
                    5) Choisis ton compte habituel, et non Administrateur
                    scanne ton PC en mode sans échec avec antivir
                    redémarre normalement et poste le rapport obtenu

                    0
                    1. oulala! j'ai télécharger antivir mais là ça me dit "avirus or unwanted program was found! what should happen with the file?
                      move to quarantine
                      delete
                      rename
                      deny access
                      ignore

                      je coche quoi??????
                      0
                  3. Contributeur sécurité
                    tu refais exactement comme pour le premier rapport hijack this, lu jlances hijack this tu cliques sur "do a system scan and save a logfile" et tu postes ce que tu as dans le bloc notes en faisant un copier coller
                    0
                    1. Logfile of HijackThis v1.99.1
                      Scan saved at 15:41:02, on 26/05/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\aspimgr.exe
                      c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                      C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                      C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
                      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                      c:\APPS\HIDSERVICE\HIDSERVICE.exe
                      C:\Program Files\Microsoft LifeCam\MSCamS32.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      C:\WINDOWS\RTHDCPL.EXE
                      C:\WINDOWS\system32\igfxtray.exe
                      C:\WINDOWS\system32\hkcmd.exe
                      C:\WINDOWS\system32\igfxpers.exe
                      C:\WINDOWS\AGRSMMSG.exe
                      C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
                      C:\Apps\Powercinema\PCMService.exe
                      C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
                      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE
                      C:\WINDOWS\vVX1000.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\Program Files\Orange\Systray\SystrayApp.exe
                      C:\Program Files\AXPFixer\AXPFixer.exe
                      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe
                      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\Program Files\RALINK\Common\RaUI.exe
                      C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
                      C:\Program Files\Orange\Launcher\Launcher.exe
                      C:\WINDOWS\svchost.exe
                      c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                      C:\Program Files\Orange\Deskboard\deskboard.exe
                      C:\Program Files\Orange\connectivity\connectivitymanager.exe
                      C:\WINDOWS\system32\wscntfy.exe
                      C:\Program Files\Orange\connectivity\CoreCom\CoreCom.exe
                      C:\Program Files\Orange\connectivity\CoreCom\OraConfigRecover.exe
                      C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\Internet Explorer\iexplore.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\DOCUME~1\PORTAB~1\LOCALS~1\Temp\Répertoire temporaire 2 pour hijackthis[1].zip\HijackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                      O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
                      O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
                      O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
                      O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
                      O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
                      O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
                      O4 - HKLM\..\Run: [EPSON Stylus DX6000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE /FU "C:\WINDOWS\TEMP\E_S91.tmp" /EF "HKLM"
                      O4 - HKLM\..\Run: [VX1000] C:\WINDOWS\vVX1000.exe
                      O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
                      O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
                      O4 - HKLM\..\Run: [ASocksrv] SocksA.exe
                      O4 - HKLM\..\Run: [AXPFixer] C:\Program Files\AXPFixer\AXPFixer.exe
                      O4 - HKLM\..\Run: [lanmanwrk.exe clean] C:\WINDOWS\System32\lanmanwrk.exe clean
                      O4 - HKLM\..\Run: [KernelDrv.exe clean] C:\WINDOWS\System32\KernelDrv.exe clean
                      O4 - HKLM\..\Run: [sysrest32.exe] C:\WINDOWS\system32\sysrest32.exe
                      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [OM2_Monitor] "C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe"
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                      O4 - Global Startup: Ralink Wireless Utility.lnk = C:\Program Files\RALINK\Common\RaUI.exe
                      O4 - Global Startup: Symantec Fax Starter Edition Port.lnk = C:\Program Files\Microsoft Office\Office\1036\OLFSNT40.EXE
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                      O9 - Extra button: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                      O9 - Extra 'Tools' menuitem: Titan Poker - {49783ED4-258D-4f9f-BE11-137C18D3E543} - C:\Poker\Titan Poker\casino.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O15 - Trusted Zone: https://www.orange.fr/portail
                      O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                      O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
                      O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
                      O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
                      O23 - Service: Microsoft ASPI Manager (aspimgr) - Unknown owner - C:\WINDOWS\system32\aspimgr.exe
                      O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
                      O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
                      O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                      O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      0
                  4. Contributeur sécurité
                    je t'ai fait attendre,mais je suis au taf....

                    peux tu me poster un nouveau rapport hijack this ?
                    0
                    1. Désolée de faire le super boulet mais je fais comment pour te poster un nouveau rapport?......
                      0
                  5. au fait: comment j'ai fait pour choper ce truc?
                    0
                    1. ça y est Papyber, j'ai suivi toutes tes instructions.... est-ce que c'est bon? parce que j'en sais rien, si c'est réglé!!!!!
                      Merci beaucoup en tout cas.
                      Caro
                      0
                      1. Rebooting

                        Service sysrest.sys - Deleted

                        [b]Checking Files [/b]:

                        Trojan Files Found:

                        C:\WINDOWS\system32\lanmandrv.sys - Deleted
                        C:\WINDOWS\system32\sysrest.sys - Deleted

                        Folder C:\Documents and Settings\All Users\Application Data\SalesMon - Removed

                        Removing Temp Files

                        [b]ADS Check [/b]:

                        [b]Final Check [/b]:

                        catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                        Rootkit scan 2008-05-26 13:07:42
                        Windows 5.1.2600 Service Pack 2 NTFS

                        scanning hidden processes ...

                        scanning hidden services & system hive ...

                        scanning hidden registry entries ...

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
                        "OfflineDetectionPending"=dword:00000001

                        scanning hidden files ...

                        scan completed successfully
                        hidden processes: 0
                        hidden services: 0
                        hidden files: 0

                        [b]Remaining Services [/b]:

                        Authorized Application Key Export:

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "C:\\APPS\\Powercinema\\PowerCinema.exe"="C:\\APPS\\Powercinema\\PowerCinema.exe:*:Enabled:PowerCinema"
                        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                        "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
                        "C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"="C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe:*:Enabled:LifeCam.exe"
                        "C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"="C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe:*:Enabled:LifeExp.exe"
                        "C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"="C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe:*:Enabled:Assistance … distance - Windows Messenger et voix"
                        "C:\\Program Files\\NetMeeting\\conf.exe"="C:\\Program Files\\NetMeeting\\conf.exe:*:Enabled:Windows© NetMeeting©"
                        "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
                        "C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe"="C:\\Program Files\\Orange\\Connectivity\\ConnectivityManager.exe:*:enabled:CSS"
                        "C:\\Documents and Settings\\portablenec\\Local Settings\\Temp\\.tt14.tmp"="C:\\Documents and Settings\\portablenec\\Local Settings\\Temp\\.tt14.tmp:*:Enabled:enable"
                        "C:\\WINDOWS\\system32\\sysrest32.exe"="C:\\WINDOWS\\system32\\sysrest32.exe:*:Enabled:enable"

                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                        "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                        "C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe"="C:\\Program Files\\McAfee\\Managed VirusScan\\Agent\\myAgtSvc.exe:*:Enabled:McAfee Managed Services Agent"
                        "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                        "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                        [b]Remaining Files [/b]:

                        File Backups: - C:\SDFix\backups\backups.zip

                        [b]Files with Hidden Attributes [/b]:

                        Tue 19 Jun 2007 211 A.SHR --- "C:\BOOT.BAK"
                        Sun 3 Dec 2006 45,056 ..SH. --- "C:\tel.xls.exe"
                        Sun 3 Dec 2006 45,056 ..SH. --- "C:\WINDOWS\svchost.exe"
                        Sun 11 May 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\24af2a69c06a4de03e35dc89d706475f\BIT9.tmp"
                        Fri 24 Sep 2004 29,184 A..H. --- "C:\Documents and Settings\portablenec\Mes documents\dolores\comptabilit‚\cloture compte\~WRL0001.tmp"

                        [b]Finished![/b]
                        0
                        1. SmitFraudFix v2.322

                          Rapport fait à 12:38:23,54, 26/05/2008
                          Executé à partir de C:\Documents and Settings\portablenec\Bureau\SmitfraudFix
                          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                          Le type du système de fichiers est NTFS
                          Fix executé en mode normal

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          127.0.0.1 localhost

                          »»»»»»»»»»»»»»»»»»»»»»»» VACFix

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                          S!Ri's WS2Fix: LSP not Found.

                          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                          GenericRenosFix by S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                          C:\WINDOWS\svchost.exe supprimé
                          C:\WINDOWS\system32\ctfmona.exe supprimé

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                          404Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Miniport d'ordonnancement de paquets
                          DNS Server Search Order: 192.168.1.1

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{503196CF-3F1A-4B31-AF3D-12464FB82787}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{503196CF-3F1A-4B31-AF3D-12464FB82787}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{503196CF-3F1A-4B31-AF3D-12464FB82787}: DhcpNameServer=192.168.1.1

                          »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "System"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                          Nettoyage terminé.

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» Fin
                          0
                          • 1
                          • 2