Urgent plus d' internet

Bonjour, merci a vous pour votre aide
virus qui a infecte mon Pc tout est bloque et je ne peux pas me connecter a internet
je suis novice et pour une aide SVP du pas a pas merci je travaille avec windows xp
je transmet le rapport HIJACKTHIS
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:58: VIRUS ALERT!, on 25/07/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
C:\Program Files\Trust\3010A WIRELESS DESKSET\Keyboard\kbdap32a.EXE
C:\Program Files\Trust\3010A WIRELESS DESKSET\Mouse\mouse32a.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\SPAMfighter\SFAgent.exe
C:\WINDOWS\system32\lphcjadj0en0l.exe
C:\Program Files\rhcnadj0en0l\rhcnadj0en0l.exe
C:\Program Files\AntiSpywareExpert\ase_fr.exe
C:\Program Files\PCPrivacyCleaner\pcpc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Antivirus 2009\av2009.exe
C:\Program Files\Zapu\Zapu\wDivi.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\WINDOWS\system32\LVComS.exe
C:\WINDOWS\system32\pphcjadj0en0l.exe
C:\WINDOWS\explorer.exe
H:\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
R3 - URLSearchHook: (no name) - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - (no file)
O1 - Hosts: 212.150.54.250 dv-networks.com
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
O3 - Toolbar: (no name) - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - (no file)
O3 - Toolbar: qndsfmao - {3FCAEB7D-F8AE-4A67-AE6C-57EE1416BB6D} - C:\WINDOWS\qndsfmao.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Trust\3010A WIRELESS DESKSET\Keyboard\kbdap32a.EXE
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\3010A WIRELESS DESKSET\Mouse\mouse32a.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [lphcjadj0en0l] C:\WINDOWS\system32\lphcjadj0en0l.exe
O4 - HKLM\..\Run: [SMrhcnadj0en0l] C:\Program Files\rhcnadj0en0l\rhcnadj0en0l.exe
O4 - HKLM\..\Run: [AntiSpywareExpert] C:\Program Files\AntiSpywareExpert\ase_fr.exe
O4 - HKLM\..\Run: [DNSE] "C:\Program Files\Fichiers communs\SystemDoctor\DNSE.exe" -c
O4 - HKLM\..\Run: [MDRV_Check] "C:\Program Files\Fichiers communs\SystemDoctor\usdrmdr.exe"
O4 - HKLM\..\Run: [DC6V_Check] "C:\Program Files\Fichiers communs\SystemDoctor\usdrdc.exe"
O4 - HKLM\..\Run: [PCPrivacyCleaner] C:\Program Files\PCPrivacyCleaner\pcpc.exe
O4 - HKLM\..\Run: [289b1a07] rundll32.exe "C:\WINDOWS\system32\suogtggi.dll",b
O4 - HKLM\..\Run: [BM2ba8299b] Rundll32.exe "C:\WINDOWS\system32\vgadmesq.dll",s
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [43715048443554727929868964026577] C:\Program Files\Antivirus 2009\av2009.exe
O4 - HKCU\..\Run: [ieupdate] "C:\WINDOWS\system32\ieupdates.exe"
O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
O4 - Startup: Zapu Acceleration Engine.lnk = C:\Program Files\Zapu\Zapu\wincm.exe
O4 - Startup: Zapu.lnk = C:\Program Files\Zapu\Zapu\wDivi.exe
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.87 85.255.112.234
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.87 85.255.112.234
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.87 85.255.112.234
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O24 - Desktop Component 0: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

--
End of file - 7587 bytes
Configuration: Windows XP
Internet Explorer 7.0

34 réponses

Résumé de la discussion

Un PC sous Windows XP est infecté par un malware qui bloque l’accès à Internet et rend le système instable, comme le montre le rapport HijackThis. Plusieurs éléments observés montrent une configuration infestée avec des composants au démarrage et des services malveillants, nécessitant une désinfection manuelle guidée et l’installation d’un antivirus. La meilleure approche proposée combine le mode sans échec, la désinstallation des programmes indésirables, la suppression de fichiers et l’exécution d’un antivirus fiable comme Avira AntiVir Personal. D’autres étapes recommandées incluent la vérification des entrées de démarrage, la correction des paramètres réseau, puis un balayage systématique pour éviter les réinfections et retrouver l’accès aux outils de sécurité.

Bobot (l’IA à votre service)
  1. Contributeur
    Si ça ne marche pas avec smitfraudfix

    je vais te guider et t'aider à désinfecter ton PC manuellement ensuite nous aurons plus de chance pour retrouver
    l'utilisation d'outils.
    Tu n'as pas d'Anti-virus ni de pare-feu il t'en faut absolument pour bien te protéger.
    Tu devras aussi faire les mises à jours de ton système d'exploitation, mais pour ça, nous verrons à la fin de ta désinfection.
    Je vais te donner des étapes à suivre pour remédier à tout ça, si tu as des questions surtout n'hésite pas à les poser.

    Tu vas commencer par l'Antivirus
    Télécharge sur ton Bureau ==> https://www.malekal.com/avira-free-security-antivirus-gratuit/" Avira AntiVir Persona<== ANTI-VIRUS
    Suis le lien pour l'installation. <== Il est important de bien le paramétrer, il fera ses mises à jour automatiquement, il travaillera seul si il est bien paramétré.
    Ne fait pas de scan pour le moment , nous le ferons plus tard en mode sans échec.

    Si tu as un doute ou des questions demande des explications avant de commencer la désinfection.

    Relance le Pc et tapote la touche F8 ( ou F5 pour certains) , jusqu’à l’apparition des inscriptions avec choix de démarrage
    Avec les touches « flèches », sélectionne Mode sans échec ==> entrée ==>nom utilisateur habituel



    Dans ce mode nous allons désinstaller des applications infectieuses, nous devrons aussi supprimer des services, supprimer des fichiers, suit les étapes une par une.

    Première étape : Une fois en mode sans échec tu retrouveras Avira AntiVir Personal via le menu démarrer > Tous les programmes > "Antivir PersonnalEdition Classic" > Clique sur "Start Avira Antivir Personnal" > Une fenêtre s'ouvre. Clique sur "Scan system now".
    Tu retrouveras le rapport en cliquant sur Reports qui se trouve à gauche de la page principal de Avira AntiVir Personal, ensuite clique sur la ligne Scan à droite, une nouvelle fenêtre s'ouvre et clique sur Report file copie/colle le résultat à la fin des étapes.
    (Si tu ne peux pas faire cette étapes tu le feras en dernier )

    Deuxième étape : Ensuite fait: Windows+e > Outils > Options des dossiers > Affichage > bouton radio "Afficher les fichiers et dossiers cachés"> décoche "Masquer les extensions de fichiers connus" > décoche "Masquer les fichiers protégés du Système" > Clique sur Appliquer à tous les dossiers > Appliquer et ok

    Recherche dans Ajout et suppression de programmes, via le Panneau de configuration.

    PCPrivacyCleaner
    Antivirus 2009
    Zapu
    SystemDoctor


    fait de même dans C:\Program Files en suivant ce chemin: Démarrer > Poste de travail > Disque C: > Program Files
    Tu les recherche et supprime.

    Troisième étapes : Relance hijack et clique sur "Do a system scan only"
    Ensuite recherche ces lignes et coches les cases

    O3 - Toolbar: qndsfmao - {3FCAEB7D-F8AE-4A67-AE6C-57EE1416BB6D} - C:\WINDOWS\qndsfmao.dll
    O4 - HKLM\..\Run: [DNSE] "C:\Program Files\Fichiers communs\SystemDoctor\DNSE.exe" -c
    O4 - HKLM\..\Run: [MDRV_Check] "C:\Program Files\Fichiers communs\SystemDoctor\usdrmdr.exe"
    O4 - HKLM\..\Run: [DC6V_Check] "C:\Program Files\Fichiers communs\SystemDoctor\usdrdc.exe"
    O4 - HKLM\..\Run: [PCPrivacyCleaner] C:\Program Files\PCPrivacyCleaner\pcpc.exe
    O4 - HKLM\..\Run: [289b1a07] rundll32.exe "C:\WINDOWS\system32\suogtggi.dll",b
    O4 - HKLM\..\Run: [BM2ba8299b] Rundll32.exe "C:\WINDOWS\system32\vgadmesq.dll",s
    O4 - HKCU\..\Run: [43715048443554727929868964026577] C:\Program Files\Antivirus 2009\av2009.exe
    O4 - HKCU\..\Run: [ieupdate] "C:\WINDOWS\system32\ieupdates.exe"
    O4 - Startup: Zapu Acceleration Engine.lnk = C:\Program Files\Zapu\Zapu\wincm.exe
    O4 - Startup: Zapu.lnk = C:\Program Files\Zapu\Zapu\wDivi.exe

    Une fois coché, ferme toutes les fenêtres et applications et clique sur "Fix checked"
    Nous devrons refaire cette manip avec d'autres lignes un peu plus tard ;)


    Quatrième étapes
    Recherche et supprime ces fichiers en gras.

    C:\WINDOWS\qndsfmao.dll
    C:\Program Files\Fichiers communs\SystemDoctor
    C:\WINDOWS\system32\suogtggi.dll",b
    C:\WINDOWS\system32\vgadmesq.dll",s
    C:\WINDOWS\system32\ieupdates.exe"


    Cinquièmes étapes
    Redémarre ton PC en mode Normal

    Télécharge FixWareout de l'un de ces deux liens :
    http://downloads.subratam.org/Fixwareout.exe
    http://download.bleepingcomputer.com/lonny/Fixwareout.exe

    Sauvegarde-le sur ton Bureau, puis lance-le.
    Clique Next, puis Install, et assure-toi que "Run fixit" soit coché, puis clique Finish.
    Suis les directives à l'écran.
    L'outil va te demander de redémarrer ton PC; fais-le s'il te plaît.
    Le redémarrage risque de prendre un peu plus de temps; ceci est normal.

    Lorsque redémarré, un fichier texte apparaîtra (report.txt); copie/colle ce rapport dans ta prochaine réponse, avec

    Sixième étapes
    Télécharge sur ton bureau RHosts (Merci à S!ri) disponible ici,
    http://siri.urz.free.fr/Softs/RHosts.exe
    Double-clique sur Rhosts.exe et clique sur "restaurer".

    ensuite pour finir refais un nouveau rapport HijackThis stp

    @+

    2
    1. Modérateur
      As-tu essayé avec MalwareByte's Anti-Malware ?
      0
      1. je place ma cle poste de travail je vais sur ma cle je clic sur la cle et rien le sablier reste quelques secondes et rien
        0
        1. Modérateur
          Sois plus précis.
          0
          1. La cite

            execute combofix depuis la clé usb pour voir stp
            0
            1. Modérateur
              Essaie avec MalwareByte's Anti-Malware :
              http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htm
              0
              1. je telecharge sur un portable je transfert par usb sur mon pc je l'instale sur le bureau et la il ne le retrouve pas je dois avoir un anti virus mis par windows xp qui bloc
                0
                1. merci , je place combo sur mon pc mais je ne peux l'ouvrir
                  0
                  1. Modérateur
                    Pour avoir le net, fais ceci sur le PC infecté :

                    ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
                    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                    /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

                    ---> Double-clique sur Combofix.exe
                    Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
                    Accepte en cliquant sur "Oui"

                    ---> Mets-le en langue française F
                    Tape sur la touche 1 (Yes) pour démarrer le scan.

                    /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

                    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                    /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                    Note : Le rapport se trouve également là : C:\ComboFix.txt
                    0
                    1. une jounee passée sur ce foutu ordi il est vrais que je ne metrise pas
                      je refais un rapport car je n'ai toujours pas le net

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 18:14: VIRUS ALERT!, on 26/07/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\Program Files\Ahead\InCD\InCDsrv.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\system32\RUNDLL32.EXE
                      C:\Program Files\Ahead\InCD\InCD.exe
                      C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
                      C:\Program Files\Trust\3010A WIRELESS DESKSET\Keyboard\kbdap32a.EXE
                      C:\Program Files\Trust\3010A WIRELESS DESKSET\Mouse\mouse32a.exe
                      C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                      C:\WINDOWS\system32\WgaTray.exe
                      C:\Program Files\Logitech\Video\LogiTray.exe
                      C:\Program Files\SPAMfighter\SFAgent.exe
                      C:\WINDOWS\system32\lphcjadj0en0l.exe
                      C:\WINDOWS\system32\rundll32.exe
                      C:\Program Files\MSN Messenger\MsnMsgr.Exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\WINDOWS\system32\LVComS.exe
                      C:\WINDOWS\system32\pphcjadj0en0l.exe
                      C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
                      C:\WINDOWS\explorer.exe
                      G:\HiJackThis.exe
                      G:\HiJackThis.exe
                      G:\HiJackThis.exe

                      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
                      R3 - URLSearchHook: (no name) - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - (no file)
                      O1 - Hosts: 212.150.54.250 dv-networks.com
                      O2 - BHO: {9ceee6d9-f2af-549a-bef4-c496b7b96025} - {52069b7b-694c-4feb-a945-fa2f9d6eeec9} - C:\WINDOWS\system32\qtkozy.dll
                      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
                      O2 - BHO: (no name) - {769D8280-A207-4EEA-9963-F8B156C32855} - C:\WINDOWS\system32\wvUoOHaW.dll
                      O2 - BHO: QXK Olive - {790BB05E-4C7C-4603-B129-0E0464C389CA} - C:\WINDOWS\nfavxwdbeam.dll
                      O2 - BHO: QXK Olive - {812AE34E-162C-4C94-BAA1-A2C0431AEC84} - C:\WINDOWS\kgxmotapktx.dll
                      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: (no name) - {9A32CC4E-7F52-4101-BA6D-0F20C508F52C} - C:\WINDOWS\system32\geBtTMcY.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
                      O3 - Toolbar: (no name) - {4596013b-6c31-408b-a266-deae5c086dc2} - (no file)
                      O3 - Toolbar: (no name) - {7009fcd4-05be-44f4-9583-93fe419ab7b0} - (no file)
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
                      O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
                      O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\Trust\3010A WIRELESS DESKSET\Keyboard\kbdap32a.EXE
                      O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Trust\3010A WIRELESS DESKSET\Mouse\mouse32a.exe
                      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
                      O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
                      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
                      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
                      O4 - HKLM\..\Run: [SPAMfighter Agent] "C:\Program Files\SPAMfighter\SFAgent.exe" update delay 60
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [lphcjadj0en0l] C:\WINDOWS\system32\lphcjadj0en0l.exe
                      O4 - HKLM\..\Run: [SMrhcnadj0en0l] C:\Program Files\rhcnadj0en0l\rhcnadj0en0l.exe
                      O4 - HKLM\..\Run: [289b1a07] rundll32.exe "C:\WINDOWS\system32\wujmjgkc.dll",b
                      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
                      O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
                      O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
                      O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
                      O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                      O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                      O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.87 85.255.112.234
                      O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.116.87 85.255.112.234
                      O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.87 85.255.112.234
                      O20 - Winlogon Notify: wvUoOHaW - C:\WINDOWS\SYSTEM32\wvUoOHaW.dll
                      O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      0
                      1. j ai juste donné un avis pour rendre service, ni plus ni moins
                        0
                        1. Contributeur
                          Bon et bien messieurs à vous la main
                          0
                          1. Modérateur
                            Chiquitine29 a raison.
                            0
                            1. Salut ep44

                              vu le degré d infection, combofix sera je pense nécessaire

                              Bonne suite

                              @++
                              0
                              • 1
                              • 2