Virus

Résolu
bonjour, j'ai été infecté par un virus qui n'a pu être supprimé par AVAST, je l'ai alors desinstalé puis ajouté ANTIVIR. Cependant il me reste en fond d'écran un message " warning spyware detected on your computer ! install an antivirus or spyware remover to clean your computer ". De + quand je vais sur internet il m'ouvre régulièrement des pubs (malgré popup bloqué)
ANTIVIR trouve toujours 5 warning.

voici le rapport que ANTIVIR me donne :

Avira AntiVir Personal
Report file date: mercredi 30 juillet 2008 18:42

Scanning for 1519486 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Boot mode: Save mode
Username: Administrateur
Computer name: ACER-9DEB84EBB9

Version information:
BUILD.DAT : 8.1.0.326 16933 Bytes 11/07/2008 12:57:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:54
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:42
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:20
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:54
ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:16
ANTIVIR2.VDF : 7.0.5.174 2027008 Bytes 25/07/2008 11:51:52
ANTIVIR3.VDF : 7.0.5.192 149504 Bytes 30/07/2008 11:51:52
Engineversion : 8.1.1.12
AEVDF.DLL : 8.1.0.5 102772 Bytes 09/07/2008 08:46:52
AESCRIPT.DLL : 8.1.0.59 307579 Bytes 30/07/2008 11:52:00
AESCN.DLL : 8.1.0.23 119156 Bytes 30/07/2008 11:51:58
AERDL.DLL : 8.1.0.20 418165 Bytes 09/07/2008 08:46:52
AEPACK.DLL : 8.1.2.1 364917 Bytes 30/07/2008 11:51:58
AEOFFICE.DLL : 8.1.0.21 192891 Bytes 30/07/2008 11:51:58
AEHEUR.DLL : 8.1.0.44 1343863 Bytes 30/07/2008 11:51:56
AEHELP.DLL : 8.1.0.15 115063 Bytes 09/07/2008 08:46:52
AEGEN.DLL : 8.1.0.31 311669 Bytes 30/07/2008 11:51:54
AEEMU.DLL : 8.1.0.6 430451 Bytes 09/07/2008 08:46:52
AECORE.DLL : 8.1.1.7 172406 Bytes 30/07/2008 11:51:54
AEBB.DLL : 8.1.0.1 53617 Bytes 24/04/2008 08:50:42
AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:06
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:02
AVREP.DLL : 8.0.0.2 98561 Bytes 30/07/2008 11:51:52
AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:42
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:24
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:50
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:04
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:42
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:12
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:08
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:38

Configuration settings for the scan:
Jobname..........................: Manual Selection
Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\folder.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:, D:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: Intelligent file selection
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: mercredi 30 juillet 2008 18:42

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'hpgs2wnf.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'Explorer.EXE' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
12 processes with 12 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Master boot sector HD2
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Master boot sector HD3
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.
Master boot sector HD4
[INFO] No virus was found!
[WARNING] System error [21]: Le périphérique n'est pas prêt.

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '87' files ).

Starting the file scan:

Begin scan in 'C:\' <ACER>
C:\pagefile.sys
[WARNING] The file could not be opened!
Begin scan in 'D:\' <ACERDATA>

End of the scan: jeudi 31 juillet 2008 02:01
Used time: 7:18:46 Hour(s)

The scan has been done completely.

6546 Scanning directories
373415 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
373414 Files not concerned
6854 Archives were scanned
5 Warnings
0 Notes

Pourriez vous m'aider svp.
Merci.
Configuration: Windows XP
Internet Explorer 6.0

27 réponses

Résumé de la discussion

Un utilisateur signale une infection logicielle persistante après l'échec d'AVAST, avec un message d'alarme affiché sur le bureau et des publicités récurrentes malgré l'utilisation d'AntiVir. Des conseils préconisent de mettre à jour le navigateur et le système, en recommandant notamment une montée de version d'Internet Explorer et, éventuellement, le passage à Firefox pour améliorer la sécurité. Des propositions techniques évoquent l'emploi d'outils de nettoyage comme ComboFix pour analyser et nettoyer le système. D'autres intervenants soulignent l'importance de vérifier les mises à jour des extensions et des composants système, et de prévenir les redémarrages intempestifs en cas d'infection persistante.

Bobot (l’IA à votre service)
  1. Contributeur
    Salut azerty1963,

    un dernier truc :

    Télécharge ToolsCleaner sur ton bureau.
    --> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
    # Clique sur Recherche et laisse le scan agir ...
    # Clique sur Suppression pour finaliser.
    # Tu peux, si tu le souhaites, te servir des Options facultatives.
    # Clique sur Quitter pour obtenir le rapport.
    # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

    je met en resolu`

    @+
    0
    1. on peut mettre le statut à "résolu" mais je ne sais pas faire !
      0
      1. Contributeur
        ok ;)
        on met en resolu ?
        0
        1. Oui c'est bon j'ai un pare feu.
          Merci beaucoup.
          0
          1. Contributeur
            c´est ce que je me disais aussi > que des racourcis ;)

            garde antivir > c´est ton antivirus !

            regle le comme ca d´ailleur pour qu´il soit bien efficace :

            Reglages :

            une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
            ceux qui ne voie pas root kit search : clcik sur le parapluie dans ta barre des tache > dans la fenetre d´antivir click sur local protection click en suite sur scanner
            dans la fenetre de droite : tu a rootkit search vers le bas > tu developpe en appuyant sur le petit +
            et coche tes disques...
            puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
            coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
            puis sur la droite coche les case suivantes :
            scan boot sectors of selected drives
            scan master boot sectors
            scan memory
            search foe rootkit before scan
            decoche :
            ignore off line files
            toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

            malwarebytes tu peux le garder pour scanner de temps en temps.

            toolcleaner2 > supprime

            spywaregard et spywareblaster, tu garde c´est de tres bonne protections, spyware blaster a mettre a jour de temps en temps, et tout sur "enable" ;)

            tu as installé un par feu ?

            @+
            0
            1. pour antivirus XP 2008 c'est bon : ce n'était que des raccourcis que j'ai supprimé.

              pour le reste :
              antivir
              Malwarebytes' Anti-Malware

              CCleaner
              ToolsCleaner2

              spywaregard
              spywareblaster

              je garde ?
              0
              1. Contributeur
                on l´a supprimé, mais oui supprime les restes que tu touves de lui...

                dis moi

                @+
                0
                1. On retrouve juste "antivirus XP 2008 " dans le menu démarrer.
                  mais pas dans "ajout/suppression de programme".

                  est il desinstallé ? comment en être sur ?

                  Peut on supprimer les fichiers dans le menu démarrer ?
                  0
                  1. Contributeur
                    oui carrement !
                    essaie de le desinstaller si tu ne peux pas dis moi
                    @+
                    0
                    1. Je ne sais pas comment XP antivirus est arrivé. Mais effectivement on l'a.
                      Il faut le désinstallé ?
                      0
                      1. Contributeur
                        azerty1963.

                        tu me fais peur c´est quoi xp antivirus tu as ca ?

                        @+
                        0
                        1. Super, tous mes remerciements !

                          juste une dernière question, suite à tout ça, j'ai beaucoup de programmes, faut il que je fasse un peu de propre?
                          lesquels dois je supprimer? on a

                          antivirus XP
                          antivir
                          Malwarebytes' Anti-Malware

                          CCleaner
                          ToolsCleaner2

                          spywaregard
                          spywareblaster

                          sinon on peut effectivement mettre en résolu. génial !
                          merci encore
                          0
                          1. Contributeur
                            ok

                            on met en resolu ?

                            @+
                            0
                            1. voici le rapport:

                              -->- Recherche:

                              C:\Qoobox: trouvé !
                              C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
                              C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
                              C:\Documents and Settings\famille\Bureau\HijackThis.lnk: trouvé !
                              C:\Documents and Settings\famille\Bureau\ComboFix.exe: trouvé !
                              C:\Documents and Settings\famille\Bureau\SmitFraudfix: trouvé !
                              C:\Program Files\Trend Micro\HijackThis: trouvé !
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !

                              ---------------------------------
                              -->- Suppression:

                              C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
                              C:\Documents and Settings\famille\Bureau\HijackThis.lnk: supprimé !
                              C:\Documents and Settings\famille\Bureau\ComboFix.exe: supprimé !
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                              C:\Qoobox: supprimé !
                              C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
                              C:\Documents and Settings\famille\Bureau\SmitFraudfix: supprimé !
                              C:\Program Files\Trend Micro\HijackThis: supprimé !
                              0
                              1. Contributeur
                                CA DOIT ALLER MAINTENANT NON ?

                                a l´aide de hijack this coche et fix les lignes suivantes :

                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                                O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                                O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                                O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                                O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) - http://webiq005.webiqonline.com/...{896A23A1-5821-4609-A6C6-6D5536C585C9}
                                O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
                                O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://photoservice.fujicolor.de/...
                                O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab

                                comment fixer :

                                Tutoriel d´utilisation (video) : (Merci a Balltrap34 pour cette réalisation)

                                -> http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

                                puis

                                ta version de acrobat reader n´est pas a jour, tu veux la derniere verion en date alors desinstale ta version par le panneau de configuration / ajoue et suppression de programme

                                et instale la derniere :

                                https://get2.adobe.com/reader/otherversions/

                                ou oublie completement acrobat reader et instales foxit plus léger a la place:

                                https://www.clubic.com/telecharger-fiche13808-foxit-reader.html

                                tu n´as pas de par feu :

                                Comodo 3 pro :

                                http://www.commentcamarche.net/telecharger/telecharger 34055041 comodo firewall pro

                                tuto : https://www.malekal.com/tutorial-comodo-firewall/

                                Online armor :

                                http://www.commentcamarche.net/telecharger/telecharger 34055356 online armor personal firewall

                                tuto : https://www.malekal.com/tutorial-online-armor-free/

                                ou zone alarm plus facil a configurer mais moins performant

                                https://www.malekal.com/tutoriel-zonealarm-firewall/

                                regle antivir comme suit :

                                une fois antivir ouvert click surconfiguration et coche la case "expert mode" puis sur l´onglet scanner dans la fenetre du dessous tu va voir : rootkit search click sur le petit + pour deployer et coche la case a coté de ton disk dur
                                ceux qui ne voie pas root kit search : clcik sur le parapluie dans ta barre des tache > dans la fenetre d´antivir click sur local protection click en suite sur scanner
                                dans la fenetre de droite : tu a rootkit search vers le bas > tu developpe en appuyant sur le petit +
                                et coche tes disques...
                                puis click sur configuration en haut a droite; dans la nouvelle fenetre a gauche >scanner > coche "scan all files" et en dessous >scanner priority = High
                                coche : allow stopping the scanner, comme cela tu peux faire une pause pendant le scan si tu le desir.
                                puis sur la droite coche les case suivantes :
                                scan boot sectors of selected drives
                                scan master boot sectors
                                scan memory
                                search foe rootkit before scan
                                decoche :
                                ignore off line files
                                toujours a gauche > scan > deploie > heuristique > macrovirus heuristic = coché et en dessous > win32 heuristic la case coché et high detection level

                                anti spyware :

                                bonus :

                                spywareblaster :

                                http://www.brightfort.com/spywareblaster.html

                                c´est un resident, il suffit de le mettre a jour de temps en temps car la version gratuite ne le fait pas toute seul , une fois installé et mis a jour tu mets toutes les protections sur "enable"

                                tuto : https://www.malekal.com/tutorial-spywareblaster/

                                et

                                spyware gard :

                                https://www.zebulon.fr/dossiers/securite/47-spywareguard.html

                                pour supprimer les outils utilisés :

                                Télécharge ToolsCleaner sur ton bureau.
                                --> http://www.commentcamarche.net/telecharger/telechargement 34055291 toolsclean(...)
                                # Clique sur Recherche et laisse le scan agir ...
                                # Clique sur Suppression pour finaliser.
                                # Tu peux, si tu le souhaites, te servir des Options facultatives.
                                # Clique sur Quitter pour obtenir le rapport.
                                # Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                                @+
                                0
                                1. voici le rapport hijack this,
                                  merci encore pour ta rapidité!

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 20:10:01, on 31/07/2008
                                  Platform: Windows XP SP2 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v7.00 (7.00.5730.0013)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                  C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                                  C:\WINDOWS\system32\nvsvc32.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\SOUNDMAN.EXE
                                  C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                                  C:\WINDOWS\system32\RUNDLL32.EXE
                                  C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                  C:\Program Files\Acer\Acer eMode Management\AspireService.exe
                                  C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                                  C:\Program Files\Acer\Acer eConsole\MediaSync.exe
                                  C:\Program Files\Real\RealPlayer\RealPlay.exe
                                  C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
                                  C:\Program Files\Logitech\ImageStudio\LogiTray.exe
                                  C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                                  C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
                                  C:\Program Files\FinePixViewer\QuickDCF.exe
                                  C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                                  C:\Program Files\Messenger\msmsgs.exe
                                  C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
                                  C:\Program Files\Outlook Express\msimn.exe
                                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                  C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                  R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                  R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                  O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                  O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                  O4 - HKLM\..\Run: [LaunchApp] Alaunch
                                  O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                  O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
                                  O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                                  O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                                  O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                                  O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                                  O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                                  O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                  O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                  O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                  O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                  O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
                                  O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
                                  O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                                  O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
                                  O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
                                  O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
                                  O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
                                  O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
                                  O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                                  O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                  O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                  O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                  O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
                                  O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
                                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                  O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                  O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                                  O4 - Global Startup: Exif Launcher.lnk = ?
                                  O4 - Global Startup: BTTray.lnk = ?
                                  O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                  O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                  O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                                  O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                  O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                  O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
                                  O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                                  O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                                  O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) - http://webiq005.webiqonline.com/WebIQ/DataServer/Pub/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
                                  O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
                                  O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                  O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://photoservice.fujicolor.de/ips-opdata/operator/27859021/activex/IPSUploader4.cab
                                  O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                  O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                                  O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                                  O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                  O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
                                  O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                  O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                  O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                  O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                                  O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                  0
                                  1. Contributeur
                                    super,

                                    post un nouveau rapport hijack this stp

                                    @+
                                    0
                                    1. voici le rapport:
                                      Malwarebytes' Anti-Malware 1.24
                                      Version de la base de données: 1012
                                      Windows 5.1.2600 Service Pack 2

                                      18:53:45 31/07/2008
                                      mbam-log-7-31-2008 (18-53-45).txt

                                      Type de recherche: Examen complet (C:\|D:\|)
                                      Eléments examinés: 140455
                                      Temps écoulé: 36 minute(s), 50 second(s)

                                      Processus mémoire infecté(s): 0
                                      Module(s) mémoire infecté(s): 0
                                      Clé(s) du Registre infectée(s): 2
                                      Valeur(s) du Registre infectée(s): 3
                                      Elément(s) de données du Registre infecté(s): 0
                                      Dossier(s) infecté(s): 0
                                      Fichier(s) infecté(s): 8

                                      Processus mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Module(s) mémoire infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Clé(s) du Registre infectée(s):
                                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhcr1cj0er1q (Rogue.Multiple) -> Quarantined and deleted successfully.
                                      HKEY_LOCAL_MACHINE\SOFTWARE\rhcr1cj0er1q (Rogue.Multiple) -> Quarantined and deleted successfully.

                                      Valeur(s) du Registre infectée(s):
                                      HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                                      HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
                                      HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.

                                      Elément(s) de données du Registre infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Dossier(s) infecté(s):
                                      (Aucun élément nuisible détecté)

                                      Fichier(s) infecté(s):
                                      C:\System Volume Information\_restore{18120FB7-1173-47C3-9BCD-321152D5F4E4}\RP586\A0114822.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                      C:\System Volume Information\_restore{18120FB7-1173-47C3-9BCD-321152D5F4E4}\RP586\A0114823.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                                      C:\System Volume Information\_restore{18120FB7-1173-47C3-9BCD-321152D5F4E4}\RP586\A0114827.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                      C:\QooBox\Quarantine\C\WINDOWS\elqw.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                      C:\QooBox\Quarantine\C\WINDOWS\system32\qoMfGaWN.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                                      C:\QooBox\Quarantine\C\WINDOWS\system32\yayxxxYQ.dll.vir (Trojan.Vundo) -> Quarantined and deleted successfully.
                                      C:\Documents and Settings\All Users\Bureau\Antivirus XP 2008.lnk (Rogue.Antivirus) -> Quarantined and deleted successfully.
                                      C:\Documents and Settings\famille\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk (Rogue.Antivirus2008) -> Quarantined and deleted successfully.
                                      0
                                      1. Contributeur
                                        ok

                                        supprime ceci :

                                        C:\WINDOWS\system32\uwskgbie.ini

                                        puis

                                        Fais un scan avec cet antispyware :

                                        Telecharge malwarebytes + tutoriel :

                                        -> https://www.malekal.com/tutoriel-malwarebyte-anti-malware/

                                        Tu l´instale; le programme va se mettre automatiquement a jour.

                                        Une fois a jour, le programme va se lancer; click sur l´onglet parametre, et coche la case : "Arreter internet explorer pendant la suppression".

                                        Click maintenant sur l´onglet recherche et coche la case : "executer un examun complet".

                                        Puis click sur "rechercher".

                                        Laisse le scanner le pc...

                                        Si des elements on ete trouvés > click sur supprimer la selection.

                                        si il t´es demandé de redemarrer > click sur "yes".

                                        A la fin un rapport va s´ouvrir; sauvegarde le de maniere a le retrouver en vu de le poster sur le forum.

                                        Copie et colle le rapport stp.

                                        @+
                                        0
                                        1. Voilà :

                                          ComboFix 08-07-30.02 - famille 2008-07-31 17:56:56.2 - [color=red][b]FAT32[/b][/color]x86
                                          Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.563 [GMT 2:00]
                                          Endroit: C:\Documents and Settings\famille\Bureau\ComboFix.exe
                                          Command switches used :: C:\Documents and Settings\famille\Bureau\CFScript.txt
                                          * Création d'un nouveau point de restauration

                                          [color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/b][/color]

                                          FILE ::
                                          C:\WINDOWS\system32\eibgkswu.dll
                                          .

                                          (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
                                          .

                                          C:\Documents and Settings\Administrateur\Application Data\Symantec
                                          C:\WINDOWS\system32\eibgkswu.dll

                                          .
                                          ((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-06-28 to 2008-07-31 ))))))))))))))))))))))))))))))))))))
                                          .

                                          2008-07-31 17:24 . 2008-07-31 17:54 474 ---hs---- C:\WINDOWS\system32\uwskgbie.ini
                                          2008-07-31 17:09 . 2008-07-31 17:09 <REP> d-------- C:\WINDOWS\system32\fr-fr
                                          2008-07-31 17:08 . 2008-07-31 17:09 1,374 --a------ C:\WINDOWS\imsins.BAK
                                          2008-07-31 15:51 . 2008-07-31 15:51 <REP> d-------- C:\Program Files\Trend Micro
                                          2008-07-31 15:04 . 2008-07-31 15:04 4,460 --a------ C:\WINDOWS\system32\tmp.reg
                                          2008-07-31 15:03 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
                                          2008-07-31 15:03 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
                                          2008-07-31 15:03 . 2008-05-29 09:35 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
                                          2008-07-31 15:03 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
                                          2008-07-31 15:03 . 2008-07-02 13:33 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
                                          2008-07-31 15:03 . 2008-05-23 18:21 81,920 --a------ C:\WINDOWS\system32\404Fix.exe
                                          2008-07-31 15:03 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
                                          2008-07-31 15:03 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
                                          2008-07-31 15:03 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
                                          2008-07-31 14:55 . 2008-07-31 14:55 268 --ah----- C:\sqmdata19.sqm
                                          2008-07-31 14:55 . 2008-07-31 14:55 244 --ah----- C:\sqmnoopt19.sqm
                                          2008-07-31 14:02 . 2008-07-31 14:02 268 --ah----- C:\sqmdata18.sqm
                                          2008-07-31 14:02 . 2008-07-31 14:02 244 --ah----- C:\sqmnoopt18.sqm
                                          2008-07-31 13:45 . 2008-07-31 13:45 <REP> d--hs---- C:\FOUND.000
                                          2008-07-30 18:42 . <REP> C:\Documents and Settings\Administrateur\Application Data\Dossier de t‚l‚chargement Share-to-Web
                                          2008-07-30 18:41 . 2005-01-23 11:51 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage r‚seau
                                          2008-07-30 18:41 . 2005-01-23 11:51 <REP> d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
                                          2008-07-30 18:41 . 2005-01-23 11:51 <REP> d--h----- C:\Documents and Settings\Administrateur\ModŠles
                                          2008-07-30 18:41 . 2005-01-23 12:07 <REP> dr------- C:\Documents and Settings\Administrateur\Mes documents
                                          2008-07-30 18:41 . 2005-01-23 11:51 <REP> dr------- C:\Documents and Settings\Administrateur\Menu D‚marrer
                                          2008-07-30 18:41 . 2005-01-23 12:07 <REP> dr------- C:\Documents and Settings\Administrateur\Favoris
                                          2008-07-30 18:41 . 2005-01-23 11:51 <REP> d-------- C:\Documents and Settings\Administrateur\Bureau
                                          2008-07-30 18:41 . 2008-07-30 18:41 <REP> d-------- C:\Documents and Settings\Administrateur
                                          2008-07-30 13:49 . 2008-07-30 13:49 <REP> d-------- C:\Program Files\Avira
                                          2008-07-30 13:49 . 2008-07-30 13:49 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira
                                          2008-07-30 13:40 . 2008-07-30 13:40 <REP> d-------- C:\Program Files\CCleaner
                                          2008-07-29 12:33 . 2008-07-29 12:33 <REP> d-------- C:\Documents and Settings\All Users\Application Data\ESET
                                          2008-07-25 12:32 . 2008-07-25 12:32 <REP> d-------- C:\Program Files\Sun
                                          2008-07-18 18:11 . 2008-07-18 18:11 1,202 --a------ C:\Documents and Settings\famille\Application Data\filterclsid.dat
                                          2008-06-14 11:11 . 2008-06-14 11:11 268 --ah----- C:\sqmdata17.sqm
                                          2008-06-14 11:11 . 2008-06-14 11:11 244 --ah----- C:\sqmnoopt17.sqm
                                          2008-06-11 13:00 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
                                          2008-06-11 13:00 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\dllcache\bthport.sys

                                          .
                                          (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
                                          .
                                          2008-07-30 16:42 --------- d-----w C:\Documents and Settings\Administrateur\Application Data\Dossier de téléchargement Share-to-Web
                                          2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\mswsock.dll
                                          2008-06-20 17:41 247,808 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
                                          2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
                                          2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\drivers\tcpip.sys
                                          2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
                                          2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\drivers\afd.sys
                                          2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
                                          2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\drivers\tcpip6.sys
                                          2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
                                          2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\dllcache\rmcast.sys
                                          2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
                                          2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\dllcache\quartz.dll
                                          2008-04-21 06:57 474,624 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll
                                          2008-04-21 06:57 152,064 ----a-w C:\WINDOWS\system32\dllcache\cdfview.dll
                                          2008-04-21 06:57 1,499,648 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll
                                          2008-04-21 06:57 1,056,768 ----a-w C:\WINDOWS\system32\dllcache\danim.dll
                                          2008-04-21 06:57 1,024,512 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll
                                          .

                                          ((((((((((((((((((((((((((((( snapshot@2008-07-31_17.25.33.50 )))))))))))))))))))))))))))))))))))))))))
                                          .
                                          .
                                          ((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
                                          .
                                          .
                                          REGEDIT4
                                          *Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s

                                          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                          "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 05:00 15360]
                                          "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 12:55 5674352]
                                          "LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe" [2007-02-13 07:14 67128]
                                          "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-16 19:48 68856]
                                          "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 16:45 313472]
                                          "Shareaza"="C:\Program Files\Shareaza\Shareaza.exe" [2007-02-05 04:05 4354048]

                                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                          "LaunchApp"="Alaunch" [X]
                                          "ntiMUI"="c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe" [2005-05-11 18:15 45056]
                                          "RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
                                          "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" [2004-08-05 05:00 208952]
                                          "MSPY2002"="C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-05 05:00 59392]
                                          "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 05:00 455168]
                                          "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-05 05:00 455168]
                                          "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-11-11 04:47 7311360]
                                          "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2005-11-11 04:47 86016]
                                          "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
                                          "AspireService"="C:\Program Files\Acer\Acer eMode Management\AspireService.exe" [2006-01-19 09:46 110592]
                                          "MediaSync"="C:\Program Files\Acer\Acer eConsole\MediaSync.exe" [2005-09-21 13:48 425984]
                                          "eRecoveryService"="C:\Acer\Empowering Technology\eRecovery\Monitor.exe" [2005-11-16 17:00 397312]
                                          "RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2006-08-20 12:46 20480]
                                          "LVCOMS"="C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 17:54 127022]
                                          "LogitechGalleryRepair"="C:\Program Files\Logitech\ImageStudio\ISStart.exe" [2002-12-10 18:32 155648]
                                          "LogitechImageStudioTray"="C:\Program Files\Logitech\ImageStudio\LogiTray.exe" [2002-12-10 18:31 61440]
                                          "REGSHAVE"="C:\Program Files\REGSHAVE\REGSHAVE.EXE" [2002-02-04 22:32 53248]
                                          "Share-to-Web Namespace Daemon"="C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2001-07-03 09:11 57344]
                                          "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 14:28 266497]
                                          "SoundMan"="SOUNDMAN.EXE" [2005-09-22 16:42 90112 C:\WINDOWS\soundman.exe]
                                          "nwiz"="nwiz.exe" [2005-11-11 04:47 1519616 C:\WINDOWS\system32\nwiz.exe]

                                          [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
                                          "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 05:00 15360]

                                          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                          "VIDC.SP53"= SP5X_32.DLL
                                          "VIDC.SP54"= SP5X_32.DLL
                                          "VIDC.SP55"= SP5X_32.DLL
                                          "VIDC.SP56"= SP5X_32.DLL
                                          "VIDC.SP57"= SP5X_32.DLL
                                          "VIDC.SP58"= SP5X_32.DLL
                                          "VIDC.SP59"= SP5X_32.DLL
                                          "VIDC.YV12"= yv12vfw.dll

                                          [HKEY_LOCAL_MACHINE\software\microsoft\security center]
                                          "AntiVirusDisableNotify"=dword:00000001

                                          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                          "%windir%\\system32\\sessmgr.exe"=
                                          "C:\\Program Files\\Messenger\\msmsgs.exe"=
                                          "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
                                          "C:\\Program Files\\MSN Messenger\\livecall.exe"=
                                          "C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
                                          "C:\\Program Files\\Skype\\Phone\\Skype.exe"=
                                          "C:\\Program Files\\Shareaza\\Shareaza.exe"=

                                          R2 int15.sys;int15.sys;C:\Acer\Empowering Technology\eRecovery\int15.sys [2005-01-13 14:46]
                                          S3 LVBulk;LVBulk Service;C:\WINDOWS\system32\DRIVERS\LVBulk.sys [2002-06-10 14:21]
                                          S3 PID_0900_V;Logitech ClickSmart 310(PID_0900_V);C:\WINDOWS\system32\DRIVERS\LV551AV.sys [2002-06-10 14:24]

                                          *Newly Created Service* - INT15.SYS
                                          .
                                          **************************************************************************

                                          catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                          Rootkit scan 2008-07-31 18:00:16
                                          Windows 5.1.2600 Service Pack 2 FAT NTAPI

                                          Balayage processus cach‚s ...

                                          Balayage cach‚ autostart entries ...

                                          Balayage des fichiers cach‚s ...

                                          Scan termin‚ avec succŠs
                                          Les fichiers cach‚s: 0

                                          **************************************************************************
                                          .
                                          ------------------------ Other Running Processes ------------------------
                                          .
                                          C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\SCHED.EXE
                                          C:\PROGRAM FILES\ACER\ACER ECONSOLE\MEDIASERVERSERVICE.EXE
                                          C:\PROGRAM FILES\AVIRA\ANTIVIR PERSONALEDITION CLASSIC\AVGUARD.EXE
                                          C:\PROGRAM FILES\WIDCOMM\LOGICIEL BLUETOOTH\BIN\BTWDINS.EXE
                                          C:\WINDOWS\SYSTEM32\NVSVC32.EXE
                                          C:\WINDOWS\SYSTEM32\RUNDLL32.EXE
                                          C:\PROGRAM FILES\HEWLETT-PACKARD\HP SHARE-TO-WEB\HPGS2WNF.EXE
                                          C:\Program Files\FinePixViewer\QuickDCF.exe
                                          C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                                          C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                          C:\WINDOWS\SoftwareDistribution\Download\f210c4ef6dbbd58ee8abd2177a3090d6\update\update.exe
                                          .
                                          **************************************************************************
                                          .
                                          Temps d'accomplissement: 2008-07-31 18:02:45 - machine was rebooted
                                          ComboFix-quarantined-files.txt 2008-07-31 16:02:42
                                          ComboFix2.txt 2008-07-31 15:25:50

                                          Pre-Run: 8,399,126,528 octets libres
                                          Post-Run: 8,393,752,576 octets libres

                                          172 --- E O F --- 2008-07-24 09:54:13

                                          Logfile of Trend Micro HijackThis v2.0.2
                                          Scan saved at 18:03:41, on 31/07/2008
                                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                                          MSIE: Internet Explorer v7.00 (7.00.5730.0013)
                                          Boot mode: Normal

                                          Running processes:
                                          C:\WINDOWS\System32\smss.exe
                                          C:\WINDOWS\system32\winlogon.exe
                                          C:\WINDOWS\system32\services.exe
                                          C:\WINDOWS\system32\lsass.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\System32\svchost.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\system32\spoolsv.exe
                                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                          C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
                                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                          C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                                          C:\WINDOWS\system32\nvsvc32.exe
                                          C:\WINDOWS\system32\svchost.exe
                                          C:\WINDOWS\SOUNDMAN.EXE
                                          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                                          C:\WINDOWS\system32\RUNDLL32.EXE
                                          C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                                          C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                          C:\Program Files\Acer\Acer eMode Management\AspireService.exe
                                          C:\Program Files\Acer\Acer eConsole\MediaSync.exe
                                          C:\Program Files\Real\RealPlayer\RealPlay.exe
                                          C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
                                          C:\Program Files\Logitech\ImageStudio\LogiTray.exe
                                          C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                                          C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                                          C:\WINDOWS\system32\ctfmon.exe
                                          C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                          C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe
                                          C:\Program Files\FinePixViewer\QuickDCF.exe
                                          C:\Program Files\WIDCOMM\Logiciel Bluetooth\BTTray.exe
                                          C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                          C:\WINDOWS\system32\wuauclt.exe
                                          C:\WINDOWS\explorer.exe
                                          C:\WINDOWS\system32\notepad.exe
                                          C:\Program Files\Microsoft Office\Office\WINWORD.EXE
                                          C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                          R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
                                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                          O4 - HKLM\..\Run: [LaunchApp] Alaunch
                                          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                                          O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
                                          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                                          O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                                          O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                                          O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                                          O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                          O4 - HKLM\..\Run: [AspireService] C:\Program Files\Acer\Acer eMode Management\AspireService.exe
                                          O4 - HKLM\..\Run: [MediaSync] C:\Program Files\Acer\Acer eConsole\MediaSync.exe
                                          O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\Monitor.exe
                                          O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
                                          O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
                                          O4 - HKLM\..\Run: [LogitechGalleryRepair] C:\Program Files\Logitech\ImageStudio\ISStart.exe
                                          O4 - HKLM\..\Run: [LogitechImageStudioTray] C:\Program Files\Logitech\ImageStudio\LogiTray.exe
                                          O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
                                          O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
                                          O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                                          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
                                          O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                          O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
                                          O4 - HKCU\..\Run: [Shareaza] "C:\Program Files\Shareaza\Shareaza.exe" -tray
                                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                          O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
                                          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
                                          O4 - Global Startup: Exif Launcher.lnk = ?
                                          O4 - Global Startup: BTTray.lnk = ?
                                          O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                                          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                                          O8 - Extra context menu item: Envoyer à &Bluetooth - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie_ctx.htm
                                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                                          O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
                                          O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                                          O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Logiciel Bluetooth\btsendto_ie.htm
                                          O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                                          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                          O16 - DPF: {315B0BFB-2BD4-481B-80A3-A9B80727C61B} (WebIQ Engine Application Object) - http://webiq005.webiqonline.com/WebIQ/DataServer/Pub/DataServer.dll?Handler=GetEngineDistribution&EDID={896A23A1-5821-4609-A6C6-6D5536C585C9}
                                          O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
                                          O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
                                          O16 - DPF: {AE2B937E-EA7D-4A8D-888C-B68D7F72A3C4} (IPSUploader4 Control) - http://photoservice.fujicolor.de/ips-opdata/operator/27859021/activex/IPSUploader4.cab
                                          O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                          O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
                                          O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                                          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                                          O23 - Service: Acer Media Server - Acer Inc. - C:\Program Files\Acer\Acer eConsole\MediaServerService.exe
                                          O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
                                          O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                                          O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                                          O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Logiciel Bluetooth\bin\btwdins.exe
                                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                          0
                                          • 1
                                          • 2