Infection

Bonjour,
Je pense etre infecté par trois virus/spyware, à savoir : VSB Malware gen / Fraudtool.Gl[Tool] / Trojan -gen

Que faire qui peut m'aider?

Merci d'avance
Configuration: Windows XP
Internet Explorer 7.0

8 réponses

  1. Fixes les lignes (lance hijacthis, coches la ligne, fais "fix checked", en bas à gauche)

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*http://f­r.yahoo.com

    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    Ensuite met à jour Windows (Service Pack 3) et Java : https://www.java.com/fr/

    Ensuite refais un log hijackthis, histoire d'avoir un log à jour.
    0
    1. re hijackthis:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 02:31:18, on 05/09/2008
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
      C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
      C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
      C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\Acer\Empowering Technology\eLock\LockServ.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\WINDOWS\system32\wbem\unsecapp.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\pauline levesque\Bureau\hijackthis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
      O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
      O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
      O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
      O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://express.foto.com/Newuploader/ImageUploader4.cab
      O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
      O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      O23 - Service: LockServ - Unknown owner - C:\Acer\Empowering Technology\eLock\LockServ.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      0
      1. Malware :

        Malwarebytes' Anti-Malware 1.26
        Version de la base de données: 1112
        Windows 5.1.2600 Service Pack 2

        05/09/2008 02:22:55
        mbam-log-2008-09-05 (02-22-55).txt

        Type de recherche: Examen complet (C:\|D:\|)
        Eléments examinés: 98365
        Temps écoulé: 1 hour(s), 40 minute(s), 2 second(s)

        Processus mémoire infecté(s): 0
        Module(s) mémoire infecté(s): 0
        Clé(s) du Registre infectée(s): 5
        Valeur(s) du Registre infectée(s): 5
        Elément(s) de données du Registre infecté(s): 2
        Dossier(s) infecté(s): 12
        Fichier(s) infecté(s): 18

        Processus mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Module(s) mémoire infecté(s):
        (Aucun élément nuisible détecté)

        Clé(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\rhcc41j0ev0v (Rogue.Multiple) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\rhcc41j0ev0v (Rogue.Multiple) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Software Notifier (Rogue.Multiple) -> Quarantined and deleted successfully.

        Valeur(s) du Registre infectée(s):
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphc941j0ev0v (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> Quarantined and deleted successfully.

        Elément(s) de données du Registre infecté(s):
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispBackgroundPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\NoDispScrSavPage (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

        Dossier(s) infecté(s):
        C:\Program Files\rhcc41j0ev0v (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v\Quarantine (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v\Quarantine\BrowserObjects (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v\Quarantine\Packages (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v\Quarantine\Autorun (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v\Quarantine\Autorun\HKCU (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v\Quarantine\Autorun\HKCU\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v\Quarantine\Autorun\HKLM (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v\Quarantine\Autorun\HKLM\RunOnce (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v\Quarantine\Autorun\StartMenuAllUsers (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Application Data\rhcc41j0ev0v\Quarantine\Autorun\StartMenuCurrentUser (Rogue.Multiple) -> Quarantined and deleted successfully.

        Fichier(s) infecté(s):
        C:\WINDOWS\system32\blphc941j0ev0v.scr (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\Program Files\rhcc41j0ev0v\rhcc41j0ev0v.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Program Files\rhcc41j0ev0v\database.dat (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Program Files\rhcc41j0ev0v\msvcp71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Program Files\rhcc41j0ev0v\MFC71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Program Files\rhcc41j0ev0v\MFC71ENU.DLL (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Program Files\rhcc41j0ev0v\msvcr71.dll (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Program Files\rhcc41j0ev0v\license.txt (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Program Files\rhcc41j0ev0v\rhcc41j0ev0v.exe.local (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\Program Files\rhcc41j0ev0v\Uninstall.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\tdssinit.dll (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\tdssservers.dat (Trojan.Agent) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\phc941j0ev0v.bmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\WINDOWS\system32\lphc941j0ev0v.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Local Settings\Temp\.tt1.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Local Settings\Temp\.tt2.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Local Settings\Temp\.tt4.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
        C:\Documents and Settings\pauline levesque\Local Settings\Temp\.tt9.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
        0
        1. akors voici les resuktats : anti ir

          Avira AntiVir Personal
          Report file date: jeudi 4 septembre 2008 23:44

          Scanning for 1369550 virus strains and unwanted programs.

          Licensed to: Avira AntiVir PersonalEdition Classic
          Serial number: 0000149996-ADJIE-0001
          Platform: Windows XP
          Windows version: (Service Pack 2) [5.1.2600]
          Boot mode: Save mode
          Username: pauline levesque
          Computer name: PAULINE

          Version information:
          BUILD.DAT : 8.1.0.331 16934 Bytes 12/08/2008 11:46:00
          AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 08:57:54
          AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 07:56:42
          LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 12:44:20
          LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 07:58:54
          ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 10:33:34
          ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 13:54:16
          ANTIVIR2.VDF : 7.0.5.20 142336 Bytes 30/06/2008 05:20:54
          ANTIVIR3.VDF : 7.0.5.23 17408 Bytes 30/06/2008 09:24:48
          Engineversion : 8.1.1.19
          AEVDF.DLL : 8.1.0.5 102772 Bytes 25/02/2008 09:58:22
          AESCRIPT.DLL : 8.1.0.63 311673 Bytes 06/08/2008 13:13:48
          AESCN.DLL : 8.1.0.23 119156 Bytes 10/07/2008 12:44:50
          AERDL.DLL : 8.1.0.20 418165 Bytes 24/04/2008 12:37:50
          AEPACK.DLL : 8.1.2.1 364917 Bytes 15/07/2008 12:58:36
          AEOFFICE.DLL : 8.1.0.21 192891 Bytes 18/07/2008 06:35:22
          AEHEUR.DLL : 8.1.0.47 1368437 Bytes 06/08/2008 13:13:48
          AEHELP.DLL : 8.1.0.15 115063 Bytes 10/07/2008 12:44:50
          AEGEN.DLL : 8.1.0.35 315764 Bytes 06/08/2008 14:38:48
          AEEMU.DLL : 8.1.0.7 430452 Bytes 31/07/2008 08:33:22
          AECORE.DLL : 8.1.1.8 172406 Bytes 31/07/2008 08:33:22
          AEBB.DLL : 8.1.0.1 53617 Bytes 10/07/2008 12:44:50
          AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 08:40:06
          AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 09:28:02
          AVREP.DLL : 7.0.0.1 155688 Bytes 30/06/2008 14:35:22
          AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 11:26:42
          AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 08:29:24
          AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 12:27:50
          SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 17:28:04
          SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 12:49:42
          NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 12:05:12
          RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 13:48:08
          RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 13:34:38

          Configuration settings for the scan:
          Jobname..........................: Manual Selection
          Configuration file...............: C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\PROFILES\folder.avp
          Logging..........................: low
          Primary action...................: interactive
          Secondary action.................: ignore
          Scan master boot sector..........: on
          Scan boot sector.................: on
          Boot sectors.....................: C:, D:, E:,
          Process scan.....................: on
          Scan registry....................: on
          Search for rootkits..............: off
          Scan all files...................: All files
          Scan archives....................: on
          Recursion depth..................: 20
          Smart extensions.................: on
          Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,
          Macro heuristic..................: on
          File heuristic...................: medium
          Skipped files....................: C:\ATI,
          Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,

          Start of the scan: jeudi 4 septembre 2008 23:44

          The scan of running processes will be started
          Scan process 'avscan.exe' - '1' Module(s) have been scanned
          Scan process 'avcenter.exe' - '1' Module(s) have been scanned
          Scan process 'Explorer.EXE' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'svchost.exe' - '1' Module(s) have been scanned
          Scan process 'lsass.exe' - '1' Module(s) have been scanned
          Scan process 'services.exe' - '1' Module(s) have been scanned
          Scan process 'winlogon.exe' - '1' Module(s) have been scanned
          Scan process 'csrss.exe' - '1' Module(s) have been scanned
          Scan process 'smss.exe' - '1' Module(s) have been scanned
          11 processes with 11 modules were scanned

          Starting master boot sector scan:
          Master boot sector HD0
          [INFO] No virus was found!

          Start scanning boot sectors:
          Boot sector 'C:\'
          [INFO] No virus was found!
          Boot sector 'D:\'
          [INFO] No virus was found!

          Starting to scan the registry.
          The registry was scanned ( '59' files ).

          Starting the file scan:

          Begin scan in 'C:\' <ACER>
          C:\pagefile.sys
          [WARNING] The file could not be opened!
          C:\Documents and Settings\pauline levesque\Local Settings\Temp\.tt1.tmp.vbs
          [DETECTION] Contains recognition pattern of the VBS/Agent.1002 VBS script virus
          [NOTE] The file was moved to '49345c9c.qua'!
          C:\Documents and Settings\pauline levesque\Local Settings\Temp\.tt2.tmp.vbs
          [DETECTION] Contains recognition pattern of the VBS/Agent.1002 VBS script virus
          [NOTE] The file was moved to '49345cab.qua'!
          C:\Documents and Settings\pauline levesque\Bureau\SmitfraudFix\restart.exe
          [DETECTION] Contains recognition pattern of the SPR/Tool.Hardoff.A program
          [NOTE] The file was moved to '49335e55.qua'!
          C:\system volume information\_restore{7D0A09CF-FCEC-40B1-949D-E158943906CC}\RP4\A0000679.exe
          [DETECTION] Contains recognition pattern of the SPR/Tool.Hardoff.A program
          [NOTE] The file was moved to '48f06180.qua'!
          Begin scan in 'D:\' <ACERDATA>
          Begin scan in 'E:\'
          Search path E:\ could not be opened!
          System error [21]: Le périphérique n'est pas prêt.

          End of the scan: vendredi 5 septembre 2008 00:38
          Used time: 53:43 Minute(s)

          The scan has been done completely.

          6194 Scanning directories
          380176 Files were scanned
          4 viruses and/or unwanted programs were found
          0 Files were classified as suspicious:
          0 files were deleted
          0 files were repaired
          4 files were moved to quarantine
          0 files were renamed
          1 Files cannot be scanned
          380171 Files not concerned
          8631 Archives were scanned
          1 Warnings
          4 Notes
          0
          1. 1) Désinstalles PROPREMENT Avast, c'est important, et installes soit Antivir ( si tu reste en gratuit), soit Nod32 (payant) ou encore Kaspersky (payant).

            Tu peux le constater de toi-même :

            http://forum.malekal.com/ftopic3528.php

            Si tu décides d'installer Antivir, fais ceci :

            2) Télécharges Avira antivir PersonalEdition Classic a partir de ce lien : https://www.avira.com/ sur ton Bureau.
            3) Télécharges le désinstalleur d'Avast sur ton Bureau : https://www.avast.com/fr-fr/uninstall-utility
            4) Mets toi hors connexion, puis désinstalle avast, avec le désinstalleur!
            5) Redémarre ton PC comme demandé et supprime le dossier C:\Program Files\Alwils Software
            6) Double-cliques sur l'installeur d'Antivir.
            7) Une fois celui-ci installé, reconnectes-toi afin d’effectuer sa mise à jour, et le paramétrer.
            8) Ferme le scan qui s'est lancé de manière automatique.

            Paramètres-le comme :

            ici : http://speedweb1.free.fr/frames2.php?page=tuto5
            ou là : https://www.malekal.com/avira-free-security-antivirus-gratuit/

            9) Redémarres en mode sans échec

            - Au redémarrage de l'ordinateur, une fois le chargement du BIOS terminé, il y a un écran noir qui apparaît, tapotes la touche F8 (ou F5 sur certains PC) jusqu'à l'affichage du menu des options avancées de Windows.
            - Sélectionne "Mode sans échec" et appuyer sur la touche Enter.
            - Choisis ta session habituelle, pas le compte "Administrateur".

            Tutoriel ci-besoin :

            https://forum.pcastuces.com/sujet.asp?f=25&s=3902

            10) Lances Avira antivir.
            11) Cliques sur Local protection (colonne à gauche), puis sur « Scanner », puis vérifies à RootKit search et Manuelle détection (en développant avec la petite croix devant chacun d'eux), que tous tes disques durs soient bien cochés, puis cliques sur la loupe (en dessous de statut).
            12) Une fenêtre va s’ouvrir « Luke Filewalker » .. le scan va démarrer.
            13) Mets tout ce qu il trouve en "Quarantine".
            14) Une fois le scan achevé, fermes les deux fenêtres d'Antivir et sauvegardes le rapport.
            15) Redémarres en mode normal puis postes le rapport d'Antivir.

            Tuto http://www.malekal.com/tutorial_antivir.html et/ou http://www.libellules.ch/tuto_antivir.php

            16) Télécharges Malwarebyte's à l'adresse ci-dessous, puis redémarres en mode sans échec. Pour cela, tapotes F8 au démarrage, avant que le logo de windows n'apparaisse. Fais un scan complet, et supprimes tout ce qu'il te trouve. Ensuite sauvegardes le résultat (à la fin du scan, l'option "afficher le résultat", apparait).

            https://www.generation-nt.com/malwarebytes-anti-malware-protection-agents-malveillants-securite-anti-malwares-telecharger-telechargement-47800.html

            17) Lorsque tu as fini ça, refais un log hijackthis et post-le à la suite du résultat de Malwarebyte's.
            0
            1. voici! est-ce bien ce ke vous attendiez

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 22:43:11, on 04/09/2008
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16705)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\csrss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              C:\Program Files\Alwil Software\Avast4\ashServ.exe
              C:\WINDOWS\Explorer.EXE
              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
              C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
              C:\Program Files\Canon\MyPrinter\BJMyPrt.exe
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe
              C:\WINDOWS\system32\lphc941j0ev0v.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
              C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              C:\WINDOWS\eHome\ehRecvr.exe
              C:\WINDOWS\eHome\ehSched.exe
              C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
              C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              C:\Acer\Empowering Technology\eLock\LockServ.exe
              C:\WINDOWS\system32\nvsvc32.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\ehome\mcrdsvc.exe
              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              C:\WINDOWS\system32\dllhost.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\System32\alg.exe
              C:\WINDOWS\system32\wbem\unsecapp.exe
              C:\WINDOWS\system32\wbem\wmiprvse.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Documents and Settings\pauline levesque\Bureau\hijackthis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ycomp/defaults/su/*https://fr.yahoo.com/
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
              O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
              O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
              O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
              O4 - HKLM\..\Run: [lphc941j0ev0v] C:\WINDOWS\system32\lphc941j0ev0v.exe
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
              O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
              O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
              O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.1.2.dll/206 (file missing)
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
              O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://express.foto.com/Newuploader/ImageUploader4.cab
              O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
              O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
              O23 - Service: PIXMA Extended Survey Program (IJPLMSVC) - Unknown owner - C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE
              O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
              O23 - Service: LockServ - Unknown owner - C:\Acer\Empowering Technology\eLock\LockServ.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              0