Un virus

Résolu
bonsoir a tous

quelqu'un ma envoyer ce fichier: readme.doc.exe
je veux savoir de quel type des virus il s'agit
merci d'avance
Configuration: Windows XP
Internet Explorer 6.0

27 réponses

Résumé de la discussion

Un utilisateur reçoit le fichier readme.doc.exe sur Windows XP avec Internet Explorer 6 et cherche à identifier le type de virus potentiel et évalue les risques pour le système. Plusieurs propositions recommandent d'utiliser MalwareBytes pour analyser et supprimer les infections, puis de consulter les rapports et logs pour vérifier les résultats et éviter des suppressions inadaptées. D'autres conseils évoquent des outils complémentaires comme OTMoveIt3, NaviPromo et des vérifications de dépose de barres d'outils, tout en soulignant qu'une désinfection sûre dépend de chaque configuration. En cas de doute, il est recommandé de partager les rapports pour analyse et d'éviter l'exécution des étapes de désinfection sans supervision, afin d'éviter la perte de données.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Castelcops n'est plus mis à jour depuis 1 mois.
    Il va devenir obsolète.

    Change pour systemLookup.
    1. Contributeur sécurité
      Citation : 1) Lance Hijackthis et tu choisis " Do a system scan only ".
      Tu sélectionnes les lignes suivantes :

      O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
      O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe

      Tu choisis l'option " Fixchecked" en bas de la page


      C est bien toi qui a demandé ça donc ne soit pas étonné mdr

      L infection est une BHO infectée... Je viens de faire des recherches et c est bien une infection
    2. Contributeur sécurité
      Ouh la,

      regarder bien le lien de systemlookup avant de supprimer cette ligne.
      1. Contributeur sécurité
        Bonsoir,

        Laquelle, celle que DrHouse a indiqué.
        C'est ZebHelp qui l'a détecte comme faux positif.

        je remets le lien :
        http://www.systemlookup.com/search.php?type=clsid&client=malwaresearch-ff&search={6EBF7485-159F-4bff-A14F-B9E3AAC4465B}

        Citation :
        Et on ne fait pas fixer des lignes infectées, ça ne supprime pas l infection !!
        Et puis dis moi quelle ligne infectieuse j'ai demandé de fixer avec Hijackthis.

        salut.
        1. Hi,

          oui je veux faire la même chose avec mon Pc de travail
          est ce que je peux t'envoyer mon demande d'aide par message privé?


          Qu'il fini déjà celui la après tu verras.

          Alut.

          1. Contributeur sécurité
            Sara29 fais ceci stp :

            ▶ Télécharge OTMoveIt3 (de Old_Timer) sur ton Bureau

            ▶ Double-clique sur OTMoveIt.exe pour le lancer.

            ▶ Assure toi que la case Unregister Dll's and Ocx's soit bien cochée.

            ▶ Copie la liste qui se trouve en gras dans la citation ci-dessous et colle-la dans le cadre de gauche de OTMoveIt sous "Paste instructions for item to be moved".

            :files
            c:\program files\microsoft\search enhancement pack\search helper\searchhelper.dll

            :reg
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]
            [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}]


            ▶ clique sur MoveIt! pour lancer la suppression.

            ▶ Le résultat apparaitra dans le cadre "Results".

            ▶ Clique sur Exit pour fermer.

            ▶ Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.

            ▶ Il te sera peut-être demandé de redémarrer le pc pour achever la suppression. Si c'est le cas accepte par Yes.

            ensuite redémarre le pc et refais un nouveau rapport hijackthis stp
            1. Contributeur sécurité
              Salut !!

              Verni il reste une ligne infectée, House a raison !!

              Et on ne fait pas fixer des lignes infectées, ça ne supprime pas l infection !!
              1. Contributeur sécurité
                DrHouse1998,

                regarde le lien ( il était cassé ) et mets le site systemlookup dans tes favoris pour analyse de toutes les lignes du Hijackthis.

                Salut.
                1. Hi,

                  La ligne O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll

                  ==>INFECTION.

                  Alut.

                  1. Contributeur sécurité
                    est-ce que ton PC est sécurisé ?
                    Antivir + Comodo. Oui.

                    Ton PC est maintenant propre et protégé.

                    Peux-tu mettre le sujet en résolu ? Merci.

                    Enchanté de t'avoir donner un coup de main.
                    Bon surf et bonne continuation.

                    @+
                    1. merci bien pr votre aide et pr tout le temps que tu m'a donné
                      dernière question
                      est ce que je peux faire toutes ces étapes et les même avec les autres Pc pr.la vérification et la protection?
                      merci encore
                    2. Contributeur sécurité
                      @sara29Sarah29

                      La démarche de désinfection est propre à chaque PC.
                      Il ne faut surtout pas que tu passes certains outils sans conseil.

                      Si tu as d'autres PC, on peut continuer sur ce sujet.

                      A+
                    3. @verni29oui je veux faire la même chose avec mon Pc de travail
                      est ce que je peux t'envoyer mon demande d'aide par message privé?

                  2. Contributeur sécurité
                    Ne confonds pas les deux manips.

                    Pour désactiver les points de restauartion :

                    Panneau de configuration --> Système --> Restauration du système

                    cocher " Désactiver la restauration .... " ( si elle est cochée sinon la décocher -- > valider -- > cocher )

                    Une fenêtre va s’ouvrir pour t’avertir que les poins de restauration existants seront supprimés.
                    Accepte.

                    Décoche ensuite « Désactiver la restauration .... » pour réactiver la restauration système

                    Pour créer un point de restauration, suis les consignes du message
                    http://www.commentcamarche.net/forum/affich 9407948 un virus?#21

                    A+
                    1. c'est bon la point est crée, maintenant est ce que mon pc est bien sécurisé ?
                  3. Contributeur sécurité
                    Si, c'est la première étape qui est faite.

                    A+
                    1. salut verni29, voila le rapport de TCleaner

                      [ Rapport ToolsCleaner version 2.2.6 (par A.Rothstein & dj QUIOU) ]

                      -->- Recherche:

                      C:\fixnavi.txt: trouvé !
                      C:\cleannavi.txt: trouvé !
                      C:\TB.txt: trouvé !
                      C:\Toolbar SD: trouvé !
                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: trouvé !
                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: trouvé !
                      C:\Documents and Settings\WINXP\Bureau\HijackThis.lnk: trouvé !
                      C:\Program Files\Navilog1.exe: trouvé !
                      C:\Program Files\HJTInstall.exe: trouvé !
                      C:\Program Files\ToolBarSD.exe: trouvé !
                      C:\Program Files\Trend Micro\HijackThis: trouvé !
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: trouvé !
                      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: trouvé !

                      ---------------------------------
                      -->- Suppression:

                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis\HijackThis.lnk: supprimé !
                      C:\Documents and Settings\WINXP\Bureau\HijackThis.lnk: supprimé !
                      C:\Program Files\Navilog1.exe: supprimé !
                      C:\Program Files\HJTInstall.exe: supprimé !
                      C:\Program Files\ToolBarSD.exe: supprimé !
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe: supprimé !
                      C:\fixnavi.txt: supprimé !
                      C:\cleannavi.txt: supprimé !
                      C:\TB.txt: supprimé !
                      C:\Program Files\Trend Micro\HijackThis\hijackthis.log: supprimé !
                      C:\Toolbar SD: supprimé !
                      C:\Documents and Settings\All Users\Menu Démarrer\Programmes\HijackThis: supprimé !
                      C:\Program Files\Trend Micro\HijackThis: supprimé !

                      mais, pr la restauration du système je ne trouve pas ou je coche pr désactiver la restauration
                      regardez les 2 images

                      https://imageshack.com/
                      https://imageshack.com/
                  4. Contributeur sécurité
                    C'est bon.
                    Elles ont été supprimées.
                    C'était pour vérification.

                    A+
                    1. donc je ne fait rien pour le reste des étapes?
                  5. Contributeur sécurité
                    C'est nickel. On termine.
                    Je te mets pas mal de manips. Tu peux me poser des questions au fur et à mesure si tu le désires.

                    1) Lance Hijackthis et tu choisis " Do a system scan only ".
                    Tu sélectionnes les lignes suivantes :

                    O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                    O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                    O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe

                    Tu choisis l'option " Fixchecked" en bas de la page.

                    2) Télécharge OTCleanIT d’Old Timer.
                    http://download.bleepingcomputer.com/oldtimer/OTCleanIt.exe
                    Enregistre le fichier sur ton bureau.

                    Double clique sut OTCleanit.exe pour l’exécuter.
                    Clique sur CleanUp !.
                    Le logiciel va te demander de commencer l’analyse. Accepte.

                    Il te sera demandé le redémarrage de ton PC pour finir la suppression des fichiers et supprimer également OTCleanIT. Accepte.

                    3) On va enlever les logiciels qui ont été utilisés..
                    Télécharge ToolsCleaner .sur le bureau
                    http://pc-system.fr/

                    Double-clique sur ToolsCleaner2.exe --> Recherche --> Suppression.
                    Il est possible que ton bureau disparaisse.

                    Fais un copier/coller du rapport qui se trouve dans C:\TCleaner.txt

                    4) Les points de restauration :
                    - Panneau de configuation --> Système --> Restauration du sytème
                    cocher " Désactiver la restauration .... " ( si elle est cochée sinon la décocher -- > valider -- > cocher )
                    Une fenêtre va s’ouvrir pour t’avertir que les poins de restauration existants seront supprimés.
                    Accepte.
                    Décoche ensuite « Désactiver la restauration .... » pour réactiver la restauration système
                    - Tu vas recréer un point de restauration propre.
                    Pour recréer un point de restauration :
                    Démarrer --> Programmes --> Accessoires --> Outils système --> Restauration système
                    Choisis "Créer un point de restauration". Suis les invites.

                    A+
                    1. j'ai bien comprie ces 4 étapes a faire
                      mais premierement je ne trouve pas les lignes exacte à sélectionner
                      O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                      O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe

                      voila le nouveau rapport de Hijackthis

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 20:34:28, on 19/11/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Webroot\Washer\WasherSvc.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\system32\wscntfy.exe
                      C:\WINDOWS\VM305_STI.EXE
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Program Files\COMODO\SafeSurf\cssurf.exe
                      C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
                      C:\Program Files\LG Electronics\Modem USB LG Electronics\IEUM.exe
                      C:\Program Files\Windows Live\Toolbar\wltuser.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                      C:\Program Files\Internet Explorer\IEXPLORE.EXE
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/spresults.aspx
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?fdr=lc&toHttps=1&redig=FA6AD360E0BE4C719380F8C470A3D3A8
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10587&gct=&gc=1&q=
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10587&gct=&gc=1&q=
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx
                      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=10587&gct=&gc=1&q=%s
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll (file missing)
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                      O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
                      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.5470\swg.dll
                      O2 - BHO: Windows Live Toolbar Beta - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                      O3 - Toolbar: &Windows Live Toolbar Beta - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
                      O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
                      O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
                      O4 - HKCU\..\Run: [UMService] C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                      O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{985C9893-8F51-4CA5-82C9-6FF34E5FC9EF}: NameServer = 192.168.50.55 196.12.209.6
                      O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll C:\WINDOWS\system32\cssdll32.dll
                      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (file missing)
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                      O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
                  6. Contributeur sécurité
                    Pas sur qu'il soit supprimé.

                    Télécharge OTMoveIt3 (de Old_Timer).
                    http://oldtimer.geekstogo.com/OTMoveIt3.exe
                    Enregistre-le sur ton Bureau.

                    - Double-clique sur OTMoveit3.exe pour le lancer.
                    ( Si tu es sous Vista, click droit sur l'icone d'OTMoveIt3 --> exécuter en tant qu'administrateur pour le lancer )
                    - Vérifie que l'option Unregister Dll's and Ocx's est cochée.
                    - Copie la liste qui se trouve dans la zone code ci-dessous et colle-la dans le cadre de gauche de OTMoveIt sous Paste instructions for Items to be Moved.

                    :Processes
                    explorer.exe

                    :Files
                    C:\Program Files\AskBarDis
                    C:\WINDOWS\system32\amvo.exe

                    :Commands
                    [purity]
                    [emptytemp]
                    [start explorer]


                    - Clique sur MoveIt! pour lancer la suppression. Le résultat apparaitra dans le cadre "Results".
                    - Copie toute la sélection apparaissant dans ce cadre Résults. Colle ce rapport dans ton prochain message.
                    - Clique sur Exit pour fermer.
                    - Si tu ne trouves plus le rapport,c'est un fichier .log qui se trouve en C:\_OTMoveIt\MovedFiles.

                    Remarque : Il est possible qu'il te soit demandé de redémarrer ton ordinateur pour supprimer les fichiers.
                    Accepte.

                    A+
                    1. salut verni29
                      voila le ficher
                      et dit s'il te plait est ce que maintenant c'est bien?

                      ========== PROCESSES ==========
                      Process explorer.exe killed successfully.
                      ========== FILES ==========
                      File/Folder C:\Program Files\AskBarDis not found.
                      File/Folder C:\WINDOWS\system32\amvo.exe not found.
                      ========== COMMANDS ==========
                      User's Temp folder emptied.
                      User's Temporary Internet Files folder emptied.
                      User's Internet Explorer cache folder emptied.
                      Local Service Temp folder emptied.
                      File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                      Local Service Temporary Internet Files folder emptied.
                      Windows Temp folder emptied.
                      Temp folders emptied.
                      Explorer started successfully

                      OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 11192008_191220

                      Files moved on Reboot...
                      File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
                  7. Contributeur sécurité
                    Ah, flute.
                    En installant Comodo, tu as installé une barre d'outil infectieuse : AskBar.
                    c'est une option à ne pas choisir.

                    Il faut la désinstaller. Sinon, comment se passe l'apprentissage avec le parefeu ?

                    Télécharge Toolbar-S&D sur ton Bureau :
                    https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

                    * Lance l'installation du programme en exécutant le fichier téléchargé.
                    * Double-clique sur le raccourci de Toolbar-S&D.
                    * Sélectionne la langue puis valide.
                    * Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
                    * Copie/colle le contenu du rapport qui va s’afficher.
                    Si tu ne le trouves pas, il est situé à C:\TB.txt .

                    A+
                    1. bonsoir
                      je croie que la désinstallation de (skBar) est fait
                      voila le rapport de ToolBar

                      -----------\\ ToolBar S&D 1.2.4 XP/Vista

                      "C:\ToolBar SD" ( MAJ : 27-10-2008|09:25 )
                      Option : [1] ( 18/11/2008|19:38 )

                      -----------\\ Recherche de Fichiers / Dossiers ...

                      -----------\\ [..\Internet Explorer\Main]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                      "Start Page"="https://www.google.com/?gws_rd=ssl"
                      "Search Page"="https://www.bing.com/?fdr=lc&toHttps=1&redig=FA6AD360E0BE4C719380F8C470A3D3A8"
                      "Search Bar"="http://www.bing.com/spresults.aspx"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                      "Default_Search_URL"="http://toolbar.ask.com/toolbarv/askRedirect?o=10587&gct=&gc=1&q="
                      "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                      "Start Page"="http://home.sweetim.com"

                      --------------------\\ Recherche d'autres infections

                      --------------------\\ Cracks & Keygens ..

                      C:\DOCUME~1\WINXP\Bureau\tlbat\nab\www.tlbat.com\images\fonts_en\crackman.gif
                      C:\DOCUME~1\WINXP\Bureau\tlbat\nab\www.tlbat.com\up\fonts_en\crackman.zip

                      1 - "C:\ToolBar SD\TB_1.txt" - 18/11/2008|19:40 - Option : [1]

                      -----------\\ Fin du rapport a 19:40:41,28
                  8. Contributeur sécurité
                    Il n'y a aucune protection sur ton ordinateur : antivirus, parefeu.
                    C'est nécessaire.

                    1) Je te conseillerais d'installer Antivir. Il est en anglais mais la version française va bientôt sortir.
                    C'est l'antivirus le plus côté actuellement.

                    Suis le tuto pour installer Antivir :
                    https://www.malekal.com/avira-free-security-antivirus-gratuit/

                    Mets à jour Antivir et lance un scan complet :
                    Pour cela, clique sur l'onglet Local Protection puis Scanner
                    Choisis les éléments à scanner ( local hard disks ).
                    Lance le scan ( ( la loupe au dessus ).
                    Lorsque le scan est terminé, tu as la possibilité de générer un rapport en cliquant sur le bouton report.
                    Poste le rapport.

                    2) On va installer un parefeu. C'est un peu compliqué car les parefeus actuels peuvent être capricieux.
                    Ils interfèrent dans toutes les applications qui veulent accéder au net.
                    Tu as donc dans un premier temps des alertes qui te demandent si tu acceptes ou pas que tel ou tel programme accède à tel ou tel autre programme.

                    Si tu n'es pas très habitué à ce genre d'alertes, je te conseille de ne pas choisir un niveau trop élevé de protections. Ce sera suffisant mais tu ne seras pas gené tout le temps.

                    je t'indique trois produits. Installe en un et dis moi ton choix.
                    Essaie le et comprend le fonctionnement de ce type de protection.

                    pare-feu gratuits :

                    Zone alarm :
                    https://www.malekal.com/tutoriel-zonealarm-firewall/

                    - Comodo™ Firewall ( version 3.0 en anglais, sinon 2.4 multi-langues )
                    https://www.malekal.com/tutorial-comodo-firewall/
                    http://www.personalfirewall.comodo.com/download_firewall.html#fw2.4

                    - Kerio Personal Firewall
                    https://www.malekal.com/tutorial-et-guide-counterspy/

                    Le meilleur, à mon avis, est Comodo., mais il faut savoir le configurer.
                    il y a différents niveaux de protection ( trial pour apprentissage, safe par défaut, .., paranoid déconseillé ).

                    ZoneAlarm est connu. Lis le tuto. Il y a une partie Contrôle des programmes et leurs accès à internet. Ceci t'expliquera comment réagir avec les alertes.

                    Installe ces deux protections puis poste un rapport Hijackthis pour contrôle.

                    Ce n'est pas simple mais essentiel d'avoir ces deux protections.

                    A+
                    1. bonjour,
                      Salut verni29, merci bien pour tes indications j'ai fait ce que tu m'as dis, j'ai trouvée beaucoup des problèmes avec le téléchargement de ces programmes
                      Enfin j'ai terminée. Donc voila les rapports :

                      1-rapport Avira AntiVir Personal

                      Report file date: lundi 17 novembre 2008 19:49

                      Scanning for 1038808 virus strains and unwanted programs.

                      Licensed to: Avira AntiVir PersonalEdition Classic
                      Serial number: 0000149996-ADJIE-0001
                      Platform: Windows XP
                      Windows version: (Service Pack 2) [5.1.2600]
                      Boot mode: Normally booted
                      Username: WINXP
                      Computer name: WINKILLERXP

                      Version information:
                      BUILD.DAT : 8.2.0.336 16933 Bytes 30/10/2008 11:40:00
                      AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 10:57:53
                      AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 09:56:40
                      LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 14:44:19
                      LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 09:58:52
                      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 19:35:53
                      ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 09/11/2008 19:37:01
                      ANTIVIR2.VDF : 7.1.0.89 221184 Bytes 16/11/2008 19:37:20
                      ANTIVIR3.VDF : 7.1.0.97 45056 Bytes 17/11/2008 19:37:26
                      Engineversion : 8.2.0.31
                      AEVDF.DLL : 8.1.0.6 102772 Bytes 14/10/2008 12:05:56
                      AESCRIPT.DLL : 8.1.1.15 332156 Bytes 17/11/2008 19:40:12
                      AESCN.DLL : 8.1.1.5 123251 Bytes 17/11/2008 19:39:49
                      AERDL.DLL : 8.1.1.3 438645 Bytes 17/11/2008 19:39:43
                      AEPACK.DLL : 8.1.3.4 393591 Bytes 17/11/2008 19:39:29
                      AEOFFICE.DLL : 8.1.0.30 196986 Bytes 17/11/2008 19:39:12
                      AEHEUR.DLL : 8.1.0.71 1487222 Bytes 17/11/2008 19:39:05
                      AEHELP.DLL : 8.1.1.3 119157 Bytes 17/11/2008 19:38:07
                      AEGEN.DLL : 8.1.1.0 319859 Bytes 17/11/2008 19:38:00
                      AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 12:05:56
                      AECORE.DLL : 8.1.4.1 172405 Bytes 17/11/2008 19:37:38
                      AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 12:05:56
                      AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 10:40:05
                      AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 11:28:01
                      AVREP.DLL : 8.0.0.2 98344 Bytes 17/11/2008 19:37:29
                      AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 13:26:40
                      AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 10:29:23
                      AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 14:27:49
                      SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 19:28:02
                      SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 14:49:40
                      NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 14:05:10
                      RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 15:48:07
                      RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 15:34:37

                      Configuration settings for the scan:
                      Jobname..........................: Local Hard Disks
                      Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
                      Logging..........................: low
                      Primary action...................: interactive
                      Secondary action.................: ignore
                      Scan master boot sector..........: on
                      Scan boot sector.................: on
                      Boot sectors.....................: C:,
                      Process scan.....................: on
                      Scan registry....................: on
                      Search for rootkits..............: off
                      Scan all files...................: Intelligent file selection
                      Scan archives....................: on
                      Recursion depth..................: 20
                      Smart extensions.................: on
                      Macro heuristic..................: on
                      File heuristic...................: medium

                      Start of the scan: lundi 17 novembre 2008 19:49

                      The scan of running processes will be started
                      Scan process 'avscan.exe' - '1' Module(s) have been scanned
                      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                      Scan process 'wlcomm.exe' - '1' Module(s) have been scanned
                      Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                      Scan process 'avguard.exe' - '1' Module(s) have been scanned
                      Scan process 'sched.exe' - '1' Module(s) have been scanned
                      Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
                      Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                      Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                      Scan process 'wltuser.exe' - '1' Module(s) have been scanned
                      Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
                      Scan process 'IEUM.exe' - '1' Module(s) have been scanned
                      Scan process 'UMAService.exe' - '1' Module(s) have been scanned
                      Scan process 'realsched.exe' - '1' Module(s) have been scanned
                      Scan process 'VM305_STI.EXE' - '1' Module(s) have been scanned
                      Scan process 'explorer.exe' - '1' Module(s) have been scanned
                      Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
                      Scan process 'WasherSvc.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'lsass.exe' - '1' Module(s) have been scanned
                      Scan process 'services.exe' - '1' Module(s) have been scanned
                      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                      Scan process 'csrss.exe' - '1' Module(s) have been scanned
                      Scan process 'smss.exe' - '1' Module(s) have been scanned
                      31 processes with 31 modules were scanned

                      Starting master boot sector scan:
                      Master boot sector HD0
                      [INFO] No virus was found!

                      Start scanning boot sectors:
                      Boot sector 'C:\'
                      [INFO] No virus was found!

                      Starting to scan the registry.
                      The registry was scanned ( '46' files ).

                      Starting the file scan:

                      Begin scan in 'C:\'
                      C:\autorun.inf
                      [DETECTION] Is the TR/Autorun.596 Trojan
                      [NOTE] The file was deleted!
                      C:\pagefile.sys
                      [WARNING] The file could not be opened!
                      C:\Documents and Settings\WINXP\Bureau\tlbat\nab\www.tlbat.com\up_file\boom.zip
                      [0] Archive type: ZIP
                      --> boom/boom/joke/zwaban.zip
                      [1] Archive type: ZIP
                      --> PIC.exe
                      [DETECTION] Contains recognition pattern of the Padania virus
                      [NOTE] The file was deleted!

                      End of the scan: lundi 17 novembre 2008 22:23
                      Used time: 2:34:31 Hour(s)

                      The scan has been done completely.

                      3077 Scanning directories
                      101239 Files were scanned
                      2 viruses and/or unwanted programs were found
                      0 Files were classified as suspicious:
                      2 files were deleted
                      0 files were repaired
                      0 files were moved to quarantine
                      0 files were renamed
                      1 Files cannot be scanned
                      101236 Files not concerned
                      1379 Archives were scanned
                      1 Warnings
                      2 Notes

                      Avira AntiVir Personal
                      Report file date: lundi 17 novembre 2008 19:49

                      Scanning for 1038808 virus strains and unwanted programs.

                      Licensed to: Avira AntiVir PersonalEdition Classic
                      Serial number: 0000149996-ADJIE-0001
                      Platform: Windows XP
                      Windows version: (Service Pack 2) [5.1.2600]
                      Boot mode: Normally booted
                      Username: WINXP
                      Computer name: WINKILLERXP

                      Version information:
                      BUILD.DAT : 8.2.0.336 16933 Bytes 30/10/2008 11:40:00
                      AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 10:57:53
                      AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 09:56:40
                      LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 14:44:19
                      LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 09:58:52
                      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 19:35:53
                      ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 09/11/2008 19:37:01
                      ANTIVIR2.VDF : 7.1.0.89 221184 Bytes 16/11/2008 19:37:20
                      ANTIVIR3.VDF : 7.1.0.97 45056 Bytes 17/11/2008 19:37:26
                      Engineversion : 8.2.0.31
                      AEVDF.DLL : 8.1.0.6 102772 Bytes 14/10/2008 12:05:56
                      AESCRIPT.DLL : 8.1.1.15 332156 Bytes 17/11/2008 19:40:12
                      AESCN.DLL : 8.1.1.5 123251 Bytes 17/11/2008 19:39:49
                      AERDL.DLL : 8.1.1.3 438645 Bytes 17/11/2008 19:39:43
                      AEPACK.DLL : 8.1.3.4 393591 Bytes 17/11/2008 19:39:29
                      AEOFFICE.DLL : 8.1.0.30 196986 Bytes 17/11/2008 19:39:12
                      AEHEUR.DLL : 8.1.0.71 1487222 Bytes 17/11/2008 19:39:05
                      AEHELP.DLL : 8.1.1.3 119157 Bytes 17/11/2008 19:38:07
                      AEGEN.DLL : 8.1.1.0 319859 Bytes 17/11/2008 19:38:00
                      AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 12:05:56
                      AECORE.DLL : 8.1.4.1 172405 Bytes 17/11/2008 19:37:38
                      AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 12:05:56
                      AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 10:40:05
                      AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 11:28:01
                      AVREP.DLL : 8.0.0.2 98344 Bytes 17/11/2008 19:37:29
                      AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 13:26:40
                      AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 10:29:23
                      AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 14:27:49
                      SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 19:28:02
                      SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 14:49:40
                      NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 14:05:10
                      RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 15:48:07
                      RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 15:34:37

                      Configuration settings for the scan:
                      Jobname..........................: Local Hard Disks
                      Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
                      Logging..........................: low
                      Primary action...................: interactive
                      Secondary action.................: ignore
                      Scan master boot sector..........: on
                      Scan boot sector.................: on
                      Boot sectors.....................: C:,
                      Process scan.....................: on
                      Scan registry....................: on
                      Search for rootkits..............: off
                      Scan all files...................: Intelligent file selection
                      Scan archives....................: on
                      Recursion depth..................: 20
                      Smart extensions.................: on
                      Macro heuristic..................: on
                      File heuristic...................: medium

                      Start of the scan: lundi 17 novembre 2008 19:49

                      The scan of running processes will be started
                      Scan process 'avscan.exe' - '1' Module(s) have been scanned
                      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                      Scan process 'wlcomm.exe' - '1' Module(s) have been scanned
                      Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                      Scan process 'avguard.exe' - '1' Module(s) have been scanned
                      Scan process 'sched.exe' - '1' Module(s) have been scanned
                      Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
                      Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                      Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                      Scan process 'wltuser.exe' - '1' Module(s) have been scanned
                      Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
                      Scan process 'IEUM.exe' - '1' Module(s) have been scanned
                      Scan process 'UMAService.exe' - '1' Module(s) have been scanned
                      Scan process 'realsched.exe' - '1' Module(s) have been scanned
                      Scan process 'VM305_STI.EXE' - '1' Module(s) have been scanned
                      Scan process 'explorer.exe' - '1' Module(s) have been scanned
                      Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
                      Scan process 'WasherSvc.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'lsass.exe' - '1' Module(s) have been scanned
                      Scan process 'services.exe' - '1' Module(s) have been scanned
                      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                      Scan process 'csrss.exe' - '1' Module(s) have been scanned
                      Scan process 'smss.exe' - '1' Module(s) have been scanned
                      31 processes with 31 modules were scanned

                      Starting master boot sector scan:
                      Master boot sector HD0
                      [INFO] No virus was found!

                      Start scanning boot sectors:
                      Boot sector 'C:\'
                      [INFO] No virus was found!

                      Starting to scan the registry.
                      The registry was scanned ( '46' files ).

                      Starting the file scan:

                      Begin scan in 'C:\'
                      C:\autorun.inf
                      [DETECTION] Is the TR/Autorun.596 Trojan
                      [NOTE] The file was deleted!
                      C:\pagefile.sys
                      [WARNING] The file could not be opened!
                      C:\Documents and Settings\WINXP\Bureau\tlbat\nab\www.tlbat.com\up_file\boom.zip
                      [0] Archive type: ZIP
                      --> boom/boom/joke/zwaban.zip
                      [1] Archive type: ZIP
                      --> PIC.exe
                      [DETECTION] Contains recognition pattern of the Padania virus
                      [NOTE] The file was deleted!

                      End of the scan: lundi 17 novembre 2008 22:23
                      Used time: 2:34:31 Hour(s)

                      The scan has been done completely.

                      3077 Scanning directories
                      101239 Files were scanned
                      2 viruses and/or unwanted programs were found
                      0 Files were classified as suspicious:
                      2 files were deleted
                      0 files were repaired
                      0 files were moved to quarantine
                      0 files were renamed
                      1 Files cannot be scanned
                      101236 Files not concerned
                      1379 Archives were scanned
                      1 Warnings
                      2 Notes

                      Report file date: lundi 17 novembre 2008 19:49

                      Scanning for 1038808 virus strains and unwanted programs.

                      Licensed to: Avira AntiVir PersonalEdition Classic
                      Serial number: 0000149996-ADJIE-0001
                      Platform: Windows XP
                      Windows version: (Service Pack 2) [5.1.2600]
                      Boot mode: Normally booted
                      Username: WINXP
                      Computer name: WINKILLERXP

                      Version information:
                      BUILD.DAT : 8.2.0.336 16933 Bytes 30/10/2008 11:40:00
                      AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 10:57:53
                      AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 09:56:40
                      LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 14:44:19
                      LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 09:58:52
                      ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 19:35:53
                      ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 09/11/2008 19:37:01
                      ANTIVIR2.VDF : 7.1.0.89 221184 Bytes 16/11/2008 19:37:20
                      ANTIVIR3.VDF : 7.1.0.97 45056 Bytes 17/11/2008 19:37:26
                      Engineversion : 8.2.0.31
                      AEVDF.DLL : 8.1.0.6 102772 Bytes 14/10/2008 12:05:56
                      AESCRIPT.DLL : 8.1.1.15 332156 Bytes 17/11/2008 19:40:12
                      AESCN.DLL : 8.1.1.5 123251 Bytes 17/11/2008 19:39:49
                      AERDL.DLL : 8.1.1.3 438645 Bytes 17/11/2008 19:39:43
                      AEPACK.DLL : 8.1.3.4 393591 Bytes 17/11/2008 19:39:29
                      AEOFFICE.DLL : 8.1.0.30 196986 Bytes 17/11/2008 19:39:12
                      AEHEUR.DLL : 8.1.0.71 1487222 Bytes 17/11/2008 19:39:05
                      AEHELP.DLL : 8.1.1.3 119157 Bytes 17/11/2008 19:38:07
                      AEGEN.DLL : 8.1.1.0 319859 Bytes 17/11/2008 19:38:00
                      AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 12:05:56
                      AECORE.DLL : 8.1.4.1 172405 Bytes 17/11/2008 19:37:38
                      AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 12:05:56
                      AVWINLL.DLL : 1.0.0.12 15105 Bytes 09/07/2008 10:40:05
                      AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 11:28:01
                      AVREP.DLL : 8.0.0.2 98344 Bytes 17/11/2008 19:37:29
                      AVREG.DLL : 8.0.0.1 33537 Bytes 09/05/2008 13:26:40
                      AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 10:29:23
                      AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 14:27:49
                      SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 19:28:02
                      SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 14:49:40
                      NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 14:05:10
                      RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 15:48:07
                      RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 15:34:37

                      Configuration settings for the scan:
                      Jobname..........................: Local Hard Disks
                      Configuration file...............: c:\program files\avira\antivir personaledition classic\alldiscs.avp
                      Logging..........................: low
                      Primary action...................: interactive
                      Secondary action.................: ignore
                      Scan master boot sector..........: on
                      Scan boot sector.................: on
                      Boot sectors.....................: C:,
                      Process scan.....................: on
                      Scan registry....................: on
                      Search for rootkits..............: off
                      Scan all files...................: Intelligent file selection
                      Scan archives....................: on
                      Recursion depth..................: 20
                      Smart extensions.................: on
                      Macro heuristic..................: on
                      File heuristic...................: medium

                      Start of the scan: lundi 17 novembre 2008 19:49

                      The scan of running processes will be started
                      Scan process 'avscan.exe' - '1' Module(s) have been scanned
                      Scan process 'avcenter.exe' - '1' Module(s) have been scanned
                      Scan process 'avgnt.exe' - '1' Module(s) have been scanned
                      Scan process 'wlcomm.exe' - '1' Module(s) have been scanned
                      Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
                      Scan process 'avguard.exe' - '1' Module(s) have been scanned
                      Scan process 'sched.exe' - '1' Module(s) have been scanned
                      Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
                      Scan process 'WLLoginProxy.exe' - '1' Module(s) have been scanned
                      Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
                      Scan process 'wltuser.exe' - '1' Module(s) have been scanned
                      Scan process 'IEXPLORE.EXE' - '1' Module(s) have been scanned
                      Scan process 'IEUM.exe' - '1' Module(s) have been scanned
                      Scan process 'UMAService.exe' - '1' Module(s) have been scanned
                      Scan process 'realsched.exe' - '1' Module(s) have been scanned
                      Scan process 'VM305_STI.EXE' - '1' Module(s) have been scanned
                      Scan process 'explorer.exe' - '1' Module(s) have been scanned
                      Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
                      Scan process 'WasherSvc.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'svchost.exe' - '1' Module(s) have been scanned
                      Scan process 'lsass.exe' - '1' Module(s) have been scanned
                      Scan process 'services.exe' - '1' Module(s) have been scanned
                      Scan process 'winlogon.exe' - '1' Module(s) have been scanned
                      Scan process 'csrss.exe' - '1' Module(s) have been scanned
                      Scan process 'smss.exe' - '1' Module(s) have been scanned
                      31 processes with 31 modules were scanned

                      Starting master boot sector scan:
                      Master boot sector HD0
                      [INFO] No virus was found!

                      Start scanning boot sectors:
                      Boot sector 'C:\'
                      [INFO] No virus was found!

                      Starting to scan the registry.
                      The registry was scanned ( '46' files ).

                      Starting the file scan:

                      Begin scan in 'C:\'
                      C:\autorun.inf
                      [DETECTION] Is the TR/Autorun.596 Trojan
                      [NOTE] The file was deleted!
                      C:\pagefile.sys
                      [WARNING] The file could not be opened!
                      C:\Documents and Settings\WINXP\Bureau\tlbat\nab\www.tlbat.com\up_file\boom.zip
                      [0] Archive type: ZIP
                      --> boom/boom/joke/zwaban.zip
                      [1] Archive type: ZIP
                      --> PIC.exe
                      [DETECTION] Contains recognition pattern of the Padania virus
                      [NOTE] The file was deleted!

                      End of the scan: lundi 17 novembre 2008 22:23
                      Used time: 2:34:31 Hour(s)

                      The scan has been done completely.

                      3077 Scanning directories
                      101239 Files were scanned
                      2 viruses and/or unwanted programs were found
                      0 Files were classified as suspicious:
                      2 files were deleted
                      0 files were repaired
                      0 files were moved to quarantine
                      0 files were renamed
                      1 Files cannot be scanned
                      101236 Files not concerned
                      1379 Archives were scanned
                      1 Warnings
                      2 Notes

                      2-rapport Hijackthis

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 11:29:15, on 18/11/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\Program Files\Webroot\Washer\WasherSvc.exe
                      C:\WINDOWS\system32\wscntfy.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\WINDOWS\VM305_STI.EXE
                      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                      C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                      C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
                      C:\Program Files\Webroot\Washer\wwDisp.exe
                      C:\WINDOWS\system32\wuauclt.exe
                      C:\Program Files\LG Electronics\Modem USB LG Electronics\IEUM.exe
                      C:\program files\internet explorer\iexplore.exe
                      C:\Program Files\Windows Live\Toolbar\wltuser.exe
                      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      C:\WINDOWS\system32\NOTEPAD.exe
                      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com/spresults.aspx
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?fdr=lc&toHttps=1&redig=FA6AD360E0BE4C719380F8C470A3D3A8
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10587&gct=&gc=1&q=
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://home.sweetim.com/
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=10587&gct=&gc=1&q=
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.bing.com/spresults.aspx
                      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=10587&gct=&gc=1&q=%s
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
                      O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
                      O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
                      O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
                      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.509.5470\swg.dll
                      O2 - BHO: Windows Live Toolbar Beta - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                      O3 - Toolbar: &Windows Live Toolbar Beta - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                      O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
                      O4 - HKLM\..\Run: [BigDog305] C:\WINDOWS\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)
                      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                      O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
                      O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
                      O4 - HKLM\..\RunOnce: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfpconfg.exe" -z -o
                      O4 - HKCU\..\Run: [UMService] C:\Program Files\LG Electronics\Modem USB LG Electronics\UMAService.exe
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [amva] C:\WINDOWS\system32\amvo.exe
                      O4 - HKCU\..\RunOnce: [Index Washer] C:\Program Files\Webroot\Washer\WashIdx.exe "WINXP"
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-20\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\S-1-5-18\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - HKUS\.DEFAULT\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'Default user')
                      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
                      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                      O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                      O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
                      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
                      O17 - HKLM\System\CCS\Services\Tcpip\..\{985C9893-8F51-4CA5-82C9-6FF34E5FC9EF}: NameServer = 192.168.50.55 196.12.209.6
                      O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll C:\WINDOWS\system32\cssdll32.dll
                      O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                      O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                      O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe (file missing)
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                      O23 - Service: Window Washer Engine (wwEngineSvc) - Webroot Software, Inc. - C:\Program Files\Webroot\Washer\WasherSvc.exe
                  • 1
                  • 2