Trojans

Résolu
Bonjour,j'ai fait une analyse bitdefender voici le rapport:

//-----------------------------------------------------------------
//
// ProduitBitDefender Antivirus Plus v10
// Produit10.2
//
// Créé le: 01/04/2009 21:27:27
//
//-----------------------------------------------------------------

Statistiques

Chemin cible: C:\
D:\
E:\
F:\
G:\
I:\
Dossiers : 9669
Fichiers : 60133
Processus Mémoire analysés : 0
Archives : 78
Fichiers enpaquetés : 3157
Virus trouvés : 2
Fichiers infectés : 4
Processus Mémoire infectés : 0
Fichiers suspects : 0
Alertes : 0
Fichiers désinfectés : 0
Fichiers effacés : 0
Fichiers déplacés : 4
Erreurs I/O : 14
Temps d'analyse :=00:31:17
Fichiers/seconde :32

Statistiques Spywares

Registres analysés : 0
Registres infectés : 0
Cookies analysés : 0
Cookies infectés : 0
Fichiers spyware infectés : 0
Menaces Spyware détectées : 0

Définitions virus : 2816251
Plugins d'analyse : 17
Plugins archives : 45
Plug-ins décompression : 7
Plug-ins messagerie : 6
Plug-ins système : 5

Options d'analyse

Détection
[X] Analyser le secteur de boot
[X] Processus mémoire
[ ] Analyser les archives
[X] Analyser les fichiers enpaquetés
[X] Analyser la messagerie

Masque fichiers
[X] Programmes
[ ] Tous les fichiers
[ ] Extensions définies par l'utilisateur:
[ ] Exclure les extensions: ;

Action

Objets infectés
[ ] Ignorer
[X] Désinfecter
[ ] Effacer
[ ] Mettre en quarantaine
[ ] Demander l'action

Seconde action
[ ] Ignorer
[ ] Effacer
[X] Mettre en quarantaine
[ ] Demander l'action

Options d'analyse
[X] Activer les alertes
[ ] Activer l'heuristique
[ ] Afficher tous les fichiers dans le journal
[X] Fichier journal: C:\Documents and Settings\All Users\Application Data\Bitdefender\Desktop\Profiles\Logs\full_scan\1238614047.log

Options d'analyse Spyware

[X] Analyse contre les risques non-viraux
[ ] Ecarter de l'analyse les dialers et les applications
[X] Clés de registres
[X] Cookies

Résumé:

C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\C70VIZC3\count[1].htm Infecté: Exploit.HTML.Iframe.G
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\C70VIZC3\count[1].htm Désinfection impossible
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\C70VIZC3\count[1].htm Déplacé
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\C70VIZC3\count[3].htm Infecté: Exploit.HTML.Iframe.G
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\C70VIZC3\count[3].htm Désinfection impossible
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\C70VIZC3\count[3].htm Déplacé
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\C70VIZC3\index[1].htm Infecté: Trojan.JS.PYC
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\C70VIZC3\index[1].htm Désinfection impossible
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\C70VIZC3\index[1].htm Déplacé
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\YV4JB4P0\index[1].htm Infecté: Trojan.JS.PYC
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\YV4JB4P0\index[1].htm Désinfection impossible
C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\YV4JB4P0\index[1].htm Déplacé
ensuite j'ai fait une analyse thisjackis:
ogfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:09:41, on 02/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Softwin\BitDefender10\bdagent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Microsoft ActiveSync\wcescomm.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Fichiers communs\Adobe\Updater5\AdobeUpdater.exe
C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
C:\Program Files\Softwin\BitDefender10\vsserv.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Softwin\BitDefender10\bdmcon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Windows Live\Photo Gallery\WLXQuickTimeControlHost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\morgane gentric\Bureau\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Desktop Manager 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - D:\Alcohol 120\StarWind\StarWindServiceAE.exe (file missing)
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - Unknown owner - C:\WINDOWS\System32\TuneUpDefragService.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
O24 - Desktop Component 0: (no name) - https://images.king-jouet.com/4/GU109377_4.jpg

--
End of file - 9951 bytes

je ne sais pas comment faire pour supprimer ces trojans
merci de votre aide
Configuration: Windows XP
Firefox 3.0.8

37 réponses

Résumé de la discussion

Un utilisateur signale une détection par BitDefender et une analyse HijackThis sur Windows XP indiquant des infections Exploit.HTML.Iframe.G et Trojan.JS.PYC, avec des désinfections impossibles et des fichiers déplacés. Plusieurs éléments infectés apparaissent dans les fichiers temporaires du navigateur et BitDefender ne peut pas tous les désinfecter, ce qui invite à mettre en quarantaine ou déplacer les objets problématiques et à nettoyer temporaires. Des mesures complémentaires consistent à examiner les éléments listés par HijackThis, désactiver ou supprimer ceux non reconnus, puis redémarrer en mode sans échec et relancer un scan complet. En dernier recours, sauvegarder les données critiques et créer un point de restauration avant toute manipulation, puis envisager une réinstallation propre ou l'aide d'un spécialiste si les infections réapparaissent.

Bobot (l’IA à votre service)
  1. bonjour :

    Télécharge Superantispyware (SAS)

    Choisis "enregistrer" et enregistre-le sur ton bureau.

    Double-clique sur l'icône d'installation qui vient de se créer et suis les instructions.

    Créé une icône sur le bureau.

    Double-clique sur l'icône de SAS (une tête dans un cercle rouge barré) pour le lancer.

    - Si l'outil te demande de mettre à jour le programme ("update the program definitions", clique sur yes.
    - Sous Configuration and Preferences, clique sur le bouton "Preferences"
    - Clique sur l'onglet "Scanning Control "
    - Dans "Scanner Options ", assure toi que la case devant lles lignes suivantes est cochée :

    Close browsers before scanning
    Scan for tracking cookies
    Terminate memory threats before quarantining
    - Laisse les autres lignes décochées.

    - Clique sur le bouton "Close" pour quitter l'écran du centre de contrôle.

    - Dans la fenêtre principale, clique, dans "Scan for Harmful Software", sur "Scan your computer".

    Dans la colonne de gauche, coche C:\Fixed Drive.

    Dans la colonne de droite, sous "Complete scan", clique sur "Perform Complete Scan"

    Clique sur "next" pour lancer le scan. Patiente pendant la durée du scan.

    A la fin du scan, une fenêtre de résultats s'ouvre . Clique sur OK.

    Assure toi que toutes les lignes de la fenêtre blanche sont cochées et clique sur "Next".

    Tout ce qui a été trouvé sera mis en quarantaine. S'il t'es demandé de redémarrer l'ordi ("reboot"), clique sur Yes.

    Pour recopier les informations sur le forum, fais ceci :

    - après le redémarrage de l'ordi, double-clique sur l'icône pour lancer SAS.
    - Clique sur "Preferences" puis sur l'onglet "Statistics/Logs ".
    - Dans "scanners logs", double-clique sur SUPERAntiSpyware Scan Log.

    - Le rapport va s'ouvrir dans ton éditeur de texte par défaut.

    - Copie son contenu dans ta réponse.

    Regarde bien le tuto SUPERAntiSpyware il est très bien expliqué.
    0
    1. je l'ais télécharger et installer sur le bureau et quand je l installe ça me dit error 1327 invalid drive
      0
      1. ok explique ton souci de puis le debut

        pourquoi as-tu lance L analmyse ?

        cmommment reagit le pc car là on ne sait meme pas quel genre d'aide il te faut

        Merci
        0
        1. j'ai lancer une analyse hier matin avec bitdefender parce que depuis quelques temps ca rame et il a trouvé des trojans désinfection impossible, je ne sais pas comment les supprimer
          0
          1. mon mari a lancer une analyse avec spyware terminator mais elle n est pas encore terminée
            0
            1. ok bien nous verrons ce que ca a donné avec Spyware Terminator et eventuellement passerons a plus "costaud"
              0
              1. l'analyse en ai à 75% dès que c'est terminé je t'envois le rapport.
                merci pour ton aide,par contre si tu veux voici mon mail ce sera plus commode
                morgane.gentric@hotmail.fr
                0
                1. pour toi ce sera plus commode mais pour moi.....non

                  Je préfère que nous continuions ici si tu peux comprendre Merci
                  0
                  1. oui oui ok pas de soucis je comprends
                    0
                    1. un conseil aussi evite de balancer ton adresse msn sur les forums

                      tu vas te ramener tous les spammeurs de la terre
                      0
                      1. tout le monde voit nos conversations là?
                        0
                        1. la terre entière madame

                          nous sommes quand même sur un des plus grands sites d'entraide francophone du monde !!

                          :)
                          0
                          1. wouhaaa!!!!!ok la derniere fois mon mari avait donné notre adresse à quelqu'un qui nous aidait sur le forum.
                            0
                            1. re, avec spyware terminator il n'y a aucun objet detecter
                              0
                              1. ok alors un dignoostic general :

                                Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

                                ! Déconnecte toi et ferme toutes tes applications en cours !

                                Double-clique sur " RSIT.exe " pour le lancer .

                                -> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

                                * Devant l'option "List files/folders created ..." , tu choisis : 2 months

                                * clique ensuite sur " Continue " pour lancer l'analyse ...

                                -> laisse faire le scan et ne touche pas au PC ...

                                Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

                                Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

                                Important : poste un rapport, puis l'autre dans la réponse suivante
                                Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum

                                ( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
                                0
                                1. Logfile of random's system information tool 1.06 (written by random/random)
                                  Run by morgane gentric at 2009-04-03 14:30:29
                                  Microsoft Windows XP Édition familiale Service Pack 3
                                  System drive C: has 2 GB (8%) free of 20 GB
                                  Total RAM: 478 MB (41% free)

                                  Logfile of Trend Micro HijackThis v2.0.2
                                  Scan saved at 14:31:02, on 03/04/2009
                                  Platform: Windows XP SP3 (WinNT 5.01.2600)
                                  MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
                                  Boot mode: Normal

                                  Running processes:
                                  C:\WINDOWS\System32\smss.exe
                                  C:\WINDOWS\system32\winlogon.exe
                                  C:\WINDOWS\system32\services.exe
                                  C:\WINDOWS\system32\lsass.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Ahead\InCD\InCDsrv.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\WINDOWS\system32\spoolsv.exe
                                  C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                                  C:\WINDOWS\System32\svchost.exe
                                  C:\Program Files\Java\jre6\bin\jqs.exe
                                  C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                                  C:\WINDOWS\Explorer.EXE
                                  C:\Program Files\Spyware Terminator\sp_rsser.exe
                                  C:\WINDOWS\system32\svchost.exe
                                  C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                                  C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                                  C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
                                  C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                                  C:\Program Files\Softwin\BitDefender10\bdmcon.exe
                                  C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
                                  C:\Program Files\Softwin\BitDefender10\bdagent.exe
                                  C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                  C:\WINDOWS\system32\ctfmon.exe
                                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                  C:\Program Files\Microsoft ActiveSync\wcescomm.exe
                                  C:\PROGRA~1\MI3AA1~1\rapimgr.exe
                                  C:\Program Files\Canon\CAL\CALMAIN.exe
                                  C:\Program Files\Softwin\BitDefender10\vsserv.exe
                                  C:\Program Files\Windows Live\Photo Gallery\WLXQuickTimeControlHost.exe
                                  C:\Program Files\Windows Live\Contacts\wlcomm.exe
                                  C:\WINDOWS\system32\msiexec.exe
                                  C:\Documents and Settings\morgane gentric\Bureau\RSIT.exe
                                  C:\Documents and Settings\morgane gentric\Bureau\morgane gentric.exe

                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60076
                                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60076
                                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                                  O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                                  O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                                  O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                                  O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                                  O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                  O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                  O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
                                  O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
                                  O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                                  O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                  O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                                  O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
                                  O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                                  O4 - HKLM\..\Run: [BDMCon] "C:\Program Files\Softwin\BitDefender10\bdmcon.exe" /reg
                                  O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
                                  O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\Softwin\BitDefender10\bdagent.exe"
                                  O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.EXE /auto
                                  O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                                  O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
                                  O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                                  O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                                  O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                                  O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                                  O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                  O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                                  O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                                  O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                                  O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
                                  O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
                                  O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
                                  O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll
                                  O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                                  O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                                  O16 - DPF: {0E8D0700-75DF-11D3-8B4A-0008C7450C4A} (DjVuCtl Class) - http://downloadcenter.samsung.com/content/common/cab/DjVuControlLite_EN.cab
                                  O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
                                  O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/MSNPUpld.cab
                                  O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
                                  O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
                                  O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Program Files\Fichiers communs\Softwin\BitDefender Scan Server\bdss.exe
                                  O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
                                  O23 - Service: Google Desktop Manager 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                  O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                                  O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                                  O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                                  O23 - Service: InCD Helper (read only) (InCDsrvR) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                                  O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                                  O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                                  O23 - Service: BitDefender Desktop Update Service (LIVESRV) - SOFTWIN S.R.L. - C:\Program Files\Fichiers communs\Softwin\BitDefender Update Service\livesrv.exe
                                  O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                                  O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
                                  O23 - Service: StarWind AE Service (StarWindServiceAE) - Unknown owner - D:\Alcohol 120\StarWind\StarWindServiceAE.exe (file missing)
                                  O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - Unknown owner - C:\WINDOWS\System32\TuneUpDefragService.exe (file missing)
                                  O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                                  O23 - Service: BitDefender Virus Shield (VSSERV) - SOFTWIN S.R.L. - C:\Program Files\Softwin\BitDefender10\vsserv.exe
                                  O23 - Service: BitDefender Communicator (XCOMM) - Softwin - C:\Program Files\Fichiers communs\Softwin\BitDefender Communicator\xcommsvr.exe
                                  O24 - Desktop Component 0: (no name) - https://images.king-jouet.com/4/GU109377_4.jpg
                                  0
                                  1. ---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

                                    ---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

                                    ---> Double-clique sur OTMoveIt3.exe afin de le lancer.

                                    ---> Copie (Ctrl+C) le texte suivant ci-dessous :



                                    :processes
                                    explorer.exe

                                    :files
                                    C:\Poker
                                    C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357}

                                    :reg
                                    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
                                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                                    "MSConfig"=-
                                    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
                                    "msnmsgr"=-
                                    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
                                    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Amazing3DAquariumWallpaper]
                                    [-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EleFunAnimatedWallpaper]
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                    "AppInit_DLLS"=""
                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{4F07DA45-8170-4859-9B5F-037EF2970034}]
                                    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                                    "C:\WINDOWS\system32\drivers\svchost.exe"="C:\WINDOWS\system32\drivers\svchost.exe:*:Disabled:svchost"
                                    "C:\WINDOWS\system32\drivers\svchost.exe"=-

                                    :commands
                                    [purity]
                                    [emptytemp]
                                    [start explorer]
                                    [reboot]



                                    ---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

                                    ---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

                                    Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                                    Accepte en cliquant sur YES.

                                    ---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
                                    Le nom du rapport correspond au moment de sa création : date_heure.log
                                    0
                                    1. ========== PROCESSES ==========
                                      Process explorer.exe killed successfully.
                                      ========== FILES ==========
                                      File/Folder C:\Poker not found.
                                      File/Folder C:\ProgramData\{55A29068-F2CE-456C-9148-C869879E2357} not found.
                                      ========== REGISTRY ==========
                                      Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\\ deleted successfully.
                                      Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MSConfig deleted successfully.
                                      Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr deleted successfully.
                                      Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater\\ deleted successfully.
                                      Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Amazing3DAquariumWallpaper\\ deleted successfully.
                                      Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EleFunAnimatedWallpaper\\ deleted successfully.
                                      HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLS"|"" /E : value set successfully!
                                      HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\"C:\WINDOWS\system32\drivers\svchost.exe"|"C:\WINDOWS\system32\drivers\svchost.exe:*:Disabled:svchost" /E : value set successfully!
                                      Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\WINDOWS\system32\drivers\svchost.exe deleted successfully.
                                      ========== COMMANDS ==========
                                      File delete failed. C:\DOCUME~1\MORGAN~1\LOCALS~1\Temp\etilqs_rX6jEbtYyRQqtHl7m2Iy scheduled to be deleted on reboot.
                                      File delete failed. C:\DOCUME~1\MORGAN~1\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot.
                                      User's Temp folder emptied.
                                      User's Internet Explorer cache folder emptied.
                                      File delete failed. C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\G9URS34V\info[1].swf scheduled to be deleted on reboot.
                                      File delete failed. C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                                      User's Temporary Internet Files folder emptied.
                                      Local Service Temp folder emptied.
                                      File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                                      Local Service Temporary Internet Files folder emptied.
                                      Network Service Temp folder emptied.
                                      File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                                      Network Service Temporary Internet Files folder emptied.
                                      File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_734.dat scheduled to be deleted on reboot.
                                      Windows Temp folder emptied.
                                      Java cache emptied.
                                      File delete failed. C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
                                      File delete failed. C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
                                      File delete failed. C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
                                      File delete failed. C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
                                      File delete failed. C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
                                      File delete failed. C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\XUL.mfl scheduled to be deleted on reboot.
                                      FireFox cache emptied.
                                      Temp folders emptied.
                                      Explorer started successfully

                                      OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04032009_150024

                                      Files moved on Reboot...
                                      File C:\DOCUME~1\MORGAN~1\LOCALS~1\Temp\etilqs_rX6jEbtYyRQqtHl7m2Iy not found!
                                      C:\DOCUME~1\MORGAN~1\LOCALS~1\Temp\WCESLog.log moved successfully.
                                      File move failed. C:\Documents and Settings\morgane gentric\Local Settings\Temporary Internet Files\Content.IE5\G9URS34V\info[1].swf scheduled to be moved on reboot.
                                      File C:\WINDOWS\temp\Perflib_Perfdata_734.dat not found!
                                      C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\Cache\_CACHE_001_ moved successfully.
                                      C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\Cache\_CACHE_002_ moved successfully.
                                      C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\Cache\_CACHE_003_ moved successfully.
                                      C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\Cache\_CACHE_MAP_ moved successfully.
                                      C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\urlclassifier3.sqlite moved successfully.
                                      C:\Documents and Settings\morgane gentric\Local Settings\Application Data\Mozilla\Firefox\Profiles\ij0mxgc5.default\XUL.mfl moved successfully.
                                      0
                                      1. Maintenant redemarre et retente ICI
                                        0
                                        1. toujours la meme ,error 1327 invalid drive
                                          0
                                      • 1
                                      • 2