VIRUS et Autres

Résolu
Bonsoir,

Merci pour votre aide, à dévéroler en hors connexion un PC de bureau qui a besoin d'être alléger pour installer les sécurités. Ceci, avant de pouvoir le mettre sous connexion internet à fin, de faire toutes les MAJ (java, windows et etc...) et d'y mettre toutes les sécurités.
Le PC est un Acer, XP sp2, sans protection antivirus (juste le pare feu windows), internet explorer7.

Virus connus : vista antivirus 2008, winspywareprotect et très certainement registry helper. Très certainement d'autres aussi.
Il m'est impossible d'installer malwarebytes et smitfraudfix qui ont été télécharger par carte SD et ceci même en mode sans échec (pc très atteint ???).
J'ai passé un coup de Ccleaner qui a allégé un peu ainsi qu'une défragmentation.

Merci à tous de votre aide.

--
à+++ à tous
Stéphane
Configuration: Windows XP
Firefox 3.5.6

40 réponses

Résumé de la discussion

Un PC Acer sous Windows XP SP2, dépourvu d’antivirus et limité à un pare-feu Windows, doit être allégé hors connexion pour pouvoir installer les sécurités et effectuer les mises à jour ensuite. Plusieurs réponses recommandent des outils de désinfection hors ligne et en ligne, notamment MBAM, ESET Online Scanner et Combofix, suivis de scans en mode sans échec et de nettoyages ciblés. La démarche suggère aussi de supprimer les outils téléchargés, vérifier les points de restauration et, après remise en état, d’appliquer des mises à jour critiques, un antivirus à jour et un pare-feu configuré. En cas de doute persistant, des scans en ligne et l’analyse des rapports générés par les outils de désinfection permettent d’identifier les composants restants et d’orienter la remise en état sans compromettre la sécurité.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Salut steph77phane

    Télécharge combofix.exe (de sUBs) et mettre sur le bureau du PC malade :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

    Important Désactive ton Antivirus et antispyware avant le scan avec Combofix :
    https://forum.pcastuces.com/default.asp

    ==> Sauvegarde ton travail et ferme toutes les fenêtres actives, il peut y avoir un redémarrage du PC. Ne lance aucun programme tant que Combofix n’est pas fini. <==

    Double clique sur combofix.exe, clique sur OUI et valide par Entrée

    Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt

    Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure

    @++ :)
    1
    1. Bonsoir dédétraqué,

      Merci pour ton intervention.
      Je viens de fermer le pc en question et j'allais fermer celui ci, je m'occupe de tout ça dès demain matin et te posterai le rapport combofix.

      bonne nuit à toi et merci
      0
      1. Bonsoir dédétraqué,

        Merci encore pour ton intervention.
        Combofix ne veux pas démarrer non plus.
        je suis là, vers 9h15
        à+
        0
        1. Contributeur sécurité
          Salut steph77phane

          Supprime la version de Combofix que tu as télécharger.

          Faire un clic droit sur ce lien :

          http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

          Pour Internet Explorer

          - Choisi Enregistrer la cible sous ...

          Pour Firefox

          - Choisi Enregistrer la cible du lien sous...

          - Choisi le bureau comme lieu d'enregistrement

          - Donne lui ce nom bibite.exe clique sur Enregistrer

          Redémarre en mode sans échec :

          Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur

          Continu le reste de la procédure donné de Combofix

          @++ :)
          1
          1. bonjour dédétraqué,

            Je te fais ça cette après midi.

            Pour essayer de faire avancer les choses j'avais tenté, en mode normal et sans échec de lancer un : HJT, smitfraudix et combofix rien à faire.

            J'ai réussi à faire un usbfix en mode normal et un RSIT (en voici le rapport).

            --------------------------------------------------------------------------
            Logfile of random's system information tool 1.06 (written by random/random)
            Run by Administrateur at 2009-12-30 12:23:38
            Microsoft Windows XP Professionnel Service Pack 2
            System drive C: has 94 GB (81%) free of 116 GB
            Total RAM: 767 MB (84% free)

            HijackThis download failed

            ======Scheduled tasks folder======

            C:\WINDOWS\tasks\AppleSoftwareUpdate.job

            ======Registry dump======

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5AB8CFAF-2D09-4A74-B4BD-0B46D4C14F45}]
            C:\WINDOWS\system32\yaywuttr.dll [2008-07-10 318208]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}]
            C:\WINDOWS\system32\wvUkICtu.dll [2008-07-10 29568]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}]
            GamesBar - C:\Program Files\GamesBar\oberontb.dll [2007-06-19 380928]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
            SSVHelper Class - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll [2005-11-10 184423]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
            Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-05-11 2436160]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
            Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll [2008-05-15 325048]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fa73dea3-6c81-491b-b7b6-4a81403a1be7}]
            C:\WINDOWS\system32\hevyce.dll [2008-07-10 112256]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
            {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\WINDOWS\system32\eDStoolbar.dll [2006-03-08 106496]
            {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-05-11 2436160]
            {6F282B65-56BF-4BD1-A8B2-A4449A05863D} - GamesBar - C:\Program Files\GamesBar\oberontb.dll [2007-06-19 380928]

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
            "ehTray"=C:\WINDOWS\ehome\ehtray.exe [2005-09-29 67584]
            "LaunchApp"=Alaunch []
            "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2006-07-11 7626752]
            "nwiz"=nwiz.exe /install []
            "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2006-06-01 16208384]
            "SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
            "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
            "ntiMUI"=c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe [2005-05-11 45056]
            ""= []
            "IMJPMIG8.1"=C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE [2004-08-10 208952]
            "IMEKRMIG6.1"=C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE [2004-08-10 44032]
            "MSPY2002"=C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe [2004-08-10 59392]
            "PHIME2002ASync"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-10 455168]
            "PHIME2002A"=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE [2004-08-10 455168]
            "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2006-07-11 86016]
            "SunJavaUpdateSched"=C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe [2005-11-10 36975]
            "Acer Empowering Technology Monitor"=C:\WINDOWS\system32\SysMonitor.exe [2006-04-18 49152]
            "eDataSecurity Loader"=C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe [2006-03-17 345088]
            "eRecoveryService"=C:\Acer\Empowering Technology\eRecovery\eRAgent.exe [2006-06-01 413696]
            "HP Software Update"=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2005-05-11 49152]
            "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2007-04-27 282624]
            "SearchSettings"=C:\Program Files\Search Settings\SearchSettings.exe [2008-06-12 991584]
            "Antivirus"=C:\Program Files\VAV\vav.exe [2008-07-06 324608]
            "NPSStartup"= []

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
            ""= []

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
            "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-10 15360]

            C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage
            Acer Empowering Technology.lnk - C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
            Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
            HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvUkICtu]
            C:\WINDOWS\system32\wvUkICtu.dll [2008-07-10 29568]

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
            "{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}"=C:\WINDOWS\system32\wvUkICtu.dll [2008-07-10 29568]

            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
            "authentication packages"=msv1_0
            C:\WINDOWS\system32\yaywuttr

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
            "dontdisplaylastusername"=0
            "legalnoticecaption"=
            "legalnoticetext"=
            "shutdownwithoutlogon"=1
            "undockwithoutlogon"=1
            "InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
            "InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme

            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveTypeAutoRun"=145

            [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
            "NoDriveAutoRun"=
            "NoDriveTypeAutoRun"=
            "HonorAutoRunSetting"=

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
            "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
            "C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Enabled:hpqste08.exe"
            "C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe"
            "C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe"
            "C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe"
            "C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
            "C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
            "C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe"
            "C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe"
            "C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
            "C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
            "C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe"
            "C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
            "C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe"="C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
            "C:\WINDOWS\$NtUninstallKB883939$\TrackMania Nations ESWC\TmNationsESWC.exe"="C:\WINDOWS\$NtUninstallKB883939$\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
            "C:\WINDOWS\$NtUninstallKB888239$\TrackMania Nations ESWC\TmNationsESWC.exe"="C:\WINDOWS\$NtUninstallKB888239$\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
            "C:\Program Files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe"="C:\Program Files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:*:Enabled:Crysis_32_sp_demo"
            "C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsasvr.exe:*:Enabled:KTF MUSIC AoD Server"
            "C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe"="C:\Program Files\Samsung\Samsung New PC Studio\npsvsvr.exe:*:Enabled:KTF MUSIC VoD Server"
            "C:\Documents and Settings\ \Local Settings\Temp\7zS4E.tmp\SymNRT.exe"="C:\Documents and Settings\ \Local Settings\Temp\7zS4E.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool"
            "C:\Documents and Settings\ \Local Settings\Temp\7zS50.tmp\SymNRT.exe"="C:\Documents and Settings\ \Local Settings\Temp\7zS50.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool"
            "C:\Documents and Settings\ \Local Settings\Temp\7zS52.tmp\SymNRT.exe"="C:\Documents and Settings\ \Local Settings\Temp\7zS52.tmp\SymNRT.exe:*:Enabled:Norton Removal Tool"

            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
            "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

            ======List of files/folders created in the last 3 months======

            2096-11-07 00:49:16 ----A---- C:\WINDOWS\system32\MRT.exe
            2009-12-30 12:23:05 ----RASHD---- C:\autorun.inf
            2009-12-30 12:06:14 ----A---- C:\UsbFix.txt
            2009-12-30 12:05:48 ----A---- C:\WINDOWS\SchedLgU.Txt
            2009-12-30 12:00:35 ----A---- C:\WINDOWS\ntbtlog.txt
            2009-12-30 11:02:04 ----D---- C:\UsbFix
            2009-12-30 10:45:10 ----D---- C:\Program Files\trend micro
            2009-12-30 10:45:09 ----D---- C:\rsit
            2009-12-30 00:29:57 ----A---- C:\WINDOWS\system32\RNAPH.DLL
            2009-12-30 00:29:56 ----A---- C:\WINDOWS\system32\SMMSCRPT.DLL
            2009-12-30 00:24:37 ----D---- C:\WINDOWS\Cegetel
            2009-12-30 00:19:33 ----D---- C:\Program Files\CEGETEL
            2009-12-29 05:52:12 ----D---- C:\Program Files\Sécurité PC
            2009-12-06 10:19:37 ----A---- C:\WINDOWS\system32\xinput1_1.dll
            2009-12-06 10:19:36 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
            2009-12-06 10:19:25 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
            2009-12-06 10:19:25 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
            2009-12-06 10:19:25 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
            2009-12-06 10:19:24 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
            2009-12-06 10:19:23 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
            2009-12-06 10:19:22 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
            2009-12-06 10:19:21 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
            2009-12-06 10:19:21 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
            2009-12-06 10:19:20 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
            2009-12-06 10:19:17 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
            2009-12-06 10:14:47 ----D---- C:\Program Files\Empire Interactive
            2009-11-21 03:36:27 ----A---- C:\WINDOWS\ModemLog_SAMSUNG USB Mobile Modem #2.txt
            2009-11-17 07:13:44 ----A---- C:\WINDOWS\ModemLog_SAMSUNG USB Mobile Modem.txt
            2009-11-17 07:12:49 ----D---- C:\Documents and Settings\All Users\Application Data\PC Suite
            2009-11-17 07:11:53 ----A---- C:\WINDOWS\system32\nmwcdcls.dll
            2009-11-17 07:10:42 ----D---- C:\WINDOWS\system32\Samsung_USB_Drivers
            2009-11-17 07:10:32 ----A---- C:\WINDOWS\system32\FsUsbExService.Exe
            2009-11-17 07:10:32 ----A---- C:\WINDOWS\system32\FsUsbExDevice.Dll
            2009-11-17 07:08:51 ----D---- C:\Program Files\MarkAny
            2009-11-17 07:08:48 ----D---- C:\Program Files\PC Connectivity Solution
            2009-11-17 07:08:25 ----D---- C:\Program Files\Samsung
            2009-11-07 03:20:22 ----D---- C:\Program Files\AVIConverter

            ======List of files/folders modified in the last 3 months======

            2009-12-30 12:23:33 ----ASH---- C:\WINDOWS\system32\rttuwyay.ini
            2009-12-30 12:22:33 ----ASH---- C:\WINDOWS\system32\rttuwyay.ini2
            2009-12-30 12:18:21 ----SHD---- C:\RECYCLER
            2009-12-30 12:18:01 ----AD---- C:\WINDOWS
            2009-12-30 12:07:54 ----D---- C:\WINDOWS\temp
            2009-12-30 12:06:23 ----D---- C:\WINDOWS\Registration
            2009-12-30 11:43:34 ----D---- C:\WINDOWS\Prefetch
            2009-12-30 10:57:02 ----D---- C:\WINDOWS\Debug
            2009-12-30 10:45:10 ----RD---- C:\Program Files
            2009-12-30 10:19:05 ----D---- C:\WINDOWS\system32\CatRoot2
            2009-12-30 10:04:53 ----AD---- C:\WINDOWS\system32
            2009-12-30 10:04:52 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
            2009-12-30 00:29:49 ----HD---- C:\Program Files\InstallShield Installation Information
            2009-12-29 13:46:09 ----D---- C:\Program Files\VAV
            2009-12-29 13:43:43 ----AD---- C:\VALUEADD
            2009-12-29 13:04:52 ----D---- C:\Program Files\Fichiers communs\Symantec Shared
            2009-12-29 13:04:49 ----AD---- C:\WINDOWS\system32\drivers
            2009-12-29 13:04:48 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
            2009-12-29 13:04:46 ----D---- C:\Program Files\Norton AntiVirus
            2009-12-29 13:04:13 ----SHD---- C:\WINDOWS\Installer
            2009-12-29 12:48:59 ----D---- C:\Program Files\Registry Helper
            2009-12-29 12:31:45 ----D---- C:\WINDOWS\security
            2009-12-29 09:00:28 ----SHD---- C:\Config.Msi
            2009-12-29 07:55:42 ----HD---- C:\WINDOWS\inf
            2009-12-29 07:32:36 ----D---- C:\WINDOWS\system32\appmgmt
            2009-12-29 05:57:14 ----D---- C:\WINDOWS\Minidump
            2009-12-06 10:19:11 ----D---- C:\WINDOWS\system32\DirectX
            2009-11-25 08:58:17 ----D---- C:\WINDOWS\system32\FxsTmp
            2009-11-21 12:23:30 ----A---- C:\WINDOWS\iPlayer.INI
            2009-11-17 07:15:49 ----SH---- C:\WINDOWS\system32\fpxtcfun.ini
            2009-11-17 07:11:43 ----DC---- C:\WINDOWS\system32\DRVSTORE
            2009-11-07 12:19:31 ----A---- C:\WINDOWS\system32\mcrh.tmp
            2009-11-07 03:23:50 ----D---- C:\Acer

            ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
            R3 NTIDrvr;Upper Class Filter Driver; C:\WINDOWS\system32\DRIVERS\NTIDrvr.sys [2006-08-11 6144]
            R3 usbehci;Pilote miniport de contrôleur d'hôte amélioré Microsoft USB 2.0; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-10 26624]
            R3 usbhub;Concentrateur USB2; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-10 57600]
            R3 usbohci;Pilote miniport de contrôleur hôte ouvert USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-10 17024]
            R3 USBSTOR;Pilote de stockage de masse USB; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
            S1 AmdK8;Pilote de processeur AMD; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-18 43520]
            S2 CdaC15BA;CdaC15BA; \??\C:\WINDOWS\system32\drivers\CdaC15BA.SYS []
            S3 Arp1394;Protocole client ARP 1394; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-10 60800]
            S3 FsUsbExDisk;FsUsbExDisk; \??\C:\WINDOWS\system32\FsUsbExDisk.SYS []
            S3 hidusb;Pilote de classe HID Microsoft; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-10 9600]
            S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-07 51120]
            S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-07 16496]
            S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-07 21744]
            S3 int15.sys;int15.sys; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys []
            S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-06-05 4284928]
            S3 MHNDRV;Pilote MHN; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-10 11008]
            S3 mouhid;Pilote HID de souris; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-10 12288]
            S3 NIC1394;Pilote réseau 1394; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-10 61824]
            S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2006-07-11 3934592]
            S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
            S3 psdfilter;psdfilter; \??\C:\WINDOWS\system32\Drivers\psdfilter.sys []
            S3 psdvdisk;psdvdisk; \??\C:\WINDOWS\system32\Drivers\psdvdisk.sys []
            S3 RTL8187B;TRENDnet TEW-424UB 54M USB Dongle; C:\WINDOWS\system32\DRIVERS\RTL8187B.sys []
            S3 SjyPkt;SjyPkt; \??\C:\WINDOWS\System32\Drivers\SjyPkt.sys []
            S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\WINDOWS\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
            S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\WINDOWS\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
            S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\WINDOWS\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
            S3 usbccgp;Pilote parent générique USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
            S3 usbprint;Classe d'imprimantes USB Microsoft; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
            S3 usbscan;Pilote de scanneur USB; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
            S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-03-03 18944]
            S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-11-01 76672]
            S3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2006-06-29 244864]
            S3 ZD1211BU(ZyDAS);ZyDAS ZD1211B IEEE 802.11 b+g Wireless LAN Driver (USB)(ZyDAS); C:\WINDOWS\system32\DRIVERS\zd1211Bu.sys []
            S3 ZD1211U(ZyDAS);ZyDAS ZD1211 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyDAS); C:\WINDOWS\system32\DRIVERS\zd1211u.sys []
            S3 ZDPSp50;ZDPSp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\ZDPSp50.sys []
            S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

            ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

            S2 AcerMemUsageCheckService;Memory Check Service; C:\Acer\Empowering Technology\ePerformance\MemCheck.exe [2006-05-11 28672]
            S2 C-DillaCdaC11BA;C-DillaCdaC11BA; C:\WINDOWS\system32\drivers\CDAC11BA.EXE [2008-06-25 54784]
            S2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2006-04-09 237568]
            S2 ehSched;Service de planification Media Center; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 103424]
            S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-10 268800]
            S2 FsUsbExService;FsUsbExService; C:\WINDOWS\system32\FsUsbExService.Exe [2009-03-30 233472]
            S2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe [2006-02-17 73728]
            S2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
            S2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2006-07-11 155715]
            S2 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\system32\HPZipm12.exe [2004-09-29 69632]
            S2 sfrem01;SF FrontLine Drivers Auto Removal (v1); C:\WINDOWS\system32\sfrem01.exe [2006-05-10 353912]
            S2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-08-03 38912]
            S3 aspnet_state;Service d'état ASP.NET; C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
            S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-11 138168]
            S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe [2005-11-14 69632]
            S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2004-08-10 14336]
            S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-06 430592]
            S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-10 14336]

            -----------------EOF-----------------

            à+
            bonne app à toi
            0
            1. Re,

              n'ayant pas accès internet (en plus je n'arrive pas à le configuré) par le pc défectueux, je n'arrive pas à faire ce que tu m'a donné ci dessous :

              --------------------------------
              Salut steph77phane

              Supprime la version de Combofix que tu as télécharger.

              Faire un clic droit sur ce lien :

              http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

              Pour Internet Explorer

              - Choisi Enregistrer la cible sous ...

              Pour Firefox

              - Choisi Enregistrer la cible du lien sous...

              - Choisi le bureau comme lieu d'enregistrement

              - Donne lui ce nom bibite.exe clique sur Enregistrer

              Redémarre en mode sans échec :

              Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur

              Continu le reste de la procédure donné de Combofix

              @++ :)
              ------------------------------------------------------
              0
              1. Re,

                ok autant pour moi, j'ai réussi à le relancer en reprenant un tuto, j'attends donc qu'il se finisse pour te poster le rapport du combofix, il a commencé il y a 5mn

                -----------------------------------------------------------------------------------------------------
                (en gras) info à faire remonter : à précisez la désactivation de l'antivirus et autres de le faire avant le téléchargement et pas avant le scan du combofix. C'est la raison pour laquelle que cela n'avait pas marcher :).

                ----------------------------------------------------------------------------------------------
                Télécharge combofix.exe (de sUBs) et mettre sur le bureau du PC malade :

                http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                http://www.geekstogo.com/forum/files/file/197-combofix-by-subs/

                Important Désactive ton Antivirus et antispyware avant le scan avec Combofix :
                http://forum.pcastuces.com/desactiver_les_protections_reside­ntes-f31s4.htm

                ==> Sauvegarde ton travail et ferme toutes les fenêtres actives, il peut y avoir un redémarrage du PC. Ne lance aucun programme tant que Combofix n’est pas fini. <==

                Double clique sur combofix.exe, clique sur OUI et valide par Entrée

                Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

                NOTE : Le rapport se trouve également ici : C:\Combofix.txt

                Combofix est détecté par certains antivirus comme une infection, ne pas en tenir compte, il s'agit d'un faux positif, continue la procédure
                - Choisi Enregistrer la cible du lien sous...

                - Choisi le bureau comme lieu d'enregistrement

                - Donne lui ce nom bibite.exe clique sur Enregistrer

                Redémarre en mode sans échec :

                Au redémarrage de ton PC tapote sur la touche F8 ou F5, sur l'écran suivant déplace toi avec les flèches de direction et choisis Mode sans échec. Choisis ta session habituelle et non la session Administrateur

                Continu le reste de la procédure donné de Combofix

                0
                1. Contributeur sécurité
                  Salut steph77phane

                  Télécharge OTM (de Old_Timer) sur le bureau :

                  http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/

                  Double-clique sur OTM.exe sur le bureau

                  - Copie le texte qui se trouve en gras ci-dessous et colle le dans le cadre de gauche de OTM nommé Paste Instructions for Items to be Moved

                  :reg
                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Explorer\Browser Helper Objects\{5AB8CFAF-2D09-4A74-B4BD-0B46D4C14F45}]
                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Explorer\Browser Helper Objects\{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}]
                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Explorer\Browser Helper Objects\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}]
                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersio­n\Explorer\Browser Helper Objects\{fa73dea3-6c81-491b-b7b6-4a81403a1be7}]
                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}]
                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
                  "SearchSettings"=-
                  "Antivirus"=-
                  "NPSStartup"=-
                  [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvUkICtu]
                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                  "{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}"=-

                  :files
                  C:\WINDOWS\system32\yaywuttr.dll
                  C:\WINDOWS\system32\wvUkICtu.dll
                  C:\Program Files\GamesBar\oberontb.dll
                  C:\WINDOWS\system32\hevyce.dll
                  C:\Program Files\Search Settings
                  C:\Program Files\VAV
                  C:\WINDOWS\system32\rttuwyay.ini
                  C:\WINDOWS\system32\rttuwyay.ini2
                  C:\WINDOWS\system32\mcrh.tmp
                  C:\WINDOWS\system32\fpxtcfun.ini

                  :commands
                  [purity]
                  [emptytemp]
                  [reboot]


                  - Clique sur MoveIt! pour lancer la suppression.
                  - Ferme OTM

                  Ton PC va redémarrer pour finir la suppression, si il ne le fais pas lui-même, redémarre le.

                  Poste le rapport de OTMoveIt qui se trouve dans C:\_OTM\MovedFiles.

                  @++ :)
                  1
                  1. Je remercie si, quelqu'un de passage sur ce topic pouvait me répondre à ceci, ci dessous :
                    Bizarre, est-ce normal que combofix n'apparaisse pas dans le gestionnaire de tâches, renommer en bibitte.exe, il n'apparait pas non plus dans le processus ? donc combofix est-il en activité (ou pas) ?
                    ----------------------------------------------------------------

                    Bonjour dédétraqué,

                    A cette heure ci, près de 16h de scan combofix, il n'est pas encore fini et j'attends donc toujours le rapport (la lumière du pc indique qu'il travaille).
                    J'ai actuellement sur le bureau, des fenêtres ouvertes m'indiquant des "messages d'alertes" mais provenant des virus.

                    Est ce possible, de faire remonter l'info au concepteur de combofix, qu'il serait bien de mettre une barre de progression dans combofix car là, on ne sait rien de rien. Je ne sais même pas si, le combofix actuellement est vraiment actif et je n'ose donc rien faire .

                    Donc, dès que je le peux, je fais tes instructions du message N°8

                    à++ ;)
                    0
                2. Re,

                  Ouuufff, voici le rapport demandé d'' OTM
                  Combofix n'était plus actif, je vois pour le relancer

                  ------------------------------------------------------------

                  All processes killed
                  ========== REGISTRY ==========
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi­o­n\Explorer\Browser Helper Objects\{5AB8CFAF-2D09-4A74-B4BD-0B46D4C14F45}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AB8CFAF-2D09-4A74-B4BD-0B46D4C14F45}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi­o­n\Explorer\Browser Helper Objects\{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi­o­n\Explorer\Browser Helper Objects\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi­o­n\Explorer\Browser Helper Objects\{fa73dea3-6c81-491b-b7b6-4a81403a1be7}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fa73dea3-6c81-491b-b7b6-4a81403a1be7}\ deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}\ not found.
                  Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                  Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                  Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersio­n\Run not found.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\wvUkICtu\ deleted successfully.
                  Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286} deleted successfully.
                  Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{684BFE7F-F5B2-4AB3-A95E-EB5036A2D286}\ deleted successfully.
                  ========== FILES ==========
                  DllUnregisterServer procedure not found in C:\WINDOWS\system32\yaywuttr.dll
                  C:\WINDOWS\system32\yaywuttr.dll moved successfully.
                  DllUnregisterServer procedure not found in C:\WINDOWS\system32\wvUkICtu.dll
                  File move failed. C:\WINDOWS\system32\wvUkICtu.dll scheduled to be moved on reboot.
                  C:\Program Files\GamesBar\oberontb.dll moved successfully.
                  DllUnregisterServer procedure not found in C:\WINDOWS\system32\hevyce.dll
                  C:\WINDOWS\system32\hevyce.dll moved successfully.
                  C:\Program Files\Search Settings\kb127\temp folder moved successfully.
                  C:\Program Files\Search Settings\kb127\res folder moved successfully.
                  C:\Program Files\Search Settings\kb127 folder moved successfully.
                  C:\Program Files\Search Settings folder moved successfully.
                  C:\Program Files\VAV folder moved successfully.
                  C:\WINDOWS\system32\rttuwyay.ini moved successfully.
                  C:\WINDOWS\system32\rttuwyay.ini2 moved successfully.
                  C:\WINDOWS\system32\mcrh.tmp moved successfully.
                  C:\WINDOWS\system32\fpxtcfun.ini moved successfully.
                  ========== COMMANDS ==========

                  [EMPTYTEMP]

                  User: Administrateur
                  ->Temp folder emptied: 16384 bytes
                  ->Temporary Internet Files folder emptied: 134 bytes

                  User: All Users

                  User: Default User
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 32768 bytes

                  User: LocalService
                  ->Temp folder emptied: 115616 bytes
                  ->Temporary Internet Files folder emptied: 32902 bytes

                  User: NetworkService
                  ->Temp folder emptied: 0 bytes
                  ->Temporary Internet Files folder emptied: 378118 bytes

                  User: XXXXXXX
                  ->Temp folder emptied: 22349246 bytes
                  ->Temporary Internet Files folder emptied: 5444713 bytes

                  %systemdrive% .tmp files removed: 0 bytes
                  %systemroot% .tmp files removed: 1057393 bytes
                  %systemroot%\System32 .tmp files removed: 69379679 bytes
                  Windows Temp folder emptied: 62878454 bytes
                  %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
                  %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
                  RecycleBin emptied: 0 bytes

                  Total Files Cleaned = 154,00 mb

                  OTM by OldTimer - Version 3.1.4.0 log created on 12312009_134220

                  Files moved on Reboot...
                  File move failed. C:\WINDOWS\system32\wvUkICtu.dll scheduled to be moved on reboot.

                  Registry entries deleted on Reboot...

                  0
                  1. Re,

                    Bon, j'ai réussi à installer avira d'antivir, j'ai commencé à faire un scan en mode sans échec et je te dis quoi ensuite :) (actuellement, il y a adware et trojans vundo, Agent).
                    Le pc n'est toujours pas connecté au net car je n'arrive pas à faire le réglage dans option internet puis connexion :) (voir aussi, les messages N°9 et 10).

                    Au cas où, je te souhaite une bonne fin d'année et un bon réveillon (ainsi qu'à tous les modo, les helper et les dépannés).
                    0
                    1. Contributeur sécurité
                      Salut steph77phane

                      Et le scan avec Antivir a donner quel résultat?

                      Essai de réinstaller MBAM voir si cela va fonctionner, tiens moi au courant.

                      @++ :)
                      1
                      1. Bonsoir dédétraqué,

                        Tous mes meilleurs voeux pour 2010.

                        Avira c'est ok (plus de 2300 infections trojans, adware, malware, :)), j'ai réussi à installer et à passer MBAM il ne me reste plus qu'à mettre zonealarm, donc là, plus rien à éradiquer dans l'immédiat, ça parait propre après tout ça mais il sera bon après de faire je pense, un RSIT ou un HJT.

                        Je fini d'installer certaines choses et fais des mises à jour de certains programmes par carte SD (XP sp3 et IE8 etc...).
                        Là, je m'a prête à installer mon cegetel pour l'internet (attention je ne suis plus joignable de suite) et dès que tout est prêt après, il me restera les dernières MAJ (windows updates, java ...), je te recontact pour un RSIT ou autre de tes conseils à suivre une fois que tout ce que je veux mettre sur le PC est mis.

                        (Encore merci pour tout)

                        à +tard

                        stéphane
                        0
                    2. Re,

                      Je n'arrive pas à me connecter à internet en apparence, il y aurait un soucis de controleur éthernet (pas de pilote) je dois demandé le cd rom XP à la personne.
                      J'ai mis télécharger et installer part carte SD, IE8, XP sp3 après il me restera les MAJ une fois connecter au net.

                      Dans l'immédiat, voici un rapport RSIT, peux tu me dire si tout te parait normal :

                      ------------------------------------------------------------------------------------------

                      Logfile of random's system information tool 1.06 (written by random/random)
                      Run by THOMINE at 2010-01-01 20:22:00
                      Microsoft Windows XP Professionnel Service Pack 3
                      System drive C: has 92 GB (80%) free of 116 GB
                      Total RAM: 767 MB (64% free)

                      Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 20:22:06, on 01/01/2010
                      Platform: Windows XP SP3 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v8.00 (8.00.6001.18702)
                      Boot mode: Normal

                      Running processes:
                      C:\WINDOWS\System32\smss.exe
                      C:\WINDOWS\system32\winlogon.exe
                      C:\WINDOWS\system32\services.exe
                      C:\WINDOWS\system32\lsass.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\System32\svchost.exe
                      C:\WINDOWS\system32\spoolsv.exe
                      C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                      C:\WINDOWS\Explorer.EXE
                      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                      C:\WINDOWS\eHome\ehRecvr.exe
                      C:\WINDOWS\eHome\ehSched.exe
                      C:\WINDOWS\system32\FsUsbExService.Exe
                      c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      C:\WINDOWS\system32\nvsvc32.exe
                      C:\WINDOWS\system32\svchost.exe
                      C:\WINDOWS\ehome\ehtray.exe
                      C:\WINDOWS\system32\dllhost.exe
                      C:\WINDOWS\RTHDCPL.EXE
                      C:\WINDOWS\eHome\ehmsas.exe
                      C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                      C:\WINDOWS\system32\wscntfy.exe
                      C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                      C:\WINDOWS\system32\SysMonitor.exe
                      C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      C:\Program Files\QuickTime\qttask.exe
                      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                      C:\WINDOWS\system32\ctfmon.exe
                      C:\Program Files\Messenger\msmsgs.exe
                      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      C:\PROGRA~1\BERENG~1\AmBiAnZ\AMBIAN~1.exe
                      C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                      C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                      C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
                      C:\Documents and Settings\THOMINE\Bureau\RSIT.exe
                      C:\Program Files\trend micro\HijackThis\THOMINE.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
                      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
                      O2 - BHO: (no name) - {B0E5A6BD-DBEB-4B37-945A-2C0DE1E241CB} - (no file)
                      O2 - BHO: {7eb1a304-18a4-6b7b-b194-18c63aed37af} - {fa73dea3-6c81-491b-b7b6-4a81403a1be7} - (no file)
                      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                      O4 - HKLM\..\Run: [LaunchApp] Alaunch
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                      O4 - HKLM\..\Run: [ntiMUI] c:\Program Files\NewTech Infosystems\NTI CD & DVD-Maker 7\ntiMUI.exe
                      O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
                      O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
                      O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
                      O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                      O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                      O4 - HKLM\..\Run: [Acer Empowering Technology Monitor] C:\WINDOWS\system32\SysMonitor.exe
                      O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 0
                      O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [AmBiAnZ] C:\PROGRA~1\BERENG~1\AmBiAnZ\AMBIAN~1.exe
                      O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                      O4 - HKCU\..\Run: [Configuration de la C-BOX] C:\Program Files\CEGETEL\C-BOX\Wizard\QuickAccess.exe
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - Global Startup: Acer Empowering Technology.lnk = ?
                      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
                      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                      O8 - Extra context menu item: Add to AMV Converter... - C:\Program Files\MP3 Player Utilities 4.18\AMVConverter\grab.html
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                      O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                      O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                      O23 - Service: FsUsbExService - Teruten - C:\WINDOWS\system32\FsUsbExService.Exe
                      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
                      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                      O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
                      O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
                      O23 - Service: SF FrontLine Drivers Auto Removal (v1) (sfrem01) - Protection Technology (StarForce) - C:\WINDOWS\system32\sfrem01.exe
                      0
                      1. Contributeur sécurité
                        Salut steph77phane

                        Télécharge OTM (de Old_Timer) sur le bureau :

                        http://www.geekstogo.com/forum/files/file/402-otm-oldtimers-move-it/

                        Double-clique sur OTM.exe sur le bureau

                        - Copie le texte qui se trouve en gras ci-dessous et colle le dans le cadre de gauche de OTM nommé Paste Instructions for Items to be Moved

                        :processes

                        :services
                        clbdriver

                        :reg
                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B0E5A6BD-DBEB-4B37-945A-2C0DE1E241CB}]
                        [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fa73dea3-6c81-491b-b7b6-4a81403a1be7}]
                        [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\clbdriver.sys]
                        [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\clbdriver.sys]
                        [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
                        "Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00
                        "Notification Packages"=hex(7):73,63,65,63,6c,69,00,00

                        :files
                        C:\WINDOWS\003056_.tmp

                        :commands
                        [purity]
                        [emptytemp]
                        [reboot]


                        - Clique sur MoveIt! pour lancer la suppression.
                        - Ferme OTM

                        Ton PC va redémarrer pour finir la suppression, si il ne le fais pas lui-même, redémarre le.

                        Poste le rapport de OTMoveIt qui se trouve dans C:\_OTM\MovedFiles.

                        @++ :)
                        1
                        1. Bonjour dédétraqué,

                          Alors, le RSIT était catastrophique ?
                          Pour info, à l'allumage du PC avira biip, je pense qu'il y a encore des truc qui coince ;)
                          Je suis entrain de faire un usbfix où détecter par avira il me découvre un virus portugais (après recherche avec mon ami google :) ) nommé : yong.exe dans C:\program files\yong.exe provenant de msn, je l'ai mis en 40taine et le supprimerais ensuite sinon je passe un msnfix.

                          Voici le log de OTM demandé.

                          ----------------------------------------------------------------------------

                          All processes killed
                          ========== PROCESSES ==========
                          ========== SERVICES/DRIVERS ==========
                          Error: No service named clbdriver was found to stop!
                          Unable to stop service clbdriver!
                          ========== REGISTRY ==========
                          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B0E5A6BD-DBEB-4B37-945A-2C0DE1E241CB}\ deleted successfully.
                          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B0E5A6BD-DBEB-4B37-945A-2C0DE1E241CB}\ not found.
                          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fa73dea3-6c81-491b-b7b6-4a81403a1be7}\ deleted successfully.
                          Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fa73dea3-6c81-491b-b7b6-4a81403a1be7}\ not found.
                          Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\clbdriver.sys\ deleted successfully.
                          Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\clbdriver.sys\ deleted successfully.
                          HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\\"Authentication Packages"|hex(7):6d,73,76,31,5f,30,00,00 /E : value set successfully!
                          HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa\\"Notification Packages"|hex(7):73,63,65,63,6c,69,00,00 /E : value set successfully!
                          ========== FILES ==========
                          C:\WINDOWS\003056_.tmp moved successfully.
                          ========== COMMANDS ==========

                          [EMPTYTEMP]

                          User: Administrateur
                          ->Temp folder emptied: 0 bytes
                          ->Temporary Internet Files folder emptied: 33170 bytes

                          User: All Users

                          User: Default User
                          ->Temp folder emptied: 0 bytes
                          ->Temporary Internet Files folder emptied: 0 bytes

                          User: LocalService
                          ->Temp folder emptied: 1120328 bytes
                          ->Temporary Internet Files folder emptied: 33170 bytes

                          User: NetworkService
                          ->Temp folder emptied: 1049784 bytes
                          ->Temporary Internet Files folder emptied: 0 bytes

                          User: XXXXXX
                          ->Temp folder emptied: 23810869 bytes
                          ->Temporary Internet Files folder emptied: 33170 bytes
                          ->FireFox cache emptied: 3481994 bytes

                          %systemdrive% .tmp files removed: 0 bytes
                          %systemroot% .tmp files removed: 0 bytes
                          %systemroot%\System32 .tmp files removed: 0 bytes
                          Windows Temp folder emptied: 548912 bytes
                          %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
                          %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
                          RecycleBin emptied: 0 bytes

                          Total Files Cleaned = 29,00 mb

                          OTM by OldTimer - Version 3.1.4.0 log created on 01022010_083937

                          Files moved on Reboot...

                          Registry entries deleted on Reboot...

                          0
                      2. Contributeur sécurité
                        Salut
                        0
                        1. bonjour dédétraqué,

                          Bon, je pense avoir éradiquer le virus msn portugais yong.exe
                          Sinon, j'ai encore essayé un combofix mais il ne va pas plus loin que la ligne étape 50.
                          voilà les infos :)

                          je te fais un log smitfraudix

                          0
                      3. Re,

                        voici le log smitfraudix
                        je viens de voir ton MP, je mi colle ;)

                        SmitFraudFix v2.424

                        Rapport fait à 17:51:24,10, 02/01/2010
                        Executé à partir de C:\Documents and Settings\THOMINE\Bureau\SmitfraudFix
                        OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                        Le type du système de fichiers est NTFS
                        Fix executé en mode normal

                        »»»»»»»»»»»»»»»»»»»»»»»» Process

                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir Desktop\sched.exe
                        C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                        C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                        C:\WINDOWS\eHome\ehRecvr.exe
                        C:\WINDOWS\eHome\ehSched.exe
                        C:\WINDOWS\system32\FsUsbExService.Exe
                        c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
                        C:\WINDOWS\system32\nvsvc32.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\ehome\ehtray.exe
                        C:\WINDOWS\RTHDCPL.EXE
                        C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
                        C:\WINDOWS\system32\dllhost.exe
                        C:\WINDOWS\eHome\ehmsas.exe
                        C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
                        C:\WINDOWS\system32\SysMonitor.exe
                        C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
                        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                        C:\PROGRA~1\BERENG~1\AmBiAnZ\AMBIAN~1.exe
                        C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
                        C:\WINDOWS\system32\wscntfy.exe
                        C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
                        C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
                        C:\Documents and Settings\THOMINE\Bureau\SmitfraudFix\Policies.exe
                        C:\WINDOWS\system32\cmd.exe

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\THOMINE

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\THOMINE\LOCALS~1\Temp

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\THOMINE\Application Data

                        »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\THOMINE\Favoris

                        »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                        »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                        C:\Program Files\Google\googletoolbar1.dll PRESENT !

                        »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                        »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                        "Source"="About:Home"
                        "SubscribedURL"="About:Home"
                        "FriendlyName"="Ma page d'accueil"

                        »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        o4Patch
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        IEDFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Agent.OMZ.Fix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        Agent.OMZ.Fix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        VACFix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        404Fix
                        Credits: Malware Analysis & Diagnostic
                        Code: S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                        !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"

                        »»»»»»»»»»»»»»»»»»»»»»»» RK

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                        "System"=""

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{FC822F04-860A-47F0-A6A3-E30882728B89}: DhcpNameServer=192.168.1.254
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{FC822F04-860A-47F0-A6A3-E30882728B89}: DhcpNameServer=192.168.1.254
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{FC822F04-860A-47F0-A6A3-E30882728B89}: DhcpNameServer=192.168.1.254
                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
                        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254

                        »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Fin

                        0
                        1. voici le lien enfin si j'ai tout compris comment ça marche :)

                          http://cjoint.com/data/bcszSbZs8w.htm
                          0
                          1. Contributeur sécurité
                            Salut steph77phane

                            Supprime ce dossier en gras
                            C:\Program Files\GamesBar

                            Le scan avec Antivir cela dit quoi?

                            @++ :)
                            1
                            1. Re,

                              pour le scan avira que j'ai fais seulement au message N°11 il y avait 2300 infections que j'avais mis en 40taine et supprimer ensuite.

                              ok je vais supprimer ce qui est en gras mais avec quel élément de suppression ? après veux tu que je refasse un avira ?
                              0
                          2. Contributeur sécurité
                            Salut steph77phane

                            Commence par faire un clique droit sur le dossier et sélectionne Supprimer, sinon voir en mode sans échec.

                            Oui refais moi un scan avec Antivir et poste le rapport.

                            @++ :)
                            1
                            1. Re,

                              Gamesbar est supprimé.
                              Là, je fais un MBAM en examen rapide puis je te fais l'avira dans la foulée :)) et te poste le log (avira).
                              il faudra que je vois aussi si, j'arrive à me connecté au net car ce n'était pas le cas jusqu'à présent.
                              Soucis avec le controleur éthernet (point d'interrogation en jaune), il n'y aurait pas de pilote.

                              0
                          3. Contributeur sécurité
                            Salut steph77phane

                            Citation :
                            Soucis avec le controleur éthernet (point d'interrogation en jaune)
                            Faire un clique droit sur le ? jaune et désinstalle-le, Windows devrais réparer au démarrage.

                            @++ :)
                            1
                            1. ok je vais faire ça avant de lancer avira.

                              Merci pour ton aide (je sais, ce n'est pas encore fini :D )
                              0
                            2. @steph77phaneCitation :
                              Soucis avec le controleur éthernet (point d'interrogation en jaune)
                              Faire un clique droit sur le ? jaune et désinstalle-le, Windows devrais réparer au démarrage.

                              ok, j'ai désinstaller mais il est réapparu après le redémarrage;
                              Allez j'ai lancé avira
                              Je te reprends plus tard si tu es là ;). Bon app :)

                              au faite le tout n'est pas fait sous internet donc je n'ai pas les dernières MAJ pour les scans
                              0
                          4. Voici le log MBAM (j'ai supprimé l'infection)
                            Je m'occupe d'avira

                            Malwarebytes' Anti-Malware 1.43
                            Version de la base de données: 3458
                            Windows 5.1.2600 Service Pack 3
                            Internet Explorer 8.0.6001.18702

                            02/01/2010 19:25:44
                            mbam-log-2010-01-02 (19-25-44).txt

                            Type de recherche: Examen rapide
                            Eléments examinés: 114438
                            Temps écoulé: 4 minute(s), 23 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 1
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 0

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\poof (Rootkit.Agent) -> Quarantined and deleted successfully.

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            (Aucun élément nuisible détecté)
                            0
                            • 1
                            • 2