Cheval de troie

Résolu
Bonjour,

En téléchargeant live-player.exe, j'ai été infectée par un cheval de troie qui je n'arrive pas à supprimer..
Pourriez-vous m'aider s'il-vous-plaît?

En vous remerciant et en vous souhaitant une bonne année par la même occasion :)

Jeannat.
Configuration: Windows XP
Firefox 3.0.16

22 réponses

  1. Contributeur sécurité
    bonsoir

    • Télécharge Random's System Information Tool (RSIT) de Random/Random.

    http://images.malwareremoval.com/random/RSIT.exe

    • Enregistre le sur ton Bureau.

    • Double clique sur RSIT.exe pour lancer l'outil.

    • Clique sur "Continue" à l'écran Disclaimer.

    • Si l'outil HijackThis n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu s'il te le demande)

    et tu devras accepter la licence.

    • Une fois le scan terminé, deux rapports vont apparaître : poste les dans deux messages séparés stp

    Les rapports se trouvent à cet endroit:
    C:\rsit\info.txt
    C:\rsit\log.txt

    0
    1. info.txt logfile of random's system information tool 1.06 2010-01-02 00:32:59

      ======Uninstall list======

      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
      Adobe Reader 9.1 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A91000000001}
      AIDA32 v3.93-->"C:\Program Files\AIDA32 - Personal System Information\unins000.exe"
      Archiveur WinRAR-->C:\Program Files\WinRAR\uninstall.exe
      Assistant de connexion Windows Live-->MsiExec.exe /I{DCE8CD14-FBF5-4464-B9A4-E18E473546C7}
      Atheros Client Utility-->C:\Program Files\InstallShield Installation Information\{16E8BF9A-B419-4A44-A020-30F8CFB84B9D}\setup.exe -runfromtemp -l0x040c
      ATI - Utilitaire de désinstallation du logiciel-->C:\Program Files\ATI Technologies\UninstallAll\AtiCimUn.exe
      ATI Control Panel-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe"
      ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
      Bluetooth Stack for Windows by Toshiba-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
      DivX Plus Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
      Favorit-->"c:\documents and settings\lina\local settings\application data\evgwev.exe" -uninstall
      Galerie de photos Windows Live-->MsiExec.exe /X{B131E59D-202C-43C6-84C9-68F0C37541F1}
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      Installation Windows Live-->C:\Program Files\Windows Live\Installer\wlarp.exe
      Installation Windows Live-->MsiExec.exe /I{46ABBC54-1872-4AA3-95E2-F2C063A63F31}
      Intel(R) PROSet-->MsiExec.exe /I{74C9DFA1-338F-4bf3-B317-99A9EC8EF9A6}
      Junk Mail filter update-->MsiExec.exe /I{E2DFE069-083E-4631-9B6C-43C48E991DE5}
      K-Lite Mega Codec Pack 4.8.5-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
      LiveUpdate 1.7 (Symantec Corporation)-->C:\Program Files\\Symantec\LiveUpdate\LSETUP.EXE /U
      Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
      Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
      Microsoft Choice Guard-->MsiExec.exe /X{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}
      Microsoft Office Access MUI (French) 2007-->MsiExec.exe /X{90120000-0015-040C-0000-0000000FF1CE}
      Microsoft Office Excel MUI (French) 2007-->MsiExec.exe /X{90120000-0016-040C-0000-0000000FF1CE}
      Microsoft Office InfoPath MUI (French) 2007-->MsiExec.exe /X{90120000-0044-040C-0000-0000000FF1CE}
      Microsoft Office Live Add-in 1.3-->MsiExec.exe /I{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}
      Microsoft Office Outlook Connector-->MsiExec.exe /I{95120000-0122-040C-0000-0000000FF1CE}
      Microsoft Office Outlook MUI (French) 2007-->MsiExec.exe /X{90120000-001A-040C-0000-0000000FF1CE}
      Microsoft Office PowerPoint MUI (French) 2007-->MsiExec.exe /X{90120000-0018-040C-0000-0000000FF1CE}
      Microsoft Office Professional Plus 2007-->"C:\Program Files\Fichiers communs\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROPLUS /dll OSETUP.DLL
      Microsoft Office Professional Plus 2007-->MsiExec.exe /X{90120000-0011-0000-0000-0000000FF1CE}
      Microsoft Office Proof (Arabic) 2007-->MsiExec.exe /X{90120000-001F-0401-0000-0000000FF1CE}
      Microsoft Office Proof (Dutch) 2007-->MsiExec.exe /X{90120000-001F-0413-0000-0000000FF1CE}
      Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
      Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
      Microsoft Office Proof (German) 2007-->MsiExec.exe /X{90120000-001F-0407-0000-0000000FF1CE}
      Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
      Microsoft Office Proofing (French) 2007-->MsiExec.exe /X{90120000-002C-040C-0000-0000000FF1CE}
      Microsoft Office Publisher MUI (French) 2007-->MsiExec.exe /X{90120000-0019-040C-0000-0000000FF1CE}
      Microsoft Office Shared MUI (French) 2007-->MsiExec.exe /X{90120000-006E-040C-0000-0000000FF1CE}
      Microsoft Office Word MUI (French) 2007-->MsiExec.exe /X{90120000-001B-040C-0000-0000000FF1CE}
      Microsoft Search Enhancement Pack-->MsiExec.exe /I{9C9CEB9D-53FD-49A7-85D2-FE674F72F24E}
      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft SQL Server 2005 Compact Edition [ENU]-->MsiExec.exe /I{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}
      Microsoft Sync Framework Runtime Native v1.0 (x86)-->MsiExec.exe /I{8A74E887-8F0F-4017-AF53-CBA42211AAA5}
      Microsoft Sync Framework Services Native v1.0 (x86)-->MsiExec.exe /I{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}
      Mozilla Firefox (3.0.16)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
      MSVCRT-->MsiExec.exe /I{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}
      Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
      Outil de téléchargement Windows Live-->MsiExec.exe /I{205C6BDD-7B73-42DE-8505-9A093F35A238}
      Pilote du DVD-RAM-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D765FA6-F2BC-40AF-8145-50808F9BDF4E}\Setup.exe" DVD-RAM Driver
      Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
      Realtek Fast Ethernet Adapter Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{97AA0C55-AFAD-4126-B21C-F1318FB6DADA}\Setup.exe" -l0x40c REMOVE
      Réducteur de bruit lect. CD/DVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9FE35071-CAB2-4E79-93E7-BFC6A2DC5C5D}\Setup.exe" -l0x40c
      Segoe UI-->MsiExec.exe /I{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}
      Skype web features-->MsiExec.exe /I{F1362843-0E0E-4F74-8662-724CF101ADCE}
      Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36}
      SMSC IrCC V5.1.3600.5-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0700\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F1B8DB67-D30E-4FF9-A85F-3CEE51825AA2}\setup.exe" -l0x40c UNINSTALL
      SRS WOW XT Plug-In for Windows Media Player for Toshiba version 1.0.2-->C:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{68D368EE-F5AC-4402-BD45-B454B5453FE1}
      Symantec AntiVirus Client-->MsiExec.exe /X{0EFC6259-3AD8-4CD2-BC57-D4937AF5CC0E}
      VC80CRTRedist - 8.0.50727.4053-->MsiExec.exe /I{5EE7D259-D137-4438-9A5F-42F432EC0421}
      VLC media player 0.9.9-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Windows Imaging Component-->"C:\WINDOWS\$NtUninstallWIC$\spuninst\spuninst.exe"
      Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
      Windows Live Call-->MsiExec.exe /I{82C7B308-0BDD-49D8-8EA5-9CD3A3F9DF41}
      Windows Live Communications Platform-->MsiExec.exe /I{3B4E636E-9D65-4D67-BA61-189800823F52}
      Windows Live FolderShare-->MsiExec.exe /X{2075CB0A-D26F-4DAA-B424-5079296B43BA}
      Windows Live Mail-->MsiExec.exe /I{5DD76286-9BE7-4894-A990-E905E91AC818}
      Windows Live Messenger-->MsiExec.exe /X{770F1BEC-2871-4E70-B837-FB8525FFA3B1}
      Windows Live Toolbar-->MsiExec.exe /X{F7D27C70-90F5-49B9-B188-0A133C0CE353}
      Windows Live Writer-->MsiExec.exe /X{4634B21A-CC07-4396-890C-2B8168661FEA}
      Windows Media Player Firefox Plugin-->MsiExec.exe /I{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}

      ======System event log======

      Computer Name: LINA-PORTABLE
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service NAVEX15.

      Record Number: 15431
      Source Name: Service Control Manager
      Time Written: 20091128103830.000000+060
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      Computer Name: LINA-PORTABLE
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service NAVAP.

      Record Number: 15430
      Source Name: Service Control Manager
      Time Written: 20091128103830.000000+060
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      Computer Name: LINA-PORTABLE
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service SymEvent.

      Record Number: 15429
      Source Name: Service Control Manager
      Time Written: 20091128103829.000000+060
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      Computer Name: LINA-PORTABLE
      Event Code: 7036
      Message: Le service Explorateur d'ordinateur est entré dans l'état : arrêté.

      Record Number: 15428
      Source Name: Service Control Manager
      Time Written: 20091128103828.000000+060
      Event Type: Informations
      User:

      Computer Name: LINA-PORTABLE
      Event Code: 7036
      Message: Le service Gestionnaire de connexions d'accès distant est entré dans l'état : en cours d'exécution.

      Record Number: 15427
      Source Name: Service Control Manager
      Time Written: 20091128103828.000000+060
      Event Type: Informations
      User:

      =====Application event log=====

      Computer Name: LINA-PORTABLE
      Event Code: 23
      Message:

      Protection temps réel Symantec AntiVirus chargée.

      Record Number: 5594
      Source Name: Norton AntiVirus
      Time Written: 20091127153124.000000+060
      Event Type: Informations
      User:

      Computer Name: LINA-PORTABLE
      Event Code: 1800
      Message: Le service Centre de sécurité Windows a démarré.

      Record Number: 5593
      Source Name: SecurityCenter
      Time Written: 20091127153118.000000+060
      Event Type: Informations
      User:

      Computer Name: LINA-PORTABLE
      Event Code: 0
      Message:
      Record Number: 5592
      Source Name: SeaPort
      Time Written: 20091127153117.000000+060
      Event Type: Informations
      User:

      Computer Name: LINA-PORTABLE
      Event Code: 1
      Message:
      Record Number: 5591
      Source Name: ccxroaming
      Time Written: 20091127153105.000000+060
      Event Type: Informations
      User:

      Computer Name: LINA-PORTABLE
      Event Code: 1
      Message:
      Record Number: 5590
      Source Name: ccxroaming
      Time Written: 20091127153105.000000+060
      Event Type: Informations
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Toshiba\Bluetooth Toshiba Stack\sys\;C:\Program Files\ATI Technologies\ATI Control Panel
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 13 Stepping 6, GenuineIntel
      "PROCESSOR_REVISION"=0d06
      "NUMBER_OF_PROCESSORS"=1
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP

      -----------------EOF-----------------
      0
      1. Logfile of random's system information tool 1.06 (written by random/random)
        Run by Lina at 2010-01-02 00:32:33
        Microsoft Windows XP Professionnel Service Pack 2
        System drive C: has 4 GB (26%) free of 15 GB
        Total RAM: 510 MB (14% free)

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 00:32:55, on 02/01/2010
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\ZCfgSvc.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\spoolsv.exe
        C:\WINDOWS\system32\acs.exe
        C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Atheros\ACU.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Messenger\msmsgs.exe
        C:\documents and settings\lina\local settings\application data\evgwev.exe
        C:\WINDOWS\system32\RAMASST.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
        C:\WINDOWS\system32\DVDRAMSV.exe
        C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
        C:\WINDOWS\system32\wscntfy.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Documents and Settings\Lina\Bureau\TAF\RSIT.exe
        C:\Program Files\trend micro\Lina.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
        O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
        O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\system32\ZCfgSvc.exe
        O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
        O4 - HKCU\..\Run: [evgwev] "c:\documents and settings\lina\local settings\application data\evgwev.exe" evgwev
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - http://www.mediapluspro.com/mediaplus66/Download/msrdp.cab
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
        O23 - Service: Service de configuration Atheros (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
        O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
        O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
        O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
        O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
        0
        1. Contributeur sécurité
          vu

          dans cet ordre

          1)

          Infection Navipromo….Pour info :

          Il s'installe via certains programmes, dont ceux-ci qu'il faut éviter à tout prix:
          * Funky Emoticons
          * go-astro
          * Games Attack
          * GoRecord
          * HotTVPlayer / HotTVPlayer & Paris Hilton
          * Live-Player
          * MailSkinner
          * Messenger Skinner
          * Instant Access
          * InternetGameBox
          * Officiale Emule (Version d'Emule modifiée)
          * Original Solitaire
          * SuperSexPlayer
          * Speed Downloading
          * Sudoplanet
          * Webmediaplayer

          il faudrait télécharge navilog1 sur le bureau :
          http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe

          Certaines infections bloquent les téléchargements d' outils de désinfection utilisez ce lien alternatif:
          http://ww38.toofiles.com/fr/oip/documents/exe/yop3.html

          1°Double-clique sur navilog1.exe présent sur ton bureau
          2°Sélectionnez la langue désirée dans le menu puis valide le choix par la touche « entrer »
          3°Petit message d’avertissement, appuyez sur une touche pour passe à la suite
          4°un nouveau avertissement, appuie sur une touche pour suivre
          5°Vérification de l’installation de Navilog1 : si tout est bon, appuyez sur une touche pour continuer
          6°Choisir option 1 : recherche/désinfection automatique
          7°La recherche va se lancer automatiquement et peut durée quelques minutes, patientez
          8°Une fois l’analyse terminé, fermez et enregistrez votre travail en cours, puis appuiez sur une touche pour que votre pc puisse démarrer
          9°Au redémarrage du pc, Navilog va supprimer ce qu’il a trouvé, patientez quelques instants.

          Un rapport est gèneré par l'outil. Il se trouve à cette emplacement :
          XP : demarrer/poste de travail/c:/cleannavi.txt
          Vista : logo « demarrer »/ordinateur/c:/ cleannavi.txt

          .............................

          Téléchargez USBFIX de Chiquitine29, C_xx

          http://pagesperso-orange.fr/NosTools/Chiquitine29/UsbFix.exe
          ou
          https://www.ionos.fr/?affiliate_id=77097

          /!\ Utilisateur de vista et windows 7 :
          ne pas oublier de désactiver Le contrôle des comptes utilisateurs
          https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

          /!\ Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) susceptible d'avoir été infectées sans les ouvrir

          • Double clic sur le raccourci UsbFix présent sur le bureau .

          • Choisir l'option2
          (d’autres options disponibles, voir le tutoriel).
          • Laissez travailler l'outil.
          Le menu démarrer et les icônes vont disparaître.. c'est normal.

          Si un message te demande de redémarrer l'ordinateur fais le ...

          ● Au redémarrage, le fix se relance... laisses l'opération s'effectuer.

          ● Le bloc note s'ouvre avec un rapport, envoies le dans la prochaine réponse

          • Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

          ( CTRL+A Pour tout sélectionner , CTRL+C pour copier et CTRL+V pour coller )

          • Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
          Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

          • Tuto : http://pagesperso-orange.fr/NosTools/usbfix.html

          UsbFix peut te demander d'uploader un dossier compressé à cette adresse : https://www.ionos.fr/?affiliate_id=77097

          Il est enregistré sur ton bureau.

          Merci de l'envoyer à l'adresse indiquée afin d'aider l'auteur de UsbFix dans ses recherches.

          Merci

          ..........................

          3)

          Téléchargez MalwareByte's Anti-Malware

          http://www.malwarebytes.org/mbam/program/mbam-setup.exe

          . Enregistres le sur le bureau
          . Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
          . Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
          . Si le pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
          . Une fois la mise à jour terminé
          . Rend-toi dans l'onglet, Recherche
          . Sélectionnes Exécuter un examen complet
          . Cliques sur Rechercher
          . Le scan démarre.
          . A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
          . Cliques sur Ok pour poursuivre.
          . Si des malwares ont été détectés, clique sur Afficher les résultats
          . Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
          . Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
          . Rends toi dans l'onglet rapport/log
          . Tu cliques dessus pour l'afficher, une fois affiché
          . Tu cliques sur edition en haut du boc notes, et puis sur sélectionner tous
          . Tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
          . tu cliques droit dans le cadre de la reponse et coller

          Si tu as besoin d'aide regarde ces tutoriels :
          Aide: https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
          http://www.infos-du-net.com/forum/278396-11-tuto-malwarebytes-anti-malware-mbam

          0
          1. Fix Navipromo version 4.0.5 commencé le 02/01/2010 0:58:51,92

            !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
            !!! Postez ce rapport sur le forum pour le faire analyser !!!

            Outil exécuté depuis C:\Program Files\navilog1

            Mise à jour le 10.11.2009 à 18h00 par IL-MAFIOSO

            Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
            X86-based PC ( Uniprocessor Free : Intel(R) Pentium(R) M processor 1.60GHz )
            BIOS : Phoenix NoteBIOS 4.0 Release 6.0
            USER : Lina ( Administrator )
            BOOT : Normal boot

            C:\ (Local Disk) - NTFS - Total:14 Go (Free:3 Go)
            D:\ (Local Disk) - NTFS - Total:59 Go (Free:59 Go)
            E:\ (CD or DVD)
            G:\ (CD or DVD)

            Recherche executée en mode normal

            Nettoyage exécuté au redémarrage de l'ordinateur

            C:\WINDOWS\prefetch\evgwev*.pf supprimé !
            c:\docume~1\lina\locals~1\applic~1\evgwev.exe supprimé !
            c:\docume~1\lina\locals~1\applic~1\evgwev.dat supprimé !
            c:\docume~1\lina\locals~1\applic~1\evgwev_nav.dat supprimé !
            c:\docume~1\lina\locals~1\applic~1\evgwev_navps.dat supprimé !

            Nettoyage contenu C:\WINDOWS\Temp effectué !
            Nettoyage contenu C:\Documents and Settings\Lina\locals~1\Temp effectué !

            *** Sauvegarde du Registre vers dossier Safebackup ***

            sauvegarde du Registre réalisée avec succès !

            *** Nettoyage Registre ***

            Nettoyage Registre Ok

            *** Scan terminé 02/01/2010 1:02:35,62 ***
            0
            1. Malwarebytes' Anti-Malware 1.43
              Version de la base de données: 3471
              Windows 5.1.2600 Service Pack 2
              Internet Explorer 6.0.2900.2180

              02/01/2010 01:53:06
              mbam-log-2010-01-02 (01-53-06).txt

              Type de recherche: Examen complet (C:\|D:\|E:\|G:\|)
              Eléments examinés: 127599
              Temps écoulé: 33 minute(s), 1 second(s)

              Processus mémoire infecté(s): 0
              Module(s) mémoire infecté(s): 0
              Clé(s) du Registre infectée(s): 0
              Valeur(s) du Registre infectée(s): 0
              Elément(s) de données du Registre infecté(s): 0
              Dossier(s) infecté(s): 0
              Fichier(s) infecté(s): 2

              Processus mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Module(s) mémoire infecté(s):
              (Aucun élément nuisible détecté)

              Clé(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Valeur(s) du Registre infectée(s):
              (Aucun élément nuisible détecté)

              Elément(s) de données du Registre infecté(s):
              (Aucun élément nuisible détecté)

              Dossier(s) infecté(s):
              (Aucun élément nuisible détecté)

              Fichier(s) infecté(s):
              C:\Documents and Settings\Lina\Mes documents\Downloads\Live-Player_setup (1).exe (Adware.NaviPromo) -> Quarantined and deleted successfully.
              C:\Documents and Settings\Lina\Mes documents\Downloads\Live-Player_setup.exe (Adware.NaviPromo) -> Quarantined and deleted successfully.
              0
              1. Et voilà je pense avoir fait les trois étapes... :)
                0
                1. Contributeur sécurité
                  il me manque le rapport usbfix qui se trouve ici
                  C:\UsbFix.txt

                  comment va le pc ?

                  relances RSIT et postes le rapport log stp

                  -

                  Je cherche beaucoup...et parfois je trouve ! 
                  (sourire)
                  0
                  1. ############################## | UsbFix V6.069 |

                    User : Lina (Administrateurs) # LINA-PORTABLE
                    Update on 01/01/2010 by El Desaparecido , C_XX & Chimay8
                    Start at: 01:10:33 | 02/01/2010
                    Website : http://pagesperso-orange.fr/NosTools/index.html
                    Contact : FindyKill.Contact@gmail.com

                    Intel(R) Pentium(R) M processor 1.60GHz
                    Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                    Internet Explorer 6.0.2900.2180
                    Windows Firewall Status : Enabled

                    C:\ -> Disque fixe local # 14,65 Go (4,87 Go free) # NTFS
                    D:\ -> Disque fixe local # 59,87 Go (59,81 Go free) # NTFS
                    E:\ -> Disque CD-ROM
                    G:\ -> Disque CD-ROM

                    ############################## | Processus actifs |

                    C:\WINDOWS\System32\smss.exe 668
                    C:\WINDOWS\system32\csrss.exe 744
                    C:\WINDOWS\system32\winlogon.exe 772
                    C:\WINDOWS\system32\services.exe 816
                    C:\WINDOWS\system32\lsass.exe 828
                    C:\WINDOWS\system32\Ati2evxx.exe 988
                    C:\WINDOWS\system32\svchost.exe 1000
                    C:\WINDOWS\system32\svchost.exe 1084
                    C:\WINDOWS\System32\svchost.exe 1276
                    C:\WINDOWS\system32\svchost.exe 1328
                    C:\WINDOWS\system32\svchost.exe 1400
                    C:\WINDOWS\system32\logonui.exe 1436
                    C:\WINDOWS\system32\ZCfgSvc.exe 1740
                    C:\WINDOWS\Explorer.EXE 1884
                    C:\WINDOWS\system32\spoolsv.exe 164
                    C:\WINDOWS\system32\acs.exe 228
                    C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe 1244
                    C:\WINDOWS\system32\DVDRAMSV.exe 1264
                    C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe 1356
                    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 1636
                    C:\WINDOWS\system32\svchost.exe 1680
                    C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe 1788
                    C:\WINDOWS\system32\wscntfy.exe 1968
                    C:\WINDOWS\System32\alg.exe 496
                    C:\WINDOWS\system32\wbem\wmiprvse.exe 640

                    ################## | Elements infectieux |

                    Supprimé ! C:\Recycler\S-1-5-21-1844237615-920026266-682003330-1003
                    Supprimé ! D:\Recycler\S-1-5-21-1844237615-920026266-682003330-1003

                    ################## | Registre |

                    ################## | Mountpoints2 |

                    Supprimé ! HKCU\...\Explorer\MountPoints2\{85dcb2ec-b81a-11de-9d66-000e35e9af84}\Shell\AutoRun\Command

                    ################## | Listing des fichiers présent |

                    [14/06/2009 12:44|--a------|0] C:\AUTOEXEC.BAT
                    [14/06/2009 19:42|---hs----|212] C:\boot.ini
                    [05/08/2004 13:00|-rahs----|4952] C:\Bootfont.bin
                    [02/01/2010 01:02|--a------|1428] C:\cleannavi.txt
                    [14/06/2009 12:44|--a------|0] C:\CONFIG.SYS
                    [14/06/2009 12:44|-rahs----|0] C:\IO.SYS
                    [14/06/2009 12:44|-rahs----|0] C:\MSDOS.SYS
                    [05/08/2004 13:00|-rahs----|47564] C:\NTDETECT.COM
                    [05/08/2004 13:00|-rahs----|251712] C:\ntldr
                    [29/02/2004 16:44|--a------|52576] C:\orange.bmp
                    [?|?|?] C:\pagefile.sys
                    [14/06/2009 14:50|--a------|16846] C:\PkgClnup.log
                    [02/01/2010 01:11|--a------|2774] C:\UsbFix.txt
                    [14/06/2009 15:03|--ah-----|23447] C:\_NavCClt.Log

                    ################## | Vaccination |

                    # C:\autorun.inf -> Dossier créé par UsbFix.
                    # D:\autorun.inf -> Dossier créé par UsbFix.

                    ################## | Crack > Keygen > Serial |
                    0
                    1. Contributeur sécurité
                      comment va le pc ?

                      relances RSIT et postes juste le rapport log
                      0
                      1. Logfile of random's system information tool 1.06 (written by random/random)
                        Run by Lina at 2010-01-02 13:53:12
                        Microsoft Windows XP Professionnel Service Pack 2
                        System drive C: has 5 GB (33%) free of 15 GB
                        Total RAM: 510 MB (19% free)

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 13:53:19, on 02/01/2010
                        Platform: Windows XP SP2 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\ZCfgSvc.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\WINDOWS\system32\acs.exe
                        C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
                        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        C:\Program Files\Atheros\ACU.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\WINDOWS\system32\RAMASST.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
                        C:\WINDOWS\system32\DVDRAMSV.exe
                        C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
                        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                        C:\WINDOWS\system32\wscntfy.exe
                        C:\Documents and Settings\Lina\Bureau\TAF\RSIT.exe
                        C:\Program Files\trend micro\Lina.exe

                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                        O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                        O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                        O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                        O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                        O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
                        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [ACU] "C:\Program Files\Atheros\ACU.exe" -nogui
                        O4 - HKLM\..\Run: [ZCfgSvc.exe] C:\WINDOWS\system32\ZCfgSvc.exe
                        O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
                        O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                        O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                        O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
                        O23 - Service: Service de configuration Atheros (ACS) - Atheros - C:\WINDOWS\system32\acs.exe
                        O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
                        O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
                        O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
                        O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
                        O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
                        0
                        1. Le PC semble être guéri! Avant lorsque j'ouvrais des pages internet, elles se fermaient toutes seules, et le PC étaient lent... Mais là, tout semble aller pour le mieux! :D
                          0
                          1. Contributeur sécurité
                            ok

                            alors on nettoie

                            1)
                            Cherches et cliques sur C:\Program Files\trend micro\Lina.exe
                            Au menu principal, choisir do a scan only, puis cocher la case devant les lignes suivantes à corriger et cliquer en bas sur Fix Checked

                            O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                            O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                            O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
                            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user'


                            .................................

                            2)
                            Mettre à jour XP
                            https://www.commentcamarche.net/telecharger/systemes-d-exploitation/20759-sp3-windows-xp/

                            Et internet explorer
                            https://support.microsoft.com/fr-fr/allproducts

                            ...........................

                            3)
                            IMPORTANT

                            Purger la restauration systeme XP

                            http://www.bibou0007.com/windows-xp-f101/purger-la-restauration-du-systeme-sous-windows-xp-t151.htm

                            .....................

                            4)
                            Télécharge ToolsCleaner2sur ton Bureau.
                            https://www.commentcamarche.net/telecharger/securite/22061-toolscleaner/

                            * Double-clique (clic droit "en tant qu'administrateur" pour Vista) sur ToolsCleaner2.exe pour le lancer.
                            * Clique sur Recherche et laisse le scan agir.
                            * Clique sur Suppression pour finaliser.
                            * Tu peux, si tu le souhaites, te servir des Options Facultatives.
                            * Clique sur Quitter pour obtenir le rapport.
                            * Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

                            0
                            1. Je viens de m'apercevoir que j'ai oublier de "guérir" une clé, celle de mon i pod! Je pense donc qu'il faut que je relance USBfix pour cette clé...
                              0
                              1. Contributeur sécurité
                                option vaccination
                                0
                                1. En fait j'ai commencé par faire "suppression", puis vaccination. Voilà les deux rapports.

                                  ############################## | UsbFix V6.069 |

                                  User : Lina (Administrateurs) # LINA-PORTABLE
                                  Update on 01/01/2010 by El Desaparecido , C_XX & Chimay8
                                  Start at: 14:11:37 | 02/01/2010
                                  Website : http://pagesperso-orange.fr/NosTools/index.html
                                  Contact : FindyKill.Contact@gmail.com

                                  Intel(R) Pentium(R) M processor 1.60GHz
                                  Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                                  Internet Explorer 6.0.2900.2180
                                  Windows Firewall Status : Enabled

                                  C:\ -> Disque fixe local # 14,65 Go (4,83 Go free) # NTFS
                                  D:\ -> Disque fixe local # 59,87 Go (59,81 Go free) # NTFS
                                  E:\ -> Disque CD-ROM
                                  G:\ -> Disque CD-ROM

                                  ############################## | Processus actifs |

                                  C:\WINDOWS\System32\smss.exe 672
                                  C:\WINDOWS\system32\csrss.exe 736
                                  C:\WINDOWS\system32\winlogon.exe 764
                                  C:\WINDOWS\system32\services.exe 808
                                  C:\WINDOWS\system32\lsass.exe 820
                                  C:\WINDOWS\system32\Ati2evxx.exe 980
                                  C:\WINDOWS\system32\svchost.exe 992
                                  C:\WINDOWS\system32\svchost.exe 1076
                                  C:\WINDOWS\System32\svchost.exe 1268
                                  C:\WINDOWS\system32\svchost.exe 1324
                                  C:\WINDOWS\system32\svchost.exe 1556
                                  C:\WINDOWS\system32\ZCfgSvc.exe 1748
                                  C:\WINDOWS\Explorer.EXE 1884
                                  C:\WINDOWS\system32\spoolsv.exe 168
                                  C:\WINDOWS\system32\acs.exe 208
                                  C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe 1248
                                  C:\WINDOWS\system32\DVDRAMSV.exe 1292
                                  C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe 1380
                                  C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe 1472
                                  C:\WINDOWS\system32\svchost.exe 1572
                                  C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe 1616
                                  C:\WINDOWS\System32\alg.exe 1132
                                  C:\WINDOWS\system32\wscntfy.exe 1776
                                  C:\WINDOWS\system32\wbem\wmiprvse.exe 1452

                                  ################## | Elements infectieux |

                                  Supprimé ! C:\Recycler\S-1-5-21-1844237615-920026266-682003330-1003
                                  Supprimé ! D:\Recycler\S-1-5-21-1844237615-920026266-682003330-1003

                                  ################## | Registre |

                                  ################## | Mountpoints2 |

                                  ################## | Listing des fichiers présent |

                                  [14/06/2009 12:44|--a------|0] C:\AUTOEXEC.BAT
                                  [14/06/2009 19:42|---hs----|212] C:\boot.ini
                                  [05/08/2004 13:00|-rahs----|4952] C:\Bootfont.bin
                                  [02/01/2010 01:02|--a------|1428] C:\cleannavi.txt
                                  [14/06/2009 12:44|--a------|0] C:\CONFIG.SYS
                                  [14/06/2009 12:44|-rahs----|0] C:\IO.SYS
                                  [14/06/2009 12:44|-rahs----|0] C:\MSDOS.SYS
                                  [05/08/2004 13:00|-rahs----|47564] C:\NTDETECT.COM
                                  [05/08/2004 13:00|-rahs----|251712] C:\ntldr
                                  [29/02/2004 16:44|--a------|52576] C:\orange.bmp
                                  [?|?|?] C:\pagefile.sys
                                  [14/06/2009 14:50|--a------|16846] C:\PkgClnup.log
                                  [02/01/2010 14:13|--a------|2631] C:\UsbFix.txt
                                  [14/06/2009 15:03|--ah-----|23447] C:\_NavCClt.Log
                                  [04/11/2009 23:57|---------|0] F:\.metadata_never_index
                                  [04/11/2009 23:58|--ah-----|4096] F:\._.Trashes

                                  ################## | Vaccination |

                                  # C:\autorun.inf -> Dossier créé par UsbFix.
                                  # D:\autorun.inf -> Dossier créé par UsbFix.
                                  # F:\autorun.inf -> Dossier créé par UsbFix.

                                  ################## | Crack > Keygen > Serial |

                                  ################## | Upload |

                                  Veuillez envoyer le fichier : C:\DOCUME~1\Lina\Bureau\UsbFix_Upload_Me_LINA-PORTABLE.zip : https://www.ionos.fr/?affiliate_id=77097
                                  Merci pour votre contribution .

                                  ################## | ! Fin du rapport # UsbFix V6.069 ! |
                                  0
                                  1. ############################## | UsbFix V6.069 |

                                    User : Lina (Administrateurs) # LINA-PORTABLE
                                    Update on 01/01/2010 by El Desaparecido , C_XX & Chimay8
                                    Start at: 14:19:33 | 02/01/2010
                                    Website : http://pagesperso-orange.fr/NosTools/index.html
                                    Contact : FindyKill.Contact@gmail.com

                                    Intel(R) Pentium(R) M processor 1.60GHz
                                    Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
                                    Internet Explorer 6.0.2900.2180
                                    Windows Firewall Status : Enabled

                                    C:\ -> Disque fixe local # 14,65 Go (4,84 Go free) # NTFS
                                    D:\ -> Disque fixe local # 59,87 Go (59,81 Go free) # NTFS
                                    E:\ -> Disque CD-ROM
                                    F:\ -> Disque amovible # 7,39 Go (7,14 Go free) [LINOU'POD] # FAT32
                                    G:\ -> Disque CD-ROM

                                    ################## | Vaccination |

                                    # C:\autorun.inf -> Dossier créé par UsbFix.
                                    # D:\autorun.inf -> Dossier créé par UsbFix.
                                    # F:\autorun.inf -> Dossier créé par UsbFix.

                                    ################## | ! Fin du rapport # UsbFix V6.069 ! |
                                    0
                                    1. Voilà... Est-ce tout bon maintenant? :)
                                      0
                                      1. Voilà j'ai tout fait, sauf qu'à la fin, pour Tcleaner, je ne trouvais pas le rapport (j'ai cliqué sur "quitter" avant de copier-coller le rapport)... Mais j'ai vu que tous les fichiers précédemment téléchargés pour supprimer le virus avaient été supprimés.

                                        J'ai refais Tcleaner une 2e fois, dont voici le rapport:

                                        [ Rapport ToolsCleaner version 2.3.11 (par A.Rothstein & dj QUIOU) ]

                                        --> Recherche:

                                        ---------------------------------
                                        --> Suppression:

                                        Voilà qu'en pensez-vous?
                                        0
                                        • 1
                                        • 2