TR/Downloader.Gen

Résolu
Bonjour, j'ai une saloprie qui revient tout le temps

TR/Downloader.Gen

j'ai avira antivir et à chaque demarrage de mon pc il me demande ce q'u il doit faire du trojan !! je dis acces denied et il revient

que faire svp ???????

Avira AntiVir Personal
Report file date: dimanche 16 novembre 2008 23:57

Scanning for 1036369 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows Vista
Windows version: (Service Pack 1) [6.0.6001]
Boot mode: Normally booted
Username: SYSTEM
Computer name: PC

Version information:
BUILD.DAT : 8.2.0.336 16933 Bytes 30/10/2008 11:40:00
AVSCAN.EXE : 8.1.4.7 315649 Bytes 26/06/2008 09:57:53
AVSCAN.DLL : 8.1.4.0 40705 Bytes 26/05/2008 08:56:40
LUKE.DLL : 8.1.4.5 164097 Bytes 12/06/2008 13:44:19
LUKERES.DLL : 8.1.4.0 12033 Bytes 26/05/2008 08:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 27/10/2008 10:45:20
ANTIVIR1.VDF : 7.1.0.56 411136 Bytes 9/11/2008 10:45:21
ANTIVIR2.VDF : 7.1.0.89 221184 Bytes 16/11/2008 20:26:33
ANTIVIR3.VDF : 7.1.0.90 2048 Bytes 16/11/2008 20:26:34
Engineversion : 8.2.0.31
AEVDF.DLL : 8.1.0.6 102772 Bytes 14/10/2008 11:05:56
AESCRIPT.DLL : 8.1.1.15 332156 Bytes 16/11/2008 10:45:30
AESCN.DLL : 8.1.1.5 123251 Bytes 16/11/2008 10:45:30
AERDL.DLL : 8.1.1.3 438645 Bytes 16/11/2008 10:45:29
AEPACK.DLL : 8.1.3.4 393591 Bytes 16/11/2008 10:45:28
AEOFFICE.DLL : 8.1.0.30 196986 Bytes 16/11/2008 10:45:27
AEHEUR.DLL : 8.1.0.71 1487222 Bytes 16/11/2008 10:45:26
AEHELP.DLL : 8.1.1.3 119157 Bytes 16/11/2008 10:45:25
AEGEN.DLL : 8.1.1.0 319859 Bytes 16/11/2008 10:45:24
AEEMU.DLL : 8.1.0.9 393588 Bytes 14/10/2008 11:05:56
AECORE.DLL : 8.1.4.1 172405 Bytes 16/11/2008 10:45:24
AEBB.DLL : 8.1.0.3 53618 Bytes 14/10/2008 11:05:56
AVWINLL.DLL : 1.0.0.12 15105 Bytes 9/07/2008 09:40:05
AVPREF.DLL : 8.0.2.0 38657 Bytes 16/05/2008 10:28:01
AVREP.DLL : 8.0.0.2 98344 Bytes 16/11/2008 10:45:23
AVREG.DLL : 8.0.0.1 33537 Bytes 9/05/2008 12:26:40
AVARKT.DLL : 1.0.0.23 307457 Bytes 12/02/2008 09:29:23
AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 12/06/2008 13:27:49
SQLITE3.DLL : 3.3.17.1 339968 Bytes 22/01/2008 18:28:02
SMTPLIB.DLL : 1.2.0.23 28929 Bytes 12/06/2008 13:49:40
NETNT.DLL : 8.0.0.1 7937 Bytes 25/01/2008 13:05:10
RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 12/06/2008 14:48:07
RCTEXT.DLL : 8.0.52.0 86273 Bytes 27/06/2008 14:34:37

Configuration settings for the scan:
Jobname..........................: Complete system scan
Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: on
Scan boot sector.................: on
Boot sectors.....................: C:,
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: dimanche 16 novembre 2008 23:57

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'SearchFilterHost.exe' - '1' Module(s) have been scanned
Scan process 'SearchProtocolHost.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'Azureus.exe' - '1' Module(s) have been scanned
Scan process 'wmpnetwk.exe' - '1' Module(s) have been scanned
Scan process 'nSvcIp.exe' - '1' Module(s) have been scanned
Scan process 'nSvcAppFlt.exe' - '1' Module(s) have been scanned
Scan process 'SearchIndexer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'PnkBstrA.exe' - '1' Module(s) have been scanned
Scan process 'nTuneService.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'ehmsas.exe' - '1' Module(s) have been scanned
Scan process 'wmpnscfg.exe' - '1' Module(s) have been scanned
Scan process 'VistaStartMenu.exe' - '1' Module(s) have been scanned
Scan process 'ehtray.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'RtHDVCpl.exe' - '1' Module(s) have been scanned
Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
Scan process 'comrepl.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'dwm.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'taskeng.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'SLsvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'audiodg.exe' - '0' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'nvvsvc.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsm.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'wininit.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
53 processes with 53 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!

Starting to scan the registry.
The registry was scanned ( '35' files ).

Starting the file scan:

Begin scan in 'C:\' <HDD Western Digital>
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Windows\System32\drivers\sptd.sys
[WARNING] The file could not be opened!

End of the scan: lundi 17 novembre 2008 00:59
Used time: 1:02:15 Hour(s)

The scan has been done completely.

18125 Scanning directories
356005 Files were scanned
0 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
0 files were moved to quarantine
0 files were renamed
2 Files cannot be scanned
356003 Files not concerned
1862 Archives were scanned
2 Warnings
0 Notes
Configuration: Windows Vista
Firefox 3.0.4

97 réponses

Résumé de la discussion

Une détection récurrente TR/Downloader.Gen est signalée par Avira AntiVir Personal lors du démarrage, accompagnée d’un message d’accès refusé et d’une demande d’action sur le Trojan. Le diagnostic indique qu’aucun virus n’a été détecté lors du balayage complet et que certains fichiers n’ont pas pu être ouverts, ce qui peut laisser penser à un faux positif ou à des fichiers protégés. Des conseils complémentaires préconisent de mettre à jour les définitions, de relancer un scan en mode sans échec et d’envisager l’emploi d’outils complémentaires pour confirmer l’absence d’infection. En cas de doute persistant, l’emploi d’un second antivirus ou d’un outil anti‑rootkit peut être envisagé, tout en restant prudent avec les fichiers système bloqués lors du premier balayage.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Re,

    poste le rapport du scan effectué par antivir avec la mention du nom du fichier infecté.

    On n'a pas besoin du log de toutes les opérations effectuées par antivir depuis son installation.

    Quant à ça : hé si pas d'aide !! il est evident que je poserai la qestion ailleur qd meme

    totobetourne en fera ce qu'il voudra, en ce qui me concerne, tu te débrouilles désormais sans moi.

    3
    1. bonjour

      1)pour vista si infection.

      Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection: IMPORTANT A NE SURTOUT PAS OUBLIER):

      - Va dans démarrer puis panneau de configuration
      - Double Clique sur l'icône "Comptes d'utilisateurs"
      - Clique ensuite sur désactiver et valide.

      http://www.laboratoire-microsoft.org/tips-23933-desactiver-uac-vista.html

      2)telecharge cela:util pour voir ce que peut etre l infection et agir ensuite.

      http://www.commentcamarche.net/telecharger/telecharger 159 hijackthis

      installe le normallement comme tout autre programme dans c/programme/...............
      clique sur do a scan and save a logfile, tu obtiens un rapport que tu colles.
      parfois alerte comme quoi, sans la fonction administrateur le rapport ne peut pas etre complet .
      a ce moment relance hijack avec un clique droit sur le raccourci et executer en tant qu administrateur.
      1
      1. re ! merci de ton aide d'abord ! :)

        voici le rapport demandé :

        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 18:40:21, on 17/11/2008
        Platform: Windows Vista SP1 (WinNT 6.00.1905)
        MSIE: Internet Explorer v8.00 (8.00.6001.18241)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Windows\RtHDVCpl.exe
        C:\Program Files\Java\jre6\bin\jusched.exe
        C:\Users\Kira\AppData\Roaming\esentutl.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\Windows\ehome\ehtray.exe
        C:\Program Files\Vista Start Menu\VistaStartMenu.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Windows\ehome\ehmsas.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
        F3 - REG:win.ini: load=C:\Users\Kira\AppData\Roaming\esentutl.exe
        O1 - Hosts: ::1 localhost
        O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dll
        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
        O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
        O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
        O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
        O4 - HKCU\..\Run: [VistaStartMenu] "C:\Program Files\Vista Start Menu\VistaStartMenu.exe"
        O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
        O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
        O4 - HKLM\..\Policies\Explorer\Run: [ComRepl] C:\Users\Kira\AppData\Roaming\MICROS~1\comrepl.exe /waitservice
        O4 - HKCU\..\Policies\Explorer\Run: [CmSTP] C:\Windows\cmstp.exe /waitservice
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [Spool] C:\Users\Kira\AppData\Roaming\spoolsv.exe /waitservice (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [Spool] C:\Users\Kira\AppData\Roaming\spoolsv.exe /waitservice (User 'Default user')
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
        O13 - Gopher Prefix:
        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
        O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} - https://www.eset.com/
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: Application Driver Auto Removal Service (01) (appdrvrem01) - Protection Technology - C:\Windows\System32\appdrvrem01.exe
        O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
        O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
        O23 - Service: nTune Service (nTuneService) - NVIDIA - C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
        O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
        O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
        O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
        0
      2. @Light-YagamiBonjour,
        J'ai le même trojan,
        Voici mon rapport. Merci
        Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 22:31:53, on 17/11/2008
        Platform: Windows XP SP3 (WinNT 5.01.2600)
        MSIE: Internet Explorer v7.00 (7.00.6000.16735)
        Boot mode: Normal

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
        C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\system32\RunDll32.exe
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
        C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
        C:\Program Files\Razer\Reclusa\razerhid.exe
        C:\WINDOWS\system32\dumprep.exe
        C:\Program Files\CyberLink\PCM4Everio\EverioService.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
        C:\WINDOWS\system32\rundll32.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
        C:\Program Files\Microsoft ActiveSync\wcescomm.exe
        C:\Program Files\Razer\Reclusa\razertra.exe
        C:\Documents and Settings\cédric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
        C:\PROGRA~1\MICROS~4\rapimgr.exe
        C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
        C:\WINDOWS\System32\drivers\comrepl.exe
        C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avnotify.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.1.1:1
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
        F3 - REG:win.ini: load=C:\WINDOWS\System32\drivers\comrepl.exe
        O1 - Hosts: 169.254.41.199 NPIF9EB29
        O1 - Hosts: 169.254.41.199 NPIF9EB29
        O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
        O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files\Winamp Toolbar\winamptb.dll
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - (no file)
        O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
        O2 - BHO: (no name) - {A88CC5B3-A813-1EA8-EC13-8BB18BDA85CA} - (no file)
        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
        O2 - BHO: (no name) - {F34F3015-35CD-1AF0-BA2A-90574F0F1D06} - (no file)
        O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
        O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
        O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
        O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
        O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
        O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [Reclusa] C:\Program Files\Razer\Reclusa\razerhid.exe
        O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
        O4 - HKLM\..\Run: [EverioService] "C:\Program Files\CyberLink\PCM4Everio\EverioService.exe"
        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
        O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
        O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\cédric\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
        O4 - HKLM\..\Policies\Explorer\Run: [SessMgr] C:\WINDOWS\System32\drivers\sessmgr.exe /waitservice
        O4 - HKCU\..\Policies\Explorer\Run: [rsvp] C:\WINDOWS\System\rsvp.exe /waitservice
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [SessMgr] C:\WINDOWS\System\sessmgr.exe /waitservice (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
        O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [SessMgr] C:\WINDOWS\System\sessmgr.exe /waitservice (User 'Default user')
        O8 - Extra context menu item: &Winamp Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
        O8 - Extra context menu item: Choisir comme avatar MSN - C:\Program Files\MSN Pictures Displayer\AddIEPicture.htm
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
        O8 - Extra context menu item: Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
        O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
        O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
        O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
        O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe (file missing)
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O14 - IERESET.INF: START_PAGE_URL=http://www.carrefour.fr/
        O16 - DPF: teleir_cert - https://static.ir.dgi.minefi.gouv.fr/secure/connexion/archives/ie4n4/teleir_cert.cab
        O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab28578.cab
        O16 - DPF: {09F1ADAC-76D8-4D0F-99A5-5C907DADB988} - http://fr.systemdoctor.com/download/2006/cab/SystemDoctor2006FreeInstall_fr.cab
        O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
        O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
        O16 - DPF: {4CCA4E80-9259-11D9-AC6E-444553544200} (FixController Control) - http://h30155.www3.hp.com/ediags/dd/install/HPInstallMgr_v01_6.cab
        O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://cedricbasquin.spaces.msn.com//PhotoUpload/MsnPUpld.cab
        O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
        O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
        O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab28578.cab
        O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.photoways.com/clients/ImageUploader3.cab
        O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/msnmessengersetupdownloader.cab
        O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - https://www.3ds.com/products-services/3dvia/
        O16 - DPF: {CE3409C4-9E26-4F8E-83E4-778498F9E7B4} (PB_Uploader Class) - http://www.photoways.com/clients/uploader_v2.2.0.6.cab
        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
        O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
        O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
        O17 - HKLM\System\CCS\Services\Tcpip\..\{CCB97ACC-483C-46C9-8168-CD49C938953B}: NameServer = 212.27.53.252,212.27.54.252
        O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
        O20 - Winlogon Notify: 4E - C:\WINDOWS\system32\4E.tmp (file missing)
        O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
        O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
        O23 - Service: Client de licence CA (CA_LIC_CLNT) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmt.exe
        O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\lic98rmtd.exe
        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
        O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
        O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
        O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
        O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
        O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
        O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
        0
    2. personne pour aider ????????????????
      0
      1. Contributeur sécurité
        Bonjour,

        en attendant totobetourne,

        1) règle antivir pour activer le scanner de rootkit

        2) fais un scan avec mise en quarantaine du trojan (et pas acces denied)

        3) poste le rapport avec l'indication du fichier infecté.
        2
        1. 18.11.2008 11:44:35 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
          18.11.2008 11:44:35 - Backup Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\BACKUP\
          18.11.2008 11:44:35 - Temp Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\TEMP\AVUPDATE_49229c8f\
          18.11.2008 11:44:35 - Using System's global Proxy settings
          18.11.2008 11:44:35 - Launching GUI... display mode: 1
          18.11.2008 11:44:36 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlib.dll
          18.11.2008 11:44:36 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlibrc.dll
          18.11.2008 11:44:35 - Installation Directory: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
          18.11.2008 11:44:35 - Backup Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\BACKUP\
          18.11.2008 11:44:35 - Temp Directory: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\TEMP\AVUPDATE_49229c8f\
          18.11.2008 11:44:35 - Using System's global Proxy settings
          18.11.2008 11:44:35 - Launching GUI... display mode: 1
          18.11.2008 11:44:36 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlib.dll
          18.11.2008 11:44:36 - selftest successful: C:\Program Files\Avira\AntiVir PersonalEdition Classic\updlibrc.dll
          18.11.2008 11:44:36 - Avira AntiVir Personal - Free Antivirus
          18.11.2008 11:44:38 - Copy file C:\ProgramData\Avira\AntiVir PersonalEdition Classic\TEMP\AVUPDATE_49229c8f\idx/master.idx to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\IDX\master.idx
          18.11.2008 11:44:38 - Master IDX file has changed
          18.11.2008 11:44:39 - Downloading the product.info file from http://dl6.avgate.net/upd/idx/vdf.info.gz
          18.11.2008 11:44:40 - Downloading the product.info file from http://dl6.avgate.net/upd/idx/specvir-nt.info.gz
          18.11.2008 11:44:41 - Downloading the product.info file from http://dl6.avgate.net/upd/idx/ave2.info.gz
          18.11.2008 11:44:41 - Downloading the product.info file from http://dl6.avgate.net/upd/idx/info-wks-classic-nt-en.info.gz
          18.11.2008 11:44:42 - Module: SELFUPDATE Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 15
          18.11.2008 11:44:43 - Module: MAIN Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 85
          18.11.2008 11:44:50 - Module: COMMAPPDATA_AV Source: winwks\en\ Destination: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\ Files: 1
          18.11.2008 11:44:50 - Module: COMMAPP Source: winwks\en\ Destination: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\JOBS\ Files: 4
          18.11.2008 11:44:50 - Module: COMMAPDATA_AV_PROFILES Source: winwks\en\ Destination: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\PROFILES\ Files: 2
          18.11.2008 11:44:50 - Module: TEXT Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 3
          18.11.2008 11:44:50 - Module: VDF Source: vdf\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 4
          18.11.2008 11:44:55 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir3.vdf 7.1.0.98 < 7.1.0.101
          18.11.2008 11:44:55 - Module: AVREP_NT Source: engine\nt\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 1
          18.11.2008 11:44:55 - Module: AVE2 Source: ave2\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 14
          18.11.2008 11:44:55 - Module: DRV Source: winwks\en\ Destination: C:\Windows\SYSTEM32\drivers\ Files: 4
          18.11.2008 11:44:55 - Module: PRODINFO Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 1
          18.11.2008 11:44:55 - Minifilter is installed
          18.11.2008 11:44:55 - Minifilter is possible
          18.11.2008 11:44:55 - Reading registry value successful: Software\Avira\AntiVir PersonalEdition Classic | FilterType
          18.11.2008 11:44:55 - File basic-nt/xp/avgntdd.sys which was recognized as modified, must not be updated
          18.11.2008 11:44:55 - File basic-nt/xp/avgntmgr.sys which was recognized as modified, must not be updated
          18.11.2008 11:44:55 - The Module DRV which was recognized as modified, must not be updated
          18.11.2008 11:44:55 - Initialize avnotify.exe
          18.11.2008 11:44:55 - Starting avnotify.exe successful
          18.11.2008 11:44:55 - Preparing to download files
          18.11.2008 11:44:55 - 1 files need to be downloaded / copied from http://dl6.avgate.net/upd/
          18.11.2008 11:44:55 - #1: Downloading and extracting http://dl6.avgate.net/upd/vdf/antivir3.vdf.gz to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\TEMP\AVUPDATE_49229c8f\vdf\antivir3.vdf
          18.11.2008 11:45:07 - Keyfile: OK [FULL Mode]
          18.11.2008 11:45:07 - Status of service AntiVirService is running
          18.11.2008 11:45:07 - Starting to install
          18.11.2008 11:45:07 - Copy file C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir3.vdf to C:\ProgramData\Avira\AntiVir PersonalEdition Classic\BACKUP\antivir3.vdf
          18.11.2008 11:45:07 - Processing module VDF Source: C:\ProgramData\Avira\AntiVir PersonalEdition Classic\TEMP\AVUPDATE_49229c8f\vdf\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\
          18.11.2008 11:45:07 - Copy file C:\ProgramData\Avira\AntiVir PersonalEdition Classic\TEMP\AVUPDATE_49229c8f\vdf\antivir3.vdf to C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir3.vdf
          18.11.2008 11:45:07 - A total of 1 files were updated
          18.11.2008 11:45:07 - Initialize AVWSC.EXE
          18.11.2008 11:45:07 - Registry entry created successfully: Software\Avira\AntiVir PersonalEdition Classic |UpdateInProgress
          18.11.2008 11:45:07 - Status of service AntiVirService is running
          18.11.2008 14:09:39 - Reinitialization of AntiVirService carried out successfully.
          18.11.2008 14:09:39 - Dialup: 0
          18.11.2008 14:09:39 - Downloaded bytes: 96349
          18.11.2008 14:09:39 - Downloaded file(s): 1
          18.11.2008 14:09:39 - Downloaded file(s): antivir3.vdf
          18.11.2008 14:09:39 - Required time: 25:07
          18.11.2008 14:09:39 - Registry entry created successfully: Software\Avira\AntiVir PersonalEdition Classic |LastUpdate
          18.11.2008 14:09:40 - Update finished successfully
          0
          1. dsl mais le point 3 ne parait pas clair ...
            le raport que j'ai , est tellement grd qu'il ne rentre pas sur le site ....

            hé si pas d'aide !! il est evident que je poserai la qestion ailleur qd meme

            c un pc a 1200 euro alors il me faut une solution .....
            0
            1. nouveaux virus !!!

              Virus or unwanted program 'TR/ATRAPS.Gen [trojan]'
              detected in file 'C:\Users\Kira\AppData\Local\Temp\~tmp\lvprf03\lvprf03.exe.
              Action performed: Move file to quarantine

              Virus or unwanted program 'TR/ATRAPS.Gen [trojan]'
              detected in file 'C:\Users\Kira\AppData\Local\Temp\~tmp\lvprf03\lvprf03.exe.
              Action performed: Move file to quarantine

              Virus or unwanted program 'TR/ATRAPS.Gen [trojan]'
              detected in file 'C:\Users\Kira\AppData\Local\Temp\~tmp\lvprf03\lvprf03.exe.
              Action performed: Move file to quarantine

              Virus or unwanted program 'TR/Downloader.Gen [trojan]'
              detected in file 'C:\Users\Kira\AppData\Local\Temp\~tmp\shbdchk10\shbdchk10.exe
              Action performed: Move file to quarantine

              Virus or unwanted program 'TR/Downloader.Gen [trojan]'
              detected in file 'C:\Users\Kira\AppData\Local\Temp\~tmp\shbdchk10\shbdchk10.exe.
              Action performed: Move file to quarantine

              ????????????????????????????????????????? svp
              0
              1. ok merci !!!!!!

                je sais ce qui me reste à faire

                ciao !!
                -1
                1. merci à comment ça marche !

                  bonne continuation .... à vous
                  0
                  1. dommage , je ne reviens que maintenant.allez reviens.

                    pas mal de probleme sur ton hijack, si tu revenais apres avoir mis le rapport antivir et bien l activer est bien important tout de meme pour reussir un scan tout de meme realiste + ou -.

                    ensuite passe cet outil
                    Bonjour,

                    *Télécharge SDFix (créé par AndyManchesta)
                    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
                    *Double-clique sur SDFix.exe
                    *Choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
                    *Redémarre en mode sans échec
                    *Ouvre le dossier SDFix qui vient d'être créé à la racine de ton disque dur C:\
                    *Double clique sur RunThis.bat pour lancer le script. (Le .bat peut ne pas apparaître)
                    *Appuie sur Y pour commencer le processus de nettoyage.
                    *Appuie sur une touche pour redémarrer quand SDFix te demander d'appuyer sur une touche pour redémarrer.
                    *Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                    *Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                    *Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                    *Les icônes du Bureau affichées, le rapport SDFix s'ouvrira. Il porte le nom de Report.txt.
                    *Copie/colle le contenu

                    *Si Sdfix ne se lance pas
                    * Clique sur Démarrer > Exécuter
                    *Copie/colle ceci: %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe
                    *Clique sur Ok.
                    *Redémarre et essaie de relance SDFix.
                    0
                    1. merci de ton aide ;)

                      "apres avoir mis le rapport antivir et bien l activer est bien important tout de meme pour reussir un scan tout de meme realiste + ou -. "

                      activer ??

                      je dois refaire un scan c ça ?? ou je fais maintenant le SDFix

                      sorry pas capter :(

                      :) thx
                      0
                      1. autrement dis , je peux faire le SDfix directement ???

                        c ça ?

                        thx :)
                        0
                        1. Bonjour,
                          L'attaque des virus s'intensifie, pourriez vous détaillez clairement la procédure pour se débarrasser de ces 3 Trojans.
                          Merci beaucoup, a vous.
                          0
                      2. ne trouve pas executer en mode ss echec ... SDfix ne demarre pas meme en mode ss echec ....

                        :( :( :( :( :( :( :( :(:( : (: (:( :(

                        79 detection depuis 4 jours ....
                        0
                        1. Hi,

                          passe ceci avant alors:

                          ==>>Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.<<===

                          Toolbar-S&D

                          !! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!

                          * double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...

                          * Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .

                          * Choisis l'option 1 ( "recherche") et tapes "entrée" .

                          * Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
                          de son contenu dans ta prochaine réponse ...

                          ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

                          Alut.

                          PS:Ne vas pas ailleurs sert à rien de dire cela c'est un forum et chacun et libre de ou pas te répondre.
                          0
                          1. merci de ton aide !! :)

                            voici le rapport demandé...

                            On Error Resume Next
                            Dim fso
                            Set FSO = CreateObject("Scripting.FileSystemObject")
                            Set FTX = FSO.createTextFile("OS_v.txt",true)
                            strComputer = "."
                            Set objWMIService = GetObject("winmgmts:" & "{impersonationLevel=impersonate}!\\" & _
                            strComputer & "\root\cimv2")

                            Set OS__infos = objWMIService.ExecQuery("Select * from Win32_OperatingSystem")
                            Set BO__infos = objWMIService.ExecQuery("Select * from Win32_ComputerSystem")
                            Set US__infos = objWMIService.ExecQuery("Select * from Win32_NetworkLoginProfile")
                            Set PR__infos = objWMIService.ExecQuery("Select * from Win32_Processor")
                            Set BI__infos = objWMIService.ExecQuery("Select * from Win32_BIOS")
                            Set DI__infos = objWMIService.ExecQuery("Select * from Win32_LogicalDisk",,48)
                            Set objWMISecurity = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\SecurityCenter")
                            Set colAV = objWMISecurity.ExecQuery("Select * from AntiVirusProduct")
                            Set colFI = objWMISecurity.ExecQuery("Select * from FirewallProduct")
                            Set wshNetwork = CreateObject("WScript.Network")
                            strUser = wshNetwork.Username
                            For Each objOS__ in OS__infos
                            OSvers = objOS__.Caption & " ( v" & objOS__.Version & " ) " & objOS__.CSDVersion
                            OSbuild = objOS__.BuildType
                            Next
                            For Each objBO__ in BO__infos
                            BOprocT = objBO__.SystemType
                            Next
                            For Each objPR__ in PR__infos
                            PRprocN = objPR__.Name
                            Next
                            For Each objBI__ in BI__infos
                            BIbios = "BIOS : " & objBI__.Name
                            Next
                            For Each objUS__ in US__infos
                            If objUS__.Privileges = 2 Then
                            USuser = "USER : " & strUser & " ( Administrator )"
                            Else
                            USuser = "USER : " & strUser & " ( Not Administrator ! )"
                            End If
                            Next
                            For Each objBO__ in BO__infos
                            BOboot = "BOOT : " & objBO__.BootupState
                            Next
                            For Each objAV In colAV
                            If objAV.OnAccessScanningEnabled = 0 Then
                            AVstatus = "Not Activated"
                            Else
                            AVstatus = "Activated"
                            End If
                            Next
                            For Each objFI In colFI
                            If objFI.Enabled = 0 Then
                            FIstatus = "Not Activated"
                            Else
                            FIstatus = "Activated"
                            End If
                            Next
                            For Each objAV in colAV
                            AVstat = "Antivirus : " & objAV.DisplayName & " " & objAV.VersionNumber & " (" & AVstatus & ")"
                            Next
                            For Each objFI In colFI
                            FIstat = "Firewall : " & objFI.DisplayName & " " & objFI.VersionNumber & " (" & FIstatus & ")"
                            Next
                            For Each objDI__ in DI__infos
                            Select Case objDI__.DriveType
                            Case 1 strTL = "..."
                            Case 2 strTL = "USB"
                            Case 3 strTL = "Local Disk"
                            Case 4 strTL = "Network Disk"
                            Case 5 strTL = "CD or DVD"
                            Case 6 strTL = "RAM"
                            Case Else strTL = "..."
                            End Select
                            If objDI__.DriveType =2 Then
                            strTD = Int(objDI__.Size /1048576) & " Mo"
                            Else
                            strTD = Int(objDI__.Size /1073741824) & " Go"
                            End If
                            if strTD = " Go" Then
                            strDI = strDI & objDI__.Name & "\ (" & strTL & ")" & vbCrlf
                            elseif strTD = " Mo" Then
                            strDI = strDI & objDI__.Name & "\ (" & strTL & ")" & vbCrlf
                            else
                            strDI = strDI & objDI__.Name & "\ (" & strTL & ") - " & objDI__.FileSystem & _
                            " - Total:" & strTD & " (Free:" & Int(objDI__.FreeSpace /1073741824) & " Go)" & vbCrlf
                            end if
                            Next
                            FTX.writeline OSvers
                            FTX.writeline BOprocT & " ( " & OSbuild & " : " & PRprocN & " )"
                            FTX.writeline BIbios
                            FTX.writeline USuser
                            FTX.writeline BOboot
                            FTX.writeline ""
                            FTX.writeline AVstat
                            FTX.writeline FIstat
                            FTX.writeline ""
                            FTX.writeline strDI
                            FTX.close
                            0
                            1. faut comprendre que sans les rapports complet apres mise a jour , on ne peut pas avancer.
                              tu as differentes infections , il faut les traiter petit a petit.

                              1)fait toolbar sd comme indique .fait le en option 1 et ensuite en option 2 (suppression), , colle les rapports obtenus a chaque fois.

                              2)puis fait sd fix comme indique et le rapport

                              3)puis fait antivir comme indique apres l avoir bien configurer si tu comprends mieux.fait un scan complet apres mise a jour

                              4)et pour finir refais nous un rapport hijack et colle le comme les autres.
                              0
                              1. ne ressemble pas a cela le rapport toolbar sd , as tu bien tout fait comme indique?
                                0
                                1. ok je vois , mais voici le rapport , mais je n'ai aucun possibilité d'accéder au point 2 "suppression" il me mets "fin de rapport sur fond rouge mais pas de popssiblité de revenir en menu de "toolbar SD "

                                  comment et ou ? entré "2" pour suppression ???

                                  deso c lourd ... :( mais suis noob ...

                                  -----------\\ ToolBar S&D 1.2.4 XP/Vista

                                  "C:\ToolBar SD" ( MAJ : 27-10-2008|09:25 )
                                  Option : [1] ( mer. 19/11/2008|17:50 )

                                  [ UAC => 1 ]

                                  -----------\\ Recherche de Fichiers / Dossiers ...

                                  C:\Program Files\Search Settings
                                  C:\Program Files\Search Settings\kb127
                                  C:\Program Files\Search Settings\SearchSettings.exe

                                  -----------\\ [..\Internet Explorer\Main]

                                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                                  "Local Page"="C:\\Windows\\system32\\blank.htm"
                                  "Url"="https://www.msn.com/fr-fr/actualite/"

                                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                  "Start Page"="https://www.msn.com/fr-fr/?ocid=iehp"
                                  "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                                  "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                                  "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                                  --------------------\\ Recherche d'autres infections

                                  Aucune autre infection trouvée !

                                  [ UAC => 1 ]

                                  1 - "C:\ToolBar SD\TB_1.txt" - mer. 19/11/2008|17:48 - Option : [1]
                                  2 - "C:\ToolBar SD\TB_2.txt" - mer. 19/11/2008|17:50 - Option : [1]

                                  -----------\\ Fin du rapport a 17:50:16,98
                                  0
                                  1. voila je pense avoir trouvé ????

                                    second rapport :

                                    -----------\\ ToolBar S&D 1.2.4 XP/Vista

                                    "C:\ToolBar SD" ( MAJ : 27-10-2008|09:25 )
                                    Option : [2] ( mer. 19/11/2008|17:57 )

                                    [ UAC => 1 ]

                                    -----------\\ SUPPRESSION

                                    Supprime! - C:\Program Files\Search Settings\kb127
                                    Supprime! - C:\Program Files\Search Settings\SearchSettings.exe
                                    Supprime! - C:\Program Files\Search Settings

                                    -----------\\ Recherche de Fichiers / Dossiers ...

                                    -----------\\ [..\Internet Explorer\Main]

                                    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                                    "Local Page"="C:\\Windows\\system32\\blank.htm"
                                    "Url"="https://www.msn.com/fr-fr/actualite/"

                                    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                    "Start Page"="https://www.msn.com/fr-fr/"
                                    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                                    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
                                    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"

                                    --------------------\\ Recherche d'autres infections

                                    Aucune autre infection trouvée !

                                    [ UAC => 1 ]

                                    1 - "C:\ToolBar SD\TB_1.txt" - mer. 19/11/2008|17:48 - Option : [1]
                                    2 - "C:\ToolBar SD\TB_2.txt" - mer. 19/11/2008|17:50 - Option : [1]
                                    3 - "C:\ToolBar SD\TB_3.txt" - mer. 19/11/2008|17:57 - Option : [2]

                                    -----------\\ Fin du rapport a 17:57:21,94
                                    0
                                    1. impossible d'ouvrir SDfix , je ne trouve pas "executer" en mode ss echec ...

                                      donc impossible de rentrer la commande :

                                      %systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

                                      les touches pour accéder aux commandes svp ??? je ne les connais pas :(

                                      merci d'avance ....
                                      0
                                      • 1
                                      • 2
                                      • 3
                                      • 4
                                      • 5