J'ai deux fichiers (online security guide et live safety center) qui sont apparus dans mon menu démarrer et triangle jaune qui me dit que mon PC est infecté par PSW trojan. J'ai suivi la procédure de pré-nettoyage d'un PC infecté (scan Antivir et rapport HijackThis en mode sans échec --> rapports joints plus bas). Antivir a effectué une désinfection. Etant donné que j'avais Avast, je l'ai désinstallé et remplaçé par Antivir. Depuis, je n'arrive plus a lancer le mode normal car au démarrage je suis bloqué sur une fenêtre d'Antivir qui essaye d'éradiquer un fichier nommé _c001E674.dat dans le répertoire system32 de windows. quelqu'un peur-il m'aider à me sortir de cette panade? merci d'avance


Rapport HijackThis :


Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 08:35:27, on 24/11/2007

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Boot mode: Safe mode


Running processes:








C:\Downloads\procedure virus\hijackthis\HijackThis.exe


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx

O2 - BHO: Flashget Catch Url Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll

O2 - BHO: (no name) - {40205287-E793-41AC-B95C-D8D064BA33CA} - (no file)

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll

O2 - BHO: (no name) - {7D5085E4-75D2-4503-8A36-2560551AF48D} - (no file)

O2 - BHO: {fec6d653-8372-6bf9-2594-5e305aa9ee58} - {85ee9aa5-03e5-4952-9fb6-2738356d6cef} - C:\WINDOWS\system32\cxlhhsxx.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll

O2 - BHO: CAdBlocker Object - {E24AD748-155E-4254-B674-4EDF86E7E1DF} - (no file)

O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll

O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll

O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar1.01.2607.0\fr\msntb.dll

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [ssAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [M-Audio Delta Taskbar Icon] C:\WINDOWS\System32\DeltTray.exe

O4 - HKLM\..\Run: [DeltTray] DeltTray.exe

O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup

O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized

O4 - HKLM\..\Run: [Emjysoft_Partage_Scan_Client] C:\Program Files\Emjysoft\Partage Scan\Client\scan.exe start

O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe

O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm

O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe

O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe


O16 - DPF: fdjeux -

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) -

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} -

O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} -

O17 - HKLM\System\CCS\Services\Tcpip\..\{25031501-951F-4B3C-A830-F7DCA33455A9}: NameServer =,

O17 - HKLM\System\CS1\Services\Tcpip\..\{25031501-951F-4B3C-A830-F7DCA33455A9}: NameServer =,

O17 - HKLM\System\CS2\Services\Tcpip\..\{25031501-951F-4B3C-A830-F7DCA33455A9}: NameServer =,

O20 - Winlogon Notify: wwedwrgg - wwedwrgg.dll (file missing)

O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Fichiers communs\Autodesk Shared\Service\AdskScSrv.exe

O23 - Service: Service Elève pcAnywhere (awhost32) - Unknown owner - C:\Program Files\Symantec\pcAnywhere\awhost32.exe (file missing)

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Unknown owner - C:\Program Files\Bonjour\mDNSResponder.exe (file missing)

O23 - Service: COM+ Alerter Service - Unknown owner - C:\WINDOWS\system32\altsvc.exe

O23 - Service: DCPFLICS - Unknown owner - C:\Program Files\DCPFLICS\DCPFLICS.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Jaws Service (JawsService.exe) - SpeedSix Software Ltd. - C:\Program Files\SpeedSix\bin\JawsService.exe

O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe

O23 - Service: mental ray 3.6 Satellite for Autodesk 3ds Max 2008 32-bit 32-bit (mi-raysat_3dsMax2008_32) - Unknown owner - C:\Program Files\Autodesk\3ds Max 2008\mentalray\satellite\raysat_3dsMax2008_32server.exe

O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\MSCSPTISRV.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\PACSPTISVR.exe

O23 - Service: Sentinel Protection Server (SentinelProtectionServer) - SafeNet, Inc - C:\Program Files\Fichiers communs\SafeNet Sentinel\Sentinel Protection Server\WinNT\spnsrvnt.exe

O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Fichiers communs\Sony Shared\AVLib\SPTISRV.exe

O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe



End of file - 8082 bytes


Rapport Antivir :


AntiVir PersonalEdition Classic

Report file date: vendredi 23 novembre 2007 15:39


Scanning for 941284 virus strains and unwanted programs.


Licensed to: Avira AntiVir PersonalEdition Classic

Serial number: 0000149996-ADJIE-0001

Platform: Windows XP

Windows version: (Service Pack 2) [5.1.2600]

Username: soriano francois

Computer name: PAKITO


Version information:

BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00

AVSCAN.EXE : 290856 Bytes 23/08/2007 13:16:29

AVSCAN.DLL : 49192 Bytes 16/08/2007 12:23:51

LUKE.DLL : 147496 Bytes 14/08/2007 15:32:47

LUKERES.DLL : 10280 Bytes 21/08/2007 12:35:20

ANTIVIR0.VDF : 11030528 Bytes 18/07/2007 14:27:15

ANTIVIR1.VDF : 1640448 Bytes 13/09/2007 14:26:55

ANTIVIR2.VDF : 1393152 Bytes 23/11/2007 14:16:41

ANTIVIR3.VDF : 11776 Bytes 23/11/2007 14:16:41

AVEWIN32.DLL : 3125760 Bytes 23/11/2007 14:16:41

AVWINLL.DLL : 14376 Bytes 26/02/2007 10:36:26

AVPREF.DLL : 25640 Bytes 18/07/2007 07:39:17

AVREP.DLL : 155688 Bytes 16/04/2007 13:16:24

AVPACK32.DLL : 360488 Bytes 03/08/2007 08:46:00

AVREG.DLL : 30760 Bytes 18/07/2007 07:17:06

AVARKT.DLL : 278568 Bytes 28/08/2007 12:26:33

AVEVTLOG.DLL : 86056 Bytes 18/07/2007 07:10:18

NETNT.DLL : 7720 Bytes 08/03/2007 11:09:42

RCIMAGE.DLL : 2342952 Bytes 07/08/2007 12:38:13

RCTEXT.DLL : 86056 Bytes 21/08/2007 12:50:37

SQLITE3.DLL : 339968 Bytes 23/07/2007 09:37:21


Configuration settings for the scan:

Jobname..........................: Local Drives

Configuration file...............: c:\program files\avira\antivir personaledition classic\alldrives.avp

Logging..........................: low

Primary action...................: interactive

Secondary action.................: ignore

Scan master boot sector..........: off

Scan boot sector.................: on

Boot sectors.....................: G:,

Scan memory......................: on

Process scan.....................: on

Scan registry....................: on

Search for rootkits..............: on

Scan all files...................: All files

Scan archives....................: on

Recursion depth..................: 20

Smart extensions.................: on

Deviating archive types..........: +BSD Mailbox, +Netscape/Mozilla Mailbox, +Eudora Mailbox, +Squid cache, +Pegasus Mailbox, +MS Outlook Mailbox,

Macro heuristic..................: on

File heuristic...................: medium

Deviating risk categories........: +APPL,+GAME,+JOKE,+PCK,+SPR,


Start of the scan: vendredi 23 novembre 2007 15:39


Starting search for hidden objects.

The driver could not be initialized.


The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'iexplore.exe' - '1' Module(s) have been scanned

Scan process 'explorer.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

12 processes with 12 modules were scanned


Start scanning boot sectors:

Boot sector 'C:\'

[NOTE] No virus was found!

Boot sector 'D:\'

[NOTE] No virus was found!

Boot sector 'A:\'

[NOTE] In the drive 'A:\' no data medium is inserted!


Starting to scan the registry.


[DETECTION] Is the Trojan horse TR/Vundo.AU

[iNFO] The file was moved to '47bee687.qua'!


[DETECTION] Is the Trojan horse TR/Vundo.AU


[DETECTION] Is the Trojan horse TR/Vundo.CA

[WARNING] An error has occurred and the file was not deleted. ErrorID: 16003

[WARNING] The file could not be deleted!


[DETECTION] Is the Trojan horse TR/Vundo.CA


The registry was scanned ( '30' files ).



Starting the file scan:


Begin scan in 'C:\' <VAIO>


[WARNING] The file could not be opened!

C:\Downloads\procedure virus\SmitfraudFix.exe

[0] Archive type: RAR SFX (self extracting)

--> SmitfraudFix\Reboot.exe

[DETECTION] Contains detection pattern of the SPR/Tool.Reboot.C program

--> SmitfraudFix\restart.exe

[DETECTION] Contains detection pattern of the SPR/Tool.Hardoff.A program

[iNFO] The file was moved to '47afed10.qua'!

C:\Downloads\procedure virus\SmitfraudFix\Reboot.exe

[DETECTION] Contains detection pattern of the SPR/Tool.Reboot.C program

[iNFO] The file was moved to '47a8ed1b.qua'!

C:\Downloads\procedure virus\SmitfraudFix\restart.exe

[DETECTION] Contains detection pattern of the SPR/Tool.Hardoff.A program

[iNFO] The file was moved to '47b9ed1e.qua'!

C:\Program Files\Fichiers communs\Yazzle1122OinUninstaller.exe

[DETECTION] Is the Trojan horse TR/Dldr.Purity.DZ.3

[iNFO] The file was moved to '47c0f222.qua'!

C:\Program Files\Hijackthis Version Française\VERSION TRADUITE ORIGINALE.EXE

[DETECTION] File has been compressed with an unusual runtime compression tool (PCK/Dumped). Please verify the origin of the file

[iNFO] The file was moved to '4798f46a.qua'!

C:\Program Files\Panda Security\NanoScan\Engine\psnflg.dll

[DETECTION] Is the Trojan horse TR/Agent.bux.1

[iNFO] The file was moved to '47b4f634.qua'!

C:\Program Files\Panda Security\TotalScan\pskavs.dll

[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738

[iNFO] The file was moved to '47b1f63b.qua'!


[DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/JuanSearch.B

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/Vundo.CA

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/Vundo.Gen

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/Dldr.Agen.ZV.1.B

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/Fotomoto.F.1

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/Dldr.ConHook.Gen

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/Dldr.Agen.ZV.1.B

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/Vundo.CA

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/Fotomoto.F.1

[WARNING] The file was ignored!


[DETECTION] Is the Trojan horse TR/Dldr.Agen.ZV.1.B

[WARNING] The file was ignored!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!

Begin scan in 'D:\' <VAIO>


[DETECTION] Contains detection pattern of the dropper DR/SpyBot.1434364

[WARNING] The file was ignored!


[0] Archive type: RAR SFX (self extracting)

--> setup.exe

[DETECTION] Contains detection pattern of the worm WORM/Rbot.1347584

[WARNING] The file was ignored!

Begin scan in 'A:\'

Search path A:\ could not be opened!

Le périphérique n'est pas prêt.


Begin scan in 'E:\'

Search path E:\ could not be opened!

Le périphérique n'est pas prêt.


Begin scan in 'F:\'

Search path F:\ could not be opened!

Le périphérique n'est pas prêt.


Begin scan in 'G:\'

Search path G:\ could not be opened!

Le périphérique n'est pas prêt.




End of the scan: vendredi 23 novembre 2007 18:00

Used time: 2:21:23 min


The scan has been done completely.


12286 Scanning directories

439462 Files were scanned

24 viruses and/or unwanted programs were found

0 Files were classified as suspicious:

0 files were deleted

0 files were repaired

8 files were moved to quarantine

0 files were renamed

4 Files cannot be scanned

439438 Files not concerned

7913 Archives were scanned

18 Warnings

10 Notes

Télécharge Combofix (de sUBs) sur ton Bureau.


Désactive temporairement toute protection résidente ! (Antivirus, antispywares..)

Double clique combofix.exe.

Tape sur la touche 1 (Yes) pour démarrer le scan.

Lorsque le scan sera complété, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.


Le rapport se trouve ici : C:\Combofix.txt



Merci pour ton aide.

Je suis parvenu à supprimer le virus grace aux differents outils trouves sur ce forum. Et par une restauration à un point anterieur je n'ai plus rien. Mon Xp tourne nickel.


Encore merci au forum zebulon


Le problème semble avoir trouvé sa solution.

Ainsi, afin de signaler clairement à ceux qui ont un problème similaire qu'ils ont peut-être une solution toute trouvée (s'ils pensent à utiliser la fonction Recherche en indiquant le mot-clé "résolu" auparavant), et afin de signaler aux autres contributeurs qu'il est inutile de continuer à se creuser la tête sur le problème (à moins d'avoir des suppléments d'informations à apporter pour mieux comprendre ce qui posait problème), un modérateur a préfixé le titre du topic avec la mention [résolu].

Merci, à l'avenir, de bien vouloir prendre à votre charge cette mise à jour quand vous estimez que votre problème a été résolu de manière satisfaisante (et parallèlement, si le problème a disparu "mystérieusement", inutile d'induire les gens en erreur :P) Pour cela, p_edit.gif votre premier message :P

