Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés


Voici le rapport COMBOFIX


Par ailleurs, Antivir m'envoie une alerte pour Trojan TR\CRYPT.XPACK.GEN qu'in n'arrive pas à supprimer apparement... je ne sais pas si cela peut vous aider



ComboFix 08-03-30.1 - Gaet 2008-03-30 13:29:04.1 - NTFSx86

Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.460 [GMT 2:00]

Endroit: C:\Documents and Settings\Gaet\Bureau\ComboFix.exe



(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))



C:\Documents and Settings\Gaet\Mes documents\SMANTE~1

C:\Documents and Settings\Gaet\Mes documents\SMANTE~1\S?mantec\

C:\Documents and Settings\Gaet\Mes documents\SSTEM~1














((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-02-28 to 2008-03-30 ))))))))))))))))))))))))))))))))))))



2008-03-30 12:13 . 2008-03-30 12:23 <REP> d-------- C:\Program Files\Navilog1

2008-03-30 11:46 . 2008-03-30 11:55 3,076 --a------ C:\WINDOWS\system32\tmp.reg

2008-03-30 11:45 . 2008-03-30 12:27 <REP> d-------- C:\smitfraudfix

2008-03-30 10:17 . 2008-03-30 10:17 <REP> d-------- C:\Program Files\Avira

2008-03-30 10:17 . 2008-03-30 10:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira

2008-03-30 08:29 . 2008-03-30 08:29 264,960 --a------ C:\spyware2.JPG

2008-03-30 08:22 . 2008-03-30 08:22 54,454 --a------ C:\spyware.JPG

2008-03-30 07:57 . 2008-03-30 07:57 <REP> d-------- C:\Documents and Settings\Gaet\Application Data\Template

2008-03-29 13:49 . 2008-03-29 13:49 <REP> d-------- C:\Documents and Settings\Gaet\Application Data\PC-Cleaner

2008-03-29 13:47 . 2008-03-29 13:50 <REP> d-------- C:\Program Files\PC-Cleaner

2008-03-29 13:25 . 2008-03-29 13:25 94,208 --a------ C:\WINDOWS\system32\ybizynml.exe

2008-03-29 12:50 . 2008-03-30 12:18 <REP> d-------- C:\Program Files\Spyware Doctor

2008-03-29 12:50 . 2008-03-29 12:50 <REP> d-------- C:\Documents and Settings\Gaet\Application Data\PC Tools

2008-03-29 12:50 . 2007-12-10 15:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys

2008-03-29 12:50 . 2007-12-10 15:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys

2008-03-29 12:50 . 2008-02-01 13:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys

2008-03-29 12:50 . 2007-12-10 15:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys

2008-03-29 12:08 . 2008-03-29 12:42 294 ---hs---- C:\WINDOWS\system32\gdnmimbc.ini

2008-03-29 11:59 . 2008-03-29 11:59 114,688 --a------ C:\WINDOWS\system32\tydkfajs.exe

2008-03-28 20:42 . 2008-03-28 20:42 2 --a------ C:\WINDOWS\msoffice.ini

2008-03-28 17:00 . 2008-03-29 12:41 327 --a------ C:\WINDOWS\wininit.ini

2008-03-28 16:29 . 2008-03-30 11:38 <REP> d-------- C:\Program Files\Spybot - Search & Destroy

2008-03-28 16:29 . 2008-03-28 17:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

2008-03-28 14:29 . 2008-03-30 10:23 <REP> d-------- C:\Documents and Settings\All Users\Application Data\afitsvsz

2008-03-28 14:29 . 98,304 C:\WINDOWS\system32\ahkxofkx.exe

2008-03-02 11:36 . 2008-03-02 11:36 268 --ah----- C:\sqmdata16.sqm

2008-03-02 11:36 . 2008-03-02 11:36 244 --ah----- C:\sqmnoopt16.sqm

2008-02-22 13:17 . 2008-02-22 13:17 <REP> d-------- C:\Program Files\DivX

2008-02-21 04:05 . 2008-02-21 04:05 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll

2008-02-21 04:05 . 2008-02-21 04:05 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll

2008-02-02 12:58 . 2008-02-02 12:58 268 --ah----- C:\sqmdata15.sqm

2008-02-02 12:58 . 2008-02-02 12:58 244 --ah----- C:\sqmnoopt15.sqm



(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))


2008-03-30 11:36 --------- d-----w C:\Program Files\Steam

2008-03-30 11:36 --------- d-----w C:\Documents and Settings\Gaet\Application Data\Skype

2008-03-30 11:35 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP

2008-03-30 11:33 --------- d-----w C:\Program Files\Moon Secure Antivirus

2008-03-30 10:01 --------- d-----w C:\Documents and Settings\Gaet\Application Data\OpenOffice.org2

2008-03-28 18:43 --------- d-----w C:\Program Files\Fichiers communs\aolshare

2008-03-28 18:43 --------- d-----w C:\Program Files\Fichiers communs\AOL

2008-03-28 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL

2008-03-28 18:33 --------- d-----w C:\Program Files\Yahoo!

2008-03-28 14:42 --------- d-----w C:\Program Files\Warcraft III

2008-03-28 14:27 --------- d-----w C:\Program Files\Messenger Plus! Live

2008-02-23 21:28 --------- d-----w C:\Program Files\GUILD WARS

2008-02-06 12:16 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-02-06 12:15 28,256 ----a-w C:\WINDOWS\system32\drivers\MxlW2k.sys

2007-12-24 22:43 81,920 ------r C:\WINDOWS\bwUnin-

2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys

2007-12-07 14:37 3,080,192 ------w C:\WINDOWS\system32\dllcache\mshtml.dll

2007-12-06 13:07 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe

2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll

2007-12-04 18:41 550,912 ------w C:\WINDOWS\system32\dllcache\oleaut32.dll



((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))




*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E96B1FB-2310-4552-9A02-27677D005307}]


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{2B75C5E6-A52E-4F8C-8A27-EFC415575B04}]


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{39D58212-2091-4DFE-85C7-31AE36C6F29D}]


[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{94BC3D1D-22E9-4744-8ED1-3E08A3B74078}]



"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]

"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-10-13 18:20 20058152]

"Steam"="c:\program files\steam\steam.exe" [2008-03-28 11:54 1271032]

"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2007-05-16 12:21 190024]

"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-10-05 09:52 98304]

"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]

"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:55 5674352]

"rsazddul"="C:\WINDOWS\system32\ahkxofkx.exe" [ ]

"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]

"xnblnnla"="C:\WINDOWS\system32\tydkfajs.exe" [ ]

"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2007-12-25 00:43 20480]



"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-20 01:09 94208]

"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-20 01:06 77824]

"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-20 01:10 114688]

"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 19:48 32881]

"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 02:20 339968 C:\WINDOWS\stsystra.exe]

"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 22:12 221184]

"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 18:19 53248]

"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-04 20:42 98304]

"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 03:01 86016]

"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 03:05 127035]

"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]

"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 18:50 81920]

"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-11-04 20:41 26112]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-10-05 23:11 866584]

"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 18:41 45056]

"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-09 00:00 128920]

"Moon Secure Antivirus"="C:\Program Files\Moon Secure Antivirus\moontray.exe" [2007-01-24 20:49 1153536]

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-10-21 14:28 29696 C:\WINDOWS\KHALMNPR.Exe]

"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 13:55 1103240]

"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-03-30 12:07 249896]



"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [ ]

"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 14:45 36040]


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXoMeeC]


[HKEY_LOCAL_MACHINE\software\microsoft\security center]



[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]



[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]



[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]




"EnableFirewall"= 0 (0x0)





"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=

"C:\\Programmes\\Activision\\Rome - Total War\\RomeTW-BI.exe"=

"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=

"C:\\Program Files\\Sierra\\FEAR MP Demo\\FEARMPDemo.exe"=

"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"=

"C:\\Program Files\\Sierra\\FEAR MP Demo\\FEARServer.exe"=

"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"C:\\Program Files\\Third Wave Games\\War World - Tactical Combat DEMO 1.09\\War World.exe"=

"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

"C:\\Program Files\\Steam\\SteamApps\\dsfge83\\counter-strike source\\hl2.exe"=

"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=

"C:\\Program Files\\THQ\\Titan Quest\\Titan Quest.exe"=

"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"C:\\Program Files\\MSN Messenger\\livecall.exe"=

"C:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe"=

"C:\\Team17\\Worms World Party\\wwp.exe"=

"C:\\Program Files\\Steam\\steam.exe"=

"C:\\Program Files\\THQ\\Titan Quest Immortal Throne\\Tqit.exe"=

"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=




"C:\\Documents and Settings\\Gaet\\Bureau\\Counter-Strike Source\\hl2.exe"=

"C:\\Program Files\\Skype\\Phone\\Skype.exe"=



"6112:TCP"= 6112:TCP:6112

"6112:UDP"= 6112:UDP:6112bis


R2 msav;Moon Secure Antivirus Core;C:\Program Files\Moon Secure Antivirus\msavcore.exe [2007-01-24 20:49]

S3 Am772;SMC2602W 11 Mbps Wireless 802.11 Adapter;C:\WINDOWS\system32\DRIVERS\Am772.sys [2004-01-26 14:40]

S3 P1130VID;Creative WebCam NX Pro;C:\WINDOWS\system32\DRIVERS\P1130Vid.sys [2003-06-11 03:00]



Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'

"2008-03-30 11:37:01 C:\WINDOWS\Tasks\MP Scheduled Scan.job"

- C:\Program Files\Windows Defender\MpCmdRun.exe

"2008-03-30 11:19:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"

Posté(e) (modifié)

)Combo, Nettoyage

# Déconnectez-vous du net et désactivez l'antivirus (juste le temps de la procédure !)

Lancez Combofix

# Dans le bloc-note ,copiez-collez ces lignes :



* Attention, ce code a été rédigé spécialement pour cet utilisateur, prière de ne pas le réutiliser dans d'autres cas !





















C:\Documents and Settings\All Users\Application Data\afitsvsz




[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\byXoMeeC]






[HKEY_LOCAL_MACHINE\software\microsoft\security center]


[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]


[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]



[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]





"C:\Program Files\Logitech\\Desktop Messenger\8876480\Program\backWeb-8876480.exe"=-


Enregistrez-le en lui donnant le nom CFScript.txt


* Faire un glisser/déposer de ce fichier CFScript sur le fichier ComboFix.exe




* Au message qui apparait dans une fenêtre bleue ( Type 1 to continue, or 2 to abort) , taper 1 puis valider.

* Patienter le temps du scan.Le bureau va disparaitre à plusieurs reprises: c'est normal!

Ne toucher à rien tant que le scan n'est pas terminé.

* Une fois le scan achevé, un rapport va s'afficher: poster son contenu.

* Si le fichier n'apparait pas, il se trouve ici > C:\ComboFix.txt


Et un nouvel Hijackthis, svp.

Modifié par pear

Voici le rapport COMBOFIX


ComboFix 08-03-30.1 - Gaet 2008-03-30 15:00:42.2 - NTFSx86

Microsoft Windows XP Édition familiale 5.1.2600.2.1252.1.1036.18.616 [GMT 2:00]

Endroit: C:\Documents and Settings\Gaet\Bureau\ComboFix.exe

Command switches used :: C:\Documents and Settings\Gaet\Bureau\CFScript.txt

* Création d'un nouveau point de restauration


















The following files were disabled during the run:

C:\Program Files\Moon Secure Antivirus\MoonSysH.dll



(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))



C:\Documents and Settings\All Users\Application Data\afitsvsz












---- Previous Run -------


C:\Documents and Settings\Gaet\Mes documents\SMANTE~1

C:\Documents and Settings\Gaet\Mes documents\SMANTE~1\S?mantec\

C:\Documents and Settings\Gaet\Mes documents\SSTEM~1














((((((((((((((((((((((((((((( Fichiers cr‚‚s 2008-02-28 to 2008-03-30 ))))))))))))))))))))))))))))))))))))



2008-03-30 13:37 . 2008-03-30 13:37 268 --ah----- C:\sqmdata17.sqm

2008-03-30 13:37 . 2008-03-30 13:37 244 --ah----- C:\sqmnoopt17.sqm

2008-03-30 12:13 . 2008-03-30 12:23 <REP> d-------- C:\Program Files\Navilog1

2008-03-30 11:45 . 2008-03-30 12:27 <REP> d-------- C:\smitfraudfix

2008-03-30 10:17 . 2008-03-30 10:17 <REP> d-------- C:\Program Files\Avira

2008-03-30 10:17 . 2008-03-30 10:17 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Avira

2008-03-30 07:57 . 2008-03-30 07:57 <REP> d-------- C:\Documents and Settings\Gaet\Application Data\Template

2008-03-29 13:49 . 2008-03-29 13:49 <REP> d-------- C:\Documents and Settings\Gaet\Application Data\PC-Cleaner

2008-03-29 13:47 . 2008-03-29 13:50 <REP> d-------- C:\Program Files\PC-Cleaner

2008-03-29 12:50 . 2008-03-30 13:51 <REP> d-------- C:\Program Files\Spyware Doctor

2008-03-29 12:50 . 2008-03-29 12:50 <REP> d-------- C:\Documents and Settings\Gaet\Application Data\PC Tools

2008-03-29 12:50 . 2007-12-10 15:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys

2008-03-29 12:50 . 2007-12-10 15:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys

2008-03-29 12:50 . 2008-02-01 13:55 42,376 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys

2008-03-29 12:50 . 2007-12-10 15:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys

2008-03-28 20:42 . 2008-03-28 20:42 2 --a------ C:\WINDOWS\msoffice.ini

2008-03-28 17:00 . 2008-03-29 12:41 327 --a------ C:\WINDOWS\wininit.ini

2008-03-28 16:29 . 2008-03-30 11:38 <REP> d-------- C:\Program Files\Spybot - Search & Destroy

2008-03-28 16:29 . 2008-03-28 17:00 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy

2008-02-22 13:17 . 2008-02-22 13:17 <REP> d-------- C:\Program Files\DivX

2008-02-21 04:05 . 2008-02-21 04:05 1,044,480 --a------ C:\WINDOWS\system32\libdivx.dll

2008-02-21 04:05 . 2008-02-21 04:05 200,704 --a------ C:\WINDOWS\system32\ssldivx.dll



(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))


2008-03-30 13:07 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP

2008-03-30 13:07 --------- d-----w C:\Program Files\Steam

2008-03-30 13:05 --------- d-----w C:\Program Files\Moon Secure Antivirus

2008-03-30 12:53 --------- d-----w C:\Documents and Settings\Gaet\Application Data\Skype

2008-03-30 10:01 --------- d-----w C:\Documents and Settings\Gaet\Application Data\OpenOffice.org2

2008-03-28 18:43 --------- d-----w C:\Program Files\Fichiers communs\aolshare

2008-03-28 18:43 --------- d-----w C:\Program Files\Fichiers communs\AOL

2008-03-28 18:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\AOL

2008-03-28 18:33 --------- d-----w C:\Program Files\Yahoo!

2008-03-28 14:42 --------- d-----w C:\Program Files\Warcraft III

2008-03-28 14:27 --------- d-----w C:\Program Files\Messenger Plus! Live

2008-02-23 21:28 --------- d-----w C:\Program Files\GUILD WARS

2008-02-06 12:16 --------- d--h--w C:\Program Files\InstallShield Installation Information

2008-02-06 12:15 28,256 ----a-w C:\WINDOWS\system32\drivers\MxlW2k.sys

2007-12-18 09:51 179,584 ------w C:\WINDOWS\system32\dllcache\mrxdav.sys

2007-12-07 14:37 3,080,192 ------w C:\WINDOWS\system32\dllcache\mshtml.dll

2007-12-06 13:07 18,432 ------w C:\WINDOWS\system32\dllcache\iedw.exe

2007-12-04 18:41 550,912 ----a-w C:\WINDOWS\system32\oleaut32.dll

2007-12-04 18:41 550,912 ------w C:\WINDOWS\system32\dllcache\oleaut32.dll



((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))




*Note* les ‚l‚ments vides & les ‚l‚ments initiaux l‚gitimes ne sont pas list‚s



"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]

"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2006-10-13 18:20 20058152]

"Steam"="c:\program files\steam\steam.exe" [2008-03-28 11:54 1271032]

"MessengerPlus3"="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" [2007-05-16 12:21 190024]

"Creative Detector"="C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" [2004-10-05 09:52 98304]

"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 18:24 1694208]

"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:55 5674352]

"rsazddul"="C:\WINDOWS\system32\ahkxofkx.exe" [ ]

"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 12:43 2097488]

"xnblnnla"="C:\WINDOWS\system32\tydkfajs.exe" [ ]

"LDM"="C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2007-12-25 00:43 20480]



"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-07-20 01:09 94208]

"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-07-20 01:06 77824]

"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-07-20 01:10 114688]

"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 19:48 32881]

"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 02:20 339968 C:\WINDOWS\stsystra.exe]

"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 22:12 221184]

"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 18:19 53248]

"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-04 20:42 98304]

"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2004-09-15 03:01 86016]

"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2004-12-06 03:05 127035]

"ISUSPM Startup"="C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 18:50 221184]

"ISUSScheduler"="C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" [2004-07-27 18:50 81920]

"RealTray"="C:\Program Files\Real\RealPlayer\RealPlay.exe" [2005-11-04 20:41 26112]

"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-10-05 23:11 866584]

"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 18:41 45056]

"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2005-11-09 00:00 128920]

"Moon Secure Antivirus"="C:\Program Files\Moon Secure Antivirus\moontray.exe" [2007-01-24 20:49 1153536]

"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2004-10-21 14:28 29696 C:\WINDOWS\KHALMNPR.Exe]

"ISTray"="C:\Program Files\Spyware Doctor\pctsTray.exe" [2008-02-01 13:55 1103240]

"avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-03-30 12:07 249896]



"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 14:00 15360]

"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [ ]

"DWQueuedReporting"="C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" [2005-04-25 14:45 36040]





"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=

"C:\\Programmes\\Activision\\Rome - Total War\\RomeTW-BI.exe"=

"C:\\Program Files\\Warcraft III\\Warcraft III.exe"=

"C:\\Program Files\\Sierra\\FEAR MP Demo\\FEARMPDemo.exe"=

"C:\\Program Files\\GameSpy Arcade\\Aphex.exe"=

"C:\\Program Files\\Sierra\\FEAR MP Demo\\FEARServer.exe"=

"C:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"C:\\Program Files\\Third Wave Games\\War World - Tactical Combat DEMO 1.09\\War World.exe"=

"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=

"C:\\Program Files\\Steam\\SteamApps\\dsfge83\\counter-strike source\\hl2.exe"=

"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"=

"C:\\Program Files\\THQ\\Titan Quest\\Titan Quest.exe"=

"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=

"C:\\Program Files\\MSN Messenger\\livecall.exe"=

"C:\\Program Files\\TrackMania Nations ESWC\\TmNationsESWC.exe"=

"C:\\Team17\\Worms World Party\\wwp.exe"=

"C:\\Program Files\\Steam\\steam.exe"=

"C:\\Program Files\\THQ\\Titan Quest Immortal Throne\\Tqit.exe"=

"C:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\backWeb-8876480.exe"=




"C:\\Documents and Settings\\Gaet\\Bureau\\Counter-Strike Source\\hl2.exe"=

"C:\\Program Files\\Skype\\Phone\\Skype.exe"=



"6112:TCP"= 6112:TCP:6112

"6112:UDP"= 6112:UDP:6112bis


R2 msav;Moon Secure Antivirus Core;C:\Program Files\Moon Secure Antivirus\msavcore.exe [2007-01-24 20:49]

S3 Am772;SMC2602W 11 Mbps Wireless 802.11 Adapter;C:\WINDOWS\system32\DRIVERS\Am772.sys [2004-01-26 14:40]

S3 P1130VID;Creative WebCam NX Pro;C:\WINDOWS\system32\DRIVERS\P1130Vid.sys [2003-06-11 03:00]



Contenu du dossier 'Scheduled Tasks/Tƒches planifi‚es'

"2008-03-30 13:08:38 C:\WINDOWS\Tasks\MP Scheduled Scan.job"

- C:\Program Files\Windows Defender\MpCmdRun.exe

"2008-03-30 12:19:01 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"





Voici le rapport Hijackthis


Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 15:12, on 2008-03-30

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal


Running processes:









C:\Program Files\Windows Defender\MsMpEng.exe





C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe


C:\Program Files\Moon Secure Antivirus\msavcore.exe


C:\Program Files\Spyware Doctor\pctsAuxs.exe

C:\Program Files\Spyware Doctor\pctsSvc.exe


C:\Program Files\Spyware Doctor\pctsTray.exe



C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe


C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

C:\Program Files\Dell\Media Experience\DMXLauncher.exe


C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe

C:\Program Files\Real\RealPlayer\RealPlay.exe

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\DAEMON Tools\daemon.exe


C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe


C:\Program Files\Skype\Phone\Skype.exe

C:\program files\steam\steam.exe

C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe

C:\Program Files\MSN Messenger\msnmsgr.exe


C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe


C:\Documents and Settings\Gaet\Bureau\HiJackThis.exe


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe

O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

O4 - HKLM\..\Run: [intelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe

O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay

O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [Moon Secure Antivirus] "C:\Program Files\Moon Secure Antivirus\moontray.exe"

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [steam] "c:\program files\steam\steam.exe" -silent

O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart

O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKCU\..\Run: [rsazddul] C:\WINDOWS\system32\ahkxofkx.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [xnblnnla] C:\WINDOWS\system32\tydkfajs.exe

O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: 2.0.lnk = C:\Program Files\ 2.0\program\quickstart.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites -

O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?93312415fec24941a7829038b1e5d384

O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?93312415fec24941a7829038b1e5d384

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll

O9 - Extra button: - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\system32\shdocvw.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -

O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) -,0,0,

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE

O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe



End of file - 10074 bytes


Je crois que je me suis réjouie trop vite : j'ai toujours une alerte Antivir sur Trojan TR\CRYPT.XPACK.GEN . Je choisit Delete à chaque fois mais cela revient quand même au bout d'un moment



Posté(e) (modifié)


Vous avez bien avancé!


Copiez /collez les lignes suivantes dans le bloc notes, sans ligne blanche au début,

enregistrez, sur le bureau, sous regit.reg et fusionnez(clic droit sur fichier)

Acceptez la modification du régistre.


Windows Registry Editor Version 5.00






Dans un hijackthis, cochez ces lignes puis clic sur Fix checked


C:\program files\steam\steam.exe

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')


Pour supprimer Ctfmon: Panneau de configuration->Options Régionales et linguistiques->Désactiver Langues d'Extrême Orient


Java n'est pas à jour,donc moins sécurisé.


Rendez vous là:


Java Runtime Environment (JRE) 6 Update 5

Download Now


S'ouvre une bouvelle page.


Vous descendrez là:


Java Runtime Environment (JRE) 6 Update 5

Clic sur Download


Nouvelle page.


Sélectionnez votre platform->Windows

Cochez "I agree to the java..."

clic sur continue


Nouvelle page



Windows Online Installation

Cochez la flèche orange

" Cochez ici"jre-6u5-windows-i586-p-iftw.exe


Cela fait, supprimez les installations java antérieures par "Ajout/Suppression de Programmes"


Relancez Combofix.

Faites un scan Antivir et postez en le rapport avec un Hijackthis.

Modifié par pear

Rapport Antivir




AntiVir PersonalEdition Classic

Report file date: dimanche 30 mars 2008 19:10


Scanning for 1169688 virus strains and unwanted programs.


Licensed to: Avira AntiVir PersonalEdition Classic

Serial number: 0000149996-ADJIE-0001

Platform: Windows XP

Windows version: (Service Pack 2) [5.1.2600]

Username: SYSTEM

Computer name: SEXYCOMPUTER


Version information:

BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00

AVSCAN.EXE : 290856 Bytes 23/08/2007 12:16:29

AVSCAN.DLL : 49192 Bytes 16/08/2007 11:23:51

LUKE.DLL : 147496 Bytes 14/08/2007 14:32:47

LUKERES.DLL : 10280 Bytes 21/08/2007 11:35:20

ANTIVIR0.VDF : 11030528 Bytes 18/07/2007 13:27:15

ANTIVIR1.VDF : 5447168 Bytes 07/03/2008 17:08:53

ANTIVIR2.VDF : 434176 Bytes 27/03/2008 17:08:53

ANTIVIR3.VDF : 20480 Bytes 28/03/2008 17:08:53

AVEWIN32.DLL : 3408384 Bytes 30/03/2008 17:08:54

AVWINLL.DLL : 14376 Bytes 26/02/2007 09:36:26

AVPREF.DLL : 25640 Bytes 18/07/2007 06:39:17

AVREP.DLL : 155688 Bytes 16/04/2007 12:16:24

AVPACK32.DLL : 360488 Bytes 30/03/2008 17:08:54

AVREG.DLL : 30760 Bytes 18/07/2007 06:17:06

AVARKT.DLL : 278568 Bytes 28/08/2007 11:26:33

AVEVTLOG.DLL : 86056 Bytes 18/07/2007 06:10:18

NETNT.DLL : 7720 Bytes 08/03/2007 10:09:42

RCIMAGE.DLL : 2342952 Bytes 07/08/2007 11:38:13

RCTEXT.DLL : 86056 Bytes 21/08/2007 11:50:37

SQLITE3.DLL : 339968 Bytes 23/07/2007 08:37:21


Configuration settings for the scan:

Jobname..........................: Complete system scan

Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp

Logging..........................: low

Primary action...................: interactive

Secondary action.................: ignore

Scan master boot sector..........: off

Scan boot sector.................: on

Boot sectors.....................: C:,

Scan memory......................: on

Process scan.....................: on

Scan registry....................: on

Search for rootkits..............: off

Scan all files...................: Intelligent file selection

Scan archives....................: on

Recursion depth..................: 20

Smart extensions.................: on

Macro heuristic..................: on

File heuristic...................: medium


Start of the scan: dimanche 30 mars 2008 19:10


The scan of running processes will be started

Scan process 'avscan.exe' - '1' Module(s) have been scanned

Scan process 'avcenter.exe' - '1' Module(s) have been scanned

Scan process 'sched.exe' - '1' Module(s) have been scanned

Scan process 'avgnt.exe' - '1' Module(s) have been scanned

Scan process 'avguard.exe' - '1' Module(s) have been scanned

Scan process 'explorer.exe' - '1' Module(s) have been scanned

Scan process 'CLI.exe' - '1' Module(s) have been scanned

Scan process 'CLI.exe' - '1' Module(s) have been scanned

Scan process 'KHALMNPR.exe' - '1' Module(s) have been scanned

Scan process 'soffice.bin' - '1' Module(s) have been scanned

Scan process 'soffice.exe' - '1' Module(s) have been scanned

Scan process 'KEM.exe' - '1' Module(s) have been scanned

Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'ctfmon.exe' - '1' Module(s) have been scanned

Scan process 'jusched.exe' - '1' Module(s) have been scanned

Scan process 'daemon.exe' - '1' Module(s) have been scanned

Scan process 'CLI.exe' - '1' Module(s) have been scanned

Scan process 'MSASCui.exe' - '1' Module(s) have been scanned

Scan process 'realplay.exe' - '1' Module(s) have been scanned

Scan process 'issch.exe' - '1' Module(s) have been scanned

Scan process 'tfswctrl.exe' - '1' Module(s) have been scanned

Scan process 'DMXLauncher.exe' - '1' Module(s) have been scanned

Scan process 'DVDLauncher.exe' - '1' Module(s) have been scanned

Scan process 'stsystra.exe' - '1' Module(s) have been scanned

Scan process 'pctsTray.exe' - '1' Module(s) have been scanned

Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned

Scan process 'alg.exe' - '1' Module(s) have been scanned

Scan process 'UStorSrv.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'pctsSvc.exe' - '1' Module(s) have been scanned

Scan process 'pctsAuxs.exe' - '1' Module(s) have been scanned

Scan process 'msavcore.exe' - '1' Module(s) have been scanned

Scan process 'CTSVCCDA.EXE' - '1' Module(s) have been scanned

Scan process 'spoolsv.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'MsMpEng.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'svchost.exe' - '1' Module(s) have been scanned

Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned

Scan process 'lsass.exe' - '1' Module(s) have been scanned

Scan process 'services.exe' - '1' Module(s) have been scanned

Scan process 'winlogon.exe' - '1' Module(s) have been scanned

Scan process 'csrss.exe' - '1' Module(s) have been scanned

Scan process 'smss.exe' - '1' Module(s) have been scanned

47 processes with 47 modules were scanned


Start scanning boot sectors:

Boot sector 'C:\'

[NOTE] No virus was found!


Starting to scan the registry.

The registry was scanned ( '32' files ).



Starting the file scan:


Begin scan in 'C:\'


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen

[iNFO] The file was deleted!

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP492\A0084412.dll

[DETECTION] Is the Trojan horse TR/BHO.Agent.221184

[iNFO] The file was deleted!

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP492\A0084413.exe

[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen

[iNFO] The file was deleted!

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP494\A0085121.exe

[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen

[iNFO] The file was deleted!

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP496\A0085337.exe

[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen

[iNFO] The file was moved to '481fee8c.qua'!

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP496\A0085390.exe

[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen

[iNFO] The file was deleted!

C:\System Volume Information\_restore{EA39A09C-50BA-4996-869B-915C83FE3B53}\RP497\A0085437.exe

[DETECTION] Is the Trojan horse TR/Crypt.XPACK.Gen

[iNFO] The file was deleted!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!


[WARNING] The file could not be opened!



End of the scan: dimanche 30 mars 2008 22:11

Used time: 3:01:18 min


The scan has been done completely.


8183 Scanning directories

482997 Files were scanned

7 viruses and/or unwanted programs were found

0 Files were classified as suspicious:

6 files were deleted

0 files were repaired

1 files were moved to quarantine

0 files were renamed

5 Files cannot be scanned

482990 Files not concerned

9247 Archives were scanned

5 Warnings

1 Notes



Rapport HijackThis



Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:23:56, on 30/03/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal


Running processes:









C:\Program Files\Windows Defender\MsMpEng.exe






C:\Program Files\Moon Secure Antivirus\msavcore.exe

C:\Program Files\Spyware Doctor\pctsAuxs.exe

C:\Program Files\Spyware Doctor\pctsSvc.exe





C:\Program Files\Spyware Doctor\pctsTray.exe


C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe

C:\Program Files\Dell\Media Experience\DMXLauncher.exe


C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe

C:\Program Files\Real\RealPlayer\RealPlay.exe

C:\Program Files\Windows Defender\MSASCui.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\DAEMON Tools\daemon.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe



C:\Program Files\MSN Messenger\msnmsgr.exe

C:\Program Files\Logitech\SetPoint\KEM.exe

C:\Program Files\ 2.0\program\soffice.exe

C:\Program Files\ 2.0\program\soffice.BIN

C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe


C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe


C:\Documents and Settings\Gaet\Bureau\HiJackThis.exe



R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll

O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe

O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe

O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe

O4 - HKLM\..\Run: [sigmatelSysTrayApp] stsystra.exe

O4 - HKLM\..\Run: [intelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe

O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"

O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe

O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe

O4 - HKLM\..\Run: [iSUSPM Startup] C:\PROGRA~1\FICHIE~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup

O4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Fichiers communs\InstallShield\UpdateService\issch.exe" -start

O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide

O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay

O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033

O4 - HKLM\..\Run: [Moon Secure Antivirus] "C:\Program Files\Moon Secure Antivirus\moontray.exe"

O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE

O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [steam] "c:\program files\steam\steam.exe" -silent

O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\FICHIE~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')

O4 - Startup: 2.0.lnk = C:\Program Files\ 2.0\program\quickstart.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites -

O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?93312415fec24941a7829038b1e5d384

O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?93312415fec24941a7829038b1e5d384

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -

O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) -,0,0,

O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) -

O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -

O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Fichiers communs\Symantec Shared\ccSvcHst.exe

O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE

O23 - Service: Moon Secure Antivirus Core (msav) - Unknown owner - C:\Program Files\Moon Secure Antivirus\msavcore.exe

O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe

O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe

O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe



End of file - 9347 bytes




Dans Hijackthis, cochez ces lignes puis Fix checked.

O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background

O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} (Java Plug-in 1.4.2_03) -


Microsoft Windows Defender

PC Tools Spyware Doctor

Avira AntiVir PersonalEdition Classic

Avira AntiVir PersonalEdition

Symantec Norton Antivirus

Moon Secure Antivirus

Choisissez, mais jamais 2 logiciels de protection de même type actifs.

Donc, 1 seul antivirus , 1 seul antispyware.


Je vous conseille de ne garder que Antivir comme antivirus.


Dans mon précédent message , je vous avais demandé de lancer Combofix.


J'en attendais le rapport.


Quand vous l'aurez posté:

Pour désinstaller les outils:


Télécharger ToolsCleaner! de A.Rothstein pour enlever les programmes utilisés pendant la procédure.

* Enregistrer ToolsCleaner2.exe sur le Bureau.

Sous Vista,Clic-droit > Exécuter en tant que Administrateur

* Double-cliquer dessus, puis cliquer sur Recherche --> Le programme va chercher les utilitaires installés

------> Il se peut que la fenêtre devienne blanche pendant le scan, c'est normal !

* Copier-coller le contenu du rapport qui apparait dans la fenêtre blanche.


Les rapports Hijackthis et Antivir sont corrects.

Pour supprmer les traces de virus:


Désinstallez la Restauration Système.


Poste de Travail->Propriétés->Restauration Système.

Décocher la Restauration sur tous les lecteurs.


Vous la rétablirez ensuite.

Un nouveau point de restauration sera créé.


Avec vos derniers rapports, dites moi comment se comporte le pc.

Avez vous quelque disfonctionnement?


Je vous enverrais tout cela ce soir, quand je serais rentré du boulot


Je vais garder Antivir + Spy Doctor. J'ai supprimé MoonSecure et Spybot


Mon fils a travaillé (je veux dire jouer !!!) toute la journée sur son poste (ah le blocage du lycée !!) et tout fonctionne très bien


je vous remercie BEAUCOUP de m'avoir donné de votre temps et de votre expertise pour m'aider.... :P

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
  • Créer...