Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

Messages recommandés

Posté(e) (modifié)

Bonjour,

 

Un ami a un problème avec la navigation avec ie et firefox. Par contre skype fonctionne très bien. juste pour dire qu'il n'y a pas de problème réseau.

 

Si quelqu'un peut aider ça serait sympat.

 

Voici donc son rapport hijackthis :

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:55:26, on 23/09/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe

C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe

C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\Rundll32.exe

C:\WINDOWS\system32\rundll32.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe

C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe

C:\Program Files\Skype\Plugin Manager\skypePM.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://recherche.neuf.fr/ie/default.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://recherche.neuf.fr/

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://recherche.neuf.fr/ie/default.html

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [4817e8c0] rundll32.exe "C:\WINDOWS\system32\tpqexfee.dll",b

O4 - HKLM\..\Run: [bM4b24db5c] Rundll32.exe "C:\WINDOWS\system32\jcgxluoj.dll",s

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020

O4 - HKCU\..\Run: [Widget Neuf] "C:\Program Files\Neuf\Widget Neuf\9widget.exe"

O4 - HKCU\..\Run: [vTunerStartUp] C:\PROGRA~1\vTuner\vTuner.exe WinStart=Yes

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [Real Desktop] "C:\Program Files\Real Desktop\Real Desktop.exe"

O4 - HKCU\..\Policies\Explorer\Run: [NT Printing Services5] dllhosts.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Image Transfer.lnk = ?

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll

O9 - Extra button: Antivirus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab

O16 - DPF: {38D6D77C-5EC1-4A4A-AFEB-85FE780CD61A} (FontDownloaderIE Class) - http://www.qurancomplex.org/downloads/FontDown.cab

O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: thdjco.dll

O21 - SSODL: WebProxy - {66186F05-BBBB-4a39-864F-72D84615C679} - sockins32.dll (file missing)

O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe

O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

 

--

End of file - 7598 bytes

Modifié par jfezkejpe

Posté(e)

Bonjour,

 

KAV 6? C'est un vrai de vrai ça?

Si oui, je te conseille d'aller demander comment obtenir une version plus récente Sur le forum Kaspersky fr

 

On en est à la v8 :P

 

Télécharge SDFix (créé par AndyManchesta) et sauvegarde le sur ton Bureau.

***Si le lien ne fonctionne pas, essaie celui-ci : http://download.bleepingcomputer.com/andymanchesta/SDFix.exe ***

 

Double clique sur SDFix.exe et choisis Install. L'outil sera extrait à la racine du lecteur système (généralement le C:\).

Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :

  • Redémarre ton ordinateur
  • Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
  • A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
  • Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
  • Choisis ton compte.

Déroule la liste des instructions ci-dessous :

  • Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
  • Appuie sur Y pour commencer le processus de nettoyage.
  • Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
  • Appuie sur une touche pour redémarrer le PC.
  • Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
  • Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
  • Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
  • Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
  • Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !

N.B.:

- Le fichier SDFIX_README.htm (dans le dossier SDFix) contient la liste des malwares pris en compte par l'outil.

- Andy fait plusieurs mises à jour, souvent plus d'une par jour... N'hésitez donc pas à demander de télécharger une nouvelle version lorsque le nettoyage dure et que l'outil ne semble pas tout voir.

Si SDfix ne se lançait pas:

 

- Démarrer/Exécuter

- Copie/colle ceci:

%systemroot%\system32\cmd.exe /K %systemdrive%\SDFix\apps\FixPath.exe

 

-Clique sur ok, et valide.

-Redémarre et essaie de nouveau de lancer SDfix.

 

Poste un nouveau log Hijackthis après la fin du travail de SDFix stp.

 

@++

  • 2 semaines après...
Posté(e)

Bonjour,

 

Il a mis le temps mais c'est fait.

 

voici le rapport sdfix :

 

SDFix: Version 1.232

Run by Karim on 07/10/2008 at 15:24

 

Microsoft Windows XP [version 5.1.2600]

Running From: C:\Documents and Settings\Karim\Bureau\SDFix

 

Checking Services :

 

 

Restoring Default Security Values

Restoring Default Hosts File

 

Rebooting

 

 

Checking Files :

 

Trojan Files Found:

 

C:\DOCUME~1\Karim\LOCALS~1\Temp\GLF23.tmp.dll - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\GLF24.tmp.dll - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\GLF33.tmp.dll - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\GLF63.tmp.dll - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\GLF79.tmp.dll - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\TMP14.tmp - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\TMP1B.tmp - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\TMP20.tmp - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\TMP30.tmp - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\tmp41.tmp - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\tmp5.tmp - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\TMP6.tmp - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\TMP7.tmp - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\TMP7E.tmp - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\TMPA.tmp - Deleted

C:\DOCUME~1\Karim\LOCALS~1\Temp\removalfile.bat - Deleted

C:\WINDOWS\index.html - Deleted

C:\WINDOWS\pskt.ini - Deleted

C:\WINDOWS\system32\sft.res - Deleted

 

 

 

Folder C:\Program Files\AntiSpywareExpert - Removed

 

 

Removing Temp Files

 

ADS Check :

 

 

 

Final Check :

 

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2008-10-07 15:34:27

Windows 5.1.2600 Service Pack 2 NTFS

 

scanning hidden processes ...

 

scanning hidden services & system hive ...

 

scanning hidden registry entries ...

 

scanning hidden files ...

 

scan completed successfully

hidden processes: 0

hidden services: 0

hidden files: 0

 

 

Remaining Services :

 

 

 

 

Authorized Application Key Export:

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"

"C:\\Program Files\\eMule\\emule.exe"="C:\\Program Files\\eMule\\emule.exe:*:Enabled:eMule"

"C:\\Program Files\\SymplisIT\\DriverMagic\\DriverMagic.exe"="C:\\Program Files\\SymplisIT\\DriverMagic\\DriverMagic.exe:*:Enabled:DriverMagic"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe"="C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 6.0\\avp.exe:*:Disabled:Kaspersky Anti-Virus"

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"

"C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe"="C:\\Program Files\\Kaspersky Lab\\Kaspersky Anti-Virus 7.0\\avp.exe:*:Enabled:Kaspersky Anti-Virus"

"C:\\Program Files\\Reallusion\\CrazyTalk for Skype\\CT4Skype.exe"="C:\\Program Files\\Reallusion\\CrazyTalk for Skype\\CT4Skype.exe:*:Enabled:CrazyTalk"

"C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"

 

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"

"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

 

Remaining Files :

 

 

File Backups: - C:\DOCUME~1\Karim\Bureau\SDFix\backups\backups.zip

 

Files with Hidden Attributes :

 

Sat 3 May 2008 193 A.SHR --- "C:\BOOT.BAK"

Mon 21 Jul 2008 315,392 ...H. --- "C:\Program Files\All-into-One Flash Mixer\~LiveUpdate.exe"

Tue 23 Sep 2008 847,482 ..SH. --- "C:\WINDOWS\system32\eefxeqpt.tmp"

Thu 15 May 2008 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"

Mon 1 Nov 1993 48,224 A..H. --- "C:\Documents and Settings\Karim\Bureau\COMMCTRL.DLL"

Tue 10 Oct 2000 65,536 A..H. --- "C:\Documents and Settings\Karim\Bureau\IEHost.exe"

Wed 18 Aug 1993 265,216 A..H. --- "C:\Documents and Settings\Karim\Bureau\install.exe"

Thu 22 Feb 1996 18,720 A..H. --- "C:\Documents and Settings\Karim\Bureau\KEYP.SYS"

Wed 12 Sep 2001 212,992 A..H. --- "C:\Documents and Settings\Karim\Bureau\NavBrowser.exe"

Fri 18 Apr 1997 16,384 A..H. --- "C:\Documents and Settings\Karim\Bureau\REBOOT.EXE"

Thu 22 Feb 1996 77,036 A..H. --- "C:\Documents and Settings\Karim\Bureau\SKEYADD.EXE"

Thu 22 Feb 1996 78,300 A..H. --- "C:\Documents and Settings\Karim\Bureau\SKEYRM.EXE"

Thu 24 Aug 1995 42,080 A..H. --- "C:\Documents and Settings\Karim\Bureau\WINSOCK.DLL"

Fri 15 Aug 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

 

Finished!

Posté(e)

Bonjour,

 

Voici le rapport hijackthis :

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:19:09, on 08/10/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\WINDOWS\system32\wscntfy.exe

C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe

C:\ATI Technologies\ATI Control Panel\atiptaxx.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe

C:\Documents and Settings\Karim\Local Settings\Application Data\Google\Update\GoogleUpdate.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe

C:\Program Files\Skype\Plugin Manager\skypePM.exe

C:\WINDOWS\system32\rundll32.exe

C:\Documents and Settings\Karim\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Karim\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Documents and Settings\Karim\Local Settings\Application Data\Google\Chrome\Application\chrome.exe

C:\Program Files\EoRezo\EoEngine.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\WINDOWS\explorer.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lo.st

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lo.st

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC

O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName

O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Fichiers communs\Nero\Lib\NeroCheck.exe

O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC

O4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32

O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min

O4 - HKLM\..\Run: [ATIPTA] C:\ATI Technologies\ATI Control Panel\atiptaxx.exe

O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [bM4b24db5c] Rundll32.exe "C:\WINDOWS\system32\kkehktkk.dll",s

O4 - HKLM\..\Run: [4817e8c0] rundll32.exe "C:\WINDOWS\system32\sptdvvhl.dll",b

O4 - HKLM\..\Run: [EoEngine] "C:\Program Files\EoRezo\EoEngine.exe"

O4 - HKLM\..\Run: [itsTV] "C:\Program Files\ItsLabel\ItsTV.exe"

O4 - HKCU\..\Run: [Widget Neuf] "C:\Program Files\Neuf\Widget Neuf\9widget.exe"

O4 - HKCU\..\Run: [vTunerStartUp] C:\PROGRA~1\vTuner\vTuner.exe WinStart=Yes

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [Real Desktop] "C:\Program Files\Real Desktop\Real Desktop.exe"

O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020

O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Karim\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')

O4 - Global Startup: Image Transfer.lnk = ?

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Plugin Control) - http://appldnld.apple.com.edgesuite.net/co...ex/qtplugin.cab

O16 - DPF: {38D6D77C-5EC1-4A4A-AFEB-85FE780CD61A} (FontDownloaderIE Class) - http://www.qurancomplex.org/downloads/FontDown.cab

O16 - DPF: {B0067CA5-2C37-4C6B-AAEC-5E2CE8635061} (FontDown Class) - http://www.qurancomplex.org/Downloads/FontSmooth.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL

O20 - AppInit_DLLs: ngfbpm.dll

O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe

O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe

O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe

O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

 

--

End of file - 7924 bytes

Posté(e)

Bonjour,

 

Il semble y avoir un Vundo.

 

On vérifie et on le liquide:

 

Télécharge Malwarebytes' Anti-Malware (MBAM)

 

  • Double clique sur le fichier téléchargé pour lancer le processus d'installation.
  • Dans l'onglet "Mise à jour", clique sur le bouton "Recherche de mise à jour": si le pare-feu demande l'autorisation à MBAM de se connecter, accepte.
  • Une fois la mise à jour terminée, rends-toi dans l'onglet "Recherche".
  • Sélectionne "Exécuter un examen complet"
  • Clique sur "Rechercher"
  • L'analyse démarre, le scan est relativement long, c'est normal.
  • A la fin de l'analyse, un message s'affiche :
    L'examen s'est terminé normalement. Clique sur 'Afficher les résultats' pour afficher tous les objets trouvés.
    Clique sur "Ok" pour poursuivre. Si MBAM n'a rien trouvé, il te le dira aussi.
  • Ferme tes navigateurs.
  • Si des malwares ont été détectés, clique sur Afficher les résultats.
    Sélectionne tout (ou laisse coché) et clique sur Supprimer la sélection, MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
  • MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Copie-colle ce rapport et poste-le dans ta prochaine réponse.

Si MBAM demande à être redémarré, reboote le pc.

 

Poste un nouveau log Hijackthis après le redémarrage de la machine stp.

Posté(e)

Bonjour,

 

voici le rapport MBAM :

 

Malwarebytes' Anti-Malware 1.28

Version de la base de données: 1246

Windows 5.1.2600 Service Pack 2

 

09/10/2008 12:29:36

mbam-log-2008-10-09 (12-29-19).txt

 

Type de recherche: Examen rapide

Eléments examinés: 49194

Temps écoulé: 20 minute(s), 20 second(s)

 

Processus mémoire infecté(s): 0

Module(s) mémoire infecté(s): 5

Clé(s) du Registre infectée(s): 12

Valeur(s) du Registre infectée(s): 1

Elément(s) de données du Registre infecté(s): 2

Dossier(s) infecté(s): 2

Fichier(s) infecté(s): 123

 

Processus mémoire infecté(s):

(Aucun élément nuisible détecté)

 

Module(s) mémoire infecté(s):

C:\WINDOWS\system32\pmnoNEWq.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\wmtfpvmj.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\ngfbpm.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\dgrbpddo.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\qzhdeu.dll (Trojan.Vundo.H) -> No action taken.

 

Clé(s) du Registre infectée(s):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0e68421d-c535-4bee-9f22-7b5d05835735} (Trojan.Vundo.H) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{0e68421d-c535-4bee-9f22-7b5d05835735} (Trojan.Vundo.H) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a532345b-a7c7-44bb-a56e-52afea15dff0} (Trojan.Vundo.H) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{a532345b-a7c7-44bb-a56e-52afea15dff0} (Trojan.Vundo.H) -> No action taken.

HKEY_CLASSES_ROOT\CLSID\{66186f05-bbbb-4a39-864f-72d84615c679} (Trojan.Agent) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IProxyProvider (Trojan.Vundo) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> No action taken.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.

 

Valeur(s) du Registre infectée(s):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4817e8c0 (Trojan.Vundo.H) -> No action taken.

 

Elément(s) de données du Registre infecté(s):

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\pmnonewq -> No action taken.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\pmnonewq -> No action taken.

 

Dossier(s) infecté(s):

C:\WINDOWS\system32\IE updates (Adware.Agent) -> No action taken.

C:\WINDOWS\system32\drivers\downld (Trojan.Agent) -> No action taken.

 

Fichier(s) infecté(s):

C:\WINDOWS\system32\qzhdeu.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\pmnoNEWq.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\qWENonmp.ini (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\qWENonmp.ini2 (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\jgjedplr.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\rlpdejgj.ini (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\jrrhnrep.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\pernhrrj.ini (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\ltjqkvnv.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\vnvkqjtl.ini (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\oogbqyxp.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\pxyqbgoo.ini (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\qfjudcgk.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\kgcdujfq.ini (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\sptdvvhl.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\lhvvdtps.ini (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\uhjkfvxl.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\lxvfkjhu.ini (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\wmtfpvmj.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\jmvpftmw.ini (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\xmxkpvkb.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\bkvpkxmx.ini (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\system32\ngfbpm.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\dgrbpddo.dll (Trojan.Vundo.H) -> No action taken.

C:\WINDOWS\ebook_library.dll (Adware.Agent) -> No action taken.

C:\WINDOWS\Adobe Pdf Money Guide.exe (Adware.Agent) -> No action taken.

C:\WINDOWS\system32\gtgtqwxv.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\gutctedr.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\cguyxlmt.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\chdzqo.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\Checker.exe (Adware.Agent) -> No action taken.

C:\WINDOWS\system32\cxkotddk.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\eyynhkgd.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\ipcdnhqf.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\jmcbdmox.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\jtkiahdw.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\jwpqfbyv.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\kkehktkk.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\mbnnksos.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\msdqbkxj.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\mwabsdfb.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\nfjictxt.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\odpuqfwh.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\rtbnrhxo.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\scaiclqk.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\osjjsiwg.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\pagpspdh.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\pbgwuies.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\pcejmqkd.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\vgjoabpu.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\vnaaofer.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\vscvrwrs.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\uosgkepl.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\urpkjslv.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\woaoevbk.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\womaqb.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\weqqoy.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\wfftjshq.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\fsibldmh.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\ihvesoti.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\imqaihka.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\nvtqahqm.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\midaheeo.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\spkvjmkg.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\axtvxg.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\puxwmkit.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\qmekyt.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\wprdrnwc.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\wkbvvlre.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\xrqsmbid.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\xthlftdk.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\xxestned.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\ycjwlwhm.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\ygoxswqd.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\ytcwqted.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\yxckngie.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\mthjfenx.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\lpsmqowa.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\noxhok.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\icvobpkd.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\ohuprftk.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\kuovsqtx.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\sllejwrv.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\aukdvihu.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\wuvglz.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\wvafabme.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\xbkcle.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\xfsxoxgi.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\xgmpxogk.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\lfhcbxte.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\luddgbjo.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\lvanotnv.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\lxajvgbh.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\hueyabxt.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\gbefph.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\gmrlqqlx.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\txdmwnsq.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\bjcnhmob.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\bmkucsfx.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\bnotagnl.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\iwhgfg.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\jdgwwxny.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\aqidcc.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\edrnkecv.dll (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\ekmbtivi.dll (Trojan.Vundo) -> No action taken.

C:\Documents and Settings\Karim\Local Settings\Temporary Internet Files\Content.IE5\6VLT6JEH\nd82m0[2] (Trojan.Vundo.H) -> No action taken.

C:\Documents and Settings\Karim\Local Settings\Temporary Internet Files\Content.IE5\9FESLX76\upd105320[1] (Trojan.Vundo.H) -> No action taken.

C:\Documents and Settings\Karim\Local Settings\Temporary Internet Files\Content.IE5\9FESLX76\kb678031[1] (Trojan.Vundo) -> No action taken.

C:\WINDOWS\system32\IE updates\Roulette Cheat Guide - Make Money Online TODAY.url (Adware.Agent) -> No action taken.

C:\WINDOWS\system32\IE updates\sexYsexlog.url (Adware.Agent) -> No action taken.

C:\WINDOWS\system32\Crack.txt (Rogue.Link) -> No action taken.

C:\WINDOWS\system32\How To Use The Checker.pdf (Rogue.Link) -> No action taken.

C:\WINDOWS\Quick Money Guide.pdf (Rogue.Link) -> No action taken.

C:\WINDOWS\Read Me First.txt (Rogue.Link) -> No action taken.

C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> No action taken.

C:\WINDOWS\pskt.ini (Trojan.Vundo) -> No action taken.

C:\WINDOWS\BM4b24db5c.xml (Trojan.Vundo) -> No action taken.

C:\WINDOWS\BM4b24db5c.txt (Trojan.Vundo) -> No action taken.

C:\Documents and Settings\Karim\Menu Démarrer\Adobe Pdf Money Guide.lnk (Rogue.Link) -> No action taken.

C:\Documents and Settings\Karim\Menu Démarrer\Crack Money Maker Checker.lnk (Rogue.Link) -> No action taken.

C:\Documents and Settings\Karim\Menu Démarrer\Money Maker Checker Help Guide.lnk (Rogue.Link) -> No action taken.

C:\Documents and Settings\Karim\Menu Démarrer\Money Maker Checker.lnk (Rogue.Link) -> No action taken.

C:\Documents and Settings\Karim\Menu Démarrer\Quick Money Guide.lnk (Rogue.Link) -> No action taken.

Posté(e)

Bonjour,

 

No action taken.
Il faudrait lire les procédures qu'on vous prépare!

 

Tu as perdu du temps pour rien; recommence l'analyse MBAM et fais ce que j'ai indiqué en rouge.

 

@++

Posté(e)

Je fais passer le message

 

Merci.

 

Bonjour,

 

Il faudrait lire les procédures qu'on vous prépare!

 

Tu as perdu du temps pour rien; recommence l'analyse MBAM et fais ce que j'ai indiqué en rouge.

 

@++

Posté(e)

Voici la suite :

 

Malwarebytes' Anti-Malware 1.28

Version de la base de données: 1246

Windows 5.1.2600 Service Pack 2

 

09/10/2008 13:29:22

mbam-log-2008-10-09 (13-29-22).txt

 

Type de recherche: Examen rapide

Eléments examinés: 48941

Temps écoulé: 10 minute(s), 49 second(s)

 

Processus mémoire infecté(s): 0

Module(s) mémoire infecté(s): 3

Clé(s) du Registre infectée(s): 9

Valeur(s) du Registre infectée(s): 1

Elément(s) de données du Registre infecté(s): 2

Dossier(s) infecté(s): 2

Fichier(s) infecté(s): 68

 

Processus mémoire infecté(s):

(Aucun élément nuisible détecté)

 

Module(s) mémoire infecté(s):

C:\WINDOWS\system32\pmnoNEWq.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\system32\wmtfpvmj.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\system32\qzhdeu.dll (Trojan.Vundo.H) -> Delete on reboot.

 

Clé(s) du Registre infectée(s):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0e68421d-c535-4bee-9f22-7b5d05835735} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_CLASSES_ROOT\CLSID\{0e68421d-c535-4bee-9f22-7b5d05835735} (Trojan.Vundo.H) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8fcbfe44-6e65-4c9e-a0f9-4ca5ab84f27c} (Trojan.Vundo.H) -> Delete on reboot.

HKEY_CLASSES_ROOT\CLSID\{8fcbfe44-6e65-4c9e-a0f9-4ca5ab84f27c} (Trojan.Vundo.H) -> Delete on reboot.

HKEY_CLASSES_ROOT\CLSID\{66186f05-bbbb-4a39-864f-72d84615c679} (Trojan.Agent) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.

 

Valeur(s) du Registre infectée(s):

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\4817e8c0 (Trojan.Vundo.H) -> Quarantined and deleted successfully.

 

Elément(s) de données du Registre infecté(s):

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\pmnonewq -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\pmnonewq -> Delete on reboot.

 

Dossier(s) infecté(s):

C:\WINDOWS\system32\IE updates (Adware.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\drivers\downld (Trojan.Agent) -> Quarantined and deleted successfully.

 

Fichier(s) infecté(s):

C:\WINDOWS\system32\qzhdeu.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\system32\pmnoNEWq.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\system32\qWENonmp.ini (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\system32\qWENonmp.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\ltjqkvnv.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\vnvkqjtl.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\sptdvvhl.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\lhvvdtps.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\wmtfpvmj.dll (Trojan.Vundo.H) -> Delete on reboot.

C:\WINDOWS\system32\jmvpftmw.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\ebook_library.dll (Adware.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\Adobe Pdf Money Guide.exe (Adware.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\gutctedr.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\chdzqo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\Checker.exe (Adware.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\dgrbpddo.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\eyynhkgd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\ipcdnhqf.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\kkehktkk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\mbnnksos.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\nfjictxt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\ngfbpm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\scaiclqk.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\pagpspdh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\vgjoabpu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\vscvrwrs.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\urpkjslv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\womaqb.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\weqqoy.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\fsibldmh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\ihvesoti.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\nvtqahqm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\axtvxg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\qmekyt.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\xrqsmbid.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\xxestned.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\ycjwlwhm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\ygoxswqd.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\lpsmqowa.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\noxhok.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\sllejwrv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\wuvglz.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\xbkcle.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\lfhcbxte.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\luddgbjo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\lvanotnv.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\gmrlqqlx.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\bjcnhmob.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\iwhgfg.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\jdgwwxny.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\aqidcc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\Documents and Settings\Karim\Local Settings\Temporary Internet Files\Content.IE5\6VLT6JEH\nd82m0[2] (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\Documents and Settings\Karim\Local Settings\Temporary Internet Files\Content.IE5\9FESLX76\upd105320[1] (Trojan.Vundo.H) -> Quarantined and deleted successfully.

C:\Documents and Settings\Karim\Local Settings\Temporary Internet Files\Content.IE5\9FESLX76\kb678031[1] (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\IE updates\Roulette Cheat Guide - Make Money Online TODAY.url (Adware.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\IE updates\sexYsexlog.url (Adware.Agent) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\Crack.txt (Rogue.Link) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\How To Use The Checker.pdf (Rogue.Link) -> Quarantined and deleted successfully.

C:\WINDOWS\Quick Money Guide.pdf (Rogue.Link) -> Quarantined and deleted successfully.

C:\WINDOWS\Read Me First.txt (Rogue.Link) -> Quarantined and deleted successfully.

C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.

C:\WINDOWS\BM4b24db5c.xml (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\WINDOWS\BM4b24db5c.txt (Trojan.Vundo) -> Quarantined and deleted successfully.

C:\Documents and Settings\Karim\Menu Démarrer\Adobe Pdf Money Guide.lnk (Rogue.Link) -> Quarantined and deleted successfully.

C:\Documents and Settings\Karim\Menu Démarrer\Crack Money Maker Checker.lnk (Rogue.Link) -> Quarantined and deleted successfully.

C:\Documents and Settings\Karim\Menu Démarrer\Money Maker Checker Help Guide.lnk (Rogue.Link) -> Quarantined and deleted successfully.

C:\Documents and Settings\Karim\Menu Démarrer\Money Maker Checker.lnk (Rogue.Link) -> Quarantined and deleted successfully.

C:\Documents and Settings\Karim\Menu Démarrer\Quick Money Guide.lnk (Rogue.Link) -> Quarantined and deleted successfully.

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...