Trojan vundo

Fermé
kmi_vundo - 14 févr. 2009 à 10:58
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 - 15 févr. 2009 à 22:34
Bonjour,
j'ai y a qq jours eut le virus trjan vundo, j'ai essayser de le virer avec malwarebytes et combo fix, mais apparament il en reste....voici mon rapport hijak

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:53:13, on 14.02.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Brother\ControlCenter3\brccMCtl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\WINDOWS\system32\drwtsn32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Documents and Settings\Gilbert\Mes documents\VundoFix.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\CA Yahoo! Anti-Spy\CAYahooAntispy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ch/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/?p=us
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://blueadit.bluewin.ch/adsl/router/index_f.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {b5146c40-189a-4311-bda9-fbae3e023187} - (no file)
R3 - URLSearchHook: (no name) - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - (no file)
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\IPSBHO.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {b5146c40-189a-4311-bda9-fbae3e023187} - (no file)
O3 - Toolbar: (no name) - {40d1c3a7-4ffb-4443-b3a0-a64b2df7fc3b} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
O4 - HKLM\..\Run: [BrMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKLM\..\Run: [VideoraiPodConverter] C:\Documents and Settings\Gilbert\Bureau\VideoraiPodConverter\VideoraiPodConverter.exe -t
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ch\msntabres.dll.mui/229?ab265c967b2a4e61a486609fec3bd1c1
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-ch\msntabres.dll.mui/230?ab265c967b2a4e61a486609fec3bd1c1
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
O16 - DPF: {104B0A37-AB99-4F06-8032-8BBDC3B77DDB} (Telechargement Control) - http://www2.photoweb.fr/telechargement/Photoweb_uploader.cab
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) - http://www.ipix.com/download/ipixx.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - https://support.norton.com/sp/en/us/home/current/info
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://www.new2.foto.com/ImageUploader5.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E5E167B-1566-4316-B27F-0DDAB3484CF7} (Image Uploader Control) - http://www.extrafilm.ch/ImageUploader4.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - https://www.pixum.fr/?p_ref=crm_umleitung_photoreflex_1113
O16 - DPF: {A73BAEFA-EE65-494D-BEDB-DD3E5A34FA98} (Image Uploader) - http://www.extrafilm.ch/ImageUploader4.cab
O16 - DPF: {BB75AB3B-C666-4CAC-B22A-83C5A7DCCA77} (FFCHUploadX) - https://www.fujifilm.ch/fujifilmshop/plugins/activexupload/FFCHUploadX.cab
O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\coIEPlg.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton Internet Security - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O24 - Desktop Component 0: (no name) - http://sanctuary-of-lilith.com/image-0171085.jpg
O24 - Desktop Component 1: (no name) - http://sanctuary-of-lilith.com/image-0171386.jpg
O24 - Desktop Component 2: (no name) - http://sanctuary-of-lilith.com/image-0171086.jpg
O24 - Desktop Component 3: (no name) - http://sanctuary-of-lilith.com/image-0171380.jpg
O24 - Desktop Component 4: (no name) - http://sanctuary-of-lilith.com/image-0171093.jpg
O24 - Desktop Component 5: (no name) - http://www.tourismebretagne.com/image/bretagne_legende/images/fees/roche.jpg
O24 - Desktop Component 6: (no name) - http://www.tourismebretagne.com/image/bretagne_legende/images/ys/1.jpg
O24 - Desktop Component 7: (no name) - http://www.tourismebretagne.com/image/bretagne_legende/images/fees/feesMelusine.jpg
O24 - Desktop Component 8: (no name) - http://www.tourismebretagne.com/image/bretagne_legende/images/korrigans/6.jpg
A voir également:

8 réponses

Franzy49 Messages postés 12 Date d'inscription jeudi 12 février 2009 Statut Membre Dernière intervention 11 mars 2009 5
14 févr. 2009 à 12:32
salut
essaie de faire un scan avec Avast au démarrage du pc avant que t'arrive sur le bureau!! sinon télécharge un petit logiciel "lopSD" que tu trouve la http://forum.telecharger.01net.com/microhebdo/6/tuto-securite/lopsd-eliminez-les-pubs-cid-353105/messages-1.html

donc voila!!
a+
0
VOICI LE rapport de lops
que puis je faire d'autre....quand j'utilise explorer, des fenetres d'erreur continue de venir ( voulez vous envoyez le rapport d'erreur a microsoft) etc.....????
merci

--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A02
USER : Gilbert ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 16.2.0.7 (Activated)
Firewall : Norton Internet Security 16.2.0.7 (Activated)
C:\ (Local Disk) - NTFS - Total:232 Go (Free:46 Go)
D:\ (CD or DVD)
E:\ (USB)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [1] ( 14.02.2009|17:05 )

--------------------\\ Listing des dossiers dans APPLIC~1

[01.01.2009|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[14.02.2009|10:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[21.10.2006|12:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[28.07.2007|15:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[27.10.2006|16:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[08.07.2008|15:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Brother
[30.05.2008|19:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BVRP Software
[04.06.2008|18:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[25.01.2009|19:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EPSON
[01.09.2007|11:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[04.11.2007|13:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[08.07.2008|15:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[12.05.2008|20:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[08.02.2009|20:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[04.06.2008|18:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[25.01.2009|19:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Norton
[25.01.2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NortonInstaller
[04.11.2007|13:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[05.06.2008|10:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\River Past G5
[09.07.2008|14:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[02.07.2007|23:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[25.01.2009|19:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[19.01.2009|09:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tarma Installer
[13.05.2008|18:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[13.05.2008|10:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[11.04.2007|06:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[22.10.2006|16:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[12.09.2008|15:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[28.07.2008|11:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
[28.07.2008|13:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

[15.05.2006|08:38] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[15.05.2008|08:59] C:\DOCUME~1\GILBAN~1\APPLIC~1\Adobe
[15.05.2008|09:36] C:\DOCUME~1\GILBAN~1\APPLIC~1\AdobeUM
[11.10.2007|07:38] C:\DOCUME~1\GILBAN~1\APPLIC~1\Apple Computer
[23.01.2008|20:38] C:\DOCUME~1\GILBAN~1\APPLIC~1\Google
[17.04.2008|15:04] C:\DOCUME~1\GILBAN~1\APPLIC~1\Help
[11.08.2007|19:30] C:\DOCUME~1\GILBAN~1\APPLIC~1\Identities
[13.08.2007|11:34] C:\DOCUME~1\GILBAN~1\APPLIC~1\Macromedia
[14.08.2007|15:04] C:\DOCUME~1\GILBAN~1\APPLIC~1\Microsoft
[22.04.2008|08:48] C:\DOCUME~1\GILBAN~1\APPLIC~1\Nokia
[04.11.2007|15:54] C:\DOCUME~1\GILBAN~1\APPLIC~1\PC Suite
[19.11.2007|16:27] C:\DOCUME~1\GILBAN~1\APPLIC~1\Real
[15.09.2008|14:38] C:\DOCUME~1\GILBAN~1\APPLIC~1\yahoo!

[14.02.2009|10:16] C:\DOCUME~1\Gilbert\APPLIC~1\Adobe
[17.09.2006|10:54] C:\DOCUME~1\Gilbert\APPLIC~1\AdobeUM
[17.09.2006|16:25] C:\DOCUME~1\Gilbert\APPLIC~1\Ahead
[07.11.2008|18:10] C:\DOCUME~1\Gilbert\APPLIC~1\Apple Computer
[31.03.2007|17:39] C:\DOCUME~1\Gilbert\APPLIC~1\Arcsoft
[09.07.2008|09:35] C:\DOCUME~1\Gilbert\APPLIC~1\Brother
[15.05.2006|09:09] C:\DOCUME~1\Gilbert\APPLIC~1\Creative
[09.07.2008|07:04] C:\DOCUME~1\Gilbert\APPLIC~1\DivX
[19.03.2007|21:58] C:\DOCUME~1\Gilbert\APPLIC~1\EuroTalk
[01.09.2007|22:05] C:\DOCUME~1\Gilbert\APPLIC~1\Google
[29.04.2007|12:07] C:\DOCUME~1\Gilbert\APPLIC~1\Help
[15.05.2006|08:51] C:\DOCUME~1\Gilbert\APPLIC~1\Identities
[25.04.2008|09:03] C:\DOCUME~1\Gilbert\APPLIC~1\InstallShield
[08.06.2008|15:55] C:\DOCUME~1\Gilbert\APPLIC~1\KompoZer
[28.03.2007|18:03] C:\DOCUME~1\Gilbert\APPLIC~1\Leadertech
[17.02.2007|01:39] C:\DOCUME~1\Gilbert\APPLIC~1\Macromedia
[08.02.2009|20:00] C:\DOCUME~1\Gilbert\APPLIC~1\Malwarebytes
[30.05.2008|19:23] C:\DOCUME~1\Gilbert\APPLIC~1\Microsoft
[27.08.2006|16:24] C:\DOCUME~1\Gilbert\APPLIC~1\Mozilla
[05.12.2007|13:22] C:\DOCUME~1\Gilbert\APPLIC~1\Nokia
[25.01.2009|11:52] C:\DOCUME~1\Gilbert\APPLIC~1\OpenOffice.org2
[05.12.2007|12:26] C:\DOCUME~1\Gilbert\APPLIC~1\PC Suite
[01.07.2007|17:07] C:\DOCUME~1\Gilbert\APPLIC~1\PPTminimizer
[02.11.2008|15:58] C:\DOCUME~1\Gilbert\APPLIC~1\Real
[02.06.2008|20:18] C:\DOCUME~1\Gilbert\APPLIC~1\River Past G5
[09.07.2008|14:21] C:\DOCUME~1\Gilbert\APPLIC~1\ScanSoft
[12.05.2008|20:18] C:\DOCUME~1\Gilbert\APPLIC~1\Simply Super Software
[21.05.2006|11:34] C:\DOCUME~1\Gilbert\APPLIC~1\Symantec
[28.07.2008|14:04] C:\DOCUME~1\Gilbert\APPLIC~1\Yahoo!

[12.07.2008|08:00] C:\DOCUME~1\iman\APPLIC~1\Adobe
[27.11.2008|17:01] C:\DOCUME~1\iman\APPLIC~1\Apple Computer
[12.07.2008|08:01] C:\DOCUME~1\iman\APPLIC~1\DivX
[27.11.2008|08:36] C:\DOCUME~1\iman\APPLIC~1\Google
[12.07.2008|07:58] C:\DOCUME~1\iman\APPLIC~1\Identities
[26.07.2008|19:47] C:\DOCUME~1\iman\APPLIC~1\Macromedia
[27.11.2008|08:20] C:\DOCUME~1\iman\APPLIC~1\Microsoft
[12.07.2008|07:58] C:\DOCUME~1\iman\APPLIC~1\PC Suite
[12.07.2008|07:59] C:\DOCUME~1\iman\APPLIC~1\Real
[27.11.2008|08:36] C:\DOCUME~1\iman\APPLIC~1\Yahoo!

[29.06.2007|21:16] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[02.07.2007|23:20] C:\DOCUME~1\INVIT~1\APPLIC~1\Macromedia
[03.07.2007|21:22] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[04.07.2007|20:14] C:\DOCUME~1\INVIT~1\APPLIC~1\OpenOffice.org2
[29.06.2007|21:16] C:\DOCUME~1\INVIT~1\APPLIC~1\Real
[12.07.2007|21:20] C:\DOCUME~1\INVIT~1\APPLIC~1\Skype

[15.05.2006|08:42] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[01.10.2006|09:27] C:\DOCUME~1\LOCALS~1\APPLIC~1\Symantec

[15.05.2006|08:41] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[12.02.2009 12:33][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[14.02.2009 16:58][--a------] C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job
[14.02.2009 10:09][--ah-----] C:\WINDOWS\tasks\SA.DAT
[10.08.2004 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[17.10.2006|18:15] C:\Program Files\Adobe
[21.10.2006|12:23] C:\Program Files\Ahead
[06.11.2008|03:09] C:\Program Files\Apple Software Update
[08.11.2008|22:55] C:\Program Files\AviSynth 2.5
[21.05.2006|11:05] C:\Program Files\Bluewin
[01.01.2009|12:40] C:\Program Files\Bonjour
[08.07.2008|15:10] C:\Program Files\Brother
[14.02.2009|10:43] C:\Program Files\CA Yahoo! Anti-Spy
[21.05.2006|11:42] C:\Program Files\CCleaner
[15.05.2006|08:34] C:\Program Files\ComPlus Applications
[04.11.2007|13:47] C:\Program Files\DIFX
[12.11.2006|14:29] C:\Program Files\directx
[04.07.2008|20:30] C:\Program Files\DivX
[16.11.2006|22:10] C:\Program Files\DVD Video Mobile
[11.02.2009|13:51] C:\Program Files\eMule
[25.01.2009|19:13] C:\Program Files\EPSON
[14.02.2007|00:21] C:\Program Files\ewido anti-malware
[06.12.2008|10:23] C:\Program Files\ewido anti-spyware 4.0
[27.06.2006|19:02] C:\Program Files\excel
[14.02.2009|10:39] C:\Program Files\Fichiers communs
[14.07.2008|16:43] C:\Program Files\GameSpy Arcade
[14.07.2008|16:36] C:\Program Files\Google
[02.06.2008|14:10] C:\Program Files\GXTranscoderv5
[04.03.2007|17:20] C:\Program Files\Infogrames
[20.12.2008|17:52] C:\Program Files\InstallShield Installation Information
[15.05.2006|08:56] C:\Program Files\Intel
[12.12.2008|03:02] C:\Program Files\Internet Explorer
[01.01.2009|12:42] C:\Program Files\iPod
[01.01.2009|12:42] C:\Program Files\iTunes
[25.01.2009|19:11] C:\Program Files\KaraFun
[14.02.2009|10:11] C:\Program Files\Malwarebytes' Anti-Malware
[27.12.2008|14:19] C:\Program Files\Messenger
[10.05.2007|02:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[16.07.2007|19:27] C:\Program Files\microsoft frontpage
[02.06.2006|16:50] C:\Program Files\Microsoft Games
[12.09.2008|15:04] C:\Program Files\Microsoft SQL Server Compact Edition
[27.12.2008|14:15] C:\Program Files\Movie Maker
[25.01.2009|19:11] C:\Program Files\Mozilla Firefox
[15.05.2006|08:32] C:\Program Files\MSN
[15.05.2006|08:32] C:\Program Files\MSN Gaming Zone
[11.02.2009|08:21] C:\Program Files\MSN Messenger
[16.11.2006|03:00] C:\Program Files\MSXML 4.0
[23.07.2008|17:13] C:\Program Files\Multi_Media
[17.09.2006|14:50] C:\Program Files\Nero
[27.12.2008|14:12] C:\Program Files\NetMeeting
[25.01.2009|19:19] C:\Program Files\Norton Internet Security
[25.01.2009|19:22] C:\Program Files\Norton Support
[25.01.2009|19:18] C:\Program Files\NortonInstaller
[08.07.2008|15:08] C:\Program Files\Nuance
[15.05.2006|08:34] C:\Program Files\Online Services
[23.07.2008|17:13] C:\Program Files\Online_TV
[30.10.2006|20:20] C:\Program Files\OpenOffice.org 2.0
[13.05.2008|13:37] C:\Program Files\Orange Shark
[27.12.2008|14:12] C:\Program Files\Outlook Express
[04.11.2007|13:46] C:\Program Files\PC Connectivity Solution
[02.06.2008|13:50] C:\Program Files\Philips
[27.06.2006|19:01] C:\Program Files\power point
[01.01.2009|12:40] C:\Program Files\QuickTime
[29.03.2007|17:18] C:\Program Files\Real
[08.11.2008|22:34] C:\Program Files\Red Kawa
[08.07.2008|15:06] C:\Program Files\ScanSoft
[15.05.2006|08:36] C:\Program Files\Services en ligne
[25.01.2009|19:19] C:\Program Files\Symantec
[14.02.2009|10:52] C:\Program Files\Trend Micro
[20.05.2008|14:26] C:\Program Files\Uninstall Information
[08.11.2008|22:30] C:\Program Files\VideoraiPodConverter
[16.11.2006|21:57] C:\Program Files\WinASPI
[15.09.2008|02:01] C:\Program Files\Windows Live
[30.11.2007|03:01] C:\Program Files\Windows Live Toolbar
[14.02.2007|00:15] C:\Program Files\Windows Media Player
[27.12.2008|14:12] C:\Program Files\Windows NT
[15.05.2006|08:34] C:\Program Files\Windows Plus
[25.01.2009|19:19] C:\Program Files\Windows Sidebar
[15.05.2006|08:36] C:\Program Files\WindowsUpdate
[15.05.2006|08:38] C:\Program Files\xerox
[28.07.2008|11:44] C:\Program Files\Yahoo!
[12.09.2008|14:44] C:\Program Files\Yontoo Layers Client for Internet Explorer
[21.01.2007|10:43] C:\Program Files\Zero G Registry

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[15.05.2008|09:37] C:\Program Files\Fichiers communs\Adobe
[21.10.2006|12:20] C:\Program Files\Fichiers communs\Ahead
[01.01.2009|12:42] C:\Program Files\Fichiers communs\Apple
[13.05.2008|10:40] C:\Program Files\Fichiers communs\InstallShield
[08.05.2008|07:09] C:\Program Files\Fichiers communs\Microsoft Shared
[15.05.2006|08:36] C:\Program Files\Fichiers communs\MSSoap
[15.05.2006|10:25] C:\Program Files\Fichiers communs\ODBC
[27.08.2006|16:09] C:\Program Files\Fichiers communs\Real
[14.02.2009|10:39] C:\Program Files\Fichiers communs\Scanner
[08.07.2008|15:07] C:\Program Files\Fichiers communs\ScanSoft Shared
[15.05.2006|08:36] C:\Program Files\Fichiers communs\Services
[15.05.2006|10:25] C:\Program Files\Fichiers communs\SpeechEngines
[25.01.2009|19:23] C:\Program Files\Fichiers communs\Symantec Shared
[27.12.2008|14:12] C:\Program Files\Fichiers communs\System
[12.09.2008|15:03] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[27.08.2006|16:09] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 48 Processes )

iexplore.exe ~ [PID:3852]

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

C:\DOCUME~1\Gilbert\LOCALS~1\Temp\nsu6A.tmp
C:\Program Files\Multi_Media
C:\Program Files\Multi_Media\INSTALL.LOG
C:\Program Files\Multi_Media\LanguagePack.xml
C:\Program Files\Multi_Media\LocalSettings.txt
C:\Program Files\Multi_Media\RadioPlayer
C:\Program Files\Multi_Media\tbMult.dll
C:\Program Files\Multi_Media\ThirdPartyComponents.xml
C:\Program Files\Multi_Media\toolbar.cfg
C:\Program Files\Multi_Media\UNWISE.EXE
C:\Program Files\Multi_Media\update.xml
C:\Program Files\Multi_Media\_tbMul1.dll

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-14 17:07:00
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 5

--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[F:18][D:4]-> C:\DOCUME~1\Gilbert\LOCALS~1\Temp
[F:59][D:0]-> C:\DOCUME~1\Gilbert\Cookies
[F:3639][D:20]-> C:\DOCUME~1\Gilbert\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 14.02.2009|17:08 - Option : [1]

--------------------\\ Fin du rapport a 17:08:42
0
Franzy49 Messages postés 12 Date d'inscription jeudi 12 février 2009 Statut Membre Dernière intervention 11 mars 2009 5
14 févr. 2009 à 21:12
é ca donne quoi en faisant un scan avec avast au démarrage du pc??ya un autre logiciel qui est pas mal que je ne connaissait pas avant c'est "super antispyware" la version gratuite, donc essaie le....!!!

a+
0
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
14 févr. 2009 à 22:52
slt

refais lop sd choisi l'option 2 et colle le rapport



puis colle un rapport malwarebyte


puis un combofix
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
alors dans l'ordre. lops point 2


--------------------\\ Lop S&D 4.2.5-0 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Pentium(R) D CPU 2.80GHz )
BIOS : Phoenix ROM BIOS PLUS Version 1.10 A02
USER : Gilbert ( Administrator )
BOOT : Normal boot
Antivirus : Norton Internet Security 16.2.0.7 (Activated)
Firewall : Norton Internet Security 16.2.0.7 (Activated)
C:\ (Local Disk) - NTFS - Total:232 Go (Free:46 Go)
D:\ (CD or DVD)
E:\ (USB)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)

"C:\Lop SD" ( MAJ : 19-12-2008|23:40 )
Option : [2] ( 15.02.2009|10:18 )


\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ SUPPRESSION

Supprime! - C:\DOCUME~1\Gilbert\LOCALS~1\Temp\nsu6A.tmp
Supprime! - C:\Program Files\Multi_Media\INSTALL.LOG
Supprime! - C:\Program Files\Multi_Media\LanguagePack.xml
Supprime! - C:\Program Files\Multi_Media\LocalSettings.txt
Supprime! - C:\Program Files\Multi_Media\RadioPlayer
Supprime! - C:\Program Files\Multi_Media\tbMult.dll
Supprime! - C:\Program Files\Multi_Media\ThirdPartyComponents.xml
Supprime! - C:\Program Files\Multi_Media\toolbar.cfg
Supprime! - C:\Program Files\Multi_Media\UNWISE.EXE
Supprime! - C:\Program Files\Multi_Media\update.xml
Supprime! - C:\Program Files\Multi_Media\_tbMul1.dll
Supprime! - C:\Program Files\Multi_Media

\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\


--------------------\\ Listing des dossiers dans APPLIC~1

[01.01.2009|12:42] C:\DOCUME~1\ALLUSE~1\APPLIC~1\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
[14.02.2009|10:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Adobe
[21.10.2006|12:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Ahead
[28.07.2007|15:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple
[27.10.2006|16:34] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Apple Computer
[08.07.2008|15:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Brother
[30.05.2008|19:16] C:\DOCUME~1\ALLUSE~1\APPLIC~1\BVRP Software
[04.06.2008|18:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Creative
[25.01.2009|19:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\EPSON
[01.09.2007|11:20] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Google
[04.11.2007|13:46] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Installations
[08.07.2008|15:08] C:\DOCUME~1\ALLUSE~1\APPLIC~1\InstallShield
[12.05.2008|20:29] C:\DOCUME~1\ALLUSE~1\APPLIC~1\MailFrontier
[08.02.2009|20:00] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Malwarebytes
[04.06.2008|18:26] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Microsoft
[25.01.2009|19:19] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Norton
[25.01.2009|19:12] C:\DOCUME~1\ALLUSE~1\APPLIC~1\NortonInstaller
[04.11.2007|13:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\PC Suite
[05.06.2008|10:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\River Past G5
[09.07.2008|14:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\ScanSoft
[02.07.2007|23:23] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Skype
[25.01.2009|19:22] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec
[19.01.2009|09:52] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Tarma Installer
[13.05.2008|18:07] C:\DOCUME~1\ALLUSE~1\APPLIC~1\TEMP
[13.05.2008|10:37] C:\DOCUME~1\ALLUSE~1\APPLIC~1\UDL
[11.04.2007|06:55] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Genuine Advantage
[22.10.2006|16:43] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Windows Live Toolbar
[12.09.2008|15:02] C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
[28.07.2008|11:45] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo!
[28.07.2008|13:17] C:\DOCUME~1\ALLUSE~1\APPLIC~1\Yahoo! Companion

[15.05.2006|08:38] C:\DOCUME~1\DEFAUL~1\APPLIC~1\Microsoft

[15.05.2008|08:59] C:\DOCUME~1\GILBAN~1\APPLIC~1\Adobe
[15.05.2008|09:36] C:\DOCUME~1\GILBAN~1\APPLIC~1\AdobeUM
[11.10.2007|07:38] C:\DOCUME~1\GILBAN~1\APPLIC~1\Apple Computer
[23.01.2008|20:38] C:\DOCUME~1\GILBAN~1\APPLIC~1\Google
[17.04.2008|15:04] C:\DOCUME~1\GILBAN~1\APPLIC~1\Help
[11.08.2007|19:30] C:\DOCUME~1\GILBAN~1\APPLIC~1\Identities
[13.08.2007|11:34] C:\DOCUME~1\GILBAN~1\APPLIC~1\Macromedia
[14.08.2007|15:04] C:\DOCUME~1\GILBAN~1\APPLIC~1\Microsoft
[22.04.2008|08:48] C:\DOCUME~1\GILBAN~1\APPLIC~1\Nokia
[04.11.2007|15:54] C:\DOCUME~1\GILBAN~1\APPLIC~1\PC Suite
[19.11.2007|16:27] C:\DOCUME~1\GILBAN~1\APPLIC~1\Real
[15.09.2008|14:38] C:\DOCUME~1\GILBAN~1\APPLIC~1\yahoo!

[14.02.2009|10:16] C:\DOCUME~1\Gilbert\APPLIC~1\Adobe
[17.09.2006|10:54] C:\DOCUME~1\Gilbert\APPLIC~1\AdobeUM
[17.09.2006|16:25] C:\DOCUME~1\Gilbert\APPLIC~1\Ahead
[07.11.2008|18:10] C:\DOCUME~1\Gilbert\APPLIC~1\Apple Computer
[31.03.2007|17:39] C:\DOCUME~1\Gilbert\APPLIC~1\Arcsoft
[09.07.2008|09:35] C:\DOCUME~1\Gilbert\APPLIC~1\Brother
[15.05.2006|09:09] C:\DOCUME~1\Gilbert\APPLIC~1\Creative
[09.07.2008|07:04] C:\DOCUME~1\Gilbert\APPLIC~1\DivX
[19.03.2007|21:58] C:\DOCUME~1\Gilbert\APPLIC~1\EuroTalk
[01.09.2007|22:05] C:\DOCUME~1\Gilbert\APPLIC~1\Google
[29.04.2007|12:07] C:\DOCUME~1\Gilbert\APPLIC~1\Help
[15.05.2006|08:51] C:\DOCUME~1\Gilbert\APPLIC~1\Identities
[25.04.2008|09:03] C:\DOCUME~1\Gilbert\APPLIC~1\InstallShield
[08.06.2008|15:55] C:\DOCUME~1\Gilbert\APPLIC~1\KompoZer
[28.03.2007|18:03] C:\DOCUME~1\Gilbert\APPLIC~1\Leadertech
[17.02.2007|01:39] C:\DOCUME~1\Gilbert\APPLIC~1\Macromedia
[08.02.2009|20:00] C:\DOCUME~1\Gilbert\APPLIC~1\Malwarebytes
[30.05.2008|19:23] C:\DOCUME~1\Gilbert\APPLIC~1\Microsoft
[27.08.2006|16:24] C:\DOCUME~1\Gilbert\APPLIC~1\Mozilla
[05.12.2007|13:22] C:\DOCUME~1\Gilbert\APPLIC~1\Nokia
[25.01.2009|11:52] C:\DOCUME~1\Gilbert\APPLIC~1\OpenOffice.org2
[05.12.2007|12:26] C:\DOCUME~1\Gilbert\APPLIC~1\PC Suite
[01.07.2007|17:07] C:\DOCUME~1\Gilbert\APPLIC~1\PPTminimizer
[02.11.2008|15:58] C:\DOCUME~1\Gilbert\APPLIC~1\Real
[02.06.2008|20:18] C:\DOCUME~1\Gilbert\APPLIC~1\River Past G5
[09.07.2008|14:21] C:\DOCUME~1\Gilbert\APPLIC~1\ScanSoft
[12.05.2008|20:18] C:\DOCUME~1\Gilbert\APPLIC~1\Simply Super Software
[21.05.2006|11:34] C:\DOCUME~1\Gilbert\APPLIC~1\Symantec
[28.07.2008|14:04] C:\DOCUME~1\Gilbert\APPLIC~1\Yahoo!

[12.07.2008|08:00] C:\DOCUME~1\iman\APPLIC~1\Adobe
[27.11.2008|17:01] C:\DOCUME~1\iman\APPLIC~1\Apple Computer
[12.07.2008|08:01] C:\DOCUME~1\iman\APPLIC~1\DivX
[27.11.2008|08:36] C:\DOCUME~1\iman\APPLIC~1\Google
[12.07.2008|07:58] C:\DOCUME~1\iman\APPLIC~1\Identities
[26.07.2008|19:47] C:\DOCUME~1\iman\APPLIC~1\Macromedia
[27.11.2008|08:20] C:\DOCUME~1\iman\APPLIC~1\Microsoft
[12.07.2008|07:58] C:\DOCUME~1\iman\APPLIC~1\PC Suite
[12.07.2008|07:59] C:\DOCUME~1\iman\APPLIC~1\Real
[27.11.2008|08:36] C:\DOCUME~1\iman\APPLIC~1\Yahoo!

[29.06.2007|21:16] C:\DOCUME~1\INVIT~1\APPLIC~1\Identities
[02.07.2007|23:20] C:\DOCUME~1\INVIT~1\APPLIC~1\Macromedia
[03.07.2007|21:22] C:\DOCUME~1\INVIT~1\APPLIC~1\Microsoft
[04.07.2007|20:14] C:\DOCUME~1\INVIT~1\APPLIC~1\OpenOffice.org2
[29.06.2007|21:16] C:\DOCUME~1\INVIT~1\APPLIC~1\Real
[12.07.2007|21:20] C:\DOCUME~1\INVIT~1\APPLIC~1\Skype

[15.05.2006|08:42] C:\DOCUME~1\LOCALS~1\APPLIC~1\Microsoft
[01.10.2006|09:27] C:\DOCUME~1\LOCALS~1\APPLIC~1\Symantec

[15.05.2006|08:41] C:\DOCUME~1\NETWOR~1\APPLIC~1\Microsoft

--------------------\\ Tâches planifiées dans C:\WINDOWS\tasks

[12.02.2009 12:33][--a------] C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[15.02.2009 09:58][--a------] C:\WINDOWS\tasks\Vérifier les mises à jour de Windows Live Toolbar.job
[14.02.2009 18:05][--ah-----] C:\WINDOWS\tasks\SA.DAT
[10.08.2004 13:00][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing des dossiers dans C:\Program Files

[17.10.2006|18:15] C:\Program Files\Adobe
[21.10.2006|12:23] C:\Program Files\Ahead
[06.11.2008|03:09] C:\Program Files\Apple Software Update
[08.11.2008|22:55] C:\Program Files\AviSynth 2.5
[21.05.2006|11:05] C:\Program Files\Bluewin
[01.01.2009|12:40] C:\Program Files\Bonjour
[08.07.2008|15:10] C:\Program Files\Brother
[14.02.2009|10:43] C:\Program Files\CA Yahoo! Anti-Spy
[21.05.2006|11:42] C:\Program Files\CCleaner
[15.05.2006|08:34] C:\Program Files\ComPlus Applications
[04.11.2007|13:47] C:\Program Files\DIFX
[12.11.2006|14:29] C:\Program Files\directx
[04.07.2008|20:30] C:\Program Files\DivX
[16.11.2006|22:10] C:\Program Files\DVD Video Mobile
[11.02.2009|13:51] C:\Program Files\eMule
[25.01.2009|19:13] C:\Program Files\EPSON
[14.02.2007|00:21] C:\Program Files\ewido anti-malware
[06.12.2008|10:23] C:\Program Files\ewido anti-spyware 4.0
[27.06.2006|19:02] C:\Program Files\excel
[14.02.2009|10:39] C:\Program Files\Fichiers communs
[14.07.2008|16:43] C:\Program Files\GameSpy Arcade
[14.07.2008|16:36] C:\Program Files\Google
[02.06.2008|14:10] C:\Program Files\GXTranscoderv5
[04.03.2007|17:20] C:\Program Files\Infogrames
[20.12.2008|17:52] C:\Program Files\InstallShield Installation Information
[15.05.2006|08:56] C:\Program Files\Intel
[12.12.2008|03:02] C:\Program Files\Internet Explorer
[01.01.2009|12:42] C:\Program Files\iPod
[01.01.2009|12:42] C:\Program Files\iTunes
[25.01.2009|19:11] C:\Program Files\KaraFun
[14.02.2009|10:11] C:\Program Files\Malwarebytes' Anti-Malware
[27.12.2008|14:19] C:\Program Files\Messenger
[10.05.2007|02:01] C:\Program Files\Microsoft CAPICOM 2.1.0.2
[16.07.2007|19:27] C:\Program Files\microsoft frontpage
[02.06.2006|16:50] C:\Program Files\Microsoft Games
[12.09.2008|15:04] C:\Program Files\Microsoft SQL Server Compact Edition
[27.12.2008|14:15] C:\Program Files\Movie Maker
[25.01.2009|19:11] C:\Program Files\Mozilla Firefox
[15.05.2006|08:32] C:\Program Files\MSN
[15.05.2006|08:32] C:\Program Files\MSN Gaming Zone
[11.02.2009|08:21] C:\Program Files\MSN Messenger
[16.11.2006|03:00] C:\Program Files\MSXML 4.0
[17.09.2006|14:50] C:\Program Files\Nero
[27.12.2008|14:12] C:\Program Files\NetMeeting
[25.01.2009|19:19] C:\Program Files\Norton Internet Security
[25.01.2009|19:22] C:\Program Files\Norton Support
[25.01.2009|19:18] C:\Program Files\NortonInstaller
[08.07.2008|15:08] C:\Program Files\Nuance
[15.05.2006|08:34] C:\Program Files\Online Services
[23.07.2008|17:13] C:\Program Files\Online_TV
[30.10.2006|20:20] C:\Program Files\OpenOffice.org 2.0
[13.05.2008|13:37] C:\Program Files\Orange Shark
[27.12.2008|14:12] C:\Program Files\Outlook Express
[04.11.2007|13:46] C:\Program Files\PC Connectivity Solution
[02.06.2008|13:50] C:\Program Files\Philips
[27.06.2006|19:01] C:\Program Files\power point
[01.01.2009|12:40] C:\Program Files\QuickTime
[29.03.2007|17:18] C:\Program Files\Real
[08.11.2008|22:34] C:\Program Files\Red Kawa
[08.07.2008|15:06] C:\Program Files\ScanSoft
[15.05.2006|08:36] C:\Program Files\Services en ligne
[25.01.2009|19:19] C:\Program Files\Symantec
[14.02.2009|10:52] C:\Program Files\Trend Micro
[20.05.2008|14:26] C:\Program Files\Uninstall Information
[08.11.2008|22:30] C:\Program Files\VideoraiPodConverter
[16.11.2006|21:57] C:\Program Files\WinASPI
[15.09.2008|02:01] C:\Program Files\Windows Live
[30.11.2007|03:01] C:\Program Files\Windows Live Toolbar
[14.02.2007|00:15] C:\Program Files\Windows Media Player
[27.12.2008|14:12] C:\Program Files\Windows NT
[15.05.2006|08:34] C:\Program Files\Windows Plus
[25.01.2009|19:19] C:\Program Files\Windows Sidebar
[15.05.2006|08:36] C:\Program Files\WindowsUpdate
[15.05.2006|08:38] C:\Program Files\xerox
[28.07.2008|11:44] C:\Program Files\Yahoo!
[12.09.2008|14:44] C:\Program Files\Yontoo Layers Client for Internet Explorer
[21.01.2007|10:43] C:\Program Files\Zero G Registry

--------------------\\ Listing des dossiers dans C:\Program Files\Fichiers communs

[15.05.2008|09:37] C:\Program Files\Fichiers communs\Adobe
[21.10.2006|12:20] C:\Program Files\Fichiers communs\Ahead
[01.01.2009|12:42] C:\Program Files\Fichiers communs\Apple
[13.05.2008|10:40] C:\Program Files\Fichiers communs\InstallShield
[08.05.2008|07:09] C:\Program Files\Fichiers communs\Microsoft Shared
[15.05.2006|08:36] C:\Program Files\Fichiers communs\MSSoap
[15.05.2006|10:25] C:\Program Files\Fichiers communs\ODBC
[27.08.2006|16:09] C:\Program Files\Fichiers communs\Real
[14.02.2009|10:39] C:\Program Files\Fichiers communs\Scanner
[08.07.2008|15:07] C:\Program Files\Fichiers communs\ScanSoft Shared
[15.05.2006|08:36] C:\Program Files\Fichiers communs\Services
[15.05.2006|10:25] C:\Program Files\Fichiers communs\SpeechEngines
[25.01.2009|19:23] C:\Program Files\Fichiers communs\Symantec Shared
[27.12.2008|14:12] C:\Program Files\Fichiers communs\System
[12.09.2008|15:03] C:\Program Files\Fichiers communs\WindowsLiveInstaller
[27.08.2006|16:09] C:\Program Files\Fichiers communs\xing shared

--------------------\\ Process

( 50 Processes )

... OK !

--------------------\\ Recherche avec S_Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Recherche de Fichiers / Dossiers Lop

Aucun fichier / dossier Lop trouvé !

--------------------\\ Verification du Registre

..... OK !

--------------------\\ Verification du fichier Hosts

Fichier Hosts PROPRE


--------------------\\ Recherche de fichiers avec Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-15 10:20:07
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 5

--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !

[F:18][D:3]-> C:\DOCUME~1\Gilbert\LOCALS~1\Temp
[F:136][D:0]-> C:\DOCUME~1\Gilbert\Cookies
[F:7916][D:20]-> C:\DOCUME~1\Gilbert\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - 14.02.2009|17:08 - Option : [1]
2 - "C:\Lop SD\LopR_2.txt" - 15.02.2009|10:23 - Option : [2]

--------------------\\ Fin du rapport a 10:23:34
je fais la suite....
0
Malwarebytes' Anti-Malware 1.34
Version de la base de données: 1761
Windows 5.1.2600 Service Pack 3

15.02.2009 11:46:19
mbam-log-2009-02-15 (11-46-19).txt

Type de recherche: Examen complet (C:\|)
Eléments examinés: 174702
Temps écoulé: 1 hour(s), 16 minute(s), 21 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 0

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
(Aucun élément nuisible détecté)


puis la suite....
0
et le combo fix......je veux bien essayer avec avast, mais vu que j'ai payé norton ca m'embete un peu de devoir le désinstaller, et petite question bête.....comment starter l'antivirus au démarage du pc???

ComboFix 09-02-14.01 - Gilbert 2009-02-15 11:56:10.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.3.1252.33.1036.18.2046.1296 [GMT 1:00]
Lancé depuis: c:\documents and settings\Gilbert\Bureau\ComboFix.exe
AV: Norton Internet Security *On-access scanning disabled* (Updated)
FW: Norton Internet Security *enabled*
* Un nouveau point de restauration a été créé
.

((((((((((((((((((((((((((((( Fichiers créés du 2009-01-15 au 2009-02-15 ))))))))))))))))))))))))))))))))))))
.

2009-02-14 17:04 . 2009-02-15 10:23 <REP> d-------- C:\Lop SD
2009-02-14 10:52 . 2009-02-14 10:52 <REP> d-------- c:\program files\Trend Micro
2009-02-14 10:39 . 2009-02-14 10:39 <REP> d-------- c:\program files\Fichiers communs\Scanner
2009-02-14 10:38 . 2009-02-14 10:43 <REP> d-------- c:\program files\CA Yahoo! Anti-Spy
2009-02-08 20:00 . 2009-02-08 20:00 <REP> d-------- c:\documents and settings\Gilbert\Application Data\Malwarebytes
2009-02-08 20:00 . 2009-02-08 20:00 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-02-08 20:00 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-02-08 20:00 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-02-08 19:59 . 2009-02-14 10:11 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-02-08 19:44 . 2009-02-08 19:44 <REP> d-------- C:\VundoFix Backups
2009-02-08 18:56 . 2009-02-08 18:57 120 ---hs---- c:\windows\system32\ivdkkaep.tmp
2009-01-25 19:22 . 2009-01-25 19:22 <REP> dr------- c:\program files\Norton Support
2009-01-25 19:21 . 2009-01-25 19:19 36,272 -ra------ c:\windows\system32\drivers\SymIM.sys
2009-01-25 19:19 . 2009-01-25 19:19 <REP> d-------- c:\windows\system32\drivers\NIS
2009-01-25 19:19 . 2009-01-25 19:19 <REP> d-------- c:\program files\Windows Sidebar
2009-01-25 19:19 . 2009-01-25 19:19 <REP> d-------- c:\program files\Symantec
2009-01-25 19:19 . 2009-01-25 19:19 <REP> d-------- c:\program files\Norton Internet Security
2009-01-25 19:19 . 2009-01-25 19:19 124,464 --a------ c:\windows\system32\drivers\SYMEVENT.SYS
2009-01-25 19:19 . 2009-01-25 19:19 60,808 --a------ c:\windows\system32\S32EVNT1.DLL
2009-01-25 19:19 . 2009-01-25 19:19 10,635 --a------ c:\windows\system32\drivers\SYMEVENT.CAT
2009-01-25 19:19 . 2009-01-25 19:19 806 --a------ c:\windows\system32\drivers\SYMEVENT.INF
2009-01-25 19:18 . 2009-01-25 19:18 <REP> d-------- c:\program files\NortonInstaller
2009-01-25 19:12 . 2009-01-25 19:12 <REP> d-------- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-01-25 19:12 . 2009-01-25 19:19 <REP> d-------- c:\documents and settings\All Users\Application Data\Norton
2009-01-25 19:11 . 2009-01-25 19:11 173 --a------ c:\windows\wininit.ini
2009-01-25 19:10 . 2009-01-25 19:10 <REP> d-------- c:\documents and settings\All Users\Symantec Temporary Files
2009-01-25 13:00 . 2009-01-25 13:00 406 --a------ C:\ve.exe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-02-11 12:51 --------- d-----w c:\program files\eMule
2009-02-11 07:21 --------- d-----w c:\program files\MSN Messenger
2009-01-25 18:23 --------- d-----w c:\program files\Fichiers communs\Symantec Shared
2009-01-25 18:22 --------- d-----w c:\documents and settings\All Users\Application Data\Symantec
2009-01-25 18:13 --------- d-----w c:\program files\EPSON
2009-01-25 18:13 --------- d-----w c:\documents and settings\All Users\Application Data\EPSON
2009-01-25 18:11 --------- d-----w c:\program files\KaraFun
2009-01-25 10:52 --------- d-----w c:\documents and settings\Gilbert\Application Data\OpenOffice.org2
2009-01-19 08:52 --------- d-----w c:\documents and settings\All Users\Application Data\Tarma Installer
2009-01-01 11:42 --------- d-----w c:\program files\iTunes
2009-01-01 11:42 --------- d-----w c:\program files\iPod
2009-01-01 11:42 --------- d-----w c:\program files\Fichiers communs\Apple
2009-01-01 11:42 --------- d-----w c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2009-01-01 11:40 --------- d-----w c:\program files\QuickTime
2009-01-01 11:40 --------- d-----w c:\program files\Bonjour
2008-12-20 16:52 --------- d--h--w c:\program files\InstallShield Installation Information
2006-07-23 18:32 4,677,596 ----a-w c:\program files\eMule0.47a-Installer.exe
2006-07-04 15:27 37,518,744 ----a-w c:\program files\iTunesSetup.exe
2006-06-27 18:01 9,977 ----a-w c:\program files\power point.zip
2008-08-27 08:24 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
.

((((((((((((((((((((((((((((( SnapShot@2009-02-08_21.00.08.29 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-02-14 17:06:40 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_360.dat
.
((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}]
2008-08-21 06:54 192448 --------- c:\program files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-09-08 68856]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-05 64512]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2005-07-08 7110656]
"TkBellExe"="c:\program files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-08-27 180269]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-08-27 29744]
"SSBkgdUpdate"="c:\program files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2007-01-29 30248]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2007-01-29 46632]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 255528]
"BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd.exe" [2007-03-12 663552]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2007-01-26 65536]
"VideoraiPodConverter"="c:\documents and settings\Gilbert\Bureau\VideoraiPodConverter\VideoraiPodConverter.exe" [2005-11-11 483328]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"CTHelper"="CTHELPER.EXE" [2005-10-29 c:\windows\CTHELPER.EXE]
"CTxfiHlp"="CTXFIHLP.EXE" [2005-10-29 c:\windows\system32\CTXFIHLP.EXE]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2006-10-17 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.dvsd"= pdvcodec.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Bluewin\\Netopia_Router\\Wizard\\NetAgentBW.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=

R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1002000.007\SymEFA.sys [2009-01-25 309296]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\NIS\1002000.007\BHDrvx86.sys [2009-01-25 255536]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1002000.007\cchpx86.sys [2009-01-25 362544]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090206.001\IDSxpx86.sys [2009-02-11 276344]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe [2009-01-25 115560]
R3 camvid20;Philips ToUcam Camera; Video;c:\windows\system32\drivers\camdrv21.sys [2008-06-04 223232]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Fichiers communs\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-01-26 99376]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2009-02-08 38496]
S3 GoogleDesktopManager-061008-081103;Google Desktop Manager 5.7.806.10245;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-09-06 29744]

--- Autres Services/Pilotes en mémoire ---

*NewlyCreated* - MBAMSWISSARMY
.
Contenu du dossier 'Tâches planifiées'

2009-02-12 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]

2009-02-15 c:\windows\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 11:20]
.
.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.ch/
uSearchMigratedDefaultUrl = hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZJxdm002YYCH&fl=0&ptb=W963AXNIG.Rc.vqwMYayFQ&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&st=sb&searchfor={searchTerms}
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = https://blueadit.bluewin.ch/adsl/router/index_f.html
uInternet Settings,ProxyOverride = *.local
IE: &Windows Live Search - c:\program files\Windows Live Toolbar\msntb.dll/search.htm
IE: Ouvrir dans un nouvel onglet d'arrière-plan - c:\program files\Windows Live Toolbar\Components\fr-ch\msntabres.dll.mui/229?ab265c967b2a4e61a486609fec3bd1c1
IE: Ouvrir dans un nouvel onglet de premier plan - c:\program files\Windows Live Toolbar\Components\fr-ch\msntabres.dll.mui/230?ab265c967b2a4e61a486609fec3bd1c1
Handler: symres - {AA1061FE-6C41-421f-9344-69640C9732AB} - c:\program files\Norton Internet Security\Engine\16.2.0.7\CoIEPlg.dll
DPF: {104B0A37-AB99-4F06-8032-8BBDC3B77DDB} - hxxp://www2.photoweb.fr/telechargement/Photoweb_uploader.cab
DPF: {BB75AB3B-C666-4CAC-B22A-83C5A7DCCA77} - hxxps://www.fujifilm.ch/fujifilmshop/plugins/activexupload/FFCHUploadX.cab
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-15 12:00:39
Windows 5.1.2600 Service Pack 3 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\16.2.0.7\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Engine\16.2.0.7\diMaster.dll\" /prefetch:1"
.
Heure de fin: 2009-02-15 12:04:28
ComboFix-quarantined-files.txt 2009-02-15 11:03:39
ComboFix2.txt 2009-02-14 09:09:55
ComboFix3.txt 2009-02-08 20:01:15

Avant-CF: 49'993'240'576 octets libres
Après-CF: 50,274,852,864 octets libres

166 --- E O F --- 2009-01-14 02:02:32
merci a tous
0
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
15 févr. 2009 à 22:34
analyse ce fichiers sur virus total et si infecté tu le vire: https://www.virustotal.com/gui/

c:\windows\system32\ivdkkaep.tmp


_ç____________________


mettre à jour adobe reader
https://acrobat.adobe.com/fr/fr/acrobat/pdf-reader.html

_______________________


Télécharge ToolsCleaner sur ton bureau.
--> http://www.commentcamarche.net/telecharger/telecharger 34055291 toolscleaner
# Clique sur Recherche et laisse le scan agir ...
# Clique sur Suppression pour finaliser.
# Tu peux, si tu le souhaites, te servir des Options facultatives.
# Clique sur Quitter pour obtenir le rapport.
# Poste le rapport (TCleaner.txt) qui se trouve à la racine de ton disque dur (C:\).

_______________________


désactive ta restauration puis redémarre ton ordi puis réactive la pour virer les infections qui seraient dedans
https://www.informatruc.com


_______________________


encore des infections vundo trouvées? colle un rapport norton
0