Bonjour,
J'ai le même problème que kevin596 de pubs intempestives. J'avais la barre d'outils bizarre qui était mise mais j'ai réussi à l'enlever avec les deux programmes ci dessous.
J'ai téléchargé rogue remover puis smitfraud fix
J'ai lancé c'est deux là puis j'ai téléchargé combofix et j'ai le rapport d'erreur mais je ne sais pas maintenant quels sont les éléments à mettre dans un message texte pour eliminer les problèmes. C'est un peu du chinois pour moi ce rapport, je suis complètement novice en la matière. Pourriez vous m'aider, voici le rapport combofix. D'avance merci.
ComboFix 08-07-03.5 - user 2008-07-05 12:26:52.4 - NTFSx86
Microsoft Windows XP Édition familiale 5.1.2600.2.1252.33.1036.18.577 [GMT 2:00]
Endroit: C:\Documents and Settings\user\Bureau\ComboFix.exe
* Resident AV is active
[color=red][b]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !!/b/color
.
(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
---- Previous Run -------
.
C:\WINDOWS\cookies.ini
C:\WINDOWS\system32\byXNhExw.dll
C:\WINDOWS\system32\cJQsYJlm.ini
C:\WINDOWS\system32\cJQsYJlm.ini2
C:\WINDOWS\system32\dfxqxxqp.ini
C:\WINDOWS\system32\lxpybgsl.ini
C:\WINDOWS\system32\mlJYsQJc.dll
C:\WINDOWS\system32\wxEhNXyb.ini
C:\WINDOWS\system32\wxEhNXyb.ini2
.
((((((((((((((((((((((((((((( Fichiers créés 2008-06-05 to 2008-07-05 ))))))))))))))))))))))))))))))))))))
.
2008-07-05 11:52 . 2008-07-05 11:52 88,576 --a------ C:\WINDOWS\system32\lsgbypxl.dll
2008-07-05 11:51 . 2008-07-05 11:51 <REP> d----c--- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-07-05 11:49 . 2008-07-05 11:51 <REP> d-------- C:\Program Files\CCleaner
2008-07-05 10:41 . 2008-07-05 10:41 88,576 --a------ C:\WINDOWS\system32\pqxxqxfd.dll
2008-07-04 02:28 . 2008-07-04 11:21 <REP> d-a--c--- C:\Documents and Settings\All Users\Application Data\TEMP
2008-07-04 01:16 . 2008-07-05 12:09 1,410 --a------ C:\WINDOWS\system32\tmp.reg
2008-07-04 01:08 . 2008-07-04 01:12 <REP> d-------- C:\Program Files\RogueRemover FREE
2008-07-03 14:22 . 2008-07-03 14:22 28,800 --a------ C:\WINDOWS\system32\qoMeCVoo.dll
2008-07-03 14:21 . 2008-07-03 14:21 28,800 --a------ C:\WINDOWS\system32\pmnoOIxv.dll
2008-06-24 22:49 . 2008-06-24 22:49 <REP> d-------- C:\Documents and Settings\user\Application Data\Ordigramme
2008-06-24 20:34 . 2008-07-05 12:31 81,984 --a------ C:\WINDOWS\system32\bdod.bin
2008-06-11 21:51 . 2008-06-14 19:59 272,768 --------- C:\WINDOWS\system32\drivers\bthport.sys
2008-06-11 21:51 . 2008-06-14 19:59 272,768 -----c--- C:\WINDOWS\system32\dllcache\bthport.sys
2008-06-09 14:22 . 2008-06-29 10:07 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-06-09 14:22 . 2008-06-09 14:22 1,409 --a------ C:\WINDOWS\QTFont.for
.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-07-05 09:49 --------- d-----w C:\Program Files\Yahoo!
2008-07-05 08:38 --------- d-----w C:\Program Files\Windows Live Safety Center
2008-07-04 09:41 --------- d-----w C:\Program Files\DivX
2008-07-03 11:17 --------- d-----w C:\Documents and Settings\user\Application Data\U3
2008-06-30 21:25 --------- d-----w C:\Documents and Settings\user\Application Data\Image Zone Express
2008-06-24 20:49 --------- d-----w C:\Program Files\eBayCenter
2008-06-24 18:30 86,792 ----a-w C:\WINDOWS\system32\drivers\bdfndisf.sys
2008-06-07 15:55 --------- d-----w C:\Documents and Settings\user\Application Data\DVD Flick
2008-05-28 10:45 99,264 ----a-w C:\WINDOWS\system32\drivers\AnyDVD.sys
2008-05-25 13:12 --------- d-----w C:\Program Files\vso
2008-05-25 12:43 --------- d-----w C:\Documents and Settings\user\Application Data\Vso
2008-05-25 12:38 --------- d-----w C:\Program Files\MediaCoder
2008-05-23 08:21 244 ------w C:\Program Files\Key.AnyDVD
2008-05-20 20:03 --------- d-----w C:\Program Files\Fichiers communs\Adobe
2008-05-20 16:22 --------- d-----w C:\Documents and Settings\user\Application Data\AdobeUM
2008-05-08 12:28 202,752 ----a-w C:\WINDOWS\system32\drivers\rmcast.sys
2008-05-07 05:15 1,293,824 ----a-w C:\WINDOWS\system32\quartz.dll
2008-05-02 15:53 71,721 ----a-w C:\Program Files\unstopcp.zip
2008-04-23 04:16 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-04-19 10:51 77,824 ----a-w C:\WINDOWS\system32\xcomm.dll
2007-08-09 11:34 47,360 ----a-w C:\Documents and Settings\user\Application Data\pcouffin.sys
2006-09-17 11:53 81,920 ----a-w C:\Documents and Settings\user\Application Data\ezpinst.exe
2005-09-01 09:34 1,312,392 ----a-w C:\Program Files\NPSWF32.dll
2006-10-23 11:41 88 --sh--r C:\WINDOWS\system32\45C086AF4B.sys
2006-10-23 11:41 3,350 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-07-04_13.43.08.48 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-04 11:34:20 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-07-05 10:23:37 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-07-04 10:59:56 53,608 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-07-05 10:28:02 53,608 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-07-04 10:59:56 64,492 ----a-w C:\WINDOWS\system32\perfc00C.dat
+ 2008-07-05 10:28:02 64,492 ----a-w C:\WINDOWS\system32\perfc00C.dat
- 2008-07-04 10:59:56 383,254 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-07-05 10:28:02 383,254 ----a-w C:\WINDOWS\system32\perfh009.dat
- 2008-07-04 10:59:56 447,772 ----a-w C:\WINDOWS\system32\perfh00C.dat
+ 2008-07-05 10:28:02 447,772 ----a-w C:\WINDOWS\system32\perfh00C.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{5D72C2A4-9AC6-4727-A705-CEA1F0220B78}]
2008-07-03 14:21 28800 --a------ C:\WINDOWS\system32\pmnoOIxv.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 14:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 19:58 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2006-10-30 10:36 256576]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43 83608]
C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
D‚marrage rapide du logiciel HP Image Zone.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2004-11-04 19:50:52 53248]
eBayCenter.lnk - C:\Program Files\eBayCenter\ebaycenter.exe [2008-04-25 01:25:50 269144]
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-11 23:23:26 282624]
Lancement rapide d'Adobe Reader.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 03:38:16 29696]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5D72C2A4-9AC6-4727-A705-CEA1F0220B78}"= "C:\WINDOWS\system32\pmnoOIxv.dll" [2008-07-03 14:21 28800]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnoOIxv]
2008-07-03 14:21 28800 C:\WINDOWS\system32\pmnoOIxv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.XVID"= xvid.dll
"VIDC.HFYU"= huffyuv.dll
"msacm.l3codec"= L3codecp.acm
"VIDC.VP40"= vp4vfw.dll
"vidc.yv12"= yv12vfw.dll
"vidc.DIV3"= DivXc32.dll
"vidc.DIV4"= DivXc32f.dll
"msacm.divxa32"= DivXa32.acm
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^G DATA Firewall Tray.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\G DATA Firewall Tray.lnk
backup=C:\WINDOWS\pss\G DATA Firewall Tray.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"GDFwSvc"=3 (0x3)
"AVKWCtl"=2 (0x2)
"AVKService"=2 (0x2)
"AVKProxy"=2 (0x2)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"H/PC Connection Agent"="C:\Program Files\Microsoft ActiveSync\wcescomm.exe"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\support.com\\bin\\tgcmd.exe"=
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe"= C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe"= C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe"= C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"C:\\WINDOWS\\pchealth\\helpctr\\binaries\\HelpCtr.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"C:\\Program Files\\MSN Messenger\\msnmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R0 DVDRM;DVDRM;C:\WINDOWS\system32\drivers\dvdrm.sys [2004-10-16 23:19]
R2 MSCamSvc;MSCamSvc;"C:\Program Files\Microsoft LifeCam\MSCamS32.exe" [2006-10-13 18:01]
R2 UxTuneUp;Extension de conception TuneUp;C:\WINDOWS\System32\svchost.exe [2004-08-05 14:00]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;C:\WINDOWS\system32\DRIVERS\bdfndisf.sys [2008-06-24 20:30]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
\Shell\AutoRun\command - I:\LaunchU3.exe -a
.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-07-02 19:50:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-06-21 00:10:13 C:\WINDOWS\Tasks\Maintenance en 1 clic.job"
- C:\Program Files\TuneUp Utilities 2006\SystemOptimizer.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-05 12:29:21
Windows 5.1.2600 Service Pack 2 NTFS
Balayage processus cachés ...
Balayage caché autostart entries ...
Balayage des fichiers cachés ...
Scan terminé avec succès
Les fichiers cachés: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\bdfsfltr]
"ImagePath"=hex:73,00,79,00,73,00,74,00,65,00,6d,00,33,00,32,00,5c,00,44,00,52,\
.
--------------------- DLLs a chargé sous des processus courants ---------------------
PROCESS: C:\WINDOWS\system32\winlogon.exe
-> C:\WINDOWS\system32\pmnoOIxv.dll
.
Temps d'accomplissement: 2008-07-05 12:33:42
ComboFix-quarantined-files.txt 2008-07-05 10:33:36
ComboFix2.txt 2008-07-04 11:43:47
Pre-Run: 9,611,993,088 octets libres
Post-Run: 9,598,271,488 octets libres
192 --- E O F --- 2008-06-21 00:11:25
Configuration: Windows XP Internet Explorer 7.0
