infecte virus Tojan.Vundo - Sécurité - Virus
TomsGuide.com : 700 000 inscrits répondent à toutes vos questions high-tech et informatique.
Pour obtenir de l'aide, inscrivez-vous gratuitement !
 




Mot :   Pseudo :  
 
Bas de page
Auteur
 Sujet : infecte virus Tojan.Vundo
 
Profil : IDNaute
Plus d'informations

Bonjour,

Je suis moi aussi infecté par le virus Trojan.Vundo, et j'aimerai bien m'en debarasser...

Est-ce qu'une ame charitable pourrait m'aider ?

Merci d'avance


rapport vundofix

VundoFix V7.0.3

Scan started at 14:58:48 15/03/2008

Listing files found while scanning....

C:\WINDOWS\system32\nscB.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\nscB.dll
C:\WINDOWS\system32\nscB.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V7.0.3

Scan started at 15:25:59 17/03/2008

Listing files found while scanning....

No infected files were found.


Beginning removal...



rapport VBG.TXT
[03/17/2008, 16:08:15] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Sébastien\Mes documents\Séb\VirtumundoBeGone.exe" )
[03/17/2008, 16:08:25] - Detected System Information:
[03/17/2008, 16:08:25] - Windows Version: 5.1.2600, Service Pack 2
[03/17/2008, 16:08:25] - Current Username: Sébastien (Admin)
[03/17/2008, 16:08:25] - Windows is in NORMAL mode.
[03/17/2008, 16:08:25] - Searching for Browser Helper Objects:
[03/17/2008, 16:08:25] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[03/17/2008, 16:08:25] - BHO 2: {40B48F81-FA67-41CB-8B6C-786EDFAB6E96} ()
[03/17/2008, 16:08:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/17/2008, 16:08:25] - Checking for HKLM\...\Winlogon\Notify\lanuta89104
[03/17/2008, 16:08:25] - Key not found: HKLM\...\Winlogon\Notify\lanuta89104, continuing.
[03/17/2008, 16:08:25] - BHO 3: {43FC67B6-4C25-4afd-AE7A-9EF3E4587026} (browser optimizer superiorads)
[03/17/2008, 16:08:25] - BHO 4: {733716E1-76D2-4003-AC39-845281C0EF85} (dcads)
[03/17/2008, 16:08:25] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[03/17/2008, 16:08:25] - BHO 6: {9a55a41a-443f-435f-9710-d5de31586790} ()
[03/17/2008, 16:08:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/17/2008, 16:08:25] - Checking for HKLM\...\Winlogon\Notify\jtpsyxfj
[03/17/2008, 16:08:25] - Key not found: HKLM\...\Winlogon\Notify\jtpsyxfj, continuing.
[03/17/2008, 16:08:25] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/17/2008, 16:08:25] - BHO 8: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[03/17/2008, 16:08:25] - BHO 9: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper)
[03/17/2008, 16:08:25] - BHO 10: {BDF3E430-B101-42AD-A544-FADC6B084872} (CNavExtBho Class)
[03/17/2008, 16:08:25] - BHO 11: {DDFA1356-E6ED-42a5-9D62-93211D424A90} (MySidesearch Search Assistant)
[03/17/2008, 16:08:25] - BHO 12: {E08DE81E-7E47-4777-84C5-C45DA13BCF91} ()
[03/17/2008, 16:08:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/17/2008, 16:08:25] - Checking for HKLM\...\Winlogon\Notify\nnnnkjj
[03/17/2008, 16:08:25] - Found: HKLM\...\Winlogon\Notify\nnnnkjj - This is probably Virtumundo.
[03/17/2008, 16:08:25] - Assigning {E08DE81E-7E47-4777-84C5-C45DA13BCF91} MSEvents Object
[03/17/2008, 16:08:25] - BHO list has been changed! Starting over...
[03/17/2008, 16:08:25] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[03/17/2008, 16:08:25] - BHO 2: {40B48F81-FA67-41CB-8B6C-786EDFAB6E96} ()
[03/17/2008, 16:08:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/17/2008, 16:08:25] - Checking for HKLM\...\Winlogon\Notify\lanuta89104
[03/17/2008, 16:08:25] - Key not found: HKLM\...\Winlogon\Notify\lanuta89104, continuing.
[03/17/2008, 16:08:25] - BHO 3: {43FC67B6-4C25-4afd-AE7A-9EF3E4587026} (browser optimizer superiorads)
[03/17/2008, 16:08:25] - BHO 4: {733716E1-76D2-4003-AC39-845281C0EF85} (dcads)
[03/17/2008, 16:08:25] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[03/17/2008, 16:08:25] - BHO 6: {9a55a41a-443f-435f-9710-d5de31586790} ()
[03/17/2008, 16:08:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/17/2008, 16:08:25] - Checking for HKLM\...\Winlogon\Notify\jtpsyxfj
[03/17/2008, 16:08:25] - Key not found: HKLM\...\Winlogon\Notify\jtpsyxfj, continuing.
[03/17/2008, 16:08:25] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/17/2008, 16:08:25] - BHO 8: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[03/17/2008, 16:08:25] - BHO 9: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper)
[03/17/2008, 16:08:25] - BHO 10: {BDF3E430-B101-42AD-A544-FADC6B084872} (CNavExtBho Class)
[03/17/2008, 16:08:25] - BHO 11: {DDFA1356-E6ED-42a5-9D62-93211D424A90} (MySidesearch Search Assistant)
[03/17/2008, 16:08:25] - BHO 12: {E08DE81E-7E47-4777-84C5-C45DA13BCF91} (MSEvents Object)
[03/17/2008, 16:08:25] - ALERT: Found MSEvents Object!
[03/17/2008, 16:08:25] - BHO 13: {FE0957CF-218A-459F-BA24-0DAB3AA9E8A4} ()
[03/17/2008, 16:08:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/17/2008, 16:08:25] - Checking for HKLM\...\Winlogon\Notify\mljge
[03/17/2008, 16:08:25] - Key not found: HKLM\...\Winlogon\Notify\mljge, continuing.
[03/17/2008, 16:08:25] - Finished Searching Browser Helper Objects
[03/17/2008, 16:08:25] - *** Detected MSEvents Object
[03/17/2008, 16:08:25] - Trying to remove MSEvents Object...
[03/17/2008, 16:08:26] - Terminating Process: IEXPLORE.EXE
[03/17/2008, 16:08:31] - Terminating Process: RUNDLL32.EXE
[03/17/2008, 16:08:34] - Disabling Automatic Shell Restart
[03/17/2008, 16:08:34] - Terminating Process: EXPLORER.EXE
[03/17/2008, 16:08:40] - Suspending the NT Session Manager System Service
[03/17/2008, 16:08:44] - Terminating Windows NT Logon/Logoff Manager
[03/17/2008, 16:08:45] - Re-enabling Automatic Shell Restart
[03/17/2008, 16:08:45] - File to disable: C:\WINDOWS\system32\nnnnkjj.dll
[03/17/2008, 16:08:45] - Removing HKLM\...\Browser Helper Objects\{E08DE81E-7E47-4777-84C5-C45DA13BCF91}
[03/17/2008, 16:08:47] - Removing HKCR\CLSID\{E08DE81E-7E47-4777-84C5-C45DA13BCF91}
[03/17/2008, 16:08:47] - Adding Kill Bit for ActiveX for GUID: {E08DE81E-7E47-4777-84C5-C45DA13BCF91}
[03/17/2008, 16:08:48] - Deleting ATLEvents/MSEvents Registry entries
[03/17/2008, 16:08:48] - Removing HKLM\...\Winlogon\Notify\nnnnkjj
[03/17/2008, 16:08:48] - Searching for Browser Helper Objects:
[03/17/2008, 16:08:48] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Aide pour le lien d'Adobe PDF Reader)
[03/17/2008, 16:08:48] - BHO 2: {40B48F81-FA67-41CB-8B6C-786EDFAB6E96} ()
[03/17/2008, 16:08:48] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/17/2008, 16:08:48] - Checking for HKLM\...\Winlogon\Notify\lanuta89104
[03/17/2008, 16:08:48] - Key not found: HKLM\...\Winlogon\Notify\lanuta89104, continuing.
[03/17/2008, 16:08:48] - BHO 3: {43FC67B6-4C25-4afd-AE7A-9EF3E4587026} (browser optimizer superiorads)
[03/17/2008, 16:08:48] - BHO 4: {733716E1-76D2-4003-AC39-845281C0EF85} (dcads)
[03/17/2008, 16:08:48] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[03/17/2008, 16:08:48] - BHO 6: {9a55a41a-443f-435f-9710-d5de31586790} ()
[03/17/2008, 16:08:48] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/17/2008, 16:08:48] - Checking for HKLM\...\Winlogon\Notify\jtpsyxfj
[03/17/2008, 16:08:48] - Key not found: HKLM\...\Winlogon\Notify\jtpsyxfj, continuing.
[03/17/2008, 16:08:48] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/17/2008, 16:08:48] - BHO 8: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[03/17/2008, 16:08:48] - BHO 9: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper)
[03/17/2008, 16:08:48] - BHO 10: {BDF3E430-B101-42AD-A544-FADC6B084872} (CNavExtBho Class)
[03/17/2008, 16:08:48] - BHO 11: {DDFA1356-E6ED-42a5-9D62-93211D424A90} (MySidesearch Search Assistant)
[03/17/2008, 16:08:48] - BHO 12: {FE0957CF-218A-459F-BA24-0DAB3AA9E8A4} ()
[03/17/2008, 16:08:48] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/17/2008, 16:08:48] - Checking for HKLM\...\Winlogon\Notify\mljge
[03/17/2008, 16:08:48] - Key not found: HKLM\...\Winlogon\Notify\mljge, continuing.
[03/17/2008, 16:08:48] - Finished Searching Browser Helper Objects
[03/17/2008, 16:08:48] - Finishing up...
[03/17/2008, 16:08:48] - A restart is needed.
[03/17/2008, 16:08:52] - Attempting to Restart via STOP error (Blue Screen!)

rapport HijackThis!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:37:54, on 17/03/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe
C:\windows\system32\jswnw64p.exe
C:\WINDOWS\system32\mcnttkwb.exe
C:\Program Files\Fichiers communs\NettoyeurDePC\stm.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
C:\Program Files\Roxio\GoBack\GBPoll.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\slserv.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\Program Files\Fichiers communs\DataViz\DvzIncMsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live Toolbar\msn_sl.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://home.neuf.fr/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {247F29DD-533A-4355-AC79-985547283716} - C:\WINDOWS\system32\mljge.dll
O2 - BHO: (no name) - {40B48F81-FA67-41CB-8B6C-786EDFAB6E96} - C:\Program Files\Internet Explorer\lanuta89104.dll
O2 - BHO: browser optimizer superiorads - {43FC67B6-4C25-4afd-AE7A-9EF3E4587026} - C:\WINDOWS\system32\sprt_ads.dll
O2 - BHO: dcads - {733716E1-76D2-4003-AC39-845281C0EF85} - C:\WINDOWS\system32\nscB.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: {09768513-ed5d-0179-f534-f344a14a55a9} - {9a55a41a-443f-435f-9710-d5de31586790} - C:\WINDOWS\system32\jtpsyxfj.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: MySidesearch Search Assistant - {DDFA1356-E6ED-42a5-9D62-93211D424A90} - C:\WINDOWS\system32\mysidesearch_sidebar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [{14-40-07-74-DW}] C:\windows\system32\jswnw64p.exe DWram
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\mcnttkwb.exe DWram
O4 - HKLM\..\Run: [Salestart] "C:\Program Files\Fichiers communs\NettoyeurDePC\stm.exe" dm=http://nettoyeurdepc.com ad=http://nettoyeurdepc.com sd=http://paylogs.nettoyeurdepc.com
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [spa_start] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\sprt_ads.dll" DllInit
O4 - HKLM\..\Run: [bm(1)] "C:\Program Files\Fichiers communs\VirusEffaceur\bm.exe" dm=http://viruseffaceur.com ad=http://viruseffaceur.com sd=http://gregistre.viruseffaceur.com
O4 - HKLM\..\Run: [a8e140db] rundll32.exe "C:\WINDOWS\system32\atgxldql.dll",b
O4 - HKLM\..\Run: [BMabd27347] Rundll32.exe "C:\WINDOWS\system32\bqeywyft.dll",s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Configuration de la neuf Box] C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [StopNetSend] C:\Documents and Settings\Sébastien\Mes documents\Séb\netsend.exe small
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\mcnttkwb.exe
O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\jswnw64p.exe
O4 - Startup: palmOne Registration.lnk = C:\Program Files\palmOne\register.exe
O4 - Global Startup: DataViz Inc Messenger.lnk = C:\Program Files\Fichiers communs\DataViz\DvzIncMsgr.exe
O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: LUMIX Simple Viewer.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.ya [...] 040510.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ [...] wflash.cab
O23 - Service: Boonty Games - BOONTY - C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Fichiers communs\EPSON\EBAPI\eEBSVC.exe
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Fichiers communs\EPSON\EBAPI\SAgent2.exe
O23 - Service: GBPoll - Roxio, Inc. - C:\Program Files\Roxio\GoBack\GBPoll.exe
O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

End of file - 12045 bytes

Liens sponsorisés


Inscrivez-vous ou connectez-vous pour masquer ceci.

Profil : Helper
Plus d'informations

Bonjour,

Désactive tes protections résidentes (antivirus, Spybot...) !

  • Télécharge Combofix (sUBs) sur ton Bureau.
  • Double clique sur combofix.exe afin de le lancer.
  • Tape sur la touche 1 (Yes) pour démarrer le scan.
  • Lorsque le scan sera complété, un rapport apparaîtra. Poste ce rapport dans ta prochaine réponse.


---------------
Prévention & Protection|Les logiciels gratuits|L'homme du FLCCF
Profil : IDNaute
Plus d'informations

Bonjour,
Voila le rapport, je n'ai plus le message d'alerte de norton (bon signe)

ComboFix 08-03-17.1 - Sébastien 2008-03-18 14:45:45.4 - NTFSx86
Endroit: C:\Documents and Settings\Sébastien\Mes documents\Séb\ComboFix.exe

[color=red]AVERTISSEMENT - LA CONSOLE DE RÉCUPÉRATION N'EST PAS INSTALLÉE SUR CETTE MACHINE !![/color]
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Sébastien\Application Data\urlredir.cfg
C:\Documents and Settings\Sébastien\Menu Démarrer\Programmes\Démarrage\Deewoo.lnk
C:\Documents and Settings\Sébastien\Menu Démarrer\Programmes\Démarrage\DW_Start.lnk
C:\WINDOWS\system32\msnav32.ax
.
---- Previous Run -------
.
C:\Program Files\Internet Explorer\lanuta89104.dll
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\sanR24
C:\Temp\sanR24\lDii.log
C:\WINDOWS\BMabd27347.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Fonts\-
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\atgxldql.dll
C:\WINDOWS\system32\bqeywyft.dll
C:\WINDOWS\system32\cfuorqto.dll
C:\WINDOWS\system32\egjlm.ini
C:\WINDOWS\system32\egjlm.ini2
C:\WINDOWS\system32\fboaljpq.dll
C:\WINDOWS\system32\fcvltapx.dll
C:\WINDOWS\system32\jtpsyxfj.dll
C:\WINDOWS\system32\lqdlxgta.ini
C:\WINDOWS\system32\mcnttkwb.exe
C:\WINDOWS\system32\mcnttkwd.exe
C:\WINDOWS\system32\mljge.dll
C:\WINDOWS\system32\msnav32.ax
C:\WINDOWS\system32\owvsgyun.dll
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\rev1
C:\WINDOWS\system32\rev1\dincomsdll3.exe
C:\WINDOWS\system32\sprt_ads.dll
C:\WINDOWS\system32\vabkxhij.dll
C:\WINDOWS\system32\vpwfculi.dll
C:\WINDOWS\system32\winpfz37.sys
C:\WINDOWS\system32\zxdnt3d.cfg
C:\x.dat
C:\z.dat

.
((((((((((((((((((((((((((((( Fichiers créés 2008-02-18 to 2008-03-18 ))))))))))))))))))))))))))))))))))))
.

2008-03-15 15:14 . 2008-03-15 15:14 24,576 --a------ C:\WINDOWS\system32\VundoFixSVC.exe
2008-03-15 14:58 . 2008-03-17 15:25 <REP> d-------- C:\VundoFix Backups
2008-03-15 14:21 . 2008-03-15 14:21 <REP> d-------- C:\Program Files\Trend Micro
2008-03-14 15:45 . 2008-03-14 15:45 40,730 --a------ C:\WINDOWS\system32\superiorads-uninst.exe
2008-03-14 14:44 . 2005-11-17 14:05 53,248 --a------ C:\WINDOWS\UpdtNv28.exe
2008-03-14 13:31 . 2008-03-14 13:31 32 --ahs---- C:\WINDOWS\system32\{C52C397B-F83C-4A7A-845C-8377348F152B}.dat
2008-03-14 13:31 . 2008-03-14 13:31 32 --ahs---- C:\WINDOWS\{BDEE1F5A-E078-4FB3-96B2-A425E96FAAEA}.dat
2008-03-14 13:26 . 2008-03-14 13:26 32 --ahs---- C:\WINDOWS\system32\{54A44583-CDBC-4F8A-AB4A-4A259B37B42C}.dat
2008-03-14 13:26 . 2008-03-14 13:26 32 --ahs---- C:\WINDOWS\{C79BFEF9-0FCC-4A6B-8A67-A9A48B6A561C}.dat
2008-03-14 13:21 . 2008-03-14 13:21 32 --ahs---- C:\WINDOWS\system32\{7F25D8A8-4A03-4F20-AEC2-E9AE79111D27}.dat
2008-03-14 13:21 . 2008-03-14 13:21 32 --ahs---- C:\WINDOWS\{9C3A4A3A-E801-41C7-8C6E-8938DA05758F}.dat
2008-03-14 13:17 . 2002-08-14 06:03 34,578 --a------ C:\WINDOWS\system32\drivers\NPDRIVER.SYS
2008-03-14 13:17 . 2002-08-14 06:03 31,744 --a------ C:\WINDOWS\system32\S32STAT.DLL
2008-03-14 13:16 . 2006-08-25 16:51 617,472 --a------ C:\WINDOWS\system32\COMCTL32.NU7
2008-03-14 13:11 . 2002-08-13 17:00 94,208 --a------ C:\WINDOWS\system32\qdcsinet.dll
2008-03-14 13:11 . 2002-08-13 17:00 86,016 --a------ C:\WINDOWS\system32\apitrap.dll
2008-03-14 13:09 . 1998-06-24 00:00 609,584 --a------ C:\WINDOWS\system32\COMCTL32.OCX
2008-03-14 13:09 . 1998-06-26 00:00 89,600 --a------ C:\WINDOWS\system32\MSCAL.OCX
2008-03-14 12:53 . 2008-03-14 12:53 <REP> d-------- C:\Program Files\Roxio
2008-03-14 12:53 . 2002-01-21 12:36 156,301 --a------ C:\WINDOWS\system32\drivers\GoBack2K.sys
2008-03-14 12:53 . 2002-01-21 12:37 15,024 --a------ C:\WINDOWS\system32\drivers\GBFSHook.sys
2008-03-14 12:53 . 2002-01-21 12:37 3,945 --a------ C:\WINDOWS\system32\drivers\GBDevice.sys
2008-03-14 12:52 . 2008-03-14 12:52 32 --ahs---- C:\WINDOWS\system32\{B9169E37-C31E-4F68-9B47-E0D2526DAEFE}.dat
2008-03-14 12:52 . 2008-03-14 12:52 32 --ahs---- C:\WINDOWS\{67355712-61A7-43BD-82C7-1764C5FB6820}.dat
2008-03-14 12:51 . 2008-03-14 12:51 14 --a------ C:\WINDOWS\system32\SR2.dat
2008-03-14 12:50 . 2008-03-14 17:30 <REP> d-------- C:\Program Files\Norton SystemWorks
2008-03-14 12:50 . 2008-03-14 13:11 <REP> d-------- C:\Documents and Settings\Sébastien\Application Data\Symantec
2008-03-14 12:50 . 2002-08-28 16:41 123,619 --a------ C:\WINDOWS\system32\SYMEVNT.386
2008-03-14 12:50 . 2002-08-28 16:41 83,672 --a------ C:\WINDOWS\system32\S32EVNT1.DLL
2008-03-14 12:50 . 2002-08-28 16:41 73,224 --a------ C:\WINDOWS\system32\drivers\SYMEVENT.SYS
2008-03-14 12:49 . 2008-03-14 13:21 <REP> d-------- C:\Program Files\Symantec
2008-03-14 12:49 . 2008-03-14 12:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-14 12:47 . 2008-03-18 13:41 <REP> d-------- C:\Program Files\Fichiers communs\Symantec Shared
2008-03-14 10:37 . 2008-03-15 10:37 1,367,103 ---hs---- C:\WINDOWS\system32\ptkrqnuv.ini
2008-03-14 09:54 . 2008-03-14 09:54 <REP> d-------- C:\Program Files\Kaspersky Lab
2008-03-12 21:30 . 2008-03-12 21:30 206 --a------ C:\WINDOWS\system32\MRT.INI
2008-03-11 14:45 . 2008-03-11 14:45 339,968 --a------ C:\WINDOWS\system32\mysidesearch_sidebar.dll
2008-03-10 12:25 . 2008-03-10 12:25 <REP> d-------- C:\Program Files\CCleaner
2008-03-10 12:04 . 2008-03-10 12:04 <REP> d-------- C:\Documents and Settings\Sébastien\Application Data\NettoyeurDePC
2008-03-10 11:52 . 2008-03-10 11:52 <REP> d-------- C:\Program Files\Fichiers communs\NettoyeurDePC
2008-03-10 11:52 . 2008-03-10 11:52 <REP> dr------- C:\Documents and Settings\All Users\Application Data\SalesMon
2008-03-10 11:52 . 2008-03-10 11:52 <REP> d-------- C:\Documents and Settings\All Users\Application Data\NettoyeurDePC
2008-03-07 17:40 . 2008-03-07 17:40 49,170 --a------ C:\WINDOWS\system32\jswnw64p.exe
2008-03-02 19:46 . 2005-03-07 19:44 45,056 --a------ C:\WINDOWS\system32\PhDi2.sys
2008-03-02 19:45 . 2008-03-02 19:45 <REP> d-------- C:\Documents and Settings\Sébastien\Application Data\Panasonic
2008-03-02 19:44 . 2008-03-02 19:46 <REP> d-------- C:\Program Files\Panasonic
2008-03-02 19:43 . 2008-03-02 19:43 <REP> d-------- C:\Documents and Settings\Sébastien\Application Data\InstallShield
2008-02-29 11:28 . 2008-02-29 11:28 <REP> d-------- C:\Program Files\WinISO
2008-02-29 10:43 . 2008-02-29 11:50 <REP> d-------- C:\Program Files\Smart Projects
2008-02-27 16:31 . 2008-02-27 16:31 147,456 --a------ C:\WINDOWS\system32\vbzip10.dll
2008-02-27 16:29 . 2008-03-14 19:47 <REP> d-------- C:\WINDOWS\system32\fab3
2008-02-27 16:29 . 2008-02-27 16:29 <REP> d-------- C:\WINDOWS\system32\bmv4
2008-02-27 16:29 . 2008-02-27 16:29 <REP> d-------- C:\WINDOWS\system32\aux9
2008-02-27 16:29 . 2008-02-27 16:29 332,800 --a------ C:\WINDOWS\system\wget.exe
2008-02-27 16:29 . 2008-02-27 16:29 212,085 --a------ C:\Temp\txNog4220.exe
2008-02-27 16:29 . 2008-02-27 16:29 49,165 --a------ C:\WINDOWS\system32\rwwnw64d.exe
2008-02-27 16:29 . 2008-02-27 16:29 134 --a------ C:\n.bat
2008-02-27 16:28 . 2008-03-14 19:47 <REP> d-------- C:\WINDOWS\system32\iDlo18
2008-02-27 16:28 . 2008-02-27 16:28 2,268,319 --a------ C:\WINDOWS\system\wltrysvc.exe
2008-02-27 16:28 . 2008-02-27 16:28 2,268,319 --a------ C:\WINDOWS\system\lsass.exe
2008-02-27 16:28 . 2008-02-27 16:28 24,576 --a------ C:\WINDOWS\system\mdma.exe
2008-02-27 16:28 . 2008-02-27 16:28 24,576 --a------ C:\WINDOWS\system\kill.exe
2008-02-27 16:28 . 2008-02-27 16:28 24,576 --a------ C:\WINDOWS\system\alg.exe
2008-02-27 16:25 . 2008-02-27 16:25 32,768 --a------ C:\WINDOWS\winupd.exe
2008-02-27 15:41 . 2006-04-28 01:51 29,968 --a------ C:\WINDOWS\system32\mdimon.dll
2008-02-27 15:37 . 2008-02-27 15:37 <REP> d-------- C:\Program Files\MSBuild
2008-02-27 15:35 . 2008-02-27 15:35 <REP> d-------- C:\Program Files\Microsoft.NET
2008-02-27 15:35 . 2008-02-27 15:35 <REP> d-------- C:\Program Files\Microsoft Works
2008-02-27 15:30 . 2008-02-27 15:48 <REP> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-02-27 15:29 . 2008-02-27 15:29 <REP> dr-h----- C:\MSOCache
2008-02-20 12:38 . 2008-03-12 09:28 84,729 --a------ C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-17 15:08 6,206,976 ----a-w C:\WINDOWS\Internet Logs\xDB59.tmp
2008-03-17 15:08 2,785,280 ----a-w C:\WINDOWS\Internet Logs\xDB58.tmp
2008-03-15 11:48 17,695,135 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
2008-03-14 18:57 22 ----a-w C:\WINDOWS\Fonts\x.zip
2008-03-14 12:00 6,130,688 ----a-w C:\WINDOWS\Internet Logs\xDB57.tmp
2008-03-12 19:55 --------- d-----w C:\Documents and Settings\Sébastien\Application Data\LimeWire
2008-03-10 20:17 2,578,432 ----a-w C:\WINDOWS\Internet Logs\xDB56.tmp
2008-03-09 18:23 5,990,912 ----a-w C:\WINDOWS\Internet Logs\xDB55.tmp
2008-03-09 18:23 2,761,728 ----a-w C:\WINDOWS\Internet Logs\xDB54.tmp
2008-03-08 15:17 --------- d-----w C:\Program Files\Yahoo!
2008-03-08 15:17 --------- d-----w C:\Program Files\Common Files
2008-03-03 18:48 2,769,408 ----a-w C:\WINDOWS\Internet Logs\xDB53.tmp
2008-03-02 18:46 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-02-29 14:18 --------- d-----w C:\Program Files\eMule
2008-02-27 18:00 5,924,352 ----a-w C:\WINDOWS\Internet Logs\xDB51.tmp
2008-02-27 13:49 --------- d-----w C:\Program Files\LimeWire
2008-02-16 19:30 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-02-16 14:04 --------- d-----w C:\Program Files\Boilsoft Video Joiner
2008-02-09 16:25 --------- d-----w C:\Program Files\avijoin
2008-02-06 14:59 --------- d-----w C:\Documents and Settings\All Users\Application Data\WinZip
2008-02-05 09:38 --------- d-----w C:\Program Files\Fichiers communs\DirectX
2008-01-22 10:21 --------- d-----w C:\Program Files\ISO Commander
2008-01-04 22:35 5,624,320 ----a-w C:\WINDOWS\Internet Logs\xDB50.tmp
2007-12-15 14:03 22,336 ----a-w C:\Documents and Settings\Sébastien\Application Data\GDIPFONTCACHEV1.DAT
2007-05-08 11:09 85,752 ----a-w C:\WINDOWS\Internet Logs\vsmon_2nd_2007_05_07_23_52_43_small.dmp.zip
2007-05-07 21:52 758,784 ----a-w C:\WINDOWS\Internet Logs\xDB4F.tmp
2007-05-02 12:05 50,716 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_05_01_17_30_43_small.dmp.zip
2007-05-02 12:05 43,629 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_05_01_17_29_00_small.dmp.zip
2007-04-18 17:08 49,344 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_04_18_14_43_32_small.dmp.zip
2007-04-18 17:08 12,659,939 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_04_18_14_40_48_full.dmp.zip
2007-04-18 12:38 52,811 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_04_16_19_16_22_small.dmp.zip
2007-04-18 12:38 43,542 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_04_16_19_14_52_small.dmp.zip
2007-04-13 10:11 48,258 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_04_12_18_59_35_small.dmp.zip
2007-04-13 10:11 43,989 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_04_12_18_57_56_small.dmp.zip
2007-04-05 13:37 586,752 ----a-w C:\WINDOWS\Internet Logs\xDB4D.tmp
2007-04-05 13:37 4,001,792 ----a-w C:\WINDOWS\Internet Logs\xDB4E.tmp
2007-04-04 08:08 48,752 ----a-w C:\WINDOWS\Internet Logs\zlclient_2nd_2007_04_03_11_09_34_small.dmp.zip
2007-04-02 16:32 3,973,632 ----a-w C:\WINDOWS\Internet Logs\xDB4C.tmp
2007-03-19 20:50 3,944,448 ----a-w C:\WINDOWS\Internet Logs\xDB52.tmp
2007-03-19 20:50 3,944,448 ----a-w C:\WINDOWS\Internet Logs\xDB4B.tmp
2007-03-18 22:01 3,927,040 ----a-w C:\WINDOWS\Internet Logs\xDB4A.tmp
2007-03-15 21:58 48,128 ----a-w C:\WINDOWS\Internet Logs\xDB47.tmp
2007-03-15 21:58 3,931,648 ----a-w C:\WINDOWS\Internet Logs\xDB49.tmp
2007-03-14 21:34 89,088 ----a-w C:\WINDOWS\Internet Logs\xDB46.tmp
2007-03-08 23:18 110,080 ----a-w C:\WINDOWS\Internet Logs\xDB45.tmp
2007-03-02 18:24 3,907,072 ----a-w C:\WINDOWS\Internet Logs\xDB48.tmp
2007-03-02 18:24 3,907,072 ----a-w C:\WINDOWS\Internet Logs\xDB44.tmp
2007-03-02 18:24 1,141,248 ----a-w C:\WINDOWS\Internet Logs\xDB43.tmp
2007-03-01 17:31 3,905,536 ----a-w C:\WINDOWS\Internet Logs\xDB42.tmp
2007-02-28 16:42 3,905,024 ----a-w C:\WINDOWS\Internet Logs\xDB41.tmp
2007-02-23 21:26 3,926,016 ----a-w C:\WINDOWS\Internet Logs\xDB40.tmp
2007-02-20 18:00 3,898,880 ----a-w C:\WINDOWS\Internet Logs\xDB3F.tmp
2007-02-12 21:24 101,376 ----a-w C:\WINDOWS\Internet Logs\xDB3D.tmp
2007-02-06 14:40 44,032 ----a-w C:\WINDOWS\Internet Logs\xDB3C.tmp
2007-02-06 14:38 3,851,264 ----a-w C:\WINDOWS\Internet Logs\xDB3E.tmp
2007-02-05 12:42 29,696 ----a-w C:\WINDOWS\Internet Logs\xDB3B.tmp
2007-02-03 11:55 54,784 ----a-w C:\WINDOWS\Internet Logs\xDB39.tmp
2007-02-03 11:55 3,846,656 ----a-w C:\WINDOWS\Internet Logs\xDB3A.tmp
2007-02-01 22:06 87,040 ----a-w C:\WINDOWS\Internet Logs\xDB38.tmp
2007-01-29 13:10 9,216 ----a-w C:\WINDOWS\Internet Logs\xDB36.tmp
2007-01-29 13:09 92,160 ----a-w C:\WINDOWS\Internet Logs\xDB35.tmp
2007-01-29 13:09 3,839,488 ----a-w C:\WINDOWS\Internet Logs\xDB37.tmp
2007-01-26 23:19 50,176 ----a-w C:\WINDOWS\Internet Logs\xDB33.tmp
2007-01-26 23:19 3,837,952 ----a-w C:\WINDOWS\Internet Logs\xDB34.tmp
2007-01-25 22:30 9,216 ----a-w C:\WINDOWS\Internet Logs\xDB32.tmp
2007-01-25 22:28 44,032 ----a-w C:\WINDOWS\Internet Logs\xDB31.tmp
2007-01-24 21:58 79,872 ----a-w C:\WINDOWS\Internet Logs\xDB2F.tmp
2007-01-24 21:58 3,843,072 ----a-w C:\WINDOWS\Internet Logs\xDB30.tmp
2007-01-23 16:08 62,976 ----a-w C:\WINDOWS\Internet Logs\xDB2D.tmp
2007-01-23 16:08 3,838,976 ----a-w C:\WINDOWS\Internet Logs\xDB2E.tmp
2007-01-22 21:44 3,833,856 ----a-w C:\WINDOWS\Internet Logs\xDB2C.tmp
2007-01-22 15:18 34,816 ----a-w C:\WINDOWS\Internet Logs\xDB2A.tmp
2007-01-22 15:18 3,832,832 ----a-w C:\WINDOWS\Internet Logs\xDB2B.tmp
2007-01-21 11:15 51,712 ----a-w C:\WINDOWS\Internet Logs\xDB29.tmp
2007-01-19 16:37 90,112 ----a-w C:\WINDOWS\Internet Logs\xDB27.tmp
2007-01-19 16:37 3,830,784 ----a-w C:\WINDOWS\Internet Logs\xDB28.tmp
2007-01-16 15:45 43,008 ----a-w C:\WINDOWS\Internet Logs\xDB24.tmp
2007-01-16 15:45 3,828,736 ----a-w C:\WINDOWS\Internet Logs\xDB26.tmp
2007-01-14 20:40 43,520 ----a-w C:\WINDOWS\Internet Logs\xDB23.tmp
2007-01-14 20:40 3,840,512 ----a-w C:\WINDOWS\Internet Logs\xDB25.tmp
2007-01-13 17:50 9,216 ----a-w C:\WINDOWS\Internet Logs\xDB21.tmp
2007-01-13 17:49 76,288 ----a-w C:\WINDOWS\Internet Logs\xDB20.tmp
2007-01-13 17:49 3,824,640 ----a-w C:\WINDOWS\Internet Logs\xDB22.tmp
2007-01-10 22:02 204,800 ----a-w C:\WINDOWS\Internet Logs\xDB1F.tmp
2006-12-30 17:52 40,448 ----a-w C:\WINDOWS\Internet Logs\xDB1E.tmp
2006-12-22 15:31 3,746,816 ----a-w C:\WINDOWS\Internet Logs\xDB1D.tmp
2006-12-22 15:31 143,872 ----a-w C:\WINDOWS\Internet Logs\xDB1C.tmp
2006-12-20 22:52 3,724,800 ----a-w C:\WINDOWS\Internet Logs\xDB1B.tmp
2006-12-18 10:34 74,240 ----a-w C:\WINDOWS\Internet Logs\xDB1A.tmp
2006-12-15 23:10 453,120 ----a-w C:\WINDOWS\Internet Logs\xDB18.tmp
2006-12-15 23:10 3,724,288 ----a-w C:\WINDOWS\Internet Logs\xDB19.tmp
2006-12-15 22:07 25 ----a-w C:\Documents and Settings\Sébastien\RomInfo.dat
2006-12-15 22:07 25 ----a-w C:\Documents and Settings\Sébastien\RomInfo.dat
2006-12-06 21:37 3,614,208 ----a-w C:\WINDOWS\Internet Logs\xDB17.tmp
2006-12-01 14:03 165,376 ----a-w C:\WINDOWS\Internet Logs\xDB16.tmp
2006-11-26 23:10 3,598,848 ----a-w C:\WINDOWS\Internet Logs\xDB15.tmp
2006-11-26 23:10 2,657,792 ----a-w C:\WINDOWS\Internet Logs\xDB14.tmp
2006-11-23 18:51 3,596,288 ----a-w C:\WINDOWS\Internet Logs\xDB13.tmp
2006-11-21 18:51 3,594,240 ----a-w C:\WINDOWS\Internet Logs\xDB12.tmp
2006-11-16 13:35 3,559,936 ----a-w C:\WINDOWS\Internet Logs\xDB11.tmp
2006-08-25 15:51 617,472 --sha-w C:\WINDOWS\system32\comctl32.dll
2004-08-05 12:00 57,344 --sha-w C:\WINDOWS\system32\mfc42loc.dll
2004-08-05 12:00 413,696 --sha-w C:\WINDOWS\system32\msvcp60.dll
2004-08-05 12:00 253,952 --sha-w C:\WINDOWS\system32\msvcrt20.dll
.

((((((((((((((((((((((((((((( snapshot@2008-03-18_13.47.16.96 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-03-18 12:32:41 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
+ 2008-03-18 13:17:26 4,212 ---h--w C:\WINDOWS\system32\zllictbl.dat
.
((((((((((((((((((((((((((((((((( Point de chargement Reg )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{733716E1-76D2-4003-AC39-845281C0EF85}]
C:\WINDOWS\system32\nscB.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{DDFA1356-E6ED-42a5-9D62-93211D424A90}]
2008-03-11 14:45 339968 --a------ C:\WINDOWS\system32\mysidesearch_sidebar.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-05 13:00 15360]
"Configuration de la neuf Box"="C:\Program Files\neuf telecom\neuf Box\Wizard\QuickAccess.exe" [2005-12-13 14:19 389120]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-05-23 11:23 68856]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [ ]
"StopNetSend"="C:\Documents and Settings\Sébastien\Mes documents\Séb\netsend.exe" [2008-03-14 14:59 302592]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"="SOUNDMAN.EXE" [2004-02-26 16:53 65024 C:\WINDOWS\SOUNDMAN.EXE]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 11:50 155648]
"TkBellExe"="C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" [2006-03-05 20:21 180269]
"EPSON Stylus CX3200"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.exe" [2002-07-01 04:05 74752]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"Samsung Common SM"="C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" [2004-05-17 06:34 360448]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-02-16 09:54 282624]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-03-14 18:05 257088]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Edition Découverte\3.2\Apps\apdproxy.exe" [2007-03-16 11:45 63712]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 19:51 39792]
"{14-40-07-74-DW}"="C:\windows\system32\rwwnw64d.exe" [2008-02-27 16:29 49165]
"ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2007-12-13 19:27 919016]
"ccApp"="C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe" [2002-08-19 22:22 50880]
"ccRegVfy"="C:\Program Files\Fichiers communs\Symantec Shared\ccRegVfy.exe" [2002-08-19 22:23 34504]
"bm(1)"="C:\Program Files\Fichiers communs\VirusEffaceur\bm.exe" [ ]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-05 13:00 15360]
"ALUAlert"="C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe" [2002-08-07 09:04 54936]

C:\Documents and Settings\S‚bastien\Menu D‚marrer\Programmes\D‚marrage\
palmOne Registration.lnk - C:\Program Files\palmOne\register.exe [2005-02-11 13:44:58 2301952]

C:\Documents and Settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
DataViz Inc Messenger.lnk - C:\Program Files\Fichiers communs\DataViz\DvzIncMsgr.exe [2006-02-03 00:05:27 28672]
GoBack.lnk - C:\Program Files\Roxio\GoBack\GBTray.exe [2008-03-14 12:53:19 524288]
HotSync Manager.lnk - C:\Program Files\palmOne\Hotsync.exe [2004-06-09 14:16:08 471040]
LUMIX Simple Viewer.lnk - C:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exe [2008-03-02 19:44:09 57344]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 09:01:04 83360]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=

R3 A_USBETHMP;USB PowerPacket Network Adapter;C:\WINDOWS\system32\Drivers\usbethmp.sys [2002-10-25 14:54]
R3 FA312;Pilote de la carte Fast Ethernet FA330/FA312/FA311 NETGEAR;C:\WINDOWS\system32\DRIVERS\FA312nd5.sys [2001-08-17 21:12]
S3 Boonty Games;Boonty Games;"C:\Program Files\Fichiers communs\BOONTY Shared\Service\Boonty.exe" [2007-07-07 16:26]
S3 MemStPCI;Contrôleur Sony Memory Stick (PCI);C:\WINDOWS\system32\DRIVERS\MemStPCI.SYS [2004-08-03 23:00]
S3 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;C:\WINDOWS\system32\PLCNDIS5.SYS [2002-10-25 20:54]

.
Contenu du dossier 'Scheduled Tasks/Tâches planifiées'
"2008-03-14 19:10:28 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2008-03-14 19:23:44 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job"
- C:\PROGRA~1\NORTON~1\NORTON~1\NAVW32.exeG/task:C:\DOCUME~1\ALLUSE~1\APPLIC~1\Symantec\NORTON~1\Tasks\mycomp.sca
"2008-03-14 16:48:37 C:\WINDOWS\Tasks\Norton SystemWorks One Button Checkup.job"
- C:\Program Files\Norton SystemWorks\OBC.exe
"2008-03-18 13:20:07 C:\WINDOWS\Tasks\Symantec NetDetect.job"
- C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE
"2008-03-18 13:00:06 C:\WINDOWS\Tasks\Vérifier les mises à jour de Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-18 14:48:29
Windows 5.1.2600 Service Pack 2 NTFS

Balayage processus cachés ...

Balayage caché autostart entries ...

Balayage des fichiers cachés ...

Scan terminé avec succès
Les fichiers cachés: 0

**************************************************************************
.
Temps d'accomplissement: 2008-03-18 14:49:45
ComboFix-quarantined-files.txt 2008-03-18 13:49:42
.
2008-03-12 20:30:50 --- E O F ---

Profil : Helper
Plus d'informations

Re,

Télécharge MalwareByte's Anti-Malware et installe le.

~Redémarre l'ordinateur en mode sans échec (F8 au démarrage de l'ordinateur)
Aide


  • Lance MalwareByte's Anti-Malware et sélectionne "Exécuter un examen complet". Patiente le temps du scan.
  • Une fois le scan terminé,clique sur "Afficher les résultats" et enregistre le rapport sur ton Bureau.
  • Clique enfin sur "Supprimer la sélection".


Si MalwareByte's Anti-Malware a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok.
Aide


---------------
Prévention & Protection|Les logiciels gratuits|L'homme du FLCCF
Profil : IDNaute
Plus d'informations

Bonjour, voici le rapport
J'ai à nouveau une fenêtre norton qui me signale le virus.

Malwarebytes' Anti-Malware 1.08
Version de la base de données: 471

Type de recherche: Examen complet (C:\|D:\|E:\|F:\|)
Eléments examinés: 126031
Temps écoulé: 2 hour(s), 13 minute(s), 13 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 9
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 2
Fichier(s) infecté(s): 29

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
HKEY_CURRENT_USER\Software\MediaHoldings (Adware.PlayMP3Z) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Deewoo Network Manager (Adware.Radio) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Nvchost (Trojan.Goldun) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\ugac (Rogue.PCSecureSystem) -> No action taken.

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
C:\Program Files\Fichiers communs\NettoyeurDePC (Rogue.Multiple) -> No action taken.
C:\WINDOWS\system32\iDlo18 (Trojan.Downloader) -> No action taken.

Fichier(s) infecté(s):
C:\Program Files\Fichiers communs\NettoyeurDePC\stm.exe (Rogue.Multiple) -> No action taken.
C:\Program Files\Fichiers communs\System\Mapi\1036\f.exe (Spyware.FirePass) -> No action taken.
C:\QooBox\Quarantine\C\Program Files\Internet Explorer\lanuta89104.dll.vir (Adware.TTC) -> No action taken.
C:\QooBox\Quarantine\C\WINDOWS\system32\rev1\dincomsdll3.exe.vir (Trojan.Downloader) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP523\A0370677.dll (Rogue.Multiple) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP524\A0371525.exe (Rogue.PCPrivacyTool) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP528\A0375161.dll (Adware.TTC) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP528\A0375547.exe (Rogue.Multiple) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP528\A0375554.dll (Adware.TTC) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP532\A0376484.exe (Rogue.PCSecureSystem) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP532\A0376503.exe (Trojan.DownLoader) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP532\A0376628.dll (Adware.TTC) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP532\A0376684.exe (Rogue.Multiple) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP535\A0382608.exe (Trojan.Downloader) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP535\A0382616.dll (Adware.TTC) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP535\A0383660.sys (Rogue.PCSecureSystem) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP535\A0383700.dll (Rogue.Multiple) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP535\A0383701.dll (Rogue.Multiple) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP535\A0383702.exe (Rogue.Multiple) -> No action taken.
C:\System Volume Information\_restore{BB77AB2F-B2C4-4FCA-8677-5188BC0C1B4D}\RP535\A0383703.exe (Rogue.PCSecureSystem) -> No action taken.
C:\WINDOWS\system32\WhoisCL.exe (Adware.Fotomoto) -> No action taken.
C:\WINDOWS\system32\aux9\pon89104.exe (Adware.TTC) -> No action taken.
C:\WINDOWS\system32\bmv4\dewondll4.exe (Adware.ZenoSearch) -> No action taken.
C:\n.bat (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\rwwnw64d.exe (Adware.Zenosearch) -> No action taken.
C:\WINDOWS\system32\msnav32.ax (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\zxdnt3d.cfg (Malware.Trace) -> No action taken.
C:\WINDOWS\system32\winpfz37.sys (Malware.Trace) -> No action taken.
C:\WINDOWS\system\lsass.exe (Heuristic.Reserved.Word.Exploit) -> No action taken.

Profil : IDNaute
Plus d'informations

nom du viris trojan.horse

Profil : Helper
Plus d'informations
n°293046
20-03-2008 à 15:42:25
Masquer