Suis les étapes dans l´ordre.
Télécharge AVG anti spyware, installe, mets le à jour et c´est tout.
http://www.01net.com/telecharger/windows/Securite/anti-spyware/fiches/31851.html
Redémarre en mode sans échec,
http://forum.telecharger.01net.com/telecharger/virus_et_assimiles/failles_de_securite/redemarrer_en_mode_sans_echec_pourquoi_et_comment-387297/messages-1.html
Double clic sur clean, dans le menu choisis l´option 2 en appuyant sur la touche 2 de ton clavier. Copie/Colle le rapport.
Toujours en mode sans échec :
- Ensuite lance AVG et clique sur « Analyse » puis sur le sous-onglet Paramètres
- Dans Comment Réagir ? Choisis Quarantaine.
- Reviens au sous-onglet Analyser puis clique sur Analyse complète du système.
- le scan démarre.
Quand le scan touche à sa fin, clique sur Appliquer toutes les actions, les éléments sont alors déplacé en quarantaine.
Enfin, clique sur Enregistrer le rapport d´analyse, enregistre le sur le bureau et poste le ici.
Tuto:
http://www.malekal.com/tum/tutorial_AVG_AntiSpyware.php
Reposte un log Hijackthis mais en mode normal !! !
Ca va mieux ?
"nn,oblivion par exemple, passe extremement bien (super super fluide)!"
Le mytho du siecle, ou alors tu as de gros problemes de vision.
[M24]-) j´y voit pas trop mon interet de debatre avec toi, t´y croit tant mieu t´y croi pas c´est pas mon pb.Pour info jen´ai pas de "gros problemes de vision", par contre toi du ne doit pas t´y connaitre beaucoup en informatique pour dire cela ;- )
EvilElf -) jte met les rapports dans 5 mins !
Par contre c´est clair que Oblivion avec une 9600 c´est hard quoi ..
Surtout : comment avoir une 9600 Pro (AGP) avec un E4300 ?
Lightice -) avec une carte mère ayant un port pci express et agp !
Mais oblivion tourne nikel avec un niveau graph moyen.
Ca doit être moche quand même lol
Meme en 800X600 avec les détails en moyen ca peut pas etre "super fluide", ca doit meme pas etre fluide tout court.
[M24] -) franchement jtrouve plutot fluide mm si u zone de chargement sa lag un ptit peu pendant 3 sconde,mais bon faut pas tro en demandé nn plus a une 9600 pro ^^
EvilElf-)niveau graph moyen quoi...
Sinon elle dure longtemp l´analyse avec avg la ^^
EvilElf -) jte met les rapport en fin d´aprèm, enfin en tous cas, merci de ton aide.
rapport clean en mode sans echec:
Script execute en mode sans echec
Rapport clean par Malekal_morte -
http://www.malekal.com
Script execute en mode sans echec 03/06/2007 a 20:47:03,96
Microsoft Windows XP [version 5.1.2600]
tentative de suppression de "C:\Program Files\Fichiers communs\Yazzle????OinAdmin.exe"
Rapport avg en mode sans echec:
--------------------------------------------------
-------
AVG Anti-Spyware - Rapport d´analyse
--------------------------------------------------
-------
+ Créé à: 17:28:45 04/06/2007
+ Résultat de l´analyse:
C:\Hijackthis\backups\backup-20070603-200635-765.d
ll -> Adware.Virtumonde : Aucune action entreprise.
C:\System Volume
Information\_restore{440849FA-3A72-42F4-A801-33298
51A76BC}\RP120\A0010120.exe -> Adware.Virtumonde : Aucune action entreprise.
C:\WINDOWS\system32\khhgdcb.dll -> Adware.Virtumonde : Aucune action entreprise.
C:\WINDOWS\system32\ssqpqpm.dll -> Adware.Virtumonde : Aucune action entreprise.
C:\WINDOWS\system32\vtustuv.dll -> Adware.Virtumonde : Aucune action entreprise.
[1052] C:\WINDOWS\system32\vtustuv.dll -> Adware.Virtumonde : Aucune action entreprise.
[208] C:\WINDOWS\system32\geebc.dll -> Adware.Virtumonde : Aucune action entreprise.
[632] C:\WINDOWS\system32\geebc.dll -> Adware.Virtumonde : Aucune action entreprise.
C:\System Volume
Information\_restore{440849FA-3A72-42F4-A801-33298
51A76BC}\RP122\A0010214.exe -> Downloader.PurityScan.eg : Aucune action entreprise.
C:\System Volume
Information\_restore{440849FA-3A72-42F4-A801-33298
51A76BC}\RP122\A0010663.exe -> Downloader.PurityScan.eg : Aucune action entreprise.
C:\System Volume
Information\_restore{440849FA-3A72-42F4-A801-33298
51A76BC}\RP124\A0010725.exe -> Downloader.PurityScan.eg : Aucune action entreprise.
C:\System Volume
Information\_restore{440849FA-3A72-42F4-A801-33298
51A76BC}\RP124\A0010752.exe -> Downloader.PurityScan.eg : Aucune action entreprise.
C:\System Volume
Information\_restore{440849FA-3A72-42F4-A801-33298
51A76BC}\RP131\A0011129.exe -> Downloader.PurityScan.eg : Aucune action entreprise.
:mozilla.79:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.247realmedia : Aucune action entreprise.
:mozilla.154:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Adbrite : Aucune action entreprise.
:mozilla.56:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Adbrite : Aucune action entreprise.
:mozilla.57:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Adbrite : Aucune action entreprise.
:mozilla.58:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Adbrite : Aucune action entreprise.
:mozilla.59:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Adbrite : Aucune action entreprise.
:mozilla.20:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.22:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.38:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.39:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Adtech : Aucune action entreprise.
:mozilla.35:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.36:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.37:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.38:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Advertising : Aucune action entreprise.
:mozilla.151:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Atdmt : Aucune action entreprise.
C:\Documents and
Settings\Constant.CONSTANT-FO4495\Cookies\constant
@atdmt[1].txt -> TrackingCookie.Atdmt : Aucune action entreprise.
:mozilla.19:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
:mozilla.62:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
:mozilla.18:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
:mozilla.20:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Doubleclick : Aucune action entreprise.
:mozilla.101:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Estat : Aucune action entreprise.
:mozilla.147:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Fastclick : Aucune action entreprise.
:mozilla.148:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Fastclick : Aucune action entreprise.
:mozilla.117:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Googleadservices : Aucune action entreprise.
:mozilla.71:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Imrworldwide : Aucune action entreprise.
:mozilla.74:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Imrworldwide : Aucune action entreprise.
:mozilla.84:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Liveperson : Aucune action entreprise.
:mozilla.85:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Liveperson : Aucune action entreprise.
:mozilla.86:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Liveperson : Aucune action entreprise.
:mozilla.33:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Mediaplex : Aucune action entreprise.
:mozilla.63:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Overture : Aucune action entreprise.
:mozilla.34:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Paypal : Aucune action entreprise.
:mozilla.122:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.123:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.124:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.125:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.126:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.127:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
:mozilla.130:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.131:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.132:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.15:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.16:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.17:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
:mozilla.150:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Statcounter : Aucune action entreprise.
:mozilla.108:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Targetnet : Aucune action entreprise.
:mozilla.15:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.16:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.18:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.19:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
:mozilla.10:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.44:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.47:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.48:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.9:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Weborama : Aucune action entreprise.
:mozilla.145:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.146:C:\Documents and Settings\Constant\Application
Data\Mozilla\Firefox\Profiles\a8br8b8g.default\coo
kies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.40:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.41:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
:mozilla.42:C:\Documents and Settings\Constant.CONSTANT-FO4495\Application
Data\Mozilla\Firefox\Profiles\fim0fpyq.default\coo
kies.txt -> TrackingCookie.Yieldmanager : Aucune action entreprise.
C:\System Volume
Information\_restore{440849FA-3A72-42F4-A801-33298
51A76BC}\RP120\A0010118.exe -> Trojan.Inject.br : Aucune action entreprise.
C:\Documents and Settings\Constant.CONSTANT-FO4495\Mes documents\TEMP\keygen XP\XPKey.exe -> Trojan.Small.edz : Aucune action entreprise.
C:\Documents and Settings\Constant.CONSTANT-FO4495\Mes documents\TEMP\validité xp\XP Genuine_In_5_sec_2\Windows Toolkit.zip/windowsxp_keygen.exe -> Trojan.Small.edz : Aucune action entreprise.
Fin du rapport
Log HijackThis en mode normal:
Logfile of HijackThis v1.99.1
Scan saved at 19:28:36, on 04/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\Mcafee\MWL\MWLGui.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\Program Files\Mcafee\MWL\MwlSvc.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Hijackthis\scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
C:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.ht
m
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
C:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.ht
m
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {46A2CD97-0557-4B13-BD98-0BE6E30C5E3D} - C:\WINDOWS\system32\geebc.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {BF2C383D-235F-4439-9332-884E119A00FD} - C:\WINDOWS\system32\vtustuv.dll (file missing)
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\system32\qqollsld.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [MWLExe] C:\Program Files\Mcafee\MWL\MWLGui.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [Genuine] rundll32.exe "C:\WINDOWS\system32\ipketldu.dll",realset
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra ´Tools´ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ´Tools´ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
http://www.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection.cab?version=
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} -
C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DL
L
O20 - Winlogon Notify: geebc - C:\WINDOWS\system32\geebc.dll (file missing)
O20 - Winlogon Notify: vtustuv - vtustuv.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. -
c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: McAfee Wireless Network Security Service (MWLSvc) - McAfee, Inc. - C:\Program Files\Mcafee\MWL\MwlSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Pour info jvois une diference (bien que assez petite)
upupup !! !
Solution INFAILLIBLE
Formatage + Ghost et en cas de problème chargement du Ghost !
Point final à tout problème de virus, troyens ou autres malwares daubés!
http://www.commentcamarche.net/faq/sujet-304-creation-d-image-systeme-ghost
Re ![]()
Alala ça résiste ^^
Relance Hijackthis, coche les lignes suivante et fix les :
O2 - BHO: (no name) - {46A2CD97-0557-4B13-BD98-0BE6E30C5E3D} - C:\WINDOWS\system32\geebc.dll (file missing)
O2 - BHO: (no name) - {BF2C383D-235F-4439-9332-884E119A00FD} - C:\WINDOWS\system32\vtustuv.dll (file missing)
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\system32\qqollsld.dll
O4 - HKLM\..\Run: [Genuine] rundll32.exe "C:\WINDOWS\system32\ipketldu.dll",realset
O20 - Winlogon Notify: geebc - C:\WINDOWS\system32\geebc.dll (file missing)
O20 - Winlogon Notify: vtustuv - vtustuv.dll (file missing)
Répète la même opération avec OTMovelt que la dernière fois avec cette ligne :
C:\WINDOWS\system32\qqollsld.dll
Telecharge VirtumundoBegone
http://secured2k.home.comcast.net/tools/VirtumundoBeGone.exe
Redémarre en mode sans échec, double clique sur VirtumundoBeGone.exe et laisse le faire le travail. Enfin poste le rapport.
Telecharge Vundofix (by Atribune) sur ton bureau.
http://www.atribune.org/ccount/click.php?id=4
Clique sur "Vundofix.exe" puis sur "Scan for Vundo".
Lorsque le scan est terminer clique sur "Remove Vundo". On te demandera si tu veux supprimer les fichiers clique sur "Yes" (si le bureau disparaît c’est normal) puis on te demandera si tu veux redémarrer ton PC clique alors sur OK.
Copie/colle le rapport ici (situer ici : "C:\vundofix.txt").
Reposte un log Hijackthis.
++
Rajoute cette lignes à OTMovelt :
C:\WINDOWS\system32\ipketldu.dll
rapport de VirtumundoBegone :
[06/04/2007, 21:46:05] - VirtumundoBeGone v1.5 ( "C:\Documents and
Settings\Constant.CONSTANT-FO4495\Bureau\Virtumund
oBeGone.exe" )
[06/04/2007, 21:46:07] - Detected System Information:
[06/04/2007, 21:46:07] - Windows Version: 5.1.2600, Service Pack 2
[06/04/2007, 21:46:07] - Current Username: Constant (Admin)
[06/04/2007, 21:46:07] - Windows is in SAFE mode with Networking.
[06/04/2007, 21:46:07] - Searching for Browser Helper Objects:
[06/04/2007, 21:46:07] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[06/04/2007, 21:46:07] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[06/04/2007, 21:46:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/04/2007, 21:46:07] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[06/04/2007, 21:46:07] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[06/04/2007, 21:46:07] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[06/04/2007, 21:46:07] - BHO 4: {7DB2D5A0-7241-4E79-B68D-6309F01C5231} (scriptproxy)
[06/04/2007, 21:46:07] - BHO 5: {BF2C383D-235F-4439-9332-884E119A00FD} ()
[06/04/2007, 21:46:07] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/04/2007, 21:46:07] - Checking for HKLM\...\Winlogon\Notify\vtustuv
[06/04/2007, 21:46:07] - Key not found: HKLM\...\Winlogon\Notify\vtustuv, continuing.
[06/04/2007, 21:46:07] - Finished Searching Browser Helper Objects
[06/04/2007, 21:46:07] - Finishing up...
[06/04/2007, 21:46:07] - Nothing found! Exiting...
Rapport Vundofix:
VundoFix V6.4.2
Checking Java version...
Scan started at 21:52:24 04/06/2007
Listing files found while scanning....
C:\WINDOWS\system32\bqxrgjce.dll
C:\WINDOWS\system32\qomljkk.dll
C:\WINDOWS\system32\urqropo.dll
Beginning removal...
Attempting to delete C:\WINDOWS\system32\bqxrgjce.dll
C:\WINDOWS\system32\bqxrgjce.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\qomljkk.dll
C:\WINDOWS\system32\qomljkk.dll Has been deleted!
Attempting to delete C:\WINDOWS\system32\urqropo.dll
C:\WINDOWS\system32\urqropo.dll Has been deleted!
Performing Repairs to the registry.
Done!
Log Hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 22:12:34, on 04/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\McAfee\MSK\MskAgent.exe
C:\Program Files\Mcafee\MWL\MWLGui.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\McAfee\MPS\mpsevh.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Program Files\Mcafee\MWL\MwlSvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\alg.exe
C:\Hijackthis\scanner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
C:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.ht
m
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
C:\WINDOWS\PCHealth\HelpCtr\System\panels\blank.ht
m
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O2 - BHO: (no name) - {BF2C383D-235F-4439-9332-884E119A00FD} - C:\WINDOWS\system32\vtustuv.dll (file missing)
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [MskAgentexe] C:\Program Files\McAfee\MSK\MskAgent.exe
O4 - HKLM\..\Run: [MWLExe] C:\Program Files\Mcafee\MWL\MWLGui.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: E&xporter vers Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra ´Tools´ menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra ´Tools´ menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} -
http://www.touslesdrivers.com/fichiers/hardwaredetection/hardwaredetection.cab?version=
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Fichiers communs\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} -
C:\PROGRA~1\FICHIE~1\MICROS~1\OFFICE12\MSOXMLMF.DL
L
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FICHIE~1\McAfee\EmProxy\emproxy.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Fichiers communs\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\fichiers communs\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FICHIE~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. -
c:\PROGRA~1\FICHIE~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: McAfee Wireless Network Security Service (MWLSvc) - McAfee, Inc. - C:\Program Files\Mcafee\MWL\MwlSvc.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
voila!
Re
Coche et fix cette ligne :
O2 - BHO: (no name) - {BF2C383D-235F-4439-9332-884E119A00FD} - C:\WINDOWS\system32\vtustuv.dll (file missing)
Comment se porte ton ordi ?