Bonjour,
Mon Pc à la maison est totalement contaminé et je ne sais pas quoi faire. J'ai suivi la mini manip ce qui m'a permit de redemarrer le PC en mode normal, mais j'ai toujours un fonctionnement aléatoire. Voila le dernier rapport:
Deckard's System Scanner v20071014.68
Run by Guillaume on 2008-02-27 21:30:32
Computer is in Normal Mode.
--------------------------------------------------------------------------------
Total Physical Memory: 224 MiB (512 MiB recommended).
-- HijackThis (run as Guillaume.exe) -------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:30:59, on 27/02/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\AVG\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Documents and Settings\Guillaume\Bureau\ds.exe
C:\Jaquo\GUILLA~1.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = proxy.free.fr:3128
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O1 - Hosts: 124.217.252.77 www.bravesentry.com
O1 - Hosts: 124.217.252.77 bravesentry.com
O1 - Hosts: 124.217.252.78 secure.isoftpay.com
O1 - Hosts: 124.217.252.77 www.bravesentry.com
O1 - Hosts: 124.217.252.77 bravesentry.com
O1 - Hosts: 124.217.252.78 secure.isoftpay.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O2 - BHO: (no name) - {F9F799B9-3391-4CF5-B0C4-EDF7305A7F09} - C:\WINDOWS\System32\mllmj.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\fr\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\RunServices: [UpdateWin] C:\WINDOWS\System32\olethk32z.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .mp3: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpeg: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: cru629.dat
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\AVG\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
--
End of file - 6026 bytes
-- Files created between 2008-01-27 and 2008-02-27 -----------------------------
2008-02-27 21:16:43 5632 --a------ C:\WINDOWS\cru629.dat
2008-02-27 20:10:28 3503 --a------ C:\Start_.cmd
2008-02-27 20:10:27 0 d-------- C:\327882R2FWJFW
2008-02-27 18:54:45 0 d-------- C:\WINDOWS\pss
2008-02-26 20:19:46 0 d-------- C:\Program Files\Avira
2008-02-26 20:19:46 0 d-------- C:\Documents and Settings\All Users\Application Data\Avira
2008-02-26 20:18:07 0 d-------- C:\Antivir
2008-02-23 21:36:52 36352 --a------ C:\WINDOWS\System32\drivers\beep.sys
2008-02-23 21:02:44 0 dr-h----- C:\Documents and Settings\Guillaume\Recent
2008-02-23 19:42:29 3758 --a------ C:\WINDOWS\System32\tmp.reg
2008-02-23 19:31:40 0 d-------- C:\Documents and Settings\Guillaume\Application Data\Grisoft
2008-02-23 19:31:07 0 --a------ C:\WINDOWS\System32\dllgh8jkd1q8.exe
2008-02-23 19:08:37 24576 --a------ C:\WINDOWS\System32\VundoFixSVC.exe <Not>
2008-02-23 18:46:20 0 d-------- C:\VundoFix Backups
2008-02-23 18:43:26 0 dr-h----- C:\Documents and Settings\Administrateur\Recent
2008-02-23 18:26:38 0 d-------- C:\Jaquo
2008-02-23 18:23:42 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Grisoft
2008-02-23 18:23:09 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-02-23 18:20:43 0 d-------- C:\AVG
2008-02-23 18:08:10 0 d-------- C:\CCleaner
2008-02-12 16:58:02 0 d---s---- C:\Documents and Settings\Administrateur\Application Data\Microsoft
2008-02-12 16:58:02 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Identities
2008-02-12 16:58:01 0 d--h----- C:\Documents and Settings\Administrateur\Voisinage réseau
2008-02-12 16:58:01 0 d--h----- C:\Documents and Settings\Administrateur\Voisinage d'impression
2008-02-12 16:58:01 0 dr-h----- C:\Documents and Settings\Administrateur\SendTo
2008-02-12 16:58:01 0 d--h----- C:\Documents and Settings\Administrateur\Modèles
2008-02-12 16:58:01 0 dr------- C:\Documents and Settings\Administrateur\Mes documents
2008-02-12 16:58:01 0 dr------- C:\Documents and Settings\Administrateur\Menu Démarrer
2008-02-12 16:58:01 0 d--h----- C:\Documents and Settings\Administrateur\Local Settings
2008-02-12 16:58:01 0 dr------- C:\Documents and Settings\Administrateur\Favoris
2008-02-12 16:58:01 0 d---s---- C:\Documents and Settings\Administrateur\Cookies
2008-02-12 16:58:01 0 d-------- C:\Documents and Settings\Administrateur\Bureau
2008-02-12 16:58:01 0 dr-h----- C:\Documents and Settings\Administrateur\Application Data
2008-02-12 16:58:01 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Roxio
2008-02-12 16:58:01 0 d-------- C:\Documents and Settings\Administrateur\Application Data\Macromedia
2008-02-12 16:58:01 0 d-------- C:\Documents and Settings\Administrateur\Application Data\CyberLink
2008-02-12 16:58:00 0 d-------- C:\Documents and Settings\Administrateur\WINDOWS
2008-02-12 16:58:00 0 d---s---- C:\Documents and Settings\Administrateur\UserData
2008-02-12 16:57:59 1048576 --ah----- C:\Documents and Settings\Administrateur\NTUSER.DAT
2008-02-12 13:01:13 0 d-------- C:\Documents and Settings\Guillaume\Application Data\Anti-Virus-Pro.com
2008-02-12 12:59:57 10 --a------ C:\WINDOWS\System32\kr_done1
2008-02-12 12:59:51 0 d-------- C:\Program Files\AntiVirusPro
2008-02-08 17:52:32 0 d--hs---- C:\FOUND.004
2008-02-08 17:17:02 0 d-------- C:\Program Files\Microsoft Security Adviser
2008-02-06 22:05:16 0 d--hs---- C:\FOUND.003
2008-02-06 21:43:24 144 --ahs---- C:\WINDOWS\System32\691013646.dat
-- Find3M Report ---------------------------------------------------------------
2008-01-12 21:52:06 0 d-------- C:\Program Files\uTorrent
2008-01-12 21:51:58 0 d-------- C:\Documents and Settings\Guillaume\Application Data\uTorrent
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F9F799B9-3391-4CF5-B0C4-EDF7305A7F09}]
C:\WINDOWS\System32\mllmj.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AliceSAV"="C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe" [16/12/2005 17:57]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [30/08/2002 06:00]
"qqzduv"="c:\windows\system32\qqzduv.exe" [06/02/2008 18:31]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
"UpdateWin"=C:\WINDOWS\System32\olethk32z.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=cru629.dat
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"= msv1_0 C:\WINDOWS\System32\mllmj.dll
"UpdateWin"= C:\WINDOWS\System32\olethk32z.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Menu Démarrer^Programmes^Démarrage^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Guillaume^Menu Démarrer^Programmes^Démarrage^Yahoo! Widget Engine.lnk]
path=C:\Documents and Settings\Guillaume\Menu Démarrer\Programmes\Démarrage\Yahoo! Widget Engine.lnk
backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\!AVG Anti-Spyware]
"C:\AVG\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avgnt]
"C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\braviax]
braviax.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
C:\Program Files\Ahead\InCD\InCD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X1100 Series]
"C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechSoftwareUpdate]
"C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
C:\Program Files\Logitech\Video\ISStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
C:\Program Files\Logitech\Video\LogiTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LVCOMSX]
C:\WINDOWS\System32\LVCOMSX.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
"C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\net64]
C:\WINDOWS\svhoster.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netc]
C:\WINDOWS\svc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netsv32]
C:\WINDOWS\sv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netw]
C:\WINDOWS\svw.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netx]
C:\WINDOWS\svx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\netzip]
C:\WINDOWS\svzip.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NWEReboot]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\qqzduv]
c:\windows\system32\qqzduv.exe qqzduv
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioAudioCentral]
"C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioEngineUtility]
"C:\Program Files\Fichiers communs\Roxio Shared\System\EngUtil.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
"C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SystemSv121]
C:\WINDOWS\System32\n2ewma1xxsv234.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateWin]
C:\WINDOWS\System32\olethk32z.exe
-- End of Deckard's System Scanner: finished at 2008-02-27 21:33:42 ------------
Est-ce que quelqu'un peut m'indiquer ce que je dois faire.
Merci d'avance pour votre aide precieuse.