Tom's Guide > Forum > Sécurité - Virus > Pub CID intempestives
Mot :    Pseudo :           
 

Bonjour à tous

Voici mon problème, lorsque je suis sur internet, j'utilise firefox, internet explorer s'ouvre sur une pub CID et ca arrète pas de faire ca durant toute les connexion ce qui est plutot énervant.

Cela fait plusieurs jours que j'essaye d'éliminer ce problème mais impossible c'est pour cela que je m'adresse à vous.

Voici mon rapport hijackthis :

Citation :


Logfile of HijackThis v1.99.1
Scan saved at 19:22:13, on 19/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5w.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Source Engine\OSE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Jonathan\Bureau\Outils de netoyage virus\hijackthis\HijackThisAide.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB002" /M "Stylus CX6600"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [ApacheTomcatMonitor] "C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5w.exe" //MS//Tomcat5
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [jfoqwxsswr] c:\windows\system32\jfoqwxsswr.exe jfoqwxsswr
O4 - HKLM\..\Run: [face bin load show] C:\Documents and Settings\All Users\Application Data\title tool face bin\Fast Dash.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?2bda6f0555224614989493e51d1d0f37
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?2bda6f0555224614989493e51d1d0f37
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bugland1985.spaces.live.com [...] nPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)




Merci de me répondre, bonne journée

Liens sponsorisés
Inscrivez-vous ou connectez-vous pour masquer ceci.

Bonjour,

Télécharge LopResearch.zip
Dézippe-le sur ton Bureau uniquement.
Ouvre le dossier LopResearch puis double-clique sur le Scan.bat.
Un rapport sera généré, poste son contenu ici.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Merci de ta réponse je ferai ca ce soir en rentrant du boulot.

Répondre à bugland

Voila j'ai bien fait toute ces instructions et voici le fichier que cela m'a généré :

Citation :



----------------------------[ LopResearch v3 ]----------------------------

Version : Microsoft Windows XP [version 5.1.2600] [ OS : Windows_NT ]

Lancé depuis : C:\Documents and Settings\Jonathan\Bureau\LopResearch v3.1

Rapport crée : Le 21/09/2007 à 17:45:59,48 PC : JON

! Faire analyser le rapport par un Helper avant intervention !

---------------------[ Listing des Applications Data ]--------------------

C:\Documents and Settings\All Users\Application Data\Apple Computer
C:\Documents and Settings\All Users\Application Data\Grisoft
C:\Documents and Settings\All Users\Application Data\Delete Hide Support Math
C:\Documents and Settings\All Users\Application Data\title tool face bin
C:\Documents and Settings\All Users\Application Data\wave log show title
C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
C:\Documents and Settings\All Users\Application Data\avg7
C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Documents and Settings\All Users\Application Data\UDL
C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
C:\Documents and Settings\All Users\Application Data\desktop.ini
C:\Documents and Settings\All Users\Application Data\nView_Profiles

C:\Documents and Settings\Camille\Application Data\army file bows
C:\Documents and Settings\Camille\Application Data\AVG7
C:\Documents and Settings\Camille\Application Data\Microsoft
C:\Documents and Settings\Camille\Application Data\Real
C:\Documents and Settings\Camille\Application Data\Symantec
C:\Documents and Settings\Camille\Application Data\Notepad++
C:\Documents and Settings\Camille\Application Data\SolidWorks
C:\Documents and Settings\Camille\Application Data\DWGeditor
C:\Documents and Settings\Camille\Application Data\Creative
C:\Documents and Settings\Camille\Application Data\Morpheus
C:\Documents and Settings\Camille\Application Data\MessengerSkinner
C:\Documents and Settings\Camille\Application Data\Apple Computer
C:\Documents and Settings\Camille\Application Data\Adobe
C:\Documents and Settings\Camille\Application Data\vlc
C:\Documents and Settings\Camille\Application Data\Media Player Classic
C:\Documents and Settings\Camille\Application Data\Help
C:\Documents and Settings\Camille\Application Data\Sun
C:\Documents and Settings\Camille\Application Data\AdobeUM
C:\Documents and Settings\Camille\Application Data\Macromedia
C:\Documents and Settings\Camille\Application Data\Mozilla
C:\Documents and Settings\Camille\Application Data\Logitech
C:\Documents and Settings\Camille\Application Data\Identities
C:\Documents and Settings\Camille\Application Data\desktop.ini

C:\Documents and Settings\dan\Application Data\Real
C:\Documents and Settings\dan\Application Data\Microsoft
C:\Documents and Settings\dan\Application Data\Adobe
C:\Documents and Settings\dan\Application Data\Macromedia
C:\Documents and Settings\dan\Application Data\Mozilla
C:\Documents and Settings\dan\Application Data\Identities
C:\Documents and Settings\dan\Application Data\desktop.ini

C:\Documents and Settings\Default User\Application Data\desktop.ini
C:\Documents and Settings\Default User\Application Data\Microsoft

C:\Documents and Settings\Jonathan\Application Data\army file bows
C:\Documents and Settings\Jonathan\Application Data\Screenshot Sender
C:\Documents and Settings\Jonathan\Application Data\Microsoft
C:\Documents and Settings\Jonathan\Application Data\AVG7
C:\Documents and Settings\Jonathan\Application Data\Adobe
C:\Documents and Settings\Jonathan\Application Data\uTorrent
C:\Documents and Settings\Jonathan\Application Data\AdobeUM
C:\Documents and Settings\Jonathan\Application Data\Notepad++
C:\Documents and Settings\Jonathan\Application Data\Creative
C:\Documents and Settings\Jonathan\Application Data\Morpheus
C:\Documents and Settings\Jonathan\Application Data\Apple Computer
C:\Documents and Settings\Jonathan\Application Data\Macromedia
C:\Documents and Settings\Jonathan\Application Data\Ahead
C:\Documents and Settings\Jonathan\Application Data\Sun
C:\Documents and Settings\Jonathan\Application Data\Media Player Classic
C:\Documents and Settings\Jonathan\Application Data\.ABC 3.01
C:\Documents and Settings\Jonathan\Application Data\Help
C:\Documents and Settings\Jonathan\Application Data\vlc
C:\Documents and Settings\Jonathan\Application Data\dvdcss
C:\Documents and Settings\Jonathan\Application Data\Microsoft Web Folders
C:\Documents and Settings\Jonathan\Application Data\Symantec
C:\Documents and Settings\Jonathan\Application Data\FotoWire
C:\Documents and Settings\Jonathan\Application Data\Logitech
C:\Documents and Settings\Jonathan\Application Data\Mozilla
C:\Documents and Settings\Jonathan\Application Data\desktop.ini
C:\Documents and Settings\Jonathan\Application Data\Identities

C:\Documents and Settings\LocalService\Application Data\Microsoft
C:\Documents and Settings\LocalService\Application Data\AVG7

C:\Documents and Settings\NetworkService\Application Data\Microsoft
C:\Documents and Settings\NetworkService\Application Data\Symantec

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

C:\WINDOWS\tasks\A7E7BDD091D42E90.job
C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\SA.DAT
C:\WINDOWS\tasks\desktop.ini

--------------[ Listing des dossiers dans C:\Program Files ]--------------

C:\Program Files\ABC
C:\Program Files\Adobe
C:\Program Files\Ahead
C:\Program Files\Alwil Software
C:\Program Files\AMD
C:\Program Files\Apache Software Foundation
C:\Program Files\Apple Software Update
C:\Program Files\army file bows
C:\Program Files\AtomixMP3
C:\Program Files\Audible
C:\Program Files\AvRack
C:\Program Files\AWicons Pro
C:\Program Files\Bible
C:\Program Files\BSW
C:\Program Files\CCleaner
C:\Program Files\CDBurnerXP Pro 3
C:\Program Files\CodeBlocks
C:\Program Files\Common Files
C:\Program Files\ComPlus Applications
C:\Program Files\Comptes et Budget Free V5.0
C:\Program Files\Creative
C:\Program Files\DivX
C:\Program Files\EasyPHP1-8
C:\Program Files\epson
C:\Program Files\Everest Poker
C:\Program Files\FairStars Audio Converter
C:\Program Files\Fichiers communs
C:\Program Files\FileZilla
C:\Program Files\GiveMeTac 1.1
C:\Program Files\Grisoft
C:\Program Files\Guitar Pro 5
C:\Program Files\I.P.E
C:\Program Files\Internet Explorer
C:\Program Files\iTunes
C:\Program Files\Java
C:\Program Files\K-Lite Codec Pack
C:\Program Files\Logitech
C:\Program Files\Messenger
C:\Program Files\MessengerSkinner
C:\Program Files\Microsoft CAPICOM 2.1.0.2
C:\Program Files\microsoft frontpage
C:\Program Files\Microsoft Office
C:\Program Files\Microsoft Visual Studio
C:\Program Files\Microsoft Visual Studio .NET
C:\Program Files\Microsoft Visual Studio .NET 2003
C:\Program Files\Microsoft.NET
C:\Program Files\Morpheus
C:\Program Files\Movie Maker
C:\Program Files\Mozilla Firefox
C:\Program Files\MP3 Player Utilities
C:\Program Files\MSI
C:\Program Files\MSN
C:\Program Files\MSN Gaming Zone
C:\Program Files\MSN Messenger
C:\Program Files\MUSICMATCH
C:\Program Files\NetMeeting
C:\Program Files\Neuf
C:\Program Files\Norton SystemWorks
C:\Program Files\Notepad++
C:\Program Files\NVIDIA Corporation
C:\Program Files\Online Services
C:\Program Files\Outlook Express
C:\Program Files\Publication Web
C:\Program Files\Real
C:\Program Files\Realtek Sound Manager
C:\Program Files\Services en ligne
C:\Program Files\Smart Panel
C:\Program Files\SnIco Edit
C:\Program Files\softnyx
C:\Program Files\Sophos SWEEP for NT
C:\Program Files\Symantec
C:\Program Files\uTorrent
C:\Program Files\VideoLAN
C:\Program Files\Web Publish
C:\Program Files\Windows Live Safety Center
C:\Program Files\Windows Live Toolbar
C:\Program Files\Windows Media Connect 2
C:\Program Files\Windows Media Player
C:\Program Files\Windows NT
C:\Program Files\WinRAR
C:\Program Files\xerox
C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]-----

C:\Program Files\Fichiers communs\Adobe
C:\Program Files\Fichiers communs\Ahead
C:\Program Files\Fichiers communs\Bluebeam Software
C:\Program Files\Fichiers communs\Designer
C:\Program Files\Fichiers communs\eDrawings2006
C:\Program Files\Fichiers communs\FotoWire
C:\Program Files\Fichiers communs\InstallShield
C:\Program Files\Fichiers communs\Java
C:\Program Files\Fichiers communs\Logitech
C:\Program Files\Fichiers communs\Microsoft Shared
C:\Program Files\Fichiers communs\MSSoap
C:\Program Files\Fichiers communs\ODBC
C:\Program Files\Fichiers communs\Real
C:\Program Files\Fichiers communs\Services
C:\Program Files\Fichiers communs\Solidworks Data
C:\Program Files\Fichiers communs\SpeechEngines
C:\Program Files\Fichiers communs\Symantec Shared
C:\Program Files\Fichiers communs\System
C:\Program Files\Fichiers communs\WhenU

----------------------[ Recherche dans le Registre ]----------------------

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]


-----------------[ Recherche de Fichiers - Dossiers Lop ]-----------------

C:\WINDOWS\tasks\A7E7BDD091D42E90.job

--------------------[ Vérification du fichier Hosts ]---------------------

Fichier Hosts : Propre

--------------------[ Recherche d'autres infections ]---------------------

C:\WINDOWS\pack.epk
C:\WINDOWS\system32\nvs2.inf

! EGDACCESS Possible !


--------------------[ Fin du rapport à 17:46:07,29 ]----------------------




Répondre à bugland

Re,

Télécharge Navilog1.exe (IL-MAFIOSO)
Enregistre-le sur ton Bureau.
Lance l'installation en double cliquant sur navilog.exe.
Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
(Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau)

Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.
! N'utilise pas l'option 2, 3 et 4 sans notre accord !
Patiente jusqu'à l'apparition de ce message :
"*** Analyse Termine le ..... ***"
Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste-nous son contenu de cette manière :

-> Edition / Sélectionner tout
-> Edition / Copier
-> Clique-Droit / Coller dans ta réponse


NOTE : Le rapport se trouve également ici : C:\fixnavi.txt

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

J'ail installé le programme en le lancantil me demand ela langue je lui met f mais rien ne se passe.

Répondre à bugland

Et t'appuie sur Entrée après ? :d

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Non mais je bien appuyé sur entrer on dirait que c'est comme si il me faisait quitter directement.

Le fichier bat à lancer c'est bien navilog1.bat?


Message édité par bugland le 21-09-2007 à 19:04:24
Répondre à bugland

Oui. Tu as un programme qui bloque l'accès au registre ?

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Un programme qui bloque euh je sais pas.
C'est peut etre le firewall de windows??
J'ai aussi AVG en barre des tache ca peut y jouer.


Message édité par bugland le 21-09-2007 à 19:07:07
Répondre à bugland

On va voir qq chose :

Désinstalle correctement Avast! pour le remplacer par AntiVir.
Pourquoi changer ? Avast! vs AntiVir

Fais un scan complet puis poste le rapport en fin d'analyse.
AIDE : Tutorial sur l'antivirus AntiVir Personal Edition Classic

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Ok je le désinstall, et j'install antivire.

Répondre à bugland

Voila je viens de finir le scan d'ailleurs il a repéré plusieurs virus, voici le rapport :

Citation :




AntiVir PersonalEdition Classic
Report file date: vendredi 21 septembre 2007 19:36

Scanning for 1077818 virus strains and unwanted programs.

Licensed to: Avira AntiVir PersonalEdition Classic
Serial number: 0000149996-ADJIE-0001
Platform: Windows XP
Windows version: (Service Pack 2) [5.1.2600]
Username: Jonathan
Computer name: JON

Version information:
BUILD.DAT : 268 15604 Bytes 31/08/2007 13:04:00
AVSCAN.EXE : 7.0.6.1 290856 Bytes 21/09/2007 17:31:02
AVSCAN.DLL : 7.0.6.0 49192 Bytes 21/09/2007 17:31:02
LUKE.DLL : 7.0.5.3 147496 Bytes 21/09/2007 17:31:03
LUKERES.DLL : 7.0.6.1 10280 Bytes 21/09/2007 17:31:03
ANTIVIR0.VDF : 6.35.0.1 7371264 Bytes 31/05/2006 13:08:58
ANTIVIR1.VDF : 6.39.0.129 7251968 Bytes 10/07/2007 17:31:05
ANTIVIR2.VDF : 6.39.1.120 1918464 Bytes 12/09/2007 17:31:06
ANTIVIR3.VDF : 6.39.1.163 208896 Bytes 21/09/2007 17:31:06
AVEWIN32.DLL : 7.6.0.15 2806272 Bytes 21/09/2007 17:31:07
AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 09:36:26
AVPREF.DLL : 7.0.2.2 25640 Bytes 21/09/2007 17:31:02
AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 12:16:24
AVPACK32.DLL : 7.3.0.15 360488 Bytes 21/09/2007 17:31:07
AVREG.DLL : 7.0.1.6 30760 Bytes 21/09/2007 17:31:02
AVARKT.DLL : 1.0.0.20 278568 Bytes 21/09/2007 17:31:02
AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 21/09/2007 17:31:02
NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 10:09:42
RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 21/09/2007 17:30:54
RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/09/2007 17:30:54
SQLITE3.DLL : 3.3.17.1 339968 Bytes 21/09/2007 17:31:03

Configuration settings for the scan:
Jobname..........................: Manual Selection
Configuration file...............: C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic\PROFILES\folder.avp
Logging..........................: low
Primary action...................: interactive
Secondary action.................: ignore
Scan master boot sector..........: off
Scan boot sector.................: on
Boot sectors.....................: C:,
Scan memory......................: on
Process scan.....................: on
Scan registry....................: on
Search for rootkits..............: off
Scan all files...................: All files
Scan archives....................: on
Recursion depth..................: 20
Smart extensions.................: on
Macro heuristic..................: on
File heuristic...................: medium

Start of the scan: vendredi 21 septembre 2007 19:36

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'sched.exe' - '1' Module(s) have been scanned
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'usnsvc.exe' - '1' Module(s) have been scanned
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Scan process 'cmkewv.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'iexplore.exe' - '1' Module(s) have been scanned
Scan process 'jusched.exe' - '1' Module(s) have been scanned
Scan process 'E_FATI9EE.EXE' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'alg.exe' - '1' Module(s) have been scanned
Scan process 'tomcat5.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
Scan process 'guard.exe' - '0' Module(s) have been scanned
Scan process 'ashServ.exe' - '1' Module(s) have been scanned
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
34 processes with 34 modules were scanned

Start scanning boot sectors:
Boot sector 'C:\'
[NOTE] No virus was found!

Starting to scan the registry.
The registry was scanned ( '32' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Daniel\Ma musique\ALBUM - Corneille.ace
[0] Archive type: ACE
--> Corneille Parce Qu'On Vient De Loin - MP3 - 2003 - By The Dude\05-Rˆves_De_Star.mp3
[WARNING] Error creating the file
--> Corneille Parce Qu'On Vient De Loin - MP3 - 2003 - By The Dude\06-Avec_Classe.mp3
[WARNING] No further files can be extracted from this archive. The archive will be closed
[WARNING] No further files can be extracted from this archive. The archive will be closed
C:\Documents and Settings\All Users\Application Data\Delete Hide Support Math\curb bash.exe
[DETECTION] Is the Trojan horse TR/Dldr.Swizzor.Gen
[INFO] The file was moved to '476609f1.qua'!
C:\Documents and Settings\Camille\Application Data\army file bows\Mfcd Default Rect Dupe.exe
[DETECTION] Is the Trojan horse TR/Obfuscated.EN.493
[INFO] The file was moved to '47570a1c.qua'!
C:\Documents and Settings\Camille\Application Data\army file bows\MultiSecondActive.exe
[DETECTION] Is the Trojan horse TR/Obfuscated.EN.53
[INFO] The file was moved to '47600a2f.qua'!
C:\Documents and Settings\Camille\Application Data\army file bows\qyybquac.exe
[DETECTION] Is the Trojan horse TR/FatObfus.2.Gen
[INFO] The file was moved to '476d0a36.qua'!
C:\Documents and Settings\Camille\Application Data\army file bows\SoftwareAxis.exe
[DETECTION] Is the Trojan horse TR/Obfuscated.EN.497
[INFO] The file was moved to '475a0a2e.qua'!
C:\Documents and Settings\Camille\Local Settings\Temp\sta1.exe
[DETECTION] Is the Trojan horse TR/Obfuscated.EN.497
[INFO] The file was moved to '47550ac3.qua'!
C:\Documents and Settings\Jonathan\qlriie.exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Bifrose.NU Backdoor server programs
[INFO] The file was moved to '47660c24.qua'!
C:\Documents and Settings\Jonathan\zpszuw.exe
[DETECTION] Contains a detection pattern of the (dangerous) backdoor program BDS/Bifrose.NU Backdoor server programs
[INFO] The file was moved to '47670c31.qua'!
Catched Exception ScanDirectory:
ACCESS_VIOLATION
EAX = 00184000 EBX = 00000001
ECX = 003C006C EDX = B7030004
ESI = 003C48A8 EDI = 00000000
EIP = 77C17FD4 EBP = 0246E17C
ESP = 0246E17C Flg = 00010206
CS = 00000023 SS = 0000001B


End of the scan: vendredi 21 septembre 2007 20:23
Used time: 47:01 min

The scan has been done completely.

2725 Scanning directories
354381 Files were scanned
8 viruses and/or unwanted programs were found
0 Files were classified as suspicious:
0 files were deleted
0 files were repaired
8 files were moved to quarantine
0 files were renamed
1 Files cannot be scanned
354373 Files not concerned
2088 Archives were scanned
4 Warnings
0 Notes




Répondre à bugland

Malgrès la désinfection de certain virus le problème de ces pub persiste.
Et il y a un truc très bizarre aussi, je n'arrive pas à lancer Navilog1 pourtant je l'ai désintaller et reinstaller impossible de le lancer.


Message édité par bugland le 22-09-2007 à 10:12:17
Répondre à bugland

Tu peux refaire un scan LopResearch ?

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Voila le scan Lpresearch :

Citation :



----------------------------[ LopResearch v3 ]----------------------------

Version : Microsoft Windows XP [version 5.1.2600] [ OS : Windows_NT ]

Lancé depuis : C:\Documents and Settings\Jonathan\Bureau\LopResearch v3.1

Rapport crée : Le 22/09/2007 à 12:05:36,37 PC : JON

! Faire analyser le rapport par un Helper avant intervention !

---------------------[ Listing des Applications Data ]--------------------

C:\Documents and Settings\All Users\Application Data\Delete Hide Support Math
C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
C:\Documents and Settings\All Users\Application Data\addr_file.html
C:\Documents and Settings\All Users\Application Data\Apple Computer
C:\Documents and Settings\All Users\Application Data\Grisoft
C:\Documents and Settings\All Users\Application Data\title tool face bin
C:\Documents and Settings\All Users\Application Data\wave log show title
C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
C:\Documents and Settings\All Users\Application Data\avg7
C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Documents and Settings\All Users\Application Data\UDL
C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
C:\Documents and Settings\All Users\Application Data\desktop.ini
C:\Documents and Settings\All Users\Application Data\nView_Profiles

C:\Documents and Settings\Camille\Application Data\army file bows
C:\Documents and Settings\Camille\Application Data\AVG7
C:\Documents and Settings\Camille\Application Data\Microsoft
C:\Documents and Settings\Camille\Application Data\Real
C:\Documents and Settings\Camille\Application Data\Symantec
C:\Documents and Settings\Camille\Application Data\Notepad++
C:\Documents and Settings\Camille\Application Data\SolidWorks
C:\Documents and Settings\Camille\Application Data\DWGeditor
C:\Documents and Settings\Camille\Application Data\Creative
C:\Documents and Settings\Camille\Application Data\Morpheus
C:\Documents and Settings\Camille\Application Data\MessengerSkinner
C:\Documents and Settings\Camille\Application Data\Apple Computer
C:\Documents and Settings\Camille\Application Data\Adobe
C:\Documents and Settings\Camille\Application Data\vlc
C:\Documents and Settings\Camille\Application Data\Media Player Classic
C:\Documents and Settings\Camille\Application Data\Help
C:\Documents and Settings\Camille\Application Data\Sun
C:\Documents and Settings\Camille\Application Data\AdobeUM
C:\Documents and Settings\Camille\Application Data\Macromedia
C:\Documents and Settings\Camille\Application Data\Mozilla
C:\Documents and Settings\Camille\Application Data\Logitech
C:\Documents and Settings\Camille\Application Data\Identities
C:\Documents and Settings\Camille\Application Data\desktop.ini

C:\Documents and Settings\dan\Application Data\Mozilla

C:\Documents and Settings\Default User\Application Data\desktop.ini
C:\Documents and Settings\Default User\Application Data\Microsoft

C:\Documents and Settings\Jonathan\Application Data\army file bows
C:\Documents and Settings\Jonathan\Application Data\Screenshot Sender
C:\Documents and Settings\Jonathan\Application Data\Microsoft
C:\Documents and Settings\Jonathan\Application Data\AVG7
C:\Documents and Settings\Jonathan\Application Data\Adobe
C:\Documents and Settings\Jonathan\Application Data\uTorrent
C:\Documents and Settings\Jonathan\Application Data\AdobeUM
C:\Documents and Settings\Jonathan\Application Data\Notepad++
C:\Documents and Settings\Jonathan\Application Data\Creative
C:\Documents and Settings\Jonathan\Application Data\Morpheus
C:\Documents and Settings\Jonathan\Application Data\Apple Computer
C:\Documents and Settings\Jonathan\Application Data\Macromedia
C:\Documents and Settings\Jonathan\Application Data\Ahead
C:\Documents and Settings\Jonathan\Application Data\Sun
C:\Documents and Settings\Jonathan\Application Data\Media Player Classic
C:\Documents and Settings\Jonathan\Application Data\.ABC 3.01
C:\Documents and Settings\Jonathan\Application Data\Help
C:\Documents and Settings\Jonathan\Application Data\vlc
C:\Documents and Settings\Jonathan\Application Data\dvdcss
C:\Documents and Settings\Jonathan\Application Data\Microsoft Web Folders
C:\Documents and Settings\Jonathan\Application Data\Symantec
C:\Documents and Settings\Jonathan\Application Data\FotoWire
C:\Documents and Settings\Jonathan\Application Data\Logitech
C:\Documents and Settings\Jonathan\Application Data\Mozilla
C:\Documents and Settings\Jonathan\Application Data\desktop.ini
C:\Documents and Settings\Jonathan\Application Data\Identities

C:\Documents and Settings\LocalService\Application Data\Microsoft
C:\Documents and Settings\LocalService\Application Data\AVG7

C:\Documents and Settings\NetworkService\Application Data\Microsoft
C:\Documents and Settings\NetworkService\Application Data\Symantec

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

C:\WINDOWS\tasks\A7E7BDD091D42E90.job
C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\SA.DAT
C:\WINDOWS\tasks\desktop.ini

--------------[ Listing des dossiers dans C:\Program Files ]--------------

C:\Program Files\ABC
C:\Program Files\Adobe
C:\Program Files\Ahead
C:\Program Files\Alwil Software
C:\Program Files\AMD
C:\Program Files\AntiVir PersonalEdition Classic
C:\Program Files\Apache Software Foundation
C:\Program Files\Apple Software Update
C:\Program Files\army file bows
C:\Program Files\AtomixMP3
C:\Program Files\Audible
C:\Program Files\AvRack
C:\Program Files\AWicons Pro
C:\Program Files\Bible
C:\Program Files\BSW
C:\Program Files\CCleaner
C:\Program Files\CDBurnerXP Pro 3
C:\Program Files\CodeBlocks
C:\Program Files\Common Files
C:\Program Files\ComPlus Applications
C:\Program Files\Comptes et Budget Free V5.0
C:\Program Files\Creative
C:\Program Files\DivX
C:\Program Files\EasyPHP1-8
C:\Program Files\epson
C:\Program Files\Everest Poker
C:\Program Files\FairStars Audio Converter
C:\Program Files\Fichiers communs
C:\Program Files\FileZilla
C:\Program Files\GiveMeTac 1.1
C:\Program Files\Grisoft
C:\Program Files\Guitar Pro 5
C:\Program Files\I.P.E
C:\Program Files\Internet Explorer
C:\Program Files\iTunes
C:\Program Files\Java
C:\Program Files\K-Lite Codec Pack
C:\Program Files\Logitech
C:\Program Files\Messenger
C:\Program Files\MessengerSkinner
C:\Program Files\Microsoft CAPICOM 2.1.0.2
C:\Program Files\microsoft frontpage
C:\Program Files\Microsoft Office
C:\Program Files\Microsoft Visual Studio
C:\Program Files\Microsoft Visual Studio .NET
C:\Program Files\Microsoft Visual Studio .NET 2003
C:\Program Files\Microsoft.NET
C:\Program Files\Morpheus
C:\Program Files\Movie Maker
C:\Program Files\Mozilla Firefox
C:\Program Files\MP3 Player Utilities
C:\Program Files\MSI
C:\Program Files\MSN
C:\Program Files\MSN Gaming Zone
C:\Program Files\MSN Messenger
C:\Program Files\MUSICMATCH
C:\Program Files\Navilog1
C:\Program Files\NetMeeting
C:\Program Files\Neuf
C:\Program Files\Norton SystemWorks
C:\Program Files\Notepad++
C:\Program Files\NVIDIA Corporation
C:\Program Files\Online Services
C:\Program Files\Outlook Express
C:\Program Files\Publication Web
C:\Program Files\Real
C:\Program Files\Realtek Sound Manager
C:\Program Files\Services en ligne
C:\Program Files\Smart Panel
C:\Program Files\SnIco Edit
C:\Program Files\softnyx
C:\Program Files\Sophos SWEEP for NT
C:\Program Files\Symantec
C:\Program Files\uTorrent
C:\Program Files\VideoLAN
C:\Program Files\Web Publish
C:\Program Files\Windows Live Safety Center
C:\Program Files\Windows Live Toolbar
C:\Program Files\Windows Media Connect 2
C:\Program Files\Windows Media Player
C:\Program Files\Windows NT
C:\Program Files\WinRAR
C:\Program Files\xerox
C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]-----

C:\Program Files\Fichiers communs\Adobe
C:\Program Files\Fichiers communs\Ahead
C:\Program Files\Fichiers communs\Bluebeam Software
C:\Program Files\Fichiers communs\Designer
C:\Program Files\Fichiers communs\eDrawings2006
C:\Program Files\Fichiers communs\FotoWire
C:\Program Files\Fichiers communs\InstallShield
C:\Program Files\Fichiers communs\Java
C:\Program Files\Fichiers communs\Logitech
C:\Program Files\Fichiers communs\Microsoft Shared
C:\Program Files\Fichiers communs\MSSoap
C:\Program Files\Fichiers communs\ODBC
C:\Program Files\Fichiers communs\Real
C:\Program Files\Fichiers communs\Services
C:\Program Files\Fichiers communs\Solidworks Data
C:\Program Files\Fichiers communs\SpeechEngines
C:\Program Files\Fichiers communs\Symantec Shared
C:\Program Files\Fichiers communs\System
C:\Program Files\Fichiers communs\WhenU

----------------------[ Recherche dans le Registre ]----------------------

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]


-----------------[ Recherche de Fichiers - Dossiers Lop ]-----------------

C:\WINDOWS\tasks\A7E7BDD091D42E90.job

--------------------[ Vérification du fichier Hosts ]---------------------

Fichier Hosts : Propre

--------------------[ Recherche d'autres infections ]---------------------

C:\WINDOWS\pack.epk
C:\WINDOWS\system32\nvs2.inf

! EGDACCESS Possible !


--------------------[ Fin du rapport à 12:05:49,03 ]----------------------


Répondre à bugland

Re,

Télécharge Blacklight (F-Secure), clique sur " I ACCEPT " en bas de la page :
Clique sur le premier " Download " afin de télécharger le programme
Sauvegarde le sur ton Bureau
Double-clique fsbl.exe et accepte la licence; clique Scan puis Next.

A la fin du scan, NE TOUCHE A RIEN !

Tu verras un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).
Nous devons analyser ce rapport, ferme donc le BlackLight.

Poste le rapport sur le forum.

AIDE : Tuto sur BlackLight (Malekal)

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Voila le nouveau rapport :

Citation :


09/22/07 12:18:56 [Info]: BlackLight Engine 1.0.64 initialized
09/22/07 12:18:56 [Info]: OS: 5.1 build 2600 (Service Pack 2)
09/22/07 12:18:59 [Note]: 7019 4
09/22/07 12:18:59 [Note]: 7005 0
09/22/07 12:19:04 [Note]: 7006 0
09/22/07 12:19:04 [Note]: 7011 2032
09/22/07 12:19:04 [Note]: 7026 0
09/22/07 12:19:04 [Note]: 7026 0
09/22/07 12:19:04 [Note]: 7024 3
09/22/07 12:19:04 [Info]: Hidden process: c:\windows\system32\veambqrw.exe
09/22/07 12:19:16 [Note]: FSRAW library version 1.7.1022
09/22/07 12:45:46 [Info]: Hidden file: c:\WINDOWS\system32\veambqrw.dat
09/22/07 12:45:46 [Note]: 10002 1
09/22/07 12:45:47 [Info]: Hidden file: c:\windows\system32\veambqrw.exe
09/22/07 12:45:47 [Note]: 10002 1
09/22/07 12:45:48 [Info]: Hidden file: c:\WINDOWS\system32\veambqrw_nav.dat
09/22/07 12:45:48 [Note]: 10002 1
09/22/07 12:45:49 [Info]: Hidden file: c:\WINDOWS\system32\veambqrw_navps.dat
09/22/07 12:45:49 [Note]: 10002 1
09/22/07 12:45:50 [Info]: Hidden file: c:\WINDOWS\system32\veambqrw_navup.dat
09/22/07 12:45:50 [Note]: 10002 1
09/22/07 13:01:09 [Note]: 2000 1012
09/22/07 13:01:09 [Note]: 2000 1012


Répondre à bugland

Re,

La procédure est longue et en partie en mode sans échec,
imprime ou mets dans un fichier texte les instructions.
Les manipulations sont à faire sans interruption et dans l'ordre.
Si tu ne comprends pas quelque chose, demande des explications avant de commencer.


Télécharge:

Brute Force Uninstaller
Créé un nouveau dossier directement sur le C:\ et nomme-le BFU. Décompresse le fichier téléchargé dans ce nouveau dossier (C:\BFU)

FAIS UN CLIC-DROIT ICI et choisis "Enregistrer la cible sous..." afin de
télécharger EGDACCESS.bfu (de Metallica). Sauvegarde dans le dossier créé (C:\BFU). **Note : si tu utlises Internet Explorer; lors de la sauvegarde, assure-toi que le champs "Type :" affiche "Tous les fichiers". Tu dois maintenant avoir deux fichiers dans le dossier C:\BFU : EGDACCESS.bfu et BFU.exe (très important).

Ouvre le Bloc-Notes et copie-colle les lignes en bleu ci-dessous :

RegDeleteKey HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\veambqrw
RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|veambqrw
FileDelete %SYSDIR%\veambqrw_navps.dat
FileDelete %SYSDIR%\veambqrw_nav.dat
FileDelete %SYSDIR%\veambqrw.dat
FileDelete %SYSDIR%\veambqrw.exe
FileDelete %WINDIR%\PREFETCH\veambqrw.exe*.pf

SystemEmptyRecycleBin

FileDelete C:\egd.txt
SystemRun regedit|/e C:\egd.txt "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run"|0

OptionBFUExit


Sauvegarde dans le dossier créé (C:\BFU) (Nom du fichier : "Fixme.bfu " -sans inclure les guillemets- ; Type : Tous les fichiers).

Redémarre en mode Sans Échec : au redémarrage, tapote immédiatement la touche F8; tu verras un écran avec choix de démarrages apparaître. Utilisant les flèches du clavier, choisis "Mode Sans Échec" et valide avec "Entrée". Choisis ton compte usuel, et non Administrateur.

Démarre le "Brute Force Uninstaller" en double-cliquant BFU.exe (du dossier C:\BFU)

- Clique sur le petit dossier jaune, à la droite de la boîte Scriptline to execute, et double-clique sur :

EGDACCESS.bfu

- Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\EGDACCESS.bfu

Clique sur Execute et laisse-le faire son travail.

Attendre que Complete script execution apparaîsse et clique sur OK.
Clique Exit pour fermer le programme BFU.

Relance ensuite BFU
- Clique sur le petit dossier jaune, à la droite de la boîte Scriptline to execute, et double-clique sur :

Fixme.bfu

Clique sur Execute et laisse-le faire son travail.

Redémarre normalement.

Poste les rapports situés ici :
C:\egd.txt
accompagné d'un rapport Hijackthis.

NOTE :

Si tu ne sais pas où trouver le Bloc-Notes, voici comment le trouver rapidement :
Démarrer-> Exécuter...-> Tape Notepad puis valide

AIDE : Tuto de Lazzzy

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

J'ai pas bien compris ce que c'était le champs type??

Répondre à bugland

Lorsque tu fais Enregistrer Sous... tu as Type : en bas.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

J'ai bien suivi toute la procédure donc voici le premier rapport de egd :

Citation :


Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
"NeroCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"EPSON Stylus CX6600 Series"="C:\\WINDOWS\\System32\\spool\\DRIVERS\\W32X86\\3\\E_FATI9EE.EXE /P26 \"EPSON Stylus CX6600 Series\" /O6 \"USB002\" /M \"Stylus CX6600\""
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_02\\bin\\jusched.exe\""
"face bin load show"="C:\\Documents and Settings\\All Users\\Application Data\\title tool face bin\\Fast Dash.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
"qmllozbpie"="c:\\windows\\system32\\qmllozbpie.exe qmllozbpie"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"NoChange"="1"
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"





Et voici le rapport Hijackthis :

Citation :


Logfile of HijackThis v1.99.1
Scan saved at 20:18:01, on 22/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Jonathan\Bureau\Outils de netoyage virus\hijackthis\HijackThisAide.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB002" /M "Stylus CX6600"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [face bin load show] C:\Documents and Settings\All Users\Application Data\title tool face bin\Fast Dash.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?2bda6f0555224614989493e51d1d0f37
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?2bda6f0555224614989493e51d1d0f37
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bugland1985.spaces.live.com [...] nPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)



Répondre à bugland

Refais un scan LopResearch maintenant.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Voici le rapport LopResearch :

Citation :



----------------------------[ LopResearch v3 ]----------------------------

Version : Microsoft Windows XP [version 5.1.2600] [ OS : Windows_NT ]

Lancé depuis : C:\Documents and Settings\Jonathan\Bureau\LopResearch v3.1

Rapport crée : Le 23/09/2007 à 13:49:53,98 PC : JON

! Faire analyser le rapport par un Helper avant intervention !

---------------------[ Listing des Applications Data ]--------------------

C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
C:\Documents and Settings\All Users\Application Data\Delete Hide Support Math
C:\Documents and Settings\All Users\Application Data\addr_file.html
C:\Documents and Settings\All Users\Application Data\Apple Computer
C:\Documents and Settings\All Users\Application Data\Grisoft
C:\Documents and Settings\All Users\Application Data\title tool face bin
C:\Documents and Settings\All Users\Application Data\wave log show title
C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
C:\Documents and Settings\All Users\Application Data\avg7
C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Documents and Settings\All Users\Application Data\UDL
C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
C:\Documents and Settings\All Users\Application Data\desktop.ini
C:\Documents and Settings\All Users\Application Data\nView_Profiles

C:\Documents and Settings\Camille\Application Data\army file bows
C:\Documents and Settings\Camille\Application Data\AVG7
C:\Documents and Settings\Camille\Application Data\Microsoft
C:\Documents and Settings\Camille\Application Data\Real
C:\Documents and Settings\Camille\Application Data\Symantec
C:\Documents and Settings\Camille\Application Data\Notepad++
C:\Documents and Settings\Camille\Application Data\SolidWorks
C:\Documents and Settings\Camille\Application Data\DWGeditor
C:\Documents and Settings\Camille\Application Data\Creative
C:\Documents and Settings\Camille\Application Data\Morpheus
C:\Documents and Settings\Camille\Application Data\MessengerSkinner
C:\Documents and Settings\Camille\Application Data\Apple Computer
C:\Documents and Settings\Camille\Application Data\Adobe
C:\Documents and Settings\Camille\Application Data\vlc
C:\Documents and Settings\Camille\Application Data\Media Player Classic
C:\Documents and Settings\Camille\Application Data\Help
C:\Documents and Settings\Camille\Application Data\Sun
C:\Documents and Settings\Camille\Application Data\AdobeUM
C:\Documents and Settings\Camille\Application Data\Macromedia
C:\Documents and Settings\Camille\Application Data\Mozilla
C:\Documents and Settings\Camille\Application Data\Logitech
C:\Documents and Settings\Camille\Application Data\Identities
C:\Documents and Settings\Camille\Application Data\desktop.ini

C:\Documents and Settings\dan\Application Data\Mozilla

C:\Documents and Settings\Default User\Application Data\desktop.ini
C:\Documents and Settings\Default User\Application Data\Microsoft

C:\Documents and Settings\Jonathan\Application Data\army file bows
C:\Documents and Settings\Jonathan\Application Data\Screenshot Sender
C:\Documents and Settings\Jonathan\Application Data\Microsoft
C:\Documents and Settings\Jonathan\Application Data\AVG7
C:\Documents and Settings\Jonathan\Application Data\Adobe
C:\Documents and Settings\Jonathan\Application Data\uTorrent
C:\Documents and Settings\Jonathan\Application Data\AdobeUM
C:\Documents and Settings\Jonathan\Application Data\Notepad++
C:\Documents and Settings\Jonathan\Application Data\Creative
C:\Documents and Settings\Jonathan\Application Data\Morpheus
C:\Documents and Settings\Jonathan\Application Data\Apple Computer
C:\Documents and Settings\Jonathan\Application Data\Macromedia
C:\Documents and Settings\Jonathan\Application Data\Ahead
C:\Documents and Settings\Jonathan\Application Data\Sun
C:\Documents and Settings\Jonathan\Application Data\Media Player Classic
C:\Documents and Settings\Jonathan\Application Data\.ABC 3.01
C:\Documents and Settings\Jonathan\Application Data\Help
C:\Documents and Settings\Jonathan\Application Data\vlc
C:\Documents and Settings\Jonathan\Application Data\dvdcss
C:\Documents and Settings\Jonathan\Application Data\Microsoft Web Folders
C:\Documents and Settings\Jonathan\Application Data\Symantec
C:\Documents and Settings\Jonathan\Application Data\FotoWire
C:\Documents and Settings\Jonathan\Application Data\Logitech
C:\Documents and Settings\Jonathan\Application Data\Mozilla
C:\Documents and Settings\Jonathan\Application Data\desktop.ini
C:\Documents and Settings\Jonathan\Application Data\Identities

C:\Documents and Settings\LocalService\Application Data\Microsoft
C:\Documents and Settings\LocalService\Application Data\AVG7

C:\Documents and Settings\NetworkService\Application Data\Microsoft
C:\Documents and Settings\NetworkService\Application Data\Symantec

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

C:\WINDOWS\tasks\A7E7BDD091D42E90.job
C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\SA.DAT
C:\WINDOWS\tasks\desktop.ini

--------------[ Listing des dossiers dans C:\Program Files ]--------------

C:\Program Files\ABC
C:\Program Files\Adobe
C:\Program Files\Ahead
C:\Program Files\Alwil Software
C:\Program Files\AMD
C:\Program Files\AntiVir PersonalEdition Classic
C:\Program Files\Apache Software Foundation
C:\Program Files\Apple Software Update
C:\Program Files\army file bows
C:\Program Files\AtomixMP3
C:\Program Files\Audible
C:\Program Files\AvRack
C:\Program Files\AWicons Pro
C:\Program Files\Bible
C:\Program Files\BSW
C:\Program Files\CCleaner
C:\Program Files\CDBurnerXP Pro 3
C:\Program Files\CodeBlocks
C:\Program Files\Common Files
C:\Program Files\ComPlus Applications
C:\Program Files\Comptes et Budget Free V5.0
C:\Program Files\Creative
C:\Program Files\DivX
C:\Program Files\EasyPHP1-8
C:\Program Files\epson
C:\Program Files\Everest Poker
C:\Program Files\FairStars Audio Converter
C:\Program Files\Fichiers communs
C:\Program Files\FileZilla
C:\Program Files\GiveMeTac 1.1
C:\Program Files\Grisoft
C:\Program Files\Guitar Pro 5
C:\Program Files\I.P.E
C:\Program Files\Internet Explorer
C:\Program Files\iTunes
C:\Program Files\Java
C:\Program Files\K-Lite Codec Pack
C:\Program Files\Logitech
C:\Program Files\Messenger
C:\Program Files\Microsoft CAPICOM 2.1.0.2
C:\Program Files\microsoft frontpage
C:\Program Files\Microsoft Office
C:\Program Files\Microsoft Visual Studio
C:\Program Files\Microsoft Visual Studio .NET
C:\Program Files\Microsoft Visual Studio .NET 2003
C:\Program Files\Microsoft.NET
C:\Program Files\Morpheus
C:\Program Files\Movie Maker
C:\Program Files\Mozilla Firefox
C:\Program Files\MP3 Player Utilities
C:\Program Files\MSI
C:\Program Files\MSN
C:\Program Files\MSN Gaming Zone
C:\Program Files\MSN Messenger
C:\Program Files\MUSICMATCH
C:\Program Files\Navilog1
C:\Program Files\NetMeeting
C:\Program Files\Neuf
C:\Program Files\Norton SystemWorks
C:\Program Files\Notepad++
C:\Program Files\NVIDIA Corporation
C:\Program Files\Online Services
C:\Program Files\Outlook Express
C:\Program Files\Publication Web
C:\Program Files\Real
C:\Program Files\Realtek Sound Manager
C:\Program Files\Services en ligne
C:\Program Files\Smart Panel
C:\Program Files\SnIco Edit
C:\Program Files\softnyx
C:\Program Files\Sophos SWEEP for NT
C:\Program Files\Symantec
C:\Program Files\uTorrent
C:\Program Files\VideoLAN
C:\Program Files\Web Publish
C:\Program Files\Windows Live Safety Center
C:\Program Files\Windows Live Toolbar
C:\Program Files\Windows Media Connect 2
C:\Program Files\Windows Media Player
C:\Program Files\Windows NT
C:\Program Files\WinRAR
C:\Program Files\xerox
C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]-----

C:\Program Files\Fichiers communs\Adobe
C:\Program Files\Fichiers communs\Ahead
C:\Program Files\Fichiers communs\Bluebeam Software
C:\Program Files\Fichiers communs\Designer
C:\Program Files\Fichiers communs\eDrawings2006
C:\Program Files\Fichiers communs\FotoWire
C:\Program Files\Fichiers communs\InstallShield
C:\Program Files\Fichiers communs\Java
C:\Program Files\Fichiers communs\Logitech
C:\Program Files\Fichiers communs\Microsoft Shared
C:\Program Files\Fichiers communs\MSSoap
C:\Program Files\Fichiers communs\ODBC
C:\Program Files\Fichiers communs\Real
C:\Program Files\Fichiers communs\Services
C:\Program Files\Fichiers communs\Solidworks Data
C:\Program Files\Fichiers communs\SpeechEngines
C:\Program Files\Fichiers communs\Symantec Shared
C:\Program Files\Fichiers communs\System
C:\Program Files\Fichiers communs\WhenU

----------------------[ Recherche dans le Registre ]----------------------

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]


-----------------[ Recherche de Fichiers - Dossiers Lop ]-----------------

C:\WINDOWS\tasks\A7E7BDD091D42E90.job

--------------------[ Vérification du fichier Hosts ]---------------------

Fichier Hosts : Propre

--------------------[ Recherche d'autres infections ]---------------------

C:\WINDOWS\pack.epk

! EGDACCESS Possible !


--------------------[ Fin du rapport à 13:50:02,96 ]----------------------


Répondre à bugland

Re,

Supprime ce fichier :
C:\WINDOWS\pack.epk

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

C'est bon c'est fait.

Répondre à bugland

Supprime LopResearch puis recommence.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Euh comment ca je recommence?
Si je supprime LopResearch je peux pas recommencer?

Répondre à bugland

Tu le supprime puis retélécharge :)

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Ok je vais le supprimer et je le retélécharge puis je poste le rapport.

En tout cas merci beaucoup pour toutes l'aide que tu m'apporte je t'en suis très reconnaissant.

Répondre à bugland

Mon rapport LopResearch :


Citation :



----------------------------[ LopResearch v3 ]----------------------------

Version : Microsoft Windows XP [version 5.1.2600] [ OS : Windows_NT ]

Lancé depuis : C:\Documents and Settings\Jonathan\Bureau\LopResearch v3.1

Rapport crée : Le 23/09/2007 à 19:14:15,62 PC : JON

! Faire analyser le rapport par un Helper avant intervention !

---------------------[ Listing des Applications Data ]--------------------

C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic
C:\Documents and Settings\All Users\Application Data\Delete Hide Support Math
C:\Documents and Settings\All Users\Application Data\addr_file.html
C:\Documents and Settings\All Users\Application Data\Apple Computer
C:\Documents and Settings\All Users\Application Data\Grisoft
C:\Documents and Settings\All Users\Application Data\title tool face bin
C:\Documents and Settings\All Users\Application Data\wave log show title
C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
C:\Documents and Settings\All Users\Application Data\avg7
C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Symantec
C:\Documents and Settings\All Users\Application Data\UDL
C:\Documents and Settings\All Users\Application Data\Windows Live Toolbar
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
C:\Documents and Settings\All Users\Application Data\desktop.ini
C:\Documents and Settings\All Users\Application Data\nView_Profiles

C:\Documents and Settings\Camille\Application Data\army file bows
C:\Documents and Settings\Camille\Application Data\AVG7
C:\Documents and Settings\Camille\Application Data\Microsoft
C:\Documents and Settings\Camille\Application Data\Real
C:\Documents and Settings\Camille\Application Data\Symantec
C:\Documents and Settings\Camille\Application Data\Notepad++
C:\Documents and Settings\Camille\Application Data\SolidWorks
C:\Documents and Settings\Camille\Application Data\DWGeditor
C:\Documents and Settings\Camille\Application Data\Creative
C:\Documents and Settings\Camille\Application Data\Morpheus
C:\Documents and Settings\Camille\Application Data\MessengerSkinner
C:\Documents and Settings\Camille\Application Data\Apple Computer
C:\Documents and Settings\Camille\Application Data\Adobe
C:\Documents and Settings\Camille\Application Data\vlc
C:\Documents and Settings\Camille\Application Data\Media Player Classic
C:\Documents and Settings\Camille\Application Data\Help
C:\Documents and Settings\Camille\Application Data\Sun
C:\Documents and Settings\Camille\Application Data\AdobeUM
C:\Documents and Settings\Camille\Application Data\Macromedia
C:\Documents and Settings\Camille\Application Data\Mozilla
C:\Documents and Settings\Camille\Application Data\Logitech
C:\Documents and Settings\Camille\Application Data\Identities
C:\Documents and Settings\Camille\Application Data\desktop.ini

C:\Documents and Settings\dan\Application Data\Mozilla

C:\Documents and Settings\Default User\Application Data\desktop.ini
C:\Documents and Settings\Default User\Application Data\Microsoft

C:\Documents and Settings\Jonathan\Application Data\army file bows
C:\Documents and Settings\Jonathan\Application Data\Screenshot Sender
C:\Documents and Settings\Jonathan\Application Data\Microsoft
C:\Documents and Settings\Jonathan\Application Data\AVG7
C:\Documents and Settings\Jonathan\Application Data\Adobe
C:\Documents and Settings\Jonathan\Application Data\uTorrent
C:\Documents and Settings\Jonathan\Application Data\AdobeUM
C:\Documents and Settings\Jonathan\Application Data\Notepad++
C:\Documents and Settings\Jonathan\Application Data\Creative
C:\Documents and Settings\Jonathan\Application Data\Morpheus
C:\Documents and Settings\Jonathan\Application Data\Apple Computer
C:\Documents and Settings\Jonathan\Application Data\Macromedia
C:\Documents and Settings\Jonathan\Application Data\Ahead
C:\Documents and Settings\Jonathan\Application Data\Sun
C:\Documents and Settings\Jonathan\Application Data\Media Player Classic
C:\Documents and Settings\Jonathan\Application Data\.ABC 3.01
C:\Documents and Settings\Jonathan\Application Data\Help
C:\Documents and Settings\Jonathan\Application Data\vlc
C:\Documents and Settings\Jonathan\Application Data\dvdcss
C:\Documents and Settings\Jonathan\Application Data\Microsoft Web Folders
C:\Documents and Settings\Jonathan\Application Data\Symantec
C:\Documents and Settings\Jonathan\Application Data\FotoWire
C:\Documents and Settings\Jonathan\Application Data\Logitech
C:\Documents and Settings\Jonathan\Application Data\Mozilla
C:\Documents and Settings\Jonathan\Application Data\desktop.ini
C:\Documents and Settings\Jonathan\Application Data\Identities

C:\Documents and Settings\LocalService\Application Data\Microsoft
C:\Documents and Settings\LocalService\Application Data\AVG7

C:\Documents and Settings\NetworkService\Application Data\Microsoft
C:\Documents and Settings\NetworkService\Application Data\Symantec

----------------[ Tâches planifiées dans C:\WINDOWS\tasks ]---------------

C:\WINDOWS\tasks\A7E7BDD091D42E90.job
C:\WINDOWS\tasks\V‚rifier les mises … jour de Windows Live Toolbar.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\SA.DAT
C:\WINDOWS\tasks\desktop.ini

--------------[ Listing des dossiers dans C:\Program Files ]--------------

C:\Program Files\ABC
C:\Program Files\Adobe
C:\Program Files\Ahead
C:\Program Files\Alwil Software
C:\Program Files\AMD
C:\Program Files\AntiVir PersonalEdition Classic
C:\Program Files\Apache Software Foundation
C:\Program Files\Apple Software Update
C:\Program Files\army file bows
C:\Program Files\AtomixMP3
C:\Program Files\Audible
C:\Program Files\AvRack
C:\Program Files\AWicons Pro
C:\Program Files\Bible
C:\Program Files\BSW
C:\Program Files\CCleaner
C:\Program Files\CDBurnerXP Pro 3
C:\Program Files\CodeBlocks
C:\Program Files\Common Files
C:\Program Files\ComPlus Applications
C:\Program Files\Comptes et Budget Free V5.0
C:\Program Files\Creative
C:\Program Files\DivX
C:\Program Files\EasyPHP1-8
C:\Program Files\epson
C:\Program Files\Everest Poker
C:\Program Files\FairStars Audio Converter
C:\Program Files\Fichiers communs
C:\Program Files\FileZilla
C:\Program Files\GiveMeTac 1.1
C:\Program Files\Grisoft
C:\Program Files\Guitar Pro 5
C:\Program Files\I.P.E
C:\Program Files\Internet Explorer
C:\Program Files\iTunes
C:\Program Files\Java
C:\Program Files\K-Lite Codec Pack
C:\Program Files\Logitech
C:\Program Files\Messenger
C:\Program Files\Microsoft CAPICOM 2.1.0.2
C:\Program Files\microsoft frontpage
C:\Program Files\Microsoft Office
C:\Program Files\Microsoft Visual Studio
C:\Program Files\Microsoft Visual Studio .NET
C:\Program Files\Microsoft Visual Studio .NET 2003
C:\Program Files\Microsoft.NET
C:\Program Files\Morpheus
C:\Program Files\Movie Maker
C:\Program Files\Mozilla Firefox
C:\Program Files\MP3 Player Utilities
C:\Program Files\MSI
C:\Program Files\MSN
C:\Program Files\MSN Gaming Zone
C:\Program Files\MSN Messenger
C:\Program Files\MUSICMATCH
C:\Program Files\Navilog1
C:\Program Files\NetMeeting
C:\Program Files\Neuf
C:\Program Files\Norton SystemWorks
C:\Program Files\Notepad++
C:\Program Files\NVIDIA Corporation
C:\Program Files\Online Services
C:\Program Files\Outlook Express
C:\Program Files\Publication Web
C:\Program Files\Real
C:\Program Files\Realtek Sound Manager
C:\Program Files\Services en ligne
C:\Program Files\Smart Panel
C:\Program Files\SnIco Edit
C:\Program Files\softnyx
C:\Program Files\Sophos SWEEP for NT
C:\Program Files\Symantec
C:\Program Files\uTorrent
C:\Program Files\VideoLAN
C:\Program Files\Web Publish
C:\Program Files\Windows Live Safety Center
C:\Program Files\Windows Live Toolbar
C:\Program Files\Windows Media Connect 2
C:\Program Files\Windows Media Player
C:\Program Files\Windows NT
C:\Program Files\WinRAR
C:\Program Files\xerox
C:\Program Files\Yahoo!

------[ Listing des dossiers dans C:\Program Files\Fichiers communs ]-----

C:\Program Files\Fichiers communs\Adobe
C:\Program Files\Fichiers communs\Ahead
C:\Program Files\Fichiers communs\Bluebeam Software
C:\Program Files\Fichiers communs\Designer
C:\Program Files\Fichiers communs\eDrawings2006
C:\Program Files\Fichiers communs\FotoWire
C:\Program Files\Fichiers communs\InstallShield
C:\Program Files\Fichiers communs\Java
C:\Program Files\Fichiers communs\Logitech
C:\Program Files\Fichiers communs\Microsoft Shared
C:\Program Files\Fichiers communs\MSSoap
C:\Program Files\Fichiers communs\ODBC
C:\Program Files\Fichiers communs\Real
C:\Program Files\Fichiers communs\Services
C:\Program Files\Fichiers communs\Solidworks Data
C:\Program Files\Fichiers communs\SpeechEngines
C:\Program Files\Fichiers communs\Symantec Shared
C:\Program Files\Fichiers communs\System
C:\Program Files\Fichiers communs\WhenU

----------------------[ Recherche dans le Registre ]----------------------

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]


[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]


-----------------[ Recherche de Fichiers - Dossiers Lop ]-----------------

C:\WINDOWS\tasks\A7E7BDD091D42E90.job

--------------------[ Vérification du fichier Hosts ]---------------------

Fichier Hosts : Propre

--------------------[ Recherche d'autres infections ]---------------------


--------------------[ Fin du rapport à 19:14:31,60 ]----------------------


Répondre à bugland

Re,

Télécharge OTMoveIt (d'OldTimer). Sauvegarde-le sur ton Bureau.
Sélectionne TOUS les emplacements en gras ci-dessous :

C:\Documents and Settings\All Users\Application Data\Delete Hide Support Math
C:\Documents and Settings\All Users\Application Data\title tool face bin
C:\Documents and Settings\All Users\Application Data\wave log show title
C:\Documents and Settings\Camille\Application Data\army file bows
C:\Documents and Settings\Jonathan\Application Data\army file bows
C:\WINDOWS\tasks\A7E7BDD091D42E90.job
C:\Program Files\army file bows
C:\Program Files\Fichiers communs\WhenU


---> Clique-droit puis Copier (ou Ctrl+C)

Double-clique sur OTMoveIt.exe afin de le lancer.
Fais un Clique-droit sur le cadre de gauche puis choisis Coller (ou Ctrl+V).
Clique maintenant sur MoveIt!

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.


Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log

->Informations sur le logiciel<-

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Voila le rapport OTMoveIt :

Citation :


C:\Documents and Settings\All Users\Application Data\Delete Hide Support Math moved successfully.
C:\Documents and Settings\All Users\Application Data\title tool face bin moved successfully.
C:\Documents and Settings\All Users\Application Data\wave log show title moved successfully.
C:\Documents and Settings\Camille\Application Data\army file bows moved successfully.
C:\Documents and Settings\Jonathan\Application Data\army file bows moved successfully.
C:\WINDOWS\tasks\A7E7BDD091D42E90.job moved successfully.
C:\Program Files\army file bows moved successfully.
C:\Program Files\Fichiers communs\WhenU moved successfully.

Created on 09/23/2007 19:32:57


Répondre à bugland

Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Rapport Hijackthis :

Citation :


Logfile of HijackThis v1.99.1
Scan saved at 19:41:33, on 23/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\Jonathan\Bureau\OTMoveIt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Jonathan\Bureau\Outils de netoyage virus\hijackthis\HijackThisAide.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB002" /M "Stylus CX6600"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [face bin load show] C:\Documents and Settings\All Users\Application Data\title tool face bin\Fast Dash.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?2bda6f0555224614989493e51d1d0f37
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?2bda6f0555224614989493e51d1d0f37
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bugland1985.spaces.live.com [...] nPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)



Répondre à bugland

Re,

Re,

Fix les lignes en italique ci-dessous avec Hijackthis : AIDE EN IMAGES

O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O4 - HKLM\..\Run: [face bin load show] C:\Documents and Settings\All Users\Application Data\title tool face bin\Fast Dash.exe

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Ok c'est bon j'ai effectué l'opération.

Répondre à bugland

Reposte un rapport Hijackthis.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Rapport Hijackthis :

Citation :


Logfile of HijackThis v1.99.1
Scan saved at 20:46:25, on 23/09/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\notepad.exe
C:\Documents and Settings\Jonathan\Bureau\OTMoveIt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Comptes et Budget Free V5.0\Comptes.exe
C:\WINDOWS\system32\rundll32.exe
C:\Documents and Settings\Jonathan\Bureau\Outils de netoyage virus\hijackthis\HijackThisAide.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EE.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB002" /M "Stylus CX6600"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?2bda6f0555224614989493e51d1d0f37
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?2bda6f0555224614989493e51d1d0f37
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\npjpi160_02.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://bugland1985.spaces.live.com [...] nPUpld.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-F [...] E_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/bina [...] b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/bina [...] b32846.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Apache Tomcat (Tomcat5) - Unknown owner - C:\Program Files\Apache Software Foundation\Tomcat 5.5\bin\tomcat5.exe" //RS//Tomcat5 (file missing)



Répondre à bugland

Ton pc se comporte mieux ?

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Pour le moment j'ai pas encore eu de pub, donc c'est plutot bon signe.
En tout cas merci beaucoup, pour ta patience.

Jai quand même une question à te poser, comment tu fais pour arrivé a diagnostiquer un problème et à savoir la procédure à suivre pour le régler, pour mon cas par exemple.

Répondre à bugland

Citation :

Jai quand même une question à te poser, comment tu fais pour arrivé a diagnostiquer un problème et à savoir la procédure à suivre pour le régler, pour mon cas par exemple.


Lecture + Expérience ;)

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark

Je pensais que vous aviez des procédures spéciales suivant les cas.

Répondre à bugland

Il peu y avoir des ressemblances mais chaque cas est différent.

------------------------------ Prévention & Protection||Vous m'aimez ? Cliquez :o
Répondre à Angeldark
Tom's Guide > Forum > Sécurité - Virus > Pub CID intempestives
Aller à :

Il y a 536 utilisateurs connus et inconnus. Pour voir la liste des connectés connus, cliquez ici.

Attention

Vous allez répondre sur un sujet resté inactif pendant plus de 6 mois.
Assurez-vous d'apporter des éléments nouveaux à la discussion avant de poursuivre.

Répondre Annuler
Liens